Last updated on Jul 26 2025
1. Who we are
This policy is issued by Brandacy, registered at (registered address). Brandacy is a B2B lead-generation and client-acquisition partner. For privacy matters, contact info@brandacy.co or (+1 276 800 0804).
2. Scope
Because of what Brandacy does, this policy covers more than website visitors. It applies to three groups:
Website visitors – people who browse this Site, submit a form, or book a call.
Clients and business contacts – people at companies we work with or talk to commercially.
Outreach prospects – business decision-makers whose professional contact details we process in the course of delivering lead generation services for our clients.
If you have received an email, call, or LinkedIn message from a campaign we operate, Section 6 is written for you.
3. Data we collect
From website visitors: contact details you submit (name, work email, company, and phone); booking details submitted through our scheduling provider, and technical data collected automatically (IP address, device and browser information, and pages viewed) via cookies and analytics—see Section 10.
From clients and business contacts: the information exchanged in a normal commercial relationship—contact details, correspondence, and contract and billing information.
About outreach prospects: professional contact data only — name, job title, company, business email, business phone, and public professional profile information. We source it from publicly available information and licensed B2B data providers. We do not collect sensitive personal data, consumer data, or data about private individuals for outreach.
4. How we use data, and on what basis
We use personal data to: respond to inquiries and run booked calls; deliver contracted services to clients; operate outreach campaigns on behalf of clients (business contact data only); improve the Site through analytics; and meet legal obligations.
Depending on the jurisdiction, our legal bases are: performance of a contract (clients), consent (where required, e.g., certain cookies and certain jurisdictions’ outreach rules), and legitimate interest (B2B outreach to relevant professional audiences, Site security, and analytics). Where we rely on legitimate interest, we balance it against your rights and honor objections — see Sections 6 and 9.
5. Roles
When Brandacy is a controller and when a processor:
For site visitor data and our own marketing, Brandacy acts as a data controller. For campaign data processed at a client’s direction, Brandacy generally acts as a processor (or an equivalent role under applicable law) under a data processing agreement with that client.
(legal to confirm the controller/processor characterization matches the actual service contracts—this is a real legal decision, not a copy edit.)
6. Outreach
How we treat prospects: This is the section most privacy policies in our industry don’t write. Ours does, because restraint in outreach is part of how we work:
We contact business roles at businesses about matters relevant to their role—never consumers, never personal addresses where a business address exists.
Every outreach email identifies the sender and contains a working opt-out. Opt-outs are honored promptly and recorded on a suppression list, so you are not contacted again across campaigns we operate. (Confirm suppression is actually implemented across clients before this sentence publishes.)
We comply with applicable outreach laws, including India’s DPDP Act, the GDPR, and PECR when contacting EU/UK residents; CAN-SPAM in the US; and CASL in Canada. (Confirm actual target geographies with management; delete regimes that don’t apply and add ones that do.)
To ask what data we hold about you, to object, or to be suppressed: (privacy email). If your data were processed for a client’s campaign, we will act on our client’s behalf or, as required by law, route your request to them.
7. Who we share data with
We share personal data only with: service providers who process it for us — hosting, scheduling, analytics, CRM, email infrastructure, and B2B data providers; our clients, where prospect engagement data is part of contracted deliverables; professional advisers and authorities where legally required. We do not sell personal data.
8. International transfers and retention
Our providers may process data outside your country. Where required, we use recognized transfer safeguards (such as standard contractual clauses).
We keep personal data only as long as needed for the purposes above: inquiry data for client records for the engagement plus statutory retention, and prospect data for the campaign lifecycle plus suppression records (which we keep so opt-outs stick).
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to complain to a supervisory authority (including India’s Data Protection Board, an EU supervisory authority, or your state attorney general, as applicable). Exercise any of these at (privacy email). We respond within the timelines set by applicable law.
10. Cookies and analytics
The Site uses cookies and similar technologies for core functionality and, where enabled, analytics. You can control cookies through your browser and, where a consent banner is displayed, through your browser’s settings.
11. Security
We use appropriate technical and organizational measures to protect personal data—access controls, encryption in transit, and vendor due diligence. No system is perfectly secure; if a breach affects you, we will notify you and the regulators as required by law.
12. Children
The Site and our services are directed at business professionals. We do not knowingly collect data from anyone under 18.
13. Changes to this policy
We may update this policy; the current version and its effective date will always be posted here. Material changes will be flagged on this page.
14. Contact and grievance redressal
Privacy questions and requests: (e.g., privacy@brandacy.co)
Grievance Officer (required under Indian law): (name, designation, and contact; a named individual is mandatory under the DPDP Act / IT Rules; this cannot launch as a placeholder.) Postal: (registered address)