Smikap
Legal

Privacy Policy

How Smikap collects, uses and protects personal data, in line with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

Last updated: 5 August 2026

1. Introduction

Smikap ("Smikap", "we", "us" or "our") is an information technology services provider based in Ahmedabad, Gujarat, India. We provide managed IT support, cloud infrastructure, cybersecurity, software development and digital marketing services to businesses.

This Privacy Policy explains how we collect, use, disclose, store, retain and protect personal data when you visit www.smikap.com (the "Website"), communicate with us, or engage us for services. It is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") and Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

By using the Website or providing your personal data to us, you confirm that you have read and understood this Policy. Where the law requires your consent, we will ask for it separately and clearly, and you are free to decline or withdraw it.

2. Who is responsible for your data

For personal data that we collect through the Website and in the course of our own business (for example enquiries, marketing and recruitment), Smikap acts as a Data Fiduciary under the DPDP Act and determines the purpose and means of processing.

Where we process personal data on behalf of a client as part of a services engagement, for example while administering that client's systems, we act as a Data Processor. In such cases the client remains the Data Fiduciary, our processing is governed by the written agreement with that client, and any request relating to that data should be directed to the client in the first instance.

3. Personal data we collect

We collect only the personal data that is necessary for the purposes described in this Policy. Depending on how you interact with us, this may include:

  • Identity and contact data such as your name, company name, job title, email address, postal address and telephone number.
  • Enquiry and engagement data such as the content of the messages, project briefs, requirements and correspondence you send us through our contact forms, email or telephone.
  • Recruitment data such as your curriculum vitae, employment history, educational qualifications and references, where you apply for a role with us.
  • Transaction and billing data such as billing address, purchase order references, invoice records, Goods and Services Tax registration details and Permanent Account Number, where required for statutory invoicing and tax compliance.
  • Technical and usage data such as your Internet Protocol address, browser type and version, device and operating system details, referring pages, and the pages you view on the Website, collected through server logs and analytics.
  • Marketing preferences such as your newsletter subscription status and your choices about receiving communications from us.

We do not knowingly collect financial information such as full card or bank account numbers through the Website. Where payment is required, it is processed through banking channels or a third party payment provider that handles those details directly.

We do not seek sensitive personal data through the Website beyond what is described above. Please do not send us passwords, health information or other sensitive details through our contact forms.

4. Children and persons with a guardian

Our Website and services are directed at businesses and are not intended for children. We do not knowingly collect the personal data of any individual below the age of eighteen years without verifiable consent of a parent or lawful guardian, as required by Section 9 of the DPDP Act. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

If you believe that a child has provided personal data to us, please write to us at privacy@smikap.com and we will delete it promptly.

5. Purposes and lawful basis of processing

We process personal data only for lawful purposes, and only where the DPDP Act permits it, namely with your consent or for a legitimate use recognised by law. Our purposes are:

  • To respond to your enquiries, prepare proposals and quotations, and communicate with you about a possible engagement.
  • To deliver, support, maintain and improve the services you or your organisation have engaged us to provide.
  • To administer contracts, raise invoices, collect payment and maintain accounting records.
  • To operate, secure and improve the Website, diagnose technical faults, and prevent fraud, abuse and unauthorised access.
  • To send you newsletters, service updates and marketing communications where you have subscribed or where you are an existing client and the communication relates to similar services. You may opt out at any time.
  • To assess applications for employment and manage our recruitment process.
  • To comply with applicable law, respond to lawful requests from government or judicial authorities, and to establish, exercise or defend legal claims.

We will not use your personal data for a new purpose that is incompatible with those listed above without first informing you and, where required, obtaining your consent.

6. Cookies and similar technologies

The Website uses cookies and similar technologies. Strictly necessary cookies are required for the Website to function, for example to maintain security and to remember your form submissions. Analytics cookies help us understand how visitors use the Website so that we can improve it.

Most browsers allow you to refuse or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the Website from working correctly. Where required by law, we will request your consent before setting non essential cookies.

