Skip to main content
Plurentoo Systems
  • Services

    Services

    Ten service lines. One delivery team.

    Build, secure and run your systems with one accountable partner.

    All services Platforms we work with
    • 01Enterprise ApplicationsOracle, SAP, Salesforce, Workday and UKG
    • 02Data & AIData platforms, analytics, ML and generative AI
    • 03Cloud ServicesMigration, DevOps and FinOps
    • 04Software & Product EngineeringWeb, mobile, UX and quality engineering
    • 05CybersecurityVAPT, zero trust, SOC and compliance
    • 06Data Center & HardwareServers, storage, backup and devices
    • 07NetworkingLAN, WAN, SD-WAN and Wi-Fi
    • 08Embedded & IoT EngineeringFirmware, IoT platforms and automotive HMI
    • 09Managed IT ServicesService desk, NOC and application support
    • 10Technical StaffingContract, permanent and dedicated teams
  • Industries

    Industries

    Built around how your sector works.

    Use cases, regulations and systems we plan for in twelve industries.

    All industries
    • 01Automotive & Mobility
    • 02Banking, Financial Services & Insurance
    • 03Healthcare & Life Sciences
    • 04Manufacturing & Industrial
    • 05Retail & E-commerce
    • 06Hi-Tech & Software
    • 07Telecom & Media
    • 08Travel, Transport & Hospitality
    • 09Public Sector
    • 10Energy & Utilities
    • 11Education
    • 12Real Estate & Construction
  • Products

    Products

    Software we are building.

    Business software from Plurentoo, starting with risk assessment for Indian companies.

    All products
    • Risk Assessment PortfolioComing soonCheck, score and monitor the companies you work with
      • Company profiles from public records and statutory filings
      • Risk scores with the reasons shown alongside
      • Portfolio monitoring with alerts and early warnings
      • Reports and APIs for your own workflows
      Request early access
  • For colleges

    For colleges

    Programs that get students ready for industry.

    Training at your campus, and industrial visits beyond it.

    All programs
    • The Production-Ready CampusIndustry training and workshops at your campus
      • Industry-experienced trainers
      • Held at your campus
      • Current tools and practices
      Partner with us
    • Industrial VisitsData centers, infrastructure projects and landmarks
      • Planned around your syllabus
      • Sites for every discipline
      • Transport and stay arranged
      Plan a visit
  • Company

    Company

    An IT services company, built in Pune.

    Who we are, the companies we work with and how our engagements run.

    About Plurentoo
    • About usWho we are and what the name means
    • Partner companiesSister brands and companies we work with
    • How we workEngagement models and delivery principles
    • CareersRoles we hire for and how to apply
    • ContactStart a conversation with our team
    • Corporate informationCIN, GSTIN and statutory details
  • Insights
Talk to us
    • All services
    • 01 Enterprise Applications
    • 02 Data & AI
    • 03 Cloud Services
    • 04 Software & Product Engineering
    • 05 Cybersecurity
    • 06 Data Center & Hardware
    • 07 Networking
    • 08 Embedded & IoT Engineering
    • 09 Managed IT Services
    • 10 Technical Staffing
    • All industries
    • 01 Automotive & Mobility
    • 02 Banking, Financial Services & Insurance
    • 03 Healthcare & Life Sciences
    • 04 Manufacturing & Industrial
    • 05 Retail & E-commerce
    • 06 Hi-Tech & Software
    • 07 Telecom & Media
    • 08 Travel, Transport & Hospitality
    • 09 Public Sector
    • 10 Energy & Utilities
    • 11 Education
    • 12 Real Estate & Construction
    • All products
    • Risk Assessment PortfolioComing soon
    • All programs
    • The Production-Ready Campus
    • Industrial Visits
  • Platforms
    • About us
    • Partner companies
    • How we work
    • Careers
    • Contact
    • Corporate information
  • Insights
Talk to us connect@plurentoo.com
  1. Home/
  2. Privacy policy

Legal and privacy

Privacy policy

What personal data we collect, why we use it, who we share it with and how you can control it. Written with India's DPDP Act, 2023, the DPDP Rules, 2025, the GDPR and the UK GDPR in mind.

