Privacy Policy
What we collect when you use this website, why we collect it, who it is shared with, how long it is kept, and the rights you can exercise over it. This policy also explains the separate role we play when we process data on behalf of advertiser clients.
1. Who this policy is from
Appmontize Media Private Limited (CIN U74999DL2019PTC350753), a private limited company incorporated on 30 May 2019 under the Companies Act, 2013 (18 of 2013) and registered with the Registrar of Companies, Central Registration Centre, having its registered office at Office No. 903, 9th Floor, GD-ITL Northex Tower, A-9, NSP, Pitampura, New Delhi, North West Delhi, Delhi 110034, India, its principal place of business at 6th Floor, 613, Best Business Park, Plot No. P-2, Netaji Subhash Place, Pitampura, North West Delhi, Delhi 110034, India, and registered under the Goods and Services Tax Act with GSTIN 07AASCA3493N1ZW ("Appmontize", "the Company", "we", "us" or "our").
We also operate through our affiliate Appmontize Media Pte. Ltd. (UEN 202131228E), incorporated in Singapore and having its office at The Octagon, 105 Cecil Street, #13-02, Singapore 069534. Where you engage the Singapore entity, that entity is the data controller for the personal data collected in connection with that engagement and this policy applies to it on the same terms, read with the Personal Data Protection Act 2012 of Singapore.
This policy governs the website at appmontize.co.in and its subdomains (the "Site"), and any email or messaging correspondence that follows from your use of the Site. It is written to be read in full. Where a section imposes a limit on what we do, that limit is a commitment, not a description of current practice that we reserve the right to change silently — changes are handled under the "Changes to this policy" section below.
If you do not agree with this policy, please do not submit information through the Site. You can reach us at the addresses in the "How to contact us" section for any question, request or complaint arising out of it.
2. Scope, and what this policy is not about
This policy covers personal data that the Company determines the purposes and means of processing for — in the language of the Digital Personal Data Protection Act, 2023, data for which we are the Data Fiduciary; in the language of the EU and UK General Data Protection Regulation, data for which we are the controller.
It does not cover the following, each of which is governed by a separate instrument:
- Campaign and measurement data that we process on the written instructions of an advertiser or publisher client. For that data our client is the controller and we act as a processor. Section 12 describes this relationship, and the governing terms are the data processing addendum in the relevant insertion order or master services agreement — not this policy.
- Personal data collected by third-party websites, app stores, device manufacturers or advertising platforms that you reach through a link, an advertisement or an integration. Their own notices apply. We do not control and are not responsible for their practices.
- Employment and recruitment data, which is handled under our internal candidate and employee privacy notices provided at the point of collection.
3. The personal data we collect through this Site
We have deliberately kept this narrow. There is no visitor database behind this Site, no account system, no login, no user profile and no persistent identifier assigned to you by us.
Information you give us. When you complete the enquiry form on the "Start a project" page, the form transmits the fields you fill in. Those fields are:
| Field | Required | Why we ask |
|---|---|---|
| Name | Yes | To address you correctly in the reply. |
| Work email address | Yes | The only channel we use to respond to an enquiry. |
| Company | No | To research your category before the first call. |
| Budget range | No | To route the enquiry to the right team and to avoid wasting your time if we are not a fit. |
| Areas of interest | No | To bring the relevant specialists to the first conversation. |
| Message | Yes | The substance of your enquiry, in your own words. |
Anything else you choose to place in the free-text message field is also collected, because it is part of the message. Please do not include sensitive personal data, financial account details, passwords, health information, government identifiers, or the personal data of third parties in that field. If you do, we will process it only for the purpose of responding to you and will delete it in line with Section 8.
Information collected automatically. When your browser makes a request to our server, the server necessarily receives the network information required to route a response. Our contact endpoint records the originating IP address in its operational log at the time a submission is made, together with the timestamp and the outcome of the submission.
Information we do not collect. To be explicit, and so that no reader is left inferring: this Site sets no cookies of its own; runs no web analytics product; carries no advertising, retargeting or conversion pixel; does not fingerprint your device; does not use local storage or session storage to identify you; does not track you across other websites; and does not build a behavioural profile of you. If that changes, this section changes with it, and the change will be dated.
