Privacy Policy
Decimal Point Analytics Pvt. Ltd. (“DPA”, “we”, “our” or “us”) respects your privacy and is committed to protecting the personal information you share with us.
This Privacy Policy explains how we collect, receive, use, store, disclose, transfer, retain and safeguard personal information when you visit our website at www.decimalpointanalytics.com, interact with us, apply for employment, engage with us as a client, vendor, partner or service provider, or otherwise use our services.
This Privacy Policy is intended to describe DPA’s privacy practices in accordance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023, the rules made thereunder, the Information Technology Act, 2000 and other applicable Indian laws and regulations.
By using our website or services, or by providing your personal information to us, you acknowledge that you have read and understood this Privacy Policy.
1. Purpose of this Privacy Policy
The purpose of this Privacy Policy is to inform individuals about:
the types of personal information DPA collects or receives;
the purposes for which such personal information is collected and processed;
how such personal information is used, stored, protected, disclosed and retained;
the rights and choices available to individuals; and
how individuals may contact DPA for privacy-related requests, concerns or grievances.
2. Scope and Applicability
This Privacy Policy applies to personal information that DPA processes as a Data Fiduciary/controller in connection with:
this website;
marketing, business development and communications;
recruitment and employment-related interactions;
vendor, service-provider and partner relationships; and
direct business relationships with prospective, current and former clients.
Where DPA processes personal information on behalf of a client under a services engagement, including data management, analytics, managed services, technology support or similar arrangements, DPA generally acts as a Data Processor/service provider. Such processing is governed by the applicable client contract, statement of work, data processing agreement or other contractual terms, and not by this Privacy Policy, except to the extent expressly stated.
This Privacy Policy is governed by and construed in accordance with the laws of India. Any dispute arising from this Privacy Policy or from the processing of personal information under this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts at Mumbai, Maharashtra, India.
3. Definitions
For the purposes of this Privacy Policy:
“Personal Information” or “Personal Data” means any data about an individual who is identifiable by or in relation to such data, whether directly or indirectly.
“Processing” means any operation or set of operations performed on personal information, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transmission, sharing, restriction, erasure, deletion or protection.
“Data Principal” means the individual to whom the personal information relates.
“Data Fiduciary” means a person or entity that determines the purpose and means of processing personal information.
“Data Processor” means a person or entity that processes personal information on behalf of a Data Fiduciary.
“Consent” means freely given, specific, informed, unconditional and unambiguous indication of the Data Principal’s wishes through clear affirmative action, where required under applicable law.
4. Personal Information We Collect
4.1 Sources of Personal Information
We may collect or receive personal information from the following sources:
Directly from you: when you voluntarily provide information through online forms, emails, surveys, enquiries, job applications, meetings, events, contracts or other direct interactions with us.
Automatically through our digital platforms: when you access or use our website, portals or online services, certain information such as IP address, browser type, device identifiers, usage behaviour, pages visited, links clicked and interaction data may be collected automatically through cookies or similar technologies.
From third parties: where you interact with us through social media, recruitment platforms, business partners, service providers, professional networks, referrals, publicly available sources or trusted partners, with your consent where required by applicable law.
From clients or business contacts: where personal information is provided to us in connection with a business relationship, service engagement, vendor onboarding, recruitment activity or contractual arrangement.
4.2 Categories of Personal Information
Examples of personal information we may collect include:
name;
job title and organisation;
email address and phone number;
address, city, state, country and location information;
gender, date of birth and identity-related details, where relevant;
education, work experience, employment history and professional qualifications;
information submitted through job applications or recruitment processes;
photographs, video or audio recordings, where applicable;
communication records, enquiries, feedback and correspondence;
website usage data, browser information, device identifiers and cookie information;
billing, invoicing, payment and tax-related information;
client, vendor or business-contact information; and
any other information voluntarily provided to us or required for a lawful business, employment, contractual, compliance or service-related purpose.
4.3 Data Minimisation and Purpose Limitation
We collect personal information only where it is relevant, necessary and proportionate for the purposes described in this Privacy Policy or otherwise communicated to you at the time of collection.
