Effective August 2026. Covers hummingsun.co.in and workspace.hummingsun.co.in. Read alongside our Cookie Policy.
HummingSun™ ("we", "us", "our") provides workplace wellbeing, assessment, capability-building, and related advisory and technology services to organisations. This notice explains what personal data we collect through our website (hummingsun.co.in), our product (workspace.hummingsun.co.in), and our client engagements, and how we handle it.
This notice applies to three categories of people, who receive different treatment below:
3.1 Website visitors: Standard technical data — IP address, browser/device type, pages visited, referring site (via analytics/cookies — see our Cookie Policy).
3.2 Leads and prospects: Name, work email, company name, role, and anything volunteered in a form or chat conversation with the Advisor widget.
3.3 Survey and assessment participants: Responses to wellbeing survey and assessment questions, which may touch on stress, engagement, and psychological wellbeing — treated as sensitive personal data (see Section 6). Basic org-provided identifiers needed to route a participant to the right survey (e.g. employee ID, department, manager) — configurable per client, minimised wherever possible.
Under GDPR (where applicable) we rely on: consent (Art. 6(1)(a)) for survey participation and marketing communications; contract necessity (Art. 6(1)(b)) for delivering the platform to a paying client; and legitimate interest (Art. 6(1)(f)) for basic website analytics and lead follow-up.
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), we rely on consent as the primary basis for processing personal data, and on the "legitimate uses" exceptions in the Act only where they clearly apply (e.g. a voluntarily provided lead form). Consent notices must be in clear, plain language and offered in the same languages the client organisation otherwise operates in — confirm this requirement with counsel before rollout.
Wellbeing survey and assessment responses are treated as sensitive personal data. This is the category most likely to determine whether people trust and honestly participate in a survey, so it needs to be airtight before rollout, not just legally compliant.
We use third-party infrastructure providers to run the platform. As of this draft:
We do not sell personal data. Any additional sub-processor added in future will be listed here and, where required, disclosed to clients under their data processing agreement.
Because our infrastructure may be hosted outside India, transferring personal data of India-based data principals outside India needs to be checked against the DPDP Act's cross-border transfer provisions (the Act permits transfers by default except to countries the government specifically restricts by notification — confirm current status with counsel, as this list can change). If any client or participant is in the EU/UK, GDPR's transfer rules (adequacy decisions, standard contractual clauses) apply separately and need their own review.
To be defined per data category — draft placeholders below, confirm with legal and with actual product needs:
The website uses cookies for basic functionality and, if enabled, analytics. See our full Cookie Policy for details on what we use, why, and how to manage your preferences.
Under the DPDP Act, data principals have the right to access their data, seek correction and erasure, and file grievances. The Act requires companies above certain thresholds to appoint a Grievance Officer and publish their contact details; even where not strictly mandatory at your current size, publishing a named contact builds trust with enterprise clients evaluating you. Under GDPR, data subjects additionally have rights to data portability and to object to processing.
Describe actual measures once confirmed with engineering — e.g. encryption in transit and at rest, access controls, least-privilege database roles, audit logging. Do not publish specific security architecture details publicly; a general statement of commitment is standard, with detail available under NDA to enterprise clients during procurement.
Our services are intended for use by working adults in an employment context and are not directed at children. We do not knowingly collect data from anyone under 18.
We will update this notice as the product and our legal obligations evolve, and will note the effective date at the top of the page.
HummingSun™, 1159, Palam Vihar, Gurgaon 122017, India · info@hummingsun.co.in · +91 6006743501
Short-form notice shown to a participant before they begin a wellbeing survey or assessment. Intentionally plain-language, since this is read by employees, not lawyers.
Where this lives: this is not a public web page. It's an interstitial screen inside HummingSun™ Workspace itself — shown to a survey participant at the moment they click to start a survey or assessment, before any question appears. It's flagged here as the approved copy so engineering can build it as a consent step in the product flow, with a "Start" button that only proceeds after this notice is shown.
HummingSun is a workplace wellbeing enabler — a SaaS platform with Wellbeing and Assessment modules, backed by 17+ years of certified advisory expertise, built to help organisations sustain wellbeing on their own over time.
The Wellbeing module runs continuous pulse checks and surfaces root-cause hazards. The Assessment module handles evaluation and promotion-readiness scoring. Both run on the same platform.
Not self-serve, no — access is invitation-only. We configure each organisation's workspace individually. Book a demo and we'll set you up.
Use the "Book a Demo" button anywhere on the site, or leave your number below and we'll reach out directly.
Pricing depends on your organisation's size and which modules you need. Book a demo and we'll walk you through options that fit.
Most organisations are up and running within a few weeks of kickoff, depending on scope.
Yes. Every assessment is confidential and reported at the individual level — nothing is shared across organisations. See our Privacy Policy for details.
Yes — ISO 9001:2015 certified (renewal in progress) and IAS | IAF accredited.
We work across sizes — from mid-size teams to large enterprises. Tell us your size on a call and we'll scope accordingly.
Gurgaon, India — we work with organisations across India (and beyond) remotely.
Totally fine. Leave your number below, or WhatsApp / email us directly — no obligation.
Our team typically responds Mon–Fri, 9am–5pm IST, and gets back to every message within 24 hours.
Leave your number and a quick note — our team will get back to you within 24 hours.