Privacy Policy

How Dromley collects, processes, and protects information across market intelligence and advisory engagements. Transparent data handling for clients and visitors worldwide.

01

Information Collection and Processing

What Information Dromley Collects

Information You Provide Directly

When you submit an enquiry through our contact forms, book a consultation via our scheduling system, or engage with our advisory services, you provide your name, email address, telephone number, company name, industry, and details about your market intelligence requirements. This information is necessary to respond to your enquiry, schedule appointments, and deliver tailored advisory services.

Information Collected Automatically

Our website, hosted by Namecheap, collects standard technical data including your IP address, browser type, device information, pages visited, session duration, and referral source. Analytics data is collected through DataFast, which uses anonymous session identifiers stored in cookies to track page views and visitor behaviour patterns without identifying individuals.

Information from Third-Party Sources

For market intelligence engagements, Dromley analyses publicly available information from government databases, trade registries, industry publications, and corporate filings. This information relates to markets and organisations rather than individuals. Where personal data appears in public business records, it is processed solely within the scope of the commissioned engagement.

Consent and Legal Basis

Data collection operates under explicit consent where required by the Digital Personal Data Protection Act 2023 (India) and the General Data Protection Regulation (EU/UK). For enquiries and bookings, consent is obtained at the point of form submission. For advisory engagements, processing is grounded in contractual necessity. You may withdraw consent at any time without affecting the lawfulness of prior processing.

02

How Dromley Uses Your Information

Processing Purposes and Legal Basis

Delivering Advisory Services

Information collected through enquiry forms and consultation bookings is used to understand your market intelligence requirements, prepare for advisory sessions, deliver research and analysis, and provide ongoing engagement support. Processing for service delivery is grounded in contractual necessity under both DPDP Act 2023 and GDPR Article 6(1)(b).

Communication and Relationship Management

Contact information submitted through our enquiry and booking forms is synchronised with Brevo (formerly Sendinblue), which serves as our customer relationship management and email communication platform. Brevo is used for responding to enquiries, sending appointment confirmations, delivering engagement updates, and sharing relevant market intelligence content where you have opted in to receive it.

Website Analytics and Improvement

DataFast analytics data (page views, session patterns, navigation paths) is used in aggregated form to understand which services attract the most interest, identify content gaps, and improve the overall website experience. Analytics data is not used to identify, profile, or target individual visitors. No data is shared with advertising networks or used for behavioural advertising purposes.

Legal Compliance and Security

Processing activities also support compliance with applicable laws, responding to lawful requests from regulatory authorities, preventing fraud or misuse, and maintaining the security of our website and systems. Where processing is based on legitimate interests, Dromley has conducted balancing assessments to ensure individual rights are not overridden.

All processing maintains a documented legal basis under DPDP Act 2023 and GDPR

Data is used only for the purposes described in this policy or as separately agreed

Collection is limited to what is necessary for the stated purpose

Dromley does not sell personal data to third parties under any circumstances

03

Data Sharing and Third-Party Services

Service Providers and Data Processors

Technology Infrastructure

Dromley’s website is hosted by Namecheap, which provides the server infrastructure where website data and form submissions are stored. As a data processor, Namecheap handles data in accordance with its own privacy policy and data processing terms. Website data is stored on servers located in the data centre regions specified by Namecheap’s hosting infrastructure.

Form and Booking Processors

Contact and enquiry form submissions, along with consultation booking data, are stored within the website database on Namecheap servers. This data is also transmitted to Brevo for communication management and customer relationship tracking. Brevo processes this data as a sub-processor under its published data processing agreement, with data stored on Brevo’s infrastructure in the European Union.

Analytics Provider

DataFast collects anonymised website usage data (page views, sessions, navigation patterns) and processes it on DataFast’s own servers. DataFast operates as a data processor under its published terms of service and data processing addendum. DataFast does not collect payment information, and its tracking script uses anonymous identifiers rather than personally identifiable information.

Legal and Regulatory Disclosure

Dromley may disclose personal data to regulatory authorities, law enforcement, or judicial bodies only when required by a valid legal obligation such as a court order, statutory demand, or regulatory requirement. All such requests are evaluated for validity before any disclosure occurs. Dromley does not voluntarily share personal data with government agencies beyond what is legally mandated.

04

Data Security Measures

How Dromley Protects Your Information

Technical Safeguards

All data transmitted between your browser and our website is encrypted using TLS (Transport Layer Security). The website platform is maintained with current security updates, strong administrative passwords, and limited user access. Form submissions are stored in a password-protected database. Brevo provides its own encryption for data at rest and in transit within its infrastructure, and DataFast encrypts analytics data within its processing environment.

