• Who We Are
  • What We Do
  • Future of Retail
  • Insights
Privacy Notice
Last updated 29th June 2026
Introduction
Litmus7 Systems Consulting Private Limited, its subsidiaries, associates, affiliates (collectively, “Litmus7”, “we” “us”, or “our”) are committed to protecting your privacy and respecting your choices.
This Privacy Notice (“Privacy Notice”) outlines how we collect and process your Personal Data in accordance with applicable data privacy laws.
We value your privacy and are committed to protecting your personal data. This Privacy Notice explains how we collect, use, disclose, and safeguard your Personal Data across our operations.
In this Privacy Notice, “Personal Data” or “Personal Information” shall mean any information about an individual who can be identified from that information or from that information combined with other information to which we are likely to have access, including without limitation, information such as name, address, telephone number, email address, identification numbers, location data, and online identifiers.
Objective
The objective of this Privacy Notice is to provide a transparent, comprehensive, and legally compliant overview of how Litmus7 processes personal data. We are committed to safeguarding the privacy of our website visitors, office visitors, candidates, vendors, interns, partners, and customers in accordance with global data protection standards and applicable laws.
    This Privacy Notice has been formulated in order to fulfill the following obligations:
  • Clearly explain what Personal Data we collect, why we collect it, how it is used, who it is shared with, and your rights;
  • Demonstrate our commitment to compliance with applicable data protection and privacy laws, including, where applicable, the UK GDPR and Data Protection Act 2018, relevant United States federal and state privacy laws, the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”), India’s Digital Personal Data Protection Act, 2023 (“DPDP”), Australia’s Privacy Act 1988 and Australian Privacy Principles, Singapore’s Personal Data Protection Act 2012 (“PDPA”), China’s Personal Information Protection Law (“PIPL”), Japan’s Act on the Protection of Personal Information (“APPI”), and the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection etc.
  • Provide you with the necessary mechanisms to easily exercise your legal rights regarding access, correction, deletion, and control of your personal data; and
  • Establish the standards by which we protect your personal assets and ensure that cross-border data movements are handled with strict legal safeguards.
By understanding our objectives, you can confidently engage with our services, websites, and business operations knowing your privacy is prioritized.
This Privacy Notice is intended to provide a global baseline. Certain rights, notices, lawful bases, consent requirements, cross-border transfer mechanisms, breach notification obligations, regulator complaint mechanisms, and exemptions may vary depending on your location, the nature of your relationship with us, the category of Personal Data involved, and the applicable law.
In the event of any conflict between this Privacy Notice and applicable laws, the applicable laws shall prevail.
Where local law provides higher protection, such law will prevail and we assure you that we will comply with those applicable provisions ensuring all your rights are protected.
Personal Data collected by Litmus7
The following Personal Data shall be collected by Litmus7 (“Personal Data”)
CategoryTypes of Personal DataSource of Personal Data
Website Visitor
  • Identification data (name, email, phone).
  • Technical data (IP address, browser type, OS).
  • Cookies and tracking identifiers.
  • Usage data (pages visited, behavior).
When you contact us with any service-related queries, complaints or requests (using Contact Us, or similar section available on our website) or when you view our Website.
Business Partners,
Suppliers and
Customers
  • Contact details
  • Financial and contractual information
  • Due diligence/KYC documentation
  • Account information
  • Contact details
  • Payment and billing information
  • Service usage data
  • Support communications

When you contact us (through emails or other means) for business purposes; or

When you contact us with any queries (e.g. using deskside assistance, service-related queries etc.).

Visitors at Litmus7
Office
  • Name and contact details
  • Identity verification data (ID numbers, photographs where required)
  • CCTV footage
  • Access logs
When you fill our visitor logbooks (or visitor forms) or visit our office premises.
Employment
Candidates
  • Resume/CV details
  • Education, employment history
  • References and interview notes
  • Background checks (where legally permitted)

When you make an application to us;

From your referee, headhunters; or

From your or our recruiter, recruitment agency or recruitment website/platform.

Interns
  • Academic and personal data
  • Identification documents
  • Performance and evaluation records

When you make an application to us; or when you provide information as part of onboarding process.

How do we use Personal Data?
CategoryPurpose of Processing
Website VisitorWebsite optimization, security, analytics, marketing.
Business Partners,
Suppliers and
Customers

Performing contractual obligations, legal obligations, collaborations.

