Effective date: 20 July 2026
Last reviewed: 20 July 2026
BricksGenius is a trading name operated by Arnab Mohapatra, an individual based in India. In this Privacy Policy, “BricksGenius,” “we,” “us,” and “our” refer to Arnab Mohapatra operating under that trading name. BricksGenius is not a registered company, corporation, or separate legal entity.
Privacy contact (person responsible for responding to privacy enquiries; not a formally appointed Data Protection Officer): Arnab Mohapatra — arnab@bricksgenius.com — https://bricksgenius.com/contact/
This policy is designed to support compliance where applicable laws apply. It is not a certification of universal compliance. Threshold and jurisdiction analysis, and qualified legal review, may be required for specific engagements or markets.
1. Operator identity
Operator: Arnab Mohapatra trading as BricksGenius. Location: India. Contact email: arnab@bricksgenius.com. No company number, GST/VAT number, registered office, or postal address is published here because none has been provided for publication. If a postal address becomes legally required for a specific activity (for example certain commercial email rules), that activity will remain blocked until an address is supplied — we will not invent one.
2. Scope
This policy covers personal data processed in connection with https://bricksgenius.com/ and related staging or project environments we operate for delivering WordPress and Bricks Builder development services. It does not cover third-party websites we do not control.
3. Data collected directly
When you contact us or engage services, you may provide: name; email address; business/organisation name; website URL; project brief; file attachments; scheduling preferences; and billing details needed for invoices (for example business name and billing email). We do not operate customer accounts, public profiles, forums, competitions, sweepstakes, SMS campaigns, or employment application portals on this website.
4. Data collected automatically
Like most websites, our hosting and WordPress stack may process technical data such as IP address, browser/user-agent, requested URLs, timestamps, and security/log events. As of the last review date, optional analytics and marketing pixels (including Google Analytics, Plausible, Meta Pixel, and similar tools) are not active on the public site. See our Cookie Policy and cookie inventory for current similar technologies.
5. Contact-form processing
Messages submitted through site contact forms are used to respond to enquiries and assess fit for services. Form content is processed through WordPress / Bricks form tooling and delivered to our business email. We do not sell form submissions.
6. Proposal and client onboarding
If we prepare a proposal or Statement of Work, we process the business and project information you supply, correspondence, and related scheduling notes to negotiate and deliver work.
7. Project and staging access
For delivery we may create or use staging environments, repositories, design files, and project tools. Access is limited to people who need it for the engagement. Staging copies are temporary working environments and are removed or archived according to the retention criteria below and any Statement of Work terms.
8. WordPress credentials
Where you provide credentials (WordPress admin, hosting, DNS, design tools), we use them only to perform contracted work. Prefer temporary, least-privilege access. We do not use client credentials for unrelated purposes. Rotate credentials after handoff where practicable.
9. Client-site personal data
When working on a client website, we may encounter personal data of that site’s end users (for example form entries, customer records, or content). In that capacity we typically act as a processor / service provider for the client (controller), subject to the client’s instructions and applicable law. See section 18 and our draft Data Processing Addendum (for legal review before execution).
10. Billing and payment records
We keep invoice and payment records needed for accounting and tax. Payment card details, where used, are collected by the payment provider you choose for that transaction — we do not store complete card numbers on our systems. Exact payment processors vary by engagement and are not listed here unless used.
11. Service providers (subprocessors)
We use infrastructure and tooling providers to operate the website and deliver services (for example hosting, DNS/CDN, email, fonts, and policy/consent tooling). See the published Subprocessor List for verified providers and status (active / planned). We do not invent vendors.
12. Purposes of processing
- Respond to enquiries and provide proposals
- Deliver contracted development, migration, optimisation, and related services
- Operate and secure the website
- Maintain business records (contracts, invoices, support history)
- Comply with legal obligations where applicable
- Communicate about an engagement (transactional / service messages)
13. Lawful / legal grounds (where applicable)
Depending on jurisdiction and context, processing may rely on: performance of a contract or steps prior to contract; legitimate interests in operating a B2B service business (balanced against your rights); consent (for example non-essential cookies or marketing, where used); and legal obligation. Under India’s Digital Personal Data Protection Act, 2023, processing is generally based on consent or certain legitimate uses defined in that Act, subject to threshold and commencement analysis. This wording is designed to support compliance where those regimes apply; it is not legal advice.
14. Consent and withdrawal
Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing. For cookies and similar technologies, use Cookie Settings (footer control and/or the GetTerms reopen control) or visit the Cookie Policy. Withdrawal of optional consent does not delete records we must retain for legal or contractual reasons.
