1. Introduction
LogixWork ("we," "us," or "our") is a software consultancy based in Bangalore, Karnataka, India, founded by Shravan Kumar Sharma. We provide end-to-end technology services including Discovery & Strategy, SaaS Development, AI Solutions, Mobile App Development, and Legacy Modernization.
This Privacy Policy describes how LogixWork collects, uses, stores, and protects personal data when you visit our website at https://logixwork.com (the "Site"), submit a contact form, or use our Calendly-powered scheduling feature.
We have drafted this policy to be consistent with the requirements of the Indian Digital Personal Data Protection (DPDP) Act, 2023, and to address the rights of visitors from the European Economic Area (EEA) and United Kingdom under the General Data Protection Regulation (GDPR), and visitors from California, USA under the California Consumer Privacy Act (CCPA/CPRA). Where requirements differ, we aim to apply the highest applicable standard.
What this Policy Does Not Cover:
This policy applies solely to data collected through our public marketing website. It does not apply to personal data processed in the course of providing professional services to clients. Such processing is governed by the applicable Master Services Agreement (MSA), Statement of Work (SOW), and/or Data Processing Agreement (DPA) executed between LogixWork and the respective client.
If you have any questions about this policy, please contact us at info@logixwork.com.
2. Controller / Data Fiduciary Identity
Under the GDPR, LogixWork acts as the Data Controller for personal data processed through this website.
Under the India DPDP Act 2023, LogixWork acts as the Data Fiduciary for personal data processed through this website.
Identity and Contact Details:
| Field | Details |
|---|---|
| Company Name | LogixWork |
| Founder | Shravan Kumar Sharma |
| Registered Location | Bangalore, Karnataka, India |
| Website | https://logixwork.com |
| info@logixwork.com |
Grievance Officer (India — DPDP Act 2023 & IT Act, 2000):
| Field | Details |
|---|---|
| Name | Shravan Kumar Sharma |
| Organisation | LogixWork |
| Location | Bangalore, Karnataka, India |
| info@logixwork.com | |
| Response Time | Within 30 days of receiving a grievance |
6.1 Grievance Officer
In accordance with the Information Technology Act, 2000 and rules made there under, the name and contact details of the Grievance Officer are provided below:
3. Scope and Application
This Privacy Policy applies to:
- Website visitors who browse any page at logixwork.com;
- Contact form submitters who send an inquiry through our website contact form;
- Calendly users who use our embedded Calendly widget to book a discovery or consultation meeting;
- Any other person who interacts with our website in a manner that results in the collection of personal data.
This Privacy Policy does not apply to:
- Employees or contractors of LogixWork, whose data is governed by internal employment or contractor agreements;
- Clients of LogixWork, whose data processed as part of service delivery is governed by separately executed written agreements, including Data Processing Agreements (DPAs) where applicable;
- Third-party websites linked from our site, which maintain their own privacy policies.
4. What Personal Data We Collect
We practice data minimisation. We collect only the personal data that is necessary for the purposes described in this policy. Below is a full account of the categories of personal data we collect.
4.1 Data You Provide Directly
Contact Form:
When you submit our website contact form, you provide us with:
| Data Field | Description | Required / Optional |
|---|---|---|
| Full Name | Your first and last name | Required |
| Email Address | Your business or personal email address | Required |
| Company Name | The organisation you represent | Optional |
| Project Type | The category of service you are inquiring about | Optional |
| Budget Range | Approximate budget for your project | Optional |
| Message / Description | Free-text description of your project or inquiry | Required |
We advise you not to include sensitive personal data (e.g., health information, financial account numbers, government identification numbers) in the free-text message field. We do not solicit such data, and if provided inadvertently, we will delete it promptly upon discovery.
Calendly Scheduling:
When you use our Calendly scheduling widget to book a call, you provide Calendly with:
| Data Field | Description |
|---|---|
| Full Name | Your name as provided to Calendly |
| Email Address | To send meeting confirmation and reminders |
| Meeting Preferences | Event type, duration |
| Time Zone | To display available times correctly |
| Notes / Questions | Optional free-text field provided by Calendly |
Calendly is a third-party processor. Please refer to Calendly's Privacy Policy for details on how they process your data.
4.2 Data Collected Automatically
Google reCAPTCHA v3 Signals:
We use Google reCAPTCHA v3 on our contact form to distinguish human users from automated bots and to prevent spam. reCAPTCHA v3 operates invisibly (no challenge is presented to the user). It collects:
- Hardware and software information (e.g., device type, browser type and version, operating system);
- Interaction patterns with the browser and the webpage (e.g., mouse movements, keystrokes — aggregated, not individual keylogger data);
- IP address;
- Cookies previously set by Google;
- Date and time of the request.