Visitors at Litmus7
Office
Workplace safety, asset protection, building security.
Employment
Candidates
  • To assess candidate’s suitability towards job requirement as part of the recruitment or internship selection process and other associated processes including background verification by our authorized vendor.
  • To carry out various employer related activities if you are selected to join the organization and to enable us to ensure that we are compliant with any applicable labour and/or other relevant laws.
We process your Personal Data when it is necessary for the performance of a contract to which you are the party or in order to take steps at your request prior to entering into a contract or based on your consent, as per applicable laws.
Legal Basis of Processing (not applicable in India)
We process your Personal Data only where we have a lawful basis under applicable law. Depending on the jurisdiction and processing activity, this may include consent, performance of a contract or pre-contractual steps, compliance with legal obligations, legitimate interests pursued by us or a third party where not overridden by your rights, vital interests, public interest or legally recognised legitimate uses. Where we rely on legitimate interests, we consider and balance those interests against your privacy rights and expectations. Where consent is required, including for certain marketing, cookies, sensitive Personal Data, cross-border transfers, or children’s data, we will seek consent in the manner required by applicable law.
Sensitive Personal Data
We may process sensitive Personal Data, where permitted by applicable law and necessary for a specified and lawful purpose. This may include government-issued identifiers, financial data, background verification data, CCTV footage, access logs, and related physical security information. We process such data only to the extent required for identity verification, onboarding, statutory compliance, payments, background checks, workplace safety, security, fraud prevention, contractual obligations, or legal claims. Where applicable law requires consent for processing sensitive Personal Data, we will obtain such consent unless another lawful basis or statutory exception applies.
Automated Decision-Making and Profiling
We do not generally make decisions producing legal or similarly significant effects concerning you based solely on automated processing, including profiling, without human involvement. Where we do carry out such automated decision-making or profiling, we will do so only as permitted by applicable law and, where required, on the basis of your consent. In such cases, you have the right to request human review of the decision, to express your point of view, and to contest the decision.
Sharing of Personal Data
Your Personal Data will be accessible to certain authorized Litmus7’ employees in internal functions such as marketing, sales, human resources, finance, project delivery units, etc.as on case-to-case basis, depending upon the purpose for which information was shared. We do not sell your Personal Data.
    We do not share your Personal Data with anyone outside of Litmus7, except with the following trusted third parties:
  • Third-party vendors who assist with IT hosting, payment processing, background checks, HR shared services, payroll processing, security, and analytics;
  • Within affiliates and subsidiaries globally for centralized administrative purposes;
  • To comply with law enforcement, regulatory bodies, or valid legal processes (e.g., subpoenas). To the extent required by relevant, applicable law or regulation, we may be obligated to disclose Personal Data to government authorities, or to third parties pursuant to a subpoena or other legal process such information may be disclosed to; and
  • In the event we undergo a business transition involving another company, such as a merger, corporate reorganization, acquisition, the sale of all or a portion of our assets, or in the event of bankruptcy, information that we have collected from or about you may be disclosed to such other entities as part of the due diligence or business integration process and will be transferred to such entity as one of the transferred assets. For internationally based employees, the Personal Data disclosed will vary based on local labour laws.
  • We may share Personal Data with your consent or at your request.
    We do not sell your Personal Data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA.
    We can anonymize or aggregate any of the information we collect and use it for any purpose, including for research and product-development purposes. Such information will not identify you individually.
Your Rights
    Depending on your jurisdiction and subject to applicable limitations and verification requirements, you may have rights to:
  • Access your data;
  • Right to know;
  • Correct inaccurate/incomplete data;
  • Delete Personal Data;
  • Restrict processing;
  • Data portability;
  • Object to processing;
  • Withdraw consent;
  • Limit the use and disclosure of sensitive Personal Data where applicable, including for California residents where the CCPA/CPRA applies;
  • Right to non-discrimination and non-retaliation;
  • Opt out of the sale or sharing of Personal Data, cross-context behavioural advertising, targeted advertising, profiling, or direct marketing where such rights are provided by applicable law; or
  • Appeal or complain to the relevant supervisory authority, regulator, data protection authority, or competent authority where permitted by applicable law.