15. Retention schedule
We retain personal data only as long as needed for the purposes above, then delete or anonymise it where practicable. Typical criteria (not guarantees of exact deletion timing):
- Contact enquiries: up to 24 months after last meaningful correspondence, unless a project starts
- Proposal records: up to 24 months after proposal expiry or decline; longer if needed for dispute context
- Contracts / Statements of Work: duration of engagement plus up to 7 years (accounting/legal)
- Invoices and payment records: up to 7 years or longer if required by tax law
- Support messages: duration of engagement plus up to 24 months
- Project files: duration of engagement plus up to 12 months after handoff, unless SOW says otherwise
- Staging copies: removed after handoff or within 90 days of project close, unless extended access is agreed
- Backups: rotated per hosting/backup provider schedules (often 7–30 days for routine backups)
- Security logs: typically 30–180 days unless investigating an incident
- Consent records: for the life of the consent signal plus up to 24 months
- Newsletter suppression / unsubscribe records (if marketing email is ever activated): retained as needed to honour opt-out
16. Security measures
We use reasonable technical and organisational measures appropriate to a small professional practice (access control, HTTPS on the public site, least-privilege credentials, and careful handling of client environments). We do not claim specific certifications, guaranteed encryption implementations, guaranteed breach notification timings, or absolute security. No method of transmission or storage is perfectly secure.
17. International transfers
We are based in India. Service providers and tools may process data in other countries. Where a transfer mechanism is required by applicable law, we will use an appropriate mechanism for that engagement. Cross-border transfer details for verified subprocessors are summarised on the Subprocessor List where known.
18. Controller / processor role split
Website visitors and direct clients: we determine purposes for our own sales and delivery records and act as controller / data fiduciary for that data, subject to applicable law.
Personal data on client websites: the client typically remains controller / data fiduciary; we process under documented instructions as processor / service provider for the contracted scope.
19. Data-subject rights
Subject to applicable law and exemptions, you may have rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent. To exercise rights, email arnab@bricksgenius.com. We may need to verify your identity and the scope of the request.
20. India DPDP rights and process
Where India’s Digital Personal Data Protection Act, 2023 and related Rules apply, you may have rights to correction, completion, updating, erasure, and grievance redressal as provided in that framework. Contact Arnab Mohapatra at arnab@bricksgenius.com. Certain DPDP Rule obligations have staged commencement dates; we will align operational processes as those obligations become enforceable. Requires qualified legal review for specific cases.
21. GDPR / UK GDPR treatment (where applicable)
If you are in the EEA/UK and those regimes apply to a particular processing activity, the rights and transparency expectations in GDPR / UK GDPR may apply, subject to threshold and territorial analysis. We do not claim that every page visit automatically triggers full GDPR controller obligations. Contact us for jurisdiction-specific requests.
22. US state privacy treatment (where applicable)
US state laws such as the CCPA/CPRA apply only when statutory thresholds are met (for example revenue, volume of consumers, or selling/sharing). As a small B2B operator we may fall outside those thresholds. We do not currently “sell” or “share” personal information for cross-context behavioural advertising. A “Do Not Sell or Share” page will be published only if applicable processing exists or is planned.
23. Cookies and similar technologies
See our Cookie Policy. Non-essential technologies are disabled by default and require consent via the cookie consent manager before activation. Browser settings alone are not treated as the sole consent mechanism.
24. Children’s data
Our services are directed to businesses and adult professionals. We do not knowingly collect personal data from children. If you believe we have received such data, contact us and we will delete it where required.
25. Marketing communications
We do not currently operate a public newsletter signup or active bulk promotional email system (including SendFox) on this site. Transactional messages about your enquiry or project may still be sent. Bulk promotional email to US recipients is blocked until a valid physical postal address is available for CAN-SPAM compliance support. We will not invent a postal address or claim CAN-SPAM compliance without one.
26. Complaints and grievance route
Contact Arnab Mohapatra at arnab@bricksgenius.com. We aim to acknowledge privacy enquiries within 7 business days. You may also have the right to complain to a supervisory authority or the Data Protection Board of India where those bodies have jurisdiction.
27. Policy changes
We may update this policy to reflect operational or legal changes. The effective and last-reviewed dates above will be updated when material changes are published. Continued use of the site after updates constitutes notice of the revised policy for website visitors; material changes affecting clients may also be communicated through the engagement channel.
28. Contact details
Arnab Mohapatra (BricksGenius)
Email: arnab@bricksgenius.com
Contact page: https://bricksgenius.com/contact/
This policy describes actual current processing as of the last reviewed date. It does not invent inactive features (customer accounts, SMS marketing, targeted advertising, competitions, precise geolocation, demographic profiling, public comments, or stored card vaults).