Privacy Policy
How TrademarkCounselIndia.org collects, uses, shares, and protects your personal data.
Please read this Privacy Policy carefully. By using the Platform, submitting a request, or providing your personal data, you confirm that you have read, understood, and consent to the practices described herein. This Policy should be read together with our Terms and Conditions.
Data Fiduciary Identity
Under the DPDP Act, 2023, the entity that determines the purpose and means of processing personal data is the Data Fiduciary. For the purposes of this Policy:
The independent Lawyers connected through this Platform are separate Data Fiduciaries for any personal data they independently collect or process in their professional capacity and are not acting as agents of the Company.
Applicability
This Privacy Policy applies to all personal data collected, received, stored, used, shared, or otherwise processed by the Platform in digital form, in connection with:
- Use of the website TrademarkCounselIndia.org and its subdomains;
- Submission of any form, request, or query on the Platform;
- Communication via email, phone, chat, or any other channel managed by the Platform;
- Payment transactions processed through or in connection with the Platform;
- Any administrative facilitation services provided by the Company.
This Policy applies to all Users/Clients (Data Principals) located in India whose personal data is processed by the Platform.
Data We Collect
The Platform collects only such personal data as is necessary for the purposes specified below (data minimisation principle). The categories of data collected include:
| Category | Data Elements |
|---|---|
| Identity Data | Full name, PAN, Aadhaar (if voluntarily provided), government-issued identity proof |
| Contact Data | Email address, mobile number, postal / registered address |
| Business & Applicant Data | Business name, constitution type, GST number, Udyam registration, MSME status, applicant category |
| Trademark Data | Trademark name / logo, proposed class(es), description of goods/services, date of first use (if applicable) |
| Document Data | Documents voluntarily uploaded by the User (identity proof, address proof, logo file, POA/TM-48, use evidence) |
| Payment Data | Payment reference numbers, transaction IDs, and payment status records. Full card or bank account details are processed directly by the payment gateway and are not stored by the Platform. |
| Technical / Log Data | IP address, browser type, device type, pages visited, session timestamps, and error logs collected automatically for security and service improvement |
| Communication Data | Records of emails, messages, and calls (where recorded with notice) between the User and the Platform or Lawyer |
Purpose of Processing
Under Section 5 of the DPDP Act, 2023, personal data may only be processed for a specific, clear, and lawful purpose for which consent has been given. The Platform processes personal data for the following distinct purposes:
4.1 Administrative Facilitation & Service Delivery
To process and manage the User's trademark service request, coordinate with an available independent Lawyer, organise submitted documents for the Lawyer's review, and track application status updates shared by the User or Lawyer.
4.2 Communication & Scheduling
To contact the User via registered email and phone number for appointment confirmation, scheduling, follow-ups, reminders, and service-related updates. Confirmation emails dispatched to the registered email address constitute commencement of service.
4.3 Payment Processing & Verification
To process and verify the Platform Fee payment, maintain transaction records, and handle refund or dispute requests in accordance with the Refund Policy.
4.4 Legal & Regulatory Compliance
To comply with applicable laws, orders of competent courts or tribunals, directions of regulatory authorities, and obligations under the DPDP Act, 2023, IT Act, 2000, and other applicable Indian legislation.
4.5 Fraud Prevention & Security
To detect, investigate, and prevent fraudulent activity, misuse of the Platform, identity fraud, and unauthorised access; and to maintain the security and integrity of the Platform and its systems.
4.6 Grievance Handling
To receive, process, investigate, and respond to complaints, grievances, and dispute resolution requests submitted by Users in relation to Platform Services.
4.7 Service Improvement & Analytics
To analyse aggregated, anonymised usage data to improve Platform functionality, user experience, and service quality. No individually identifiable personal data is used for this purpose beyond what is technically necessary.
Consent
Under Section 6 of the DPDP Act, 2023, processing of personal data requires free, specific, informed, unconditional, and unambiguous consent of the Data Principal, signified by a clear affirmative action.
5.1 How Consent Is Given
By submitting a request form on the Platform, paying the Platform Fee, or otherwise using the Services, the User provides free, informed, and unambiguous consent to the processing of their personal data for the purposes described in Section 4 of this Policy.
5.2 Right to Withdraw Consent
The User may withdraw consent at any time by sending a written request to support@trademarkcounselindia.org. Withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal, and shall not affect obligations already incurred (such as payment of the Platform Fee, which is non-refundable once service has commenced). Withdrawal may result in the Platform being unable to continue providing the facilitation Services to the User.
5.3 Consent for Calls & Recording
Calls and messages may be recorded for quality assurance and compliance purposes where permitted by law. A notice is provided at the commencement of such recording where required. By continuing communication after such notice, the User consents to recording to the extent permitted by applicable law.
Withdrawal of consent shall be as easy as giving consent. The Platform shall act on a consent withdrawal request within a reasonable period and not later than as required under applicable law.
