Skip to main content
DPDP Act (India) 2023 Compliant Notice

Privacy Notice & Data Protection Policy

Issued pursuant to Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act, Act No. 22 of 2023, India).

Effective Date: September 12, 2026Version: DPDP-V1.0
Notice for Legal Compliance Review

[LEGAL REVIEW REQUIRED]: This document is structured to adhere to the provisions of the Digital Personal Data Protection Act, 2023 (India). It must be reviewed by qualified Indian legal counsel alongside the final notified Digital Personal Data Protection Rules and any subsequent advisories published by the Ministry of Electronics and Information Technology (MeitY) and the Data Protection Board of India (DPBI).

Language Accessibility (Section 5(3) DPDP Act)

This notice is available in English. As a Data Principal, you have the statutory option under Section 5(3) to access this notice in any of the 22 languages specified in the Eighth Schedule to the Constitution of India. To request a translated copy (e.g., Hindi, Telugu, Tamil, Marathi, Bengali, etc.), please contact our Grievance Officer.

Request Translation →

1.Identity & Role of the Data Fiduciary

This Privacy Notice is issued by MarketingKO (“MarketingKO”, “we”, “us”, or “our”), operating the website https://marketingko.in. Under the Digital Personal Data Protection Act, 2023, MarketingKO functions as a Data Fiduciaryin respect of the personal data collected from visitors, prospects, and clients (“Data Principals”).

Entity Name: MarketingKO

Principal Place of Business: Warangal, Telangana, India

Founder & Chief Engineer: Karthikeya Thallapally

Official Contact Email: [email protected]

Data Protection Grievance Email: [email protected]

2. Categories of Personal Data Collected

In compliance with the principle of data minimisation, MarketingKO collects only digital personal data that is strictly necessary for the specified purposes of providing our diagnostic audits, custom AI conversion systems, and related communications:

A. Identity & Contact Data
  • Full Name
  • Business Email Address
  • Phone / WhatsApp Number
  • Brand / Company Name & Website URL
B. Operational & Diagnostic Data
  • Estimated Monthly Revenue Tier (for qualification)
  • Current CRM & Telephony Tech Stack details
  • Current Speed-to-Lead and follow-up bottlenecks
C. Technical & Device Telemetry
  • IP Address (anonymized/masked for geographic routing)
  • Browser type, operating system & device specifications
  • Page interaction events (subject to cookie consent)
D. Consent Records & Auditable Logs
  • ISO 8601 Timestamp of consent confirmation
  • Consent text version identifier (e.g. DPDP-V1.0)
  • Granular purpose flags (Audit delivery vs Marketing updates)

3.Specified Purposes & Lawful Basis for Processing

Under Section 4 and Section 6 of the DPDP Act 2023, personal data is processed solely on the basis of freely given, specific, informed, unconditional, and unambiguous affirmative consent for the following itemised purposes:

Purpose 1: Revenue Leak Diagnostic Delivery & Consultation

To analyze your brand's inbound response pipelines, compute revenue leak metrics, prepare your bespoke strategy blueprint, and contact you directly via Email, WhatsApp, or Phone regarding this specific diagnostic request.

Purpose 2: Appointment Scheduling & Strategy Sessions

To schedule and host live 30-minute founder diagnostic sessions through our integrated calendar infrastructure (Cal.com).

Purpose 3: Educational Content & Lead Magnet Fulfillment

To transmit requested growth playbooks, AI checklists, or frameworks to your verified email address.

Purpose 4: Optional Marketing & D2C Growth Updates (Separate Opt-In)

Only if you explicitly check the separate, unticked marketing opt-in box, we may share periodic D2C teardowns and case studies. You may withdraw this consent at any time without affecting your access to our diagnostic services.

4.Third-Party Data Processors & Cross-Border Transfers

MarketingKO engages reputable third-party Data Processors under strict confidentiality and data-protection covenants. We never sell, rent, or trade your personal data.

