Privacy Policy

This policy explains what personal data Digital Factory collects, why we collect it, how we use it, and the rights available to you under Indian law — principally the Digital Personal Data Protection Act, 2023.

Effective date: [DATE — fill in before publishing]

Last updated: [DATE — fill in before publishing]

On this page

Section 1

Acceptance of terms

Firm name: [LEGAL PARTNERSHIP NAME — fill in]
Reg. no: [PARTNERSHIP REGISTRATION NUMBER — fill in]
GSTIN: [GSTIN — fill in]
Office: [FULL ADDRESS], Puducherry, India
Website: digitalfactoryindia.com

This Privacy Policy explains what personal data we collect from you, why we collect it, how we use it, and the rights available to you under Indian law — principally the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the rules made under it.

Under the DPDP Act, Digital Factory acts as a Data Fiduciary in relation to the personal data of our clients and website visitors (Data Principals).

By using our website, purchasing a package (Launch, Grow, or Scale), submitting our project intake form, or otherwise interacting with us, you agree to the practices described in this Policy.

Section 2

Information we collect

We collect only what is reasonably necessary to deliver our services. Depending on how you interact with us, this includes:

a) Information you give us directly
b) Information collected automatically
c) Information from payments

We do not collect or store your card, UPI, or net-banking details. Payments are processed by Razorpay, a licensed payment aggregator, which handles and secures this information directly. We receive confirmation of payment and a transaction reference, not your financial credentials.

d) Information from connected third-party accounts

If you choose to link an existing Google Business Profile, Facebook, Instagram, or similar account during onboarding, we access only what is necessary to set up or manage that listing on your behalf, with your authorisation.

We do not knowingly collect sensitive personal data (health records, biometric data, financial account numbers, etc.) beyond what is described above.

Section 3

Why we collect it (purpose)

Section 4

Legal basis for processing

Section 5

Who we share information with

We share personal data only where necessary to deliver our services:

RECIPIENT
PURPOSE
RECIPIENT Razorpay
PURPOSE Payment processing
RECIPIENT Google (Analytics, Search Console, Business Profile, Ads – as applicable to your package)
PURPOSE Setting up and managing your search visibility and listings
RECIPIENT Meta / social platforms
PURPOSE Setting up and managing your social channels, if applicable
RECIPIENT Our hosting and domain infrastructure providers
PURPOSE Hosting your website and registering your domain in your name
RECIPIENT Our internal team and contracted designers/developers
PURPOSE Delivering the actual work you've purchased

We do not share your data with third parties for their own independent marketing purposes. Where a third-party service (like Razorpay or Google) processes your data, their own privacy policy also applies to that processing.

We may disclose information if required by law, court order, or a valid request from a government authority in India.

Section 6

Cookies and tracking

Our website may use cookies and similar technologies to:

Section 7

Data storage and security

We take reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, consistent with the IT (Reasonable Security Practices and Procedures) Rules, 2011.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authorities as required by law.

Section 8

Data retention

We retain your personal data for as long as necessary to:

Section 9

Your rights

Under the DPDP Act, as a Data Principal you have the right to:

Section 10

Children's privacy

Section 11

Grievance officer

In accordance with the Information Technology Act, 2000 and the rules made thereunder, our Grievance Officer is:

Firm name:
Reg. no:
GSTIN:
Office:
Website:

Contact us

For any questions about this Privacy Policy or how we handle your data:

Section 13

Changes to this policy

Section 14

Governing law and jurisdiction