Legal
Privacy Policy
Last updated: August 2, 2026. Applies to shahvatsal.com, contact and newsletter forms, interactive tools lead capture, and related analytics.
Who we are (Data Fiduciary)
This site is operated by Vatsal Shah (Ahmedabad, Gujarat, India). For privacy requests use the contact form or the email in site settings. Under India’s Digital Personal Data Protection (DPDP) Act, 2023, we act as the Data Fiduciary for personal data processed through this site. Where EU/UK visitors are concerned, we align practices with core GDPR principles (lawfulness, purpose limitation, minimization, security).
Data we collect
- Contact form: name, email, company (optional), inquiry type, message, IP, and user agent — to respond to your request.
- Newsletter / tool unlocks: email (and optional source tags such as tool lead sources) — to send opt-in briefings or unlock printable summaries; double opt-in where enabled.
- Interactive tools: calculator and assessment inputs run in your browser for results. Optional work-email capture uses the newsletter subscribe flow. Anonymous tool events (tool slug, event type) may be logged for product improvement without storing prompt text.
- Analytics (optional): after consent, aggregated usage via GA4 / GTM / Clarity (pages viewed, referrers, device class). No sale of personal data.
- Cookies: essential site cookies; analytics cookies only when you Accept. See the on-site consent banner and cookie preferences.
Purpose and legal basis
We process data to: (1) respond to inquiries and operate consulting workflows; (2) deliver newsletters you opted into; (3) secure the site (CSRF, rate limits, CAPTCHA); (4) measure performance with consent. Under DPDP, processing is for the stated purpose with consent or for legitimate uses permitted by law (e.g. security). Under GDPR-style analysis, bases include consent (cookies/newsletter) and legitimate interests / contract steps (contact replies).
Retention
Contact messages and newsletter records are retained only as long as needed for those purposes or legal requirements, then deleted or anonymized. Analytics retention follows the configured vendor settings. Tool event logs are operational and periodically pruned.
Your rights (DPDP + GDPR-aligned)
- Access / correction: request a copy of data we hold about you, or ask us to correct inaccuracies.
- Erasure / withdrawal of consent: ask us to delete contact or newsletter records, or withdraw cookie consent (Essential-only).
- Data portability (where applicable): request an export of newsletter/contact data you provided.
- Grievance: contact us first; if unresolved, you may escalate to India’s Data Protection Board of India under DPDP once operational, or your local supervisory authority if GDPR applies to you.
To exercise rights, use the contact form with the email address you used and a clear request. We aim to respond within a reasonable period (typically within 30 days).
International transfers
Processors (email, CDN, analytics, CAPTCHA) may process data in other countries. We select reputable vendors and limit transfers to the stated purpose. Enterprise visitors should assume standard cloud-region processing unless a separate MSA says otherwise.
Children
This site is aimed at professionals. We do not knowingly collect personal data from children under 18.
Security
Transport is HTTPS. Forms use CSRF tokens, rate limits, honeypots, and optional Cloudflare Turnstile. We do not store payment card data on this site.
Third parties
Limited processors may include email delivery, form backends, Cloudflare (Turnstile/CDN), and analytics vendors you consent to. They process data under their policies for the stated purpose only. We do not sell personal data.
Changes
Material updates will be reflected on this page with a new “Last updated” date.