1. About This Policy
This Privacy Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025, and is also intended to meet the information requirements of Articles 13 and 14 of the EU/UK General Data Protection Regulation (“GDPR”), where applicable.
It describes how Protura Consultancy (“Protura”, “we”, “us”, or “our”), acting as a Data Fiduciary under the DPDP Act and as a data controller under GDPR, collects, uses, stores and protects the digital personal data of individuals (“Data Principals” or “data subjects”) who visit our website or engage with our services.
By using our website and submitting personal data, you provide your consent to the practices described in this policy. Such consent shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action.
This notice is provided in clear and plain English. You may contact us if you require it in another language listed in the Eighth Schedule to the Constitution of India.
For individuals in the European Economic Area (EEA), the United Kingdom and other jurisdictions where the GDPR applies, Protura Consultancy acts as the “data controller” of your personal data.
2. Data Fiduciary / Controller Information
Name: Protura Consultancy
Office: 4, Shrinivas Society, Bunglow, New Sharda Mandir Rd, Paldi, Ahmedabad, Gujarat 380007
Email: hello@protura.in
Phone: +91 92653 37189
Grievance Officer / Privacy Contact (DPDP):
Name: Ms. Viraj Chhelavda
Role: Grievance Officer / Privacy Contact
Email: hello@protura.in
Office Address: 4, Shrinivas Society, Bunglow, New Sharda Mandir Rd, Paldi, Ahmedabad, Gujarat 380007
In accordance with section 8(9) of the DPDP Act, Ms. Viraj Chhelavda is designated to answer questions and grievances about the processing of your personal data and to facilitate the exercise of your rights.
If and when required under Article 27 GDPR, we may appoint a representative in the European Union/United Kingdom; details will be updated in this policy if such an appointment is made.
3. Personal Data We Collect
3.1 Data You Provide Voluntarily
When you submit our contact form, we collect:
- First Name and Last Name — to identify you and address our communications.
- Email Address — to respond to your enquiry and communicate with you.
- Selected Practice Area / Service Required and Enquiry Details — to route your enquiry appropriately and understand your requirements.
You are not legally obliged to provide this personal data. However, if you choose not to provide the information requested in the contact form, we will be unable to respond to or process your enquiry.
We do not collect any personal data from individuals who merely browse the website without submitting the contact form, except as described under section 3.2 (technical and analytics data).
3.2 Data Collected by Third-Party Services (Technical and Analytics Data)
Certain third-party services embedded in our website may automatically collect technical data such as IP address, browser type, device information, operating system, and referring URL. These may include:
- GitHub Pages (hosting) — Our website is hosted on GitHub Pages. GitHub may log access data (such as IP address, user agent, and timestamps) to operate and secure the platform, under its own privacy policy.
- Google Fonts (font delivery) — When fonts are loaded, Google may receive your IP address and certain browser information to deliver fonts and ensure service security.
- Web3Forms (contact form processing) — When you submit the contact form, your submitted data (name, email, enquiry content) passes through Web3Forms’ servers before being delivered to our email inbox, acting as a technical relay/processor.
- Plausible Analytics (privacy-friendly analytics) — We use Plausible Analytics for simple, aggregated website usage statistics. Plausible is a cookieless, privacy-friendly analytics tool that does not use cookies or store individual personal profiles. It collects only minimal, non-personally identifiable, aggregated usage information.
These service providers act as our data processors under the DPDP Act and, where applicable, under GDPR, processing personal data on our documented instructions.
4. Purpose of Processing
We process your personal data only for the following lawful purposes:
- To receive, review and respond to your enquiry submitted via the contact form.
- To assess your legal requirements and offer relevant consultation or information.
- To communicate with you regarding our services, including follow-up questions and clarifications.
- To maintain records for quality, training and compliance purposes.
- To comply with applicable legal, regulatory, accounting or professional obligations.
We do not use your personal data for automated decision-making, profiling, or targeted advertising.
In addition to consent, we may process personal data where such processing is a “legitimate use” or is otherwise permitted under the DPDP Act, including where processing is necessary to comply with legal obligations or to respond to lawful requests from authorities.
4.1 Legal Basis for Processing (GDPR — where applicable)
For individuals in the EEA/UK and other GDPR jurisdictions, we rely on the following legal bases under Article 6 GDPR:
- Consent (Article 6(1)(a)) — When you submit our contact form, you consent to our processing of your name, email address and enquiry for the purposes described above.
- Legitimate interests (Article 6(1)(f)) — We process personal data as necessary to respond to and manage your enquiry, to operate and secure our website, and to manage client and prospect relationships. We balance these interests against your rights and freedoms.
- Legal obligation (Article 6(1)(c)) — We may process and retain personal data where necessary to comply with legal, regulatory, tax, accounting, or professional obligations, or to respond to lawful requests from courts or authorities.
5. Consent & Withdrawal
We process your personal data based on your consent, which is provided when you submit the contact form (for DPDP and, where applicable, GDPR purposes). You have the right to withdraw your consent at any time by contacting us at hello@protura.in.
Upon withdrawal, we will cease processing your personal data for the purposes based on consent within a reasonable time, unless further retention or processing is required by law, necessary for legal claims, or permitted as a legitimate use under the DPDP Act or as a separate lawful basis under GDPR.
Withdrawal of consent will not affect the lawfulness of processing carried out before such withdrawal.
6. Data Processors and Recipients
We engage the following service providers as data processors to support our website and service delivery:
- GitHub Pages — Website hosting and content delivery. May log access and technical data under its own privacy policy.
