Privacy Policy
This policy explains what personal data Anithra Solutions collects, why we collect it, who we share it with, and the rights you have over it. It is written to be read rather than to be survived.
- Last updated
- 1 July 2026
- Effective from
- 1 August 2026
- Applies to
- All Anithra Solutions entities
1. Who we are
“Anithra”, “we”, “us” and “our” mean the Anithra Solutions group of companies. Depending on how you interact with us, the controller of your personal data is one of:
- Anithra Solutions Private Limited — Level 4, Cyber Gateway, HITEC City, Madhapur, Hyderabad 500081, Telangana, India. Controller for visitors and customers in India and for group-wide employment and recruitment data.
- Anithra Solutions UK Ltd — 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Controller for visitors, clients and prospects in the United Kingdom and the EEA.
- Anithra Solutions Inc. — 5646 Milton Street, Suite 130, Dallas, TX 75206, United States. Controller for visitors, clients and prospects in the United States and Canada.
For most client engagements, our client is the controller of the personal data in their systems and Anithra acts as a processor under a Data Processing Agreement. This policy describes what we do as a controller. Where we act as a processor, our client’s privacy notice governs, and we act only on their documented instructions.
Privacy contact: privacy@anithrasolutions.com.
2. Scope of this policy
This policy covers personal data we process about:
- Visitors to https://www.anithrasolutions.com and our other marketing sites
- People who contact us, request a demo, or sign up for updates
- Client and prospect contacts, and supplier and partner contacts
- Candidates who apply for a role with us
- Users of our consumer products, in addition to each product’s in-app notice
It does not cover third-party websites we link to. It also does not replace the specific privacy notice shown inside Vaultra, Pulsr or Shareprops, which describes the additional processing those products carry out.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, work email, phone number, employer, job title | You, directly |
| Enquiry content | What you write in a contact form, email or call notes | You, directly |
| Technical | IP address (truncated for analytics), device and browser type, pages viewed, referrer | Automatically, on visit |
| Consent records | Your cookie choices and the timestamp of that choice | You, via the consent banner |
| Recruitment | CV, work history, portfolio links, interview notes, right-to-work status | You, or a referrer you named |
| Contractual | Billing contacts, purchase orders, payment records | You and your organisation |
We do not buy marketing lists, and we do not use tracking pixels that build cross-site profiles of you.
4. Why we use it, and our legal bases
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Responding to your enquiry and providing information you asked for | Consent, and steps prior to entering a contract |
| Delivering services and managing the client relationship | Performance of a contract |
| Running, securing and improving our websites and products | Legitimate interests (operating a secure, usable service) |
| Analytics and measurement | Consent |
| Marketing communications to business contacts | Consent, or legitimate interests where permitted (soft opt-in) |
| Recruitment and assessment | Steps prior to a contract, and consent for a talent pool |
| Accounting, tax, audit and regulatory record-keeping | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests / legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and you can ask for a summary of it at any time.
5. Who we share personal data with
We share personal data only with:
- Group companies — the three entities named above, for delivery, contracting and support.
- Service providers acting as processors — hosting, email delivery, CRM, analytics, error monitoring and payment processing. Each is bound by a written contract with confidentiality and security obligations, and may only act on our instructions. Our current list is published at Sub-processors.
- Professional advisers — auditors, lawyers, insurers and accountants, under duties of confidentiality.
- Authorities — where we are legally required to disclose. We assess every request, require lawful authority, and notify the affected person unless legally prohibited.
- An acquirer — if the business or part of it is sold or reorganised, under confidentiality and with notice to you where required.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
We operate from India, the United Kingdom and the United States, so personal data may be transferred between those countries. India is not the subject of a UK or EU adequacy decision. Where personal data leaves the UK or the EEA we rely on:
- the UK International Data Transfer Agreement (or the EU Standard Contractual Clauses with the UK Addendum) for transfers from the UK; and
- the European Commission’s Standard Contractual Clauses for transfers from the EEA,
in each case supported by a documented Transfer Risk Assessment and supplementary technical measures: encryption in transit and at rest, keys held in the originating region where the client requires it, least-privilege access with logged justification, and a published policy for handling government access requests. Clients may request that their data be pinned to a specific region. You can request a copy of the relevant transfer mechanism from privacy@anithrasolutions.com.
