Legal
Privacy Policy
How KCS Global Group handles personal data collected through this website, and the rights you have over it under the Digital Personal Data Protection Act, 2023.
Effective from
23 August 2026
Last reviewed
23 August 2026
Applies to
kcsglobalgroup.com
In short
The four things most people want to know.
The full policy follows. This summary is not a substitute for it, but it is accurate.
We collect very little
Only what you type into an enquiry form or send us by email, plus standard server logs that every website generates.
We never sell it
No sale, no sharing for marketing, no advertising trackers, no behavioural profiling. We are not an advertising business.
Client data is separate
Data we handle while delivering services for a client is governed by our contract with that client, not by this policy.
You can ask us to delete
Write to us and we will remove your details. You do not need to give a reason, and it costs you nothing.
Before publishing this page: every highlighted item below needs a real answer from you. They are highlighted deliberately so they cannot slip through unnoticed. A privacy policy that describes practices you do not actually follow is worse than no policy at all — it is a written statement a regulator or client can hold you to.
Delete this box once every highlighted item is resolved.
Section 01
Who we are
This website is operated by KCS Groups, trading under the brand name KCS Global Group, of 2nd Floor, Shop No. 22, 19/22, Maitri Nagar, Risali – 490006, District Durg, Chhattisgarh, India. GSTIN 22EDMPP2279B3ZJ.
Under the Digital Personal Data Protection Act, 2023, we act as a Data Fiduciary in respect of personal data we collect through this website. That means we decide why and how that data is processed, and we are accountable for it.
For any question about this policy or about how your data is handled, write to contact@kcsglobalgroup.com. CONFIRM: whether you want a dedicated privacy@ address instead — recommended, as it separates rights requests from sales enquiries
Section 02
Two different kinds of data, and why the distinction matters
We handle personal data in two entirely separate capacities, and this policy covers only the first.
Data we collect for ourselves
Information you give us when you make an enquiry, apply for a job, or simply visit this website. We decide what happens to it. This policy governs it in full.
Data we process on behalf of clients
When we deliver services, we may handle information belonging to a client organisation. In that role we act as a Data Processor, working strictly on that client’s documented instructions and under a written agreement with them. We do not use client data for our own purposes, do not disclose it to anyone else without the client’s written consent, and return or delete it on the schedule agreed with them.
If your personal data has been given to us by a company that engaged our services, your rights sit with that company under their own privacy policy. We will pass any request you send us to them, but we cannot act on it independently.
Section 03
What we collect, and why
| What | When | Why we need it |
|---|---|---|
| Name, email address, telephone number, company name, nature of enquiry, and whatever you write in the message field | When you submit an enquiry form or email us directly | To read and reply to your enquiry, and if it progresses, to scope, quote and discuss the work |
| Name, contact details, CV contents, employment and education history, and anything else in your application | When you apply for a role with us | To assess your application and contact you about it |
| IP address, browser and device type, pages requested, referring page, date and time | Automatically, in standard web server logs | To keep the site running, diagnose faults, and detect abuse or attack |
Where you provide the information yourself, you are giving consent by submitting it. That consent is specific to the purpose above, and you can withdraw it at any time (Section 08). Server logs are generated automatically as a necessary part of operating a secure website.
How enquiry data reaches us. The enquiry form on this site opens your own email application with the details filled in; you then send it. Nothing you type is stored in this website’s database. CONFIRM: this stops being true the moment you connect the form to Web3Forms, WPForms or Contact Form 7. If you do, this paragraph must be rewritten to name that provider and say where submissions are stored
Section 04
What we do not do
- We do not sell personal data, and never will
- We do not share it with anyone for their own marketing purposes
- We do not run advertising trackers, retargeting pixels or behavioural profiling
- We do not use your data to train any automated system
- We do not make automated decisions that produce legal or similarly significant effects about you
This website is directed at businesses and is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, write to us and we will delete it.