- Google Fonts — Font delivery service. Receives your IP address and browser information when fonts are loaded, for provision and security of the service.
- Web3Forms — Contact form processing. Receives and transmits your form submissions (name, email, enquiry) to our designated email address.
- Plausible Analytics — Privacy-friendly, cookie-free website analytics. Collects aggregated usage statistics without cookies or personal user profiles.
These data processors act on our documented instructions, are bound by confidentiality and data-protection obligations, and are not permitted to use your personal data for their own purposes.
We may also share personal data with professional advisors (e.g., auditors, lawyers) where necessary for compliance or legal claims, and with authorities, regulators, courts or law-enforcement agencies where we are required to do so by applicable law or court order.
7. Security Safeguards
We implement reasonable technical and organisational security safeguards appropriate to the nature, scope and purposes of processing, including: encryption of data in transit via SSL/TLS (HTTPS); access controls on computer resources and email systems; logging and monitoring for detection of unauthorised access; data backups and business-continuity measures; retention of relevant logs for a minimum of one year from the date of processing, or longer if required by law; and contractual provisions with data processors to ensure security, confidentiality and lawful processing.
While we take appropriate steps to protect your personal data, no system can be completely secure.
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights or interests:
- We will notify each affected Data Principal/data subject without undue delay through their registered communication channel, where feasible.
- We will intimate the Data Protection Board of India within seventy-two (72) hours of becoming aware of the breach, in accordance with the DPDP Act and Rules.
- Where GDPR applies, we will notify the competent supervisory authority within the time limits prescribed by GDPR, and affected data subjects where required.
Our notification will include information on the nature of the breach, categories and approximate number of affected individuals, likely consequences, and the measures taken or proposed to address the breach.
9. Data Retention
We erase personal data upon withdrawal of consent or when the specified purpose is no longer served, whichever is earlier, unless longer retention is required or permitted by law or necessary to establish, exercise or defend legal claims.
For enquiry-related data, we generally retain personal data for up to 12 months after our last interaction with you, unless we are required by law or professional regulations to retain it for a longer period, or retention is necessary in relation to potential or ongoing legal proceedings.
Processing logs and associated technical data are retained for a minimum of one year from the date of processing, or longer where required by applicable law or regulations.
10. Your Rights
Depending on the law applicable to you (DPDP Act, GDPR or other local law), you may have some or all of the following rights. We will respond to such requests in accordance with applicable law and within prescribed timelines.
Under the DPDP Act (India), you have:
- Right to Access — To obtain a summary of your personal data being processed and the identities or categories of third parties to whom it has been shared.
- Right to Correction and Erasure — To request correction of inaccurate data, completion of incomplete data, or erasure of your personal data where permitted by law.
- Right of Grievance Redressal — To have grievances addressed through our grievance redressal mechanism within a reasonable period not exceeding ninety (90) days.
- Right to Withdraw Consent — To withdraw your consent at any time for future processing.
- Right to Nominate — To nominate another individual to exercise your rights in the event of your death or incapacity.
Under the EU/UK GDPR (where applicable), you additionally have:
- Right of access — To obtain confirmation whether we process your personal data and to receive a copy of that data.
- Right to rectification — To have inaccurate or incomplete personal data corrected.
- Right to erasure (“right to be forgotten”) — To request deletion of your personal data in certain circumstances.
- Right to restriction of processing — To request that we restrict processing in certain situations.
- Right to data portability — To receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible.
- Right to object — To object, on grounds relating to your particular situation, to processing based on legitimate interests. You also have an absolute right to object to direct marketing (which we do not currently perform).
- Right to lodge a complaint — To lodge a complaint with your local data protection supervisory authority, without prejudice to any other remedy.
To exercise your rights or raise any concerns, please contact our Grievance Officer / Privacy Contact at hello@protura.in.
You are expected to first use our grievance redressal mechanism before approaching the Data Protection Board of India, as envisaged under the DPDP Act.
11. Transfer Outside India and International Transfers
Your personal data may be processed and stored on servers located outside India by our data processors or other recipients, subject to restrictions and conditions specified by the Government of India and applicable rules under the DPDP Act.
Where GDPR applies and your personal data is transferred outside the EEA/UK (for example, to service providers located in India or other countries including the United States), we will ensure that such transfers are carried out in compliance with GDPR, including by transferring to countries with an adequacy decision where applicable, using appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent transfer mechanisms, or relying on other permitted derogations under GDPR in limited cases.
You may contact us for further information on the specific transfer safeguards that apply to your data.
12. Children’s Data
Our website and services are not directed at children (individuals under 18 years). We do not knowingly process children’s personal data. We will not undertake tracking, behavioural monitoring, profiling or targeted advertising directed at children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete such data as soon as reasonably practicable.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, guidance, our processing activities or our services. Material changes will be indicated by updating the “Last Updated” date at the top of this policy and, where appropriate, we may provide additional notice (such as a banner on our website). You are encouraged to review this Policy periodically.
14. Contact Us
Protura Consultancy
Grievance Officer / Privacy Contact: Ms. Viraj Chhelavda
Email: hello@protura.in
Phone: +91 92653 37189
Office: 4, Shrinivas Society, Bunglow, New Sharda Mandir Rd, Paldi, Ahmedabad, Gujarat 380007
We will endeavour to acknowledge your request or grievance promptly and to resolve it within the timelines required by applicable law.