Legal
Privacy Policy
We collect as little as possible, sell nothing to anyone, and tell you exactly what happens to your data. This policy explains it all.
Last updated: August 24, 2026
1. Who we are
This website is operated by Moomoth Media Private Limited, a private company incorporated in India (CIN: U72900GJ2020PTC118919, registered with ROC Ahmedabad), with its registered office at 405, Atlantis, Sarabhai Compound, Vadodara, Gujarat 390023, India (“Moomoth”, “we”, “us”).
For the purposes of the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDP Act), Moomoth Media Private Limited is the data fiduciary / controller for personal data described in this policy.
2. What we collect
We run this site on a minimal-data philosophy. Depending on how you interact with us, we may process:
- Contact details you send us — name, email address, company, and the contents of your message when you email [email protected] or book a strategy call.
- Newsletter subscription data — your email address and subscription preferences.
- Client engagement data — information clients share during projects. This is governed by our client agreements, not this policy, and is never used to train AI models.
- Server logs — IP address, user agent, and request timestamps, retained briefly for security and abuse prevention.
We do not use advertising trackers or third-party analytics pixels on this site.
3. How we use it
- To respond to inquiries and schedule strategy calls (performance of a contract or steps prior to it).
- To deliver the newsletter you requested (consent).
- To operate, secure, and improve the website (legitimate interests).
- To meet legal, tax, and regulatory obligations in India.
We do not sell personal data, rent it, or share it for cross-context behavioral advertising. Ever.
4. Service providers & sharing
We share personal data only with processors that help us operate: our email and newsletter platform, our hosting provider, and professional advisors under confidentiality. All processors are bound by contract to process data only on our instructions.
5. International transfers
Our team works remotely across EU, US, and Indian time zones, and service providers may process data outside your country. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses or DPDP-compliant consent.
6. Retention
Inquiry correspondence is kept for up to 24 months unless an engagement follows. Newsletter data is kept until you unsubscribe. Server logs are kept for up to 90 days. Client engagement records are retained per contract and Indian statutory requirements.
7. Your rights
Subject to applicable law, you can ask us to access, correct, erase, or port your personal data, withdraw consent, or object to processing. Residents of the EU/EEA, the United Kingdom, India, and certain US states have statutory rights we honor regardless of where you write from.
Email [email protected] and we will respond within 30 days.
8. Security
Data in transit is encrypted (TLS); access on our side requires hardware keys and least-privilege permissions. No system is perfectly secure, but we design so that a breach of this marketing site would expose essentially nothing of value.
9. Grievance officer (India)
Under the DPDP Act, our grievance officer can be reached at [email protected] or by post at the registered office above. We acknowledge grievances within 72 hours and aim to resolve them within 30 days.
10. Changes to this policy
Material changes will be announced on this page with a new “last updated” date, and by email to subscribers where the change is significant.