
Privacy Policy
Last Updated: 10th September, 2026
This Privacy Policy explains how Abhinav DigiCompSoft Services Pvt. Ltd. ("Abhinav DCS", "we", "us", "our") collects, uses, shares and protects personal data when you visit eu.abhinavdcs.com (the "Website"), contact us, book a call, or otherwise interact with us in connection with our custom software and product configurator services for European manufacturers.
We are established in India. This policy is written to comply with the EU General Data Protection Regulation (GDPR), which applies to us because we offer services to individuals in the EU and monitor their behaviour on this Website.
1. Who is responsible for your data Controller (Art. 4(7) GDPR):
Abhinav DigiCompSoft Services Pvt. Ltd. Head office: 915, Satyaniwas, near Raut Baug, Dhankawadi, Pune 411043, Maharashtra, India Branch office: Floor 4, Snehangan Building, Katraj–Dehu Road Bypass, Ambegaon Budruk, Pune 411046, Maharashtra, India Represented by: Dr. Deepika Jagtap, Managing Director Corporate Identity Number (CIN): U72900PN2012PTC142358
Contact for privacy matters: europe@abhinavdcs.com Telephone: +91 93560 89589
Data Protection Officer. We have not appointed a statutory Data Protection Officer, as our processing does not meet the thresholds in Art. 37 GDPR. Privacy queries go to europe@abhinavdcs.com.
Controller and processor. We act as controller for data about Website visitors, enquiries and business relationships — that is what this policy covers. Where we build, host or support a system for a client, we act as processor on that client's instructions, governed by the Data Processing Agreement with them, not by this policy.
02 · Data Processing Agreement Before any project begins, we provide a signed Data Processing Agreement (DPA) governing how we process personal data on your behalf. Our DPA covers:
• The subject matter , duration, nature, and purpose of processing, and the types of personal data and categories of data subjects involved
• Our obligation to process personal data only on your documented instructions
• Confidentiality obligations for anyone authorised to process the data
• The security measures described in Section 5 below
• The conditions under which we engage sub-processors, including your right to object to new sub-processors (see Section 4)
• Our obligation to assist you with data subject requests and with your own GDPR compliance obligations (impact assessments, consultations with supervisory authorities)
• Our obligation to notify you of a personal data breach without undue delay
• Deletion or return of personal data at the end of the engagement, and deletion of existing copies unless we are legally required to retain them.Download the DPA
03 · Where your data is hosted Client systems and data are hosted with CSpace, a company established in Tallinn, Estonia, which operates its own EU fibre ring connecting Europe to India. CSpace also hosts this website.
CSpace's data centre footprint:
For EU engagements we host your data exclusively in CSpace's EU/EEA data centres — Tallinn, Amsterdam and Stockholm — pinned to the EU. Dallas and Mumbai form part of CSpace's global network and are not used for EU client data unless you specifically request or agree to a different arrangement, such as a disaster-recovery configuration spanning additional regions.
Where a client agreement does involve data leaving the EU/EEA, that constitutes an international transfer. We put an appropriate safeguard in place — Standard Contractual Clauses — before it occurs, and disclose it in your DPA.Certification - CSpace is certified to ISO/IEC 27001, the international standard for information security management systems. A copy of the certificate is available on request.
Location Used for EU client data Tallinn, Estonia
Yes
Amsterdam, Netherlands
Yes
Stockholm, Sweden
Yes
Dallas, United States
No
Mumbai, India
No
04 · Sub-processors We notify clients of any intended addition or replacement to this list, with a reasonable opportunity to object, as set out in our DPA.
Subprocessor Purpose Location and transfer basis CSpace
Hosting of this website and of client systems and data
Established in Tallinn, Estonia. EU client data pinned to Tallinn, Amsterdam and Stockholm. Dallas and Mumbai not used for EU client data except by specific agreement (section 3).
Google Ireland Ltd. / Google LLC
Business email (Google Workspace), Google Meet, Google Maps embed, Google Analytics
Google Workspace under Google's Cloud Data Processing Addendum. Transfers to the United States under the EU–U.S. Data Privacy Framework.
Calendly, LLC
Meeting scheduling
United States, under the EU–U.S. Data Privacy Framework. Calendly's DPA additionally incorporates the Standard Contractual Clauses (Module 2). Calendly offers no EU data residency; booking data is hosted in the United States.
05 · Security measures We apply technical and organisational measures appropriate to the risk, including:
• Hosting on EU-based infrastructure with role-based access control on a need-to-know basis
• Encrypted transmission of data (TLS)
• logging of support access to client systems
• confidentiality obligations on staff and contractors, reinforced by NDAs signed as a matter of course before detailed project discussions
• source code escrow for client projects, so continuity does not depend on our own business continuity
• defined incident response and breach notification procedures (section 6).06 · Breach notification If we become aware of a personal data breach affecting your data, we notify you without undue delay so that you can meet your own obligation under Art. 33 GDPR to notify your supervisory authority within 72 hours where required.
Our notification includes, so far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.07 · Your rights as a data subject If we hold your personal data — because you contacted us or booked a call — you have the right to access it, have it corrected or erased, restrict our processing of it, receive it in a portable format, object to processing based on our legitimate interests, and withdraw consent at any time where processing rests on consent.
Full detail is in our Privacy Policy. To exercise any of these rights, write to europe@abhinavdcs.com.
If you believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority.08 · International transfers beyond hosting Two situations fall outside the EU-pinned hosting described in section 3.
Support access - Where a client requests support or reports an issue, named personnel in India may access data in that client's system to diagnose and resolve it. This access is triggered by a client request rather than routine or continuous, limited to what the issue requires, restricted to authorised personnel, and logged.
Enquiry data - Personal data you send us directly — through the contact form, by email, or when booking a call — is accessible to our team in India so that we can respond and manage the relationship.
In both cases we rely on the European Commission's Standard Contractual Clauses, supported by a transfer impact assessment and supplementary technical and organisational measures.
09 · Questions from your compliance or procurement team If you are assessing us as a vendor and need something not covered here — a completed security questionnaire, a copy of our DPA ahead of a call, or confirmation of a specific data centre location:
Email: europe@abhinavdcs.com
Telephone: +91 93560 89589