Last updated16 September 2026

On this page

  1. 01Who we are
  2. 02What this policy covers
  3. 03The personal data we collect
  4. 04Why we use personal data and our legal bases
  5. 05Where the data comes from
  6. 06Who we share it with
  7. 07International transfers
  8. 08How long we keep it
  9. 09How we protect it
  10. 10Your rights
  11. 11How to exercise your rights
  12. 12Cookies, analytics and browser signals
  13. 13Children
  14. 14Automated decision-making
  15. 15Personal data breaches
  16. 16Links to other websites
  17. 17Grievance Officer and complaints
  18. 18Representatives in the EU and UK
  19. 19Language of this policy
  20. 20Changes to this policy

01 Who we are

This policy explains how Plurentoo Systems Private Limited ("Plurentoo", "we", "us") handles personal data. We are a private limited company registered in India with Corporate Identity Number U62020PN2026PTC259543 and registered office at B-334, Gera's Imperium Gateway, Near Nashik Phata Metro Station, PCMC, Pune 411034, Maharashtra, India.

For the personal data described here, we act as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and as the controller under the EU General Data Protection Regulation (GDPR) and the UK GDPR. When we process personal data on behalf of clients as part of a service, we act as their Data Processor under the DPDP Act, or processor under the GDPR, and the client's own privacy notice applies.

Until the relevant provisions of the DPDP Act come into force, we also follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

You can contact us about privacy at any time at connect@plurentoo.com.

02 What this policy covers

This policy applies to personal data we collect when you:

  • visit plurentoo.com or send us an inquiry through it;
  • make a privacy request or raise a grievance;
  • arrange training or an industrial visit for your institution, or take part in one;
  • apply for a job or send us your CV;
  • work for a client, prospective client, supplier or partner that deals with us;
  • communicate with us by email, phone or at events.

It does not cover the websites of other organizations that we link to, which have their own policies.

03 The personal data we collect

Categories of personal data
CategoryWhat it includes
Inquiry dataName, work email, company, phone number, country, the topic and industry you choose, your message and the page you sent it from.
Privacy request dataRequest type, your relationship with us, name, email, country, request details and, if you act for someone else, their name.
College program dataNames of participating students and staff, attendance and session feedback, and any details a host site requires for entry, shared by the institution we work with.
Recruitment dataThe information in your CV and cover email, interview notes and, for selected candidates and only with consent, background verification results.
Business contact dataNames, job titles, business contact details and correspondence of people at clients, suppliers and partners, and information needed to run a contract.
Website technical dataIP address, browser and device type, pages requested, date and time, and referring page, recorded in server logs by our hosting provider.
Consent recordsA random consent ID, your cookie choices, how you made them (including whether your browser sent a Global Privacy Control signal), the date and time, and the page where you made the choice. The consent record does not include your IP address.
Analytics data (only with your consent)Pseudonymous identifiers, pages viewed, approximate location, device and browser information, collected by Google Analytics if analytics is enabled and you opt in.

We do not ask for sensitive information such as passwords, financial account details, health information, biometric data or government identification numbers through this website. Please do not include them in messages or CVs.

04 Why we use personal data and our legal bases

We only use personal data for specific purposes. The table sets out each purpose and the basis we rely on.

