1. Introduction and scope
This Policy covers personal information handled by Doodl Space through the Website and the WebApp. It does not cover third-party websites or services that we link to, which have their own privacy policies. Employee and job-applicant data is handled under a separate internal policy and is not covered here.
2. Definitions
Personal information / personal data — information that identifies, or can reasonably be linked to, an individual. Processing — any operation performed on personal data, such as collecting, storing, using, or sharing it. Controller / Data Fiduciary — the party that decides why and how personal data is processed. Processor / Data Processor — a party that processes personal data on behalf of, and under the instructions of, a controller. Customer Content — files and materials a customer uploads to the WebApp to have creative work produced, such as logos, brand guidelines, brand assets, and briefing materials (which may include documents like pitch decks).
3. Our role: when we are a controller and when we are a processor
We handle two different kinds of information in two different roles:
As a controller, we decide how information is used. This applies to almost everything on our Website (cookies and usage data, newsletter sign-ups, resource downloads) and to the account information for our WebApp (the personal and company details you register with). This Policy governs that information. As a processor, we handle Customer Content only to deliver the creative services our customer has asked for, following that customer’s instructions. We do not use Customer Content for our own purposes. The confidentiality and ownership of Customer Content are governed by our Terms of Service and, where applicable, a separate Data Processing Agreement with the customer. If you are an individual whose personal data appears inside a customer’s uploaded materials, please contact that customer (the controller) to exercise your rights; we will assist them as required.
4. Information we collect
We collect the following, depending on how you interact with us:
| # | Category | Examples | Where it comes from |
|---|---|---|---|
| 4.1 | Website usage & cookies | IP address, device and browser type, pages viewed, referring links, and cookie identifiers | Automatically, when you visit the Website |
| 4.2 | Newsletter sign-up | Email address | You, when you subscribe |
| 4.3 | Resource / case-chart download | Name, email, company name, and any marketing consent choice | You, when you request the resource |
| 4.4 | WebApp account — personal details | First name, last name, phone number, designation | You, at sign-up |
| 4.5 | WebApp account — business details | Company name, business entity, phone, employee count, industry, GST/VAT | You, at sign-up |
| 4.6 | Customer Content (we act as processor) | Logos, brand guidelines and assets, and materials you upload with a design request | You, when you use the WebApp |
| 4.7 | Billing information | Billing address, GSTIN, and contact details | You, at checkout |
| 4.8 | Communications & support | Messages and information you share with our team by email, chat, phone, WhatsApp or SMS. | You |
We do not collect or store your payment card details. Card payments are handled by our payment provider and PCI-DSS-compliant payment gateways (see Section 8). We ask you not to share sensitive information such as card numbers, OTPs, or passwords with our support team.
5. How we use your information, and our legal grounds
We use personal information to:
- provide, operate, and maintain the Website, WebApp, and our creative services;
- create and manage your account and deliver the projects you request;
- process payments and comply with tax and accounting requirements (including GST);
- respond to your enquiries and provide customer support;
- send you service and account communications;
- with your consent, send you newsletters and marketing, and show you relevant advertising;
- understand how our Website and WebApp are used, so we can improve them;
- keep our services secure and prevent fraud or misuse; and
- comply with applicable law and enforce our terms.
Where the law requires us to have a specific legal basis, we rely on: your consent (for marketing and non-essential cookies); performance of a contract (to provide the services you sign up for); our legitimate interests (to run, secure, and improve our business in a way that does not override your rights); and legal obligations (such as tax and record-keeping). Under India’s Digital Personal Data Protection Act, we rely on your consent or on permitted “legitimate uses” as applicable.
6. Cookies and tracking technologies
We use cookies and similar technologies for essential site functions, analytics, and, with your consent, advertising. We use, or engage partners to use, tools including Google Analytics, advertising and retargeting pixels, and Google AdSense to measure performance and show relevant ads on our Website and elsewhere.
Non-essential cookies (analytics and advertising) are only set after you consent through our cookie banner, and you can change or withdraw your choices at any time using that banner. Full details of the cookies we use are in our separate Cookie Policy.
