PRIVACY POLICY
Resolant Infinity Assistant Private Limited (Brand: CARAMAL) CIN: U62099PN2023PTC222742 | GSTIN: 27AAMCR8807M1ZL Website: https://caramal.co Last Updated: 02 July 2026
Disclaimer: This is a drafted template based on your inputs, not legal advice. Have it reviewed by a licensed Indian counsel before publishing, given the enforceability stakes and your specific data flows.
1. INTRODUCTION AND SCOPE
1.1 This Privacy Policy (“Policy“) is published by Resolant Infinity Assistant Private Limited, a company incorporated under the Companies Act, 2013, bearing CIN U62099PN2023PTC222742, having its registered office at Dhayri Narhe Road, Dhayri, Pune, Maharashtra, India – 411041, operating under the brand name “CARAMAL” (hereinafter referred to as the “Company“, “CARAMAL“, “we“, “us“, or “our“).
1.2 This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act“), the Information Technology Act, 2000 (“IT Act“), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules“), and other applicable data protection legislation in force in India from time to time.
1.3 This Policy applies to all personal data, business data, and technical data collected by the Company through:
(a) the website https://caramal.co and its subdomains (“Website“); (b) any mobile application, landing page, or microsite operated by the Company; (c) any offline interaction, including WhatsApp, email, telephone, or in-person meetings, where such interaction leads to digital storage of information; (d) the provision of digital marketing, performance marketing, creative, and related services (collectively, “Services“) to clients (“Client“, “you“, “your“).
1.4 By accessing the Website, submitting information through any form, engaging the Company’s Services, or otherwise interacting with the Company, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with any part of this Policy, you must discontinue use of the Website and Services immediately.
1.5 This Policy is a legally binding electronic record under Section 10A of the Information Technology Act, 2000, and does not require any physical or digital signature to be valid and enforceable.
2. DEFINITIONS
For the purposes of this Policy, unless the context otherwise requires:
2.1 “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act, 2023.
2.2 “Data Principal” means the individual to whom the Personal Data relates, as defined under Section 2(j) of the DPDP Act, 2023.
2.3 “Data Fiduciary” means the Company, which alone or in conjunction with other entities determines the purpose and means of processing Personal Data, as defined under Section 2(i) of the DPDP Act, 2023.
2.4 “Data Processor” means any entity that processes Personal Data on behalf of the Company, including but not limited to Razorpay, Google, Meta, cloud hosting providers, and other Service Providers named in this Policy.
2.5 “Processing” means any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, alignment, combination, disclosure by transmission, dissemination, restriction, erasure, or destruction.
2.6 “Business Data” means non-personal information relating to a Client’s business, including but not limited to advertising account structures, campaign budgets, sales figures, business processes, and marketing strategies shared with the Company for the purpose of rendering Services.
2.7 “Technical Data” means IP addresses, browser type and version, device identifiers, operating system, referral source, page interaction data, and similar technical information collected automatically.
2.8 “Consent” means any freely given, specific, informed, and unambiguous indication of the Data Principal’s wishes, given through a clear affirmative action, in accordance with Section 6 of the DPDP Act, 2023.
2.9 “Sensitive Personal Data” means Personal Data that reveals, is related to, or constitutes financial information, health data, biometric data, or any other category treated as sensitive under applicable law.
2.10 “Cookies” means small text files placed on a Data Principal’s device, as further described in Clause 9 and the Company’s separate Cookie Policy.
2.11 “Service Providers” means third parties engaged by the Company to perform functions on its behalf, including payment processing, analytics, hosting, and communication services.
2.12 “Applicable Law” means the DPDP Act, 2023, the IT Act, 2000, the SPDI Rules, 2011, the Consumer Protection Act, 2019, and any rules, regulations, or notifications issued thereunder, as amended from time to time.
3. INFORMATION WE COLLECT
3.1 Personal Data
The Company collects the following categories of Personal Data directly from Data Principals:
(a) full name; (b) email address; (c) phone number and WhatsApp number; (d) business/company name and designation; (e) billing address and GST registration details; (f) postal address, where required for invoicing or communication; (g) profile photographs or identification documents, where voluntarily shared for onboarding or verification purposes; (h) any information voluntarily submitted through contact forms, lead forms, WhatsApp chats, or email correspondence; (i) information submitted through Meta Lead Ads, Google Lead Forms, landing pages, or similar tools deployed on behalf of Clients, where the Company acts as a Data Processor for such Client’s own end customers.