This data is processed by Google LLC in the United States. The reCAPTCHA service is subject to Google's Privacy Policy and Terms of Service. As reCAPTCHA v3 is integral to the security and functioning of the contact form, it is treated as a strictly necessary service.
Server Logs:
Our hosting provider (Vercel Inc.) automatically records standard server access logs, including:
- IP address of the requesting device;
- Date and time of the request;
- URL requested;
- HTTP status code returned;
- Browser user-agent string;
- Referring URL (if applicable).
These logs are used for security monitoring, debugging, and operational purposes. They are retained for approximately 90 days.
Analytics Data:
We use privacy-respecting, cookieless web analytics to understand how visitors use our site. The analytics data we collect includes:
- Pages viewed;
- Session duration;
- Device type (desktop, mobile, tablet);
- Browser type;
- Country of origin (derived from IP, not stored at individual level);
- Referral source.
Our analytics implementation is designed to be cookieless and to not store any personally identifiable information. We do not create individual user profiles or track users across sessions. This approach is designed to avoid triggering consent requirements for analytics under ePrivacy and DPDP frameworks.
Note: We use Vercel Analytics, a privacy-first, cookieless analytics solution.
4.3 Data We Do Not Collect
LogixWork expressly does not collect:
- Payment or financial data — we have no payment processing functionality on this website. Any commercial engagements are conducted through separately agreed invoicing processes;
- Health or medical data — we do not offer health-related services through this website;
- Government identification numbers — such as Aadhaar, PAN, passport numbers;
- Biometric data;
- Children's personal data — our site is not directed at persons under 18 years of age (or under 13 in applicable jurisdictions). See Section 15 for our Children's Privacy statement.
5. How We Use Your Data
We use the personal data we collect only for the purposes described below. We do not use your data for automated decision-making (including profiling) that produces legal or similarly significant effects on you.
| Data Category | Purpose of Processing | Legal Basis (GDPR) | India DPDP Basis |
|---|---|---|---|
| Contact form submissions | To read, assess, and respond to your business inquiry | Legitimate interests (Art. 6(1)(f)) | Consent / Legitimate use |
| Contact form submissions | To follow up on the inquiry and assess mutual fit | Legitimate interests (Art. 6(1)(f)) | Consent / Legitimate use |
| Calendly data | To schedule a discovery or consultation call | Contract performance (Art. 6(1)(b)) | Consent |
| Calendly data | To send meeting confirmations and reminders | Contract performance (Art. 6(1)(b)) | Consent |
| reCAPTCHA v3 signals | To prevent spam submissions and ensure form integrity | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Server logs | Security monitoring, intrusion detection, operational debugging | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Analytics data | To understand how the site is used and improve its content and performance | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| All personal data | To comply with applicable legal obligations (e.g., court orders, regulatory demands) | Legal obligation (Art. 6(1)(c)) | Legal obligation |
Our Legitimate Interests:
Where we rely on legitimate interests as our legal basis, we have conducted a legitimate interests assessment (LIA). Our legitimate interest is to run an effective business website, respond to genuine commercial inquiries, and protect our infrastructure from abuse. We have determined that this processing does not override the fundamental rights and freedoms of data subjects, given that:
- The data is used solely for the stated business purposes;
- We collect only the minimum data necessary;
- We do not sell, rent, or trade the data to third parties for marketing purposes;
- We provide clear disclosure and rights mechanisms.
6. Legal Bases for Processing (GDPR)
For visitors from the European Economic Area (EEA) and the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR:
6.1 Legitimate Interests (Article 6(1)(f))
We rely on legitimate interests for:
- Responding to contact form inquiries;
- Maintaining server logs for security and operational purposes;
- Running cookieless analytics to improve website performance;
- Using reCAPTCHA to protect our contact form from spam and abuse.
In each case, we have assessed that our legitimate interest is not overridden by your interests, fundamental rights, or freedoms.
6.2 Contract Performance (Article 6(1)(b))
We rely on contract performance (or steps taken at your request prior to entering a contract) for:
- Processing your Calendly booking to schedule a meeting you have requested;
- Sending meeting confirmation and reminder emails via Calendly.
6.3 Legal Obligation (Article 6(1)(c))
We may process your personal data to comply with applicable legal obligations, such as responding to lawful requests from competent authorities, courts, or regulators.
