Privacy Policy

Effective date: August 1, 2026 · Last updated: July 27, 2026

1. Who This Policy Covers

This Privacy Policy is issued by Burdenoff Consultancy Services Pvt. Ltd. (operating as Algoshred Technologies Private Limited for some properties), the data controller for personal data collected through burdenoff.com, Burdenoff Workspaces (app.burdenoff.com), the shared platform layer (identity, billing, notifications, marketplace, and administration) that underlies every Burdenoff product, and any Burdenoff product website that links to this policy. Some Burdenoff products publish a product-specific privacy addendum describing data flows unique to that product; where one exists, it supplements (and does not replace) this policy.

If your organization has a separately signed Data Processing Agreement ("DPA") with Burdenoff, that agreement governs Burdenoff's processing of personal data you submit to the Service as a data processor, and this policy describes our practices as a controller for account, billing, and platform-operations data. See burdenoff.com/dpa to request a DPA.

2. Personal Data We Collect and Why

We collect the following categories of personal data:

CategoryDataPurposeRetention
Identity & accountName, email, phone, password hash, MFA secrets (encrypted at rest)Authentication and account securityLife of account, plus any applicable legal hold
Tenant / organizationWorkspace/tenant name, member list, rolesMulti-tenant isolation and access controlLife of account
BillingPayment method tokens (processors hold full card data; we do not), invoices, tax informationBilling, subscription management, tax complianceDuration required by applicable tax/financial-record law
NotificationsEmail, phone number, device tokensTransactional messages always; marketing messages only with consentUntil you withdraw consent or close your account
Activity & audit logsActor, action, resource, timestamp, metadataSecurity, fraud prevention, compliance, and dispute forensics7 years, immutable (no admin-triggered early deletion)
Developer / publisherApp metadata, OAuth client IDs, webhook configs, payout details (encrypted)Operating the developer portal and app marketplaceLife of the developer account or listing
AI-assisted featuresPrompts and content you submit to an AI-assisted feature, where enabled for your planGenerating the requested output. We do not use your Customer Data to train generative models for the benefit of other customers unless you opt inPer the feature's documented retention, or account life

We also collect limited technical data automatically (IP address, browser/device type, pages visited) via cookies and similar technologies — see our Cookie Policy.

3. Legal Basis for Processing

Depending on your location, we rely on one or more of the following legal bases:

  • Contractual necessity (GDPR Art. 6(1)(b)) — to create your account, deliver the Service, and process billing.
  • Legitimate interests (GDPR Art. 6(1)(f)) — for security monitoring, audit logging, fraud prevention, and product improvement, balanced against your rights.
  • Consent (GDPR Art. 6(1)(a)) — for marketing communications and non-essential cookies, which you may withdraw at any time.
  • Legal obligation (GDPR Art. 6(1)(c)) — for tax, accounting, and law-enforcement requests.

For users in India, we process personal data consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act), including notice-and-consent for processing that is not otherwise permitted without consent. For California residents, see Section 8 (California Privacy Rights) below for CCPA/CPRA-specific disclosures.

4. How We Share Data & Subprocessors

We do not sell personal data. We share personal data only with: (a) subprocessors who process it on our behalf under a data-processing agreement, strictly to provide the Service (cloud hosting, payment processing, email/SMS delivery, error monitoring, and — where a product enables an AI-assisted feature — the underlying AI model provider); (b) your workspace administrators, to the extent your workspace configuration shares data with them; (c) a successor entity in a merger, acquisition, or asset sale, subject to this policy; and (d) law enforcement or regulators where required by law. The current authoritative list of subprocessors, their purpose, and processing region is published at burdenoff.com/subprocessors.

5. International Data Transfers

Our primary processing region is Central India (Microsoft Azure centralindia), with static assets and some subprocessors operating in other regions (including the United States and the European Union) as disclosed at burdenoff.com/subprocessors. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (or an equivalent recognized transfer mechanism) with the receiving party. Enterprise customers may request dedicated single-region tenancy by contract — see burdenoff.com/dpa.

6. Data Retention

We retain personal data only for as long as needed for the purposes in Section 2, or as required by law. Account and tenant data is retained for the life of your account; billing records are retained for the period required by applicable tax and financial record-keeping law; activity/audit logs are retained for a mandatory 7-year period and cannot be deleted early by an administrator, including us, to preserve an accurate forensic and compliance record. When you close your account, we delete or anonymize personal data that is not subject to a longer legal-retention or audit-log requirement, on the schedule described in Section 7.

7. Your Privacy Rights

Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, DPDP Act 2023, and similar regimes), you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure ("right to be forgotten"); request a portable copy of data you provided us; object to or restrict certain processing; and withdraw consent at any time without affecting processing that already occurred.

How to exercise these rights. Email privacy@burdenoff.com with the subject line "Data Subject Access Request," your registered account email, and the specific right you are exercising. We verify your identity before acting on a request and respond within 30 days (or the shorter period required by applicable law). Export and erasure requests are currently fulfilled by our support and platform operations team rather than a fully self-service in-product control; we are building toward an in-account self-service data request flow and will update this policy when it ships. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

8. California Privacy Rights (CCPA/CPRA)

California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined by the CCPA), and to non-discrimination for exercising these rights. Submit a request via privacy@burdenoff.com.

9. Children's Privacy

The Service is not directed to children under 13, and use by anyone under the age of majority requires the involvement and consent of a parent or legal guardian, consistent with Section 3 of our Terms of Service. We do not knowingly collect personal data from children under 13; if we learn that we have, we will delete it.

10. Cookies and Security

Details on the cookies and similar tracking technologies we use are in our Cookie Policy. Details on the technical and organizational security measures we use to protect personal data are in our Security Policy. If you believe you have found a security vulnerability, report it to security@burdenoff.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide at least 30 days' notice before the change takes effect, by posting the updated policy on this page with a new "Last updated" date and, where you have an account, by email or in-product notice.

12. Contact Us / DPO

For any question about this Privacy Policy or to exercise a privacy right, contact our privacy team:

Burdenoff Consultancy Services Pvt. Ltd.
Privacy / data protection: privacy@burdenoff.com
General: contact@burdenoff.com
Security: security@burdenoff.com
Phone: +91-7358445777
Address: Plot No.43, Veeramani Nagar, 2nd Cross Street, Nanmangalam, Chennai - 600117, Tamil Nadu, India

Effective date: August 1, 2026 · Last updated: July 27, 2026

Burdenoff LogoBurdenoff

Building tomorrow's products today through innovation, expertise, and dedication.

Contact

Stay Updated

Subscribe to our newsletter for the latest updates

Copyright © 2025 Burdenoff Consultancy Services Private Limited. All rights reserved.