Legal
Privacy policy.
What we collect on this website, why, on what legal basis, how long we keep it, and what you can require us to do about it.
Last updated 7 August 2026
Who is responsible for your data
Flutterfrog Software Solutions (LLP, GSTIN 33AAGFF7006F1ZU) is the controller of personal data collected through this website.
Registered address: No. 53C4, Kamarajar Nagar, Kattaiyanvilai, Nagercoil, Kanyakumari, Tamil Nadu 629003.
Email: gokul@theflutterfrog.com. Telephone: +91 89250 85605.
We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions, requests and complaints go to the grievance officer named at the bottom of this page, who is a real person and will answer you directly.
What we collect
Only what you type into the contact form. Your name, and then whichever of these you choose to give: company, email address, telephone number, the type of work you are enquiring about, and your message.
We also record which page or campaign you arrived from, taken from the ?e= parameter in the link you followed. That tells us which piece of our own work brought you here. It says nothing about you.
This site sets no cookies and runs no third-party scripts. No advertising pixels, no session recording, no fingerprinting. Your theme and motion preferences are stored in your own browser and never sent to us. There is no consent banner because there is nothing to consent to.
Why we use it, and on what legal basis
To answer your enquiry. Legal basis: steps taken at your request before entering into a contract (UK/EU GDPR Article 6(1)(b)), and our legitimate interest in responding to people who contact us (Article 6(1)(f)). Under India’s Digital Personal Data Protection Act 2023, submitting the form is your consent for this purpose.
To understand which of our work reaches people. Legal basis: legitimate interest (Article 6(1)(f)) in knowing whether our own writing and outreach is useful. The interest is limited and the data is not personal to you.
We do not use your details for marketing, we do not add you to a mailing list, and we do not sell, rent or share them with anyone for their own purposes.
Who else sees it
Enquiries are stored in a Google Firebase project we control, hosted in Google’s Mumbai region. Google acts as our processor and does not use the content for its own purposes.
The website itself is served from Google Firebase Hosting. Our email is operated by Hostinger.
The full list of parties who may process data on our behalf during a client engagement, with their purpose and location, is on the security page.
Where it goes
Data submitted through this website is stored in India. We are an Indian company, so our people access it from India.
India does not currently hold a UK or EU adequacy decision. Where personal data reaches us from the UK or EEA, the appropriate safeguard under Article 46 applies — the ICO’s International Data Transfer Agreement, or EU Standard Contractual Clauses with the UK Addendum. We will sign either on request, and our data processing agreement is published rather than held behind a sales conversation.
How long we keep it
Enquiries that do not become a project: deleted within 24 months of your last contact with us.
Enquiries that become a project: retained for the life of the engagement and for 8 years afterwards, the period Indian tax and companies legislation requires for business records.
Ask us to delete your details sooner and we will, unless the law requires otherwise.
Your rights
You can require us to:
- tell you what we hold about you, and give you a copy
- correct anything inaccurate or incomplete
- delete it
- stop or restrict how we use it
- hand it to you, or to someone else, in a machine-readable format
- stop relying on legitimate interest, where you object to it
Where we rely on your consent you can withdraw it at any time. Withdrawing it does not make anything we did beforehand unlawful.
Write to the grievance officer below. We respond within 30 days, usually within a few working days, and we do not charge for it.
Automated decision-making: we do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Is giving us your details compulsory? No. Nothing on this site requires it. Without a name and one contact method we cannot reply, which is the only consequence.
Security
Enquiries are written to a database that permits creation only — the browser cannot read back what has been stored, and reading it requires an authenticated administrator account. Data is encrypted in transit and at rest. Access is limited to named people under written confidentiality agreements.
If a breach affects your data we will tell you without undue delay, and notify the relevant authority within the time the law requires — six hours to CERT-In under the Directions of April 2022, and 72 hours to a supervisory authority under the GDPR.
Complaints
Tell us first — we would rather fix it. If you are not satisfied you can complain to a regulator.
India: the Data Protection Board of India, once constituted under the Digital Personal Data Protection Act 2023.
United Kingdom: the Information Commissioner’s Office, ico.org.uk.
EEA: your national supervisory authority.
Grievance officer
Gokul Kumar, Flutterfrog Software Solutions
gokul@theflutterfrog.com
No. 53C4, Kamarajar Nagar, Kattaiyanvilai, Nagercoil, Kanyakumari, Tamil Nadu 629003
Named in accordance with the grievance-redressal requirement under India’s Digital Personal Data Protection Act 2023 and the Information Technology (Reasonable Security Practices and Procedures) Rules 2011.
Changes
We review this policy at least once a year and update the date at the top whenever it changes. If a change materially affects how we use data you have already given us, we will contact you rather than rely on you noticing.