6.4 Consent (Article 6(1)(a))
Where we rely on consent (e.g., for any future non-essential cookies or marketing communications we may introduce), we will obtain clear, informed, freely given, and withdrawable consent before such processing begins. Currently, we do not rely on consent as our primary legal basis for any processing described in this policy, though consent functions as a secondary basis in the context of the India DPDP Act.
7. India DPDP Act 2023 — Specific Disclosures
The Digital Personal Data Protection Act, 2023 ("DPDP Act") governs the processing of digital personal data in India. As a company incorporated and operating in India, LogixWork complies with the DPDP Act.
7.1 Purpose Notice
At the time we collect your personal data (e.g., upon submission of the contact form), we provide you with a notice describing:
- The personal data being collected;
- The purpose for which it is being processed;
- How you can exercise your rights as a Data Principal.
This Privacy Policy serves as that purpose notice, and we present a summary notice at the point of data collection (the contact form).
7.2 Consent
Where we rely on consent as our legal basis under the DPDP Act, we will obtain consent that is:
- Free — not conditional on use of the website except where strictly necessary;
- Specific — for the particular purpose described;
- Informed — with reference to this Privacy Policy;
- Unambiguous — through a clear affirmative action (e.g., checking a box).
You may withdraw your consent at any time by contacting info@logixwork.com. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.
7.3 Grievance Officer
As required under the DPDP Act and the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, we have designated a Grievance Officer. Contact details are provided in Section 2 and Section 17.
7.4 Data Breach Notification
In the event of a personal data breach that is likely to cause harm to Data Principals, we will notify:
- The Data Protection Board of India (once established and operational) within the timeframe prescribed by the DPDP Rules;
- Affected individuals, where required by law or where notification is in their interest.
7.5 DPDP Rules 2025 — Phased Applicability
The DPDP Rules, 2025 are being notified in phases. We monitor regulatory guidance from the Ministry of Electronics and Information Technology (MeitY) and update our practices accordingly. Where DPDP Rules impose obligations on Data Fiduciaries that are not yet in force, we are taking preparatory steps to ensure timely compliance.
7.6 Significant Data Fiduciary
LogixWork does not currently meet the thresholds (volume of data processed, sensitivity, or potential impact) that would classify us as a Significant Data Fiduciary under the DPDP Act. We will reassess this as the business scales and as DPDP Rules are notified.
8. California Privacy Rights (CCPA / CPRA)
If you are a resident of California, USA, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information.
8.1 Right to Know
You have the right to request that we disclose to you:
- The categories of personal information we have collected about you;
- The categories of sources from which we collected it;
- The business or commercial purpose for collecting it;
- The categories of third parties with whom we share it;
- The specific pieces of personal information we have collected about you.
8.2 Right to Delete
You have the right to request that we delete personal information we have collected from you, subject to certain exceptions (e.g., to complete a transaction, comply with a legal obligation, or exercise free speech rights).
8.3 Right to Correct
You have the right to request that we correct inaccurate personal information we hold about you.
8.4 Right to Opt-Out of Sale or Sharing
We do not sell, rent, or share your personal information with third parties for their own marketing or commercial purposes. The concept of "sale" under the CCPA/CPRA does not apply to our data practices as described in this policy.
8.5 Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
8.6 How to Exercise Your California Rights
Submit a verifiable consumer request by emailing info@logixwork.com with the subject line "California Privacy Request". We will respond within 45 days of receiving a verifiable request, as required by law.
9. Third-Party Data Processors
We engage the following third-party companies ("processors" or "sub-processors") that may access or process personal data on our behalf. We enter into data processing agreements with processors where required by applicable law.
| Provider | Service | Data Shared | Processing Location | Privacy Policy |
|---|---|---|---|---|
| Google LLC | reCAPTCHA v3 (spam prevention) | Browser fingerprint signals, IP address, interaction data | USA (and globally) | https://policies.google.com/privacy |
| Calendly LLC | Meeting scheduling | Name, email address, meeting preferences, time zone | USA | https://calendly.com/privacy |
| GMAIL SMTP | Email delivery and communication services. | United States / Global | Privacy Policy | |
| Vercel Inc. | Website hosting & CDN | Server access logs, IP addresses | USA (global CDN) | https://vercel.com/legal/privacy-policy |
We do not permit our processors to use your personal data for their own purposes beyond the services they provide to us, except as required by law or as described in their own privacy policies (which you should review independently).
10. International Data Transfers
LogixWork is based in India. However, some of our third-party processors (Google, Calendly, Vercel) process data in the United States and potentially other countries.
