1. Introduction
LeadsIn ("we", "us", "our") operates the SaaS platform accessible at leadsin.co.in. We are committed to protecting the personal data of our users ("you", "Data Principals") in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA" or "the Act") and its rules.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access or use our services. As a Data Fiduciary under the DPDPA, we are bound by the obligations set forth in the Act.
2. Definitions (as per DPDPA, 2023)
- Data Principal: the individual whose personal data is being processed (i.e., you).
- Data Fiduciary: the entity that determines the purpose and means of processing personal data (i.e., LeadsIn).
- Data Processor: any entity that processes personal data on behalf of the Data Fiduciary.
- Personal Data: any data about an individual who is identifiable by or in relation to such data.
- Consent Manager: a person registered with the Data Protection Board who acts as a single point of contact for Data Principals to manage consent.
3. Personal Data We Collect
We collect the following categories of personal data from you:
- Full Name
- Email Address
- Phone Number
- Postal Address
4. Purpose of Data Collection
In accordance with Section 4 of the DPDPA, we process your personal data only for lawful purposes for which you have given consent. The specific purposes are:
- Providing and maintaining our services
- Legal compliance and obligations
- Processing payments and transactions
We shall not process your personal data for any purpose other than those specified above unless we obtain your fresh consent for such new purpose.
5. Consent
As required under Section 6 of the DPDPA, we obtain your free, specific, informed, unconditional, and unambiguous consent before collecting and processing your personal data. Consent is obtained through:
- Clear opt-in mechanisms at the time of data collection.
- A plain-language notice describing the data collected and the purpose of processing.
- An affirmative action by you (e.g., checking a consent box, clicking "I agree").
You have the right to withdraw your consent at any time by contacting us. Withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our standard retention period is as required by applicable law from the date of your last interaction with us.
Upon expiry of the retention period or upon your request for erasure, we shall delete or anonymize your personal data within a reasonable timeframe, as mandated by Section 8(7) of the DPDPA.
8. Rights of Data Principals
Under Chapter III of the DPDPA, you have the following rights:
- Right to Access (Section 11): request a summary of your personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.
- Right to Correction and Erasure (Section 12): request correction of inaccurate or misleading personal data, completion of incomplete data, updating of outdated data, and erasure of your personal data.
- Right to Grievance Redressal (Section 13): lodge a complaint regarding our processing of your personal data. We are obligated to respond within the timelines prescribed by the Act.
- Right to Nominate (Section 14): nominate any other individual who shall, in the event of your death or incapacity, exercise your rights as a Data Principal.
To exercise any of these rights, please contact us using the details in the Contact section below.
9. Obligations of LeadsIn as Data Fiduciary
Under Section 8 of the DPDPA, we commit to the following:
- Purpose Limitation: we process personal data only for the purposes for which consent was obtained.
- Data Accuracy: we make reasonable efforts to ensure the completeness, accuracy, and consistency of your personal data.
- Data Security: we implement reasonable security safeguards to prevent personal data breaches, including encryption, access controls, and regular security audits.
- Data Minimization: we collect only such personal data as is necessary for the specified purposes.
- Storage Limitation: we do not retain your personal data indefinitely. Data is deleted or anonymized when no longer necessary.
- Breach Notification: in the event of a personal data breach, we shall notify the Data Protection Board of India and affected Data Principals as required under Section 8(6) of the DPDPA.
10. Children's Data Protection
Our services are not directed at children (individuals under 18 years of age). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child without verifiable parental consent as required under Section 9 of the DPDPA, we will take steps to delete such data promptly.
11. Cross-Border Data Transfer
We primarily store and process your personal data within India. In the event that data transfer outside India becomes necessary, we will ensure compliance with Section 16 of the DPDPA and any applicable restrictions notified by the Central Government.
13. Data Security Measures
We implement reasonable security practices and procedures as required under the DPDPA, including:
- Encryption of personal data in transit and at rest.
- Access controls and authentication mechanisms.
- Regular security assessments and audits.
- Employee training on data protection practices.
- Incident response procedures for data breaches.
14. Data Protection Board of India
If you are dissatisfied with our response to your grievance or believe that your rights under the DPDPA have been violated, you may file a complaint with the Data Protection Board of India as established under Section 18 of the DPDPA.
15. Penalties and Compliance
LeadsIn acknowledges that non-compliance with the DPDPA may result in significant penalties of up to ₹250 crore, as specified in the Schedule to the Act. We are committed to full compliance with all provisions of the DPDPA and its rules.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. Any material changes will be communicated to you through:
- A prominent notice on our website.
- Email notification (where applicable).
- A fresh request for consent where required by the DPDPA.
17. Grievance Redressal and Contact Information
For any queries, concerns, or requests regarding your personal data or this Privacy Policy, please contact:
We shall acknowledge your request within 48 hours and endeavour to resolve your concern within the timelines prescribed under the DPDPA.
This Privacy Policy has been drafted to align with the Digital Personal Data Protection Act, 2023 (India). While it covers the key provisions of the DPDPA, we recommend consulting a qualified legal professional for advice specific to your circumstances.
See also our Terms & Conditions.