Access Controls

Access to personal data within the website administration panel, Brevo dashboard, and DataFast analytics is restricted to authorised personnel only. Administrative access uses strong credentials, and access is reviewed regularly. Third-party service providers (Namecheap, Brevo, DataFast) maintain their own access control policies as documented in their respective security frameworks.

Limitations

While Dromley implements reasonable and appropriate security measures for the nature and scale of data processed, no method of electronic transmission or storage is completely secure. Dromley cannot guarantee absolute security against all possible threats. In the event that a data breach affecting your personal information is identified, Dromley will notify affected individuals and relevant regulatory authorities within the timeframes required by applicable law.

Incident Response

If a security incident involving personal data is detected, Dromley will take immediate steps to contain and investigate the issue, assess the scope and severity, notify the Data Protection Board of India and relevant international supervisory authorities where required, and communicate directly with affected individuals including details of the incident, likely consequences, and remedial measures taken.

05

Your Rights Under Data Protection Law

Exercising Your Data Rights

Right to Access and Rectification

You may request a copy of the personal data Dromley holds about you (right to access), and request correction of any inaccurate or incomplete data (right to rectification). Access requests are fulfilled within 30 days of identity verification. Correction requests are processed within 15 days, and third parties such as Brevo are notified accordingly.

Right to Erasure, Restriction, and Portability

You may request deletion of your personal data (right to erasure) where processing is no longer necessary, you withdraw consent, or the data was unlawfully processed. You may also request that Dromley restrict processing of your data while a dispute is resolved (right to restrict processing), or receive your data in a portable format (right to data portability). You have the right to object to processing based on legitimate interests.

Right to Grievance Redressal

If you are dissatisfied with how Dromley has handled your data, you may submit a grievance. Dromley acknowledges grievances within 48 hours and provides a resolution within 30 days. Unresolved matters may be escalated to the Data Protection Board of India under the DPDP Act 2023, or to the relevant supervisory authority for EU/UK residents. As Data Fiduciary under the DPDP Act and data controller under GDPR, Dromley is responsible for ensuring your rights as a Data Principal are respected.

Rights requests should be sent to privacy@dromley.com

Identity verification is required before processing any rights request

Response timeframes comply with DPDP Act 2023 and GDPR requirements

No fees are charged for reasonable rights exercise requests

06

Cookies and Tracking Technologies

How This Website Uses Cookies

Essential Cookies

Our website sets session cookies required for it to function correctly, including login state management, form security tokens, and session handling. These cookies do not collect personal information for marketing and cannot be disabled without affecting core functionality.

Analytics Cookies

DataFast places cookies containing anonymous visitor and session identifiers to track page views, session duration, and navigation patterns. These identifiers are not linked to your name, email, or other personally identifiable information. DataFast data is processed on DataFast servers and used solely for understanding aggregate website usage. You may block these cookies through your browser settings.

Third-Party Cookies

Links to external platforms (such as social media profiles in the footer) may set their own cookies when you interact with them. Dromley does not control third-party cookies and recommends reviewing the privacy policies of external sites you visit. Dromley does not use advertising cookies, retargeting pixels, or cross-site tracking.

Managing Your Cookie Preferences

You can control cookies through your browser settings. Most browsers allow you to block all cookies, block third-party cookies, or receive warnings before cookies are set. Blocking essential cookies may affect website functionality. Dromley is implementing a cookie consent mechanism to provide granular control over non-essential cookies.

07

Data Retention

How Long Dromley Keeps Your Data

Advisory Engagement Records

Client data relating to active engagements is retained throughout the engagement period and for seven years after completion, supporting legal compliance under Indian tax and commercial law, audit requirements, and professional indemnity obligations. Records include contracts, deliverables, communications, and invoicing stored under secure archival procedures.

Enquiry and Marketing Data

Contact information submitted through enquiry forms and stored in Brevo is retained until you withdraw consent or for three years from your last interaction, whichever comes first. Unsubscribe requests are processed within 48 hours. Suppression lists are maintained to prevent re-contact. Booking records follow the same retention schedule unless an enquiry converts to an active engagement.

Technical and Analytics Data

Server logs maintained by Namecheap are retained per Namecheap’s own data retention policies. DataFast analytics data is retained per DataFast’s published schedule. Website database records including form submissions are retained as described above and securely deleted when no longer required.

