Legal & Data Governance

Privacy Policy & Data Ethics

At WebSocial Studio, data integrity and client confidentiality form our foundational standard. This policy details how we treat brand assets, campaign intelligence, and visitor telemetry with institutional rigor.

Effective Date: September 2026Jurisdiction: DPDPA (India) & Global GDPR Compliance

Zero Data Selling

We never sell, rent, or trade client email lists, lead data, or video creative files to data brokers or third parties.

Institutional NDA

Raw footage, unreleased product demos, and Meta ad campaign financials remain protected under non-disclosure.

Encrypted Transport

All form submissions, API requests, and web assets traverse 256-bit TLS/SSL encryption end-to-end.

48h Erasure SLA

Request complete erasure of your audit submission or inquiry logs, executed within 48 business hours.

Section 01

1. Overview & Core Commitment

WebSocial Studio ("we," "us," or "our") operates the web platform located at https://websocialstudio.com and provides creative, technological, and algorithmic growth services to commercial brands globally.

This Privacy Policy explains our practices regarding the collection, storage, processing, and disclosure of personal data and business materials collected when you browse our website, initiate a brand growth audit, or engage our creative and technical retainers.

We uphold the principles mandated by India's Digital Personal Data Protection Act, 2023 (DPDP Act), the European Union's General Data Protection Regulation (GDPR), and California's Consumer Privacy Act (CCPA).

Section 02

2. Information We Collect

We only collect information necessary to evaluate growth opportunities, produce video and digital assets, and optimize client marketing funnels:

A. Direct Inquiry & Client Contact Details

When you submit a contact inquiry, request a 30-minute growth strategy audit, or interact with our WhatsApp line, we collect your full name, business email address, phone/WhatsApp number, company name, website URL, and current social media handles (e.g. Instagram, TikTok, YouTube).

B. Operational Campaign & Brand Assets

For contracted brand partners, we receive raw video rushes, product assets, brand guidelines, and authorized read/write access to Meta Business Manager, Google Ads MCC, or CMS dashboards strictly for campaign deployment.

C. Automated Technical & Device Telemetry

When navigating our digital web applications, our edge servers automatically log anonymized device specifications, browser type, operating system, IP address, referral sources, and interaction duration to optimize page performance.

Section 03

3. How We Use Your Data

Every byte of data collected serves a concrete operational purpose:

  • Delivering Agency Audits: Conducting pre-call analysis on your organic video retention, conversion architecture, and ChatGPT/Perplexity AI citation indices.
  • Fulfilling Production Contracts: Scriptwriting, on-location video production, Next.js web development, and performance ads optimization.
  • Direct Communication: Scheduling strategy sessions and sending project status updates via email or WhatsApp.
  • Commercial Invoicing: Generating GST-compliant invoices and processing retainer payments in adherence to Indian statutory regulations.
  • Platform Security & Fraud Prevention: Preventing malicious bot traffic, brute-force API requests, and unauthorized access attempts.
Section 04

4. Client Assets & Video Confidentiality

As a creative and growth agency, we frequently hold unreleased physical product prototypes, proprietary marketing angles, and private client analytics. We treat client property with bank-grade confidentiality.

Raw Video Rushes & B-Roll: Any footage captured during client shoots remains the sole intellectual property of the client once financial obligations are settled. We do not license, repurpose, or distribute your raw b-roll to other creators or competitors.

Public Case Studies: We only publish campaign telemetry, before-and-after view graphs, and creative clips in our portfolio or marketing materials with explicit client written authorization or if such media is already publicly distributed on your verified social handles.

Section 05

5. Third-Party Sub-Processors

To deliver sub-second web experiences and enterprise reliability, we integrate with industry-leading cloud sub-processors:

Sub-ProcessorOperational PurposeData Location
Vercel Inc.Edge server hosting, SSL termination, and static asset deliveryGlobal Edge (US / EU / APAC)
Meta Platforms Inc.Meta Conversions API (CAPI), ad campaign delivery & analyticsUnited States / Global
Google LLCGoogle Analytics 4 telemetry, Google Workspace communicationUnited States / Global
Cloudflare Inc.DDoS mitigation, web application firewall (WAF), and DNSGlobal Anycast Network
Section 06

6. Cookies & Tracking Technologies

We deploy minimal, functional cookies necessary for website performance and attribution:

  • Essential Cookies: Preserving session states, form submission integrity, and security tokens. These cannot be toggled off as they are vital for core functionality.
  • Analytical & Performance Cookies: Measuring page load speeds, drop-off rates on portfolio case studies, and user flows via anonymized telemetry.
  • Marketing Attribution Pixels: Allowing us to measure return on ad spend (ROAS) when we run commercial growth campaigns.

You can manage or disable cookie preferences directly within your browser settings (Chrome, Safari, Firefox, or Edge) without affecting your basic access to our public portfolio.

Section 07

7. Data Retention & Erasure Protocol

We retain data only as long as required to fulfill operational, legal, and financial obligations:

Audit Inquiries

Non-contracted strategy audit submissions are securely purged after 90 days.

Active Client Contracts

Retained for the duration of the engagement plus 30 days post project offboarding.

Financial & Invoicing Records

Retained for 7 years to satisfy Indian Income Tax & GST statutory requirements.

Immediate Purge On Demand

Upon written notice to our privacy officer, inquiry records are deleted within 48 business hours.

Section 09

9. Technical & Physical Security Architecture

We apply enterprise-grade safeguards to protect brand records against unauthorized access, loss, or alteration:

Access Control & 2FA

Client Ad accounts and media storage are gated with multi-factor authentication (2FA) and least-privilege role assignments.

Cryptographic Encryption

Data in transit is encrypted using modern TLS 1.3 cryptographic suites; static assets are encrypted at rest.

Section 10

10. Contact Our Data Governance Desk

If you have questions, feedback, or grievance reports regarding our data ethics or privacy practices, reach our governance lead directly:

Operating EntityWebSocial Studio
Principal OfficeNew Delhi, Delhi, India
Direct Data Inquiriescontact@websocialstudio.com
Instant WhatsApp Support+91 8595805020

Ready to scale your brand with confidence?

Join India's leading ambitious brands partnering with WebSocial Studio for viral reels, sub-second web engineering, and verified growth.