10.1 GDPR (EEA/UK Visitors)
For transfers of personal data from the EEA or UK to the USA, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs): Where our processors are not covered by an adequacy decision, we ensure that appropriate SCCs (European Commission model clauses or UK IDTA) are in place. Major processors such as Google and Vercel maintain SCCs as part of their data processing agreements.
- Adequacy Decisions: We will rely on adequacy decisions where available and applicable.
10.2 India DPDP Act (Indian Data Principals)
Under Section 16 of the DPDP Act, personal data of Indian data principals may be transferred to countries/territories notified by the Central Government as permissible for cross-border transfers. We will comply with the cross-border transfer provisions of the DPDP Act and any Rules notified thereunder. Until specific country notifications are issued, we apply contractual safeguards with our overseas processors.
10.3 Processor Locations
| Processor | Data Processing Location |
|---|---|
| Google LLC | United States (globally distributed) |
| Calendly LLC | United States |
| Vercel Inc. | United States (global CDN) |
| SMTP Provider | [TBD] |
11. Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Contact form submissions | 24 months from the date of last meaningful contact, after which data is securely deleted or anonymised |
| Calendly booking data | Governed by Calendly's own retention policy; see https://calendly.com/privacy |
| Server logs (Vercel) | Approximately 90 days, as per Vercel's hosting practices |
| reCAPTCHA signals | Governed by Google's retention policies; see https://policies.google.com/privacy |
| Analytics data | Aggregated only; no personal identifiers retained. Aggregate statistics may be retained indefinitely |
| Legal / compliance records | As required by applicable Indian law (e.g., IT Act, Companies Act) — typically 7 years |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or rendered unreadable.
12. Data Security
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, unauthorised disclosure, or access.
12.1 Technical Measures
- HTTPS / TLS Encryption: All data transmitted between your browser and our website is encrypted using industry-standard TLS (Transport Layer Security). Our site enforces HTTPS with HSTS (HTTP Strict Transport Security).
- reCAPTCHA v3: Protects our contact form from spam and automated abuse.
- Infrastructure Security: Our website is hosted on Vercel's platform, which employs enterprise-grade physical and network security controls.
- No Payment Data Storage: We do not process or store payment card data on our website.
12.2 Organisational Measures
- Access to personal data is limited to authorised personnel with a legitimate need;
- We conduct periodic reviews of our data handling practices;
- We maintain this Privacy Policy and update it to reflect changes in our practices.
12.3 Limitations
No system is entirely secure. While we implement strong security measures, we cannot guarantee absolute security of data transmitted over the internet. If you believe your data has been compromised, please contact us immediately at info@logixwork.com.
12.4 Responsible Disclosure
If you discover a security vulnerability in our website or systems, we welcome responsible disclosure. Please report it to info@logixwork.com with the subject line "Security Vulnerability Disclosure".
13. Your Rights
Depending on your location, you may have the following rights regarding your personal data. We will respond to all valid requests promptly and within the timelines specified below.
13.1 GDPR Rights (EEA / UK Visitors)
If you are in the European Economic Area or the United Kingdom, you have the following rights under the GDPR:
| Right | Description |
|---|---|
| Right of Access (Art. 15) | Obtain confirmation of whether we process your personal data and receive a copy of it. |
| Right to Rectification (Art. 16) | Request correction of inaccurate or incomplete personal data we hold about you. |
| Right to Erasure (Art. 17) | Request deletion of your personal data where retention is no longer justified ("right to be forgotten"). |
| Right to Restriction (Art. 18) | Request restriction of processing while a dispute about accuracy or lawfulness is resolved. |
| Right to Portability (Art. 20) | Receive your personal data in a structured, commonly used, machine-readable format. |
| Right to Object (Art. 21) | Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling grounds. |
| Automated Decision-Making (Art. 22) | We do not carry out automated decision-making that produces legal or similarly significant effects on you. |
Right to Lodge a Complaint: You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or the Data Protection Authority in your EEA member state) if you believe we are processing your data unlawfully.
13.2 India DPDP Rights (Indian Data Principals)
Under the DPDP Act 2023, you have the following rights:
| Right | Description |
|---|---|
| Right to Information | Know what personal data we hold about you and how it is being processed. |
| Right to Correction & Completion | Request correction of inaccurate or incomplete personal data. |
| Right to Erasure | Request deletion of personal data that is no longer necessary for the purpose for which it was collected. |
| Right to Grievance Redressal | Lodge a grievance with our Grievance Officer (see Section 17) and receive a response within 30 days. |
| Right to Nominate | Nominate a trusted individual to exercise your rights on your behalf in the event of your death or incapacity. |
13.3 California CCPA / CPRA Rights
Refer to Section 8 for a full description of California privacy rights.
