Data handling
On this page
We process prospect lists, CRM exports and business records that belong to our clients. This page says what we do with them. It is deliberately specific — a vague assurance is not worth reading.
Our role: we are a processor, not a controller
We process personal data only on our clients’ documented instructions. Our clients decide whose data is collected and why; we do the work they ask for and nothing else.
In GDPR terms we act as a processor. Under India’s DPDP Act we act as a Data Processor for a client who is the Data Fiduciary. We do not build prospect lists on our own initiative, we do not maintain a database of our own, and we do not decide the purpose of any processing.
One exception: job applications
Everything above is about data a client sends us. There is one category where we are not a processor at all, and it would be misleading to leave it out.
When somebody applies for a job through this site, we decide what that information is for — so for applications, and only for applications, we are the controller.
We collect a name, an email address, optionally a phone number and a link to your work, a CV, and a note about why. It is used to consider the application. It is shared with nobody: no recruiter, no job board, no third party of any kind.
An application is kept 12 months and then deleted, and the CV file is deleted with the record rather than left on disk. Ask us to delete yours sooner and we will.
The full detail is on our Privacy policy → page.
What we hold
- Prospect and contact lists supplied by clients
- CRM exports and business records supplied for cleaning, appending or migration
- Data we source at a client’s instruction and to their defined criteria
- Business contact details of client staff, for running the engagement
We source business contacts only — names, roles, company details and work email addresses. We do not source personal email addresses or home contact details.
Where it lives
Three places, and no others:
| Google Workspace — Gmail and Google Drive | Working files, everything you send us, everything we send back |
| Our website host (Hostinger, EU data centre) | Only what you submit through a form on this site. No client data files are ever stored here. |
| Company laptops, full-disk encrypted, screen-locked | Only while work is actively in progress |
Google stores Workspace data across its own global infrastructure; we do not purchase region-pinned storage, so we do not claim your data stays in one country. If your contract requires it to, tell us before the engagement starts and we will agree an arrangement in writing rather than assume one.
Client data stays in those three places. It is not copied to personal devices, personal cloud accounts, WhatsApp, or any AI tool. We do not run a client portal, and we do not keep client data on this website.
Who can reach it
Access is limited to the people working on your engagement. Every person has a named account — no shared logins. Two-factor authentication is required on email and on any system holding client data. Access is removed the day someone leaves a project, and the day they leave the company.
Our team is six people. You will know which of us is working on your data, by name.
How long we keep it
This is where most policies go vague. Ours does not:
| Raw data you sent us | Deleted within 30 days of final delivery |
| Deliverables we produced | Kept 90 days, so we can help if you come back with a question, then deleted |
| The engagement record — proposal, invoices, the deletion log | Kept 8 years, because Indian company law requires it. It contains no client data. |
| After deletion | Deleted items clear our provider’s systems within a further 30 days. We hold no separate backup of client data. |
| Enquiries sent through this site | Kept 12 months, then deleted. Ask us to delete yours sooner and we will |
| An application sent through this site | Kept 12 months, then deleted — and the CV file is deleted with the record, not left behind |
| Confirmation | We email you when the deletion is done |
Ask us to delete sooner and we will, and confirm it in writing. If you need a specific retention period written into a contract, we will agree one — these are our defaults, not a limit on what we can commit to.
Agreements
We sign an NDA with every client, and always have.
For clients in the EU and UK, we also sign a Data Processing Agreement on GDPR Article 28 terms, incorporating the European Commission’s 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum where transfers are involved. Ask and we will send ours, or we will sign yours.
Where we stand on the law
We would rather be precise than reassuring.
India — DPDP Act 2023. The Act is in force and its operative obligations phase in to May 2027. Where we process data about people outside India, for a client outside India, under contract, Section 17(1)(d) disapplies most of the Act. The obligation that continues to apply to us is Section 8(5) — reasonable security safeguards — and the controls described on this page are how we meet it. We are building toward the Rule 6 requirements ahead of May 2027.
EU and UK — GDPR. We are not established in the EU or the UK, and we do not act as a controller. Where our clients are EU or UK controllers, we contract on Article 28 terms and act only on their documented instructions. We assist with data subject requests, breach notification and impact assessments as that contract requires.
United States — CAN-SPAM. Every outbound campaign we run carries accurate headers, an honest subject line, our physical postal address, and a working opt-out that we honour within two business days. The law allows ten; two is our standard.
Email authentication. We set up SPF, DKIM and DMARC on your sending domain before the first campaign goes out, and include the one-click unsubscribe header that Google, Yahoo and Microsoft now require of bulk senders.
What we never do
- We do not sell data. Not raw, not aggregated, not anonymised.
- We do not reuse one client’s data to build another client’s list. Ever.
- We do not keep a copy of your data for our own purposes after an engagement ends.
- We do not send your data to a third-party AI service without a signed agreement
covering it, and never without telling you first.
- We do not source personal email addresses.
- We do not extract from any source whose terms prohibit it — and we will tell you when
that rules out something you were hoping for.
If something goes wrong
If client data is exposed, we tell you without delay — not after we have finished investigating. You get what we know, when we know it, and what we are doing about it.
Ask us
Questions about any of this, a copy of our DPA, or a deletion request: info@jskbusinesssolutions.com
JSK Business Solutions Private Limited · CIN U93000WB2013PTC196574 · Ground Floor, Surya Kiran Apartment, 17 Bharat Chandra Roy Path, Shyamnagar, North 24 Parganas, West Bengal 743127, India