Privacy policy

Privacy policy

Last Updated: 01/08/2026

Introduction

This Privacy Policy explains how Pingol G. ("I," "me," "my," "Pingol") collects, uses, processes, and discloses information when you visit pingolg.com, purchase a template, or engage me for web design services. This policy is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules.

Because I work with clients internationally, this policy also sets out — separately and explicitly, not just "in mind" — how I handle personal data of clients based in the European Union / United Kingdom under the General Data Protection Regulation (GDPR), where it applies. Section 12 below covers this in detail.

By using this website, submitting a project enquiry form, or engaging my services, you agree to the collection and use of information as described here. If you do not agree, please do not use the site or services.

1. Who I Am (Data Fiduciary / Data Controller)

Pingol G. is an individual freelance web designer operating under the brand Pingol G., based in West Bengal, India. For the purposes of the DPDP Act, I am the Data Fiduciary for personal data collected through pingolg.com. For clients based in the EU/UK, I act as the Data Controller under GDPR for the personal data I collect to deliver services to you.

Grievance Officer / Privacy Contact: Pingol, reachable at design@pingolg.com. This is the designated contact for all privacy requests, grievances, and data rights requests referenced in this policy.

2. The Notice You Receive Before I Collect Your Data

Separately from this policy, the project enquiry/booking form on pingolg.com displays a short, standalone notice at the point of collection, stating what data is being collected, why, and how you can withdraw consent. That form-level notice is the primary notice under DPDP Rule 3; this document provides the fuller detail behind it.

3. Information I Collect

Information you provide directly

Personal information:

●        Name and contact details

●        Email address

●        Phone number (if shared for a call/booking)

●        Billing and payment details (processed by third-party payment processors, not stored by me directly)

●        Company or business name (if applicable)

Project information:

●        Brand assets, logos, and guidelines you share

●        Project briefs, requirements, and content you provide

●        Feedback and communications during the project

●        Any client-supplied content used to build your site

Information collected automatically

Website usage:

●        IP address

●        Browser and device type

●        Operating system

●        Pages visited and time spent on the site

●        Referring website

●        Date and time of visit

Cookies and tracking:

●        Essential cookies required for the site to function

●        Analytics cookies to understand site performance (used only with consent where required)

●        Preference cookies to remember your settings

●        Marketing/newsletter cookies (only if you opt in)

4. How You Give Consent

Where I rely on your consent to process personal data (for example, submitting the project enquiry form, or opting into the newsletter), consent is collected through a clear, unticked checkbox that you must actively select. I do not use pre-ticked boxes, bundled consent, or default opt-ins. You may withdraw consent at any time by emailing design@pingolg.com with the subject line "Withdraw Consent" — withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect data I am required to retain for legal, tax, or accounting purposes.

5. Why I Collect and Use This Information

I only use personal data for a specific, stated purpose — I don't collect data "just in case." Here's what each category is used for:

Service delivery:

●        Processing project requests and quotes

●        Managing bookings via my automated scheduling tool

●        Handling project communications

●        Delivering completed websites, templates, and related files

●        Processing payments through third-party processors

●        Providing customer support

Service improvement:

●        Understanding how visitors use the site

●        Improving website functionality and load speed

●        Debugging technical issues

Communication:

●        Project status updates

●        Responses to enquiries submitted through lead-capture forms

●        Newsletter content (only if you've opted in via Kit/my sign-up form)

I never sell your personal data. I do not use your data for any purpose beyond what's listed above without asking you first.

6. The Tools I Use (Third-Party Processors)

Because I run this business as a solo freelancer, I rely on a small number of trusted third-party tools to deliver services. Each of these may process personal data on my behalf:

●        Payment processing: Wise, PayPal

●        Client onboarding and project management: Notion

●        Contracts and e-signatures: DocuSign

●        Email and newsletters: Kit

●        Website hosting and business email: Hostinger

●        Booking and scheduling: Cal.com

●        Website analytics: Google Analytics, Framer

These providers only receive the minimum data needed to perform their function (e.g. your payment processor sees billing details, not your project brief) and are contractually bound by their own privacy and security obligations. Where a processor is based outside India or the EU/UK (as applicable), I rely on that processor's own compliance framework and, for EU/UK client data, on Standard Contractual Clauses or an equivalent safeguard where required — see Section 12.

7. Data Storage and Security

Data is stored using the secure cloud infrastructure of the tools listed above, with industry-standard encryption in transit and at rest. Access to client data is limited to me alone — I do not have staff or subcontractors with standing access to your information.

