1. Our Privacy Manifesto
"We do not just consult on data privacy; we architect it."
At Resolve & Evolve, we hold our own operations to the same exacting standards we set for our clients. This notice reflects that commitment — built to satisfy the EU GDPR, India's DPDP Act 2023, the CCPA, and every other major privacy framework.
Our one non-negotiable rule: We never sell your data. We only use it to deliver exceptional regulatory and commercial outcomes for you.
2. The Data We Collect
As a B2B privacy consultancy, we practise intentional data minimisation. We collect only what is strictly necessary to serve you.
A. Data You Provide to Us Directly
- Identity & Contact Data: Name, professional email, phone number, company name, and job title [collected when you book a consultation or contact us.]
- Service & Engagement Data: Information about your organisation's regulatory landscape, existing compliance frameworks, and operational context. [shared during gap assessments and advisory sessions.]
B. Data We Collect Automatically
- Technical Data: IP address, browser type, time zone, and operating system.
- Usage Data: How you navigate and interact with our website. This data is managed strictly via our Cookie Consent Manager; you remain in complete control of your data at all times.
3. Why We Use Your Data (And Our Lawful Basis)
We map every piece of data we collect to a specific purpose and a documented legal ground. No data is processed without a lawful basis.
| Purpose | What It Covers | Lawful Basis |
|---|---|---|
| Service Delivery | Execute contracts, deliver gap assessments, manage your account. | Performance of Contract |
| Site Improvement | Analyse traffic and improve our digital infrastructure. | Legitimate Interest / Consent |
| Communications | Regulatory updates, service responses, administrative notices. | Legitimate Interest / Consent |
| Legal Compliance | Maintain our own legal, tax, and accounting records. | Legal Obligation |
4. Who We Share Your Data With
We strongly believe that "One's compliance posture is only as strong as their weakest vendor" — and we take our own software supply chain seriously. We only share data with carefully vetted third-party processors, each bound by a signed Data Processing Agreement (DPA).
- Secure Cloud & Infrastructure Providers: To host our website and store encrypted business files (e.g., AWS, Google Workspace).
- Communication & CRM Tools: To manage inquiries and schedule consultations.
- Legal & Regulatory Authorities: Only when required by a binding legal mandate. Never pre-emptively, never voluntarily.
We never share, sell, license, or trade your personal data with any third party for their own commercial purposes.
5. Cross-Border Data Transfers
As a global consultancy, your data may be processed outside your home country. When it is, we ensure enterprise-grade safeguards are in place:
- EEA / UK: We rely on European Commission adequacy decisions or execute Standard Contractual Clauses (SCCs) with all processors.
- India (DPDP Act 2023): We adhere strictly to the localised data transfer frameworks mandated by the DPDP Act 2023 and DPDP Rules 2025.
- All Other Jurisdictions: Transfer impact assessments are conducted, and appropriate legal mechanisms are in place before any cross-border transfer occurs.
6. Your Global Privacy Rights
We believe privacy is a fundamental human right. Regardless of where you are in the world, the following rights apply to your data in our systems:
| Your Right | What It Means |
|---|---|
| Right to Know | Request a full account of what personal data we hold about you and why. |
| Right to Correction | If your data is inaccurate or incomplete, we will correct it without delay. |
| Right to Erasure | Request permanent deletion of your data from our active systems (subject to overriding legal obligations). |
| Right to Portability | Receive a copy of your data in a structured, machine-readable format. (Not applicable for data collected as per DPDPA 2023) |
| Right to Withdraw Consent | Revoke any consent you have given at any time; with zero friction. |
| Right to Grievance Redressal | Raise a complaint with our Grievance Officer and receive a response within the timeframes prescribed by applicable law. |
How to exercise your rights: Email us at privacy@resolveandevolve.co. We acknowledge all requests within 72 hours and respond fully within 30 days.
7. Data Security & Retention
We prepare our clients for ISO 27001 and SOC 2 audits — which means our own security controls must be, and are, equally rigorous. We protect your data through:
- End-to-end encryption, both in transit (TLS 1.2+) and at rest.
- Role-based access controls — your data is accessible only to those with a documented business need.
- Regular vulnerability assessments and penetration testing of our own systems.
- Incident response procedures aligned with applicable breach-notification timeframes.
Retention: We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or to satisfy applicable legal, regulatory, tax, or accounting obligations. Once that purpose is fulfilled or you request erasure, your data is securely deleted.
8. Cookies & Tracking Technologies
We operate a fully consent-gated cookie framework. No non-essential cookies or tracking scripts are activated until you provide free, specific, and informed consent via our Cookie Consent Manager.
- Essential Cookies: Strictly necessary for the website to function. No consent required.
- Analytics Cookies: Only activated upon your explicit consent. You may withdraw at any time.
- Marketing / Tracking Cookies: We do not deploy targeted advertising or behavioural profiling tools on our website.
For full details, see our Cookie Policy.
9. Updates to This Notice
The privacy regulatory landscape evolves — and so will this Notice. We review it at least annually and whenever there is a material change in law or our operations. If we make significant updates, we will notify you via a prominent banner on our website or a direct email to your registered address.
10. Contact Our Privacy Team
For questions, rights requests, or concerns about our data practices, contact us through any of the following channels:
| Privacy Queries | privacy@resolveandevolve.co |
|---|---|
| Grievance Officer | Amrita Grover, Independent Privacy Counsel — grievance@resolveandevolve.co |
| Registered Address | Resolve & Evolve, Bangalore, India |
| Website | www.resolveandevolve.co |
If you are located in India and remain unsatisfied with our response, you have the right to escalate your grievance to the Data Protection Board of India under the DPDP Act 2023.
Resolve & Evolve — We practise what we preach.
Privacy. Security. Compliance. Built from the inside out.