Introduction
This Privacy Policy describes how Cocoma Digital Private Limited ("Cocoma", "we", "us") collects, uses, shares, and protects information about you when you visit cocomadigital.com (the "Site"), submit a form, schedule a meeting, or otherwise interact with us through the Site.
We've written this notice to satisfy the disclosure requirements of the laws that apply to you wherever you live — including the GDPR (EU), UK GDPR, CCPA / CPRA (California), DPDP Act 2023 (India), Privacy Act 1988 (Australia), PDPA (Singapore), and APPI (Japan). Region-specific rights are spelled out under Region-specific notices.
Who we are
Cocoma Digital Private Limited
25, Maa Sharda Villa, Near St. Blaise Church, Amboli, Andheri West, Mumbai, Maharashtra 400058, India
For privacy questions, requests, or complaints, write to us at [email protected]. For users in the EU/UK, this address also serves as our data-protection contact. For users in India, this address serves as our Grievance Officer contact under Section 8(9) of the DPDP Act 2023.
Information we collect
Information you give us
When you submit a contact form, schedule a meeting, or inquire about our services, you provide:
- Identifiers — name, email address, phone number (if provided), company name, and role.
- Inquiry content — the message you send us, the type of help you're looking for, and any attachments you choose to share.
- Career applications — résumé, work history, and any other information you submit through our careers section.
Information collected automatically
When you visit the Site, we (and our service providers) may automatically collect:
- Device & connection data — IP address, browser type and version, operating system, device identifiers, time zone.
- Usage data — pages visited, links clicked, referring URL, time spent on pages.
- Cookies and similar technologies — see our Cookie Policy for the full inventory.
Information from third parties
If you reach us through a third-party platform (e.g. social-media login or referral), we may receive limited profile information from that platform under their own privacy terms.
We do not collect payment information through the Site. All paid engagements are handled through separate engagement letters and invoicing channels.
Why we use your information
We use your information for the following purposes. The legal basis on which we rely (under GDPR / UK GDPR) and the equivalent business purpose (under CCPA/CPRA) are listed beside each:
- Respond to inquiries and book meetings — performance of a contract or pre-contract steps you asked us to take.
- Process job applications — pre-contract steps; legitimate interests in evaluating candidates.
- Send marketing emails — your consent (you can withdraw at any time).
- Improve the Site and our services — legitimate interests in understanding how the Site is used.
- Detect and prevent fraud, abuse, and security incidents — legitimate interests; legal obligation.
- Comply with legal, tax, and regulatory obligations — legal obligation.
International transfers
Cocoma is headquartered in India. Some of our service providers operate from other countries — including the United States and the European Union. When we transfer personal data across borders, we rely on appropriate safeguards:
- EU/UK transfers — Standard Contractual Clauses ("SCCs") issued by the European Commission and the UK International Data Transfer Agreement / Addendum, supplemented by additional measures where needed.
- India inbound transfers — handled in line with the DPDP Act 2023 and any subsequent government-notified transfer rules.
- Other regions — equivalent contractual protections where applicable.
For a copy of the safeguards we rely on, write to [email protected].
How long we keep your information
We keep personal information only as long as we need it for the purposes listed above, or as long as the law requires. In practice:
- Inquiry data — kept while we evaluate and respond to your inquiry.
- Client engagement data — kept for the duration of our engagement and up to 30 days after the contract ends, after which it is deleted or anonymised, unless longer retention is required by law (for example, tax or accounting records).
- Marketing data — kept until you unsubscribe or otherwise withdraw consent.
- Job applications — kept for the duration of the recruitment process and a reasonable period afterwards in case of a future opening, unless you ask us to delete sooner.
Your rights
Depending on where you live, you have some or all of the following rights over your information. To exercise any of them, write to [email protected] and we'll respond within the time frame your local law requires (typically 30 days).
- Access — get a copy of the information we hold about you.
- Correction — fix information that is inaccurate or incomplete.
- Deletion / erasure — ask us to delete information we no longer need to keep.
- Object or restrict processing — limit how we use your information in specific circumstances.
- Portability — get your information in a structured, machine-readable format.
- Withdraw consent — at any time, where our processing relies on consent.
- Lodge a complaint — with your local data-protection authority (see the region-specific notices below).
We never charge a fee for an ordinary rights request, and we never penalise you for making one.
Security
We use industry-standard technical and organisational measures to protect personal information against loss, misuse, and unauthorised access — including encryption in transit, access controls, vendor due diligence, and regular review of our practices. No system is 100% secure; if we ever discover a breach affecting your information, we'll notify you and the relevant authorities in line with applicable law.
Children's privacy
The Site is not directed at children. We do not knowingly collect personal information from anyone under 13 (under US COPPA), under 16 (in many EU member states), or under 18 (under the Indian DPDP Act). If you believe a child has submitted information to us, write to [email protected] and we'll delete it.
Region-specific notices
The following notices supplement the rights described above for users in specific jurisdictions. Where a region grants stronger rights than those described earlier, the regional notice prevails for users in that region.
GDPR & UK GDPR
Controller: Cocoma Digital Private Limited, contact [email protected].
You have all the rights listed above plus the right to lodge a complaint with your local supervisory authority. In the UK, that's the Information Commissioner's Office (ico.org.uk). In the EU, your country's data-protection authority (full list at edpb.europa.eu).
We don't currently use automated decision-making that produces legal or similarly significant effects on you.
CCPA & CPRA
We've collected the categories of personal information described under Information we collect. We use it for the business purposes listed under Why we use your information. We share it with the categories of recipients listed under How we share information.
California residents have the right to know, delete, correct, opt-out of "sale" or "sharing" (for cross-context behavioural advertising), limit the use of sensitive personal information, and not be discriminated against for exercising any of those rights. We do not sell or share personal information for cross-context behavioural advertising.
To exercise any right, write to [email protected] with "California request" in the subject. You may authorise an agent to make a request on your behalf.
DPDP Act 2023
For Data Principals in India: this notice serves as our notice under Section 5 of the DPDP Act 2023. The personal data we collect, the purposes, and the manner of exercising rights are described above.
Grievance Officer / Contact: [email protected]. You may also approach the Data Protection Board of India once it has been constituted under the Act.
You may withdraw consent at any time, request access and correction, ask us to erase your data, or nominate someone to exercise these rights on your behalf in the event of your death or incapacity.
Privacy Act 1988 & Australian Privacy Principles
We handle personal information in line with the Australian Privacy Principles (APPs). You may request access and correction at any time via [email protected]. If you're not satisfied with how we've handled a complaint, you may escalate to the Office of the Australian Information Commissioner (oaic.gov.au).
PDPA
We process personal data in line with Singapore's Personal Data Protection Act. You may request access and correction via [email protected]. Complaints may also be raised with the Personal Data Protection Commission (pdpc.gov.sg).
APPI
For users in Japan, we comply with the Act on the Protection of Personal Information (APPI). The purposes for which we use your information are described above. You may request disclosure, correction, or suspension of use via [email protected]. You may also contact the Personal Information Protection Commission (ppc.go.jp/en).
Updates to this notice
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable law. The "Last updated" date at the top of the page tells you when the most recent revision took effect. For material changes, we'll give you reasonable notice before the change takes effect — typically by email or through a banner on the Site.
Contact us
For any privacy-related question, request, or complaint, please write to:
Cocoma Digital Private Limited
25, Maa Sharda Villa, Near St. Blaise Church, Amboli, Andheri West, Mumbai, Maharashtra 400058, India
Email: [email protected]
We'll acknowledge your request within a reasonable time and respond within the period your local law requires.