POLICIES & INFORMATION

India data protection (DPDP)

How we handle personal data connected with India, the DPDP rollout, your choices and the route for privacy requests.

Last updated · 31 August 2026 · Version 2026-08-31.3
On this page

Who this page covers

LucidGrowth Media Private Limited operates this website as Lucid Growth Media. Our office is WeWork Embassy TechVillage, Block L, Devarabisanahalli, Outer Ring Rd, Bellandur, Bangalore, Karnataka 560103, India. Contact legal@lucidgrowthmedia.com about personal data.

This page explains our approach to India's Digital Personal Data Protection Act, 2023 and final DPDP Rules, 2025. Read it with our Privacy notice and Cookie information for the website's detailed data practices. Client projects may need separate notices and written processing terms.

We decide why and how website enquiry and subscription information is used. In DPDP terminology, that is the Data Fiduciary role when the relevant provisions apply. When we process a client's data on documented instructions, our role and responsibilities depend on that engagement; a client agreement does not remove our own legal duties.

The law is being introduced in phases

As of 31 August 2026, the DPDP framework is only partly in force. The official commencement notification and final Rules set the following stages.

The later dates do not suspend privacy, security, contractual or other duties that already apply. This page does not claim that all future DPDP duties are active today or that publishing a policy establishes compliance. The notifications and any later amendments govern.

  • 13 November 2025: foundational provisions, including provisions establishing the Data Protection Board, and Rules 1, 2 and 17–21 commenced.
  • 13 November 2026: the specified consent-manager provisions and Rule 4 are scheduled to commence. Our website privacy controls are not represented as a registered Consent Manager.
  • 13 May 2027: most processing duties and individual rights, including the main notice, consent, security and grievance framework, and Rules 3, 5–16 and 22–23 are scheduled to commence.

Information and purposes

You can read the website without sending an enquiry or joining the newsletter. Please provide only information you are entitled to share. Do not send passwords, payment-card details, identity documents, health records, children's data or confidential client datasets through public forms.

  • Enquiries: the form requires your name, email, organisation, phone details, requested services and project information to help us understand the request, respond, arrange relevant contact and prepare a proposal. It also asks about timing.
  • Newsletter: email and first and last names are collected on final submission with a separate affirmative subscription choice. An enquiry is not a newsletter signup.
  • Privacy choices: a browser reference, selected categories, notice version, time and related technical evidence help us remember and demonstrate your choice and prevent abuse.
  • Website delivery and security: hosting and security services process technical request information needed to deliver the site and protect its forms. Optional device identification is subject to the separate choice explained below.

Permission is specific to its purpose

Where the DPDP processing framework applies and is in force, processing must be supported by consent or a legitimate use specifically provided by that Act. We do not treat a general business interest as blanket permission for unrelated use.

Newsletter permission and optional browser-feature choices are separate. Neither browsing, sending an enquiry nor agreeing to website terms gives permission for undisclosed tracking, unrelated marketing or AI model training.

You may refuse optional processing without losing access to ordinary website content or the enquiry form. If you ask us to stop processing information needed to answer your enquiry, we may be unable to continue that request. We will explain the practical effect and any lawful reason for limited retention.

Optional device identification and privacy choices

Optional device identification must remain off unless you affirmatively allow its stated purpose in Privacy choices. Any identifier is limited to the browser attributes disclosed in our Privacy notice. It is not permission to collect canvas or audio fingerprints, font inventories, deep hardware information or an unrestricted record of your activity.

A pseudonymous identifier may still relate to a person. It is not a verified identity or a guarantee of anonymity. It does not reveal your email address unless you separately provide information that can be associated with the record.

Use Privacy choices in the footer to refuse or withdraw optional processing. The preference cookie lasts up to 180 days on that browser; evidence of a recorded choice is kept for up to 730 days, subject to a documented legal preservation duty. These are our retention settings, not universal DPDP periods. Withdrawal stops future optional processing but does not recall data already lawfully received by an external provider.

Providers, retention and security

Cloudflare provides website and network services and the D1 database used for application records. Its infrastructure operates globally; we do not promise that all data stays in India. We must assess any applicable transfer restriction and any location requirement agreed for a client project.

Our Privacy notice gives the record-specific retention periods, provider disclosures and deletion limits. Expired application records are removed through scheduled processes. Limited legal, dispute or suppression records may need separate retention; backups and provider logs follow their applicable lifecycles. A consent record is not permission to retain every associated form indefinitely.

We use proportionate access restrictions, encrypted connections and server-side checks. No system eliminates all risk. We assess suspected incidents and make notifications where the applicable law requires them. The later DPDP security and breach rules require operational preparation as well as written notices.

Requests you can make now and DPDP rights

You can contact legal@lucidgrowthmedia.com now to ask about information you supplied, request correction or deletion, withdraw a permission, or raise a privacy concern. Include the email used, the type of request and enough context to locate the record. We may verify your identity or authority using proportionate information; please do not send identity documents unless we explain why they are needed.

The main DPDP rights phase is scheduled for 13 May 2027. Subject to the Act's scope, conditions and exceptions, it includes a summary of personal data and processing, information about relevant recipients, correction and erasure, grievance redressal, and nomination of another individual to exercise rights following death or incapacity.

Newsletter withdrawal is available through Newsletter preferences or support@lucidgrowthmedia.com. Changing a browser privacy choice does not itself withdraw a newsletter request or erase an enquiry. We will explain any lawful limitation on a request; deleting all evidence immediately is not always appropriate or legally possible.

Complaints and responsible contact

Send privacy concerns to legal@lucidgrowthmedia.com or our office address above. This is our company contact route. We do not describe it as a named Data Protection Officer or claim a registration or appointment that has not been established.

We will review your concern, explain any verification needed and respond within the applicable legal period. Where the DPDP grievance and Board procedures apply and are in force, the Act requires the opportunity for grievance redressal with the Data Fiduciary to be exhausted before approaching the Board.

Nothing on this page removes a mandatory complaint or statutory remedy. A Jaipur contractual forum clause does not displace the Data Protection Board, another competent authority or any forum that the law requires.

Children and updates

Our public business forms are intended for adults. Please do not submit information about a person under 18. Tell us if such information has been provided so that we can assess and remove it where appropriate. We do not use these forms to solicit children's profiles or targeted advertising.

We review this page as the law and our systems change. A policy update alone does not authorize a new purpose that needs fresh consent. Material changes to collection, optional identification, providers or retention must be reflected in the relevant notice and controls.