Purposes and legal bases
PurposeData usedBasis under the DPDP ActBasis under the GDPR and UK GDPR
Replying to inquiries and preparing proposalsInquiry dataYour consent, and data you voluntarily provide for this purpose (section 7(a))Steps at your request before a contract (Art. 6(1)(b)) or our legitimate interest in responding (Art. 6(1)(f))
Handling privacy requests and grievancesPrivacy request dataCompliance with the DPDP Act and RulesLegal obligation (Art. 6(1)(c))
Running training programs and industrial visits for institutionsCollege program dataConsent of the participant obtained through the institution, or data the participant provides for this purpose (section 7(a)); for students under 18, verifiable consent of a parent or lawful guardian (section 9)Performance of our contract with the institution (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
RecruitmentRecruitment dataYour consent, and data you voluntarily provide for this purposeSteps before a contract (Art. 6(1)(b)); consent for background checks and for keeping your CV for future roles (Art. 6(1)(a))
Managing client, supplier and partner relationshipsBusiness contact dataData voluntarily provided for the relationship, and performance of our contractsContract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Operating and securing the website, and meeting CERT-In log requirementsWebsite technical dataCompliance with law and the security safeguards the Act requiresLegitimate interests in security (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
Remembering your cookie choicesConsent recordsCompliance with lawLegal obligation (Art. 6(1)(c)) and ePrivacy rules
Website analytics, if enabledAnalytics dataYour consentYour consent (Art. 6(1)(a))
Accounting, legal claims and regulatory complianceRelevant recordsCompliance with law and legal proceedings (section 7)Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Where we rely on consent, you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect processing that already took place. If you withdraw consent for an inquiry, we will stop using your data for it, which may mean we cannot continue the conversation.

We do not send marketing emails unless you have asked for them. We do not sell personal data.

05 Where the data comes from

Most personal data comes directly from you. Business contact data may also come from your employer or from colleagues who introduce us. Background verification results come from verification providers, and only with the candidate's consent. Technical data is generated when you use the website.

06 Who we share it with

We share personal data only when needed, and only with:

  • Service providers who process it on our instructions, such as our website hosting, email and collaboration providers, and, if analytics is enabled and you consent, Google as our analytics provider;
  • Host organizations for industrial visits, limited to the details they need for entry and safety;
  • Background verification providers, for selected job candidates who have consented;
  • Professional advisors such as lawyers, auditors and accountants, under confidentiality duties;
  • Government authorities, regulators and courts when the law requires it, including the Data Protection Board of India and CERT-In;
  • A buyer or successor if our business is reorganized, merged or sold, under the same protections.

Our service providers are bound by contracts that require confidentiality, security safeguards and deletion or return of data when the service ends. We do not sell personal data or share it for cross-context behavioral advertising.

07 International transfers

We are based in India, so personal data we receive from other countries is processed in India. Under the DPDP Act, we may transfer personal data outside India except to countries the Government of India restricts by notification.

The European Commission has not issued an adequacy decision for India. Where the GDPR or UK GDPR applies to a transfer, we use appropriate safeguards such as the European Commission's standard contractual clauses or the UK International Data Transfer Addendum, together with supplementary measures where needed. Some of our service providers may process data in other countries, such as the United States, under similar safeguards or a recognized framework such as the EU-US Data Privacy Framework. You can ask us for more information about these safeguards.

08 How long we keep it

Retention periods
RecordHow long we keep it
Inquiries that do not lead to a contractUp to 24 months after our last contact
Client, supplier and partner recordsFor the relationship, then for 8 years to meet accounting and tax requirements
Job applicationsUp to 12 months after our last contact, unless you ask us to delete them sooner
College program records (participant lists, attendance, feedback)Only as long as needed to run the program and close any follow-up with the institution, then deleted
Privacy requests and grievances3 years after the request is closed
Website server and security logsAt least 180 days as CERT-In directions require, and up to one year in line with the DPDP Rules, then deleted unless needed to investigate an incident
Consent recordsYour choice is valid for 6 months; the record is kept for up to 3 years to show how consent was given
Analytics data, if enabledCookies expire after 13 months; event data is kept in Google Analytics for no more than 14 months

When a retention period ends, or when you withdraw consent and no other legal basis applies, we erase or anonymize the data unless the law requires us to keep it longer.

