Skip to main content

Legal

Privacy Policy

Canny Technologies is committed to protecting your privacy. This policy explains what personal data we collect, how we use it, and the rights available to you under GDPR, UK GDPR, and CCPA.

Last updated:January 2025

1. Overview

This Privacy Policy applies to Canny Technologies("we", "us", "our"), a software development company incorporated in India, operating globally. Our services include AI automation, custom software development, SaaS product development, and related consulting.

This policy applies to all personal data processed through our website at cannytechnology.com, our client portals, and any other services we provide. By using our website or services, you acknowledge you have read and understood this policy.

We act as a Data Controller for personal data collected via our website and marketing activities. For data processed on behalf of clients while delivering software services, we act as a Data Processor.

2. Data We Collect

2.1 Data You Provide Directly

When you contact us, request a quote, or use our services:

  • Full name and job title
  • Email address and phone number
  • Company name and website
  • Project description and budget range
  • Any files or documents you choose to share
  • Communications via email, WhatsApp, or video call

2.2 Data Collected Automatically

When you visit our website, we and our third-party partners automatically collect:

  • IP address and approximate geolocation
  • Browser type and version, operating system
  • Pages visited, time on page, referral URL
  • Click patterns and scroll depth (analytics)
  • Device type and screen resolution
  • Session identifiers (cookies)

2.3 Data from Third Parties

We may receive limited data about you from LinkedIn (if you engage with our company page), referral partners, or business card exchanges at events.

3. How We Use Your Data

We use collected data to:

  • Respond to your enquiries and provide quotations
  • Deliver software development and consulting services
  • Send project updates, invoices, and service communications
  • Improve our website, services, and marketing (with your consent)
  • Send occasional newsletters or case studies (opt-in only)
  • Comply with legal and regulatory obligations
  • Prevent fraud and ensure website security (legitimate interest)
  • Conduct client satisfaction surveys (legitimate interest)

We do not sell, rent, or trade your personal data to third parties for commercial purposes.

5. Cookies & Tracking Technologies

We use cookies and similar technologies to operate our website and understand how visitors use it. For full details, please read our Cookie Policy.

Summary of Cookies Used

  • Essential cookies: Required for the website to function. No consent needed.
  • Analytics cookies: Google Analytics 4 — helps us understand site usage. Requires consent.
  • Marketing cookies: Used for retargeting ads. Requires explicit consent.

You can manage or withdraw your cookie consent at any time via our cookie preference centre, or by adjusting your browser settings.

6. Third-Party Services

We share data with the following categories of third parties, each under appropriate data processing agreements:

  • Google Analytics 4: Website analytics. Data anonymised and processed in the EU where possible.
  • Resend / Postmark: Transactional email delivery.
  • Notion / Linear: Project management (client project data only, under NDA).
  • AWS / Google Cloud / Azure: Cloud infrastructure for hosted client solutions.
  • Stripe / Razorpay: Payment processing. We do not store card details.
  • LinkedIn:Professional network and advertising. Governed by LinkedIn's own privacy policy.

We require all third-party processors to maintain appropriate security measures and to process data only on our documented instructions.

7. International Data Transfers

As an India-based company serving global clients, your data may be transferred to and processed in countries outside your own. Where transfers occur from the EEA or UK to countries without an adequacy decision, we implement appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs)
  • Binding Corporate Rules where applicable with sub-processors

You may request a copy of the safeguards we have in place by contacting us at [email protected].

8. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this policy or as required by law:

Data TypeRetention Period
Contact form enquiries (not converted)2 years
Client project records & communications7 years (legal requirement)
Invoice and financial records7 years (tax/legal)
Website analytics (GA4)14 months, then aggregated
Marketing email subscriptionsUntil unsubscribed + 1 year
Cookie consent records1 year

After retention periods expire, data is securely deleted or anonymised.

9. Your Rights (GDPR & UK GDPR)

If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:

Right of Access

Request a copy of your personal data we hold.

Right to Rectification

Correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your data ("right to be forgotten").

Right to Restriction

Restrict how we process your data in certain circumstances.

Right to Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing based on legitimate interest or direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing relies on it.

Right to Lodge a Complaint

Complain to your national supervisory authority (e.g., ICO in UK).

To exercise any of these rights, email [email protected]. We will respond within 30 days. We may need to verify your identity before processing certain requests.

10. California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: Request deletion of personal information, subject to certain exceptions.
  • Right to Opt-Out: We do not sell personal information. If this changes, you will be notified and given a clear opt-out mechanism.
  • Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights.
  • Right to Correct: Request correction of inaccurate personal information.

To submit a verifiable consumer request, email [email protected] with the subject line "CCPA Request".

11. Children's Privacy

Our website and services are not directed to children under 16 years of age, and we do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete it promptly.

12. Data Security

We implement appropriate technical and organisational security measures to protect your personal data, including:

  • TLS/HTTPS encryption for all data in transit
  • AES-256 encryption for data at rest
  • Access controls — data accessible only to authorised personnel on a need-to-know basis
  • Regular security audits and penetration testing
  • Staff data protection training
  • Incident response plan — we will notify affected individuals and relevant supervisory authorities within 72 hours of a confirmed breach where required by law

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated by:

  • Updating the "Last updated" date at the top
  • Displaying a notice on our website for 30 days after significant changes
  • Email notification to subscribers where changes materially affect their rights

Continued use of our website after changes are posted constitutes acceptance of the revised policy. We recommend reviewing this page periodically.

14. Contact Us / Data Protection Officer

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

Canny Technologies

Data Protection Contact

Email: [email protected]

Address: Bangalore, Karnataka, India

Response time: Within 30 days of receipt

If you are unhappy with our response, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, please contact your national supervisory authority.