3.2 Business Data
The Company collects Business Data necessary to render Services, including:
(a) advertising account access (Meta Business Manager, Google Ads Manager, Google Analytics, Google Search Console); (b) historical campaign performance data, budgets, and creative assets; (c) sales, revenue, enquiry, and conversion data shared by the Client for optimisation purposes; (d) brand guidelines, logos, product catalogues, and marketing collateral; (e) internal business processes shared for the purpose of strategy development.
3.3 Technical and Device Data
The Company and its Service Providers automatically collect:
(a) IP address and approximate geolocation; (b) browser type, version, and language settings; (c) device type, operating system, and screen resolution; (d) referring/exit pages and click-stream data; (e) date and time stamps of visits; (f) unique device identifiers and advertising identifiers (e.g., Google Advertising ID, Meta device ID); (g) log files generated by the Website’s hosting servers.
3.4 Payment Data
Payment card details, UPI credentials, net banking credentials, and bank account details are collected and processed exclusively by Razorpay Software Private Limited (“Razorpay“), a Reserve Bank of India-regulated Payment Aggregator, and are not stored, viewed, or retained by the Company on its own servers at any point. The Company receives only transaction status, transaction ID, masked payment references, and settlement confirmations from Razorpay.
3.5 Communication Data
The Company collects and retains records of communications exchanged via email, WhatsApp Business API, telephone call logs (where recorded with prior notice), Slack, Google Meet, Zoom, and project management tools used to deliver Services, for the purposes of service delivery, quality assurance, and dispute resolution.
3.6 Cookies and Tracking Technologies
The Website uses cookies, pixels, and similar technologies, as detailed in Clause 9 below and the Company’s standalone Cookie Policy.
4. HOW INFORMATION IS COLLECTED
Information is collected through the following methods:
4.1 Direct submission — via contact forms, WhatsApp, email, telephonic discussions, service agreements, and onboarding questionnaires.
4.2 Automated collection — via cookies, web beacons, Google Analytics, Meta Pixel, server logs, and similar technologies deployed on the Website and, where applicable, on Client properties managed by the Company.
4.3 Third-party sources — where the Client or a Data Principal has provided information to a third-party platform (e.g., Meta, Google) that is subsequently shared with the Company pursuant to that platform’s own terms and the Data Principal’s consent obtained by such third party.
4.4 Service delivery — information generated in the course of Service delivery, such as campaign performance metrics, is collected directly from advertising platforms via authorised API or dashboard access granted by the Client.
5. PURPOSE OF PROCESSING
The Company processes Personal Data, Business Data, and Technical Data for the following specified and legitimate purposes only:
5.1 to provide, operate, and improve the Services contracted by the Client; 5.2 to communicate regarding onboarding, service delivery, invoicing, and support; 5.3 to process payments and manage subscriptions through Razorpay; 5.4 to comply with statutory obligations under the GST regime, the Companies Act, 2013, and other Applicable Law; 5.5 to conduct performance marketing, retargeting, and lookalike audience creation on behalf of Clients, using data the Client is independently responsible for lawfully sourcing; 5.6 to send transactional communications, service updates, and, where consented to, marketing communications; 5.7 to detect, prevent, and investigate fraud, unauthorised access, or breach of the Company’s Terms & Conditions; 5.8 to enforce the Company’s legal rights, defend claims, and comply with judicial or regulatory directions; 5.9 to conduct internal analytics, quality assurance, and service improvement; 5.10 to maintain business records for audit, taxation, and dispute-resolution purposes.
6. LEGAL BASIS FOR PROCESSING
6.1 The Company processes Personal Data on the following legal bases recognised under the DPDP Act, 2023:
(a) Consent — obtained under Section 6 of the DPDP Act at the point of collection, through clear affirmative action such as form submission, checkbox acceptance, or continued use of the Website after notice;
(b) Legitimate Uses — under Section 7 of the DPDP Act, including where the Data Principal has voluntarily provided Personal Data for a specified purpose and has not indicated non-consent, and where Processing is necessary for compliance with any judgment, decree, or order, or for responding to a medical emergency, or for purposes related to employment;
(c) Contractual necessity — Processing that is necessary for the performance of a contract to which the Client is a party, such as delivering the Services or processing payments;
(d) Compliance with law — Processing required to fulfil obligations under GST law, the Companies Act, 2013, and directions of governmental or regulatory authorities.