Section 05
Cookies and third-party services
This website does not set advertising or analytics cookies of its own. CONFIRM: this must change if you install Google Analytics, Meta Pixel or any similar tool. Google Search Console alone does not require a change
Some services we rely on may set cookies or receive your IP address when a page loads. We use these because they are necessary to display the site, not to track you:
Google Fonts
Typefaces on this site are loaded from Google’s servers. When a page loads, your IP address is disclosed to Google. If you would prefer this did not happen, the fonts can be self-hosted instead CONFIRM: worth doing. It removes this disclosure entirely, speeds the site up, and takes about twenty minutes
Google Maps
Our Contact page embeds a Google map. When that page loads, Google may set cookies and will receive your IP address. Google’s handling of that data is governed by its own privacy policy, not ours.
Hosting
This site is hosted by Hostinger, which maintains server logs as described in Section 03.
WordPress
The site runs on WordPress, which may set functional cookies if you log in or leave a comment. It sets no cookies for ordinary visitors.
Section 06
Who else sees your data
We share personal data only where it is necessary, and only with:
- Our hosting provider, which stores the website and its logs
- Our email provider, which carries and stores correspondence with us CONFIRM: name it — Hostinger email, Google Workspace, Zoho, or whichever you use
- Google, in the limited circumstances described in Section 05
- Any authority where we are legally required to disclose, or where disclosure is necessary to establish or defend a legal claim
Transfers outside India. Some of the providers above process data on servers located outside India. Section 16 of the DPDP Act permits such transfers except to territories the Central Government restricts by notification. We will review our arrangements if and when that list is published.
Section 07
How long we keep it
We keep personal data only as long as the purpose it was collected for still exists, and then delete it.
- Enquiry correspondence — retained for CONFIRM: suggested 24 months from our last exchange with you, then deleted
- Job applications — retained for CONFIRM: suggested 12 months from the close of the role, then deleted, unless you ask us to keep them on file for future openings
- Server logs — retained for CONFIRM: check what Hostinger actually retains and state it
- Records we must keep by law, such as tax and accounting records, for the period the relevant law requires
You can ask us to delete your data sooner than any of these periods, and we will, unless a legal obligation requires us to keep it.
Section 08
Your rights
Under the DPDP Act, 2023, as a Data Principal you have the right to:
- Access — ask what personal data of yours we hold, what we are doing with it, and who we have shared it with
- Correction and completion — have inaccurate data corrected, incomplete data completed, and outdated data updated
- Erasure — ask us to delete your data where we are not required by law to retain it
- Withdraw consent — withdraw at any time, as easily as it was given. Withdrawal does not affect processing already carried out
- Nominate — name another person to exercise these rights on your behalf in the event of your death or incapacity
- Grievance redressal — raise a complaint with us, as set out in Section 10
To exercise any of these, write to contact@kcsglobalgroup.com with enough detail for us to identify your records. There is no charge. We will respond within CONFIRM: suggested 30 days — and it must be a period you can actually meet
The Act also places a duty on Data Principals not to raise false or frivolous complaints and to provide accurate information when exercising the right to correction.
Section 09
How we protect it
We apply security measures proportionate to the small volume of personal data this website collects:
- The site is served over HTTPS
- Administrative access is limited to named individuals and protected by passwords and access controls
- Client work is performed at our own premises on company-controlled machines; we do not distribute client data to personal or remote devices
- Access is granted on a need-to-know basis and withdrawn when no longer required
- Software and plugins are kept updated
No system is perfectly secure, and we do not claim otherwise. We hold no security certification and do not represent that we do.
If a breach occurs. Should a personal data breach affect your information, we will notify you and report it to the Data Protection Board of India within the timeframes the DPDP Rules require, describing what happened, what data was involved and what you can do about it.
Section 10
Complaints
If you are unhappy with how we have handled your data or your request, write to contact@kcsglobalgroup.com, marking your message for the attention of CONFIRM: name the person responsible — for now this is almost certainly you. We will acknowledge and respond.
If our response does not resolve matters, you may complain to the Data Protection Board of India, which was constituted in November 2025 and accepts complaints from Data Principals.
Section 11
Changes to this policy
We will update this page when our practices change — in particular if we add analytics, connect the enquiry form to a third-party service, or change email provider. The effective date at the top of this page shows when it was last revised. Material changes will be summarised here rather than made silently.
Data requests
Want to know what we hold, or want it deleted?
Write to us and say so. No form to fill in, no reason required, no charge. We will confirm what we hold and act on your request.