Privacy Policy
Last Updated: July 18, 2026
1. INTRODUCTION & ACCEPTANCE
Welcome to the official website of **RoasBodhi** (accessible at https://roasbodhi.in). This Privacy Policy document governs the data collection, processing, and storage practices of **Namaste Sales Enterprises** (doing business as "RoasBodhi", hereinafter referred to as "the Company", "we", "us", or "our"). We are committed to protecting the personal data and privacy of our visitors, clients, and partners in strict compliance with the **Digital Personal Data Protection Act, 2023 (DPDP Act)**, the **Information Technology Act, 2000**, the **Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules)**, and where applicable, the **General Data Protection Regulation (GDPR)**.
By accessing our website, subscribing to our services, or submitting inquiry forms (including ad audits, calculator inputs, or WhatsApp widgets), you explicitly accept and agree to all the terms outlined in this Privacy Policy. If you do not agree to these terms, you must immediately cease all access and use of our platform.
Our services are strictly intended for individuals who are **at least 18 years of age** or have reached the age of majority in their respective jurisdiction. If you are under the age of 18, you may only access this website under the direct supervision of a parent or legal guardian who accepts full responsibility for your actions and data submissions.
2. INFORMATION WE COLLECT
2A. Information You Provide Directly
We collect information that you voluntarily submit to us through forms, contact points, and direct messaging channels. This includes:
- **Contact Information:** Your full name, email address, mobile phone number, and WhatsApp number.
- **Business Demographics:** Your corporate entity name, sector/industry type, geographical location, operational budget estimates, and current digital marketing benchmarks.
- **Payment Details:** All payment processing is handled securely by our integrated partner, **Razorpay**. We do not collect, capture, or store your credit card, debit card, or net banking credentials on our local servers.
- **Communication Logs:** Transcripts of any emails sent to roasbodhi@gmail.com, phone calls, or WhatsApp chats initiated through our custom widgets.
2B. Information Collected Automatically
When you browse our platform, certain technical indicators are automatically recorded by our hosting infrastructure and analytics pipelines:
- **Technical Identifiers:** Your Internet Protocol (IP) address, device browser type, operating system version, and system language settings.
- **Behavioral Data:** Pages visited, duration of visit per URL, scroll depth, button click events, and landing page interaction tracking.
- **Tracking Pixels & Analytics:** Integration tags from **Google Analytics 4 (GA4)**, **Google Tag Manager**, **Microsoft Clarity**, and the **Meta Pixel** to optimize ad delivery and performance metrics.
2C. Information from Third Parties
We may obtain supplementary data from commercial directories, business partners, public records, and social media platforms (such as LinkedIn or Facebook profiles) to enrich prospect profiles and tailor our marketing campaigns.
3. HOW WE USE YOUR INFORMATION
We process your personal data strictly for legitimate business objectives and services. Specifically, we utilize your information to:
- Configure and manage your ad accounts and custom website previews.
- Analyze business operational inputs inside our ROAS calculator tool.
- Process payments and subscription renewals via secure payment portals.
- Deliver weekly and monthly performance analytics dashboards.
- Address client queries, service tickets, and feedback requests.
- Send newsletters, promotional codes, and marketing updates (with your consent).
- Run personalized retargeting campaigns across Meta, Google, and YouTube networks.
- Prevent, detect, and mitigate fraudulent activities or security breaches.
- Optimize site layouts and server delivery rates using traffic data.
- Host local SEO schemas customized with target regional parameters.
- Issue tax invoices and comply with local accounting/auditing mandates.
- Comply with warrants, court decrees, and inquiries from law enforcement authorities.
- Defend the company against contractual breach claims, IP disputes, or consumer complaints.
- Conduct internal audits, research, and analysis to upgrade service packages.
- Notify you regarding revisions to this Privacy Policy or our Terms of Service.
4. LEGAL BASIS FOR PROCESSING (DPDP ACT COMPLIANT)
In compliance with Section 6 of the DPDP Act 2023, the Company processes personal data only based on the following valid grounds:
- **Consent:** When you explicitly opt-in, submit inquiry forms, or engage with our WhatsApp widget. Consent must be free, specific, informed, unconditional, and unambiguous. You retain the right to withdraw this consent at any moment.
