1. Introduction
Domain Expansion ("we", "our", "us") values your privacy. This Privacy Policy details how we collect, store, and process personal data when you visit our website domainexpansion.in, interact with our API handlers (for lead submissions and the TechGuild waitlist), or engage with our digital services.
We operate as a remote-first, remote-only digital agency. All operations and database pipelines are maintained in compliance with the Digital Personal Data Protection (DPDP) Act 2023 of India, as well as the General Data Protection Regulation (GDPR) for international visitors.
2. Information We Collect
We collect personal identifiers and corporate metadata that you voluntarily supply to us through our contact forms, Waitlist submissions, marketplace registration portal, and scheduling widgets. This data includes:
- **Identifiers**: First and last name, email address, phone number (WhatsApp preferred), and company name.
- **Verification & Corporate Records**: Incorporation certificates, CIN/GSTIN registrations, bank accounts, and portfolio case studies for agency audits.
- **Marketplace Parameters**: Project briefs, SLA configurations, bid/proposal documents, and escrow milestone records.
- **Communications**: Logs of in-platform chat messages and uploaded attachment assets between Clients and Agencies.
- **Network Details**: Client IP addresses (hashed for rate limiting), user agent metadata, referrers, and campaign UTM attributes.
- **Form Protection data**: Bot honeypot outputs.
3. How We Use Information
We use your personal parameters to fulfill commercial requests, operate our B2B marketplace, and scale digital systems:
- To evaluate your digital footprint and plan the 30-minute discovery consultation.
- To record waitlist positions, process agency audits, and compile marketplace directory listings.
- To facilitate marketplace operations, escrow payments routing, and subscription tier billing.
- To resolve project quality disputes or mediation briefs between Clients and Agencies.
- To dispatch automated transactional notifications and confirmation messages via Resend.
- To safeguard our web endpoints against DDoS or spamming attacks using rate limit thresholds.
4. Legal Basis for Processing
Under relevant privacy frameworks, our processing relies on the following grounds:
- **Consent**: You explicitly grant consent by submitting our briefing forms or joining our Waitlist arrays.
- **Contractual Performance**: Processing is required to draft project quotes, sign service contracts, operate platform escrow accounts, and deliver custom code.
- **Legitimate Interests**: To verify authentic human users, maintain server configurations, and evaluate business metrics.
5. Third Party Providers
We do not sell, lease, or rent customer database coordinates. We transfer data strictly to secure third-party subprocessors for core infrastructure services:
- **Host & Database**: Vercel (frontend deployment) and Neon Serverless (PostgreSQL database engine).
- **Payment & Escrow Gateways**: Stripe / Razorpay (subscription processing, billing logs, and payout structures).
- **Transactional Emails**: Resend (SMTP transaction deliveries).
- **Analytics**: Google Analytics 4 (anonymous traffic tracking).
- **CMS**: Sanity (static article content rendering).
6. Data Retention
We store lead parameters for exactly **one (1) year** following submission, unless you request earlier deletion. Active client contract files are retained for the duration of the commercial engagement to fulfill tax, legal, and billing parameters.
7. Your Rights (GDPR & DPDP)
Depending on your geographic coordinates, you carry absolute legal rights regarding your personal records:
- **Access & Portability**: You may request copies of your personal variables in a readable structural format.
- **Correction & Erasure**: You carry the right to update outdated details or request complete database deletion.
- **Object to Processing**: You can oppose automated sorting filters or withdraw consent triggers.
- **Nomination (DPDP)**: The right to nominate another individual to manage your data in case of incapacity.
To trigger any of these rights, email us at contact@domainexpansion.in with subject "Data Rights Request".
9. International Transfers
Your data is stored on Neon's secure cloud database nodes. By submitting your inquiry, you acknowledge that your variables will be processed in India. For EU/EEA citizens, we implement Standard Contractual Clauses (SCCs) to ensure equivalent data security.
10. Children's Privacy
Our digital services and waitlist arrays are intended exclusively for commercial entities. We do not knowingly collect personal identifiers from individuals under the age of 18.
11. Changes to Policy
We reserve the right to update this policy as legal and operational framework requirements evolve. All changes will be posted on this page with an updated timestamp.
12. Contact Details
For questions, complaints, or deletion requests, contact our designated Data Protection Officer: