Privacy Policy
Last updated: July 2026 covering our obligations under India's DPDP Act, the EU/UK GDPR and the California CCPA/CPRA.
1. Introduction & scope
This Privacy Policy explains how VEDELAM ("VEDELAM", "we", "us" or "our"), headquartered in Gurugram, India, collects, uses, stores, discloses and protects information relating to visitors of vedelam.com and to individuals connected with our clients, prospects and vendors. This Policy applies wherever you are located including India, the United States, the United Kingdom and the European Economic Area and is drafted to meet the requirements of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, as well as, where applicable to visitors from those regions, the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
2. Information we collect
We collect information in three ways: (a) information you provide directly, such as your name, company, email address, phone number, project brief and any files you share through our contact form or during an engagement; (b) information collected automatically, such as IP address, device and browser type, referring page, pages viewed and approximate location, gathered through cookies, pixels and analytics tools; and (c) information from third parties, such as publicly available business information or data shared by a client about their own end users where we act as a service provider on their behalf.
3. How we use your information
We use personal information to: respond to enquiries and provide quotes; deliver, operate and improve our services; manage contracts, invoicing and account administration; send service updates, case studies or marketing communications (with an opt-out available at any time); detect, prevent and investigate fraud, abuse or security incidents; and comply with applicable legal, tax and regulatory obligations in India and other jurisdictions in which we or our clients operate.
4. Legal basis for processing (international users)
Where the GDPR applies, we rely on one or more of the following legal bases: performance of a contract with you or your organisation; our legitimate interests in operating, promoting and securing our business, balanced against your rights; your consent, for example for marketing emails or non-essential cookies, which you may withdraw at any time; and compliance with a legal obligation. Under India's DPDP Act, we process personal data on the basis of your consent or for other lawful purposes such as compliance with law, response to a medical emergency, or performance of a contract, as permitted under the Act.
5. Cookies & tracking technologies
Our website uses cookies, local storage and similar technologies for essential site functionality, analytics (e.g. understanding traffic and engagement) and, where enabled, marketing attribution. You can control or disable cookies through your browser settings; doing so may limit some functionality. Where required by applicable law (including the GDPR's ePrivacy rules), we will request your consent before setting non-essential cookies.
6. How we share information
We do not sell personal information. We may share information with: trusted service providers who process data on our behalf under written agreements (e.g. hosting, email delivery, analytics, payment processing, CRM); professional advisors such as auditors, lawyers and insurers; a successor entity in the event of a merger, acquisition or asset sale, subject to equivalent protections; and law enforcement, regulators or courts where disclosure is required or permitted by applicable law, including the IT Act, 2000 and rules made thereunder.
7. International data transfers
As a studio serving clients across India, the United Kingdom and the United States, personal information may be transferred to, stored and processed in countries other than your own, including India, the United States and countries within the European Economic Area. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision. Where we transfer data out of India, we do so in a manner consistent with the DPDP Act and any notified restrictions on cross-border transfer.
8. Data retention
We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Policy including the duration of a client engagement plus any period required to meet legal, accounting, tax or dispute-resolution obligations (which in India can extend up to the applicable limitation period under the Limitation Act, 1963) after which it is securely deleted or anonymised.
9. Data security
We implement reasonable technical and organisational security practices and procedures, consistent with the standards referenced under the IT Act, 2000 and its rules, including access controls, encryption in transit, and restricted internal access to personal data on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your rights
Depending on where you are located, you may have rights to: access the personal data we hold about you; correct or update inaccurate data; request erasure of your data; withdraw consent at any time; object to or restrict certain processing; receive a copy of your data in a portable format; and nominate another individual to exercise your rights in the event of death or incapacity, or lodge a complaint with a supervisory authority. Indian residents may exercise these rights under the DPDP Act, 2023 by contacting our Grievance Officer below; EU/UK residents may exercise GDPR rights and lodge a complaint with their local data protection authority; California residents may exercise CCPA/CPRA rights, including the right to know, delete, correct and opt out of the sale or sharing of personal information (we do not sell personal information).
11. Children's privacy
Our website and services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Third-party links
Our website may link to third-party sites, including client work samples and social platforms. We are not responsible for the privacy practices of those sites, and we encourage you to review their policies independently.
13. Grievance Officer & Data Protection contact
In accordance with the Information Technology Act, 2000, the rules made thereunder, and the Digital Personal Data Protection Act, 2023, VEDELAM has designated a Grievance Officer to address privacy-related complaints from users in India. You may reach the Grievance Officer, and any data protection query from any jurisdiction, at mail@vedelam.com. We aim to acknowledge grievances within 24 hours and resolve them within 15 days, consistent with applicable Indian regulatory timelines.
14. Changes to this policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. Material changes will be indicated by updating the "last updated" date on this page, and where required by law, we will provide additional notice.
15. Contact us
For any questions about this Privacy Policy or how we handle your data, contact us at mail@vedelam.com or write to us at 43, Damdama Lake Road, Sohna, Gurugram, Haryana, India.