- **Contractual Obligation:** When processing is necessary to execute the service agreement, construct web previews, or deliver ad campaign setups.
- **Legal Compliance:** When required by applicable Indian statutes, including accounting laws, taxation rules (GST), and regulatory directives.
- **Legitimate Interests:** To protect our platform from cybercrime, secure internal systems, and communicate updates.
5. DATA SHARING AND DISCLOSURE
We strictly enforce a policy of **not selling, trading, or renting** your personal data to third-party data brokers or marketing agencies. Your data is shared only under the following controlled circumstances:
- **Service Providers:** We share necessary fragments of data with trusted infrastructure partners (hosting platforms, CRM tools, payment processors like Razorpay, and communication channels like WhatsApp Business APIs) who operate under strict non-disclosure obligations.
- **Legal Mandate:** We disclose information if required under Section 69 of the IT Act, 2000, or by judicial orders to aid investigation of cyber activities or fraud.
- **Corporate Transfers:** If the Company undergoes a merger, acquisition, asset sale, or restructuring, client records will be transferred to the successor entity.
6. THIRD-PARTY SERVICES WE USE
We integrate with several third-party services for operations. We recommend reviewing their respective privacy policies to understand their data processing structures:
- **Cloudflare (CDN & Security):** Cloudflare Privacy Policy
- **Google Services (Analytics/Tag Manager):** Google Privacy Policy
- **Meta Business (Pixel & Custom Audiences):** Meta Privacy Policy
- **Microsoft Clarity (Heatmaps):** Microsoft Privacy Statement
- **Razorpay (Payment Gateway):** Razorpay Privacy Policy
- **WhatsApp Business API:** WhatsApp Legal Terms
7. DATA SECURITY MEASURES
The Company implements reasonable security practices as defined under Section 43A of the IT Act, 2000 and the SPDI Rules, 2011:
- **Encryption:** All data transit between your device and our servers is secured using industry-standard **256-bit Secure Socket Layer (SSL)** encryption.
- **Network Defense:** Real-time web application firewall (WAF) rules deployed via Cloudflare to block DDoS attacks, sql injections, and automated bots.
- **Access Control:** Strict role-based database access, requiring multi-factor authentication (MFA) for administrative roles.
- **Breach Protocols:** In the event of a security compromise affecting personal data, we will notify the **Data Protection Board of India (DPBI)** and all impacted users within **72 hours** as mandated by the DPDP Act 2023.
8. DATA RETENTION
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory mandates:
- **Client Account Information:** Kept for the duration of the service contract plus **7 years** to satisfy compliance requirements under GST and corporate auditing rules.
- **Payment Records:** Maintained for **8 years** in accordance with Section 128 of the Companies Act, 2013.
- **Website Analytics:** Non-identifiable tracking data is set to expire from Google Analytics after **26 months**.
- **Communications & Lead Forms:** Inquiry data and messages are deleted after **3 years** unless active negotiations or contract completions occur.
9. YOUR RIGHTS UNDER DPDP ACT 2023
Under the Digital Personal Data Protection Act, 2023, you are recognized as a **Data Principal** and hold specific legal rights:
- **Right to Access:** You can request details of the personal data we process, along with a summary of activities performed on that data.
- **Right to Correction & Erasure:** You can ask us to update inaccurate records or permanently delete your data when the consent purpose is completed.
- **Right to Grievance Redressal:** You can submit formal complaints regarding data processing practices to our designated Grievance Officer.
- **Right to Nominate:** You can nominate an individual to exercise your rights in the event of death or incapacity.
- **Right to Withdraw Consent:** You can retract your consent at any time. Processing before withdrawal remains valid.
To exercise any of these rights, send a written request to our privacy team at roasbodhi@gmail.com. We will process and address your request within **30 days**.
10. COOKIES POLICY
Our website uses cookies (small text files saved on your browser) to identify returning visitors and compile user analytics.
- **Essential Cookies:** Required for core site performance, layout transitions, and form submissions.