8. Cross-Border Data Transfer

Under the DPDP Act, personal data may be transferred outside India except to any country the Central Government specifically restricts by notification; no such restricted-country list currently exists. Where I work with international clients or use processors based outside India, your data may be processed on servers located outside India. I remain responsible for that data regardless of where it is processed, and I only use providers with recognised international security standards.

For clients based in the EU/UK, see Section 12 for the additional safeguards that apply when your data is transferred to or processed in India.

9. Data Retention

Active client data is retained for the duration of our working relationship and for 24 months afterward, to allow for follow-up work, warranty-style fixes, or disputes. Financial and billing records are retained for as long as required by Indian tax law (currently up to 8 years for accounting records). Project files and communications are deleted or anonymised after the retention period unless you request earlier deletion or a longer retention period is legally required. You can request earlier deletion at any time — see Section 10.

10. Your Rights

Under the DPDP Act (and GDPR, where applicable — see Section 12), you have the right to:

●        Access the personal data I hold about you

●        Request a copy of your data

●        Correct inaccurate or outdated information

●        Request erasure of your data, subject to legal/financial record-keeping obligations

●        Withdraw consent for marketing communications at any time

●        Nominate another individual to exercise your rights on your behalf in case of death or incapacity (a right specific to the DPDP Act)

●        Lodge a grievance with me directly, and escalate to the Data Protection Board of India if unresolved

To exercise any of these rights, email design@pingolg.com with the subject line "Privacy Request." I will acknowledge your request promptly and resolve it within 90 days at the outer limit, in line with DPDP Rule 14 — for EU/UK clients relying on GDPR rights, I aim to respond within one month, as GDPR requires (see Section 12).

11. Data Breach Notification

If a personal data breach occurs that is likely to affect you, I will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, and take reasonable steps to notify you directly and promptly — describing what happened, what data was affected, and what protective steps you can take. For EU/UK clients, I will additionally notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, where GDPR requires this, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

12. International Clients — GDPR and Other Foreign Privacy Laws

Many of my clients are based outside India, including in the European Union and United Kingdom. Where I offer services to individuals or businesses in the EU/UK, GDPR's extraterritorial provisions (Article 3) may apply to me directly, regardless of my physical location in India. This section sets out how I handle that.

Lawful basis for processing

Where GDPR applies, my lawful basis for processing your personal data is primarily: (a) performance of a contract with you (project work, template purchases), and (b) your consent, for optional communications such as newsletters. I do not rely on legitimate interest for anything beyond basic site security and fraud prevention.

Your GDPR rights

If GDPR applies to you, you additionally have the right to data portability, the right to object to processing, and the right to lodge a complaint with your local supervisory authority. I aim to respond to GDPR access, correction, erasure, and objection requests without undue delay and within one month of receipt, extendable by two further months for complex requests, as GDPR permits.

Cross-border transfer safeguards

Because India does not currently hold a European Commission adequacy decision, transfers of EU/UK client data to me in India rely on Standard Contractual Clauses (SCCs) or an equivalent recognised safeguard. I will sign the EU Standard Contractual Clauses, or an equivalent data processing addendum, on request for any client who requires one as a condition of engaging my services.

Data Processing Agreements

If your organisation requires a formal Data Processing Agreement (DPA) as part of your own compliance obligations, I am happy to review and sign one prior to project start — please raise this during the quote/scoping stage.

No EU establishment

I do not have an establishment, office, or subsidiary in the EU/UK. As a solo freelancer whose EU/UK client processing is occasional rather than large-scale or high-risk, I do not currently maintain a designated EU representative under Article 27 GDPR; if your engagement requires one, please raise this before the project begins so we can agree how to address it.

13. Cookies

If pingolg.com uses cookies, you'll see a consent banner on your first visit. Essential cookies (required for the site to work) don't require consent; analytics and marketing cookies do, and you can decline them without affecting core site functionality.

14. Children's Privacy

My services are intended for business owners and are not directed at anyone under 18. I do not knowingly collect data from minors. If I discover I've inadvertently collected a minor's data, I will delete it promptly and will not process it further without verifiable parental or guardian consent.

15. Changes to This Policy

I may update this Privacy Policy as my tools, services, or the law change. Material changes will be reflected with an updated "Last Updated" date, and where required, I'll notify active clients directly.

16. Contact

For any privacy-related question, grievance, or rights request: design@pingolg.com — Grievance Officer: Pingol.

Create a free website with Framer, the website builder loved by startups, designers and agencies.