7. Disclosure and sharing

We do not sell, rent or trade personal data. We share personal data only in the following circumstances:

  • With service providers and processors who support our operations, such as cloud hosting, email delivery, customer relationship management, analytics and payment processing providers. These parties act on our documented instructions and are bound by confidentiality and data protection obligations.
  • With professional advisers such as auditors, accountants, bankers and lawyers, where necessary and subject to a duty of confidentiality.
  • With government authorities, regulators, courts or law enforcement agencies where disclosure is required or authorised by law, including under Section 91 of the Code of Criminal Procedure or an order of a competent court.
  • In connection with a merger, acquisition, restructuring or transfer of business assets, in which case the recipient will be bound to treat the personal data in accordance with this Policy.
  • With your consent or at your direction, in any other case.

8. Cross border transfers

Some of the service providers we use operate infrastructure outside India. Where personal data is transferred outside India, we do so in accordance with Section 16 of the DPDP Act and will not transfer data to any territory restricted by the Central Government by notification.

In all such cases we require that the recipient applies protections comparable to those described in this Policy, through contractual commitments and appropriate security measures.

9. Security safeguards

We implement reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000, read with the SPDI Rules, and take reasonable security safeguards as required under Section 8(5) of the DPDP Act.

These measures include encryption of data in transit, access controls on a need to know basis, authentication requirements for our systems, network protection, logging and monitoring, secure development practices, vendor due diligence, employee confidentiality obligations and periodic review of our controls.

No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee absolute security. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under the DPDP Act and the rules made under it, and will report incidents to the Indian Computer Emergency Response Team where required.

10. Data retention

We retain personal data only for as long as it is necessary for the purpose for which it was collected, or for as long as we are required to retain it under applicable law.

Enquiry data that does not result in an engagement is ordinarily retained for up to twenty four months. Engagement and billing records are retained for the period prescribed under tax, company and accounting law, which is generally eight years. Recruitment data is retained for up to twelve months from the conclusion of the process unless you ask us to keep it longer for future openings.

When personal data is no longer required and no legal obligation to retain it applies, we erase it or irreversibly anonymise it.

11. Your rights as a Data Principal

Subject to the conditions and exemptions in the DPDP Act, you have the following rights in respect of your personal data:

  • Right to access information: to obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and processors with whom it has been shared.
  • Right to correction and erasure: to have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose for which it was collected and no law requires it to be retained.
  • Right to withdraw consent: to withdraw your consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and we may continue processing where another lawful basis applies.
  • Right to grievance redressal: to a readily available means of raising a grievance with us before approaching the Data Protection Board of India.
  • Right to nominate: to nominate another individual who may exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, write to our Grievance Officer using the details in section 14. We may ask you to verify your identity before acting on a request. We will respond within the timelines prescribed by law and, in any event, without undue delay.

You also have a duty under Section 15 of the DPDP Act not to impersonate another person, not to suppress material information, and not to raise false or frivolous grievances.

12. Marketing communications

If you have subscribed to our newsletter or otherwise agreed to receive marketing communications, you may unsubscribe at any time using the link in any email we send or by writing to privacy@smikap.com. We will action the request promptly.

Even if you opt out of marketing, we may still send you administrative or service related messages that are necessary for an ongoing engagement, such as invoices, security notices and support updates.

13. Third party links

The Website may contain links to third party websites, platforms and social media pages. We do not control those sites and are not responsible for their content or privacy practices. We encourage you to read the privacy policy of every website you visit.

14. Grievance Officer and contact

In accordance with Section 13 of the DPDP Act and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of our Grievance Officer are set out below. The Grievance Officer will acknowledge your complaint within twenty four hours and endeavour to resolve it within fifteen days of receipt.

Grievance Officer
Smikap
General enquiries
contact@smikap.com
Address
Ahmedabad, Gujarat, India

If you are not satisfied with our response, you may register a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act.

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology or legal obligations. The revised version will be posted on this page with an updated effective date, and where the changes are significant we will take reasonable steps to notify you. Your continued use of the Website after the revised Policy takes effect constitutes acceptance of it.

16. Governing law and jurisdiction

This Policy is governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy is subject to the exclusive jurisdiction of the courts at Ahmedabad, Gujarat, India.