1. Who we are
This policy is published by Doingly Analysis & Consultancy (“Doingly”, “we”, “our”, or “us”). We are the data controller for personal information collected through our website, contact forms, client portal, and consulting engagements.
For privacy queries, data subject requests, or breach notifications, contact us at privacy@doingly.in.
2. Information we collect
We collect only the information needed to deliver and improve our services.
2.1 Information you provide directly
- Lead and contact form submissions. Name, email address, company, phone number where provided, and the contents of your message.
- Account information. Name, email address, and password hash for portal access. If you sign in with Google, we receive your name, email, and profile image from Google.
- Engagement information. Project briefs, deliverables, feedback, and any business information you choose to share during an engagement.
- Billing information. Invoice details and payment metadata. Card and bank credentials are processed by our payment provider and never stored on our servers.
2.2 Information we collect automatically
- Technical data. IP address and request metadata used by our rate limiter to protect authentication and contact endpoints from abuse. These records are short-lived.
- Application logs. Structured logs of significant events (sign-ins, password resets, invoice actions) for security, audit, and debugging. Sensitive payloads are excluded by design.
- Strictly necessary cookies. A session cookie set after you sign in. We do not use third-party advertising or analytics cookies by default.
3. How we use information
- To respond to your enquiries and deliver consulting engagements.
- To operate, secure, and improve the client portal.
- To issue invoices and accept payment for delivered work.
- To send transactional emails (password resets, invoice notifications).
- To meet legal, tax, and accounting obligations.
- To detect and prevent abuse of our systems.
We do not sell personal information. We do not use your information for advertising or for training third-party machine learning models.
4. Legal bases
We process personal information under the following lawful bases:
- Contract. To deliver the services you have engaged us for and to manage our agreement with you.
- Consent. When you submit a contact form, sign up for the portal, or opt in to specific communications.
- Legitimate interest. To secure our systems, prevent fraud, and analyse aggregate usage of our marketing site.
- Legal obligation. To comply with tax, accounting, and regulatory requirements in India.
5. Sub-processors
We rely on the following third-party services to deliver core functionality. Each has its own privacy practices and contractual data protection terms.
- Neon. Managed Postgres database hosting. Region: United States / European Union (region selectable).
- Resend. Transactional email delivery (password resets, invoices). Region: United States.
- Cloudinary. Image storage and delivery for marketing and admin uploads. Region: United States / Global CDN.
- Upstash Redis. Rate limiting on authentication and contact endpoints. Region: Global edge.
- Razorpay. Payment processing for invoices. Region: India.
- Google. Sign-in via Google OAuth (optional, user-initiated). Region: Global.
6. International transfers
Some sub-processors are located outside India. Where personal information is transferred internationally, we rely on the processor’s standard contractual terms and on regional safeguards required by applicable law. You may contact us for further detail on the safeguards in place.
7. Data retention
- Leads and contact submissions: retained for up to 24 months after last contact, then deleted or anonymised.
- Account data: retained while your account is active and for a reasonable period after closure to allow restoration on request.
- Engagement records and invoices: retained for the period required by tax and accounting law in India, currently no less than 8 years.
- Logs and rate-limit data: retained for short operational windows (typically days to weeks).
8. Your rights
Subject to applicable law, including the Digital Personal Data Protection Act 2023 of India and equivalent regimes such as the GDPR, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your information, subject to legal retention duties.
- Withdraw consent for processing based on consent.
- Object to processing based on legitimate interest.
- Request a portable copy of information you have provided.
- Lodge a complaint with the data protection authority in your jurisdiction.
To exercise any of these rights, write to privacy@doingly.in. We respond within 30 days or sooner where required by law.
9. Security
We protect personal information with industry-standard measures including TLS in transit, encryption at rest by our infrastructure providers, password hashing, least-privilege access, rate limiting on sensitive endpoints, and structured audit logs. No system is perfectly secure; if you discover a vulnerability, please report it responsibly to privacy@doingly.in.
10. Cookies
We use strictly necessary cookies to keep you signed in and to protect forms against abuse. We do not set advertising or third-party tracking cookies by default. If we add analytics in future, this policy will be updated and, where required, your consent will be requested first.
11. Children
Our services are intended for businesses and the professionals working in them. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided information to us, please contact us so we can delete it.
12. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
13. Changes to this policy
We may update this policy to reflect changes in our practices, services, or applicable law. Material changes will be highlighted on this page, and the “Last updated” date at the top will change. Continued use of our services after an update constitutes acceptance of the revised policy.
14. Contact
Privacy questions, requests, and complaints: privacy@doingly.in
General queries: hello@doingly.in