KENZED TECHLAB
Start a project
Legal / Privacy

Privacy Policy

What this website collects, what happens to an enquiry once you send it, how we handle data inside a client engagement, and the rights you hold over all of it.

In short
  • This website has no server, no database, no analytics and no advertising pixels.
  • It sets no cookies. Two preferences live in your browser's local storage and never leave it.
  • Forms compose a message and hand it to WhatsApp or your mail client — you send it, not us.
  • Data you send us by any channel is used to answer you, and for nothing else.

This summary is written for speed of reading and is not itself the agreement. Where it and the numbered sections below differ, the sections govern.

1. Who is responsible

Kenzed Tech Lab, of Rajbandh, Durgapur – 713212, West Bengal, India, decides why and how personal data reaching us through this site is handled. In the language of India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary; under the GDPR we are the controller. Reach us at [email protected].

Where we process data on a client's behalf inside an engagement, that client is the controller and we act as processor under the terms of the agreement between us. Section 6 covers that case.

2. What the website itself collects

Nothing, in the ordinary sense. kenzed.in is a statically exported set of files. There is no application server behind it, no database, no analytics tag, no advertising or social pixel, no session tracking and no profiling of visitors. We do not know who visits, how often, or what they read.

Typefaces are compiled into the site at build time and served from our own origin, so loading a page makes no request to Google Fonts or to any other third-party host.

Two small preferences are written to your browser's local storage so the site behaves the way you left it. They stay on your device, are never transmitted anywhere, and clearing your site data removes them:

Stored value
Why it exists
Theme choice
Remembers whether you selected the light or dark theme, so the page does not flash the wrong one on your next visit.
Assistant greeting flag
Records that the chat assistant has already introduced itself, so it does not greet you again on every page.

Our hosting provider will keep ordinary server logs — IP address, timestamp, requested path, user agent — as every web host does, for delivery and abuse prevention. We do not use those logs to build any profile of you and we do not combine them with anything else.

3. What happens when you send an enquiry

Every form on this site — contact, product enquiry, internship application, newsletter — is validated in your browser and then assembled into a message that opens in WhatsApp, or in your mail client. Your entries are not posted to us in the background; the browser hands the composed message to you, and you send it.

Depending on the form, that message contains what you typed:

  • your name, work email, and optionally your company and phone or WhatsApp number;
  • the service or product you are enquiring about, and any budget band you chose;
  • the message you wrote;
  • for an internship application, the role, your education and the links you supplied.

Once sent, the message sits in our WhatsApp Business inbox or our mailbox. It travels over WhatsApp's infrastructure and is subject to WhatsApp's own privacy policy alongside this one; if you would rather not involve WhatsApp, email us directly instead.

The honeypot field on our forms is a hidden input that only automated submitters fill. If it is filled we discard the submission silently. It records nothing about you.

4. Why we use it, and on what basis

What we do with it
Lawful basis
Reply to your enquiry, scope the work, and send you a proposal
Steps taken at your request before entering a contract (DPDP: your consent, given by sending the enquiry; GDPR Art. 6(1)(b))
Deliver and support an engagement you have signed
Performance of a contract (GDPR Art. 6(1)(b))
Assess an internship or job application
Steps at your request before a contract, and our legitimate interest in recruiting
Send you the occasional update if you asked for one
Your consent, withdrawable at any time
Keep records of what was agreed, invoiced and paid
Legal obligation, and our legitimate interest in defending claims
Protect the site and our systems from abuse
Our legitimate interest in security

We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to train models, our own or anyone else's. We do not make automated decisions about you that produce legal or similarly significant effects.

5. Who else touches it

A short list, and it is the whole list:

  • WhatsApp (Meta) — carries an enquiry message if you choose that route;
  • our email and hosting providers — carry and store mail and serve this site;
  • professional advisers, and a regulator or court where we are legally required to disclose;
  • an acquirer, if the business is ever sold — with notice to you and no change of purpose.

Where a provider is outside India, the transfer rests on the recipient being in a jurisdiction not restricted under the DPDP Act, and for personal data covered by the GDPR, on Standard Contractual Clauses or an adequacy decision.

6. Data inside a client engagement

When we build or run a system for a client, we may process personal data belonging to that client's users. In that relationship the client decides the purpose and we act on documented instructions, under the data-processing terms of the signed agreement.

Our standing commitments in that role: least-privilege access for named engineers only; encryption in transit and at rest; environment separation between development, staging and production; and no use of client data to train models or improve our own products.

We operate our own GPU compute at the Durgapur engineering centre, which is why private and on-premise inference is possible for clients who cannot send data to a third-party model provider. Where an engagement does use an external model API, that is agreed in writing and named in the agreement.

If you are an end user of a system we built for someone else, that organisation is the controller and its privacy notice governs. We will pass your request on to them; ask us and we will tell you who to approach.

7. How long we keep it

Category
Retention
An enquiry that does not become an engagement
Up to 24 months, then deleted
Engagement records, contracts and invoices
8 years from the end of the engagement, to meet Indian tax and company-law requirements
Unsuccessful internship and job applications
12 months, unless you ask us to keep you on file for longer
Newsletter subscription
Until you unsubscribe
Client data processed under an engagement
As the agreement specifies — returned or destroyed at the end of it

8. Your rights

Whatever framework applies to you, you can ask us to do these things, and we will not charge you or treat you differently for asking:

  • tell you what personal data of yours we hold and what we have done with it;
  • correct anything that is wrong, incomplete or out of date;
  • delete it, where we are not required to keep it;
  • give you a copy in a portable format, or send it to someone else;
  • stop, or restrict, a particular use — including any use resting on legitimate interest;
  • withdraw a consent you gave, without affecting what was lawful before you withdrew it;
  • nominate someone to exercise these rights for you if you cannot (a right the DPDP Act gives you specifically).

Write to [email protected] and we will verify who you are and respond — ordinarily within a business day, and within thirty days at the outside. If you are not satisfied you may complain to the Data Protection Board of India, or to your local supervisory authority in the EU or UK.

9. Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If a child's data has reached us, tell us and we will delete it.

Several of our education products are used by institutions whose students may be minors. In those deployments the institution is the controller and holds any consent required under the DPDP Act; we process only on its instructions.

10. Security

The site is served over HTTPS as static files, which leaves it very little to attack. Our internal systems run on least-privilege access, encrypted storage, multi-factor authentication and a physically secured facility with CCTV and biometric access control.

No system is perfectly secure. If a breach affects your personal data we will notify you and the appropriate authority as the law requires, and tell you plainly what happened and what to do about it.

11. Changes to this policy

We update this policy when what we do changes — not on a schedule. The date at the top is the operative one. A change that materially affects how we handle data already given to us will be notified to the people affected before it takes effect.

12. Contact

Questions about this document, or any request you are entitled to make under it, should go to [email protected]. Post reaches us at the engineering centre: Rajbandh, Durgapur – 713212, West Bengal, India.

We answer within one business day in the ordinary course, and within thirty days at the outside for anything that needs a formal response.

Effective 26 August 2026Kenzed Tech Lab · Durgapur, West Bengal[email protected]