Transparent collection
See what information WebCOSS collects and why it is needed.

Website enquiries, clients, users, cookies, international transfers, rights, and complaints
Use the contents panel to move between clauses or search this document.
Read the policySee what information WebCOSS collects and why it is needed.
Access, correction, deletion, objection and complaint routes are explained.
The policy covers WebCOSS operations and service delivery in the UK and India.
This Policy explains when WebCOSS acts for its own business purposes and when it processes personal data on a client’s documented instructions.
Try a different word or clear the search to show the complete policy.
This Privacy Policy explains how WebCOSS collects and uses personal data when you visit webcoss.com, submit a project enquiry, communicate with us, buy or use our services, attend a meeting, apply to work with us, or interact with our social-media pages. It also explains how we process personal data for clients when building, hosting, supporting, or operating websites and applications.
WebCOSS serves clients in the United Kingdom, India, and other countries. We aim to apply transparent and proportionate privacy practices consistent with applicable law, including the UK GDPR and Data Protection Act 2018 as amended, the Privacy and Electronic Communications Regulations as amended, and India's Digital Personal Data Protection Act 2023 and implementing rules as they come into force.
For website enquiries, marketing, supplier management, billing, and WebCOSS's own business operations, the controller or Data Fiduciary is the WebCOSS business identified in the relevant Proposal, Order, invoice, or communication. Where no project document applies, the WebCOSS team receiving your enquiry is responsible for handling it.
Where WebCOSS processes personal data only on a client's documented instructions within a client website, ecommerce store, portal, application, hosting environment, or support arrangement, that client is normally the controller or Data Fiduciary and WebCOSS acts as its processor or Data Processor. Questions about that processing should usually be directed first to the relevant client.
Contact and identity data: name, business email, telephone or WhatsApp number, job title, company or organisation, country, postal address, and preferred contact method.
Enquiry and project data: existing website, requested service, project type, budget range, preferred timeline, business goals, technical requirements, integrations, content responsibilities, communications, meeting notes, proposals, approvals, support tickets, and feedback.
Account and authentication data: usernames, user roles, login records, password-reset information, access permissions, security events, and multi-factor authentication status. We do not intentionally store readable passwords where a service supports secure password hashing or identity-provider authentication.
Commercial and transaction data: quotations, Orders, invoices, payment status, tax information, billing contacts, purchased services, subscriptions, renewals, refunds, and limited payment references. Payment-card details should be handled by the relevant payment provider and are not intentionally stored by WebCOSS unless expressly stated.
Technical and usage data: IP address, approximate location derived from IP, browser, device, operating system, referring pages, visited pages, timestamps, form interactions, log data, diagnostics, cookie identifiers, analytics events, and security information.
Client Content and end-user data: data that a client gives us or makes available in a website, database, store, portal, application, backup, migration, test environment, or support request. The categories depend on the client's service and instructions.
Marketing and preference data: newsletter or communication preferences, event participation, campaign interactions, source of enquiry, consent records, and objections.
Recruitment and supplier data: CV or resume, work history, portfolio, skills, availability, references, right-to-work information, rates, contracts, and payment information.
Public and social data: professional profile information, public posts, testimonials, reviews, comments, and messages sent through LinkedIn, Facebook, Instagram, YouTube, Pinterest, or similar platforms.
We collect data directly from you through forms, email, telephone, WhatsApp, meetings, Orders, Accounts, support channels, and payments; automatically through server logs, security tools, cookies, and similar technologies; from clients who authorise us to work on their systems; from service providers such as hosting, analytics, communications, payment, and identity providers; from professional advisers and referral partners; and from public sources such as company websites, Companies House or other business registers, and professional networks where lawful.
We use personal data only where we have a lawful purpose and a valid legal basis. Depending on the context, UK lawful bases include steps requested before a contract, performance of a contract, compliance with legal obligations, legitimate interests, consent, and in rare cases the protection of vital interests. Under Indian law, processing may be based on consent or another permitted legitimate use and must be for a lawful specified purpose.
We use contact, enquiry, and project data to respond to requests, recommend services, prepare quotations, arrange meetings, and take steps before a contract. The usual UK bases are contract steps and legitimate interests in operating a digital-services business.
