Privacy Policy
Last updated: 10 October 2026. How MindTap Solutions collects, uses, shares and protects personal data.
Contents
- About this policy
- Laws we follow
- Information we collect
- Why we use your information and our legal grounds
- Consent and withdrawing it
- Who we share information with
- International transfers
- How long we keep information
- Security and data breaches
- Your rights
- Children
- Third-party websites and services
- Cookies and similar technologies
- Grievance Officer and contact
- EEA and UK representative
- Changes to this policy
- Governing law
1. About this policy
This Privacy Policy explains how MindTap Solutions ("MindTap", "we", "us") handles personal data when you visit mindtapsolutions.com (the "Website"), use our enquiry and booking forms, or correspond with us. It applies to visitors and business contacts worldwide.
For the purposes of the Digital Personal Data Protection Act, 2023 (India) we act as a Data Fiduciary; under the EU and UK General Data Protection Regulation we act as a controller; and under the California Consumer Privacy Act we act as a business. Our contact details are in section 14.
ESG Orbit has its own website (esgorbit.com) with its own policy. Enquiries about ESG Orbit that you submit through this Website are delivered to the ESG Orbit team at [email protected] and handled under this policy.
2. Laws we follow
We handle personal data in line with the laws that apply to us and to the people whose data we handle, including:
- India: the Digital Personal Data Protection Act, 2023 and the rules made under it as they come into force; the Information Technology Act, 2000; and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- European Economic Area and United Kingdom: the General Data Protection Regulation (EU) 2016/679, the UK GDPR and the UK Data Protection Act 2018, and the ePrivacy rules (including PECR in the UK).
- United States: the California Consumer Privacy Act as amended by the California Privacy Rights Act, and other applicable state privacy laws.
- Other regions where we do business, such as the UAE, Singapore, Canada and Australia, to the extent their data protection laws apply to us.
3. Information we collect
| Category | What it includes | Source |
|---|---|---|
| Enquiry and booking forms | Name, work email, company, phone number (optional), country, service of interest, team size, project timeline, preferred time to talk, your message, and a record of your consent (tick-box, date and time, and the version of this policy). | You |
| Email and calls | The content of messages you send us and our replies, and details you share when we arrange or hold a call. | You |
| Technical data | IP address, browser and device type, pages requested, and date and time of access, recorded in standard server logs by our hosting provider. | Collected automatically |
We do not ask for or intend to collect sensitive personal data (such as health data, government identifiers, biometric data, passwords, or bank or card details). The Website has no user accounts and takes no payments. It does not use cookies, analytics or advertising trackers (see our Cookie Policy). Please do not include sensitive personal data or confidential business information in forms or first emails; we will agree a confidentiality arrangement before you share such material.
4. Why we use your information and our legal grounds
| Purpose | Legal basis |
|---|---|
| Reply to your enquiry, arrange calls, scope work and prepare proposals; arrange ESG Orbit demonstrations | India: your consent, and legitimate use where you voluntarily provide data for a stated purpose (DPDP Act ss. 6-7). EU/UK: steps you request before a contract (GDPR Art. 6(1)(b)) and our legitimate interest in handling business enquiries (Art. 6(1)(f)). |
| Keep the Website secure, prevent abuse and troubleshoot problems (server logs) | Legitimate interests (GDPR Art. 6(1)(f)); legitimate use and reasonable security safeguards under Indian law. |
| Comply with law, respond to lawful requests, and establish, exercise or defend legal claims | Legal obligation (GDPR Art. 6(1)(c)); legitimate use for compliance with law (DPDP Act s. 7). |
| Contact you about other services or news | Only with your separate opt-in consent. We do not send unsolicited marketing. |
We do not make decisions about you using solely automated processing and we do not build profiles of Website visitors.
5. Consent and withdrawing it
Where we rely on consent, you give it by ticking the consent box on our forms after reading this policy. You may withdraw consent at any time by emailing [email protected]. Withdrawal does not affect processing done before you withdrew. If you withdraw, we will stop using your details for the enquiry and delete them unless the law requires or allows us to keep them.
6. Who we share information with
- Service providers (processors). Companies that host the Website and our email, and that help us operate our systems. They may use your data only to provide services to us and under written terms that require appropriate security and confidentiality.
- ESG Orbit team. ESG Orbit enquiries are delivered to [email protected].
- Professional advisers such as lawyers, accountants and auditors, under duties of confidentiality.
- Authorities and courts where we are legally required to disclose, or to protect rights, safety and security.
