Privacy Notice.
How SMMARUN collects, uses, stores, and protects your personal data, and the rights you hold under India's Digital Personal Data Protection Act 2023, the EU and UK General Data Protection Regulations, the California Consumer Privacy Act / California Privacy Rights Act, and the other laws identified in section 13.
Who we are
SMMARUN Management Consortium Associates LLP, LLPIN ACT-2625, a limited liability partnership registered in India with its registered office at Gurugram, Haryana, India. For the purposes of the DPDPA we are a Data Fiduciary under section 2(i); for the GDPR / UK GDPR we are a controller under Article 4(7); for the CCPA / CPRA we are a business under section 1798.140(d). Referred to in this Notice as SMMARUN, we, us, or our.
For any question about this Notice or about your personal data, please write to hello@smmarun.ai, or to the Grievance Officer named in section 12.
What this Notice covers
This Notice explains how we collect, use, store, share, and protect personal data of visitors to this website (smmarun-site.vercel.app, with primary apex domain smmarun.ai as configured), and the rights you hold under the DPDPA, the GDPR / UK GDPR, the CCPA / CPRA, and the other laws identified in section 13.
It applies to:
- Visitors and prospective clients reading this site.
- People who fill in a Begin a conversation form.
- People who request gated content from our Library.
- Recipients of SMMARUN client communications and event invitations, where you have consented or where we rely on a balanced legitimate interest.
- Individuals whose personal data we receive from clients in the course of an engagement, in which case the controlling agreement and our Data Processing Addendum apply.
The personal data we collect
Information you give us
When you fill in a Begin a conversation form, you give us your name, work email, company, and the contents of your message. When you request a Library paper, you give us your name, work email, company, and (optionally) the role you hold.
Information collected automatically, only with your consent
When you accept analytics cookies we collect basic usage data: pages visited, approximate location (country or region), device type, referring source, and time spent reading, through Google Analytics 4 with IP anonymisation at intake, Google Signals disabled, and a 14-month retention window. Without your consent we do not collect this data. See our Cookie Policy for the full cookie list.
Sensitive personal information
We do not solicit Sensitive Personal Data (DPDPA), Special Category Data (GDPR Article 9), or Sensitive Personal Information (CCPA section 1798.140(ae)) through this site. If you submit any inadvertently, we will return or delete it and not retain it.
Children's data
We do not direct the website at, and do not knowingly collect personal data from, individuals under 18 (a child under DPDPA section 9), under 16 (default GDPR), or under 13 (COPPA). Where collection of a child's personal data is necessary we will obtain verifiable parental consent before processing (DPDPA section 9(1)); we do not track, behaviourally monitor, or target advertising at children (section 9(3)). See our Children's Data Notice for the full framework.
Lawful grounds for processing
Under the DPDPA we may process personal data only on lawful grounds. Mapped to each regime, the grounds we rely on are:
- Consent (DPDPA section 6 / GDPR Article 6(1)(a) / CCPA opt-in for sensitive PI): for analytics cookies, marketing communications, and storage of an enquiry beyond the immediate response window.
- Legitimate uses (DPDPA section 7) / contract performance (GDPR Article 6(1)(b)): to respond to a specific voluntary enquiry and to perform contractual obligations to clients.
- Legal obligation (DPDPA section 7(d) / GDPR Article 6(1)(c)): record-keeping under the Income-tax Act 1961 section 44AA, the Companies Act 2013 section 128, the IT (Intermediary Guidelines) Rules 2021, and CERT-In Directions of 28 April 2022.
- Legitimate interests (GDPR Article 6(1)(f)): for B2B marketing activities, site security, and aggregated analytics. A copy of our legitimate-interest balancing assessment is available on request.
You may withdraw consent at any time by the same means by which you gave it. Withdrawal does not affect the lawfulness of processing already carried out under that consent.
What we do with your data
We use your personal data to:
- Respond to your enquiry and arrange the conversation you requested.
- Send any paper or document you have explicitly requested.
- Improve the website with aggregated analytics, when you consent.
- Comply with applicable laws and regulatory obligations.
- Defend against fraud, abuse, and security threats.
- Send SMMARUN client communications and event invitations, where you have consented or where the legitimate-interest test is met.
We do not sell personal data. We do not use your personal data to train artificial-intelligence or machine-learning models, neither our own nor those of third-party LLM providers. Where we run any AI in the back office (for example, drafting tools used by our team to prepare deliverables for clients), those tools do not produce decisions with legal or similarly significant effects on you (DPDPA section 10(d); GDPR Article 22; EU AI Act Article 50). See our AI Use Disclosure for the full picture.
Who we share your data with
We share personal data only with:
- Our partners, staff, and contractors, bound by confidentiality, to deliver the conversation you requested or the engagement we are running for a client.
- Our processors, who process data under our written instructions (see the sub-processor table below).
- Professional advisors (legal, accounting, audit) where necessary.
- Authorities, when compelled by law or where necessary to protect our legitimate interests.
We do not share personal data with third parties for their own marketing.
Sub-processors
The infrastructure and software vendors that process personal data on our behalf, the categories of data each handles, and the hosting region each operates in:
| Sub-processor | Purpose | Data categories | Region · DPF status |
|---|---|---|---|
| Vercel Inc. | Website hosting, content delivery, request logs. | IP address, user-agent, request metadata. | United States, global edge cache. EU-US DPF participant. |
| Microsoft Corporation | Dynamics 365 CRM. Stores conversation enquiries and gated-content requests submitted through forms. | Name, work email, company, role, message contents, consent record. | India: Pune. EU-US DPF participant for cross-border transfers. |
| Google LLC | Google Analytics 4. Aggregated site usage measurement, only when you consent. | Pseudonymous client identifier, page paths, approximate geography, device type, referrer. | United States, with regional servers. EU-US DPF participant. |
We update this table before introducing a new sub-processor, with at least 30 days' advance notice.
