How we collect, use and protect personal data when you visit pcplusa.com or get in touch with us — written to be read, not to be survived.
Prestanda Consulting ("Prestanda", "we", "us") is an enterprise technology consulting and software development firm. We operate the website at pcplusa.com.
For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as a Data Fiduciary. For the purposes of the EU General Data Protection Regulation ("GDPR") we act as a data controller in respect of this website, and as a data processor in respect of client data we handle while delivering services under a separate agreement.
This policy covers this website only. Personal data we process on behalf of clients during an engagement is governed by the contract and data processing terms agreed with that client, not by this page.
When you submit our contact form we collect your name, email address, optional phone number, and the content of your message. You choose what to put in that message — please don't include sensitive personal information, credentials, or confidential client material in an initial enquiry.
When you browse the site we collect, subject to your cookie choices:
We do not collect special category or sensitive personal data through this website, we do not use this website for automated decision-making that produces legal effects, and we do not sell personal data to anyone.
| Purpose | Legal basis (GDPR) | Basis (DPDP Act) |
|---|---|---|
| Responding to your enquiry and providing a proposal | Steps prior to entering a contract, and legitimate interests | Consent, given by submitting the form |
| Understanding which pages and content are useful, so we can improve them | Consent | Consent |
| Understanding which channels bring us relevant enquiries | Consent | Consent |
| Keeping the site secure, available and free of errors | Legitimate interests | Legitimate use — maintaining service integrity |
| Meeting legal, tax and regulatory obligations | Legal obligation | Legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we limit collection to what is needed for the stated purpose.
A cookie is a small text file stored by your browser. We use them for three purposes only: making the site work, understanding how it is used, and understanding which channels bring us enquiries.
These are required for the site to function and to remember the cookie choice you made. They cannot be switched off.
| Cookie | Purpose | Retention |
|---|---|---|
pc_consent | Remembers your cookie preferences | 1 year |
pc_ses | Identifies a single browsing session | 1 day |
Set only if you accept them. They tell us which pages are read, where people get stuck, and what to fix.
| Cookie | Set by | Purpose | Retention |
|---|---|---|---|
pc_vid | Prestanda | Anonymous visitor identifier | 2 years |
pc_attr | Prestanda | Records how you first found us | 90 days |
_ga, _ga_* | Google Analytics 4 | Distinguishes visitors, measures usage | Up to 2 years |
_clck, _clsk | Microsoft Clarity | Session recordings and heatmaps | 1 year / 1 day |
We do not currently run advertising cookies on this site. The category exists in our consent banner so that, if we ever do, it will be off until you turn it on.
Microsoft Clarity records anonymised playback of site visits — mouse movement, clicks and scrolling. Text you type into forms is masked by default and is not captured in recordings. Recordings are used to find usability problems, never to identify individuals.
The first time you visit, a banner asks how you would like to be tracked. You can accept all, reject everything non-essential, or choose category by category. Nothing optional is loaded until you decide.
If you are in the European Economic Area, the United Kingdom or Switzerland, analytics and marketing storage default to denied until you actively grant it. Elsewhere, analytics defaults to enabled and marketing remains off — and you can decline at any time.
Use the Cookie settings link in the footer of any page. Withdrawing consent is as easy as giving it, and takes effect immediately. You can also clear cookies in your browser settings, or use Google's Analytics opt-out add-on.
We share personal data only with service providers who help us run this website and respond to you. Each is bound by contract to process data only on our instructions. We do not sell personal data, and we do not share it with advertising networks.
| Provider | What they do | Where |
|---|---|---|
| Google (Analytics 4) | Website usage measurement | USA / global |
| Microsoft (Clarity) | Session recordings and heatmaps | USA |
| Functional Software, Inc. (Sentry) | Technical error monitoring | USA |
| Formspree, Inc. | Delivers contact form submissions to us | USA |
| Netlify, Inc. | Website hosting and content delivery | Global CDN |
Where you have accepted analytics cookies, an identifier may be shared between Google Analytics and Microsoft Clarity so that a recorded session can be matched to usage data. This is used solely for product improvement.
We may also disclose personal data where required by law, court order or a valid request from a public authority, or to establish, exercise or defend legal claims.
We operate from India and the United States and serve clients worldwide, so personal data may be transferred outside your country of residence — including to the United States and to India.
For transfers of personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, together with supplementary technical measures such as encryption in transit and at rest.
Under the DPDP Act, personal data may be transferred outside India except to territories restricted by the Central Government. We monitor that list and will update our arrangements if it changes.
| Data | Retention period |
|---|---|
| Contact form enquiries that do not become engagements | 24 months from last contact |
| Enquiries that become client engagements | Per the engagement contract, then per statutory record-keeping requirements |
| Google Analytics data | 14 months |
| Microsoft Clarity recordings | Up to 13 months |
| Sentry error reports | 90 days |
| Cookie consent record | 1 year, then you will be asked again |
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer be linked to you.
We hold ISO/IEC 27001:2022 certification for information security management and are appraised at CMMI Level 3. Both are independently audited, not self-declared.
If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act and its Rules, and the relevant supervisory authority within 72 hours where the GDPR applies.
Depending on where you live, you have some or all of the following rights.
To exercise any of these, email sales@pcplusa.com. We will respond within 30 days. We may ask you to verify your identity before acting, so that we do not disclose your data to someone else.
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. Consistent with our providers' terms, our session-recording tool is not used on services targeting children. If you believe a child has provided us personal data, contact us and we will delete it.
We update this policy when our practices or the law change. The date at the top shows when it was last revised. If we make a material change to how we use personal data, we will reset the cookie banner so you can review your choices, and where required we will seek fresh consent.
For any question about this policy, or to exercise your rights or raise a grievance, contact our Grievance Officer:
Email:
sales@pcplusa.com
Phone: +91 88001 99207
Post: Third Floor, A 119, Gali Number 7, Vinod Nagar West,
Delhi, India
We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to your local data protection supervisory authority if you are in the EEA or UK.