1. Who we are
Digital Madhav AI Company (OPC) Private Limited — a One Person Company under § 2(62) of the Indian Companies Act, 2013, registered in Ahmedabad, Gujarat, India (incorporation in progress) — or its predecessor proprietorship under Madhav Anadkat at the same address, is the “data fiduciary” under India’s DPDP Act and the “data controller” under the EU GDPR for any personal data processed via digitalmadhav.aiand its services. References to “we”, “us” and “our” mean that entity.
For data-protection enquiries (access, correction, deletion, objection, complaint), email hello@digitalmadhav.ai with the subject line beginning [DPDP] or [GDPR]. Madhav personally handles every request.
2. What we collect
We aim to collect the minimum we need to do the job. The actual fields below are read directly off the data model (Lead) so this page stays in sync with reality.
2.1 Information you give us
- Identity & contact: name, work email, phone (optional), company, role.
- Location: country, state/region, city — all optional and used only to set timezone expectations and tailor regional pricing.
- Engagement context: the “reason” you pick from the dropdown on the form (e.g. 1:1 Mentorship — 15 min, Architecture review (1 week)); team size and budget range when relevant; the message you write describing what you want to ship.
- Payment metadata: when you pay via Razorpay, we receive an order id, a payment id, the amount, currency, and status — but never your card number, CVV, or banking credentials. Those stay with Razorpay.
2.2 Information we collect automatically
- Hashed IP. We hash your IP address with a one-way function and store only the hash — used for spam/abuse rate-limiting (5 form submits per IP per 10 min) and never reversed back to the raw IP.
- User agent: the browser / OS string sent by your browser. Used for diagnosing layout bugs.
- Referrer + landing path + UTM parameters (
utm_source,utm_medium,utm_campaign,utm_term,utm_content) — captured when you land via a link with those parameters. Used to understand which content brings the right people in.
2.3 Information from cookies
- NextAuth session cookie — only set after you log into the admin area (which only Madhav has access to). Visitors to the public site never get a session cookie set.
- Theme preference (
dm-theme) — local-storage value remembering your dark/light pick. Not transmitted to us; stays in your browser.
We don’t run third-party analytics today. No Google Analytics, no Meta Pixel, no LinkedIn Insight, no Hotjar. If we ever add analytics, we’ll publish a cookie banner, update this page, and email everyone with an active engagement before the analytics start running.
3. Why we collect it
We process your data for these purposes only:
- Replying to enquiries — name, email, the reason you picked, your message.
- Delivering the service you booked — scheduling a Cal.com slot, sending a Zoom link, issuing a cohort invite, generating an invoice.
- Payment processing & reconciliation — passing your name + email to Razorpay, receiving back the captured-payment confirmation, matching it to your lead/booking record.
- Spam & abuse prevention — hashed IP + rate limit + Cloudflare Turnstile. None of these stores anything more identifying than a hash and a counter.
- Improving the site — UTM + landing-path data tells us which page brought you in. Aggregate-only; never used to target you individually.
- Legal & tax compliance — Indian tax law requires us to retain payment and invoice records for up to 8 years.
4. Lawful basis
Under India’s DPDP Act 2023, we process your personal data on the basis of:
- Consent— given when you tick the implicit checkbox under each form (“by submitting you agree to one reply from Madhav”).
- Legitimate use for the contractual purpose you initiated (replying to your enquiry, delivering the cohort/call/workshop you paid for).
- Compliance with any law applicable to us — e.g. GST, income-tax, or court orders.
Under the EU GDPR(when you’re a visitor in the EU/EEA), we rely on:
- Article 6(1)(b)— performance of a contract you’ve entered or are about to enter (form submission, booking, cohort enrolment).
- Article 6(1)(f) — our legitimate interest in spam prevention, fraud detection, and improving the site, balanced against your rights and freedoms.
- Article 6(1)(c) — compliance with a legal obligation (Indian tax law for retention of payment records).
5. Third parties we share data with
We share the minimum personal data required with a small, deliberate list of third parties. Each is named here so you can audit them yourself.
- Razorpay Software Private Limited (Bangalore, India) — payment processing. Receives name, email, amount, currency, order id. RBI-licensed payment aggregator; their privacy policy is at razorpay.com/privacy.
- Cloudflare, Inc.(US) — Turnstile bot verification. Receives a one-time token from your browser during form submission. Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.
- Cal.com, Inc. (Berlin, EU) — calendar scheduling for mentorship and discovery calls. Receives name, email, and the timeslot you picked. Privacy policy at cal.com/privacy.
- Our SMTP provider— handles outbound email (lead confirmations, payment receipts, cohort welcome). Receives your name + email + the body of the transactional email. We’ll name the specific provider here once production credentials are in place.
