Bedrock Standard
0%

Privacy Policy

Last Updated:

1. Our Approach to Privacy

At Bedrock Standard, we believe information should be handled deliberately.

This Privacy Policy explains what personal information we collect, why we collect it, how we use it, when we may share it, how long we retain it and the choices available to you.

This Privacy Policy applies to personal information collected through the Bedrock Standard website, enquiry forms, diagnostic tools, communications and other digital interactions operated by us.

Where a separate client agreement or specific privacy notice applies, that document may provide additional information.

2. Who Is Responsible for Your Information?

For personal data processed through this Website, the relevant data fiduciary / controller is:

[LEGAL ENTITY NAME]
trading as Bedrock Standard
Address: [REGISTERED ADDRESS]
Email: [PRIVACY EMAIL]

For privacy-related enquiries, please contact:

Privacy Contact: [NAME / ROLE] — [PRIVACY EMAIL]

3. Information We May Collect

Depending on how you interact with us, we may collect:

Information you provide directly

  • Name
  • Email address
  • Telephone number
  • Company name
  • Job title
  • Website address
  • Business information
  • Information about your business objectives
  • Information provided through an enquiry
  • Information provided through a diagnostic or audit
  • Project requirements
  • Communications with us
  • Documents or files you voluntarily submit
  • Any other information you choose to provide

Information collected automatically

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Pages visited
  • Referring website
  • Approximate geographic information
  • Interaction information
  • Access times
  • Diagnostic information
  • Other technical information necessary for Website operation, security and analytics

We will only collect and process categories of information that are actually enabled or used by the Website.

4. How We Use Personal Information

We may use personal information to:

  • Respond to enquiries
  • Understand your business requirements
  • Assess potential engagements
  • Prepare proposals
  • Provide requested services
  • Communicate regarding projects
  • Administer client relationships
  • Provide customer support
  • Operate and improve the Website
  • Maintain Website security
  • Prevent fraud, abuse and unauthorised activity
  • Understand Website usage
  • Send communications where permitted
  • Comply with legal obligations
  • Establish, exercise or defend legal claims
  • Perform other purposes disclosed at the point of collection

We will not use personal information for materially incompatible purposes without an appropriate legal basis or notice where required.

5. Lawful Basis for Processing

Where applicable, we process personal data in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules and regulations.

Depending on the circumstances, processing may be based on:

  • Your consent
  • Your request for a service or response
  • Performance of an agreement
  • Certain legitimate uses recognised by applicable law
  • Compliance with legal obligations
  • Another lawful basis available under applicable law

Where consent is required, we will request it in the manner required by applicable law.

6. Contact & Enquiry Information

When you contact Bedrock Standard, we use the information you provide to understand your enquiry and respond appropriately.

For example, if you use our contact or “Start a Conversation” interface, we may process:

  • Your name
  • Email
  • Company
  • Role
  • Business requirements
  • Project information
  • Information you voluntarily include in your message

We do not require you to provide information that is unnecessary for the stated purpose.

7. Business Diagnostics & Audits

If you use a Bedrock Standard diagnostic, audit or assessment tool, we may process information submitted as part of that assessment.

Such information may include business information, website information, commercial information and other information necessary to produce the requested assessment.

The purpose may include:

  • Generating an assessment
  • Identifying areas of opportunity
  • Communicating results
  • Recommending relevant services
  • Understanding potential engagement requirements

Any specific diagnostic may contain additional notices concerning the information it collects.

8. Cookies & Similar Technologies

The Website may use cookies or similar technologies for:

  • Essential Website functionality
  • Security
  • Remembering preferences
  • Analytics
  • Performance measurement
  • Other functions described at the time of collection

Where applicable law requires consent for non-essential cookies or similar technologies, we will provide an appropriate mechanism for obtaining and managing that consent.

9. Analytics

If analytics technologies are used, they may collect information about how visitors interact with the Website, including:

  • Pages visited
  • Time spent
  • Traffic sources
  • Device information
  • Browser information
  • Approximate location
  • Interaction events

Analytics data may be processed by third-party technology providers acting on our behalf or independently under their own terms.

10. Marketing Communications

Where permitted by law, we may send information relating to Bedrock Standard, our services, insights, events, publications, and other relevant business information.

Where consent is required, we will obtain it before sending such communications.