Secure Deletion

When retention periods expire, data is permanently deleted from active systems. Deletion requests to Brevo result in removal from marketing lists and suppression list placement. Website database records are removed through secure deletion procedures. Backup systems follow a staggered deletion schedule to ensure complete removal across all storage locations.

08

International Data Transfers

Where Your Data May Be Processed

Transfer Mechanisms

Dromley operates from India and serves clients globally. Personal data may be transferred to, stored in, or processed in countries outside your country of residence through the third-party services described in this policy. All international transfers are conducted using appropriate safeguards including standard contractual clauses, adequacy determinations where available, or explicit consent for specific transfers as required by applicable law.

EU and UK Data Transfers

For individuals located in the European Union or United Kingdom, transfers of personal data to India (where Dromley is based) and to third-party processors operating outside the EU/UK are protected by EU-approved standard contractual clauses. Brevo stores data within the European Union and provides GDPR-compliant data processing. Where additional safeguards are needed, transfer impact assessments are conducted to identify and address specific risks.

Specific Service Provider Locations

Namecheap operates hosting infrastructure across multiple data centre locations. Brevo processes and stores customer communication data within the European Union. DataFast processes analytics data on its own servers under its published data processing addendum. The specific data residency arrangements for each service provider are governed by their respective terms and data processing agreements, which Dromley reviews to ensure adequate protection standards.

Client-Specific Arrangements

Where individual advisory engagements involve specific data residency requirements or transfer restrictions, Dromley works with clients to establish appropriate arrangements. This may include restricting processing to specific jurisdictions, implementing additional contractual protections, or using alternative communication channels where standard arrangements are not suitable for the client’s regulatory environment.

09

Contact and Regulatory Information

How to Reach Dromley on Privacy Matters

Privacy Contact

For privacy-related enquiries, rights requests, data access questions, or concerns about how your information is handled, contact Dromley at privacy@dromley.com. This inbox is monitored for all privacy and data protection matters. Dromley aims to acknowledge enquiries within 48 hours and provide substantive responses within the timeframes required by applicable data protection law.

Advisory Clients

Clients with active market intelligence engagements may also raise privacy queries through their designated engagement contact. Privacy matters raised through engagement channels receive the same level of attention and are subject to the same response timeframes as those submitted directly to the privacy contact address. Engagement-specific data processing arrangements are documented in individual service agreements.

Indian Regulatory Authorities

If you are not satisfied with how Dromley has responded to your privacy concern, you may escalate the matter to the Data Protection Board of India under the Digital Personal Data Protection Act 2023. For cybersecurity matters, complaints may also be directed to the Computer Emergency Response Team India (CERT-In). Contact details for these authorities are available on their respective government websites.

EU, UK, and International Authorities

Individuals located in the European Union may contact the data protection supervisory authority in their member state. UK residents may contact the Information Commissioner’s Office (ICO). Residents of other jurisdictions may contact the relevant privacy or data protection authority applicable to their location. Dromley cooperates with supervisory authority investigations and implements resolution measures as directed by competent authorities.

10

Policy Updates and Changes

How This Policy May Change

When Updates Occur

This privacy policy is reviewed periodically and updated to reflect changes in applicable law, the introduction of new technology platforms or service providers, changes to the types of data collected, or modifications to how data is processed. Updates may also be triggered by regulatory guidance from the Data Protection Board of India, European Data Protection Board, or other relevant supervisory authorities.

How You Will Be Notified

Material changes to this policy that affect how your personal data is processed will be communicated through a prominent notice on the Dromley website and, where practical, through direct notification to individuals whose data is affected. Material changes include new categories of data collection, new third-party processors, changes to retention periods, or modifications to your rights. Minor clarifications or formatting changes may be made without separate notification.

Your Options Following Changes

Following a material policy update, continued use of the Dromley website constitutes acceptance of the updated terms unless explicit consent is required for specific processing changes. If you disagree with a material change, you may exercise your right to erasure or withdraw consent by contacting privacy@dromley.com. For active advisory clients, material changes are discussed within the engagement relationship before taking effect.

Policy Version History

Previous versions of this privacy policy are maintained for reference and compliance audit purposes. If you have questions about how your data was processed under a previous version, contact privacy@dromley.com with the approximate date of your interaction. Dromley maintains records sufficient to address historical processing enquiries for the duration of applicable retention periods.

This policy is reviewed at least annually and following significant changes

Material amendments receive advance notification where practical

Emergency amendments may be implemented immediately with subsequent notice

The current version is always available at dromley.com/privacypolicy

Last Updated: Thursday, March 12, 2026