- Business transfers. If MindTap is involved in a merger, acquisition or restructuring, your data may transfer to the successor, which must honour this policy.
- Google Fonts. When you load a page, your browser requests font files from Google, which receives your IP address and browser details.
We do not sell personal information. We do not share it for cross-context behavioural advertising, and we do not disclose it to third parties for their direct marketing.
7. International transfers
We are based in India. Our service providers may store or process data in India or in other countries. Indian law permits transfers of personal data outside India except to countries the Central Government restricts by notification, and we will comply with any such restriction. Where we receive personal data of people in the EEA or UK, we protect transfers to India and to other countries without an adequacy decision with appropriate safeguards, such as the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum, or, where you contact us to take steps before a contract, the derogation in GDPR Art. 49(1)(b). You can request information about these safeguards by emailing [email protected].
8. How long we keep information
| Information | Retention |
|---|---|
| Enquiries that do not lead to an engagement | Up to 24 months after our last contact, then deleted or anonymised. |
| Records of engagements and related correspondence | For the duration of the engagement and then for the period required by applicable law (for example tax, accounting and contract-limitation periods). |
| Consent records | For as long as we hold the related personal data, plus the limitation period for claims. |
| Server logs | A short period set by our hosting provider, normally not more than 90 days. |
We delete or anonymise personal data once the purpose is served and no legal reason to keep it remains.
9. Security and data breaches
We apply reasonable security practices and procedures, including encryption of Website traffic in transit (HTTPS), access controls on our mailboxes and systems, limiting access to people who need it, and confidentiality obligations for personnel and providers. No method of transmission or storage is completely secure; email in particular is not end-to-end encrypted.
If a personal data breach occurs we will investigate promptly and notify the Data Protection Board of India and affected persons, and, where GDPR or UK GDPR applies, the relevant supervisory authority within 72 hours where required and affected individuals where there is a high risk to them, and any other regulator or person as the law requires.
10. Your rights
India (DPDP Act, 2023). You may: obtain a summary of the personal data we process and the processing activities, and the identities of those we have shared it with; ask us to correct, complete or update your data; ask us to erase your data; withdraw consent; use our grievance redressal (section 14); and nominate another person to exercise your rights if you die or become unable to do so.
EEA and UK (GDPR). You may request access to your data, correction, erasure, restriction of processing, portability, and object to processing based on legitimate interests. You may withdraw consent at any time, and you may complain to your local supervisory authority (in the UK, the Information Commissioner's Office).
California (CCPA/CPRA). You may request to know the categories and specific pieces of personal information we collected, the sources, purposes and recipients; to delete or correct it; and to opt out of the sale or sharing of personal information. We do not sell or share personal information and do not use sensitive personal information to infer characteristics. We will not discriminate against you for exercising your rights. In the past 12 months we collected identifiers (name, email, phone, IP address), professional information (company and role context), and internet activity limited to server logs. You may use an authorised agent, and we may need to verify your identity.
Other regions. You have the rights given by the law that applies to you.
How to exercise your rights. Email [email protected] with the subject "Privacy request". We will respond within the time the law requires (for example one month under GDPR, extendable where permitted, and 45 days under the CCPA, extendable where permitted). We do not charge a fee unless a request is manifestly unfounded or excessive. If you are not satisfied, you may complain to the Data Protection Board of India (after using our grievance process), your EEA or UK supervisory authority, or the California Attorney General or California Privacy Protection Agency.
11. Children
The Website is for business use and is not directed at anyone under 18 (under 16 in some regions). We do not knowingly collect personal data from children. If you believe a child has sent us personal data, email [email protected] and we will delete it.
12. Third-party websites and services
The Website links to other websites, including esgorbit.com and email applications. We do not control and are not responsible for their privacy practices. Please read their policies.
13. Cookies and similar technologies
We do not set cookies or use analytics or advertising trackers on the Website. See our Cookie Policy.
14. Grievance Officer and contact
For questions, requests or complaints about personal data, contact our Grievance Officer (Data Protection contact):
Grievance Officer, MindTap Solutions
Mumbai, Maharashtra, India
Email: [email protected]
We will acknowledge your message promptly and aim to resolve it within one month, or sooner where the law requires.
15. EEA and UK representative
If we are required to appoint a representative under Article 27 of the GDPR or UK GDPR, we will publish the representative's details on this page.
16. Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will post the updated version here with a new date, and where a change is material we will give a prominent notice on the Website. Where the law requires fresh consent, we will ask for it.
17. Governing law
This policy is governed by the laws of India, without limiting any mandatory rights you have under the data protection law of your country.