Legal Pages

Privacy Policy for DKode Architects

1. Introduction

This Privacy Policy (“Policy”) explains how DKode Architects (“DKode”, “we”, “us”, “our”) collects, uses, stores, shares, discloses, retains and protects your personal data when you visit www.dkodearchitects.com and its sub-pages (the “Website”), submit an enquiry or job application, subscribe to our updates, engage us for professional services, or otherwise interact with us.
DKode Architects is an architectural and design practice based in Dubai with its origin in Mumbai, India, providing architectural & interior design services.
We are committed to handling your personal data lawfully, fairly and transparently, in accordance with:
Please read this Policy carefully. By accessing the Website, submitting any form, or otherwise providing us with personal data, you acknowledge that you have read and understood this Policy. Where the law requires your consent, we will obtain it separately and specifically at the point of collection.

2. Who We Are - Data Fiduciary Details

For the purposes of the DPDP Act, DKode Architects is the Data Fiduciary in respect of the personal data described in this Policy.
Our architects are registered with the Council of Architecture under the Architects Act, 1972.

3. Definitions

For ease of reading, the following terms carry the meanings given below (which align with the DPDP Act):

4. Personal Data We Collect

4.1 Information you provide directly

(a) Website enquiry form (“Let’s Talk” / Contact page)
(b) Careers application form
(c) Newsletter / subscription
(d) Direct correspondence
(e) Client and project engagement data (post-appointment)
Where you appoint us for professional services, we may additionally collect and process:

4.2 Information collected automatically

When you use the Website, our servers, hosting provider and security/CDN provider automatically log certain technical data, including:

4.3 Cookies and similar technologies

See Section 8 below.

4.4 Information from third parties

We may receive personal data about you from:

4.5 Data we do not seek

We do not intentionally collect financial account passwords, biometric data, health data, caste or religious affiliation, or sexual orientation through the Website. Please do not include such information in free-text fields or uploaded files. If you do so, you consent to our processing it as part of your submission, and you may ask us to delete it at any time.

5. Purposes for Which We Process Your Personal Data

5.1 Lawful basis

Under the DPDP Act, we process personal data:
(a) On the basis of your consent, which is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Consent is our basis for enquiry forms, career applications, newsletters, and non-essential cookies.
(b) For “certain legitimate uses” recognised under Section 7 of the DPDP Act, including:
Where we rely on your consent, you may withdraw it at any time (see Section 12.5). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide certain services to you.

5.2 No purpose creep

We will not use your personal data for a materially different purpose without first informing you and, where required, obtaining fresh consent.

6. Who We Share Your Personal Data With

We do not sell your personal data, and we do not rent or trade it for advertising purposes. We share personal data only as set out below, and only to the extent necessary.
(a) Statutory and regulatory authorities – In the course of liaisoning and approvals work, we make submissions to and correspond with public authorities. Depending on the location of the project, these may include municipal corporations and planning authorities (such as the Municipal Corporation of Greater Mumbai (MCGM/BMC), MHADA, SRA, MMRDA or CIDCO), the relevant State fire services, tree authorities, environmental and coastal-zone authorities, the Airports Authority of India, the office of the Collector, the relevant RERA authority, and other competent bodies. Such submissions are made on your instructions and are governed by the applicable statutory processes, which may include public display or inspection of certain documents.
(b) Project consultants and contractors – structural, MEP, HVAC, plumbing, landscape, façade, acoustic, fire-safety, quantity-surveying, environmental and other consultants; contractors; vendors; and surveyors, where required to deliver your project.
(c) Service providers and processors – website hosting and maintenance providers, content-delivery and security providers, email and communications providers, document storage and backup providers, form and CRM providers, analytics providers, IT support, accountants, auditors, insurers and legal advisers. These parties are contractually required to process personal data only on our instructions and to maintain appropriate security safeguards.
(d) Professional and legal disclosures – to our advisers, insurers, or to courts, tribunals, arbitrators, law enforcement or regulators, where disclosure is required by law or is necessary to establish, exercise or defend legal claims.
(e) Business Transfer – in connection with any merger, restructuring, succession or transfer of our practice, subject to the recipient being bound by terms no less protective than this Policy.
(f) With your consent – for example, where you agree to be named in a case study, testimonial or published project credit.

7. Cross-Border Transfers

Our primary servers and records are maintained in India. However, some of our service providers (for example, cloud storage, email, security/CDN and analytics providers) may store or process data on servers located outside India.
Where personal data is transferred outside India:
For visitors in the EEA or UK, please also see Section 19.

8. Cookies and Similar Technologies

8.1 What we use

The Website is built on WordPress with the Elementor page builder, uses a forms plugin for form handling, and is served through a content delivery and security network. These technologies place the following broad categories of cookies and local storage items:

8.2 Managing cookies

9. Data Retention

We retain personal data only for as long as is necessary for the purpose for which it was collected, or for such longer period as is required under applicable law. Indicative retention periods:
On expiry of the applicable retention period, or on a valid erasure request, we will erase the personal data unless retention is necessary for compliance with law or for the establishment, exercise or defence of legal claims.

10. Security Safeguards

We implement reasonable security safeguards to prevent personal data breaches, as required under Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules. These include, as appropriate to the risk:
No system is perfectly secure. While we take our obligations seriously, transmission of information over the internet is not entirely secure, and we cannot guarantee absolute security of data transmitted to us. You are responsible for keeping confidential any credentials used to access shared project folders or file-transfer links we provide.

