Privacy Policy
TRIQOSH (“we”, “us”) operating https://triqosh.com is committed to protecting your personal data with “reasonable security practices” (IT Act 2000 §43A + SPDI Rules 2011 Rule 8) and the Digital Personal Data Protection Act, 2023, plus GDPR (EEA/UK) and CCPA/CPRA (US) where applicable. This policy explains what we collect (including via YouTube unlisted embeds, Cloudflare, Google Sheets, cookies, UPI, 3D diagnostics), why, and your rights.
Privacy Policy DPDP • GDPR • CCPA
Effective Date: 27 August 2026 • Last Updated: 27 August 2026 • Scope: India (DPDP Act 2023 + IT Act 2000) • EEA/UK GDPR • US CCPA/CPRA
Controller / Data Fiduciary: TRIQOSH • Website: https://triqosh.com • Contact: think.innovate.elevate@triqosh.com • South Delhi, New Delhi, India — Remote-first, serving India, Dubai & Global
- Introduction & Controller
- Scope, Consent & Applicability
- Definitions
- Data We Collect
- How We Collect & Use
- Lawful Bases (GDPR + DPDP)
- YouTube Unlisted Embeds
- Cloudflare
- Google Sheets
- Analytics
- Cookies
- UPI Payments
- 3D / WebGL
- Sharing & Processors
- International Transfers
- Retention
- Security
- Your Rights
- Children’s Privacy
- Do Not Track & GPC
- Grievance Officer & DPO
- Contact & Complaints
- Changes
1. Introduction & Who We Are
This Privacy Policy describes how TRIQOSH (“we”, “us”, “our”), operating https://triqosh.com (“Site”), collects, uses, discloses, and safeguards your personal data when you visit, interact, or transact on the Site. We are the Data Fiduciary under India’s DPDP Act 2023 and Controller under GDPR where applicable. By using the Site you acknowledge you have read this Policy. If you do not agree, please discontinue use and do not submit forms.
2. Scope, Consent & Applicability
This Policy applies to personal data processed via the Site, embedded YouTube, forms→Sheets, analytics, and cookies — whether you are in India, the European Economic Area (EEA), UK, or the United States. Where local law requires a higher standard, we apply it.
- India (DPDP Act 2023 + IT Act 2000): Processing is on your free, specific, informed, unconditional, and unambiguous consent (Sec.6 DPDP, Sec.5 notice) except where the Act permits “legitimate uses” (Sec.7). Sensitive personal data (SPDI Rules 2011, Rule 3) — passwords, financial, health, biometrics — gets heightened protection; we avoid collecting it unless strictly needed and with explicit consent.
- EEA/UK (GDPR): Consent must be freely given and withdrawable; you may also object to legitimate-interest processing.
- California (CCPA/CPRA): At or before collection we disclose categories, purpose, and retention (§1798.100(b)).
- By clicking “Accept” on our cookie banner or submitting a form with an unchecked consent box that you tick, you provide consent. Pre-ticked boxes are not valid.
3. Definitions
Personal Data means any data about an identified or identifiable individual. Data Principal / Data Subject is you. Data Fiduciary / Controller is TRIQOSH deciding purposes/means. Data Processor is an entity processing on our behalf (e.g., Cloudflare, Google). Sensitive personal data (SPDI) per Rule 3 includes financial, health, etc. Consent Manager (DPDP) when notified, will provide interoperable consent artefact.
4. Personal Data We Collect
- Identity & Contact: Full name
- Contact: Email address
- Contact: Phone / WhatsApp number
- Technical / Device: IP address (masked via Cloudflare), device type, browser, OS, referring URL, Ray ID
- Usage: Pages viewed, clicks, scroll, time on page, session, UTM source
- 3D / WebGL diagnostics: Canvas fingerprint only for performance (GPU tier, frame rate) — no biometric or special-category data
We also process UPI payment metadata (UPI ID, amount, txn ref) only if you pay via UPI — we do not store CVV, card numbers or UPI PIN (handled by your UPI app / NPCI / bank). We do not intentionally collect government IDs, passwords, or special-category data unless you voluntarily disclose them.
5. How We Collect Data
- Directly from you: when you fill a form, email, call/WhatsApp, or pay via UPI.
