Privacy Policy
Last updated: August 22, 2026
1. Introduction
Zenthra Global Consulting ("Zenthra," "we," "us," or "our"), a company registered in India with its principal office at Malakpet, Hyderabad, Telangana, is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you visit our website at zenthra.com (the "Site") and use our services.
This policy is published in accordance with the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR").
By accessing or using our Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Site immediately.
2. Definitions
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, 2023, and includes "personal information" as defined under the IT Act and SPDI Rules.
- "Sensitive Personal Data or Information" ("SPDI") includes passwords, financial information (bank account, credit/debit card details), health data, biometric data, sexual orientation, and any other information as specified under Rule 3 of the SPDI Rules.
- "Data Principal" refers to the individual to whom the personal data relates.
- "Data Fiduciary" refers to Zenthra Global Consulting, which determines the purpose and means of processing personal data.
- "Processing" includes collection, storage, use, disclosure, sharing, erasure, or destruction of personal data.
3. Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide Directly
- Identity Data: Full name, job title, company name.
- Contact Data: Email address, phone number, mailing address.
- Enquiry Data: Messages, queries, and any other information you submit through our contact form, email, or other communication channels.
- Contractual Data: Information provided during the course of a business engagement, including billing details and service requirements.
3.2 Information Collected Automatically
- Technical Data: Internet Protocol (IP) address, browser type and version, operating system, device type, screen resolution, time zone, and language preferences.
- Usage Data: Pages visited, time spent on pages, click patterns, referring/exit URLs, and navigation paths.
- Cookie Data: Information collected via cookies and similar tracking technologies (see Section 9 below).
3.3 Information from Third Parties
We may receive personal data from analytics providers (such as Google Analytics), advertising networks, social media platforms, and publicly available sources such as business directories and LinkedIn.
4. Purpose and Legal Basis for Processing
We process your personal data only for the following lawful purposes:
- Performance of Contract: To provide our consulting, BPO, call centre, lead generation, and customer support services as agreed upon in our service agreements.
- Consent: Where you have given explicit consent (e.g., subscribing to newsletters, submitting enquiry forms). Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous.
- Legitimate Interests: To improve our services, website functionality, and user experience; to conduct business analytics; and to prevent fraud or security threats.
- Legal Compliance: To comply with applicable Indian laws (including the IT Act, Companies Act, 2013, and GST/Income Tax regulations) and international regulations.
5. Disclosure and Sharing of Data
We do not sell, rent, or trade your personal data. We may share your data with:
- Service Providers: Third-party vendors who assist us in operating our website, conducting business, or servicing you (e.g., cloud hosting, email delivery, CRM systems), bound by strict confidentiality and data processing agreements.
- Legal Authorities: When required by law, regulation, court order, or governmental request, including requests from Indian authorities under the IT Act or DPDP Act and international law enforcement under applicable Mutual Legal Assistance Treaties (MLATs).
- Business Transfers: In connection with any merger, acquisition, reorganisation, or sale of assets, your data may be transferred as part of the transaction, subject to this Privacy Policy.
- With Your Consent: For any purpose not described herein, we will seek your explicit consent before sharing.
6. Cross-Border Data Transfers
As a global consulting firm, we may transfer your personal data to countries outside India for the purposes described in this policy. Such transfers shall be conducted in compliance with:
- Section 16 of the DPDP Act, 2023, which permits transfers to countries not restricted by the Central Government of India.
- Chapter V of the GDPR (for EEA/UK data subjects), using Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
We ensure that adequate safeguards are in place to protect your data regardless of where it is processed.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Contractual data: For the duration of our business relationship plus a period of 8 years thereafter (in accordance with the Indian Limitation Act, 1963, and Companies Act record-keeping requirements).
- Enquiry data: For up to 2 years from the date of your last interaction.
- Technical/usage data: For up to 26 months from collection.
After the applicable retention period, your data is securely deleted or anonymised.
8. Your Rights
8.1 Under Indian Law (DPDP Act, 2023)
As a Data Principal, you have the right to:
- Access: Obtain a summary of your personal data being processed and the processing activities.
- Correction and Erasure: Request correction of inaccurate or misleading data, completion of incomplete data, and erasure of data no longer necessary for the purpose for which it was collected.
- Grievance Redressal: Lodge a complaint with our Grievance Officer (details below) and, if unresolved, with the Data Protection Board of India.
- Nomination: Nominate another individual to exercise your rights in the event of your death or incapacity.
- Withdraw Consent: Withdraw previously given consent at any time, with the understanding that withdrawal does not affect the lawfulness of processing carried out prior to such withdrawal.
8.2 Under GDPR (for EEA/UK Residents)
If you are located in the European Economic Area or the United Kingdom, you additionally have the right to:
- Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format.
- Restriction of Processing: Request that we limit the processing of your data under certain circumstances.
- Object to Processing: Object to processing based on legitimate interests or for direct marketing purposes.
- Lodge a Complaint: With your local supervisory authority (e.g., the ICO in the UK, CNIL in France).
To exercise any of these rights, please contact us using the details in Section 14 below.
10. Data Security
We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules and Section 8 of the DPDP Act, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Access controls and authentication mechanisms limiting access to authorised personnel only.
- Regular security assessments and vulnerability testing.
- Incident response procedures compliant with CERT-In (Indian Computer Emergency Response Team) reporting requirements under the IT Act.
While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying you and the relevant authorities of any breach in accordance with applicable law.
11. Children's Privacy
Our Site and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us and we will take steps to delete such information in accordance with Section 9 of the DPDP Act.
12. Grievance Officer
In accordance with Rule 5(9) of the SPDI Rules and Section 8(10) of the DPDP Act, we have appointed the following Grievance Officer:
- Name: Grievance Officer, Zenthra Global Consulting
- Email: grievance@zenthra.com
- Address: Malakpet, Hyderabad, Telangana, India
The Grievance Officer shall acknowledge your complaint within 48 hours and resolve it within 30 days from the date of receipt, in compliance with applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Any material changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically. Your continued use of the Site after any modifications constitutes your acceptance of the revised policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- Email: info@zenthra.com
- Phone: +91 8977461804
- Address: Zenthra Global Consulting, Malakpet, Hyderabad, Telangana, India