6.2 Consent obtained by the Company may be withdrawn at any time, with the same ease with which it was given, in accordance with Section 6(4) of the DPDP Act, subject to Clause 13 (Data Retention) and Clause 14 (User Rights) below. Withdrawal of consent shall not affect the lawfulness of Processing carried out prior to such withdrawal, nor shall it affect processing necessary for compliance with legal obligations.
7. DATA SECURITY
7.1 The Company implements reasonable security practices and procedures as mandated under Section 43A of the IT Act, 2000 read with the SPDI Rules, 2011, and Section 8(5) of the DPDP Act, 2023, including but not limited to:
(a) encryption of data in transit using TLS/SSL protocols; (b) role-based access controls restricting internal access to Personal Data on a need-to-know basis; (c) secure password policies and multi-factor authentication for internal systems handling Client data; (d) periodic review of access logs and system vulnerabilities; (e) use of reputable, industry-standard cloud infrastructure providers with their own certified security frameworks; (f) confidentiality obligations imposed on all employees, contractors, and freelancers with access to Personal Data.
7.2 No system of data transmission or storage can be guaranteed to be 100% secure. While the Company implements industry-standard safeguards, it does not warrant or guarantee that unauthorised access, hacking, data loss, or breach will never occur, and disclaims liability to the maximum extent permitted under Applicable Law for events beyond its reasonable control, subject to Clause 17 (Data Breach Response).
8. DATA SHARING AND DISCLOSURE
8.1 The Company does not sell, rent, or trade Personal Data to any third party for monetary consideration.
8.2 The Company may share Personal Data, Business Data, and Technical Data with the following categories of Service Providers, strictly for the purposes described in Clause 5:
(a) Razorpay — for payment processing, subscription billing, AutoPay mandate management, and settlement, governed additionally by Razorpay’s own privacy policy and the Reserve Bank of India’s Payment Aggregator regulations.
(b) Google LLC — including Google Ads, Google Analytics, Google Workspace, Google Drive, and Google Search Console, for the purposes of campaign execution, website analytics, and document/file sharing, governed by Google’s Privacy Policy.
(c) Meta Platforms, Inc. — including Meta Ads Manager, Meta Pixel, Instagram, and Facebook Business Suite, for campaign execution, retargeting, and conversion tracking, governed by Meta’s Data Policy and Meta Business Tools Terms.
(d) WhatsApp Business Platform (Meta) — for transactional and service communication.
(e) Cloud service providers — including but not limited to Google Cloud Platform, Amazon Web Services, and Microsoft Azure, for secure data storage and hosting.
(f) Project management and collaboration tools — including Slack, Trello, ClickUp, Notion, Zoom, and Google Meet, for service coordination.
(g) Professional advisors — including the Company’s auditors, chartered accountants, company secretary, and legal counsel, bound by professional confidentiality obligations.
(h) Regulatory and judicial authorities — where disclosure is mandated by law, court order, or a valid request from a governmental or regulatory authority, including under Section 36(a) of the DPDP Act.
(i) Successors in business — in the event of a merger, acquisition, restructuring, or sale of business assets, Personal Data may be transferred to the successor entity, subject to equivalent confidentiality protections.
8.3 The Company requires all Service Providers with access to Personal Data to maintain confidentiality and implement reasonable security safeguards, but Clients acknowledge that the Company’s control over independent third-party platforms such as Google and Meta is limited to the extent permitted by such platforms’ own terms of service.
9. COOKIES, ANALYTICS, AND TRACKING TECHNOLOGIES
9.1 The Website uses the following categories of cookies and tracking technologies:
(a) Essential/Strictly Necessary Cookies — required for the Website to function, including session management and security.
(b) Analytics Cookies (Google Analytics) — used to understand visitor behaviour, page views, session duration, and traffic sources. Google Analytics may collect IP address (which may be anonymised), device information, and browsing behaviour, subject to Google’s own privacy practices.
(c) Advertising/Retargeting Cookies (Meta Pixel, Google Ads Tag) — used to measure the effectiveness of the Company’s own advertising campaigns and to retarget visitors with relevant advertisements across Meta and Google properties.
(d) Preference Cookies — used to remember visitor preferences such as language and region.
9.2 Third-party cookies placed by Google and Meta are governed by those companies’ own privacy and cookie policies, over which the Company exercises no control. Data Principals are encouraged to review Google’s and Meta’s respective privacy policies directly.
