Children's Data Notice.
SMMARUN's position on the personal data of children, under India's Digital Personal Data Protection Act, 2023 (§9), the United States' Children's Online Privacy Protection Act (15 U.S.C. §§6501-6506), and the EU General Data Protection Regulation (Article 8).
Who this notice is for
Parents and legal guardians who have reason to think a child of theirs may have provided personal data to SMMARUN. Regulators and supervisory authorities reviewing our child-data posture. Counsel, auditors, and procurement teams evaluating SMMARUN before engaging us. Anyone else who wants to understand how we treat children's personal data, and why.
If you are a parent or guardian and you want SMMARUN to return or delete data you believe relates to your child, the last section tells you how to reach us. We will acknowledge within 24 hours and resolve within 15 calendar days.
The site is not directed at children
SMMARUN is a business-to-business AI governance consultancy. Our website, our services, and the conversations we run with prospective clients are directed at adult professionals in regulated industries (banking, healthcare, pharma, education, public policy). The site is not designed for, marketed to, or intended to be used by children. We do not run consumer products, learning apps, games, or any other service that would plausibly attract a child audience.
We do not knowingly collect personal data from:
- Anyone under the age of 18, when the DPDPA 2023 applies (default for users in India).
- Anyone under the age of 16, when the GDPR applies (default in the EU, unless a member state has set a lower age in national law).
- Anyone under the age of 13, when COPPA applies (users in the United States).
If you are below the relevant threshold for your jurisdiction, please do not submit any personal data to us through this site.
Age-of-consent matrix
The three regimes that bind our processing of children's data, and what triggers each:
| Regime | Age threshold | What triggers it |
|---|---|---|
| DPDPA 2023, §9 (India) | Under 18 | The data principal is in India, or the processing is by a Data Fiduciary subject to the DPDPA. Verifiable parental consent is required before processing a child's personal data (§9(1)). Tracking, behavioural monitoring, and targeted advertising aimed at children are prohibited (§9(3)). |
| GDPR Article 8 (EU) | Under 16 (default; member states may lower to 13) | Information-society services offered directly to a child, where consent is the lawful basis. Parental authorisation is required below the threshold. |
| COPPA, 15 U.S.C. §§6501-6506 (US) | Under 13 | Operator of a website or online service directed to children, or actual knowledge that personal information is being collected from a child under 13. Verifiable parental consent and a clear privacy notice are required. |
Because SMMARUN treats the highest standard as the floor, our practical position is the DPDPA standard: we do not knowingly collect or process the personal data of anyone under 18, in any jurisdiction, through this site.
If a child has provided personal data to us
If we discover, or are notified by a parent or guardian, that personal data relating to a child has been submitted to us through this site, we will:
- Acknowledge the notice within 24 hours.
- Identify and isolate the data in our systems and in our sub-processors' systems (the sub-processor list is published on our Privacy Notice).
- On parental request, return the data in a structured form, or delete it permanently, or both.
- Confirm completion of the action in writing within 15 calendar days.
- Log the incident in our internal grievance register, with no public identification of the child.
A parent does not need to provide a reason. The fact that the data relates to their child is sufficient.
Verifiable parental consent
If, in the future, SMMARUN ever has a legitimate need to collect personal data from a child (for example, in connection with a research engagement directly authorised by a parent), we will only do so under DPDPA §9(1) verifiable parental consent. The workflow we would use:
- Parental identification. Verification of the parent's identity through a government-issued document, cross-checked against an independent record.
- Dual-channel confirmation. Confirmation of consent through two separate channels (for example, signed PDF returned by email, and a follow-up confirmation by telephone or video call).
- Signed consent on record. A dated, scoped consent statement, signed by the parent, specifying exactly what data, for what purpose, for how long, and with what right of withdrawal.
- Scope-bound processing. Processing strictly within the limits of the signed consent. No secondary use, no profiling, no transfer to third parties beyond the named sub-processors.
- Annual re-confirmation. If the engagement runs longer than 12 months, parental consent is re-confirmed in writing each year.
If we cannot complete the workflow, we do not collect the data. There are no shortcuts in this section.
Prohibited under DPDPA §9(3)
The following are prohibited at SMMARUN, in respect of any data of a child, irrespective of consent:
- Tracking of a child across this site or across sites.
- Behavioural monitoring of a child, including the construction of any profile or inferred-attribute record.
- Targeted advertising aimed at a child, by us or by any sub-processor acting on our behalf.
This is reaffirmed under GDPR Article 8 (which requires special protection of children's data and prohibits relying on a child's own consent in the same way as an adult's), and under COPPA's regulations on data minimisation and parental control (16 CFR §312.5 and surrounding).
How a parent can exercise rights
A parent or legal guardian can ask SMMARUN to return, delete, or stop processing personal data relating to their child. There is no form to fill in and no fee.
Grievance Officer Name: Preeti Mohan Email: preeti.mohan@smmarun.ai with the subject Children's Data request. Postal: SMMARUN Management Consortium Associates LLP, Gurugram, Haryana, India.
We will acknowledge receipt of a Children's Data request within 24 hours, and resolve it within 15 calendar days, in line with the DPDPA rules and our Grievance Officer process set out on the Privacy Notice.
Changes to this notice
We may update this notice from time to time, particularly if the rules under the DPDPA or any of the other regimes named here are amended. Material changes will be flagged on the site at the top of the next visit, and the Last reviewed date below will be updated. Previous versions are available on request.