We do not use personal information for purposes incompatible with the original purpose of collection unless permitted by law, required for contractual or legal obligations, necessary for legitimate business purposes, or based on your consent where required.
4.4 Sensitive Information
DPA does not generally collect sensitive or special-category information, such as information relating to race, religion, health, sexual orientation or similar sensitive attributes, except where required for employment, legal, statutory, compliance or other lawful purposes, and only with appropriate consent or lawful necessity where required.
4.5 Children’s Information
DPA does not knowingly collect personal information about children. If we become aware that personal information of a child has been collected without appropriate lawful basis or consent where required, we will take reasonable steps to delete or otherwise handle such information in accordance with applicable law.
5. How We Use Personal Information
DPA processes personal information only for legitimate, specific and transparent purposes, including:
Service Delivery: to provide, operate, maintain, support and improve our products and services, including account management, technical support, service delivery and functionality enhancements.
Communication: to respond to enquiries, requests, complaints or feedback and to send service-related notifications, updates or important announcements.
Billing and Payments: to process transactions, manage subscriptions or engagements, issue invoices, maintain financial records and complete payment-related activities.
Security and Fraud Prevention: to detect, prevent, investigate and respond to fraud, unauthorised access, misuse, security incidents, cyber threats, unlawful activities or violations of our policies; to protect the rights, property, systems, data and safety of DPA, our clients, users, employees, service providers and other relevant stakeholders; and to maintain the integrity, availability and security of our website, systems, networks and services.
Compliance with Legal or Regulatory Obligations: to comply with applicable laws, regulations, legal processes, court orders, governmental requests, audit requirements, statutory filings, tax obligations and regulatory requirements.
Internal Operations and Analytics: to monitor performance, analyse usage trends, conduct research, improve internal processes, develop new features and enhance user experience, often using aggregated or anonymised data where appropriate.
Marketing and Business Development: to send promotional communications about our services, events, newsletters, invitations, updates, offers or feedback requests, where permitted by law and subject to applicable consent or opt-out requirements.
Personalisation: to verify identity, manage accounts, tailor content, improve interactions and enhance your experience with our website and services.
Recruitment and Employment: to process job applications, conduct interviews, evaluate suitability, complete background or reference checks where applicable, manage employment records and support employment, recruitment, internship, vendor and alumni relations.
Contractual Necessity: to fulfil obligations under client, vendor, employment, partnership or other agreements.
Dispute Management and Legal Protection: to establish, exercise or defend legal claims, manage disputes, enforce agreements and protect DPA’s legal rights and business interests.
6. Cookies and Similar Technologies
We use cookies, pixels, tags, analytics tools and similar technologies to operate our website, improve user experience, analyse usage, support security, remember preferences and improve website performance.
Where required by applicable law, we obtain your consent before using non-essential cookies through the cookie consent mechanism available on our website. You may manage cookie preferences through the cookie banner, browser settings or other tools provided on our website.
Disabling certain cookies may affect the functionality, security or performance of our website.
7. Consent, Preferences and Withdrawal
Where DPA relies on consent to process personal information, you may withdraw your consent at any time by contacting us at privacy@decimalpointanalytics.com or by using available preference-management or unsubscribe tools, where applicable.
Withdrawal of consent will not affect processing already carried out before withdrawal. However, withdrawal of consent may affect our ability to provide certain services, respond to requests, process applications or enable features that depend on such personal information.
Even after consent is withdrawn, DPA may continue to process personal information where such processing is required or permitted by law, necessary for compliance, required for contractual obligations, necessary for legal claims, or required for legitimate business record-keeping.
We maintain appropriate records of consent, preferences and withdrawal where required by law or for audit, compliance and operational purposes.
8. Disclosure and Sharing of Personal Information
8.1 Service Providers and Business Partners
We may share personal information with authorised service providers, affiliates, group entities, professional advisors, technology providers, cloud hosting providers, analytics providers, recruitment partners, payment processors, communication platforms, auditors, consultants and other third parties who support our business operations or service delivery.
Such third parties are required to process personal information only for authorised purposes and to implement appropriate confidentiality, security and privacy safeguards.
