Privacy Policy
How we collect, use, store and protect your information — and the rights you have over it.
Last updated 27 July 2026This Privacy Policy explains how [REGISTERED BUSINESS NAME], trading as Policy Fix Experts (“we”, “us”, “our”), handles personal data when you visit policyfixexperts.com, contact us, or engage us for services.
We act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act). If you are located in the GCC, the EU or the UK, additional rights may apply to you under your local law, and we will honour them where they are stricter than Indian law.
Please read section 4 carefully. Because of the nature of our work, we are often given access to advertising accounts, websites and business documents that contain personal data belonging to you and to third parties.
1Who we are and how to reach us
Data Fiduciary: [REGISTERED BUSINESS NAME], trading as Policy Fix Experts
Registered address: [FULL REGISTERED ADDRESS], Chennai, Tamil Nadu, India
Email: info@policyfixexperts.com
Phone / WhatsApp: +91 7305950133
Grievance Officer (as required under the DPDP Act and the Information Technology Act, 2000):
Name: [GRIEVANCE OFFICER NAME]
Email: info@policyfixexperts.com
Postal address: as above
We aim to acknowledge every privacy request within 72 hours and to resolve it within 30 days.
2What personal data we collect
We collect only what we need to respond to you and to deliver the services you have asked for.
a) Information you give us directly
- Name, phone number, WhatsApp number and email address
- Company name and website address
- The service you are enquiring about and the details of your situation
- The contents of messages you send us by form, email, WhatsApp or phone
- Billing details, GST registration number and payment references
b) Information you give us during an engagement
- Suspension notices, policy manager screenshots and Google Ads customer IDs
- Access to advertising accounts, analytics properties, websites, hosting and CMS panels
- Business and identity documents supplied for Advertiser Verification or Business Operations Verification — which may include registration certificates, GST certificates, utility bills, bank statements and government-issued identity documents
- Customer or employee data contained in systems we are asked to build, migrate or integrate
c) Information collected automatically
- Standard server logs: IP address, browser type, device type, pages viewed, referring page and timestamps
- Analytics data, if and when analytics is enabled on this website
We do not knowingly collect data from children under 18. We do not deliberately collect sensitive personal data beyond the identity and business documents described above, which are collected only where a verification process requires them.
3Why we use your data, and our lawful basis
| Purpose | Data used | Basis |
|---|---|---|
| Responding to your enquiry | Contact details, enquiry contents | Your consent, given when you submit the form or message us |
| Delivering the services you engaged us for | All engagement data in section 2(b) | Performance of our contract with you |
| Preparing appeals and verification submissions | Account data, business and identity documents | Performance of contract, with your specific authorisation |
| Invoicing, accounting and tax | Billing details, GSTIN | Legal obligation under Indian tax law |
| Improving our website and services | Aggregated, non-identifying usage data | Legitimate business interest |
| Sending service updates about your active engagement | Contact details | Performance of contract |
We do not sell, rent or trade your personal data to anyone, for any purpose, at any time. We do not use your data to train artificial intelligence models, and we do not share client data between clients.
4Access to your advertising accounts, websites and systems
This section matters more than any other, so we have set it out separately.
To recover a suspended account, complete a verification, or manage campaigns, you may grant us access to systems that contain personal data — your own, your employees', and your customers'. When you do:
- We ask for the lowest level of access that allows us to do the work. Where a platform offers a limited role, we request that role rather than full administrative rights.
- Access is granted to a named individual on our team, not to a shared or generic login.
- We use access only for the agreed scope of work. We do not export, copy, retain or reuse your customer lists, audience data, remarketing lists or business data for any other purpose.
- We never share credentials outside our team, and we do not ask you to send passwords over WhatsApp or email. Where a password must be shared, we will ask you to use a secure method.
- You may revoke our access at any time, without notice and without giving a reason. We will also ask you to revoke it when the engagement ends.
- We will tell you promptly if we believe an account has been compromised.
Where we process personal data that belongs to your customers or employees, you remain the Data Fiduciary for that data and we act as a Data Processor on your instructions. We process it only as needed to deliver the agreed service.
5Who we share data with
We share personal data only where it is necessary, and only with the categories below.
- Advertising and technology platforms — Google and Meta, where an appeal, verification submission or campaign requires it. This is done on your instructions and with your authorisation.
- Service providers we rely on to operate, such as web hosting, email, cloud storage, communication tools and payment processors. They are bound to protect your data and may use it only to provide the service to us.
- Professional advisers such as accountants and lawyers, where required.
- Government or regulatory authorities, where we are legally required to disclose.
We do not share your data with any other third party without telling you first.
6Storage, security and international transfer
Our primary storage is in India. Some service providers we use may store or process data outside India. Where that happens, we take reasonable steps to ensure protection consistent with this policy and with the DPDP Act, and we do not transfer data to any territory restricted by the Government of India.
Security measures we apply include encrypted connections (HTTPS/TLS), access limited to team members who need it, multi-factor authentication on business-critical accounts, and deletion or return of verification documents once they are no longer needed.
No method of transmission or storage is completely secure. While we take security seriously, we cannot guarantee absolute security, and we will notify you and the Data Protection Board of India of any breach that is likely to affect you, as required by law.
7How long we keep your data
| Type of data | Retention period |
|---|---|
| Enquiries that do not become engagements | Up to 12 months, then deleted |
| Client engagement records and correspondence | Duration of engagement plus 3 years |
| Identity and business verification documents | Deleted within 90 days of the verification or appeal concluding, unless you ask us to keep them |
| Invoices and tax records | 8 years, as required by Indian tax law |
| Website server logs | Up to 12 months |
You may ask us to delete data sooner. We will do so unless we are legally required to retain it.
8Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you and how we process it
- Correct or complete data that is inaccurate or out of date
- Erase data where it is no longer needed for the purpose it was collected
- Withdraw consent at any time, as easily as you gave it
- Nominate another person to exercise your rights in the event of your death or incapacity
- Raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if you are not satisfied with our response
To exercise any of these, email info@policyfixexperts.com with the subject line “Data request”. We may ask you to verify your identity before we act, to protect you.
9Cookies, analytics and third-party content
This website does not set advertising or tracking cookies of its own.
It loads a web font from Google Fonts, which means your browser makes a request to Google's servers and Google may log your IP address. The site is designed to work normally if that request fails or is blocked.
If we enable Google Analytics or a similar measurement tool in future, this policy will be updated before it goes live, and a cookie notice will be added.
Our pages link to WhatsApp, and clicking through takes you to a Meta service governed by Meta's own privacy policy, not ours.
10The chat assistant on this website
The chat widget on this site runs entirely inside your own browser. It is a simple rule-based assistant, not an artificial intelligence service. It does not send your messages to any server, it does not store a transcript, and nothing you type into it reaches us unless you choose to continue the conversation on WhatsApp or submit the enquiry form.
If you do choose to continue on WhatsApp, the details you entered are passed into a pre-filled WhatsApp message that you can review and edit before sending.
11Changes to this policy
We may update this policy as our services or the law change. The version in force is always the one published on this page, with the revision date shown at the top. If a change materially affects your rights, we will make reasonable efforts to notify active clients directly.
Questions about any of this?
If something here is unclear, ask us. We would rather explain it now than have you discover it later.