7. Marketing communications and your consent
We only send marketing with your consent, for example, when you subscribe to our newsletter, tick the marketing-consent box on a resource download, or opt in during WebApp sign-up. Every marketing email includes an unsubscribe link, and you can opt out at any time. We may still send you non-promotional service messages (such as account, billing, or project updates) that are necessary to provide the service. Where you have shared a phone number, we may contact you about your account or projects, including via WhatsApp or SMS.
8. How we share your information
We share personal information only as needed to run our business and as described below. We do not sell your personal information for money. We share information with:
- Service providers who help us operate, in categories including: analytics and advertising providers; payment processing (our billing provider and PCI-DSS-compliant gateways such as Razorpay and Stripe); hosting and cloud infrastructure; and customer-relationship and email delivery tools. These providers may only use the information to provide their service to us.
- Our designers, to the extent needed to deliver your project.
- Authorities or other parties, where we are required by law, to comply with legal process, or to protect our rights, users, or the public.
- A successor entity, if we are involved in a merger, acquisition, or sale of assets.
9. International data transfers
We are based in India, and our data is hosted with reputable third-party cloud providers with servers currently located in the United States; we may host or process data in other regions as our infrastructure evolves. This means your information may be transferred to, and stored in, a country different from where you live.
Where personal data of individuals in the EU/UK is transferred outside those regions, we rely on appropriate safeguards recognised under applicable law (such as Standard Contractual Clauses) to protect it. By using our services and providing your information, you understand that it may be processed in the locations described above.
10. How long we keep your information
We keep personal information only for as long as needed for the purposes described in this Policy, for example, for the life of your account and our business relationship, and for a reasonable period afterward to meet legal, tax, accounting, or dispute-resolution requirements. When information is no longer needed, we delete it or anonymise it. Customer Content is retained and deleted in line with our Terms of Service and the customer’s instructions.
11. How we protect your information
We use reasonable technical and organisational measures designed to protect personal information against loss, misuse, and unauthorised access. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised access. If a data breach affecting your personal information occurs, we will notify the relevant authorities and affected individuals as required by applicable law.
12. Your privacy rights
Subject to applicable law, everyone can ask us to:
- access a copy of the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- delete your personal information;
- withdraw consent (this will not affect processing already carried out); and
- opt out of marketing and of non-essential cookies/advertising.
To exercise any right, contact us at anand@doodlspace.com. We may need to verify your identity, and we will respond within the timeframes set by applicable law. You will not be discriminated against for exercising your rights.
India (DPDP Act 2023). You have the right to access, correction, and erasure of your data; to grievance redressal; and to nominate another person to exercise your rights in the event of death or incapacity. You may contact our Grievance Officer (Section 14) and, if unsatisfied, approach the Data Protection Board of India.
EU / UK (GDPR). In addition to the above, you have the right to restrict or object to processing, the right to data portability, and rights relating to automated decision-making. You may lodge a complaint with your local data protection authority.
United States (California and other states). You may request to know, delete, and correct your personal information, and opt out of the “sale” or “sharing” of personal information for targeted advertising. To opt out, use the “Do Not Sell or Share My Personal Information” control on our Website or adjust your choices in our cookie banner. We also honour recognised opt-out browser signals, such as Global Privacy Control (GPC). We do not use or disclose sensitive personal information for purposes that require a right to limit.
UAE and Australia. If you are in the UAE (PDPL) or Australia (Privacy Act / Australian Privacy Principles), you have rights to access and correct your personal information, and to complain about how it is handled. You may contact us using the details below, and Australian users may also complain to the OAIC.
13. Children’s data
Our services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information from children. If we become aware that we have collected a child’s data without appropriate consent, we will delete it.
14. Grievance Officer and contact
For any questions, requests, or complaints about this Policy or your personal information, contact:
Anand Shah — Co-founder & Director (Grievance Officer), Quarkfarm Communications Private Limited (Doodl Space) · Email anand@doodlspace.com · Address: 660-E, A-Wing, 6th Floor, B.D. Patel House, Naranpura, Ahmedabad 380014, India.
15. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you. Your continued use of our services after an update means you accept the revised Policy.