8.2 Legal and Regulatory Disclosures
We may disclose personal information to government authorities, regulators, law enforcement agencies, courts, tribunals or other relevant persons where required by law, regulation, court order, governmental request, legal process, contractual obligation or to protect our rights, users, systems, services, property or safety.
8.3 Business Transfers
In the event of any merger, acquisition, restructuring, reorganisation, sale of assets, business transfer, investment, financing, due diligence process or similar corporate transaction involving DPA, personal information may be disclosed or transferred to the relevant successor, affiliate, investor, acquirer, purchaser, advisor or other relevant party, subject to appropriate confidentiality obligations and applicable data protection requirements.
Where required by applicable law, DPA will take reasonable steps to ensure that such personal information continues to be protected in accordance with this Privacy Policy and applicable data protection laws.
8.4 No Sale of Personal Information
DPA confirms that it does not sell personal information received through any channel.
9. International Data Transfers
DPA operates from India and has business operations, group relationships, clients and service providers in multiple jurisdictions, including India, the United States, the United Kingdom and other locations where DPA, its group entities, affiliates, authorised service providers or business partners operate.
Accordingly, personal information may be transferred to, stored in, accessed from or otherwise processed in countries other than the country in which it was originally collected, including for the purposes of service delivery, business operations, cloud hosting, technology support, recruitment, client management, vendor management, analytics, security, legal compliance and other purposes described in this Privacy Policy.
Where required by applicable law, DPA will implement appropriate contractual, organisational and technical safeguards designed to protect personal information and ensure that such transfers are carried out in accordance with applicable data protection requirements. Such safeguards may include access controls, confidentiality obligations, data processing agreements, transfer clauses, encryption where appropriate, vendor due diligence and other reasonable security measures.
DPA will not transfer personal information to any third party or jurisdiction in a manner that is contrary to applicable data protection law.
10. Security of Personal Information
DPA implements reasonable administrative, technical and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, loss, misuse or destruction.
These safeguards may include access controls, encryption where appropriate, logging and monitoring, employee confidentiality obligations, vulnerability management, incident response procedures, secure development practices, vendor reviews, access reviews, backup procedures and periodic review of security controls.
While DPA maintains reasonable security practices, no electronic system, transmission method or storage environment is completely secure, and absolute protection of data cannot be guaranteed.
11. Security Incidents and Breach Notification
If DPA becomes aware of a security incident involving personal information, DPA will assess the nature, scope and potential impact of the incident and take appropriate containment, investigation and remediation measures.
Where required, DPA will notify affected individuals, clients, regulators, authorities or other relevant parties without undue delay and within the timelines prescribed under the DPDP Act, the rules made thereunder, other applicable laws and applicable contractual obligations.
Such notification may include, where appropriate, details of the nature of the incident, the categories of personal information affected, likely consequences, steps taken or proposed to be taken by DPA, and measures that affected individuals may take to protect themselves.
DPA will also maintain appropriate internal records of security incidents and response actions in accordance with its internal policies, legal obligations and contractual requirements.
12. Data Retention and Disposal
DPA retains personal information only for as long as necessary to fulfil the purposes for which it was collected or processed, including service delivery, business operations, legal, regulatory, contractual, accounting, security, audit, tax and dispute-resolution requirements.
DPA may retain personal information for the longest of the following periods:
the period necessary to fulfil the relevant service, business, employment, recruitment, vendor, marketing or operational purpose;
any longer period required by applicable law, regulation, statutory obligation, professional obligation or contractual obligation;
the duration of any actual or potential litigation, investigation, audit, dispute or enforcement process, plus a reasonable subsequent period; or
the period necessary to maintain records for compliance, security, fraud prevention, accounting, tax, audit or legitimate business purposes.
When personal information is no longer required, DPA will securely delete, anonymise, aggregate or otherwise dispose of it using appropriate technical and organisational measures. Backup copies may be retained for a limited period in accordance with backup and disaster recovery procedures.
Retention by Category
13. Accuracy of Personal Information
DPA takes reasonable steps to ensure that personal information we process is accurate, complete and up to date for the purposes for which it is used.
