CPaaS Studio ("we," "us," or "our") is committed to protecting and respecting your privacy in
accordance with the EU General Data Protection Regulation (GDPR). This policy explains how
we collect, use, and protect your personal data and outlines your rights as a data subject.
This policy is effective as of 10th July 2026 and was last updated on 1st January 2026.
1. Who We Are
Data Controller: CPaaS Studio
Contact: For any GDPR-related inquiries, please contact us at:
- Email: support@cpaas.studio
- Address: 2B, II Floor, SAS Arcade,
Parakkattu Temple Road,
Chembumukku, Kakkanad,
Kochi - 682021,
Kerala, India.
- Phone: +91 95444 97777
2. What Personal Data We Collect
We collect and process the following categories of personal data:
- Identity Data: Name, username, date of birth
- Contact Data: Email address, phone number, mailing address
- Technical Data: IP address, browser type, device information, operating
system
- Usage Data: Information about how you use our website and services
- Marketing Data: Your preferences in receiving marketing communications
- Transaction Data: Details about payments and services you have
purchased
- Communication Data: Records of correspondence and support interactions
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: You have given clear consent for us to process your personal
data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or
to take steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with legal
requirements
- Legitimate Interests: Processing is necessary for our legitimate
business interests, except where overridden by your rights
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- To provide and maintain our services
- To process your transactions and manage your account
- To communicate with you about our services, updates, and offers
- To improve our website, products, and services
- To comply with legal obligations and enforce our terms
- To detect and prevent fraud, security issues, and technical problems
- To conduct analytics and market research
- To send marketing communications (with your consent)
5. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold
about you
- Right to Rectification: You can request correction of inaccurate or
incomplete data
- Right to Erasure: You can request deletion of your personal data
("right to be forgotten")
- Right to Restriction: You can request that we restrict processing of
your data
- Right to Data Portability: You can request transfer of your data to
another service
- Right to Object: You can object to processing based on legitimate
interests or direct marketing
- Right to Withdraw Consent: You can withdraw consent at any time where
we rely on consent
- Right to Lodge a Complaint: You can complain to a supervisory authority
about our data processing
To exercise any of these rights, please contact us at privacy@cpaas.studio. We will respond
to your request within 30 days.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined
in this policy, unless a longer retention period is required by law. Retention periods vary
depending on:
- The nature of the data collected
- The purpose for which it was collected
- Legal, regulatory, or contractual requirements
- Our legitimate business interests
When we no longer need your data, we will securely delete or anonymize it.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data
against:
- Unauthorized access or disclosure
- Accidental loss or destruction
- Unlawful processing
Our security measures include encryption, access controls, secure servers, regular security
assessments, and staff training on data protection.
8. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European
Economic Area (EEA). When we transfer data internationally, we ensure adequate protection
through:
- EU-approved standard contractual clauses
- Adequacy decisions by the European Commission
- Other legally approved transfer mechanisms
9. Third-Party Sharing
We may share your personal data with:
- Service Providers: Companies that provide services on our behalf (e.g.,
hosting, analytics, payment processing)
- Business Partners: Partners who help us deliver services to you
- Legal Authorities: When required by law or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset
sales
We ensure all third parties respect the security of your data and treat it in accordance with
the law.
10. Automated Decision-Making and Profiling
We do not use fully automated decision-making or profiling that produces legal or similarly
significant effects. If we do in the future, we will:
- Inform you about the logic involved
- Explain the significance and consequences
- Provide you with the right to human intervention
11. Cookies and Tracking
Our website uses cookies and similar tracking technologies. For detailed information about
how we use cookies, please refer to our Cookie
Policy.
12. Children's Privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect
personal data from children. If you believe we have collected data from a child, please
contact us immediately.
13. Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and
freedoms, we will notify you without undue delay and inform the relevant supervisory
authority within 72 hours as required by GDPR.
14. Changes to This Policy
We may update this GDPR Policy from time to time. We will notify you of significant changes
by:
- Posting the new policy on this page
- Updating the "last updated" date
- Sending you an email notification (for material changes)
We encourage you to review this policy periodically.
15. Contact Us
If you have any questions about this GDPR Policy or wish to exercise your rights, please
contact us:
- Email: support@cpaas.studio
- Phone: +91 95444 97777
- Address: 2B, II Floor, SAS Arcade,
Parakkattu Temple Road,
Chembumukku, Kakkanad,
Kochi - 682021,
Kerala, India.
16. Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority if you believe
we have not complied with GDPR requirements. Contact details for EU supervisory authorities
can be found at: https://edpb.europa.eu