We use project, Account, Client Content, and transaction data to deliver, test, secure, support, invoice, administer, and improve Services. The usual bases are contract, legal obligation, and legitimate interests. Where we act as a processor, the client's instructions and lawful basis govern the underlying processing.
We use technical, log, security, and diagnostic data to protect systems, prevent abuse, investigate incidents, maintain availability, enforce terms, and improve performance. The usual basis is legitimate interests and, where required, legal obligation or consent for non-essential storage and access technologies.
We use billing and tax data for invoicing, accounts, fraud prevention, debt recovery, and statutory records. The usual bases are contract, legal obligation, and legitimate interests.
We use communication and preference data to send service messages and, where permitted, relevant marketing. Marketing may rely on consent or legitimate interests, subject to electronic-marketing rules and your right to object or unsubscribe.
We use supplier and recruitment data to assess and manage professional relationships, make hiring decisions, pay suppliers, and comply with legal obligations. The usual bases are contract steps, contract, legal obligation, and legitimate interests.
We may use data to establish, exercise, or defend legal claims, cooperate with authorities, conduct audits, manage insurance, reorganise or sell a business, and comply with lawful requests. The bases are legal obligation, legitimate interests, and applicable legal exceptions.
We do not intend to make decisions producing legal or similarly significant effects solely by automated means. If this changes, we will provide appropriate information and safeguards.
Our legitimate interests include operating and improving our services; responding to business enquiries; managing client, supplier, and professional relationships; ensuring network and information security; preventing fraud and misuse; maintaining records; protecting legal rights; measuring website performance; and marketing relevant business services in a proportionate way. We consider the impact on individuals and do not rely on legitimate interests where rights and freedoms override our interests.
The Website and ordinary Services are not designed to collect health, biometric, genetic, political, religious, trade-union, sexual-life, criminal-offence, payment-card, national-identifier, or other highly sensitive data. Do not submit such data unless it is necessary, the parties have agreed the requirement, and suitable legal and security measures are in place.
WebCOSS services are directed to adults and business users. We do not knowingly collect personal data directly from anyone under 18 through the Website. If a client service is intended for children, the client must notify WebCOSS in advance and the parties must agree appropriate age assurance, parental consent, transparency, and safety measures. Contact us if you believe a child has provided data without proper authorisation.
The Website may use cookies, local storage, pixels, scripts, tags, embedded content, and similar storage or access technologies. Strictly necessary technologies support security, load balancing, form submission, fraud prevention, consent choices, and core operation. Preference technologies remember settings. Analytics technologies help us understand performance and usage. Marketing technologies may measure campaigns or support advertising.
Where consent is required, non-essential technologies should remain disabled until you make a choice. You can reject non-essential technologies as easily as accepting them and can change your choice through the cookie-settings control. Some limited analytics or functionality technologies may be used without consent where a legal exception applies and a simple means to object is provided.
Embedded services, such as maps, videos, social-media features, analytics, fonts, or WhatsApp links, may allow their providers to receive technical or interaction data. Their use is also governed by the provider's privacy information. A current cookie and technology inventory should be made available through the cookie banner or Cookie Notice.
We may send existing or prospective business contacts information about relevant WebCOSS services where permitted by law. You can object at any time by using an unsubscribe link or contacting us. We will keep a minimal suppression record so that we can respect the objection. Service, security, billing, and legal messages are not marketing and may continue where necessary.
We may share personal data with authorised WebCOSS personnel and contractors; hosting, cloud, backup, content-delivery, database, and cybersecurity providers; email, calendar, video-meeting, telephony, WhatsApp, helpdesk, CRM, project-management, and collaboration providers; analytics, search, advertising, and website-performance providers; payment, banking, accounting, tax, debt-recovery, and fraud-prevention providers; domain registrars, software vendors, plugin providers, API operators, and client-selected integration partners; professional advisers, auditors, insurers, and financing providers; law-enforcement, courts, regulators, and public authorities where lawfully required; and parties involved in an actual or proposed merger, financing, reorganisation, or sale.
