Last updated: 15 September 2026
MaquishTech Venture Pvt Ltd ("MaquishTech", "we", "us", or "our") is committed to protecting the privacy and personal data of our clients, employees, contractors, website visitors, and any other individuals whose information we process. Headquartered at GIDA Sector 7, Badgahan, Gorakhpur, Uttar Pradesh – 273212, India, we operate as a responsible data controller and processor in the course of delivering technology, staffing, consulting, and venture services. This Data Protection Policy describes, in plain language, how we collect, use, store, share, and safeguard personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the General Data Protection Regulation (GDPR) where applicable, and other relevant data protection laws. This policy applies to all personal data processed by MaquishTech regardless of the medium (online forms, email, telephone, paper records, or third-party platforms) and to all systems, employees, and vendors acting on our behalf.
We adhere to the following principles, which form the foundation of our data protection programme:
We process the following categories of personal data, each tied to a specific business purpose:
MaquishTech Venture Pvt Ltd has designated a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and ensuring compliance with applicable laws. The DPO serves as the primary point of contact for data subjects, the Data Protection Board of India, and other regulatory authorities. The DPO's responsibilities include monitoring internal compliance, advising on data protection impact assessments, conducting awareness training, cooperating with supervisory authorities, and handling data subject requests in a timely manner. The DPO operates independently and reports directly to senior management to ensure that data protection considerations are embedded in all business decisions.
You may contact our Data Protection Officer using the details below:
We aim to acknowledge all enquiries within five working days and to provide a substantive response within thirty days, in accordance with statutory timelines.
We rely on the following lawful bases when processing personal data, and we document the basis for each processing activity:
For processing based on consent, we ensure that consent is freely given, specific, informed, and unambiguous, and we maintain records demonstrating how consent was obtained.
We maintain a record of processing activities that describes each operation we perform on personal data. Our principal processing activities include:
Under applicable laws, individuals whose data we process have the following rights:
Individuals may exercise any of the rights above by submitting a request to our Data Protection Officer at Ankur@AnpaCorporation.com. We will verify the identity of the requester using reasonable means before disclosing any personal data. Requests are handled free of charge, although we may charge a reasonable fee for manifestly unfounded or excessive requests. We respond to access requests within thirty days of receipt; where a request is complex, this period may be extended by a further two months, in which case we will inform the requester of the extension and the reasons for it within the initial thirty days. If we refuse to act on a request, we will explain the reasons and inform the requester of their right to complain to the Data Protection Board of India.
We implement a layered security programme designed to protect personal data against unauthorised access, alteration, disclosure, and destruction. Our measures include:
In the event of a personal data breach, MaquishTech follows a documented incident response plan. Our response includes the following steps:
MaquishTech primarily processes personal data within India. Where we transfer personal data outside India—for example, to cloud service providers or to support global clients—we ensure that the transfer is subject to appropriate safeguards. These safeguards include standard contractual clauses approved by the relevant authority, binding corporate rules, adequacy assessments of the destination country's data protection regime, or explicit consent from the individual. We maintain records of all international transfers, including the categories of data transferred, the recipient, and the safeguard relied upon. We do not transfer data to jurisdictions that lack an adequate level of protection unless a suitable safeguard is in place.
We retain personal data only as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements. Our retention schedule is as follows:
At the end of the retention period, data is securely deleted or anonymised so that it can no longer identify an individual.
Our services are directed at businesses and professionals, and we do not knowingly collect personal data from children under the age of 18. Where we process data that may relate to a child—for example, through a parent or guardian acting on their behalf—we obtain verifiable parental consent in accordance with the DPDP Act. If we become aware that we have collected personal data from a child without the required consent, we take steps to delete that data promptly. Parents or guardians may contact our Data Protection Officer to review, correct, or delete any data relating to their child.
We process employee and contractor data for legitimate HR purposes, including recruitment, payroll, performance management, and statutory compliance. The categories of data we process include identity documents, contact details, bank account information for salary credits, tax declarations, attendance records, and performance evaluations. We rely on contractual necessity and legal obligation as the primary lawful bases for processing employee data. Employee data is accessible only to authorised HR and management personnel, and access is reviewed regularly. Employees have the right to access, correct, and, where applicable, request deletion of their personal data, subject to legal retention requirements.
Where we engage third-party vendors or processors to handle personal data on our behalf, we do so only under a written data processing agreement that meets the requirements of the DPDP Act and the GDPR. These agreements specify the purposes of processing, the categories of data involved, the security measures to be applied, and the vendor's obligations to assist us in fulfilling data subject requests and breach notifications. We conduct due diligence on vendors before onboarding and review their compliance periodically. Vendors are prohibited from engaging sub-processors without our prior written authorisation, and they are required to delete or return all personal data at the end of the engagement.
We believe that effective data protection depends on a culture of awareness. All employees and contractors receive data protection training as part of their onboarding and refresher training annually thereafter. Training covers the principles of data protection, individuals' rights, secure handling of personal data, breach reporting procedures, and the proper use of access controls. We also conduct targeted training for teams handling sensitive data, such as HR and finance. Completion of training is tracked, and additional resources are made available through our internal knowledge base. We regularly reinforce key messages through internal communications and simulated phishing exercises to keep security top of mind.
We may update this Data Protection Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated through our website or directly to affected individuals where appropriate. The date at the top of this policy indicates when it was last updated. We encourage visitors to review this page periodically to stay informed about how we protect personal data.
For data protection enquiries, to exercise your rights, or to raise a concern about how we handle personal data, please contact our Data Protection Officer:
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India or the relevant supervisory authority in your jurisdiction.