- **Analytics Cookies:** Used to monitor aggregate traffic patterns and loading speeds. These do not store personal details.
- **Marketing Cookies:** Used to deliver relevant advertisements and measure campaign efficiency.
You can customize, block, or delete cookies through your browser settings. However, disabling cookies may impact your access to certain interactive elements of our platform.
11. CHILDREN'S PRIVACY
Our website, services, and content are not designed, targeted, or intended for children under **18 years of age**. We do not knowingly collect or store personal data from minors. If we discover that we have inadvertently collected personal data from a child under 18 without verified parental consent, we will delete that data from our servers as quickly as possible.
12. INTERNATIONAL DATA TRANSFERS
Although our agency is based in India, some of our third-party infrastructure (like servers or cloud databases operated by Cloudflare, Google, or Meta) may be located outside of India. By submitting your personal data, you consent to the transfer, storage, and processing of your information across international borders, provided these destinations maintain data protection levels aligned with the DPDP Act 2023 and GDPR guidelines.
13. MARKETING COMMUNICATIONS
We may contact you via email or WhatsApp to provide updates on our services, pricing plans, and promotional offers. You can opt out of these updates at any time by clicking the unsubscribe link in our emails, replying "STOP" to our WhatsApp messages, or emailing us directly at roasbodhi@gmail.com.
14. GRIEVANCE REDRESSAL
In compliance with the DPDP Act 2023 and the IT Act 2000, we have appointed a designated Grievance Officer to address any data processing complaints:
- **Grievance Officer:** Aniket (Founder)
- **Email Address:** roasbodhi@gmail.com
- **Physical Office:** 501 Shankar Apartment Sec 20 Nerul W Navi Mumbai 400706
- **Response Timeline:** We will review and address all grievances within **15 days** of receipt.
15. DATA BREACH NOTIFICATION
In the unlikely event of a security breach that compromises your personal data, we will immediately initiate internal security and containment audits. We will notify the affected individuals and the Data Protection Board of India (DPBI) within **72 hours** of breach confirmation, outlining the nature of the breach, the data affected, and the mitigation steps taken.
16. CHANGES TO PRIVACY POLICY
We reserve the right to modify or update this Privacy Policy at any time. When we make updates, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website or services after any modifications indicates your acceptance of the updated policy.
17. LIMITATION OF LIABILITY
To the maximum extent permitted by law, Namaste Sales Enterprises, its directors, officers, employees, or partners shall not be held liable for any indirect, incidental, special, or consequential damages arising from:
- Data breaches or security lapses that occur on networks or devices beyond our control.
- Your failure to secure your passwords, login credentials, or personal devices.
- Phishing attacks, spoofing emails, or online scams impersonating the Company.
- **Maximum Liability Capped:** Our total liability for any data privacy claim is strictly capped at **₹1,000 INR** or the amount paid for our services in the preceding month, whichever is lower.
18. INDEMNIFICATION
You agree to indemnify, defend, and hold harmless Namaste Sales Enterprises, its founders, and employees from any claims, losses, damages, liabilities, and expenses (including legal fees) arising from your misuse of our website, violation of this Privacy Policy, or submission of false, inaccurate, or unauthorized data.
19. GOVERNING LAW AND JURISDICTION
This Privacy Policy, its terms, and any disputes arising out of it shall be governed by and construed in accordance with the **laws of India**. Any legal action, suit, or proceeding arising under or in connection with this policy shall be subject to the exclusive jurisdiction of the **courts at Thane / Navi Mumbai, Maharashtra, India**.
20. CONTACT INFORMATION
For any queries, feedback, or requests regarding this Privacy Policy or your personal data rights, please contact our team:
**Legal Entity:** Namaste Sales Enterprises
**Brand Name:** RoasBodhi™
**Grievance Officer:** Aniket (Founder)
**Contact Email:** roasbodhi@gmail.com
**Contact Phone:** +91 9082543992 (Missed call to get WhatsApp back)
**Registered Address:** 501 Shankar Apartment Sec 20 Nerul W Navi Mumbai 400706
**Response Timeline:** All inquiries will receive a response within 15 days.