๐Ÿ”’ Upgrade your existing website with smart cookie consent, user preferences, and privacy compliance.

1. Introduction

This Privacy Policy explains how ILLUME Intelligence ("ILLUME Intelligence," "we," "us," or "our"), the operator of the ComplyPolicy platform ("ComplyPolicy," the "Platform," or the "Service"), collects, uses, discloses, stores, and protects personal data when you visit complypolicy.com (the "Website"), use our Services, or interact with us in any other way.

This Policy is designed to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and its rules, and, where applicable to visitors outside India, with the General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA").

Under the DPDP Act, ILLUME Intelligence acts as the Data Fiduciary in respect of personal data collected directly from you through this Website, and you, as the individual to whom the data relates, are the Data Principal. Where our Services process cookie and consent data on behalf of our business customers ("Customers") for their own end users, ILLUME Intelligence acts as a Data Processor, and the Customer is the Data Fiduciary for that data. Section 10 explains this distinction in more detail.

By using this Website or our Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Website or the Services.

2. Personal Data We Collect

We collect personal data in the following ways:

2.1 Information You Provide Directly

  • Name, business email address, phone number, and company name when you sign up, request a demo, or contact us.
  • Billing and payment details when you purchase a subscription (processed via our payment partners; we do not store full card details).
  • Account credentials (username and password, stored in encrypted/hashed form).
  • Any information you submit through contact forms, support tickets, or WhatsApp/chat conversations.

2.2 Information Collected Automatically

  • IP address, browser type, device type, and operating system.
  • Pages visited, time spent on the Website, referring URLs, and click-stream data.
  • Cookies and similar tracking technologies (see our Cookie Policy for details).

2.3 Information Collected Through the Service

  • Consent logs, timestamps, and preference selections recorded by the ComplyPolicy cookie-consent widget when deployed on a Customer's website.
  • Technical metadata about cookies and tracking scripts detected during a cookie scan.

2.4 Information From Third Parties

  • Publicly available business information (e.g., company registration details) used for verification.
  • Data from integration partners (e.g., analytics or marketing tools) that a Customer connects to the Platform.

We do not knowingly collect Sensitive Personal Data (such as financial information beyond billing, health data, or biometric data) through this Website unless explicitly and separately consented to.

3. How We Use Personal Data

We use personal data for the following purposes, each grounded in a lawful basis under the DPDP Act (consent, or a legitimate use recognised under Section 7 of the Act, such as providing a service you have requested):

Purpose Legal Basis
Creating and managing your account Consent / Contractual necessity
Providing, operating, and improving the Service Consent / Legitimate use
Processing payments and billing Contractual necessity
Responding to enquiries and support requests Consent / Legitimate use
Sending service updates, security alerts, and (where opted in) marketing communications Consent
Detecting fraud, misuse, or security incidents Legitimate use
Complying with legal and regulatory obligations Legal obligation
Improving Website performance through analytics Consent (via cookie banner)

We do not use personal data for any purpose incompatible with the purpose for which it was originally collected, as required under the DPDP Act.

4. Cookies and Tracking Technologies

Our Website itself uses cookies for essential functionality, analytics, and (where consented to) marketing purposes.

You can manage your preferences at any time through the cookie settings icon available on the Website, or via our Cookie Policy and Manage Cookie Settings page.

Non-essential cookies are not activated until you provide consent, consistent with the "consent-first" standard the DPDP Act requires of our own Customers' deployments.

5. Data Sharing and Disclosure

We do not sell personal data. We may share personal data only in the following circumstances:

5.1 Service Providers

With vetted third-party vendors who support hosting, payment processing, email delivery, analytics, or customer support, under contractual confidentiality and data-protection obligations.

5.2 Business Customers

Where you interact with a website that uses ComplyPolicy's consent widget, your consent choices are shared with that website (as the Data Fiduciary) so it can honour your preferences.

5.3 Legal Requirements

Where disclosure is required to comply with a legal obligation, court order, or a lawful request from the Data Protection Board of India or another competent authority.