7. How long we keep personal data
| Data | Retention |
|---|---|
| Enquiries that do not become a relationship | 24 months from last contact |
| Client contract and delivery records | 7 years after the engagement ends (tax and limitation periods) |
| Unsuccessful candidate records | 12 months, or 24 months with your consent for the talent pool |
| Cookie consent records | 12 months, then we ask again |
| Analytics data | 14 months, aggregated and IP-truncated |
| Security and access logs | 12 months |
At the end of the period, data is deleted or irreversibly anonymised. Backups are purged on their own rolling cycle, which does not exceed 90 days beyond the primary deletion.
8. How we protect personal data
We run an information security management system aligned to ISO/IEC 27001 with SOC 2 Type II control coverage across production environments. Measures include encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control with mandatory multi-factor authentication, segregated environments, centralised logging, dependency and vulnerability scanning in CI, annual independent penetration testing, and a documented incident response plan tested at least yearly.
No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware and notify you without undue delay where the risk is high. Read more at the Trust Centre.
9. Your rights
Subject to the law that applies to you, you may have the right to:
- be told what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data deleted where we no longer need it or you withdraw consent;
- restrict or object to processing, including direct marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions about you.
To exercise any of these, write to privacy@anithrasolutions.com. We acknowledge within 72 hours and respond within one month (extendable by two months for complex requests, with notice). We do not charge a fee unless a request is manifestly unfounded or excessive. We may ask for proof of identity — only what is necessary to be sure we are not disclosing your data to someone else.
10. Additional information for UK and EEA residents
Our UK and EEA processing is governed by the UK GDPR and the Data Protection Act 2018, and by Regulation (EU) 2016/679 respectively. You have the right to lodge a complaint with a supervisory authority:
- United Kingdom — the Information Commissioner’s Office (ico.org.uk), Wycliffe House, Water Lane, Wilmslow SK9 5AF.
- EEA — the supervisory authority of the member state where you live, work, or where the alleged infringement occurred.
We would prefer the chance to resolve it first — please write to privacy@anithrasolutions.com — but you are not required to contact us before complaining.
11. Additional information for India (DPDP Act 2023)
Where Anithra Solutions Private Limited processes your personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023, you are a Data Principal and you have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a readily available grievance redressal mechanism.
Our grievance officer can be reached at privacy@anithrasolutions.com or by post at Level 4, Cyber Gateway, HITEC City, Madhapur, Hyderabad 500081, Telangana, India. Grievances are acknowledged within 72 hours and resolved within 30 days. If you are not satisfied you may approach the Data Protection Board of India.
Where processing relies on consent, that consent is free, specific, informed, unconditional and unambiguous, and may be withdrawn at any time with the same ease with which it was given.
12. Additional information for US residents
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to access and delete it, to correct inaccuracies, to opt out of sale, sharing for cross-context behavioural advertising and certain profiling, and not to be discriminated against for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We do not knowingly process the personal information of anyone under 16 for those purposes.
To exercise a right, write to privacy@anithrasolutions.com. You may use an authorised agent; we will ask for written authorisation. We respond within 45 days, extendable once by a further 45 days with notice. If we deny a request you may appeal by replying to our decision; we will respond to appeals within 60 days.
13. Children
Our websites and business services are not directed at children. Our consumer products are not intended for anyone under 18, and where a product is available to users aged 16 or 17 the product’s own notice describes the additional protections that apply. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to privacy@anithrasolutions.com and we will delete it.
14. Changes to this policy
We update this policy when our processing changes or the law does. The “last updated” date at the top always reflects the current version. For material changes we give at least 30 days’ notice by email to client and subscriber contacts and by a notice on this site before the change takes effect. Superseded versions are retained and available on request.
15. Contact and complaints
Privacy and data protection: privacy@anithrasolutions.com
Legal and procurement: legal@anithrasolutions.com
Security disclosure: security@anithrasolutions.com
Postal enquiries may be addressed to any of the three entities listed in section 1. Mark correspondence for the attention of the Data Protection Contact.