Who we are and how to reach us

BrandingBrandz is a commercial advisory practice operating principally in India, serving clients in hospitality, healthcare, education, retail and related sectors. For the purposes of applicable data protection law we act as a data controller in respect of our own website visitors, research subscribers and prospective clients, and as a data processor in respect of personal data we handle on behalf of client organisations during an engagement.

Questions about this policy, or requests to exercise the rights described in it, should be directed to privacy@brandingbrandz.com. We acknowledge every request within five working days and respond substantively within thirty days.

What we collect, and why

We collect only what we need for a stated purpose. In practice this falls into four categories.

  • Information you give us. Name, business email, role, organisation and telephone number when you request a report, register for a session, submit a diagnostic, apply for a role, or contact us. Where you complete a diagnostic instrument, this also includes the property and commercial parameters you enter.
  • Information collected automatically. IP address, browser and device type, referring page, pages viewed and time of visit, collected through server logs and analytics. This is used to understand how the site is used and to keep it secure.
  • Client engagement data. During an engagement we process data from client systems — property management, channel manager, analytics and advertising platforms. This may include personal data relating to the client's own guests or customers. We process it only on the client's documented instructions, under a data processing agreement.
  • Recruitment data. Where you apply for a role, the information in your application and any subsequent assessment or interview record.

Lawful basis for processing

We rely on the following bases. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

  • Consent — for marketing communications, research library access and non-essential cookies.
  • Contract — where processing is necessary to deliver an engagement you or your organisation has entered into.
  • Legitimate interests — for site security, fraud prevention, aggregate analytics and responding to business enquiries. We have assessed in each case that these interests are not overridden by your rights.
  • Legal obligation — where retention or disclosure is required by law, including tax and accounting requirements.

How long we keep it

We do not retain personal data indefinitely. Our standard periods are set out below; where a longer period is required by law or by an ongoing dispute, we retain only what that requirement covers.

Category Retention period Trigger for deletion
Website analytics 26 months Automatic expiry
Marketing contacts 24 months from last engagement Inactivity or withdrawal of consent
Diagnostic submissions 36 months Automatic expiry or request
Client engagement data Duration of engagement + 12 months Contract end, or earlier on client instruction
Unsuccessful applications 12 months Automatic expiry or request
Financial records 8 years Statutory requirement

Who we share it with

We do not sell personal data, and we do not share contact data with third parties for their own marketing purposes. We share data only in the following circumstances.

  • Service providers acting on our instructions — hosting, email delivery, analytics and CRM — each bound by contract to process only as directed and to apply appropriate security measures.
  • Client organisations, where you have submitted an enquiry that relates to an engagement they have commissioned.
  • Professional advisers — legal, accounting and insurance — where necessary and under a duty of confidence.
  • Regulators or law enforcement, where we are legally required to disclose. We will notify you unless legally prohibited from doing so.

International transfers

Some of our service providers process data outside India. Where that occurs we ensure an appropriate transfer mechanism is in place, together with a documented assessment of the recipient jurisdiction. Client engagement data is held within the client's specified jurisdiction wherever the client requires it.

Security

We apply access controls on a least-privilege basis, encrypt data in transit and at rest, log administrative access, and review permissions quarterly. Client engagement data is segregated by engagement and access is restricted to the assigned team.

No system is perfectly secure. If a breach occurs that is likely to result in risk to your rights, we will notify you and the relevant authority within the periods applicable law requires.

Your rights

Subject to the conditions in applicable law, you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent.

To exercise any of these, email privacy@brandingbrandz.com. We do not charge for a request unless it is manifestly unfounded or excessive, and we will tell you before applying any charge. If you are dissatisfied with our response, you may complain to the relevant supervisory authority.

Children

Our services are directed at businesses and are not intended for individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have, we will delete it.

Changes to this policy

We review this policy at least annually. Where we make a material change we will update the date at the top of this page and, where the change affects processing carried out on the basis of your consent, seek fresh consent.

This document was last reviewed on 1 September 2026. It is reviewed at least annually and whenever a change in our processing, contracting or technology makes a revision necessary. Questions about this document should be directed to legal@brandingbrandz.com.