DigiMint WebTroopz LLP logo
  • Services
  • Process
  • About
  • Careers
  • Blog
  • Contact
+91 738 713 6569Get Free Consultation
  • Services
  • Process
  • About
  • Careers
  • Blog
  • Contact
Get Free Consultation+91 738 713 6569
Home / User Data Protection Terms

User Data Protection Terms

DigiMint WebTroopz LLP ("DigiMint", "Processor")
Effective date: 30 September 2026 | Last updated: 30 September 2026

These User Data Protection Terms ("DP Terms") apply when DigiMint processes personal data on behalf of a client while providing Services (for example: website forms, lead lists, CRM or WhatsApp automations, ad-campaign leads, customer databases, e-commerce customer data, analytics). They form part of our Terms and Conditions and are made under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and the Information Technology Act, 2000 and rules under it.

For personal data we collect for our own purposes (such as visitors to our websites), see our Privacy Policy instead.


1. Roles

1.1 Client = Data Fiduciary. You decide why and how the personal data is processed and are responsible for compliance as Data Fiduciary.
1.2 DigiMint = Data Processor. We process personal data only on your documented instructions and for the purpose of providing the Services. If we decide the purpose or means ourselves for particular data, we are a Data Fiduciary for that data and will tell you.
1.3 The subject matter, nature, purpose and duration of processing, the type of personal data and the categories of Data Principals are as set out in the Proposal or, where not specified, as described in Annexure A.

2. Client responsibilities

You confirm and undertake that:

  1. You have a lawful basis (valid, specific, informed, unconditional and unambiguous consent, or a legitimate use under Section 7 of the DPDP Act) for the data you give us or ask us to collect.
  2. You have given Data Principals a notice that meets Section 5 of the DPDP Act (what data, purpose, how to exercise rights, how to complain to the Data Protection Board), on forms, landing pages, ads and chatbots that we build or run for you. If you require consent managers, or notice in other languages, you will tell us.
  3. You will not give us children's personal data, or data for tracking, behavioural monitoring or targeted advertising directed at children, unless you have verifiable parental consent and we have agreed in writing.
  4. You will not give us sensitive information (payment card numbers, government ID numbers, health records, biometric data) unless it is necessary and agreed in writing in advance.
  5. You will make sure your instructions comply with law and will not ask us to do anything unlawful (for example, buying or scraping lists, unsolicited messaging in breach of TRAI rules, or misusing personal data).
  6. You remain responsible for handling requests from Data Principals, and for deciding whether to erase data, retain it, or notify anyone of a breach.

3. DigiMint's obligations

We will:

  1. Process only on your instructions and for the agreed Services, unless law requires otherwise (we will tell you first where permitted).
  2. Confidentiality: make sure our people with access are bound by confidentiality and given access on a need-to-know basis.
  3. Security safeguards: apply reasonable security safeguards to prevent a personal data breach (DPDP Act, s.8(5); DPDP Rules), including those in Annexure B.
  4. Sub-processors: use sub-processors (for example cloud hosting, email, automation, analytics and advertising platforms) only under written terms giving similar protection, remain responsible for them, and provide a list on request. You consent to the sub-processors listed in Annexure C. We will give 10 days' notice of a new sub-processor; you may object on reasonable data protection grounds, and if we cannot resolve it, you may end the affected Service.
  5. Cross-border transfers: where a sub-processor is outside India, transfer only in line with Section 16 of the DPDP Act and any country restrictions the Central Government notifies.
  6. Assist you (reasonably and at cost where the work is significant) with Data Principals' requests (access, correction, erasure, grievance, nomination), and with your compliance duties, taking into account the nature of the processing.
  7. Not sell, rent or use your data for our own marketing, profiling or to train models for other clients or purposes, and not combine it with data from other clients.
  8. Keep records of processing and logs for the period required by the DPDP Rules (at least one year).
  9. Accuracy: ensure that data is completed or corrected on your instructions.

4. Personal data breach

4.1 If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware, with the information we have: what happened, when, the data and Data Principals affected, likely consequences, steps taken, and a contact point. We will send further details as we learn them.
4.2 We will take reasonable steps to contain and fix the breach and to help you.
4.3 As Data Fiduciary you are responsible for informing affected Data Principals and the Data Protection Board of India within the time and in the form set by the DPDP Rules (intimation without delay and a detailed report within 72 hours). We will provide the information you reasonably need to do so.
4.4 A notification by us is not an admission of fault.

5. Data Principal rights

If a Data Principal contacts us directly about data we process for you, we will forward the request to you within 5 working days and will not respond except to acknowledge it, unless you tell us to or the law requires. Where you instruct us in writing, we will access, correct, update or erase the relevant data within 15 days (or the shorter period the DPDP Rules require).