- Automatically: via cookies, Cloudflare logs, GA4, and YouTube player when you interact.
- From processors: Cloudflare (security logs), Google (Sheets/Analytics).
6. Purpose, Use & Lawful Basis
| Purpose | Category | Lawful Basis (India / GDPR) |
|---|---|---|
| Respond to inquiries, schedule calls, send proposals | Name, email, phone, message | Consent (DPDP Sec.6 / GDPR Art.6(1)(a)) + Contract pre-steps (Art.6(1)(b)) |
| Secure & deliver Site (CDN, WAF, TLS, fraud prevention) | IP, device, Ray ID | Legitimate interest (security, Art.6(1)(f)) + Legal obligation |
| Store leads & manage pipeline | Form data → Google Sheets | Consent + Legitimate interest (CRM) |
| Measure & improve performance (Analytics, 3D perf) | Usage, cookies, WebGL tier | Consent where cookies/ePrivacy requires; else legitimate interest (minimal) |
| Play embedded videos you request | IP, viewing interaction via YouTube | Consent (cookies) + Legitimate interest (content delivery) |
| Process UPI payments & issue invoices | UPI ID, amount, txn ref | Contract + Legal obligation (tax retains 8y) |
We use data only for the purpose collected or a compatible, disclosed purpose. We do not use automated decision-making that produces legal effects.
7. YouTube — Unlisted Video Embeds
We may embed YouTube videos set as Unlisted (accessible only via direct link / embed, not searchable). Embedded player is served by Google LLC (YouTube). When you play a video, YouTube may set cookies / use local storage and receive your IP, device, and viewing interaction per Google Privacy Policy and YouTube Terms.
- We use
youtube-nocookie.comdomain where feasible to reduce pre-play tracking, but playback still contacts Google servers. - Unlisted does not mean private/secure — anyone with the link/embed can view. We do not gate unlisted videos by login.
- Lawful basis (GDPR): legitimate interest to deliver video content you request + consent where cookies require it (Art.6(1)(a)/(f)).
- Opt-out: enable “Limit ad tracking”, block third-party cookies, or use YouTube privacy-enhanced mode. Objection: see §16.
8. Cloudflare — CDN, Security & Performance
Cloudflare, Inc. acts as our data processor for CDN caching, DDoS mitigation, Web Application Firewall (WAF), and TLS. Cloudflare may process IP address, request headers, Ray ID, country (GeoIP), and TLS fingerprints to deliver and secure the site. Data is handled under Cloudflare’s Privacy Policy and Data Processing Addendum (SCCs for EEA transfers).
- Cached assets are stored at edge nodes nearest to you; logs retained ≤ 30 days for abuse detection.
- No sale of personal data; Cloudflare is processor, not controller of site analytics.
9. Google Sheets as Lightweight Database
Form submissions (e.g., name, email, phone, message) are written to Google Sheets via Google Workspace / Apps Script endpoint. Google acts as processor under Google Workspace DPA. Sheets are access-controlled (least-privilege), not publicly shared, and may be stored in Google data centres (US/EU) with encryption at rest/in transit.
- We restrict sharing to need-to-know staff; 2-step verification enforced.
- You may request access / deletion of your Sheet row via §16.
10. Analytics (Google Analytics 4)
We use Google Analytics 4 (Google LLC) with IP anonymization, 14-month default retention, and no advertising personalization unless you consent. GA4 sets _ga, _ga_* cookies (first-party) and measures page views, scrolls, and events. See How Google uses partner data. Opt-out: GA Opt-out add-on or block analytics cookies via banner.
11. Cookies & Similar Technologies
We use cookies to keep the site secure, remember preferences, and measure performance. Required cookies run consent-free (strictly necessary); analytics/marketing cookies run only after you click “Accept”.
| Type | Examples | Purpose | Duration |
|---|---|---|---|
| Strictly Necessary | cf_clearance, __cf_bm, session | Security, load balancing, CSRF | Session — 1 year |
| Preferences | cookie_consent, theme | Remember choices | 6 — 12 months |
| Analytics | _ga, _ga_*, _gid | Usage measurement (GA4) | 1 day — 14 months |
| YouTube | VISITOR_INFO1_LIVE, YSC | Video delivery, fraud prevention | Session — 2 years |
Manage: banner “Reject non-essential”, browser Settings → Privacy → Cookies, or youronlinechoices.eu (EU). Blocking strictly necessary cookies may break playback.
