Endorphyn Web
← Back to siteGet a free mockup →
Legal

Privacy Policy

Last updated: 1 June 2025  ·  Effective: 1 June 2025  ·  Applies to: endorphynweb.com

Endorphyn Web, operated by Shivansh Chawla, Gurugram, Haryana, India ("we", "us", "our"), is committed to protecting your personal data. This Privacy Policy explains what data we collect, why, how we use it, and your rights over it.

This policy complies with the EU General Data Protection Regulation (GDPR 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act 2023 (DPDP Act).

1. Data we collect

1.1 Data you provide directly

  • Name, email address, phone number (when you submit a form)
  • Business name, business type, current website URL
  • Messages, project briefs, and files you send us
  • Payment references (Wise / Payoneer transaction IDs — we never store card numbers)

1.2 Data collected automatically

  • IP address (anonymised before storage via GA4 anonymize_ip)
  • Browser type, OS, device type, screen resolution
  • Pages visited, time on site, scroll depth, referral source
  • UTM parameters (source, medium, campaign, term, content, gclid, fbclid)
  • Session recordings and heatmaps via Microsoft Clarity (anonymised — no keystrokes or personal content recorded)

1.3 Cookies

See our Cookie Policy for full details. All non-essential cookies (analytics, marketing) load only after you accept via our consent banner.

2. Why we collect your data (legal basis)

PurposeLegal basis (GDPR)
Respond to enquiries and deliver servicesContract performance / Legitimate interests
Send the requested free mockupContract performance
Website analytics (GA4, Clarity)Consent
Marketing / retargeting (Meta Pixel)Consent
Invoicing and tax recordsLegal obligation
Fraud prevention and site securityLegitimate interests

3. How we share your data

We do not sell your personal data. We share it only with the following sub-processors, each bound by data processing agreements:

ProcessorPurposeLocation
Web3FormsForm submission processingUS
Google (GA4 / GTM)Analytics — anonymisedUS (SCCs in place)
Meta PlatformsMarketing pixel / retargetingUS (SCCs in place)
Microsoft ClaritySession analytics — anonymisedUS (SCCs in place)
Zoho CorporationEmail hosting and CRMIN / US
CloudflareWebsite hosting, CDN, DDoS protectionUS (SOC 2 certified)
Wise / PayoneerPayment processing (reference only)UK / US

4. International data transfers

Your data may be transferred to countries outside your own, including the United States and India. Transfers from the EEA / UK are protected by EU Standard Contractual Clauses (SCCs) or UK adequacy decisions where applicable.

5. Data retention

  • Enquiry form submissions: 24 months from submission
  • Client project records: 7 years (tax/legal compliance)
  • Email correspondence: 3 years
  • GA4 analytics data: 14 months (Google default)
  • Microsoft Clarity sessions: 30 days

After retention periods, data is permanently deleted or irreversibly anonymised.

6. Your rights

GDPR / UK GDPR (EU / UK residents): Right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to automated processing.

CCPA (California residents): Right to know, right to delete, right to opt out of sale (we do not sell data), right to non-discrimination.

DPDP Act (India): Right to access personal data, correction, erasure, and grievance redressal. Right to nominate a representative. Requests responded to within 15 business days.

To exercise any right: email shivansh@endorphynweb.com with subject line "Privacy Request". We respond within 30 days (15 business days for DPDP requests).

7. Grievance Redressal Officer (DPDP Act, India)

Name: Shivansh Chawla
Email: shivansh@endorphynweb.com
Response time: Within 15 business days of receipt.

8. Security

We implement HTTPS/TLS encryption on all pages, restricted access to personal data, regular security reviews, and use only SOC 2-certified or equivalent hosting infrastructure. No method of internet transmission is 100% secure, but we take all commercially reasonable measures to protect your data.

9. Children

Our website is not directed at anyone under 18. We do not knowingly collect data from minors. If you believe we have done so, contact us immediately and we will delete the data promptly.

10. Changes to this policy

We may update this policy. Material changes will be flagged by updating the "last updated" date at the top of this page. For significant changes affecting how we use personal data, we will notify active clients by email.

11. Contact

Questions about this policy: shivansh@endorphynweb.com. We aim to respond within 2 business days.

© 2025 Endorphyn Web · Privacy · Terms · Cookies · Refund Policy

🍪 We use cookies

Analytics cookies help us improve this site. Accept to enable.

Manage preferences →