9.3 Data Principals may control or disable cookies through their browser settings; however, disabling essential cookies may affect Website functionality. Further detail is available in the Company’s standalone Cookie Policy (Document 5).
10. USE OF PIXELS AND CONVERSION TRACKING FOR CLIENT CAMPAIGNS
10.1 Where the Company deploys the Meta Pixel, Google Tag, or similar tracking technology on a Client’s website or landing page for the purpose of running advertising campaigns, the Client — and not the Company — bears sole responsibility for:
(a) ensuring the Client’s own website carries an adequate, DPDP Act-compliant privacy policy and cookie consent mechanism; (b) obtaining valid consent from the Client’s own website visitors and end customers for such tracking; (c) ensuring lawful basis exists for any Personal Data of the Client’s end customers collected via such pixels or forms.
10.2 In such engagements, the Company acts as a Data Processor on behalf of the Client (who acts as Data Fiduciary in respect of its own end-customer data), and the Company’s obligations are limited to processing such data solely per the Client’s documented instructions and this Policy’s security standards.
11. INTERNATIONAL DATA TRANSFERS
11.1 Certain Service Providers used by the Company, including Google, Meta, and various cloud hosting providers, may store or process data on servers located outside India.
11.2 Such cross-border transfers are made in reliance on the Service Providers’ own compliance frameworks and, where applicable, in accordance with Section 16 of the DPDP Act, 2023, which permits transfer of Personal Data outside India except to countries restricted by the Central Government by notification.
11.3 By using the Website and Services, the Data Principal consents to such cross-border storage and processing as reasonably necessary for the Company to render its Services using industry-standard global platforms.
12. AUTOMATED DECISION-MAKING
12.1 The Company does not use Personal Data to make any legal or similarly significant automated decision concerning a Data Principal (such as credit eligibility or employment decisions) without human involvement.
12.2 Advertising platforms (Google, Meta) independently use automated bidding, audience targeting, and algorithmic ad delivery based on data processed on their own platforms. The Company does not control, and disclaims responsibility for, such third-party algorithmic processes, which are governed by the respective platform’s own terms.
13. DATA RETENTION
13.1 The Company retains Personal Data and Business Data only for as long as is reasonably necessary to fulfil the purposes outlined in this Policy, namely:
(a) for the duration of the Client’s active engagement with the Company, plus a period of seven (7) years thereafter, to comply with statutory record-keeping obligations under the Income Tax Act, 1961, the Central Goods and Services Tax Act, 2017, and the Companies Act, 2013;
(b) transactional and payment-related records are retained in accordance with Razorpay’s and the Reserve Bank of India’s applicable retention mandates;
(c) marketing communication data is retained until the Data Principal withdraws consent or unsubscribes, subject to a reasonable period for processing such withdrawal;
(d) website analytics data is retained as per Google Analytics’ default retention settings unless configured otherwise.
13.2 Upon expiry of the applicable retention period, or upon a valid erasure request under Clause 14 (subject to the exceptions in Clause 14.5), the Company shall delete or anonymise the relevant Personal Data in accordance with its internal data disposal procedures.
14. RIGHTS OF DATA PRINCIPALS UNDER THE DPDP ACT, 2023
14.1 Subject to the conditions and exceptions prescribed under the DPDP Act, 2023, and its accompanying rules, Data Principals have the following rights:
(a) Right to Access Information (Section 11) — to obtain a summary of Personal Data being processed and the Processing activities undertaken;
(b) Right to Correction and Erasure (Section 12) — to request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was processed;
(c) Right to Grievance Redressal (Section 13) — to have a readily available means of registering a grievance with the Company;
(d) Right to Nominate (Section 14) — to nominate another individual to exercise these rights in the event of the Data Principal’s death or incapacity;
(e) Right to Withdraw Consent — as set out in Clause 6.2 above.
14.2 To exercise any of the above rights, Data Principals may submit a written request to hello@caramal.co, specifying the nature of the request and providing sufficient information to verify identity.
14.3 The Company shall endeavour to respond to verified requests within a reasonable period, and in any event within the timelines prescribed under the DPDP Act and its rules, once notified.
14.4 The Company reserves the right to charge a reasonable fee for repetitive or manifestly unfounded requests, to the extent permitted under Applicable Law.
