Privacy Notice & Data Protection Policy
Issued pursuant to Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act, Act No. 22 of 2023, India).
[LEGAL REVIEW REQUIRED]: This document is structured to adhere to the provisions of the Digital Personal Data Protection Act, 2023 (India). It must be reviewed by qualified Indian legal counsel alongside the final notified Digital Personal Data Protection Rules and any subsequent advisories published by the Ministry of Electronics and Information Technology (MeitY) and the Data Protection Board of India (DPBI).
This notice is available in English. As a Data Principal, you have the statutory option under Section 5(3) to access this notice in any of the 22 languages specified in the Eighth Schedule to the Constitution of India. To request a translated copy (e.g., Hindi, Telugu, Tamil, Marathi, Bengali, etc.), please contact our Grievance Officer.
1.Identity & Role of the Data Fiduciary
This Privacy Notice is issued by MarketingKO (“MarketingKO”, “we”, “us”, or “our”), operating the website https://marketingko.in. Under the Digital Personal Data Protection Act, 2023, MarketingKO functions as a Data Fiduciaryin respect of the personal data collected from visitors, prospects, and clients (“Data Principals”).
Entity Name: MarketingKO
Principal Place of Business: Warangal, Telangana, India
Founder & Chief Engineer: Karthikeya Thallapally
Official Contact Email: [email protected]
Data Protection Grievance Email: [email protected]
2. Categories of Personal Data Collected
In compliance with the principle of data minimisation, MarketingKO collects only digital personal data that is strictly necessary for the specified purposes of providing our diagnostic audits, custom AI conversion systems, and related communications:
- Full Name
- Business Email Address
- Phone / WhatsApp Number
- Brand / Company Name & Website URL
- Estimated Monthly Revenue Tier (for qualification)
- Current CRM & Telephony Tech Stack details
- Current Speed-to-Lead and follow-up bottlenecks
- IP Address (anonymized/masked for geographic routing)
- Browser type, operating system & device specifications
- Page interaction events (subject to cookie consent)
- ISO 8601 Timestamp of consent confirmation
- Consent text version identifier (e.g. DPDP-V1.0)
- Granular purpose flags (Audit delivery vs Marketing updates)
3.Specified Purposes & Lawful Basis for Processing
Under Section 4 and Section 6 of the DPDP Act 2023, personal data is processed solely on the basis of freely given, specific, informed, unconditional, and unambiguous affirmative consent for the following itemised purposes:
To analyze your brand's inbound response pipelines, compute revenue leak metrics, prepare your bespoke strategy blueprint, and contact you directly via Email, WhatsApp, or Phone regarding this specific diagnostic request.
To schedule and host live 30-minute founder diagnostic sessions through our integrated calendar infrastructure (Cal.com).
To transmit requested growth playbooks, AI checklists, or frameworks to your verified email address.
Only if you explicitly check the separate, unticked marketing opt-in box, we may share periodic D2C teardowns and case studies. You may withdraw this consent at any time without affecting your access to our diagnostic services.
4.Third-Party Data Processors & Cross-Border Transfers
MarketingKO engages reputable third-party Data Processors under strict confidentiality and data-protection covenants. We never sell, rent, or trade your personal data.
| Data Processor | Processing Role | Data Categories | Server Location |
|---|---|---|---|
| Web3Forms | Secure Form Dispatch API | Name, Email, Phone, Revenue | United States / Cloudflare |
| Cal.com | Calendar Booking | Name, Email, Booking Time | United States / EU |
| Microsoft Clarity | Behavioral Telemetry (Consent-Gated) | Anonymized Session Data | United States |
| Google Tag Manager | Analytics & Tags (Consent-Gated) | Anonymized Interaction Data | Global / USA |
| Google Workspace / SMTP | Transactional Email Dispatch | Name, Email, Audit Reports | Global |
Cross-Border Transfers: Cross-border data transfers are executed in strict accordance with Section 16 of the DPDP Act 2023 and subject to any restrictions or blacklists notified by the Central Government of India.
5.Data Retention & Erasure Schedules
Under Section 8(7) of the DPDP Act, we retain personal data only for as long as necessary to satisfy the specified purpose for which it was collected, or as required by applicable Indian laws:
- Prospective Inquiries & Audit Requests: Retained for a maximum of 180 days from submission if no commercial engagement ensues, after which records are purged or anonymised.
- Active Client Engagement Records: Retained for the duration of the engineering sprint and 3 years thereafter for accounting, contractual, and tax compliance obligations.
- Consent Withdrawal / Erasure Requests: Upon receipt of a valid erasure or consent withdrawal request, personal data is irreversibly erased or anonymised from active databases within 30 days, barring statutory retention duties.
6. Your Rights as a Data Principal (Sections 11–14)
The DPDP Act 2023 endows you with unequivocal, enforceable statutory rights in respect of your personal data:
Obtain a summary of personal data being processed, details of processing activities, and identities of all Data Processors with whom data has been shared.
Correct inaccurate or misleading personal data, complete incomplete records, and update out-of-date information.
Request the erasure of personal data that is no longer necessary for the purpose for which it was collected, or upon consent withdrawal.
Withdraw consent at any time with the same ease with which consent was granted. Withdrawal does not affect lawful processing prior to withdrawal.
Have grievances addressed by our Data Protection & Grievance Redressal Officer within the statutory 30-day timeline.
Nominate any individual who, in the event of death or incapacity, shall exercise your rights as a Data Principal.
7.Grievance Redressal Officer & Complaint Escalation
In accordance with Section 13(1) of the DPDP Act 2023 and the Information Technology Rules, MarketingKO has designated a dedicated Grievance Redressal Officer:
Karthikeya Thallapally
Data Protection & Grievance Officer
MarketingKO, Warangal, Telangana, PIN 506001, India
Acknowledgment: Within 48 business hours
Statutory Resolution: Within 30 calendar days
Escalation to the Data Protection Board of India (DPBI)
If you are dissatisfied with the resolution provided by our Grievance Officer, or if no response is provided within the statutory period, you have the right under Section 13(3) of the DPDP Act to submit an appeal or complaint directly to the Data Protection Board of India (DPBI) via its digital portal.
8. Reasonable Security Safeguards (Section 8(5))
MarketingKO maintains reasonable organizational, administrative, and technical security safeguards to prevent personal data breaches:
- End-to-end transport encryption via modern Transport Layer Security (TLS 1.3 / HTTPS).
- Strict Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and secure headers.
- Access control protocols restricting database and webhook access strictly on a need-to-know basis.
- Documented Personal Data Breach Response Runbook with statutory 72-hour notification protocol to the DPBI and affected Data Principals (Section 8(6)).
9.Processing of Children's Personal Data (Section 9)
MarketingKO's website, diagnostic audits, and B2B/D2C revenue automation systems are strictly directed at enterprise brand owners, marketing leaders, and adult professionals. We do not knowingly collect, process, or track the personal data of children (individuals under the age of 18 years in India) or individuals with disabilities without verified parental or legal guardian consent. If you suspect that a child has provided us with personal data, please contact our Grievance Officer immediately for prompt erasure.