Legal
Privacy Policy
Last updated: 8 August 2026
This policy explains what personal data Brandsmyth collects when you visit brandsmyth.in or engage us for marketing or software work, why we collect it, who we share it with, and the rights you have over it. It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Who we are
Brandsmyth is a digital marketing, software development and technology consulting business based in Thrissur, Kerala, India. For the purposes of the DPDP Act we are the Data Fiduciary for the personal data described here.
- Trading name: Brandsmyth
- Address: IIIʳᵈ Floor, Abhcon Axis, near Galilee Retreat Centre, Nehru Nagar, Chiyyaram, Thrissur, Kerala 680026, India
- Email: brandsmythdigital@gmail.com
- Phone: +91 80898 97266
2. What we collect
Data you give us
- Contact details — your name, phone number, email address, company name and anything else you choose to write when you message us on WhatsApp or email us.
- Engagement data — during a paid engagement, the business information you share with us: billing details, campaign goals, product and pricing information, and creative assets.
- Advertising account access — where you grant it, delegated access to your Meta Business Manager, Google Ads, Google Analytics, Search Console or similar accounts. We do not copy or export the personal data of your own customers out of those platforms.
Data collected automatically
- Server and CDN logs — IP address, user agent, requested URL, referrer and timestamp, recorded by our hosting provider for security and troubleshooting.
- Analytics — if analytics is enabled on this site, Google Analytics 4 records pages viewed, approximate location derived from a truncated IP, device type, and referral source, using cookies or similar identifiers. We have IP anonymisation enabled and we do not use Google Signals or advertising personalisation features on this site.
What we do not collect
This site has no login, no shopping cart and no payment form. We do not collect passwords, card numbers, Aadhaar or PAN details through this website, and we never ask for the login password to your advertising accounts — delegated access is granted through the platform's own permission system.
3. Why we use it
- To reply to your enquiry and prepare the free growth audit you asked for.
- To deliver, invoice and support the services you engage us for.
- To keep the site secure, diagnose faults and understand which pages are useful.
- To meet accounting, tax and other legal obligations.
Under the DPDP Act we rely on your consent — given when you choose to contact us or accept analytics — and on legitimate uses such as fulfilling a service you have requested and complying with law. We do not sell personal data, and we do not use your contact details for unrelated marketing without asking you first.
4. WhatsApp
The primary contact route on this site is a WhatsApp link. Clicking it opens WhatsApp with a pre-filled message; nothing is sent until you press send. Once you message us, the conversation — including your phone number and WhatsApp profile name — is processed by WhatsApp under Meta's own privacy policy, which we do not control. We retain the conversation in our business WhatsApp account as a record of the enquiry.
5. Who we share it with
We share personal data only with processors that help us run the business, and only as far as needed:
- Hosting and CDN provider — serves this website and keeps access logs.
- Google LLC — Analytics, Google Ads and Search Console.
- Meta Platforms — WhatsApp Business and advertising platforms.
- Accounting and payment providers — for invoicing clients.
Some of these providers store data on servers outside India. We disclose personal data to a government agency only where required by law.
6. Data we handle for clients
When we run campaigns, install tracking or build systems for a client, we may come into contact with the personal data of that client's own customers and leads — form submissions, lead lists, CRM records, analytics identifiers. For that data the client is the Data Fiduciary and we act as a Data Processor on their written instructions.
- We use it only to deliver the agreed work — never for our own marketing, and never sold or shared onward.
- We do not export the personal data of a client's customers out of the advertising or analytics platforms except where the engagement specifically requires it.
- On the end of an engagement we return or delete such data at the client's instruction, subject to the retention periods below.
- Where we install tracking, tag managers or pixels on a client's property, the client is responsible for their own privacy notice and for collecting valid consent from their visitors.
If you are the customer of one of our clients and want your data corrected or erased, contact that business directly — they control it. Write to us and we will pass the request on.
7. How long we keep it
- Enquiries that do not become clients: up to 24 months, then deleted.
- Client records: for the engagement plus 8 years, as required for tax and accounting records in India.
- Server logs: typically 30–90 days, per our hosting provider's retention.
- Analytics data: 14 months in Google Analytics 4.
8. Security
The site is served over HTTPS. Access to client advertising accounts, our email and our WhatsApp Business account is restricted to the team members who need it and protected with two-factor authentication. No system is perfectly secure; if a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.
9. Your rights
As a Data Principal under the DPDP Act you may ask us to:
- confirm what personal data of yours we hold and how it is processed;
- correct or complete inaccurate data;
- erase data we no longer need for the purpose it was collected for;
- withdraw consent you previously gave — this does not affect processing already carried out;
- nominate another person to exercise these rights if you die or become incapacitated.
Email brandsmythdigital@gmail.com and we will respond within 30 days. If you are not satisfied with our response you may complain to the Data Protection Board of India.
Grievance Officer
Name: TODO — name · Designation: Grievance Officer, Brandsmyth · Email: brandsmythdigital@gmail.com · Phone: +91 80898 97266
Write to the Grievance Officer at IIIʳᵈ Floor, Abhcon Axis, near Galilee Retreat Centre, Nehru Nagar, Chiyyaram, Thrissur, Kerala 680026, India. Grievances are acknowledged within 48 hours and resolved within 30 days.
10. Cookies
This site sets no cookies of its own. If analytics is enabled, Google Analytics 4 sets a first-party cookie to distinguish one visit from another. You can block or delete it in your browser settings, or install Google's opt-out add-on, without losing access to any part of this site.
11. Children
Our services are sold to businesses and this site is not directed at children. We do not knowingly collect the personal data of anyone under 18. If you believe a child has sent us personal data, email us and we will delete it.
12. Changes
We may update this policy as our services or the law change. The revision date at the top always reflects the current version. Material changes affecting how we use data you already gave us will be communicated directly where we hold your contact details.
13. Contact
Questions about this policy: brandsmythdigital@gmail.com or +91 80898 97266. By post: Brandsmyth, IIIʳᵈ Floor, Abhcon Axis, near Galilee Retreat Centre, Nehru Nagar, Chiyyaram, Thrissur, Kerala 680026, India.