09 How we protect it

We apply reasonable security safeguards, including:

  • encryption of data in transit using TLS, and encryption at rest where our providers support it;
  • access limited to people who need it, with multi-factor authentication and regular access reviews;
  • logging and monitoring to detect and investigate unauthorized access;
  • backups to keep data available after an incident;
  • security and confidentiality terms in contracts with service providers;
  • confidentiality obligations and privacy awareness for our staff.

No system is perfectly secure. If you believe your data has been exposed, contact us right away at connect@plurentoo.com.

10 Your rights

Under the DPDP Act (India)

You have the right to:

  • obtain a summary of your personal data that we process and of our processing activities, and the identities of others we shared it with;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your data erased when it is no longer needed, unless the law requires us to keep it;
  • withdraw consent at any time;
  • have your grievances redressed by us;
  • nominate another person to exercise your rights if you die or become incapacitated.

Under the GDPR and UK GDPR

You have the right to:

  • access your data and receive a copy;
  • have inaccurate data rectified;
  • have your data erased in certain circumstances;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time;
  • complain to a data protection supervisory authority.

Under US state privacy laws

Depending on where you live, you may have rights to know, access, correct and delete personal data, and to opt out of its sale or sharing. We do not sell or share personal data for targeted advertising, and we will not treat you differently for exercising your rights.

11 How to exercise your rights

Use our privacy request form or email connect@plurentoo.com. Tell us what you would like us to do and how you have interacted with us.

  • We acknowledge requests within 7 working days.
  • We respond within 30 days. Where the GDPR applies and a request is complex, we may extend this by up to two further months and will tell you why.
  • We aim to resolve grievances within 30 days of receiving them, well within the 90-day maximum that the DPDP Rules allow.
  • We may ask for information to confirm your identity, and we use it only for that purpose.
  • We normally do not charge a fee. Where the GDPR applies and a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request, and we will explain why.

Under the DPDP Act, you need to raise a grievance with us, and give us the chance to resolve it, before you approach the Data Protection Board of India. See Grievance Officer and complaints.

12 Cookies, analytics and browser signals

At present this website sets no cookies. If we enable analytics, we will ask for your consent first, and a strictly necessary cookie will remember your choice. Details are in our cookie policy, and you can review your choice at any time using the Cookie settings link in the footer.

We treat a Global Privacy Control signal from your browser as a request to switch off optional cookies. There is no agreed standard for Do Not Track signals, so we do not respond to them separately, but you can achieve the same result by rejecting optional cookies. Google Analytics, which loads only if analytics is enabled and you consent, is the only third-party script on our site. No other third party collects information about your online activities across websites through it.

We host our fonts and scripts ourselves and do not embed third-party maps, videos or social media widgets, so visiting our pages does not send your data to those providers.

13 Children

Our website is intended for businesses, institutions and adults. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from children through this website, and we do not track, monitor or target advertising at children. Our contact form asks you to confirm that you are 18 or older. If you believe a child has sent us personal data, contact us and we will delete it. Our training programs and industrial visits can include students under 18: in that case we require the institution to obtain, and share with us a record of, verifiable consent from a parent or lawful guardian before sharing their details with us, and we use those details only to run the program.

14 Automated decision-making

We do not make decisions that have legal or similarly significant effects on you based solely on automated processing, including profiling.

15 Personal data breaches

If a personal data breach occurs, we will act to contain it and will notify affected people and the Data Protection Board of India as the DPDP Act and Rules require. Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority and affected individuals when required. We also report cyber incidents to CERT-In in line with its directions.

16 Links to other websites

Our website links to other sites, such as Google Maps, our Google Business Profile, our LinkedIn page and the websites of our partner companies. Those sites have their own privacy practices, and we are not responsible for them. We do not embed their content, so nothing is sent to them unless you follow a link.

