Legal · Effective August 2026
Privacy Policy & Data Protection Notice
Covers hummingsun.co.in and workspace.hummingsun.co.in. Read alongside our Cookie Policy.
1. Who We Are
HummingSun™ ("we", "us", "our") provides workplace wellbeing, assessment, capability-building, and related advisory and technology services to organisations. This notice explains what personal data we collect through our website (hummingsun.co.in), our product (workspace.hummingsun.co.in), and our client engagements, and how we handle it.
Data Controller: HummingSun, 1159, Palam Vihar, Gurgaon 122017, India.
Contact for privacy matters: info@hummingsun.co.in — see Section 11, Grievance Officer, for the formal contact required under Indian law.
2. Scope
This notice applies to three categories of people, who receive different treatment below:
- Website visitors — people browsing hummingsun.co.in or the public pages of workspace.hummingsun.co.in.
- Leads and prospects — people who submit a form (e.g. "Talk to Us", the contact form, or the Advisor chat widget) expressing interest in the product or advisory services.
- Survey and assessment participants — employees of a client organisation who are invited to complete a wellbeing survey or assessment inside the product. This is the most sensitive category and has additional protections in Section 6.
3. What We Collect
3.1 Website visitors: Standard technical data — IP address, browser/device type, pages visited, referring site (via analytics/cookies — see our Cookie Policy).
3.2 Leads and prospects: Name, work email, company name, role, and anything volunteered in a form or chat conversation with the Advisor widget.
3.3 Survey and assessment participants: Responses to wellbeing survey and assessment questions, which may touch on stress, engagement, and psychological wellbeing — treated as sensitive personal data (see Section 6). Basic org-provided identifiers needed to route a participant to the right survey (e.g. employee ID, department, manager) — configurable per client, minimised wherever possible.
4. Why We Process This Data (Legal Basis)
Under GDPR (where applicable) we rely on: consent (Art. 6(1)(a)) for survey participation and marketing communications; contract necessity (Art. 6(1)(b)) for delivering the platform to a paying client; and legitimate interest (Art. 6(1)(f)) for basic website analytics and lead follow-up.
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), we rely on consent as the primary basis for processing personal data, and on the "legitimate uses" exceptions in the Act only where they clearly apply (e.g. a voluntarily provided lead form). Consent notices must be in clear, plain language and offered in the same languages the client organisation otherwise operates in.
5. How We Use It
- To operate and improve the platform and respond to support requests.
- To follow up with leads who request a walkthrough, demo, or quote.
- To generate aggregated, de-identified insights and reports for the client organisation that commissioned a survey or assessment (never raw individual responses tied to identity, per Section 6).
- To meet legal, accounting, or security obligations.
6. Sensitive Data & the Anonymity Commitment
Wellbeing survey and assessment responses are treated as sensitive personal data. This is the category most likely to determine whether people trust and honestly participate in a survey, so it needs to be airtight before rollout, not just legally compliant.
Our commitment: individual survey responses are not shown to a participant's employer in a form that identifies them. Employers receive aggregated results only, and only where a minimum group size (e.g. 5+ respondents) is met, to prevent re-identification in small teams. This needs to be true at the database and reporting-logic level, not just stated in a policy.
7. Who We Share Data With (Sub-processors)
We use third-party infrastructure providers to run the platform, including:
- Supabase (database/backend) — data is hosted with encryption in transit and at rest, and access is restricted to authorised personnel.
- Vercel (hosting) — for the website and application.
- Resend (transactional email) — used for platform notifications sent from support@hummingsun.co.in.
We do not sell personal data. Any additional sub-processor added in future will be listed here and, where required, disclosed to clients under their data processing agreement.
8. International Data Transfers
Because our infrastructure may be hosted outside India, transferring personal data of India-based data principals outside India needs to be checked against the DPDP Act's cross-border transfer provisions (the Act permits transfers by default except to countries the government specifically restricts by notification). If any client or participant is in the EU/UK, GDPR's transfer rules (adequacy decisions, standard contractual clauses) apply separately and need their own review.
9. Data Retention
Our retention periods by data category:
- Website analytics: 12–14 months, then aggregated or deleted.
- Lead/prospect data: retained while the relationship is active; deleted or anonymised after a defined period of inactivity (e.g. 24 months).
- Survey/assessment data: retained per the client contract term, then deleted or returned per the client's instruction at contract end.
10. Cookies & Tracking
The website uses cookies for basic functionality and, if enabled, analytics. See our full Cookie Policy for details on what we use, why, and how to manage your preferences.
11. Your Rights / Grievance Officer
Under the DPDP Act, data principals have the right to access their data, seek correction and erasure, and file grievances. The Act requires companies above certain thresholds to appoint a Grievance Officer and publish their contact details; even where not strictly mandatory at your current size, publishing a named contact builds trust with enterprise clients evaluating you. Under GDPR, data subjects additionally have rights to data portability and to object to processing.
Grievance Officer / Privacy Contact: Deepika S, Founder — info@hummingsun.co.in
12. Security
We apply industry-standard security measures, including encryption of data in transit and at rest, role-based access controls, least-privilege access to production systems, and audit logging of key actions. Further technical and organisational detail is available under NDA to enterprise clients during procurement.
13. Children's Data
Our services are intended for use by working adults in an employment context and are not directed at children. We do not knowingly collect data from anyone under 18.
14. Changes to This Policy
We will update this notice as the product and our legal obligations evolve, and will note the effective date at the top of the page.
15. Contact Us
HummingSun™, 1159, Palam Vihar, Gurgaon 122017, India · info@hummingsun.co.in · +91 6006743501
Appendix A — Survey / Assessment Participant Consent Notice
Short-form notice shown to a participant before they begin a wellbeing survey or assessment. Intentionally plain-language, since this is read by employees, not lawyers.
Where this lives: this is not a public web page. It's an interstitial screen inside HummingSun™ Workspace itself — shown to a survey participant at the moment they click to start a survey or assessment, before any question appears.
Before you begin — how HummingSun™ handles your responses
This survey is run by HummingSun™ on behalf of your employer, [Client Org Name]. Your individual answers are never shown to your employer in a way that identifies you. Your employer only sees combined results from your team or group, and only when enough people have responded that no individual can be identified. You can skip any question you're not comfortable answering.
Questions about how your data is used? Contact info@hummingsun.co.in or see our full Privacy Policy at hummingsun.co.in/privacy.
By clicking "Start", you confirm you've read this notice and consent to your responses being processed as described.