Curlscape logo

Privacy Policy

Last updated: July 10, 2026 | Effective date: July 10, 2026

By using our website and services, you accept and consent to the practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our website or services.

1. Who we are

Curlscape Solutions Pvt. Ltd. (“Curlscape,” “we,” “us,” or “our”) operates the website https://curlscape.com (the “Site”) and provides AI consulting and engineering software services (collectively, the “Services”).

2. What this policy covers

This policy explains:

  • The personal data we collect
  • How and why we use it
  • Your choices and rights
  • How to contact us

It applies whenever you visit or interact with our Site or use our Services. It does not cover third-party websites or services we do not control.

3. The information we collect

CategoryExamplesLegal basis (GDPR) / Purpose
Account & contact dataName, email, phone, company, job titleContract performance; legitimate interest (customer support, account management)
Usage & device dataIP address, browser type, pages viewed, time spent, click streamsLegitimate interest (Site security, analytics, product improvement)
Billing & invoicing dataCompany name, billing address, tax IDs (e.g., GSTIN) — for invoicing SOW engagementsContract performance; legal obligation (tax and accounting)
Project dataEngineering data, files, and materials you share for the engagementContract performance; legitimate interest (service delivery)
Marketing preferencesNewsletter opt-in/opt-out statusConsent

Note: No special-category data (e.g., racial or health information) is intentionally collected.

4. How we collect data

  • Directly from you when you create an account, fill in forms, upload content, or communicate with us.
  • Automatically via cookies and similar technologies when you browse the Site.
  • From third parties such as payment processors, CRM integrations, or single-sign-on providers, as authorised by you.

5. Why we use your data

  1. Provide the Services and fulfil our contract with you.
  2. Operate and secure our Site (fraud detection, abuse prevention).
  3. Improve features, models, and user experience through analytics and feedback.
  4. Send service-related communications (transactional emails, security alerts).
  5. Send marketing communications if you have opted-in (you may unsubscribe anytime).
  6. Comply with legal obligations and enforce our Terms of Service.

6. Cookies & tracking technologies

We use:

TypePurposeOpt-out
Essential cookiesSite functionality, security, log-in sessionsCannot be disabled
Analytics cookies (Google Analytics 4)Measure traffic and performanceDenied by default; enabled only if you accept in the cookie banner

We use Google Analytics 4 only. We do not run advertising or marketing cookies. A consent banner appears on your first visit, and analytics is denied by default (via Google Consent Mode v2) until you accept. You can accept, reject, or change your choice at any time through the banner.

7. How we share data

We do not sell personal data. We share it only with:

  • Service providers who process data on our behalf (e.g., cloud hosting on AWS, payment processors, customer-support tools).
  • Business partners you explicitly connect to our platform (e.g., CRM integrations).
  • Legal authorities when required by law or to protect rights, property, or safety.
  • Successors in the event of a merger, acquisition, or asset sale, subject to this Policy.

All vendors are bound by contracts with strict confidentiality and security obligations.

8. International data transfers

We store data on AWS us-east-1 and eu-central-1 servers. When we transfer data outside India or the European Economic Area, we rely on EU Standard Contractual Clauses or equivalent safeguards.

9. Data retention

Data typeRetention period
Account dataWhile account is active + 2 years
Financial records7 years (statutory)
Logs & analytics12 months, then aggregated or deleted
Project dataDuration of the engagement, then returned or deleted per the SOW (unless retention is required for legal claims)

We delete or anonymise data at the end of these periods unless we must keep it for legal claims.

10. Your rights

Depending on your location (e.g., EU GDPR, UK DPA 2018, California CCPA/CPRA, India DPDP Act), you may:

  • Access, correct, or delete your personal data
  • Object to or restrict processing
  • Withdraw consent at any time
  • Receive a portable copy in a structured format
  • Lodge a complaint with your local data-protection authority

To exercise rights, email privacy@curlscape.com. We will respond within 30 days.

11. Security

We use technical and organisational measures such as:

  • TLS encryption in transit and AES-256 at rest
  • Role-based access controls
  • Continuous vulnerability scanning and penetration testing
  • ISO 27001-aligned policies and employee training

No Internet service is 100% secure, so we cannot guarantee absolute security.

12. Third-party links

Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s website. We strongly advise you to review the Privacy Policy of every site you visit, as we have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

13. Children’s privacy

Our Site and Services are not directed to children under 13 (or the minimum legal age in your jurisdiction). We do not knowingly collect data from minors. Contact us if you believe a child has provided personal data.

14. Changes to this policy

We may update this policy periodically. If changes are material, we will notify you by email or by prominently posting on the Site at least 14 days before they take effect.

15. Contact us

Data controller:
Curlscape Solutions Pvt. Ltd.
2302, Tower 18, Blueridge, Hinjewadi Phase 1, Pune, Maharashtra, India - 411057

Privacy enquiries and rights requests: privacy@curlscape.com

Book a free consultation