Privacy Policy — Vaahan Creative

Legal

Privacy Policy.

This policy explains what personal data Vaahan Creative collects, why we collect it, and the rights you have over it under Indian law.

Last updated: July 2026 · Applies to vaahancreative.io and related Vaahan Creative services


Plain-language summary: we collect the personal data you give us directly (like your name, email, or phone number when you book a call or contact us), we use it to run our agency and communicate with you, we don’t sell it, and you can ask us to access, correct, or delete it at any time by writing to the email address at the bottom of this page.

1. Who This Policy Covers

This Privacy Policy applies to anyone who visits vaahancreative.io, contacts us through the website, books a call with us, or otherwise shares personal data with Vaahan Creative (“we,” “us,” “our”), a marketing agency headquartered in Bengaluru, Karnataka, India. It is written in line with the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 notified under it, which together form India’s principal data protection law. Under this framework, Vaahan Creative acts as a Data Fiduciary and you, as the individual whose data we process, are a Data Principal.

If you engage us as a client, a separate services agreement or statement of work will govern any personal data of your own customers or contacts that we process on your behalf as part of a campaign — this policy covers our website and our direct relationship with you, not that separate client-data processing arrangement.

2. What Personal Data We Collect

We collect personal data in a few limited ways:

Data you give us directly

  • Name, email address, and phone number, when you contact us, book a pilot call, or sign up for updates
  • Company name, job title, and details about your business, when discussing a potential project
  • Any other information you choose to share with us in emails, forms, or calls

Data collected automatically

  • Basic technical data such as IP address, browser type, device type, and pages visited, collected through standard website analytics
  • Cookies and similar technologies, as described in Section 9

We do not knowingly collect sensitive personal data (such as financial information, health data, or biometric data) through our website unless you choose to share it with us directly, for example as part of a project brief.

3. How We Use Your Data

We use personal data only for purposes that are clear, limited, and directly connected to why you shared it with us, consistent with the DPDPA’s requirement that data be processed only for the specific purpose it was collected for. Specifically, we use your data to:

  • Respond to enquiries and book calls or meetings
  • Provide, manage, and improve our services to clients
  • Send updates, proposals, or information you’ve asked for
  • Understand how our website is used, so we can improve it
  • Meet legal, accounting, or regulatory obligations

We do not use your personal data for any purpose beyond what you’d reasonably expect from the context in which you shared it, and we do not sell personal data to third parties.

4. Our Legal Basis for Processing

Under the DPDPA, we process your personal data on the basis of:

  • Consent — for most interactions, such as when you submit a contact form or book a call, your act of sharing that data and engaging with us constitutes consent for us to use it for the stated purpose. Where required, we will ask for clear, specific, informed consent before processing.
  • Legitimate uses — in limited circumstances recognised under the Act, such as when you’ve voluntarily provided data for a specific purpose (for example, requesting a proposal) and processing is necessary to fulfil that purpose.

You may withdraw consent at any time by contacting us using the details in Section 14. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

5. Who We Share Data With

We do not sell or rent personal data. We may share limited personal data with:

  • Service providers we rely on to run our business — for example, email and scheduling tools (such as Calendly), analytics providers, and cloud hosting providers — who process data on our behalf and are contractually required to protect it
  • Professional advisors, such as accountants or lawyers, where necessary
  • Legal or regulatory authorities, where required by law, such as under a valid legal order

We do not share personal data with third parties for their own independent marketing purposes without your explicit consent.

6. How Long We Keep Data

We retain personal data only for as long as necessary to fulfil the purpose it was collected for, or as required by applicable law (for example, tax and accounting record-keeping requirements under Indian law). Enquiry and contact data that does not lead to an active client relationship is typically retained for a limited period and then deleted or anonymised, unless you ask us to retain it for future contact.

7. How We Protect Your Data

We take reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, consistent with the “reasonable security safeguards” standard under the DPDPA and the Information Technology Act, 2000. This includes restricting access to personal data to those who need it, using secure, reputable third-party tools for data storage and communication, and reviewing our practices periodically. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we are committed to protecting your data appropriately for the risk involved.

In the event of a personal data breach that is likely to affect you, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Rules, 2025.

8. Your Rights as a Data Principal

Under the DPDPA, you have the right to:

  • Access a summary of the personal data we hold about you and how it is being processed
  • Correct inaccurate or incomplete personal data
  • Erase personal data that is no longer necessary for the purpose it was collected for, subject to any legal retention requirements
  • Withdraw consent at any time, as described in Section 4
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Grievance redressal, as described in Section 12

To exercise any of these rights, contact us using the details in Section 14. We will respond within a reasonable time and in line with timelines required under the DPDP Rules, 2025.

9. Cookies and Tracking

Our website may use cookies and similar technologies to understand how visitors use the site and to improve its performance. You can control or disable cookies through your browser settings; doing so may affect how parts of the site function. We do not use cookies to build advertising profiles for third-party ad networks.

10. Children’s Data

Our services are directed at businesses and professionals, not children. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected data from a child without verifiable parental or guardian consent, as required under the DPDPA, we will delete it promptly.

11. Cross-Border Data Transfer

Some of the third-party tools we use to run our business (such as cloud hosting, email, or scheduling platforms) may store or process data outside India. Where this happens, we take reasonable steps to ensure such transfers are consistent with the DPDPA’s requirements for cross-border data transfer, which currently permits transfers to jurisdictions except those specifically restricted by the Central Government.

12. Grievance Redressal

If you have a concern about how we’ve handled your personal data, please contact our Grievance Officer using the details in Section 14. We will aim to acknowledge and address your concern promptly. If you’re not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India, the regulatory body established under the DPDPA.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. We will post the updated version on this page with a revised “Last updated” date. Significant changes will be communicated more prominently where appropriate.

14. Contact Us

For any questions about this policy, or to exercise your rights as a Data Principal, contact us at:

Vaahan Creative
Email: hello@vaahancreative.io
Phone: +91 99000 84261
Location: Bengaluru, Karnataka, India

Note: this policy is a general template drafted with reference to India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and is intended as a starting point. It hasn’t been reviewed by a lawyer. Before publishing this live, we’d strongly recommend having it reviewed by legal counsel familiar with the DPDPA, particularly to confirm it accurately reflects your actual data practices, third-party tools, and any client-data processing arrangements not covered here.