4. Why we process it, and on what legal basis
We process personal data only where we have a lawful basis to do so. The table below sets out each processing activity, its purpose, and the basis relied upon under the GDPR (for visitors in the European Economic Area and the United Kingdom) alongside the corresponding position under the Digital Personal Data Protection Act, 2023 (for visitors in India) and the Personal Data Protection Act 2012 (for visitors in Singapore).
| Activity | Purpose | Legal basis |
|---|---|---|
| Receiving and replying to an enquiry | To answer your question, assess whether we can help, and take steps at your request prior to entering into a contract. | GDPR Art. 6(1)(b) — steps at the data subject's request prior to contract; and Art. 6(1)(f) — our legitimate interest in responding to business enquiries. DPDP Act — the certain legitimate use of data voluntarily provided for a purpose you sought. PDPA — deemed consent by voluntary provision. |
| Follow-up correspondence about that enquiry | To continue the conversation you started, share proposals, and arrange calls. | GDPR Art. 6(1)(b) and 6(1)(f). DPDP Act — consent for the specified purpose. PDPA — consent. |
| Bot and abuse prevention on the form | To stop automated submissions, spam and denial-of-service abuse of the endpoint, so that genuine enquiries reach us. | GDPR Art. 6(1)(f) — legitimate interest in the security and availability of our systems. DPDP Act — the certain legitimate use of preventing fraud and ensuring information security. PDPA — legitimate interests. |
| Operational logging of requests and errors | To detect failures, diagnose delivery problems, and demonstrate that a message was or was not received. | GDPR Art. 6(1)(f) — legitimate interest in service integrity and in maintaining records of business communications. |
| Retaining correspondence after an engagement is agreed | To perform the contract and to keep the books, records and tax documentation required of us. | GDPR Art. 6(1)(b) and Art. 6(1)(c) — compliance with a legal obligation. In India, obligations under the Companies Act, 2013, the Income-tax Act, 1961 and the GST legislation. |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is limited to what a person submitting a business enquiry would reasonably expect, and that it does not override your rights and freedoms. You may object to processing based on legitimate interests; see Section 10.
We do not use personal data collected through this Site for automated decision-making that produces legal or similarly significant effects concerning you, and we do not carry out profiling of Site visitors.
5. What we never do with data from this Site
These are prohibitions we place on ourselves, and they are enforceable statements, not marketing language:
- We do not sell personal data. We have never sold personal data collected through this Site and we do not have a mechanism to do so.
- We do not rent, trade, or otherwise make personal data available to data brokers, list vendors, or lead-generation resellers.
- We do not add enquiry contacts to marketing lists or newsletters without a separate, affirmative opt-in from you.
- We do not use enquiry contents to target advertising at you, on this Site or anywhere else.
- We do not use the contents of your enquiry to train machine-learning models, and we do not submit that content to third-party generative AI services.
- We do not knowingly collect personal data from children. Section 13 explains what happens if we discover that we have.
6. Third parties your browser contacts, and third parties we send data to
Two categories exist and they are worth separating, because most policies blur them.
Third parties your browser contacts directly when you load the Site. When your browser renders a page, it makes requests to the following services. Those services necessarily receive your IP address and standard request headers as a technical consequence of the connection:
| Service | Provider | What it does | What it receives |
|---|---|---|---|
| Turnstile | Cloudflare, Inc. | Verifies that the enquiry form is being submitted by a person rather than an automated script. Cloudflare states that Turnstile does not use cookies for tracking and does not fingerprint users for advertising purposes. | IP address, request headers, and browser signals used to compute a challenge result. We receive only a pass or fail token. |
| Google Fonts | Google LLC / Google Ireland Ltd. | Serves the typefaces used by the Site. | IP address and request headers for the font files. |
Third parties to whom we transmit data. When you submit the form, the contents are delivered by SMTP to our own mailboxes. The mail transport and mailbox hosting are provided by our email service provider, which processes the message in transit and at rest in our mailbox under its own terms and its own security controls. No copy of the submission is written to any database of ours.
We use no other processors for Site data. In particular, there is no customer relationship management platform, no marketing automation platform, no analytics warehouse and no advertising platform in the path between your form submission and our inbox.
We may also disclose personal data to professional advisers (lawyers, auditors, accountants) bound by duties of confidentiality, and to a successor entity in the event of a merger, acquisition or restructuring, in which case the recipient remains bound by this policy in respect of data received. And we may disclose data where required to do so under Section 11.
