Last updated 7 October 2026
Privacy notice
What Comriq Studio collects when you contact us, why, and what you can ask us to do about it.
Version studio-1.0-draft
What we collect, and why
If you send us a project brief we collect your name, your company, your work email address, the country you are in, the budget band you chose, and whatever you write in the message box. We also record the options you picked in the scope estimator — the type of project, the platforms, the must-haves and the timeline.
We collect it for one purpose: to reply to you about the project you described, and to prepare a quotation if you want one. We do not use it to market unrelated services to you, and we do not sell it or share it for anyone else's marketing.
We record the moment you ticked the consent box, and which version of this notice you ticked it against. That is how we can show later what you actually agreed to.
The law we are working to
The Digital Personal Data Protection Act, 2023 and its Rules. The core duties under that Act apply from 13 May 2027.
Until then, sensitive personal data in India is governed by the Information Technology Act, 2000 s.43A and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Where we build for clients in the UAE or the United States, the UAE Personal Data Protection Law and the California Consumer Privacy Act apply to that work, and we build to them.
How to withdraw your consent
Email the grievance officer (see the grievance page) and say you want your enquiry deleted. You do not have to give a reason and we will not ask for one.
Withdrawing consent is as easy as giving it: one email, no form, no account. We will delete your enquiry and confirm when it is done.
You can also ask us for a copy of what we hold about you, ask us to correct it, and ask us to delete it.
How long we keep it
If you become a client, for as long as we work together and then for as long as Indian tax and company law requires us to keep the records of that engagement.
If you do not become a client, we keep the enquiry for 24 months so that we recognise you if you come back, and then delete it.
Access logs are kept for 180 days, which is what the CERT-In directions require.
Where your data is held
Our site and application hosting is on Vercel, our database is on Supabase, and our transactional email goes through Postmark. Those services run on infrastructure outside India as well as inside it, so your enquiry is processed outside India.
We use them because they are the services this site is built on and because each gives us a written data processing agreement. If you need your project's data to stay in a particular country, say so at the first call — it is a design decision, and it is much cheaper to make at the start.
Security
Data is encrypted in transit and at rest. Access is restricted to the people who need it and is logged. Backups are taken and restores are tested.
We have a written incident plan. If there is a personal data breach we report it to CERT-In within 6 hours, as the 2022 directions require, and we tell affected people.
Our systems synchronise their clocks to NTP, so the logs of an incident agree with each other.
Contact
Write to the grievance officer. The contact details are on the grievance page, and we answer.