Skip to main content

Privacy Policy

Last updated: 18 May 2026. This Privacy Policy explains how Dcrayons Consultancy Private Limited (India, CIN U74999RJ2016PTC) and its US affiliate Dcrayons Inc (collectively, "Dcrayons", "we", "our", "us") collect, use, share, and protect your personal information when you visit dcrayons.app, fill any of our forms, sign a Statement of Work, or otherwise interact with our services.

We take privacy seriously. We do not sell your personal information. We minimise what we collect, store it under written sub-processor agreements, and respect your rights under India's Digital Personal Data Protection Act 2023 (DPDPA), the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and other applicable privacy laws.

1. Who we are and how to contact us

The data controller for personal data collected through dcrayons.app is Dcrayons Consultancy Private Limited, registered in India. For data subject requests, privacy questions, or complaints, write to info@dcrayons.app with the subject line "Privacy request". We respond within 30 days of a verified request.

For employment-related privacy (job applications, candidate data), write to hr@dcrayons.app.

2. Personal information we collect

We collect personal information in three ways:

2.1 Information you give us directly

  • Identity and contact details: name, email, phone, company, role, country (when you fill a contact, pricing, or proposal form).
  • Business context: brand, budget range, services of interest, brief description of your goals.
  • Communication content: emails, call notes, meeting transcripts, messages exchanged with our team.
  • Engagement data: when you become a client, we hold the Statement of Work, invoices, deliverables, account credentials, and other records required to deliver the agreed services.
  • Candidate data: for job applications, your CV, work history, references, and interview notes (handled by hr@dcrayons.app).

2.2 Information collected automatically

  • Device and browser: IP address, browser type and version, operating system, screen size, language.
  • Usage: pages viewed, referring URL, session duration, clicks on links and buttons (aggregated and anonymised where possible).
  • Cookies and similar technologies: details in our Cookie Policy. Marketing and analytics cookies are loaded only after you give consent.

2.3 Information from third parties

We may receive enrichment data (company size, industry, public LinkedIn profile) from B2B data providers to qualify leads. We also receive data from payment processors when you pay an invoice, from email-delivery vendors when you open a tracked email, and from advertising platforms when you arrive via a paid campaign.

3. Why we use your information (legal bases)

We process personal data only when at least one of the following legal bases applies:

  • Consent: when you opt in to marketing emails, accept marketing cookies, or submit a contact form (you can withdraw consent at any time).
  • Contract: when we need data to deliver services you have engaged us for or to negotiate a new engagement.
  • Legitimate interests: site security, fraud prevention, B2B prospecting where the contact is acting in a professional capacity, service improvement, and aggregated analytics. We balance these against your rights and stop on objection.
  • Legal obligation: tax, accounting, and audit requirements under Indian and US law, and any other statute that compels disclosure.

4. Who we share information with

We do not sell personal information. We share it only with the following categories of recipients, each bound by a written data-processing or confidentiality agreement:

  • Sub-processors: hosting (AWS Mumbai + Singapore), email delivery (SendGrid / Postmark / SES), analytics (Google Analytics 4 with IP-anonymisation, server-side GTM), error monitoring, customer-relationship management (in-house CRM), document signing (SignDesk), and payment processing (Razorpay / Stripe). A current list is available on request.
  • Service partners: when a project requires it, we may share narrowly-scoped data with a specialist agency partner under NDA + DPA.
  • Professional advisors: lawyers, accountants, auditors, and insurers under professional confidentiality.
  • Law enforcement: only where compelled by valid legal process, and only the data specifically required.
  • Buyer in a corporate transaction: in the event of a merger, acquisition, or asset sale, your data may transfer to the buyer subject to this same Privacy Policy.

5. Where we store your data

Primary storage is in AWS data centres in Mumbai (ap-south-1) and Singapore (ap-southeast-1). Backups are encrypted at rest and replicated cross-region. Cloudflare provides edge caching of public pages globally.

If you are in the European Economic Area, the United Kingdom, or another jurisdiction outside India, your personal data will be transferred to and stored in India. We rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK IDTA for these transfers, plus the supplementary measures recommended by the European Data Protection Board.

6. How long we keep your data (retention)

  • Contact-form leads that do not convert: 24 months from last interaction, then deleted.
  • Marketing subscribers: until you unsubscribe; we keep a hashed record of unsubscribe to honour future emails.
  • Client records (engagement files, invoices): 7 years after engagement ends (Indian Income-Tax + Companies Act retention requirement).
  • Job applications that do not lead to hire: 12 months, then deleted unless you have given consent for talent-pool retention.
  • Server logs and aggregated analytics: 13 months, then deleted or fully anonymised.

7. Your rights

Subject to local law, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete information.
  • Delete your data ("right to be forgotten"), subject to legal retention obligations.
  • Restrict processing while a dispute is being investigated.
  • Port your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including any direct marketing.
  • Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
  • Lodge a complaint with your local supervisory authority (e.g. India Data Protection Board, UK ICO, your EU member state DPA, California Attorney General).

To exercise any right, email info@dcrayons.app with the subject "Data subject request" and enough information for us to verify your identity. There is no fee, and we respond within 30 days.

8. Security

We apply technical and organisational measures to protect personal data: TLS 1.2+ for all transport, encryption at rest for production databases, role-based access control with least-privilege defaults, mandatory two-factor authentication for staff, quarterly access reviews, annual penetration testing, and an incident-response runbook with notification commitments under GDPR Article 33 and DPDPA Section 8(6). No system is perfect; we keep improving.

9. Children's privacy

Dcrayons services are aimed at businesses and adults. We do not knowingly collect personal data from children under 18. If you believe we have collected such data, contact info@dcrayons.app and we will delete it promptly.

10. California residents (CCPA / CPRA)

If you are a California resident, you have the rights described in section 7 above plus the right to know what categories of personal information have been sold or shared in the preceding 12 months. Dcrayons does NOT sell personal information and does NOT share it for cross-context behavioural advertising in the CCPA sense. To exercise California rights, email info@dcrayons.app.

11. Changes to this policy

We update this Privacy Policy when our practices change. The "Last updated" date at the top reflects the most recent revision. Material changes that affect your rights are announced at least 30 days in advance via email to active subscribers and clients.

12. Contact and complaints

Dcrayons Consultancy Private Limited, India. Email info@dcrayons.app. If you are not satisfied with our response to a privacy request, you may complain to your local supervisory authority.