7. International transfers
We operate from India and Singapore, and our clients and partners operate across South and Southeast Asia, the Middle East and North Africa, Europe and North America. Personal data submitted through the Site is accessed by our personnel in India and Singapore, and is processed by service providers who may operate infrastructure in other countries.
Where personal data of individuals in the European Economic Area or the United Kingdom is transferred outside that area, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) as the transfer mechanism, supplemented where necessary by additional technical and organisational measures following a transfer impact assessment.
Where personal data of individuals in Singapore is transferred out of Singapore, we take steps in accordance with Section 26 of the Personal Data Protection Act 2012 and the Personal Data Protection Regulations to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the Act.
Transfers of personal data out of India are made in accordance with Section 16 of the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government from time to time.
You may request a copy of the safeguards applicable to a transfer by writing to the privacy contact in Section 14.
8. How long we keep it
We keep personal data only for as long as the purpose for which it was collected requires, and then we delete it. Specifically:
| Category | Retention period | Trigger for deletion |
|---|---|---|
| Enquiry that does not lead to an engagement | Up to 24 months from the last substantive correspondence. | Automatic review; deleted on request at any time. |
| Enquiry that leads to an engagement | For the duration of the engagement, and thereafter for the period required by applicable statutes of limitation and by Indian tax, GST and companies-law record-keeping obligations — generally eight years from the end of the relevant financial year. | Expiry of the statutory period. |
| Server operational logs, including IP addresses | Not more than 90 days. | Rolling expiry. |
| Records of a privacy request you make to us | 36 months, so that we can demonstrate we handled it. | Expiry of the period. |
Where a legal hold applies because of actual or anticipated litigation, regulatory investigation or a lawful preservation order, the relevant data is retained until the hold is lifted, notwithstanding the periods above.
9. How we protect it
We apply technical and organisational measures appropriate to the risk, including: transport encryption (HTTPS/TLS) for all traffic to and from the Site; authenticated SMTP over TLS for mail delivery; access to enquiry mailboxes restricted to the individuals who need it for the purpose; multi-factor authentication on those mailboxes; a bot-mitigation check at the point of submission; and the practice of not persisting Site submissions to any database, which removes an entire class of exposure.
No method of transmission or storage is perfectly secure, and we do not claim otherwise. We do not guarantee absolute security. What we do commit to is that where a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within the period required by the applicable law — including notification to the Data Protection Board of India in the form and manner prescribed under the Digital Personal Data Protection Act, 2023, notification within 72 hours under Article 33 of the GDPR where that regulation applies, and notification to the Personal Data Protection Commission of Singapore where the notification thresholds under the PDPA are met — and that we will notify affected individuals without undue delay where the law requires it.
You are responsible for the security of the device and email account from which you contact us. Email is not an inherently confidential medium; please do not send us credentials or sensitive personal data by email.
10. Your rights
Your rights depend on where you are, and we honour the following set for every person who asks, regardless of whether the law in your jurisdiction compels it:
- Access — to obtain confirmation of whether we process personal data about you, a copy of that data, and a summary of the processing activities and of the identities of any other parties with whom it has been shared.
- Correction — to have inaccurate or misleading personal data corrected, and incomplete data completed.
- Erasure — to have personal data erased where it is no longer necessary for the purpose for which it was collected, where you withdraw consent and no other basis applies, or where it has been processed unlawfully.
- Withdrawal of consent — to withdraw consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before it.
- Objection — to object to processing carried out on the basis of legitimate interests, on grounds relating to your particular situation.
- Restriction — to require that we hold data without further processing while a dispute about its accuracy or about our legal basis is resolved.
- Portability — to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Nomination — under the Digital Personal Data Protection Act, 2023, to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Complaint — to lodge a complaint with a supervisory authority, as described in Section 14.
How to exercise them. Write to the privacy contact in Section 14 from the email address you used to contact us, or, if that is not possible, provide sufficient information for us to locate the record and verify that the request is genuinely yours. We do not charge a fee for a first request. We will respond within 30 days, or within one month where the GDPR applies, and will tell you if we need a permitted extension and why. Where we decline a request in whole or in part, we will explain the legal ground for doing so and how to challenge that decision.
Verification. Because the only identifier we hold for most enquirers is an email address, our verification will usually consist of correspondence with that address. We may decline a request we cannot reasonably verify, and we will say so rather than acting on an unverified instruction.
