Digitalphy Media logo
HomeAbout UsOur ServicesPortfolioBlogContact Us
Academy
Privacy Policy from Digitalphy Media

Effective Date: 23 September 2026

Privacy Policy

This notice explains what personal data Digitalphy Media collects, why, what we do with it, and the rights you have over it under the Digital Personal Data Protection Act, 2023. We are the Data Fiduciary for the data described here, which means we are the ones answerable for it.

1. Who we are

Digitalphy Media, 2nd floor, 23, Nehru Rd, Peace Layout, Kammanahalli, Bengaluru — 560084.

Questions and complaints about personal data go to Hemanth, our Grievance Officer, at grievance@digitalphymedia.com. We answer within 30 days.

2. What we collect, and why

We collect only what a stated purpose needs. Each category below is tied to the purpose it serves, and we do not use it for anything else without asking you again:

  • Name, phone number and email address — to answer your enquiry and to discuss the services you asked about.
  • Business name, website and service requirements — to prepare a quotation or proposal for you.
  • Billing name, address and GSTIN — to raise a valid tax invoice, which the law requires to identify its customer.
  • Your signature, the date and time of signing, your IP address and your device details — recorded together when you sign an agreement, as evidence that you signed it. This is what makes an electronic signature hold up if it is ever questioned.
  • Messages you send us through forms, email or WhatsApp — to keep a record of what was agreed and asked for.
  • Marketing preferences — only if you have separately agreed to marketing.

3. Consent, and taking it back

We ask for your consent before collecting your details, and we ask separately for marketing. Nothing is pre-ticked, and you can agree to the enquiry without agreeing to marketing.

You can withdraw consent at any time, and it is as easy to withdraw as it was to give. Withdrawing marketing consent stops marketing; it does not stop service messages about work we are already doing for you.

Where we act on a contract with you, or where the law requires us to keep records, we rely on that rather than on your consent — and withdrawing consent does not remove those records. Section 5 explains which ones.

4. Your rights

Under the DPDP Act you may ask us to do any of the following, and we will act within 30 days:

Make any of these requests at digitalphymedia.com/privacy/request. We verify both your email address and your phone number before acting — handing your data to somebody who merely knew your email address would itself be a breach, and so would erasing your records because somebody else asked us to.

  • See a summary of the personal data we hold about you and what we have done with it.
  • Correct, complete or update anything that is wrong or out of date.
  • Erase your personal data, within the limits set out in Section 5.
  • Nominate someone to exercise these rights on your behalf if you die or become unable to.
  • Have a grievance answered, before or instead of going to the regulator.

5. What we cannot erase, and why

The right to erasure is not unlimited. Where another law requires us to keep something, we keep it — and we will tell you plainly what was kept rather than let you believe it all went:

Everything else goes: your enquiries and their follow-up history, your contact details, verification records, and the contents of messages we sent you.

  • Signed agreements, including the signature and its audit trail — retained for eight years after the agreement ends, as the record of what was agreed. Erasing one would leave both of us without recourse.
  • Tax invoices, receipts and payment records — retained for eight years from the end of the relevant financial year, under the Income Tax Act and the GST rules. A tax invoice must identify its customer, so your billing name, address and GSTIN stay on it.
  • A record that consent was given and withdrawn, with the dates — kept for as long as we rely on it, because otherwise we could not show that your withdrawal was acted on when you asked.

6. Who else sees it

We do not sell, rent or trade personal data. It is shared only where a purpose needs it:

  • Razorpay, to take a payment you have chosen to make. Card, UPI and banking details go to them directly — we never see or store them.
  • Resend and Meta (WhatsApp Business), to deliver the emails and messages we send you.
  • Where the law or a legal authority requires it.

7. Keeping it safe

Access to personal data inside our systems is limited by role, so people see only what their work requires. Signing links and payment links are single-purpose and expire. One-time passcodes are stored hashed, never in readable form, and are rate-limited against guessing.

If a breach occurs that affects you, we will inform you and the Data Protection Board of India, as the Act requires.

8. Cookies

Our website uses cookies to keep it working and to understand how it is used. You can manage or block them in your browser settings; the site will still work without the optional ones.

9. Third-party links

Our website links to other sites. We are not responsible for their content or their privacy practices, and this notice does not cover them.

10. Children

Our services are for businesses, and we do not knowingly collect the personal data of anyone under 18. If you believe we have, write to grievance@digitalphymedia.com and we will remove it.

11. If you are not satisfied

Raise it with Hemanth at grievance@digitalphymedia.com first — most things are quicker to fix directly. If we do not resolve it, you may complain to the Data Protection Board of India.

12. Changes to this notice

We will post any change here with a new effective date. Where a change materially affects what you agreed to, we will ask you again rather than rely on the consent you gave to the older wording.