1. Who We Are (Data Fiduciary / Controller)
Prismport is the "Data Fiduciary" under the DPDP Act (equivalent to the "Data Controller" under the GDPR) responsible for the personal data described in this policy. If you have any questions, contact us at hello@prismport.co.
2. Information We Collect
We only collect what we need to respond to you, deliver our services, and run the Site.
a) Information you give us directly
- Contact & consultation forms — your name, email address, company, and the contents of your message when you reach out or request a consultation.
- Booking tool — when you schedule a call through our embedded scheduler (e.g., Calendly), you provide your name, email, and any details you add. This information is processed by the scheduling provider on our behalf.
- Newsletter / email updates — your email address (and optionally your name) if you subscribe to receive updates from us.
- Direct correspondence — any information you include when you email us or communicate with us over other channels.
b) Information collected automatically
- Usage & device data — via analytics tools (e.g., Google Analytics or a privacy-focused alternative), we collect aggregated, largely non-identifying information such as pages viewed, time on page, approximate location (city/country), device type, browser, and referring source.
- Cookies & similar technologies — see Section 7 below.
We do not intentionally collect sensitive personal data (such as financial account details, health, biometric, or government ID information) through the Site. Please do not submit such information through our forms.
3. How We Use Your Information
We use personal data to:
- Respond to your enquiries and provide requested information.
- Schedule and conduct consultations and discovery calls.
- Deliver, manage, and improve our services for clients.
- Send updates, newsletters, or relevant information where you have opted in (you can unsubscribe at any time).
- Understand how the Site is used so we can improve it.
- Maintain the security and integrity of the Site.
- Comply with legal obligations and enforce our agreements.
4. Legal Basis for Processing
Depending on the applicable law, we rely on one or more of the following:
- Your consent — e.g., for newsletter subscriptions and non-essential cookies. Under the DPDP Act, consent is our primary basis for processing personal data, and you may withdraw it at any time.
- Performance of a contract or steps taken at your request — e.g., responding to a project enquiry or delivering services.
- Legitimate interests — e.g., basic analytics and Site security, where not overridden by your rights (GDPR).
- Legal obligations — e.g., tax, accounting, and record-keeping requirements.
5. How We Share Your Information
We do not sell your personal data. We share it only with:
- Service providers ("Data Processors") who help us operate — for example, website hosting (Webflow), the booking/scheduler provider, analytics providers, email/newsletter platforms, and CRM or spreadsheet tools where enquiries are stored. These providers process data on our instructions and are bound to protect it.
- Professional advisors (legal, accounting) where necessary.
- Authorities, if required by law, court order, or to protect our legal rights.
- A successor entity, in the event of a merger, acquisition, or reorganisation, subject to this policy.
6. International Data Transfers
We operate from India and use service providers that may store or process data in other countries, including the EU and the US. Where personal data is transferred across borders, we take reasonable steps to ensure it is protected in line with applicable law (including, where relevant, GDPR-approved transfer mechanisms such as Standard Contractual Clauses). Transfers of personal data outside India are made in accordance with the DPDP Act and any restrictions notified by the Government of India.
7. Cookies
The Site uses cookies and similar technologies to function correctly and to understand usage:
- Essential cookies — required for the Site to work.
- Analytics cookies — help us measure and improve the Site.
- Third-party cookies — set by embedded tools such as our booking scheduler.
You can control or disable cookies through your browser settings. Disabling some cookies may affect how the Site functions. Where required by law, we request your consent before setting non-essential cookies.
8. Data Retention
We keep personal data only as long as necessary for the purposes described in this policy:
- Enquiries & correspondence — retained while we are in contact and for a reasonable period afterwards for follow-up and record-keeping.
- Client project data — retained for the duration of the engagement and as required for legal, tax, and accounting purposes.
- Newsletter subscriptions — retained until you unsubscribe.
- Analytics data — retained in aggregated form per our analytics provider's settings.
When data is no longer needed, we delete or anonymise it.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Withdraw consent at any time (this does not affect processing already carried out).
- Object to or restrict certain processing.
- Data portability — receive your data in a portable format (where applicable).
- Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act).
- Grievance redressal — raise a complaint with us about how your data is handled (DPDP Act).
For California residents (CCPA/CPRA): you have the right to know what personal information we collect, to request deletion, to correct it, and to opt out of "sale" or "sharing" of personal information. We do not sell your personal information. You will not be discriminated against for exercising these rights.
To exercise any of these rights, email us at hello@prismport.co. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting on a request.
10. Grievance Officer (DPDP Act / IT Act)
If you have concerns about how your personal data is handled, you may contact our Grievance Officer:
- Name: Shreyas Paul
- Email: [hello@prismport.co]
- Address: [Doranda Bypass Road, Ranchi, Jharkhand, India]
We will acknowledge and address complaints within the timeframes prescribed by applicable law. If you are in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
11. Data Security
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children's Privacy
The Site is not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us so we can remove it.
13. Third-Party Links
The Site may link to third-party websites (for example, client sites in our case studies). We are not responsible for the privacy practices of those sites. Please review their privacy policies separately.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated where required by law. Your continued use of the Site after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
For any questions about this Privacy Policy or your personal data:
Prismport Email: hello@prismport.co Website: prismport.co





