Privacy Policy
Last updated: 24 August 2026
1. Identity and Contact Details of the Data Fiduciary
Mindsspeak International Private Limited (trading as "Mindsspeak International"; hereinafter "we", "us", "our", "Company") is the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023. We are a private limited company incorporated under the Companies Act, 2013, operating from Bengaluru, Karnataka, India.
Registered Name: Mindsspeak International Private Limited
Registered Office: Bengaluru, Karnataka, India
Grievance Officer / Data Protection Contact:
- Email: [email protected]
- Phone: +91 9008 55 0102
- Response time: Within 48 hours on business days
2. Scope and Applicability
This Privacy Policy applies to all personal data collected through our website at mindsspeakinternational.com, our enquiry and booking forms, email correspondence, WhatsApp communications, and in the course of providing event management services. It applies to all Data Principals (individuals) whose personal data we process, whether located in India or abroad.
3. Personal Data We Collect
3.1 Data You Provide Directly
- Full name, designation, and organisation name
- Email address and phone number (including WhatsApp number)
- Event requirements, budget range, and preferred dates
- Billing address and payment details (processed via secure third-party payment gateways)
- Any other information you voluntarily share in correspondence
3.2 Data Collected Automatically
- IP address, browser type, operating system, and device information
- Pages visited, time spent, and referring URLs
- Cookie identifiers and session data (see Section 9)
We do not collect Sensitive Personal Data or Information (SPDI) as defined under the SPDI Rules (such as passwords, financial account details beyond what is necessary for billing, health data, biometric data, or sexual orientation) unless strictly required for a specific service and with your explicit consent.
4. Purpose and Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data only for lawful purposes with your free, specific, informed, unconditional, and unambiguous consent, or where processing is necessary for a legitimate use as permitted by law. The specific purposes are:
- Service Delivery: To respond to enquiries, prepare event proposals, execute event management contracts, and provide post-event support.
- Contractual Necessity: To fulfil obligations under agreements entered into with you or your organisation.
- Communication: To send service-related updates, invoices, and event logistics information.
- Legal Compliance: To comply with applicable Indian laws including the Companies Act, GST Act, Income Tax Act, and other statutory requirements.
- Legitimate Business Interests: To improve our website, services, and internal processes, where such interests are not overridden by your rights.
- Marketing (with consent only): To send promotional communications about our events and services, only where you have opted in.
We will not use your personal data for any purpose other than those stated above without obtaining fresh consent from you.
5. Consent
In accordance with the DPDP Act, 2023, where we rely on consent as the legal basis for processing:
- Consent is obtained before or at the time of data collection.
- You have the right to withdraw consent at any time by contacting us at [email protected]. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.
- Withdrawal of consent for service-related processing may affect our ability to provide services to you.
6. Data Retention
We retain personal data only for as long as necessary for the stated purpose or as required by law:
- Enquiry data: Up to 2 years from the date of last contact, unless converted to a client engagement.
- Client and contract data: Up to 8 years from the end of the engagement, in compliance with the Limitation Act, 1963 and applicable tax laws (GST, Income Tax).
- Financial and billing records: As required under the Companies Act, 2013 and GST Act (minimum 6 years).
- Marketing data: Until you withdraw consent or opt out.
Upon expiry of the retention period, personal data is securely deleted or anonymised.
7. Disclosure and Sharing of Personal Data
We do not sell, rent, or trade your personal data. We may share your data with:
- Data Processors: Third-party service providers (cloud hosting, email platforms, payment gateways, event technology vendors) who process data on our behalf under written data processing agreements that bind them to confidentiality and security obligations.
- Event Partners: Co-organisers, venue operators, or sponsors, only to the extent necessary for event delivery and with your knowledge.
- Legal and Regulatory Authorities: Government bodies, courts, or law enforcement agencies where required by law, court order, or to protect our legal rights, including under the IT Act, 2000, DPDP Act, 2023, or any other applicable statute.
- Professional Advisors: Lawyers, auditors, and accountants bound by professional confidentiality obligations.
Any third party receiving your data is required to handle it in accordance with applicable Indian data protection laws.
8. Cross-Border Transfer of Personal Data
Where personal data is transferred outside India (for example, to cloud service providers or international event partners), such transfers are made only to countries or entities notified by the Central Government of India as permissible under the DPDP Act, 2023, or where adequate safeguards are in place. We ensure that any cross-border transfer complies with Section 16 of the DPDP Act and applicable rules framed thereunder.
9. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies. These include:
- Strictly Necessary Cookies: Required for the website to function. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors use the site (e.g., pages visited, session duration). These are only activated with your consent.
- Preference Cookies: Remember your settings and preferences.
You can manage or disable non-essential cookies through your browser settings. Disabling cookies may affect certain website functionality.
10. Security of Personal Data
We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules, 2011, and Section 8(4) of the DPDP Act, 2023, including:
- Encryption of data in transit using TLS/SSL protocols
- Access controls limiting data access to authorised personnel only
- Regular security assessments and vulnerability checks
- Secure disposal of data upon expiry of retention periods
In the event of a personal data breach that is likely to result in harm to you, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, 2023.
11. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to Access (Section 11): The right to obtain a summary of personal data we hold about you and the processing activities undertaken.
- Right to Correction and Erasure (Section 12): The right to correct inaccurate or incomplete personal data, and to request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
- Right to Grievance Redressal (Section 13): The right to have grievances addressed by our Grievance Officer within the timelines prescribed under the Act.
- Right to Nominate (Section 14): The right to nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to Withdraw Consent (Section 6): The right to withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please submit a written request to our Grievance Officer at [email protected]. We will respond within 30 days of receipt of your request, or within such period as prescribed under the DPDP Act.
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India, once constituted under the DPDP Act, 2023.
12. Grievance Redressal
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, we have designated a Grievance Officer to address complaints and concerns regarding the processing of personal data:
- Grievance Officer: Mindsspeak International Private Limited — Management
- Email: [email protected]
- Phone: +91 9008 55 0102
- Address: Bengaluru, Karnataka, India
- Response Time: Complaints will be acknowledged within 48 hours and resolved within 30 days of receipt.
13. Children's Privacy
Our services are directed at business professionals and organisations. We do not knowingly collect personal data from children under the age of 18. In accordance with Section 9 of the DPDP Act, 2023, we will not process the personal data of a child without verifiable parental or guardian consent. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. Material changes will be communicated by posting the updated policy on this page with a revised date. We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes acceptance of the updated policy.
15. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the rules and regulations made thereunder. Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts in Bengaluru, Karnataka, India.