- Skool (US) — community platform invited on cohort completion. Receives your email to send the invite. You join the platform under their terms once you accept the invite.
- Zoom— used for live cohort sessions and mentorship calls. Joins are by link only; we don’t create Zoom accounts on your behalf.
We don’t sell, rent, or otherwise commercialise your personal data with anyone. We don’t share it with advertising networks or data brokers — none are integrated into the site.
We may disclose personal data when compelled by a court order, regulatory authority, or other lawful demand, or where strictly necessary to investigate fraud or threats to the safety of any person. Where we’re legally allowed to, we’ll notify you first.
6. International transfers
Our primary database (PostgreSQL) and application are hosted in India. When you submit a form from outside India, your personal data is transferred to and processed in India. India has a comprehensive data-protection law (DPDP 2023) that the European Commission has not (yet) declared adequate.
For EU/EEA visitors, this transfer relies on the standard contractual clauses you implicitly accept by submitting the form, plus our commitment in this Privacy Policy to apply GDPR-equivalent protections to your data (rights of access, correction, erasure, etc.) regardless of where it sits.
A handful of third parties named in §5 also process your data outside India (Cloudflare, Skool — US; Cal.com — EU). Each operates under its own published privacy framework and regional data-residency commitments.
7. Retention
We keep different data for different windows, dictated by the purpose and Indian law:
- Lead records (name, email, message, company, role, location, status, notes): up to 7 years after the last contact, then deleted. Active engagements hold the clock until they close.
- Payment & invoice records: 8 years from the financial year in which the transaction occurred — Indian Income-Tax Act and GST requirements.
- Audit log (admin actions on leads, cohorts, etc.): 5 years.
- Hashed IP & rate-limit counters: 90 days, then automatically purged.
- Email logs (which transactional email was sent to whom, status): 3 years.
- Community invite records: kept while the community access is active, deleted on access revocation.
Deletion-on-request (see §8) overrides these defaults except where we must legally retain a record (e.g. a paid invoice we’re obliged to keep for tax). In that case, we’ll delete everything we’re not legally required to keep and tell you exactly what stays and why.
8. Your rights
Whether you’re in India, the EU/EEA, the UK, the GCC, or anywhere else, the following rights apply to your data held by us — we extend them to every visitor regardless of local law:
- Access — ask for a copy of your personal data.
- Correction— fix anything that’s inaccurate or incomplete.
- Erasure(“right to be forgotten”) — ask us to delete your data, subject to legal-retention carve-outs noted in §7.
- Portability — get a machine-readable export of the data you gave us.
- Objection — opt out of any legitimate-interest processing, including spam-prevention telemetry.
- Withdraw consent— at any time, with no penalty. Withdrawal doesn’t affect the lawfulness of processing already done.
- Complain— to India’s Data Protection Board (once constituted under the DPDP Act), or the supervisory authority in your EU/EEA country, or equivalent regulator in your jurisdiction.
To exercise any right, email hello@digitalmadhav.ai with the subject line beginning [DPDP] or [GDPR]. We’ll respond within 30 days (DPDP timeline), often faster.
10. Security
We follow industry-standard security practices for an application of our scale:
- HTTPS/TLS 1.2+ for all traffic; HSTS enabled.
- Database encrypted at rest; nightly backups in a separate volume.
- Passwords (admin only) hashed with bcrypt; 2FA via TOTP optional/recommended.
- Rate-limiting and Cloudflare Turnstile on every public form.
- Audit log on every admin mutation — append-only, separate retention.
- Razorpay HMAC-verified webhooks; idempotent fulfilment.
- Vulnerability disclosure: please email hello@digitalmadhav.ai — we acknowledge within 48 hours and don’t pursue good-faith research.
No system is perfectly secure. If a breach occurs that puts your data at material risk, we’ll notify you and the relevant regulator within the timeframe required by law (72 hours under GDPR; the DPDP-Act-prescribed period for India).
11. Children
Our services are not directed at, and we don’t knowingly collect personal data from, anyone under 18. If you believe a child has submitted personal data to us, write to hello@digitalmadhav.ai and we’ll delete it.
12. Changes to this Policy
We may update this Policy when our practice or applicable law changes. The “Last updated” date at the top changes whenever we ship a substantive edit. For material changes that reduce your rights, we’ll email everyone with an active engagement at least 14 days before the change takes effect.
13. Contact & data-protection requests
For privacy-specific enquiries, please use hello@digitalmadhav.ai with the subject line beginning [DPDP] (India) or [GDPR] (EU/EEA/UK). For everything else, use the same address — Madhav reads this inbox personally.
See the corresponding terms at /terms, the refund policy at /refund, and the cohort-specific terms at /cohort-terms.
Issued by Madhav Anadkat (Chief AI Officer · Independent AI Transformation Partner) · Ahmedabad, India · ISO-aligned operations.