11. When we disclose data because we are compelled to
We may disclose personal data where we are required to do so by applicable law, by a binding order of a court or tribunal of competent jurisdiction, or by a lawful demand from a government or regulatory authority acting within its powers.
Our practice in those cases is: to satisfy ourselves that the demand is valid, is issued by an authority with jurisdiction over us, and is not overbroad; to disclose only the narrowest set of data responsive to the demand; to seek to narrow or challenge demands that appear unlawful or excessive; and, unless we are legally prohibited from doing so or there is a risk to life or to an active investigation, to notify the affected individual so that they have the opportunity to seek their own remedy.
We may also disclose data where necessary to establish, exercise or defend legal claims, or to protect the vital interests of any person.
12. Campaign data: our role as a processor for clients
This section is included because our business would make its omission conspicuous. Appmontize is a performance marketing company. In the course of running campaigns for advertiser clients, data flows through systems we operate or configure. That data is not governed by this policy, and it is important to understand why.
For campaign data, our client is the controller (in India, the Data Fiduciary). The client determines what is collected, for what purpose and for how long. We act on documented instructions as a processor (a Data Processor). Our obligations in that role are set out in the data processing addendum executed with that client, which addresses, at minimum: processing only on documented instructions; confidentiality undertakings from personnel; security measures; the engagement of sub-processors and the client's right to object to them; assistance with data-subject requests and with breach notification; and deletion or return of data at the end of the engagement.
In practice the campaign data we handle is predominantly aggregated and pseudonymous — impression, click, install and post-install event counts, campaign and placement identifiers, device-level advertising identifiers where the operating system and the end user permit them, and attribution records produced by mobile measurement partners engaged by the client. We do not receive names, postal addresses or payment instruments in that flow, and we do not seek to re-identify individuals from campaign data.
If you are an end user who has seen or interacted with an advertisement we delivered and you wish to exercise rights over the associated data, the effective route is to contact the advertiser whose product was advertised, or the platform on which you saw the advertisement, because they hold the controller relationship and the identifiers required to locate your record. If you write to us instead, we will assist by identifying the relevant client where we can lawfully do so, and by forwarding your request to them.
13. Children
The Site is directed at businesses and is not intended for children. We do not knowingly collect personal data from any individual under the age of 18 years, which is the threshold set by the Digital Personal Data Protection Act, 2023, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
If we become aware that we hold personal data of a child collected through the Site without verifiable consent of a parent or lawful guardian, we will delete it promptly. If you believe a child has provided us with personal data, please write to the privacy contact in Section 14 and we will act on it.
14. How to contact us, and where to complain
For any question about this policy, or to exercise any right described in Section 10:
| Purpose | Address |
|---|---|
| Privacy and data protection requests | [email protected] |
| Grievance officer (India, DPDP Act) | [email protected] |
| Legal notices | [email protected] |
| General enquiries | [email protected] |
| Postal — registered office | Office No. 903, 9th Floor, GD-ITL Northex Tower, A-9, NSP, Pitampura, New Delhi, North West Delhi, Delhi 110034, India |
| Postal — principal place of business | 6th Floor, 613, Best Business Park, Plot No. P-2, Netaji Subhash Place, Pitampura, North West Delhi, Delhi 110034, India |
| Postal — Singapore | Appmontize Media Pte. Ltd., The Octagon, 105 Cecil Street, #13-02, Singapore 069534 |
Grievance redressal. In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) framework, a grievance officer is available at the address above. We acknowledge grievances within 24 hours of receipt and resolve them within 15 days, or explain in writing why more time is required.
Escalation. If you are not satisfied with our response, you may complain to the Data Protection Board of India; to the Personal Data Protection Commission of Singapore; or, if you are in the European Economic Area or the United Kingdom, to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. Complaining to us first is not a precondition, but it is usually faster.
15. Changes to this policy
We may amend this policy to reflect changes in our practices, our technology or the law. When we do, we will update the "Last updated" date at the top of this page.
Where a change materially reduces your rights or materially expands the categories of data we collect or the purposes for which we use it, we will not apply the change retrospectively to data already collected without a fresh lawful basis, and where we hold your contact details in connection with a live enquiry or engagement, we will notify you of the change directly before it takes effect.
Superseded versions are retained internally and a copy of the version in force on a given date is available on request.
Appmontize Media Private Limited · CIN U74999DL2019PTC350753 · GSTIN 07AASCA3493N1ZW. This document is published in English and is effective from 13 August 2026.