Where we work on a client's system, data may be disclosed to the client and to providers selected or authorised by the client. We require processors and service providers to protect data and use it only for authorised purposes, subject to applicable law and contracts.
We do not sell personal data for money. We do not permit third parties to use client-controlled personal data for their own marketing unless the client and affected individual have authorised it or law permits it.
Because WebCOSS operates across the UK and India and may use global cloud and technology providers, personal data may be accessed or stored outside the country where it was collected. We assess transfer requirements and use appropriate safeguards where required.
For restricted transfers governed by UK data-protection law, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, transfer risk assessments, contractual and technical measures, or a lawful exception. Transfers involving Indian personal data are subject to applicable restrictions or government requirements as they take effect.
You may contact us for further information about relevant safeguards, subject to protection of confidential and security-sensitive information.
We keep personal data only for as long as reasonably necessary for the purpose collected, including to provide Services, maintain security and backups, comply with tax and accounting rules, resolve disputes, and enforce contracts. We consider the amount, nature, sensitivity, risk, purpose, legal requirements, and available alternatives.
Indicative periods are: unsuccessful general enquiries, normally up to 24 months after the last meaningful contact; client and project records, normally for the project or subscription plus 7 years for contract, tax, insurance, and legal purposes; invoices and accounting records, normally 7 to 8 years or the statutory period; support and security logs, commonly 30 days to 24 months depending on system and risk; marketing records, until you object or withdraw consent, plus a suppression record; recruitment records for unsuccessful applicants, normally 6 to 12 months unless a longer talent-pool period is agreed; and processor data, for the service term and deletion or return period agreed with the client.
Backups may retain deleted data for a limited rolling period before secure overwrite. We may retain data longer where required by law, a litigation hold, fraud prevention, security investigation, or a valid client instruction.
We use reasonable technical and organisational measures appropriate to the risk, which may include access controls, least-privilege permissions, encryption in transit, secure development practices, logging, backups, malware protection, patching, supplier review, confidentiality obligations, and incident procedures. Measures vary by service, environment, and Order.
No internet or storage system is completely secure. You should use strong unique passwords, multi-factor authentication, supported devices and software, secure methods for credentials, and prompt reporting of suspicious activity. Do not send passwords or highly sensitive data through ordinary email unless specifically requested and protected.
We investigate suspected personal-data incidents and take reasonable containment and recovery steps. Where WebCOSS is a processor, we notify the relevant client without undue delay after becoming aware of a personal-data breach affecting client data, subject to the information available. Where WebCOSS is the controller or Data Fiduciary, we make notifications to authorities and affected individuals where applicable law requires.
Your rights depend on your location, the applicable law, and our role. They may include the right to be informed; access personal data; correct, complete, or update it; request erasure; restrict processing; receive portable data; object to processing, including direct marketing; withdraw consent without affecting prior lawful processing; request safeguards relating to significant automated decisions; nominate another person where Indian law provides; and make a privacy grievance or complaint.
Rights are not absolute. We may need to verify identity, clarify a request, protect other people's rights, retain data required by law, or refuse a request where an exemption applies. We will explain the outcome. Where we process for a client, we may refer the request to that client and assist it as required.
To exercise a right, email webcoss.anand@gmail.com with 'Privacy Request' in the subject. Please state your relationship with WebCOSS, the service or project involved, the right you wish to exercise, and enough information to locate the data. Do not send unnecessary identification documents; we will request proportionate verification if needed.
Please contact us first so we can investigate. We will acknowledge and handle privacy complaints without undue delay and in accordance with applicable deadlines.
UK individuals may also complain to the Information Commissioner's Office. Individuals in India may use WebCOSS's grievance process and, where applicable, complain to the Data Protection Board of India in the manner prescribed. You may also contact another competent regulator or court where your law provides that right.
The Website links to client projects, social networks, maps, and other external services. WebCOSS does not control their independent privacy practices. When WebCOSS builds a website or application for a client, the client is responsible for publishing accurate privacy information for its own users and configuring consent, retention, access, and integrations lawfully.
We may update this Policy to reflect changes in services, technology, law, guidance, or business operations. The revised version will show a new effective date. Where a change materially affects how we use existing personal data, we will provide additional notice where required before the new use begins.