11. Personal Data Breach

If we become aware of a personal data breach, we will:

12. Your Rights as a Data Principal

Subject to the DPDP Act and the DPDP Rules, you have the following rights.

12.1 Right to access information

You may obtain a summary of the personal data we are processing about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Data Processors with whom your data has been shared (together with a description of the data shared).

12.2 Right to correction, completion, updating and erasure

You may request that we correct inaccurate or misleading personal data, complete incomplete data, update data, or erase personal data that is no longer necessary for the purpose for which it was collected – unless retention is necessary for a specified purpose or for compliance with any law.

12.3 Right of grievance redressal

You may raise a grievance with us regarding any act or omission relating to the performance of our obligations, or regarding the exercise of your rights. We will respond within the timeline published on the Website (see Section 13). You must exhaust this route before approaching the Data Protection Board.

12.4 Right to nominate

You may nominate any other individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity. Please write to us to register a nomination.

12.5 Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time, with the same ease with which it was given. Following withdrawal, we (and our processors) will cease processing your personal data within a reasonable time, unless another lawful basis for continued processing applies.

12.6 How to exercise your rights

Send a request to admin@dkodearchitects.com with the subject line “Data Principal Request — [Access / Correction / Erasure / Withdrawal / Nomination]”, or write to us at the registered office address in Section 2. Please include:
We may need to verify your identity before acting on a request. We will acknowledge your request promptly and respond within 30 days, or such shorter period as may be prescribed. If we are unable to comply with a request in full, we will tell you why.
There is no fee for exercising your rights. We may decline manifestly unfounded, excessive or repetitive requests, or charge a reasonable fee for additional copies, and we will explain our reasons if we do.

12.7 Your duties

Under Section 15 of the DPDP Act, you must not impersonate another person while providing personal data, must not suppress material information, must not register a false or frivolous grievance or complaint, and must furnish only authentic information when seeking correction or erasure.

12.8 Escalation

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India through its digital complaint mechanism. Appeals against the Board’s orders lie with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

13. Children's Personal Data

The Website and our services are intended for adults and are not directed at children.
We do not knowingly collect personal data of any individual below 18 years of age without the verifiable consent of a parent or lawful guardian. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Internship applicants must be at least 18 years old, or must apply through a parent or lawful guardian.
If you believe that a child has provided us with personal data, please contact the Grievance Officer immediately, and we will take steps to delete it.

14. Persons with Disabilities

Where personal data relates to a person with a disability who has a lawful guardian, we will process such data only on the basis of consent given by that guardian, following verification in accordance with the DPDP Rules.

15. Marketing Communications

We will send you marketing or promotional communications only where you have opted in, or where you have engaged us and the communication relates to similar professional services.
Every marketing email contains an unsubscribe link. You may also write to info@dkodearchitects.com with the subject “Unsubscribe”. We will action opt-out requests promptly. Please note that we will continue to send you transactional and service communications relating to a live project or engagement, as these are necessary for performance of our services.

16. Third-Party Websites, Links and Social Media

The Website contains links to third-party websites and platforms, including our profiles on Instagram, Facebook and LinkedIn, embedded media, and client or partner websites. This Policy does not apply to those third parties.
We do not control and are not responsible for the privacy practices, content or security of third-party sites. We encourage you to read their privacy policies before providing them with personal data.
Any downloadable portfolio or brochure hosted on our own domain may, when opened, involve your browser or device provider processing data in accordance with their own terms.

17. Automated Decision-Making and Profiling

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Recruitment shortlisting and client engagement decisions are made by our personnel.

18. Additional Information for Visitors in the EEA and the United Kingdom

Where the EU GDPR or UK GDPR applies to our processing of your personal data (for example, if you contact us from the EEA or UK in relation to a project), the following additional information applies:
Legal bases: we rely on (i) your consent for marketing and non-essential cookies; (ii) performance of a contract or steps taken at your request prior to entering a contract, for enquiries and service delivery; (iii) legal obligation for tax, accounting and regulatory compliance; and (iv) our legitimate interests in operating and securing our website, developing our practice, and defending legal claims – balanced against your rights and freedoms.
Additional rights: you may have the right to object to processing based on legitimate interests, the right to restrict processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
International transfers: where personal data is transferred from the EEA or UK to India, we rely on appropriate safeguards, including Standard Contractual Clauses (and the UK International Data Transfer Addendum) where required.
Retention: as set out in Section 9.

19. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. The revised version will be posted on this page with an updated “Last Updated” date.
Where changes are material — for example, a new purpose of processing or a new category of recipient – we will provide prominent notice on the Website and, where required by law, obtain your fresh consent. We encourage you to review this page periodically.

20. Governing Law and Jurisdiction

This Policy is governed by and construed in accordance with the laws of India. Subject to the jurisdiction of the Data Protection Board of India under the DPDP Act, the courts and tribunals at [Mumbai, Maharashtra] shall have exclusive jurisdiction over any dispute arising out of or relating to this Policy.

21. Contact Us

DKode Architects
Office No.1440, Tamani Arts Building, Al Asayel Street, Business Bay, Dubai.
General enquiries: admin@dkodearchitects.com
Careers enquiries: admin@dkodearchitects.com
Privacy and data protection: admin@dkodearchitects.com