12. Payments — UPI
If you pay via UPI (Unified Payments Interface, NPCI), your UPI ID, amount, and bank reference are processed by your UPI app, sponsor bank, and payment gateway (e.g., Razorpay/PhonePe/Google Pay) per their privacy terms. We receive only confirmation (status, txn ID, timestamp) and do not see or store UPI PIN / MPIN.
- GST invoices (if applicable) are retained per Indian law for 8 years.
- Refunds, if any, follow the gateway’s policy and are credited to source UPI ID.
13. 3D / WebGL Diagnostics
Our site uses WebGL/Three.js for 3D visuals (hero logo, motion). We may read minimal, non-identifying diagnostics (e.g., GPU renderer string, frame capability) only to decide rendering quality and ensure 60fps. We do not derive biometric data, do not fingerprint for ad targeting, and discard data after the session.
14. Sharing & Processors
We share personal data only on a need-to-know basis with vetted processors under written DPAs / SCCs:
- Cloudflare, Inc. (USA/EU edges) — CDN/security (processor, DPA+SCCs).
- Google LLC / Google Asia Pacific Pte. Ltd. — Workspace (Sheets) & Analytics (processors, DPA+SCCs).
- Google LLC (YouTube) — video delivery (independent controller for its own purposes; SCCs where applicable).
- UPI ecosystem (your bank, NPCI, payment gateway) where you pay — independent controllers.
- Professional advisors (legal, accounting) under confidentiality, only if required.
- Legal & safety: if required by law, court order, or to protect rights, safety, and prevent fraud/abuse (DPDP Sec.7 legitimate uses).
We do not sell personal data and do not share for cross-context behavioral advertising. We authorize processors to use data only per our instructions.
15. International Data Transfers
Our primary processing is in India. Processors may store/process in the USA, EU, and edge locations. For EEA/UK transfers we rely on EU Standard Contractual Clauses (SCCs) + UK Addendum (GDPR Art.46) and ensure processors maintain adequate security. For India, cross-border transfers comply with DPDP Sec.16 and any government-notified restrictions.
16. Data Retention — Store Only as Long as Needed
- Leads / inquiries: 24 months from last interaction, then anonymized or deleted, unless you ask earlier.
- Sheets rows & form logs: same period; you may request deletion anytime.
- Cloudflare security logs: ≤ 30 days.
- GA4 analytics: 14 months (user-level), aggregated reports may persist longer without identifiers.
- Accounting / GST invoices: 8 years (Indian law).
- Cookies: per durations in §11.
We review retention annually and delete/anonymize when purpose expires or consent is withdrawn.
17. Data Security — Reasonable Security Practices
Per IT Act 2000 §43A + Rule 8 SPDI Rules (Reasonable Security Practices) and DPDP §8(5), we implement: TLS 1.2+ everywhere, HSTS, WAF via Cloudflare, least-privilege access to Sheets, 2FA on Google Workspace, encryption at rest (AES-256) and in transit, hardened headers, and periodic reviews. No method is 100% secure; if we discover a breach likely to affect you, we will notify you and the Data Protection Board per DPDP breach-notification rules without undue delay.
16. Your Rights
🇮🇳 India — DPDP Act 2023 (Data Principal rights)
As Data Principal you may: (a) obtain summary of personal data processed & processing activity; (b) seek correction, completion, updating & erasure; (c) withdraw consent at any time (withdrawal does not affect prior lawful processing, but we will stop further use that relied on consent); (d) appoint a nominee in case of death/incapacity; (e) file grievance with us first, then appeal to the Data Protection Board of India (DPB). We will acknowledge your request promptly and respond per DPDP timelines. We may require verification (OTP / email confirmation) and will not discriminate for exercising rights.
🇪🇺 EEA / UK — GDPR (Articles 15–22)
You have rights to: (i) access, (ii) rectify, (iii) erase (“be forgotten”), (iv) restrict processing, (v) data portability (machine-readable), (vi) object to legitimate-interest processing / direct marketing (absolute), (vii) withdraw consent at any time, (viii) lodge a complaint with your supervisory authority (e.g., EU SA or UK ICO). We assess legitimate-interest objections via balancing test and will cease unless compelling grounds override.
