Privacy Policy
Last updated: 8 July 2026 · policy version artelli-compliance-2026-07-08.v2.1
This policy explains how Artelli Digital Consultants ("Artelli", "we") collects and uses personal data through its internal outreach tool, Artelli Radar. It is written with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Compliance with the DPDP Act depends on rules and notifications issued by the Central Government from time to time; the controls described here reflect our current interpretation and are subject to change.
1. Who we are
Artelli Digital Consultants, Bangalore, India, acts as the Data Fiduciary. Our Grievance Officer's details are on the Grievance Officer page.
2. What data we process
- Business contact data — business name, category, address, publicly listed phone number, email, website, ratings, and reviews sourced from Google Maps, Instagram bios, Apollo.io, and public web pages accessed via Firecrawl.
- Professional profile data — full name, job title, employer, work location, and LinkedIn URL where a person has made this information publicly available on LinkedIn or Apollo.
- Engagement data — whether an email or WhatsApp message we sent was delivered, opened, bounced, or replied to.
We do not knowingly collect data about children. We do not process financial, health, biometric, or other data that would be treated as sensitive under most privacy regimes.
3. Purpose & lawful basis
We process the data for one purpose only: business-to-business outreach proposing our digital services to the business. Under the DPDP Act, we rely on the exemption in §17(1)(b) to the extent the personal data has been made publicly available by the Data Principal (for example, a phone number listed on the business's own Google Maps or Instagram profile, or a professional profile published by the person on LinkedIn / Apollo). Where §17(1)(b) does not apply — for instance, where an email address was not made publicly available by the person — we either obtain verifiable consent under §6 before sending or refrain from processing. We do not rely on a general "legitimate interest" basis, which the DPDP Act does not recognise.
4. How we contact you
First contact is a single email. A WhatsApp message is sent only where we hold a recorded opt-in (inbound message, click-to-WhatsApp, signed form, or an equivalent evidenced basis) and a TRAI DLT-registered template exists for the sending number. Every message identifies the sender, the purpose, and a one-click way to opt out. Follow-ups are sent only if you engage or reply.
5. Retention
- Leads that are never contacted are automatically deleted after 90 days by default; per-source shorter windows apply to higher-risk provenance (e.g. Apollo-guessed emails, unknown-source records).
- Contacted leads and outreach records are kept for up to 24 months to service ongoing conversations, then have personal data redacted while a minimal audit stub is retained.
- Suppression / unsubscribe records are kept indefinitely as a keyed hash (HMAC-SHA-256) — this lets us honour opt-outs without retaining the original email or phone.
- Compliance audit entries (send / block / consent / export decisions) are retained to demonstrate accountability under §8(4) of the DPDP Act.
6. Sharing & sub-processors
- Google Maps Platform — business discovery. Google's terms restrict long-term storage of Places responses; we hold them transiently for eligibility decisions.
- Apollo.io — B2B contact discovery. Apollo-sourced records are routed to human review before outreach unless independently verified.
- Firecrawl — controlled scraping of pages the business has published for us to read.
- Anthropic (Claude) / Lovable AI Gateway — AI drafting of outreach messages. Prompts are minimised (personal identifiers stripped) before being sent.
- SendGrid (Twilio) — transactional email delivery.
- Wati / Meta WhatsApp Business Platform — WhatsApp delivery, template-gated.
- Supabase / Lovable Cloud — database and application hosting.
We do not sell your data. We do not share it with anyone outside these processors.
7. Security
Data is stored in an access-controlled managed Postgres database with per-row authorisation. Access to production is restricted to the founder's account under multi-factor authentication. All traffic is encrypted in transit (TLS 1.2+). Unsubscribe tokens and suppression records use keyed HMAC hashes so the platform can honour opt-outs without retaining raw identifiers. No system is immune to compromise; we describe controls, not guarantees.
8. Your rights under the DPDP Act
Where the DPDP Act applies to our processing of your personal data, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities.
- Correct, complete, update, or erase your personal data.
- Nominate another individual to exercise these rights in the event of death or incapacity.
- Withdraw consent, where consent was our basis for processing.
- Raise a grievance with our Grievance Officer, and thereafter approach the Data Protection Board of India once operational.
To exercise any of these rights, email info@artellidigital.com, use the Grievance Officer form, or click unsubscribe in any message we sent you. Where §17(1)(b) applies (data made publicly available by you), some rights may be limited — we will still honour deletion / opt-out requests as an operational matter.
9. International transfers
Some sub-processors (SendGrid, Anthropic, Apollo, Supabase, Firecrawl) may process data on servers outside India. The Central Government has not, as of the version date above, notified restrictions on such transfers under §16 of the DPDP Act; we will update this policy if that changes.
10. Changes
We will update this policy from time to time. The "last updated" date and policy version at the top reflect the latest version.