You are responsible for ensuring that the information you provide to us is accurate and current. You may contact us at privacy@decimalpointanalytics.com to correct or update your personal information where it is inaccurate or incomplete.
14. Your Privacy Rights
Subject to applicable law, you may have the following rights in relation to your personal information:
Right to Access Information: to request information about the personal information processed by DPA and the processing activities undertaken in relation to such information.
Right to Correction: to request correction of inaccurate or misleading personal information.
Right to Completion: to request completion of incomplete personal information.
Right to Updating: to request updating of personal information that is out of date.
Right to Erasure: to request deletion or erasure of personal information where such information is no longer necessary for the purpose for which it was collected or where processing is no longer lawful, subject to applicable legal, contractual and retention requirements.
Right to Withdraw Consent: to withdraw consent where processing is based on consent.
Right to Grievance Redressal: to raise concerns, complaints or grievances in relation to the processing of your personal information.
Right to Nominate: to nominate another individual to exercise your rights in the event of death or incapacity, where applicable under law.
Depending on the applicable jurisdiction and law, you may also have additional rights, such as the right to restrict processing, object to certain processing, request data portability or obtain information about third parties with whom your information has been shared.
DPA may verify your identity before fulfilling a request and may require written authorisation when a request is made on your behalf by another person.
We will respond to valid privacy requests and grievances within ninety (90) days of receipt, or such shorter period as may be prescribed under applicable law.
To exercise your rights, please contact us at privacy@decimalpointanalytics.com.
15. Marketing Communications
Where permitted by law, DPA may send you marketing communications, newsletters, event invitations, service updates or business development communications.
You may opt out of receiving marketing communications at any time by using the unsubscribe link in the relevant communication, updating your preferences where such tools are available, or contacting us at privacy@decimalpointanalytics.com.
Even if you opt out of marketing communications, DPA may continue to send non-marketing communications, including service-related messages, legal notices, security alerts, transactional communications or other communications necessary for our relationship with you.
16. Third-Party Links and Platforms
Our website or communications may contain links to third-party websites, platforms, applications or services that are not operated or controlled by DPA.
DPA is not responsible for the privacy practices, content, security or policies of such third parties. We encourage you to review the privacy notices of any third-party websites or services you access.
17. Privacy Governance and Compliance Monitoring
DPA maintains privacy governance practices designed to monitor compliance with this Privacy Policy and applicable privacy obligations.
These practices may include periodic policy reviews, privacy risk assessments, employee awareness and training, vendor reviews, access reviews, incident management, internal escalation of privacy concerns, contractual reviews and audit or compliance monitoring.
DPA may update its privacy governance practices from time to time to reflect changes in law, business operations, technology, services, risk profile or industry standards.
18. Changes to this Privacy Policy
This Privacy Policy is effective from the date stated above and was last updated on the date stated above.
DPA reviews this Privacy Policy periodically and may update it to reflect changes in our processing activities, legal obligations, services, technologies, business operations or internal practices.
Where changes materially affect your rights or how we process your personal information, we will provide appropriate notice through our website, email or other suitable means before such changes take effect, where required by applicable law.
The latest version of this Privacy Policy will be made available on our website.
19. Privacy Contact and Grievance Redressal
If you have questions, concerns, complaints or requests regarding this Privacy Policy or our processing of your personal information, or if you wish to exercise your privacy rights, please contact us at:
Privacy / Grievance Officer: Malcolm Mascarenhas
Address: Decimal Point Analytics Pvt. Ltd., 9th Floor, Hiranandani Business Park, Lightbridge, Saki Vihar Road, Tunga Village, Chandivali, Powai, Mumbai, Maharashtra 400072, India.
We will acknowledge and respond to privacy requests and grievances within ninety (90) days of receipt, or such shorter period as may be prescribed under applicable law.
20. Our Offices
DPA has offices and business presence in multiple locations, including:
New York · London · Mumbai · Nashik · Gandhinagar
Effective Date: October 10, 2025
Last Updated: July 01, 2026
Version: 2.0