Lawful bases we rely on: Consent (Art.6(1)(a)) for analytics/YouTube cookies & marketing; Contract (Art.6(1)(b)) to reply to your inquiry; Legitimate interest (Art.6(1)(f)) for site security, performance, and improving content (balanced, minimal); Legal obligation (Art.6(1)(c)) for records.
🇺🇸 California / US — CCPA as amended by CPRA (§1798.100 et seq.)
If you are a California resident you may: (1) know categories & specific pieces of personal information collected/used/disclosed in last 12 months; (2) delete; (3) correct inaccurate data; (4) opt-out of sale/share of personal information and of targeted advertising (we do not sell or share personal information for cross-context behavioral advertising as defined by CPRA — and we will treat a GPC signal as opt-out); (5) limit use of sensitive personal information; (6) non-discrimination for exercising rights. You may use an authorized agent with signed permission. We will verify (email OTP) and respond within 45 days (extendable 45 days with notice). Two methods to exercise: email think.innovate.elevate@triqosh.com or form on triqosh.com.
To exercise any right: email think.innovate.elevate@triqosh.com or contact Grievance Officer below. We will respond without undue delay and at least within statutory windows (DPDP/GDPR: ~30 days; CCPA: 45 days).
17. Children’s Privacy
We do not knowingly collect data from children. Under India’s DPDP Act 2023 a child is below 18 and requires verifiable parental consent; under GDPR the threshold is 16 (member state may lower to 13) and under CCPA/CPRA sale/share of minors’ data has higher safeguards. If you believe a child provided data, contact us at think.innovate.elevate@triqosh.com — we will delete it promptly. Our YouTube embeds are not “directed to children” under COPPA/GDPR-K.
18. Do Not Track, GPC & DND
Some browsers transmit Do Not Track (DNT) or Global Privacy Control (GPC) signals. We treat a valid GPC as a CCPA opt-out of sale/share (we do not sell anyway). Our cookie banner respects your choice. For India DND/TRAI: transactional/service messages about your inquiry are not marketing; you may opt-out of marketing messages anytime by replying STOP or emailing us — we honor within 10 business days.
19. Grievance Officer & Data Protection Contact (India IT Rules 2011 Rule 5(9) & DPDP Act)
Grievance Officer: TRIQOSH Grievance Officer
Email: think.innovate.elevate@triqosh.com (also: think.innovate.elevate@triqosh.com)
Address: South Delhi, New Delhi, India — Remote-first, serving India, Dubai & Global
Phone: +91 90000 00000
Jurisdiction: Courts of New Delhi, India
We acknowledge complaints within 24–48 hours and resolve within 15 days (DPDP draft timelines). For GDPR matters you may also contact our representative via the same email. If unsatisfied, you may approach the Data Protection Board of India (DPB) or your supervisory authority.
20. Contact Us & Complaints
Questions, access/deletion requests, consent withdrawal, or grievances:
TRIQOSH
South Delhi, New Delhi, India — Remote-first, serving India, Dubai & Global
Email: think.innovate.elevate@triqosh.com | Grievance: think.innovate.elevate@triqosh.com
Website: https://triqosh.com
Supervisory routes: India — Data Protection Board of India under DPDP Act; EEA — your national DPA; UK — ICO (ico.org.uk); California — AG (oag.ca.gov/privacy). We will not retaliate for exercising rights.
21. Changes to This Policy
We may amend this Policy to reflect legal, technical, or business changes. We will update “Last Updated” and, for material changes, provide notice on the Site or via email where we hold it. Review periodically. Continued use after updated effective date constitutes acknowledgment.
22. Governing Law
This Policy is governed by the laws of India, without regard to conflict of laws. Courts of New Delhi, India have exclusive jurisdiction, subject to mandatory consumer-protection / data-protection forums where applicable. If any clause is found unenforceable, the remainder continues.
© 2026 TRIQOSH • https://triqosh.com • Generated via TRIQOSH Privacy Policy Agent • v1.2 • 27 Aug 2026 • Create your own policy
