Privacy Policy

How ThinkTara Global collects, uses, and protects your information 

ThinkTara Global Private Limited  ·  thinktaraglobal.com  ·  sales@thinktaraglobal.com 

38/4/1, First Floor Office, No. 103 Krushna Park, Dukirkline, Pune City, Pune, Maharashtra, India – 411014 

CIN: U73100PN2025PTC240087  ·  Udyam: UDYAM-MH-26-0890056  ·  Startup India: DIPP204613 

Last Updated: April 2025 

ThinkTara Global Private Limited (“we”, “us”, “our”) is committed to protecting the privacy and security of personal and business information provided to us through the Website and in the course of our services. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights in relation to it. 

This Policy applies to all visitors to thinktaraglobal.com, all enquirers, and all Clients engaged in Revenue Consulting or Lead Generation Services. By using the Website or engaging our services, you acknowledge and accept this Policy. 

ThinkTara Global operates an Information Security Management System certified to ISO/IEC 27001:2022 and a Privacy Information Management System certified to ISO/IEC 27701:2019. These certifications reflect our commitment to managing personal and business data responsibly.

1. DATA WE COLLECT

1.1  Website Visitor Data 

When you visit the Website, we may automatically collect: IP address, browser type and version, operating system, pages viewed, time spent, referral source, and device identifiers. This data is collected via analytics tools and cookies (described in the Cookie Policy) for the purpose of understanding Website usage and improving the user experience. 

1.2  Enquiry and Contact Data 

When you submit an enquiry through the Website, email, or any other channel, we collect: your name, job title, company name, email address, phone number, and the content of your message. This data is used solely to respond to your enquiry and to provide relevant information about our services. 

1.3  Revenue Consulting Engagement Data 

In the course of a Revenue Consulting engagement, we collect and process sensitive business information provided by the Client including: revenue and financial performance data, team structure and headcount information, customer and prospect details, CRM data and configurations, sales process information, positioning and messaging materials, and strategic plans. This information is shared in confidence for the sole purpose of delivering the agreed engagement. It is not used for any other purpose and is not shared with any third party without the Client’s explicit consent. 

1.4  Lead Generation Campaign Data 

In the course of delivering Lead Generation Services, we process campaign targeting data provided by the Client including: target audience parameters, industry and company filters, job title and seniority criteria, and approved content assets. We also generate and process prospect contact data including names, email addresses, job titles, and company information, sourced from compliant B2B data providers and our own permission-based databases. All such data is processed in accordance with applicable data protection laws. 

1.5  Communications Data 

We retain records of email correspondence, meeting notes, and other communications with enquirers and Clients for operational, legal, and compliance purposes. 

2. LEGAL BASIS FOR PROCESSING

We process personal data on the following legal bases: 

  • Consent – where you have provided explicit consent, such as subscribing to communications or submitting an enquiry. 
  • Contractual necessity – where processing is necessary to fulfil our obligations under a signed engagement agreement. 
  • Legitimate interests – where processing is necessary for our legitimate business interests, such as improving the Website, responding to enquiries, and maintaining security, provided these interests are not overridden by your rights. 
  • Legal obligation – where processing is required to comply with applicable laws and regulations. 

3. HOW WE USE YOUR DATA

We use collected data for the following purposes: 

  • To respond to enquiries and provide information about our services. 
  • To deliver Revenue Consulting or Lead Generation Services under a signed engagement. 
  • To manage the Website, monitor usage, and improve performance and content. 
  • To send service-related communications including updates, invoices, and engagement reports. 
  • To comply with legal, regulatory, and contractual obligations. 
  • To detect, investigate, and prevent fraud, security breaches, and misuse. 
  • To protect the rights, property, and safety of the Company, its staff, and its clients. 

We do not use personal data for automated profiling or automated decision-making that produces legal or similarly significant effects.

4. DATA SHARING AND DISCLOSURE

We do not sell, rent, or trade personal data to any third party for marketing purposes. 

We may share data in the following limited circumstances: 

  • Service providers – third-party contractors, data platforms, or technology providers engaged to support delivery of Lead Generation Services, subject to appropriate data processing agreements. 
  • Professional advisors – lawyers, accountants, auditors, or insurers where required for legitimate business purposes. 
  • Regulatory authorities – where required by law, court order, or regulatory directive. 
  • Business transfers – in the event of a merger, acquisition, or sale of the business, personal data may transfer to the successor entity, subject to the same privacy protections. 

