This Privacy Policy describes how Equim Private Limited (“Company,” “we,” “us,” or “our”), operating the website https://www.equimdesigns.com/ (“Equim Designs” or the “Platform”), collects, uses, stores, discloses, and safeguards your personal data when you visit our website, submit inquiries, subscribe to communications, or engage our services.
We are committed to maintaining the highest privacy and data protection standards across all jurisdictions in which we operate, with primary operations based in India and compliance mechanisms established for international visitors from the European Economic Area, United Kingdom, and the United States.
01
Information We Collect
We collect information directly provided by you, technical data generated automatically through your device, and transactional information from integrated third-party service providers.
A. Personal Information You Directly Provide
- –Identity & Account Data: Full name, username, age, password credentials (stored using irreversible cryptographic salted hash algorithms), and professional job titles.
- –Contact Information: Primary email address, mobile/telephone number, postal mailing address, and physical shipping details.
- –Billing & Payment Data: Invoicing name, billing address, and transaction metadata. Card, net-banking, and UPI details are securely tokenized and processed via our PCI-DSS-compliant payment gateway (Razorpay) and are never stored on our servers.
- –Communications & Inquiries: Messages and inquiries submitted via our contact forms (https://www.equimdesigns.com/contact), email correspondence, feedback submissions, and client support requests.
B. Information Collected Automatically
- –Device & Technical Telemetry: Internet Protocol (IP) address, browser model and version, operating system, device identifiers, preferred language, and time-zone settings.
- –Geolocation Data: Approximate or precise geographic location determined via IP address lookup and interactive Google Maps API interactions when requested by you.
- –Usage & Navigation Data: Referring URLs, navigation pathways, page dwell time, clickstream actions, bounce rates, and scrolling telemetry.
- –Tracking Technologies: Browser cookies, session storage, local storage variables, and web beacons (pixel tags).
02
Legal Bases for Processing (GDPR & Global Standards)
We process personal data only when supported by valid lawful bases under applicable data protection laws:
- –Consent: Where you have given unambiguous, informed consent (e.g., subscribing to our newsletters, opting into marketing updates, or accepting non-essential cookie tracking).
- –Contractual Necessity: Where processing is necessary to execute a contract, deliver architectural/design consulting services, create user accounts, or process orders.
- –Legitimate Interests: Where processing serves our legitimate business interests, including infrastructure security, fraud prevention, server optimization, and web analytics, provided such interests are not overridden by your fundamental privacy rights.
- –Legal Obligation: Where processing is required to comply with statutory accounting, Indian tax laws, corporate records maintenance, or court mandates.
03
Purpose of Data Collection and Processing
Your personal information is collected and processed for the following clear business purposes:
- –Platform Operation: To operate, secure, troubleshoot, and maintain the Equim Designs website and client portal.
- –Client Communications & Support: To process inquiries submitted via our contact channels, provide project quotations, and coordinate client consultations.
- –Billing & Transactions: To facilitate secure client checkouts, issue compliant GST/tax invoices, and verify transactions via Razorpay.
- –Marketing & Newsletters: To distribute newsletters, design case studies, and studio announcements via Mailchimp and Google Workspace (subject to active opt-in).
- –Telemetry & Analytics: To evaluate visitor interaction, identify UX bottlenecks, and optimize site speed using Google Analytics 4.
- –Retargeting & Advertising: To deliver relevant advertising and measure campaign conversions across Meta platforms via the Facebook Pixel.
04
Third-Party Service Providers and Sub-Processors
We share data with vetted third-party service providers bound by contractual data protection agreements to support our operations:
| Service Category | Sub-Processor / Provider | Operational Purpose |
|---|
| Hosting & Edge Delivery | Vercel Inc. & Cloudflare Pages | Platform hosting, SSL management, edge caching, and DNS routing. |
| Web Analytics | Google LLC (Google Analytics 4) | Aggregated traffic telemetry, page interaction metrics, and performance analytics. |
| Digital Advertising | Meta Platforms, Inc. (Facebook Pixel) | Ad conversion tracking, audience syndication, and retargeting. |
| Email Communications | Mailchimp (Intuit Inc.) & Google Workspace | Newsletter broadcasting, transactional notifications, and client correspondence. |
| Payment Gateway | Razorpay Software Private Limited | Secure payment gateway processing, UPI/card checkouts, and fraud prevention. |
| Mapping & Geolocation | Google LLC (Google Maps API) | Interactive studio location maps and address resolution. |
We do not sell your personal information to third-party data brokers for monetary compensation.
05
Cookies and Tracking Technologies
Equim Designs utilizes cookies, local storage variables, and tracking pixels to ensure seamless website performance and tailored marketing:
- –Essential Cookies: Strictly required for core platform navigation, security tokens, session management, and server routing. These cannot be disabled.
- –Analytics Cookies: Deployed through Google Analytics 4 to record anonymous usage patterns, referral origins, and bounce rates.
- –Marketing & Retargeting Pixels: Deployed through Meta Facebook Pixel to evaluate marketing campaign performance and serve tailored advertisements to visitors across external platforms.
Managing Preferences: You can customize your cookie settings at any time using our on-site cookie banner or through your browser configuration. Disabling certain cookies may limit platform functionality.
06
International Data Transfers
Equim Private Limited operates primarily from India. Given our use of globally distributed infrastructure vendors (such as Vercel, Cloudflare, Google, and Meta), your personal information may be transferred to, processed, and stored on cloud servers located in India, the United States, and other international jurisdictions.
For transfers of personal data originating from the European Economic Area (EEA) or the United Kingdom to countries without an adequacy decision, we enforce European Commission-approved Standard Contractual Clauses (SCCs) and verify that our sub-processors implement equivalent technical and administrative safeguards.
