azyware

Privacy Policy

Effective 17 September 2026 · EasyGenTech Innovations Pvt Ltd, trading as Eazyware

This Privacy Policy explains how EasyGenTech Innovations Pvt Ltd, trading as Eazyware ("Eazyware", "we", "us"), collects, uses, shares and protects personal data when you visit theeazyware.com, contact us, or engage us to deliver services. It applies to prospective and existing clients, website visitors, job applicants and business contacts. It is written to satisfy the Digital Personal Data Protection Act, 2023 (India), the EU and UK General Data Protection Regulation, and the California Consumer Privacy Act as amended, to the extent each applies to you.

1. Who we are and how to reach us

The data fiduciary (controller) for personal data described in this policy is EasyGenTech Innovations Pvt Ltd, registered in Bengaluru, Karnataka, India, at the address at the end of this policy.

For any privacy question, request or complaint, email privacy@theeazyware.com. We aim to acknowledge requests within three working days and to resolve them within thirty days, or sooner where the law requires.

2. What personal data we collect

We collect only what we need to respond to you, deliver services and run our business.

  • Contact and enquiry data: name, work email, phone number, company, role, the industry you select and the content of your message, when you use a form, email us, book a call or message us on WhatsApp.
  • Commercial data: proposals, contracts, purchase orders, invoices, payment references and correspondence relating to an engagement. We do not store full card numbers; payments are processed by our payment providers.
  • Project data: information you or your organisation share with us so that we can deliver a service, which may include data about your customers or employees. We process this on your instructions as a data processor (see section 7).
  • Website usage data: pages visited, referring site, approximate location derived from IP address, device and browser type, collected through privacy-respecting analytics. We do not run advertising trackers.
  • Applicant data: CV, portfolio, references and interview notes if you apply for a role.
  • Preferences: your currency selection (INR or USD), stored in your browser only.

3. Why we process it and on what basis

  • To respond to enquiries and provide proposals: performance of a contract or steps at your request before entering one (GDPR Art. 6(1)(b)); consent given by your voluntary submission (DPDP s.6).
  • To deliver, support and invoice services: performance of a contract; legal obligation for tax and accounting records.
  • To operate and secure the website and our systems: legitimate interests in running a secure, reliable service.
  • To send you information about our services: consent, or legitimate interests where you are an existing business contact; you can opt out at any time.
  • To recruit: steps prior to entering an employment contract, and legitimate interests in evaluating candidates.
  • To comply with law, respond to lawful requests and enforce our terms: legal obligation and legitimate interests.

4. Marketing

We send marketing only where you have consented or where you are an existing business contact and the message relates to services similar to those you have enquired about. Every message contains an unsubscribe link, and you can also opt out by emailing privacy@theeazyware.com. We do not sell personal data and we do not share it with third parties for their own marketing.

5. Cookies and analytics

The website uses strictly necessary storage (for example, your currency preference) that does not require consent, and first-party or privacy-respecting analytics to understand aggregate usage. Where a non-essential cookie is used that requires consent under the law of your location, we ask for it before setting it. You can clear or block storage in your browser settings; the site will continue to work.

6. Who we share personal data with

We share personal data only with parties who need it to help us provide services, under written terms that restrict its use:

  • Infrastructure and hosting providers (for example Amazon Web Services, Vercel, Hostinger) in regions chosen to meet your residency requirements.
  • Productivity, communication and CRM tools we use to run the business, including our own TheEazy suite operated by EasyGenTech Innovations.
  • Payment processors (for example Razorpay, Stripe) and our accountants and auditors.
  • AI model providers (for example OpenAI, Anthropic, Google) only when a service you have engaged us for requires it and only in line with the data handling agreed in your contract. Project data is never used to train third-party models, and we use enterprise or API terms that prohibit provider training on inputs.
  • Professional advisers, insurers and regulators, and any successor in the event of a merger or acquisition, under confidentiality.
  • Public authorities where required by law.

7. Client project data: our role as processor

When you engage us to build or operate systems that process personal data of your customers, employees or users, you are the data fiduciary/controller and we act as a data processor on your documented instructions. Our Master Services Agreement or Statement of Work contains the processing terms: purpose limitation, confidentiality, sub-processor approval, security measures, assistance with data subject requests and breach notification, return or deletion at the end of the engagement, and, where required, standard contractual clauses for international transfers. We do not use client project data for any purpose other than delivering the agreed services, and we never use it to train or improve models for other clients.

8. International transfers

We are based in India and work with clients and providers in the United States, United Kingdom, European Union, United Arab Emirates and Australia. Where personal data is transferred across borders we rely on the mechanism appropriate to the originating jurisdiction: for EU and UK data, Standard Contractual Clauses or the UK International Data Transfer Addendum together with a transfer risk assessment; for Indian data, transfers to countries not restricted by the Central Government under the DPDP Act. For client project data we will host in the region you specify in the Statement of Work.

9. How long we keep data

  • Enquiries that do not become engagements: 24 months from last contact, then deleted.
  • Client contracts, invoices and related correspondence: 8 years after the end of the engagement, as required by Indian tax and company law.
  • Project data: for the duration of the engagement plus 90 days for handover and dispute resolution, unless you instruct earlier deletion or the contract states otherwise. Backups are rotated within 35 days thereafter.
  • Website analytics: aggregated after 14 months.
  • Applicant data: 12 months after the decision, unless you ask us to keep it for future roles.

10. Your rights

Depending on where you are, you have the right to access the personal data we hold about you, correct it, have it erased, restrict or object to its processing, receive it in a portable format, withdraw consent at any time, nominate a person to exercise your rights on your behalf (DPDP), and to complain to a supervisory authority: the Data Protection Board of India, the Information Commissioner's Office (UK), your EU member state authority, or the California Privacy Protection Agency. California residents also have the right to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights. To exercise any right, email privacy@theeazyware.com from the address we hold for you; we may ask for reasonable verification.

11. Security

We protect personal data with technical and organisational measures proportionate to the risk, described in our Security page, including encryption in transit and at rest, least-privilege access, multi-factor authentication, logging, vendor due diligence and staff training. No method is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the relevant authority without undue delay and within the periods the law requires.

12. Children

Our website and services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. Where a client engagement involves children's data (for example in education), we process it only as a processor under the client's instructions and applicable safeguards, including verifiable parental consent obligations that rest with the client as fiduciary.

13. Automated decision-making and AI

We do not make decisions about you that have legal or similarly significant effects solely by automated means. Systems we build for clients may include AI components; the client, as controller, decides how they are used, and we design them with human review, logging and explainability appropriate to the use case, as described in our Security page.

14. Changes to this policy

We will post any changes here with a new effective date, and, where a change materially affects how we use personal data we already hold, we will notify affected contacts by email.

15. Grievance officer and contact

In accordance with the DPDP Act and the Information Technology Act, 2000, our Grievance Officer can be reached at privacy@theeazyware.com or by post at EasyGenTech Innovations Pvt Ltd, No 7, 4th Floor, 1st Cross Rd, Balaji Layout, AMCO Colony, Koti Hosahalli, Bengaluru, Karnataka 560092, India.

EasyGenTech Innovations Pvt Ltd
No 7, 4th Floor, 1st Cross Rd, Balaji Layout, AMCO Colony, Koti Hosahalli, Bengaluru, Karnataka 560092, India