Legal

Privacy Policy

How Storifex Media LLP collects, uses, shares, protects and retains personal data, the legal bases we rely on, and the rights you have under the DPDP Act 2023, the GDPR, the UK GDPR and the CCPA.

Effective
15 August 2026
Last updated
15 August 2026
Version
3.1
Entity
Storifex Media LLP
On this page22
01

Introduction and who we are

Storifex Media LLP ("Storifex Media", "we", "us" or "our") is committed to protecting the privacy of everyone who visits storifexmedia.com or contacts us. This Privacy Policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights and choices available to you.

For the purposes of this policy, we act as the "data controller" under the EU and UK GDPR, and as the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). This means we determine why and how your personal data is processed.

Contact for privacy matters: Storifex Media LLP, H. No. 84, At Po. Antule Nagar (Andharwadi), Hingoli, Hingoli - 431513, Maharashtra, India. Email: hello@storifexmedia.com. Our designated Grievance Officer is named in the "Complaints and Grievance Officer" section below.

Note

This policy covers our website and enquiry channels. Personal data processed during a paid engagement is governed additionally by your signed services agreement and its data-processing terms, which prevail in case of conflict for that engagement.

02

Key terms

TermMeaning
Personal dataAny information relating to an identified or identifiable natural person, called a Data Principal (DPDP Act) or data subject (GDPR).
ProcessingAny operation performed on personal data, such as collection, storage, use, disclosure or erasure.
Controller / Data FiduciaryThe party that determines the purposes and means of processing. That is us.
Processor / Data ProcessorA party that processes personal data on the controller's behalf, such as our hosting or email providers.
ConsentA freely given, specific, informed and unambiguous indication of your agreement to processing for a stated purpose.
DPDP ActThe Digital Personal Data Protection Act, 2023 (India) and rules made under it.
GDPR / UK GDPRRegulation (EU) 2016/679 and its UK equivalent, with the Data Protection Act 2018.
03

Scope and application

This policy applies to visitors and prospective clients worldwide. Because we operate from India and work with clients internationally, several data protection regimes may apply to you depending on where you are located:

  • If you are in India, the DPDP Act 2023 and the Information Technology Act, 2000 with its rules apply.
  • If you are in the European Economic Area, the EU GDPR applies.
  • If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply.
  • If you are a California resident, the CCPA (as amended) applies, and a dedicated section below sets out your rights.

Where regimes differ, we apply the protections required by the law applicable to you.

04

Personal data we collect

We collect only the data we need for the purposes described in this policy. We do not intentionally collect special-category or sensitive personal data through the website, and we ask that you do not submit it in the enquiry form.

CategoryExamplesSource
Identity and contact dataYour name, the company you represent, your work email addressYou, via the enquiry form
Enquiry detailsThe services you are interested in, indicative budget range, and the contents of your messageYou, via the enquiry form
CommunicationsEmails and messages you exchange with us and our repliesYou and us
Technical and usage dataIP address, browser and device type, operating system, referring pages, pages requested, and timestampsCollected automatically by our hosting provider
Consent and preferencesYour cookie choices and similar settingsStored on your device
Unsent form answersA part-finished answer to one of our forms, kept so you can close the page and come back to itYou, and it stays on your device until you submit the form
Billing and transaction dataThe billing name and address on your invoice, the invoice and payment reference, the amount, the currency, the date, the method used and the last four digits and card type our payment provider reports back to usYou, and our payment provider

Note

We never see, handle or store your full card number, expiry date or CVV. Card and UPI details are entered on pages served by a PCI-DSS compliant payment provider and go straight to them. What comes back to us is enough to match a payment to an invoice and to refund it, and no more.

05

How we collect your data

Directly from you

When you complete our enquiry form, email us, or otherwise communicate with us, you provide the identity, contact, enquiry and communications data above.

Automatically

When you visit the site, our hosting provider automatically logs limited technical data for security, reliability and diagnostics. We and any tools you consent to may store small amounts of data on your device, as described in our Cookie Policy.

From third parties

We do not buy personal data or build profiles from third-party sources. If a mutual contact refers you, we only process what they and you choose to share for the purpose of responding.

06

Purposes and legal bases

We process personal data only where we have a lawful basis to do so. The table maps each purpose to its basis under the GDPR and the corresponding lawful ground under the DPDP Act.