6. Retention, return and deletion

6.1 We keep your data only for the duration of the Services and the period needed for our post-handover backups, as set out in the Terms (up to 90 days after the end of the engagement, unless a maintenance plan says otherwise).
6.2 On the end of the Services, or on your written request, we will, at your choice, return the data (in a common format such as CSV or JSON) or delete it, and delete copies, and confirm in writing, unless law requires us to keep it (for example, invoices or logs), in which case we keep only that and continue to protect it.
6.3 If you do not choose within 30 days of the end of the Services, we will delete the data.
6.4 Data you hold in your own accounts (ad accounts, CRM, hosting, WhatsApp Business) stays under your control; we will remove our access on request or at the end of the engagement.

7. Access to accounts and credentials

  • Give us the minimum access required, and where possible use role-based or partner access (for example, Meta Business Manager partner access) rather than sharing passwords.
  • Do not send passwords over chat where a secure method exists. We will use a password manager or one-time links.
  • We will not share credentials with anyone else, and will keep a list of our people with access. You should remove our access at the end of the engagement.
  • Actions taken with the access you give are treated as done on your instructions.

8. Audit and information

On reasonable written request (not more than once a year, or after a breach), we will provide information that shows compliance with these DP Terms, such as a written summary of our security practices. On-site audits need at least 30 days' notice, must not disrupt our business, must protect the confidentiality of other clients, and are at your cost.

9. Liability

Liability under these DP Terms is subject to the limits in the Terms and Conditions. You are responsible for the lawfulness of the personal data and instructions you give us, and will indemnify us for claims, penalties and reasonable costs that arise from your breach of Clause 2 or from unlawful instructions. Nothing limits a liability that cannot be limited by law.

10. Term, conflict and law

10.1 These DP Terms apply as long as we process personal data for you and until we have returned or deleted it.
10.2 If these DP Terms conflict with the Terms and Conditions on personal data, these DP Terms prevail.
10.3 They are governed by Indian law, and the dispute clauses of the Terms and Conditions apply.
10.4 If the law changes (including a phased commencement of the DPDP Rules), we will update these DP Terms and the updated version applies from the date stated.

11. Contact

Data Protection Contact / Grievance Officer: Anant Bhausaheb Athare (Founder & Director), contact@digimintweb.in, +91 738 713 6569
DigiMint WebTroopz LLP, G-338/2, Guruvaarpeth, Tisgaon, Ahmednagar (Ahilyanagar), Maharashtra 414106, India


Annexure A: Description of processing (default)

ItemDetails
PurposeBuilding, hosting and operating websites and apps; running ad campaigns and lead capture; CRM and messaging automation; analytics and reporting; support
Categories of Data PrincipalsYour website visitors, leads, customers, subscribers, employees and contacts
Types of personal dataName, phone, email, city, business details, messages, order and enquiry details, IP address, device and cookie data
Sensitive dataNone expected. Not to be provided without written agreement
FrequencyContinuous for the duration of the Services
DurationDuration of the Services plus the retention period in clause 6

Annexure B: Security measures

  • Encryption in transit (HTTPS/TLS); encryption at rest where the platform supports it
  • Role-based, least-privilege access; unique accounts; multi-factor authentication where available
  • Password manager use; no shared personal passwords; prompt removal of access when no longer needed
  • Regular backups and restoration testing for hosted projects
  • Software, plugin and dependency updates; security patches applied within a reasonable time
  • Logging and monitoring of access to systems that hold personal data (logs kept at least 1 year)
  • Confidentiality undertakings from our team; awareness of data protection duties
  • Vendor selection based on security posture; written terms with sub-processors
  • Incident response process with escalation to the Grievance Officer

Annexure C: Sub-processors and platforms (indicative)

CategoryExamplesLocation
Cloud hosting / serversWeb hosting and cloud server providersIndia / global
DatabaseManaged database providersIndia / global
Email / messagingBusiness email and WhatsApp Business API providersGlobal
Automationn8n (self-hosted or cloud)India / global
AnalyticsGoogle AnalyticsGlobal
Advertising platformsMeta, Google Ads (as directed by the client)Global
PaymentsRBI-authorised payment gatewaysIndia
AccountingAccounting and invoicing softwareIndia

DigiMint WebTroopz LLP logo

India's performance-first digital growth agency. We build websites, apps, and marketing systems that engineer revenue.

+91 738 713 6569+91 866 856 6477contact@digimintweb.inwww.digimintweb.in

Services

  • Website Development
  • Performance Marketing
  • SEO & Content
  • Mobile App Development
  • AI & n8n Automation
  • Brand & Graphic Design
  • E-Commerce Development

Company

  • About Us
  • Blog
  • Careers
  • Privacy Policy
  • Terms & Conditions
  • Refund & Cancellation
  • Data Protection Terms
  • Cookie Policy
  • Cookie Settings
  • Sitemap

Locations

  • Ahmednagar (Ahilyanagar)
  • Pune
  • Mumbai
  • Maharashtra
  • Ahmedabad
  • Surat
  • Gujarat
  • Delhi
  • Delhi NCR
  • All Locations
Ahmednagar, Maharashtra 414106

© 2026 DigiMint WebTroopz LLP. All rights reserved.

Looking for JobService Enquiry