5.4 Business Transfers

In connection with a merger, acquisition, financing, or sale of assets, subject to equivalent privacy protections for transferred data.

5.5 With Your Consent

For any other purpose, only after obtaining your explicit consent.

5.6 International Data Transfers

We do not knowingly transfer personal data to any country restricted by the Central Government under the DPDP Act.

Where personal data is transferred outside India for hosting or processing, we ensure such transfers are subject to appropriate contractual safeguards.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law, including record-keeping obligations under the DPDP Act.

Consent logs and audit records are retained for the period necessary to demonstrate compliance, after which they are securely deleted or anonymised.

You may request earlier deletion of your data as described in Section 8, subject to any legal retention requirements.

7. Data Security

We implement reasonable security safeguards to protect personal data against unauthorised access, alteration, disclosure, or destruction, as required under Section 8(5) of the DPDP Act.

These safeguards include:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Access controls and role-based permissions.
  • Regular security reviews and vulnerability monitoring.
  • Secure hosting infrastructure with audit logging.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and timeframe prescribed under the DPDP Act and its rules.

8. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access: Obtain a summary of the personal data we hold about you and the processing activities carried out.
  • Correction and Updation: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data, unless retention is required by law.
  • Grievance Redressal: Raise a complaint regarding the processing of your personal data and receive a response within the timeline prescribed by law.
  • Withdraw Consent: Withdraw consent at any time, with the same ease with which it was given โ€” withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Nominate: Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, contact our Grievance Officer using the details in Section 12. We will respond within the timelines prescribed under the DPDP Rules.

9. Children's Data

Our Services are intended for business use and are not directed at individuals under the age of 18.

In accordance with Section 9 of the DPDP Act, we do not knowingly collect personal data from children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

If we become aware that we have inadvertently collected data from a child without verifiable parental/guardian consent, we will delete it promptly.

10. Our Role: Data Fiduciary vs. Data Processor

10.1 As a Data Fiduciary

For personal data you provide directly to us (e.g., account information, billing details, Website visitor data), ILLUME Intelligence determines the purpose and means of processing and is directly responsible to you under this Policy.

10.2 As a Data Processor

When our Customers deploy the ComplyPolicy consent widget on their own websites, we process the end users' consent data on the Customer's instructions.

In that case, the Customer is the Data Fiduciary responsible for their own privacy policy and end-user relationship, and our processing is governed by a separate Data Processing Agreement with that Customer.

If you are an end user of one of our Customers' websites and have questions about how your data is used, please refer to that website's own privacy policy in the first instance.

11. Third-Party Links and Integrations

Our Website and Service may contain links to, or integrations with, third-party platforms (e.g., Google Analytics, Meta Pixel, payment gateways).

This Policy does not cover the privacy practices of those third parties. We encourage you to review their respective privacy policies independently.

12. Grievance Officer / Contact Us

In accordance with the DPDP Act, we have designated a Grievance Officer to address any questions, concerns, or complaints regarding this Policy or our data practices:

Grievance Officer: CTO, ILLUME Intelligence

Email: mail@illume.in

Phone: +91 6235 24 7 365

We aim to acknowledge grievances within the timeframe prescribed by the DPDP Rules and resolve them as promptly as possible.

If you are not satisfied with our response, you retain the right to file a complaint with the Data Protection Board of India.

13. International Users (GDPR/CCPA)

Where visitors access this Website from the European Economic Area, the UK, or California, we additionally recognise applicable rights under the GDPR (including the right to data portability and the right to object to processing) and the CCPA (including the right to know, delete, and opt out of the sale/sharing of personal information โ€” noting we do not sell personal data).

Requests under these frameworks may also be directed to the contact details in Section 12.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

We will post the revised Policy on this page with an updated "Last Updated" date, and where changes are material, we will provide additional notice (such as an email or website banner) before the changes take effect.

15. Governing Law

This Policy is governed by the laws of India.

Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts in New Delhi, India.