  • You may exercise your rights by contacting us using the details in the “Contact Us” section. We may need to verify your identity and may request additional information to process your request. We will respond within the period required by applicable law.
    Please note that withdrawing your consent or requesting erasure will not affect the lawfulness of processing carried out prior to your request, nor will it require the deletion of data that we are legally obligated or permitted to retain for lawful purposes, regulatory compliance, or the defense of legal claims.
Data Retention
We retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When no longer required, data is securely deleted, anonymized, or destroyed.
Cookies
A cookie is a piece of data that a website can send to your browser, which may then be stored on your computer as a tag that identifies your computer. While cookies are often only used to measure website usage and effectiveness and to allow for ease of navigation or use and as such, are not associated with any Personal Data, they are also used at times to personalise a known visitor's experience to a website by being associated with profile information or user preferences.
To know more about cookies used by Litmus7, please visit our Cookie Policy.
Links to third party websites
The Website may contain links to external applications, plug-ins, or websites operated by third parties. Please note that Litmus7 does not own, control, or assume responsibility for the privacy practices, security measures, or tracking mechanisms utilized by these external entities.
Your interactions with any third-party services, including their use of cookies and tracking pixels, are governed strictly by their respective privacy policies rather than this Privacy Notice. We strongly encourage you to exercise caution and thoroughly review the privacy notices of any outside websites or applications you visit.
Children
We do not collect and process the personal data of children under the relevant minimum age under applicable local legal requirements except for specific services and upon the consent of the holder of parental responsibility.
International Transfer
We may transfer your Personal Data to Litmus7 group entities, service providers, vendors, professional advisers, or other authorised recipients located outside your country or region of residence, including jurisdictions that may not provide the same level of data protection as your home jurisdiction.
Where required by applicable law, we rely on appropriate safeguards or transfer mechanisms, which may include adequacy decisions, standard contractual clauses, data transfer agreements, intra-group transfer arrangements, consent, contractual necessity, security assessments, certification mechanisms, regulatory filings, or other legally recognised transfer mechanisms.
For transfers from China, Japan, Singapore, Australia, the United Kingdom, the European Economic Area, the UAE, India, California or other applicable jurisdictions, we will apply the relevant local requirements, including any required notice, consent, transfer impact assessment, comparable protection assessment, contractual protection, regulatory filing, or security assessment.
Security
We implement and maintain robust technical, organizational, and physical security measures designed to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure. Our commitment to data privacy is embedded in our corporate culture. All employees undergo mandatory, periodic data protection and cybersecurity training aligned with global compliance requirements. We practice strict data minimization, ensuring we only collect and retain data that is necessary for specified business purposes. Furthermore, we subject all third-party vendors, suppliers, and cross-border partners to rigorous privacy and security risk assessments.
Notification of a Personal Data Breach
In the event of a Personal Data breach, we will assess the incident and notify affected individuals, regulators, supervisory authorities, or competent authorities where required by applicable law and within the timelines prescribed by such law. This may include notification to the Data Protection Board of India, the UK Information Commissioner's Office, relevant US state authorities or affected individuals, the Australian Information Commissioner, Singapore's Personal Data Protection Commission, China's competent authorities, Japan's Personal Information Protection Commission, the UAE Data Office, or other applicable authorities, depending on the facts of the incident and the jurisdictions involved.
Grievance Redressal (Applicable in India)
Mr. Jacob P. Thampy will be responsible for addressing any complaints or grievances related to the Personal Data shared with Litmus7. The contact details of the designated grievance officer are provided below:
Attention: Mr. Jacob P. Thampy
Email ID: jacob@litmus7.com
Contact Number: +91 - 9048652717
Address: #1501, 15th Floor, Lulu Cyber Tower 2, Infopark SEZ, Infopark P.O, Kakkanad, Ernakulam, Kerala - 682042
Consent and Withdrawal of Consent (Applicable in India)
Where the Digital Personal Data Protection Act, 2023 applies, we process your Personal Data on the basis of your consent or for the "legitimate uses" permitted under Section 7 of the DPDP Act (for example, where you voluntarily provide your Personal Data, for employment purposes, to comply with a legal obligation, or to respond to a medical emergency). Where we rely on your consent, that consent will be free, specifically informed, unconditional and unambiguous, given through clear affirmative action, and limited to the Personal Data necessary for the specified purpose. Before or at the time of seeking consent, we will provide you with an itemized notice describing the Personal Data to be collected and the purpose of processing.