17 Grievance Officer and complaints

Our Grievance Officer answers questions and complaints about our processing of personal data:

Grievance Officer
Plurentoo Systems Private Limited
B-334, Gera's Imperium Gateway, Near Nashik Phata Metro Station, PCMC, Pune 411034, Maharashtra, India
Email: connect@plurentoo.com

We aim to resolve grievances within 30 days of receiving them. If you are not satisfied with our response, you can then complain to the Data Protection Board of India. If you are in the European Economic Area, you can complain to the supervisory authority in the country where you live or work, and in the United Kingdom to the Information Commissioner's Office.

18 Representatives in the EU and UK

If we are required to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, we will publish their contact details in this section. Until then, please contact us directly at connect@plurentoo.com.

19 Language of this policy

This policy is published in English. You can ask us for it in any language listed in the Eighth Schedule to the Constitution of India, including Hindi and Marathi, by writing to connect@plurentoo.com.

20 Changes to this policy

We review this policy regularly and at least once a year. When we make changes, we update the date at the top of the page. If a change is significant, we will also tell you through the website or by email where we have your details. This version is effective from 16 September 2026.

Next step

Tell us what you need to build, secure or run.

Start a conversation connect@plurentoo.com

Office

B-334, Gera's Imperium Gateway

Nashik Phata, Pimpri-Chinchwad, Pune

+91-8983100100, +91-7083708064

Open in Google Maps (opens in a new tab)Google Business Profile (opens in a new tab)

Services

  • Enterprise Applications
  • Data & AI
  • Cloud Services
  • Software & Product Engineering
  • Cybersecurity
  • Data Center & Hardware
  • Networking
  • Embedded & IoT Engineering
  • Managed IT Services
  • Technical Staffing

For colleges

  • The Production-Ready Campus
  • Industrial Visits

Industries

  • Automotive & Mobility
  • Banking, Financial Services & Insurance
  • Healthcare & Life Sciences
  • Manufacturing & Industrial
  • Retail & E-commerce
  • Hi-Tech & Software
  • Telecom & Media
  • Travel, Transport & Hospitality
  • Public Sector
  • Energy & Utilities
  • Education
  • Real Estate & Construction

Company

  • About us
  • Partner companies
  • Products
  • How we work
  • Platforms
  • Insights
  • Careers
  • Contact

Legal and privacy

  • Privacy policy
  • Cookie policy
  • Terms of use
  • Accessibility
  • Your privacy rights
  • Corporate information
  • Responsible disclosure
Company name
Plurentoo Systems Private Limited
CIN
U62020PN2026PTC259543
GSTIN
27AARCP4392E1ZZ
Registered office
B-334, Gera's Imperium Gateway, Near Nashik Phata Metro Station, PCMC, Pune 411034, Maharashtra, India
Email
connect@plurentoo.com
Telephone
+91-8983100100, +91-7083708064
Queries and grievances
Grievance Officer, connect@plurentoo.com
Plurentoo Systems

© 2026 Plurentoo Systems Private Limited. All rights reserved.

  • LinkedIn (opens in a new tab)
Back to top

Other product and company names on this site are trademarks or registered trademarks of their respective owners. They are used only to describe technologies we work with and do not imply partnership, endorsement or certification.

Cookie settings

Choose which optional cookies you allow. Strictly necessary cookies are always on. Your choice is stored for six months, after which we ask again. Read the cookie policy and privacy policy.

This site currently sets no optional cookies. No analytics or advertising cookies are used.

  • Strictly necessary

    Needed for the site to work and to remember your privacy choices. These cannot be switched off, and they are not used to track you.

    Cookies in this category
    • plu_consent · plurentoo.com · 6 months
      Stores your cookie choices, how and when you made them, and a random consent ID.
  • Analytics

    Help us understand which pages are useful and how visitors move through the site, using Google Analytics 4 with advertising features and Google signals switched off.

    Cookies in this category
    • _ga · Google Analytics (plurentoo.com) · 13 months
      Distinguishes one visitor from another.
    • _ga_<container-id> · Google Analytics (plurentoo.com) · 13 months
      Keeps track of the current session.