Privacy Policy

How ThinkTara Global collects, uses, and protects your information 

ThinkTara Global Private Limited  ·  thinktaraglobal.com  ·  sales@thinktaraglobal.com 

38/4/1, First Floor Office, No. 103 Krushna Park, Dukirkline, Pune City, Pune, Maharashtra, India – 411014 

CIN: U73100PN2025PTC240087  ·  Udyam: UDYAM-MH-26-0890056  ·  Startup India: DIPP204613 

Last Updated: March 2025 

ThinkTara Global Private Limited (“we”, “us”, “our”) is committed to protecting the privacy and security of personal and business information provided to us through the Website and in the course of our services. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights in relation to it. 

This Policy applies to all visitors to thinktaraglobal.com, all enquirers, and all Clients. By using the Website or engaging our services, you acknowledge and accept this Policy. ThinkTara Global operates an Information Security Management System certified to ISO/IEC 27001:2022 and a Privacy Information Management System certified to ISO/IEC 27701:2019. 

1. DATA WE COLLECT

1.1 Website Visitor Data 

When you visit the Website, we may automatically collect: IP address, browser type and version, operating system, pages viewed, time spent, referral source, and device identifiers. This data is collected via analytics tools and cookies (described in the Cookie Policy) to understand Website usage and improve the user experience. 

1.2 Enquiry and Contact Data 

When you submit an enquiry through the Website, email, or any other channel, we collect: your name, job title, company name, email address, phone number, and the content of your message. This data is used solely to respond to your enquiry and to provide relevant information about our services. 

1.3 Revenue Consulting Engagement Data 

In the course of a Revenue Consulting engagement, we review sensitive business information provided by the Client, which may include revenue and performance data, team structure, customer and prospect details, CRM data, sales process information, and strategic plans. We act as a confidential reviewer of the Client’s own data for the sole purpose of diagnosing and designing the revenue system. We do not build or retain prospect databases as part of Revenue Consulting. This information is held in confidence, used only for the engagement, and is never shared with any third party without the Client’s explicit written consent. 

1.4 Lead Generation Campaign Data 

Where we deliver Lead Generation Services as an add-on, we process campaign targeting data provided by the Client and generate prospect contact data (names, business email addresses, job titles, and company information) sourced from compliant B2B data providers and permission-based databases. This is the service line in which we process third-party personal data most extensively, and all such processing is carried out in accordance with the applicable data protection laws listed in Clause 9. 

1.5 Communications Data 

We retain records of email correspondence, meeting notes, and other communications with enquirers and Clients for operational, legal, and compliance purposes. 

2. LEGAL BASIS FOR PROCESSING

We process personal data on the following legal bases: consent (where you have provided explicit consent, such as submitting an enquiry); contractual necessity (where processing is necessary to fulfil our obligations under a signed engagement agreement); legitimate interests (such as improving the Website, responding to enquiries, and maintaining security, provided these interests are not overridden by your rights); and legal obligation (where required to comply with applicable law). 

3. HOW WE USE YOUR DATA

  • To respond to enquiries and provide information about our services; 
  • To deliver Revenue Consulting or Lead Generation Services under a signed engagement; 
  • To manage the Website, monitor usage, and improve performance and content; 
  • To send service-related communications including updates, invoices, and engagement reports; 
  • To comply with legal, regulatory, and contractual obligations; 
  • To detect, investigate, and prevent fraud, security breaches, and misuse; 
  • To protect the rights, property, and safety of the Company, its staff, and its clients. 

We do not use personal data for automated profiling or automated decision-making that produces legal or similarly significant effects. 

4. DATA SHARING AND DISCLOSURE

We do not sell, rent, or trade personal data to any third party for marketing purposes. We may share data only in these limited circumstances: with service providers and technology platforms engaged to support delivery of Lead Generation Services, subject to data processing agreements; with professional advisors (lawyers, accountants, auditors, insurers) where required; with regulatory authorities where required by law, court order, or regulatory directive; and in the event of a merger, acquisition, or sale of the business, subject to the same privacy protections. 

Revenue Consulting engagement data — including all Client business information shared during an engagement — is never disclosed to any third party without the Client’s explicit written consent, and is never used in our marketing or to benefit any other client. 

5. INTERNATIONAL DATA TRANSFERS

ThinkTara Global is incorporated in India and primarily processes data within India. Where data is transferred to or accessed from outside India — for example, in the course of Lead Generation campaigns serving international clients — such transfers are conducted in compliance with applicable data protection laws including the GDPR, the CCPA, and the DPDP Act 2023, using appropriate safeguards including contractual protections and data processing agreements.

6. DATA RETENTION

  • Website visitor and enquiry data — retained for up to 24 months from last interaction, unless a commercial engagement follows; 
  • Revenue Consulting engagement data — retained for a period of 5 years following the conclusion of the engagement, to satisfy legal, audit, and dispute-resolution requirements, after which it is securely deleted or anonymised; 
  • Lead Generation campaign data — retained in accordance with the applicable service agreement, typically the campaign duration plus 12 months; 
  • Financial and contractual records — retained for the period required under Indian law, typically 7 years. 

7. DATA SECURITY

We implement and maintain industry-standard technical and organisational security measures aligned with the ISO/IEC 27001:2022 standard, including: role-based access controls limiting access to those who require it; encryption of data in transit using TLS, and of sensitive data at rest where appropriate; audit logging of access to sensitive systems; regular internal security reviews; and data-protection training for all personnel with access to personal data. No security system is entirely impenetrable; while we take all reasonable steps to protect data, we cannot guarantee absolute security. In the event of a data breach likely to result in risk to your rights, we will notify you and the relevant regulatory authorities in accordance with applicable law. 

8. YOUR RIGHTS

Depending on your location and the applicable law, you may have the right to: access the personal data we hold about you; request correction of inaccurate or incomplete data; request erasure (subject to legal retention requirements); request restriction of processing; request data portability; object to processing based on legitimate interests; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us at sales@thinktaraglobal.com. We will respond within the timeframe required by applicable law (typically 30 days) and may need to verify your identity first. 

9. APPLICABLE DATA PROTECTION LAWS

We process personal data in compliance with the following laws and regulations, as relevant to the jurisdiction of the data subject: the Digital Personal Data Protection Act, 2023 (India); the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India); the General Data Protection Regulation (GDPR, European Union); the California Consumer Privacy Act (CCPA, United States); the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada); the Privacy Act 1988 (Australia); the ePrivacy Directive 2002/58/EC (European Union); the CAN-SPAM Act 2003 (United States); and the TRAI Telecom Commercial Communications Customer Preference Regulations (India). Our data-protection obligations apply across all Services; the most extensive processing of third-party personal data occurs within Lead Generation Services, while Revenue Consulting involves the confidential review of a Client’s own data. 

10. CHILDREN'S PRIVACY

The Website and Services are intended for business professionals and are not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted data to us, please contact us immediately. 

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. Changes will be posted on the Website with a revised effective date. Continued use of the Website after changes are posted constitutes acceptance of the updated Policy. 

12. CONTACT AND COMPLAINTS

For any privacy-related questions, requests, or concerns, contact us at sales@thinktaraglobal.com or write to ThinkTara Global Private Limited at the registered office address above. If you are located in the European Union and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.