Revenue Consulting engagement data – including all Client business information shared during an engagement – is never disclosed to any third party without the Client’s explicit written consent. This data is treated as Confidential Information under these Terms and the relevant engagement agreement. 

5. INTERNATIONAL DATA TRANSFERS

ThinkTara Global is incorporated in India and primarily processes data within India. Where data is transferred to or accessed from outside India  for example, in the course of Lead Generation campaigns serving international clients  such transfers are conducted in compliance with applicable data protection laws including the GDPR, CCPA, and the DPDP Act 2023, using appropriate safeguards including contractual protections and data processing agreements.

6. DATA RETENTION

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. 

  • Website visitor and enquiry data – retained for up to 24 months from last interaction, unless a commercial engagement follows. 
  • Revenue Consulting engagement data – retained for a period of 5 years following the conclusion of the engagement, to satisfy legal, audit, and dispute resolution requirements. 
  • Lead Generation campaign data – retained in accordance with the terms of the applicable service agreement, typically for the duration of the campaign plus 12 months. 
  • Financial and contractual records – retained for the period required under Indian law, typically 7 years. 

Upon expiry of the relevant retention period, data is securely deleted or anonymised. 

7. DATA SECURITY

We implement and maintain industry-standard technical and organisational security measures to protect personal and business data against unauthorised access, loss, destruction, or alteration. Our security measures are aligned with the ISO/IEC 27001:2022 Information Security Management System standard and include: 

  • Access controls – role-based access to data systems, with access limited to those who require it for their work. 
  • Encryption – data transmitted to and from the Website is encrypted using TLS. Sensitive data at rest is encrypted where appropriate. 
  • Audit logging – access to sensitive data systems is logged and reviewed. 
  • Security assessments – regular internal reviews of security practices and controls. 
  • Staff training – all personnel with access to personal data are trained on data protection obligations. 

No security system is entirely impenetrable. While we take all reasonable steps to protect data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in risk to your rights, we will notify you and relevant regulatory authorities in accordance with applicable law.

8. YOUR RIGHTS

Depending on your location and the applicable data protection law, you may have the following rights in relation to your personal data: 

  • Right to access – to request a copy of the personal data we hold about you. 
  • Right to rectification – to request correction of inaccurate or incomplete data. 
  • Right to erasure – to request deletion of your personal data, subject to legal retention requirements. 
  • Right to restriction – to request that we limit how we use your data in certain circumstances. 
  • Right to data portability – to request your data in a structured, machine-readable format. 
  • Right to object – to object to processing based on legitimate interests. 
  • Right to withdraw consent – where processing is based on consent, to withdraw it at any time without affecting prior processing. 

To exercise any of these rights, please contact us at sales@thinktaraglobal.com. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing a request. 

9. APPLICABLE DATA PROTECTION LAWS

ThinkTara Global processes personal data in compliance with the following applicable laws and regulations, as relevant to the jurisdiction of the data subject: 

  • Digital Personal Data Protection Act, 2023 (DPDP Act) – India 
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 – India 
  • General Data Protection Regulation (GDPR) – European Union 
  • California Consumer Privacy Act (CCPA) – United States (California) 
  • Personal Information Protection and Electronic Documents Act (PIPEDA) – Canada 
  • The Privacy Act 1988 (Australian Privacy Principles) – Australia 
  • ePrivacy Directive 2002/58/EC – European Union 
  • CAN-SPAM Act 2003 – United States 
  • TRAI Telecom Commercial Communications Customer Preference Regulations – India 

10. CHILDREN'S PRIVACY

The Website and Services are intended for business professionals and are not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted data to us, please contact us immediately.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. Changes will be posted on the Website with a revised effective date. Continued use of the Website after changes are posted constitutes acceptance of the updated Policy. 

12. CONTACT AND COMPLAINTS

For any privacy-related questions, requests, or concerns, contact us at: sales@thinktaraglobal.com or write to: ThinkTara Global Private Limited, 38/4/1, First Floor Office, No. 103 Krushna Park, Dukirkline, Pune City, Pune, Maharashtra, India – 411014. 

If you are located in the European Union and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.