14.5 The Company may decline erasure requests where retention is required for compliance with legal obligations, establishment or defence of legal claims, or other legitimate business purposes recognised under Applicable Law, and shall inform the Data Principal of such refusal with reasons.
15. MARKETING COMMUNICATIONS
15.1 The Company may send promotional emails, WhatsApp messages, or SMS regarding its own Services, subject to the Data Principal’s consent, obtained either through explicit opt-in or through the “soft opt-in” recognised for existing customers under general data protection practice.
15.2 Every marketing communication shall contain a clear mechanism to unsubscribe or opt out. Upon receipt of an opt-out request, the Company shall cease marketing communications within a reasonable period, not exceeding the timelines mandated under Applicable Law.
15.3 Transactional communications (e.g., invoices, service updates, payment confirmations) are not classified as marketing communications and may continue to be sent regardless of marketing opt-out status, as they are necessary for contract performance.
16. CHILDREN’S PRIVACY
16.1 The Website and Services are intended solely for businesses and individuals who are 18 years of age or older and who have the legal capacity to enter into a binding contract under the Indian Contract Act, 1872.
16.2 The Company does not knowingly collect Personal Data from individuals below the age of 18. In compliance with Section 9 of the DPDP Act, 2023, where the Company becomes aware that Personal Data of a child has been collected, it shall, upon verification, promptly delete such data, unless processing is demonstrably for the child’s benefit under conditions prescribed by the Central Government.
16.3 Parents or guardians who believe their child has provided Personal Data to the Company without appropriate consent are requested to contact hello@caramal.co for prompt deletion.
17. DATA BREACH RESPONSE
17.1 In the event of a Personal Data breach that compromises the confidentiality, integrity, or availability of Personal Data, the Company shall:
(a) undertake reasonable efforts to contain and remediate the breach as soon as practicable; (b) notify the Data Protection Board of India and affected Data Principals in the form and manner, and within the timelines, prescribed under Section 8(6) of the DPDP Act, 2023 and rules made thereunder; (c) cooperate with regulatory authorities and undertake reasonable investigative and corrective measures.
17.2 Notification of a breach shall not be construed as an admission of fault or liability on the part of the Company, and the Company’s liability, if any, shall remain subject to Clause 18 of the Terms & Conditions (Limitation of Liability).
18. THIRD-PARTY LINKS AND PLATFORMS
18.1 The Website and Company communications may contain links to third-party websites, including social media platforms (Instagram, Facebook, LinkedIn, YouTube) and payment gateways. This Policy does not extend to, and the Company is not responsible for, the privacy practices or content of such third-party platforms.
18.2 Data Principals are encouraged to review the privacy policies of any third-party platform before submitting Personal Data to it.
19. GRIEVANCE OFFICER
19.1 In accordance with the IT Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023, the Company has designated the following person to address grievances relating to Processing of Personal Data:
| Particulars | Details |
|---|---|
| Name | Aditya Shahade |
| Designation | Grievance Officer / Authorised Representative |
| Company | Resolant Infinity Assistant Private Limited (CARAMAL) |
| Address | Dhayri Narhe Road, Dhayri, Pune, Maharashtra, India – 411041 |
| hello@caramal.co | |
| Phone | +91 9420843350 |
19.2 The Grievance Officer shall acknowledge receipt of any grievance within a reasonable period and endeavour to resolve it in accordance with Applicable Law.
20. AMENDMENTS TO THIS POLICY
20.1 The Company reserves the right to amend, modify, or update this Policy at any time, at its sole discretion, to reflect changes in Applicable Law, business practices, or Services offered.
20.2 Material changes shall be notified through a prominent notice on the Website or via email, and the “Last Updated” date at the top of this Policy shall be revised accordingly.
20.3 Continued use of the Website or Services following any amendment constitutes acceptance of the revised Policy.
21. GOVERNING LAW AND JURISDICTION
21.1 This Policy shall be governed by and construed in accordance with the laws of India.
21.2 Subject to the arbitration provisions set out in the Company’s Terms & Conditions, courts at Pune, Maharashtra shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.
22. CONTACT US
For any questions, concerns, or requests relating to this Privacy Policy, please contact:
Resolant Infinity Assistant Private Limited (CARAMAL) Dhayri Narhe Road, Dhayri, Pune, Maharashtra, India – 411041 Email: hello@caramal.co Phone: +91 9420843350 Website: https://caramal.co
End of Privacy Policy. Proceeding to Document 2: Terms & Conditions.