Cross-border transfers
Some of our processors are located outside India. DPDPA section 16 permits cross-border transfer unless the destination is restricted by Central Government notification, a list we monitor monthly. Where personal data of EU / EEA or UK data subjects is transferred outside the EEA / UK, we rely on:
- The European Commission's Standard Contractual Clauses (Decision 2021/914, Modules 2 and 3), or the UK International Data Transfer Addendum 2022.
- The EU-US Data Privacy Framework where the importer is a DPF-certified entity.
- Supplementary technical and organisational measures: encryption in transit at TLS 1.2+, encryption at rest at AES-256 where supported, role-based access controls, and contractual challenge rights to government-access requests.
A Transfer Impact Assessment summary, completed per Schrems II (C-311/18), is available on request.
How long we keep your data
- Conversation enquiries: 12 months from your last interaction, sufficient to support reasonable follow-up and within the limitation-of-actions period for any pre-contract claim, unless a longer period is needed to fulfil a contract or comply with law.
- Engaged client records: for the duration of the engagement plus 7 years for tax record-keeping under the Income-tax Act 1961 section 44AA, books-of-account retention under the Companies Act 2013 section 128, and regulatory record-keeping under applicable sectoral rules.
- Analytics data: 14 months in Google Analytics 4, shorter than the GA4 default of 26 months, with IP anonymisation at intake and Google Signals disabled.
- Consent records: for as long as we hold consent plus 3 years after withdrawal, as evidence of the consent transaction (DPDPA section 6(3)).
How we protect your data
We apply reasonable security practices aligned with ISO/IEC 27001:2022, ISO/IEC 27701:2019, and (for AI processing) ISO/IEC 42001:2023: role-based access controls with quarterly review; encryption in transit (TLS 1.2+) and at rest (AES-256 where the processor supports it); vendor-risk diligence on our processors through a documented Third-Party Risk Management framework; and an internal data-protection incident protocol.
If a personal-data breach affects you, we will notify you in writing without undue delay and within the timelines required by applicable law. We will notify the Data Protection Board of India within the timeline notified under DPDPA rules, the lead Supervisory Authority under GDPR / UK GDPR within 72 hours of becoming aware where required (Article 33), and CERT-In within 6 hours per the 28 April 2022 Directions.
Your rights
You have the right to:
- Access the personal data we hold about you, in a structured form.
- Correction of inaccurate or out-of-date data.
- Completion of incomplete data.
- Erasure of personal data we no longer need.
- Grievance redressal through our Grievance Officer (section 12).
- Withdraw consent at any time, by the same means by which you gave it.
- Nominate another person to exercise your rights in case of death or incapacity.
Where the GDPR or UK GDPR applies, you additionally have the right to restriction of processing (Article 18); data portability (Article 20); objection to processing on legitimate-interest grounds (Article 21), with an absolute right to object to direct marketing; not to be subject to automated individual decision-making, including profiling, with legal or similarly significant effects (Article 22); and to lodge a complaint with your lead Supervisory Authority (Article 77), in India the Data Protection Board, in the UK the ICO, in the EU the EDPB and your national SA.
Where the CCPA / CPRA applies, you additionally have the right to know the categories and specific pieces of personal information we have collected (section 1798.110); delete personal information (section 1798.105); correct inaccurate information (section 1798.106); opt out of sale or sharing for cross-context behavioural advertising (section 1798.120). We honour Global Privacy Control signals as a valid request. You also have the right to limit the use of Sensitive Personal Information (section 1798.121), and to non-discrimination for the exercise of CCPA rights (section 1798.125).
To exercise any of these rights, write to hello@smmarun.ai with the subject Privacy request, or use our Data Subject Rights Portal. We will respond within the timelines prescribed by the applicable law.
Cookies
This site uses cookies. Strictly necessary cookies cannot be disabled because they are required for the site to function. Analytics cookies are set only with your express, prior, granular opt-in consent. We do not deploy marketing or advertising cookies. You can change your cookie choice at any time using the Manage cookies link in the footer or by withdrawing consent through the same mechanism by which you gave it. See the full Cookie Policy.
Grievance Officer
Under the DPDPA and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (as amended 2023), SMMARUN designates a Grievance Officer to receive complaints about the processing of personal data.
Grievance Officer Name: Preeti Mohan (Chief Responsible AI Governance) Email: preeti.mohan@smmarun.ai Postal: SMMARUN Management Consortium Associates LLP, LLPIN ACT-2625, Gurugram, Haryana, India.
We will acknowledge receipt of a grievance within 24 hours and aim to resolve it within 15 calendar days, in line with applicable rules.
Data Protection Officer; jurisdiction-specific notices
Until SMMARUN is notified as a Significant Data Fiduciary under DPDPA section 10, the Grievance Officer also discharges the DPO function. Visitors based in the EEA may direct EU GDPR queries to the same address with the subject GDPR request. UK visitors may direct UK GDPR queries with the subject UK GDPR request. California residents may direct CCPA / CPRA requests with the subject CCPA request. This Notice is supplemented (and not replaced) by jurisdiction-specific notices published on our Legal section, including a UK & EEA Annex, a California Notice at Collection, and a Children's Data Notice.
Changes to this Notice
We may update this Notice from time to time. Material changes will be flagged on the site in a banner that persists for at least 30 days from publication of the change and, for visitors who have provided an email address, by email to the address you provided. The Last reviewed date and version number below will be updated. Previous versions are available at /privacy/history or on request to hello@smmarun.ai.