PurposeData usedGDPR basisDPDP basis
Respond to and evaluate your enquiryIdentity, enquiry details, communicationsLegitimate interests; steps taken at your request prior to a contractConsent / certain legitimate uses
Send proposals and follow up with youIdentity, contact, communicationsLegitimate interests; consentConsent
Operate, maintain and secure the websiteTechnical and usage dataLegitimate interestsLegitimate use
Load optional cookies and embedded contentUsage data; consent recordConsentConsent
Meet legal, tax and accounting obligationsAs requiredLegal obligationLegal obligation / compliance
Establish, exercise or defend legal claimsAs relevantLegitimate interestsLegitimate use / legal purpose

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object at any time (see your rights below). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

07

Cookies and similar technologies

We use a minimal set of cookies and local storage. Non-essential cookies, including any third-party embedded content that sets cookies, load only after you consent through our cookie banner. Our Cookie Policy sets out each item we use, its purpose and duration, and how to change your choice at any time.

08

How we share and disclose data

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We share it only with the categories of recipient below, and only as needed for the purposes in this policy:

RecipientRole and purposeLocation
Brevo (Sendinblue GmbH / Brevo SA)Processor. Stores enquiry submissions in our CRM and sends our transactional email notifications.European Union
Vercel Inc.Processor. Hosts the website and content-delivery network, and processes server and security logs.United States and global edge network
Cloudflare, Inc.Processor. Runs the Turnstile bot check on our forms, which processes your IP address and browser signals to tell a person from a script. No advertising use.United States and global edge network
Embedded client websiteThird-party content shown as an optional live preview. Loads only with your Functional-cookie consent and is operated by the client.As operated by that client
Google (Google Analytics 4)Processor. Measures how the site is used, which pages are read and roughly where visitors come from. The tag loads on every page, so Google receives your IP address and the page address, but it runs in a denied state that stores nothing and identifies nobody until you enable Analytics cookies. We do not use it for advertising, we do not link it to any ad account, and advertising storage is refused outright whatever you choose.United States and global
Payment providersProcessors. Take card, UPI, net-banking and bank-transfer payments, run fraud checks required of them, and process refunds and chargebacks. They receive your card or account details directly and we do not.India, European Union and United States
Professional advisersLawyers, accountants and auditors, where reasonably required.India and elsewhere as engaged
Authorities and acquirersRegulators, courts or law-enforcement where legally required, and a buyer in the event of a business transfer.As applicable

Our processors act only on our documented instructions under written contracts that require appropriate security and confidentiality. We may also disclose data where required by law, to enforce our terms, or to protect the rights, property or safety of Storifex Media, our clients or others.

09

International data transfers

We operate from India and use service providers located in other countries, including the European Union and the United States. This means your personal data may be transferred to, stored in, or accessed from a country other than your own.

Where we transfer personal data out of the EEA or the UK, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), transfers to a country with an adequacy decision, or another lawful transfer mechanism. Under the DPDP Act, we may transfer personal data outside India except to any country restricted by the Central Government. You can request details of the safeguards we use by contacting us.

10

How long we keep your data

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, tax, accounting or reporting requirements. When data is no longer needed, we delete or irreversibly anonymise it. Our indicative retention periods are:

DataRetention periodRationale
Enquiry and contact dataUp to 24 months after your last contact, unless a client relationship beginsTo evaluate and pursue a potential engagement
Client relationship recordsDuration of the engagement plus up to 8 yearsContractual, tax and accounting obligations
Invoices, payment and refund records8 years from the end of the relevant financial yearMandatory under Indian tax and accounting law, and needed to defend a chargeback
Email delivery logs (Brevo)Up to 24 monthsDeliverability, security and dispute resolution
Server and security logsUp to 12 monthsSecurity, fraud prevention and diagnostics
Cookie consent recordUp to 12 months, then we ask againEvidence of your consent

You can ask us to delete your data sooner, subject to any legal obligation we have to retain it.