You may opt out of marketing communications at any time by using the unsubscribe mechanism provided or by contacting us. Opting out of marketing communications will not necessarily stop service-related or transactional communications.

11. Sharing Personal Information

We may share personal information where reasonably necessary with:

  • Employees and authorised personnel
  • Contractors
  • Professional advisers
  • Technology providers
  • Hosting providers
  • Analytics providers
  • Communication platforms
  • CRM providers
  • Payment providers
  • Cloud service providers
  • Specialist service providers
  • Legal or regulatory authorities where required
  • Other parties where you have authorised or requested such disclosure

We do not sell personal information as a commercial data product.

Where third parties process information on our behalf, we seek to use appropriate contractual, technical and organisational safeguards.

12. International Data Transfers

Some service providers or technology infrastructure used by Bedrock Standard may process information outside India.

Where personal data is transferred or processed internationally, we will take the steps required by applicable law.

The DPDP Act expressly contemplates processing outside India in connection with offering goods or services to individuals in India, subject to applicable restrictions and requirements.

13. Data Security

We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, disclosure, and destruction.

However, no digital system can be guaranteed to be completely secure. You should therefore avoid submitting passwords, payment-card information, authentication credentials or other highly sensitive information through general enquiry forms unless specifically requested through a secure process.

14. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including:

  • Providing services
  • Maintaining business records
  • Complying with legal obligations
  • Resolving disputes
  • Enforcing agreements
  • Maintaining security
  • Establishing or defending legal claims

When information is no longer required, it will be deleted, anonymised or otherwise disposed of in accordance with applicable requirements and our internal practices.

15. Your Rights

Subject to applicable law, you may have rights concerning your personal data, including rights to:

  • Obtain information about processing
  • Request access to personal data
  • Request correction of inaccurate information
  • Request erasure where applicable
  • Withdraw consent where processing is based on consent
  • Raise a grievance
  • Nominate another individual where provided for by applicable law
  • Exercise other rights available under applicable data-protection law

The DPDP Act provides Data Principals with rights including access to information about personal data, correction and erasure, grievance redressal and nomination, subject to the Act's conditions.

16. Withdrawing Consent

Where processing is based on consent, you may withdraw your consent subject to applicable law.

Withdrawal of consent does not affect processing that occurred before withdrawal or processing that may continue on another lawful basis.

Where applicable, we will provide a method for withdrawing consent that is reasonably comparable in ease to the method used to provide consent.

17. How to Make a Privacy Request

To exercise a privacy right or raise a privacy concern, contact:

Privacy Contact: [NAME / ROLE]
Email: [PRIVACY EMAIL]
Address: [REGISTERED ADDRESS]

Please provide sufficient information for us to understand and verify your request. We may need to verify your identity before responding to certain requests. We will respond within the timeframe required by applicable law.

18. Grievance Redressal

If you believe your personal information has been handled inappropriately, you may contact us using the details above.

We will review and respond to the grievance in accordance with applicable law. Where applicable law provides a right to escalate a grievance to a competent authority or Data Protection Board, you may exercise that right after following the applicable grievance process.

19. Children's Data

The Website is intended primarily for businesses and professionals. We do not knowingly seek to collect personal information from children for independent commercial purposes.

Where applicable law imposes additional requirements concerning children's personal data, we will comply with those requirements.

20. Third-Party Websites

Our Website may link to external websites. This Privacy Policy does not apply to third-party websites.

We encourage you to review the privacy policies of any external service before providing personal information.

21. Client Data

Where Bedrock Standard processes personal information supplied by a client as part of a client engagement, the applicable client agreement may establish additional responsibilities concerning that information.

Depending on the engagement, Bedrock Standard may process information on behalf of a client rather than for its own independent purposes. In those circumstances, the client's privacy notice and contractual instructions may also apply.

22. Confidential Business Information

Personal data is not the same as confidential business information. Where clients provide confidential business information, we handle that information in accordance with applicable contractual confidentiality obligations.

Our Terms & Conditions and client agreements may contain additional provisions concerning confidential information.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, technology, data practices, legal requirements, or other operational changes.

The updated version will be published on this page with a revised “Last Updated” date.

24. Contact Us

Bedrock Standard
Legal Entity: [LEGAL ENTITY NAME]
Registered Address: [REGISTERED ADDRESS]
Privacy Email: [PRIVACY EMAIL]
General Email: [GENERAL EMAIL]
Website: [WEBSITE DOMAIN]