07
Data Retention and Security Safeguards
- –Data Retention: We retain personal data only for as long as necessary to fulfill the purposes set forth in this policy, unless longer retention is required under statutory Indian tax, GST, and corporate accounting regulations (generally up to 7 to 8 years for billing and invoice records).
- –Security Safeguards: We enforce industry-standard security protocols, including HTTPS / TLS 256-bit encryption in transit, strict role-based access control (RBAC), encrypted database backups, and routine vulnerability monitoring.
08
Specific Provisions for India (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), you act as a Data Principal and Equim Private Limited acts as a Data Fiduciary.
A. Data Principal Rights
- –Right to Access & Information: Obtain a summary of the personal data held about you and the processing activities undertaken.
- –Right to Correction & Erasure: Request the correction of misleading or inaccurate data, completion of incomplete records, or erasure of data no longer necessary.
- –Right to Withdraw Consent: Withdraw previously granted consent at any time via written notice to our Grievance Officer.
- –Right of Grievance Redressal: Access an effective and timely dispute resolution mechanism for privacy-related grievances.
- –Right to Nominate: Nominate an individual to exercise data rights on your behalf in the event of death or incapacity.
B. Grievance Redressal Mechanism & Officer Details
In compliance with Section 6 and Section 8 of the DPDP Act 2023, the details of our designated Grievance Redressal Officer are published below:
Grievance Redressal OfficerChinmay Gaur
Direct Telephone+91 8563856618
Operational Office AddressHD-12, First Floor, Tower C, The Iconic Corenthum, Sector 62, Noida, Uttar Pradesh, India - 201301
Registered Corporate AddressE-88, Yamunapuram, Bulandshahr, Uttar Pradesh, India - 203001
Escalation: If your grievance is not addressed satisfactorily by our Grievance Redressal Officer within thirty (30) days, you have the statutory right to file a complaint before the Data Protection Board of India.
09
Specific Provisions for California & US Residents (CCPA/CPRA & CalOPPA)
This section applies exclusively to California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and CalOPPA.
A. Categories of Personal Information Collected (Past 12 Months)
- –Identifiers: Real name, alias, email address, postal address, IP address, unique personal identifiers.
- –Commercial Information: Commercial transaction records, products/services viewed, and billing records.
- –Internet & Network Activity: Browsing history, search history, and interactions with our website or digital advertisements.
- –Geolocation Data: General location derived from IP address telemetry.
B. Sale and Sharing of Personal Data
- –Sale of Data: We do not sell personal information for monetary compensation.
- –Cross-Context Advertising (“Sharing”): We utilize third-party pixels (Meta Facebook Pixel) for retargeting and conversion analytics. Under CPRA, this activity is classified as “sharing” personal information for cross-context behavioral advertising.
C. California Consumer Privacy Rights
- –Right to Know & Access: Request disclosure of categories and specific pieces of data collected, sources, and third parties with whom data was shared.
- –Right to Delete: Request deletion of your personal data, subject to legal retention exemptions.
- –Right to Correct: Request correction of inaccurate personal records.
- –Right to Opt-Out of Sharing: Direct us not to share your data for cross-context behavioral advertising.
- –Right to Non-Discrimination: We will never deny services, charge differing prices, or provide a lower quality of service for exercising your statutory privacy rights.
D. Exercising Opt-Out and Global Privacy Control (GPC)
- –Website Footer Link: You may exercise your right to opt out of data sharing by clicking the “Do Not Sell or Share My Personal Information” link in our website footer.
- –Global Privacy Control (GPC): Our website is engineered to detect and honor Global Privacy Control (GPC) browser signals. When a valid GPC signal is received from your browser, our platform automatically suppresses third-party retargeting scripts and treats the request as a valid opt-out.
E. CalOPPA “Do Not Track” Disclosures
Aside from automated Global Privacy Control (GPC) signals, our website does not currently alter its behavior in response to generic browser “Do Not Track” (DNT) header signals due to the lack of industry-wide technical consensus.
10
Specific Provisions for the European Economic Area & UK (GDPR)
If you are a resident of the European Economic Area (EEA) or the United Kingdom, you hold the following rights under GDPR Articles 15 through 22:
- –Right of Access (Art. 15): Obtain confirmation of whether your data is processed and request copies.
- –Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- –Right to Erasure (Art. 17): Request deletion of data where retention is no longer justified.
- –Right to Restriction (Art. 18): Request the restriction of processing under contested circumstances.
- –Right to Data Portability (Art. 20): Obtain your data in a structured, commonly used, machine-readable format.
- –Right to Object (Art. 21): Object to data processing based on legitimate interests or direct marketing.
- –Right to Lodge a Complaint: Lodge a formal complaint with your local EU Data Protection Authority or the UK Information Commissioner's Office (ICO).
To exercise any of these rights, please submit a written request to contact@equimdesigns.in.
11
Children's Privacy (Strict 18+ Policy)
Equim Designs is strictly intended for individuals who are eighteen (18) years of age or older. In accordance with the Digital Personal Data Protection Act of India, US Children's Online Privacy Protection Act (COPPA), and the GDPR, we do not knowingly market to, track, or collect personal data from minors under the age of 18.
If we discover that personal data has been inadvertently submitted by a minor under 18 without verifiable parental consent, we will promptly delete such records from our databases. If you believe a minor has provided data on our site, please notify us immediately at contact@equimdesigns.in.
12
Updates and Modifications to This Policy
We may update this Privacy Policy from time to time to maintain compliance with evolving regulatory standards or website enhancements. Material modifications will be indicated by updating the “Last Updated” date at the top of this document, displaying a notice on our website, or sending direct email notifications to active subscribers.