You may withdraw your consent at any time, and we will make the process of withdrawal as easy as it was to give consent. On withdrawal, we will cease processing your Personal Data within a reasonable time unless we are permitted or required by law to continue. The consequences of withdrawal will be borne by you, and withdrawal will not affect the lawfulness of processing carried out before the withdrawal. This Privacy Notice is available in English and, on request, in any language specified in the Eighth Schedule to the Constitution of India.
Processing of Children's Personal Data (Applicable in India)
For Data Principals in India, a "child" means a person who has not completed eighteen (18) years of age. We will not process a child's Personal Data without obtaining verifiable consent from a parent or lawful guardian. We will not undertake any processing of a child's Personal Data that is likely to cause a detrimental effect on the well-being of the child, nor will we carry out tracking, behavioral monitoring, or targeted advertising directed at children. The same protections apply to persons with a disability who have a lawful guardian.
Additional Rights of Data Principals under the Digital Personal Data Protection Act, 2023 (Applicable in India)
If you are a Data Principal in India, you have, in addition to the rights described above: (a) the right to obtain a summary of the Personal Data we process and the processing activities undertaken; (b) the right to correction, completion, updating and erasure of your Personal Data; (c) the right to readily-available grievance redressal; and (d) the right to nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity. Where we no longer need your Personal Data for the specified purpose, and retention is not required by law, we will erase it and cause our Data Processors to do the same. You may also lodge a complaint with the Data Protection Board of India, ordinarily after exhausting our grievance redressal mechanism.
Data Protection Officer/Significant Data Fiduciary
If Litmus7 is notified by the Central Government as a Significant Data Fiduciary under the DPDP Act, we will appoint a Data Protection Officer based in India who will be responsible for answering questions about the processing of your Personal Data and who will report to our Board or equivalent governing body.
Where required by other applicable laws, we will also appoint, designate, or make available appropriate privacy contacts, representatives, or responsible persons, such as a Data Protection Officer, UK or EU representative, Singapore Data Protection Officer, China personal information protection representative or contact, or other privacy contact required by applicable law.
Additional United Kingdom, Australia, Singapore, China, Japan, UAE, United States and California Provisions
We monitor the countries from which we collect Personal Data and ensure that the local applicable data protection laws are complied with. For Illustration:
  • If the UK GDPR or similar privacy laws apply, we provide information about our identity, contact details, processing purposes, lawful bases, categories of Personal Data, recipients, international transfers, retention, individual rights, complaint rights, and whether providing Personal Data is statutory, contractual, or necessary for a requested service.
  • If Australian law applies, we will handle Personal Data in accordance with the Australian Privacy Principles, including requirements relating to collection notices, cross-border disclosure, access, correction, security, and complaints.
  • If Singapore law applies, we will comply with the PDPA obligations relating to notification, consent, purpose limitation, accuracy, protection, retention, transfer limitation, access and correction, breach notification, and accountability.
  • If China's PIPL applies, we will provide required notices, obtain separate consent where required, conduct personal information protection impact assessments where applicable, apply stricter safeguards for sensitive personal information, and use lawful mechanisms for cross-border transfers.
  • If Japan's APPI applies, we will specify purposes of use, manage third-party disclosures and joint use as required, respond to access, correction, suspension and deletion requests, and apply applicable cross-border transfer requirements.
  • If UAE law applies, we will process Personal Data in accordance with lawful grounds, transparency, data subject rights, security, retention, breach notification and cross-border transfer requirements.
  • If United States state privacy laws, including California law, apply, you may have rights to know, access, correct, delete, opt out of sale or sharing, limit use and disclosure of sensitive Personal Information, and not be discriminated against for exercising your rights.
Contact Us
In case of any clarifications or any comments, you may have on this Privacy Notice, you may reach out to legal@litmus7.com
Amendments
We may amend, modify, or update this Privacy Notice at our sole discretion whenever necessary. The latest published version will always take precedence over any prior version. We will not reduce your rights under this Privacy Notice without your explicit consent. To remain informed, we encourage you to review this Privacy Notice periodically for updates.