Data ProcessorProcessing RoleData CategoriesServer Location
Web3FormsSecure Form Dispatch APIName, Email, Phone, RevenueUnited States / Cloudflare
Cal.comCalendar BookingName, Email, Booking TimeUnited States / EU
Microsoft ClarityBehavioral Telemetry (Consent-Gated)Anonymized Session DataUnited States
Google Tag ManagerAnalytics & Tags (Consent-Gated)Anonymized Interaction DataGlobal / USA
Google Workspace / SMTPTransactional Email DispatchName, Email, Audit ReportsGlobal

Cross-Border Transfers: Cross-border data transfers are executed in strict accordance with Section 16 of the DPDP Act 2023 and subject to any restrictions or blacklists notified by the Central Government of India.

5.Data Retention & Erasure Schedules

Under Section 8(7) of the DPDP Act, we retain personal data only for as long as necessary to satisfy the specified purpose for which it was collected, or as required by applicable Indian laws:

  • Prospective Inquiries & Audit Requests: Retained for a maximum of 180 days from submission if no commercial engagement ensues, after which records are purged or anonymised.
  • Active Client Engagement Records: Retained for the duration of the engineering sprint and 3 years thereafter for accounting, contractual, and tax compliance obligations.
  • Consent Withdrawal / Erasure Requests: Upon receipt of a valid erasure or consent withdrawal request, personal data is irreversibly erased or anonymised from active databases within 30 days, barring statutory retention duties.

6. Your Rights as a Data Principal (Sections 11–14)

The DPDP Act 2023 endows you with unequivocal, enforceable statutory rights in respect of your personal data:

Right to Access Information (Sec. 11)

Obtain a summary of personal data being processed, details of processing activities, and identities of all Data Processors with whom data has been shared.

Right to Correction & Completion (Sec. 12)

Correct inaccurate or misleading personal data, complete incomplete records, and update out-of-date information.

Right to Erasure (Sec. 12)

Request the erasure of personal data that is no longer necessary for the purpose for which it was collected, or upon consent withdrawal.

Right to Withdraw Consent (Sec. 6(4))

Withdraw consent at any time with the same ease with which consent was granted. Withdrawal does not affect lawful processing prior to withdrawal.

Right of Grievance Redressal (Sec. 13)

Have grievances addressed by our Data Protection & Grievance Redressal Officer within the statutory 30-day timeline.

Right to Nominate (Sec. 14)

Nominate any individual who, in the event of death or incapacity, shall exercise your rights as a Data Principal.

7.Grievance Redressal Officer & Complaint Escalation

In accordance with Section 13(1) of the DPDP Act 2023 and the Information Technology Rules, MarketingKO has designated a dedicated Grievance Redressal Officer:

Grievance Redressal Officer

Karthikeya Thallapally

Data Protection & Grievance Officer

Direct Grievance Contact[email protected]

Alternative: [email protected]

Postal Address

MarketingKO, Warangal, Telangana, PIN 506001, India

Resolution SLA

Acknowledgment: Within 48 business hours

Statutory Resolution: Within 30 calendar days

Escalation to the Data Protection Board of India (DPBI)

If you are dissatisfied with the resolution provided by our Grievance Officer, or if no response is provided within the statutory period, you have the right under Section 13(3) of the DPDP Act to submit an appeal or complaint directly to the Data Protection Board of India (DPBI) via its digital portal.

8. Reasonable Security Safeguards (Section 8(5))

MarketingKO maintains reasonable organizational, administrative, and technical security safeguards to prevent personal data breaches:

  • End-to-end transport encryption via modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Strict Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and secure headers.
  • Access control protocols restricting database and webhook access strictly on a need-to-know basis.
  • Documented Personal Data Breach Response Runbook with statutory 72-hour notification protocol to the DPBI and affected Data Principals (Section 8(6)).

9.Processing of Children's Personal Data (Section 9)

MarketingKO's website, diagnostic audits, and B2B/D2C revenue automation systems are strictly directed at enterprise brand owners, marketing leaders, and adult professionals. We do not knowingly collect, process, or track the personal data of children (individuals under the age of 18 years in India) or individuals with disabilities without verified parental or legal guardian consent. If you suspect that a child has provided us with personal data, please contact our Grievance Officer immediately for prompt erasure.