13.4 How to Exercise Your Rights
To exercise any of the rights listed above:
1. Email us at info@logixwork.com with the subject line "Privacy Request";
2. Include your full name and the email address you used when interacting with our website;
3. Describe the right you wish to exercise and the specific data it relates to;
4. We may ask you to verify your identity before processing your request;
5. We will respond within 30 days of receiving a verified request. Complex requests may require up to 60 days; we will notify you if this extension is necessary.
There is no charge for exercising your rights, except in cases of manifestly unfounded or excessive requests, where we may charge a reasonable fee or decline to act.
14. Cookies and Tracking Technologies
Our use of cookies and similar tracking technologies is described in detail in our Cookie Policy.
Summary:
- We use strictly necessary cookies and browser storage required for the website to function (including reCAPTCHA);
- We use cookieless analytics that does not set any cookies or store personal identifiers;
- The Calendly scheduling widget sets functional cookies only when you actively engage with it to book a meeting;
- We do not use advertising, targeting, or tracking cookies;
- We do not use cross-site tracking technologies.
reCAPTCHA and Browser Fingerprinting: Please be aware that Google reCAPTCHA v3 uses browser fingerprinting techniques (analysing browser attributes and interaction patterns) to assign a risk score. This is disclosed here in the interest of transparency. As this is integral to the security of the contact form, it operates without a consent prompt, but is disclosed in both this Privacy Policy and our Cookie Policy.
For full details, including how to manage cookie preferences, refer to our Cookie Policy.
15. Children's Privacy
Our website and services are directed at business professionals and are not intended for use by children. For the purposes of this policy:
- Under Indian law and the DPDP Act 2023, we treat persons under 18 years of age as children;
- Under the US Children's Online Privacy Protection Act (COPPA) and CCPA, we treat persons under 13 years of age as children.
We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate parental consent, we will take immediate steps to delete such data.
If you are a parent or guardian and believe that your child has submitted personal data to us, please contact us at info@logixwork.com and we will delete that information promptly.
16. Third-Party Links
Our website may contain hyperlinks to third-party websites, plugins, or services (for example, social media platforms, partner websites, or tools we recommend). These links are provided for your convenience and information only.
We are not responsible for the privacy practices or content of any third-party websites. Clicking on a third-party link will take you away from our site and subject you to that website's own privacy policy and terms. We encourage you to read the privacy policy of every website you visit.
The presence of a hyperlink on our website does not constitute an endorsement of that third party or their services.
17. Grievance Officer (India)
As required by the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (and the associated IT Rules 2011), LogixWork has designated a Grievance Officer to address data-related complaints and queries from Indian residents.
Grievance Officer Details:
| Field | Details |
|---|---|
| Name | Shravan Kumar Sharma |
| Organisation | LogixWork |
| Location | Bangalore, Karnataka, India |
| info@logixwork.com | |
| Response Time | Within 30 days of receipt of a written grievance |
How to Submit a Grievance:
1. Send an email to info@logixwork.com with the subject line "Data Grievance — DPDP Act";
2. Describe the nature of your grievance, the personal data concerned, and the relief you seek;
3. We will acknowledge your grievance within 3 working days and resolve it within 30 days of receipt.
If your grievance is not resolved to your satisfaction within 30 days, you may escalate it to the Data Protection Board of India once it is constituted and operational under the DPDP Act 2023.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable laws, or for other operational reasons. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy;
- Post the revised policy on our website at https://logixwork.com/privacy-policy;
- Where feasible and appropriate, notify you of significant changes via email (if you have provided us with your email address).
Your continued use of our website after the updated policy has been posted constitutes your acknowledgement of and agreement to the revised Privacy Policy. We encourage you to review this policy periodically.
For material changes that require fresh consent under applicable law, we will seek such consent before the changed processing begins.
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please reach out to us:
Bangalore, Karnataka, India
- Email: info@logixwork.com
- Website: https://logixwork.com
For privacy-related requests, use the subject line "Privacy Request" so we can route your email correctly.
For grievances under the India DPDP Act, use the subject line "Data Grievance — DPDP Act" and your request will be directed to the Grievance Officer.
We aim to respond to all privacy-related communications within 30 days.
This Privacy Policy was last reviewed and approved by LogixWork management on 14 August 2025.
Disclaimer: This document is prepared in good faith to reflect current legal requirements. It is not a substitute for independent legal advice. LogixWork recommends that this policy be reviewed by a qualified privacy lawyer prior to publication, particularly given the evolving nature of the DPDP Rules, 2025.