11

Your rights

Subject to the law applicable to you, you have the following rights over your personal data:

  • Access: obtain confirmation of whether we process your data, a copy of it, and a summary of the processing.
  • Correction and completion: have inaccurate or incomplete data corrected or updated.
  • Erasure: request deletion of your data where it is no longer needed or where you withdraw consent, subject to legal retention.
  • Withdraw consent: withdraw any consent you gave, as easily as you gave it, without affecting prior processing.
  • Restriction and objection (GDPR / UK GDPR): restrict or object to processing based on legitimate interests, and object to direct marketing at any time.
  • Data portability (GDPR / UK GDPR): receive certain data in a structured, commonly used, machine-readable format.
  • Grievance redressal (DPDP Act): a readily available means to raise a grievance with us about our handling of your data.
  • Nomination (DPDP Act): nominate another individual to exercise your rights in the event of death or incapacity.
  • Non-discrimination: we will not treat you unfairly for exercising your rights.
12

How to exercise your rights

To exercise any right, email hello@storifexmedia.com with enough detail for us to identify you and understand your request. We may ask for information to verify your identity before we act, to protect your data. We do not charge a fee unless your request is manifestly unfounded, excessive or repetitive.

We respond within the timeframe required by applicable law (generally within 30 days under the GDPR and UK GDPR, extendable for complex requests, and within the timeframes prescribed under the DPDP Act). If we cannot act on your request, we will explain why and tell you how to appeal or complain.

13

Automated decision-making and profiling

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling or targeted advertising through this website.

14

How we protect your data

We maintain reasonable technical and organisational security measures appropriate to the risk, consistent with the reasonable security practices expected under Indian law and the accountability requirements of the GDPR. These include encryption of data in transit (HTTPS), access controls and least-privilege access, use of reputable processors bound by contract, and regular review of our providers.

No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.

15

Data breach notification

If a personal data breach occurs, we will assess it and, where required by law, notify the competent authority and affected individuals within the applicable timeframes. Under the DPDP Act this includes intimation to the Data Protection Board of India and affected Data Principals; under the GDPR and UK GDPR this generally means notifying the relevant supervisory authority within 72 hours where the breach is likely to result in a risk to individuals.

16

Children's data

Our website and services are directed at businesses and are not intended for children. Under the DPDP Act we do not knowingly process the personal data of anyone under 18 without verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Under the GDPR the relevant age of digital consent is 16 (or lower where a member state provides). If you believe a child has provided us personal data, contact us and we will delete it.

17

Marketing communications

We contact you about your enquiry as part of responding to it. We send marketing communications only where we are permitted to do so, and you can opt out at any time using the unsubscribe link in any such message or by emailing us. Opting out of marketing does not stop service-related messages about an active enquiry or engagement.

19

California privacy rights (CCPA)

If you are a California resident, the California Consumer Privacy Act, as amended, gives you the right to know the categories and specific pieces of personal information we collect and the purposes; to request deletion or correction; to opt out of the sale or sharing of personal information; and not to be discriminated against for exercising these rights.

We do not sell or share personal information as those terms are defined under the CCPA. The categories we collect and our purposes are described in the sections above. To exercise a request, email hello@storifexmedia.com. We will verify your request and respond as required by law, and you may use an authorised agent.

20

Changes to this policy

We may update this policy to reflect changes in our practices or the law. The version and effective date at the top of the page show when it last changed. For material changes we will take reasonable steps to bring them to your attention, such as a notice on the site. Please review this page periodically.

21

Complaints and Grievance Officer

If you have a concern about how we handle your personal data, please contact our Grievance Officer first so we can try to resolve it: Nitesh Padghan, Storifex Media LLP, H. No. 84, At Po. Antule Nagar (Andharwadi), Hingoli, Hingoli - 431513, Maharashtra, India. Email: hello@storifexmedia.com. We aim to acknowledge grievances promptly and resolve them within the timeframes required by applicable law.

You also have the right to complain to a data protection authority: in India, the Data Protection Board of India; in the EEA, your local supervisory authority; and in the UK, the Information Commissioner's Office (ICO).

22

Contact us

Storifex Media LLP, H. No. 84, At Po. Antule Nagar (Andharwadi), Hingoli, Hingoli - 431513, Maharashtra, India. For any question about this policy or your personal data, email hello@storifexmedia.com.

Questions

Something here unclear?

Write to us and a human answers — data requests, contract questions, or anything in this document you want explained in plain language.

Other documents

Contact and business details

Storifex Media LLP, H. No. 84, At Po. Antule Nagar (Andharwadi), Hingoli, Hingoli - 431513, Maharashtra, India. This document is provided for general information and is not legal advice; please consult a qualified professional for advice specific to your circumstances.