Data Sharing
The Platform does not sell, rent, or trade personal data to any third party. Personal data may be shared only in the following limited circumstances:
6.1 Independent Lawyers (upon User request)
Contact details, trademark particulars, and documents submitted by the User may be shared with an independent Lawyer empanelled on the Platform, solely for the purpose of facilitating the trademark coordination requested by the User. Such sharing occurs only upon the User's explicit request and consent as part of the facilitation flow. The Lawyer is an independent professional and is not an employee, agent, or representative of the Company.
6.2 Payment Processors
Payment-related data is shared with authorised and PCI-DSS compliant payment gateway service providers solely for the purpose of processing the Platform Fee transaction. The Platform does not store full card or bank account details.
6.3 Technology & Infrastructure Service Providers
Data may be processed by third-party technology providers (such as cloud hosting, email delivery, and SMS service providers) engaged by the Platform as Data Processors under contractual obligations consistent with the DPDP Act, 2023. Such providers process data only on the Platform's instructions and for no other purpose.
6.4 Legal Obligation & Law Enforcement
Personal data may be disclosed to competent courts, tribunals, law enforcement agencies, or regulatory authorities where required by a legally binding order, direction, or applicable law. The Platform will, where permissible by law, notify the User of such disclosure.
6.5 Dispute Resolution
Personal data may be disclosed to arbitrators, mediators, or dispute resolution bodies in connection with a dispute involving the User and the Platform or a Lawyer, to the extent necessary for resolution of such dispute.
Data Retention
Under the DPDP Act, 2023, personal data shall not be retained beyond the period necessary for the purpose for which it was collected. The Platform retains data as follows:
| Data Category | Retention Period | Basis |
|---|---|---|
| Request & facilitation records | 3 years from date of last service interaction | Operational necessity & dispute resolution |
| Payment & transaction records | 8 years from transaction date | Compliance with accounting & tax laws (Income Tax Act, GST Act) |
| Communication records (emails, call logs) | 2 years from date of communication | Grievance handling & quality compliance |
| Uploaded documents | 1 year from service closure or last interaction, unless required longer by law | Service delivery & dispute resolution |
| Technical / log data | 6 months from collection | Security monitoring & fraud prevention |
| Grievance records | 3 years from resolution date | Regulatory compliance & legal obligation |
On expiry of the applicable retention period, personal data shall be deleted or anonymised, unless retention is required by a competent court order, ongoing legal proceeding, or applicable law.
Data Security
The Platform implements reasonable technical and organisational security safeguards as required under Section 8(5) of the DPDP Act, 2023 and Rule 6 of the IT (SPDI) Rules, 2011, to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- Encrypted transmission of data using HTTPS / TLS protocols;
- Access controls limiting data access to authorised personnel only;
- Secure storage practices for uploaded documents and personal data;
- Payment data handled exclusively by PCI-DSS compliant payment gateways;
- Regular review of security practices and vendor data-processing arrangements.
No internet-based data transmission is completely secure. While the Platform takes all reasonable steps to protect personal data, absolute security cannot be guaranteed. Users provide data at their own risk.
Your Rights Under the DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of your personal data processed by the Platform:
Right of Access (Section 11)
You may request a summary of the personal data the Platform holds about you and the purposes for which it is being processed.
Right of Correction & Update (Section 12)
You may request correction of inaccurate, incomplete, or outdated personal data held by the Platform.
Right of Erasure (Section 12)
You may request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
Right to Grievance Redressal (Section 13)
You may file a grievance with the Platform's Grievance Officer regarding processing of your personal data and receive a response within a reasonable time.
Right to Nominate (Section 14)
You may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
Right to Withdraw Consent (Section 6)
You may withdraw consent to processing at any time, subject to the effect this may have on your ability to use the Services (see Section 5.2).
Children's Data
The Platform's Services are not directed at or intended for use by individuals below the age of 18 years. The Platform does not knowingly collect personal data from minors. Trademark applications on behalf of a minor applicant must be submitted by a competent guardian or authorised representative.
If the Platform becomes aware that personal data of a minor has been collected without verifiable parental or guardian consent, it shall take steps to delete such data promptly. If you believe a minor's data has been inadvertently collected, please contact support@trademarkcounselindia.org immediately.
Cookies & Tracking Technologies
The Platform may use cookies and similar tracking technologies (such as web beacons and session trackers) to operate and improve the website. These may include:
- Strictly necessary cookies: Required for the Platform to function, such as session management and security tokens. These cannot be disabled.
- Analytical cookies: Used to understand how Users interact with the Platform (e.g., pages visited, time spent) to improve service quality. These use aggregated, anonymised data.
- Functional cookies: Used to remember User preferences and improve usability.
Third-party cookies (such as those set by payment gateways or analytics providers) are governed by the respective third party's privacy policies. The Platform does not use advertising or tracking cookies for cross-site behavioural profiling.
Users may manage or disable non-essential cookies through their browser settings. Disabling strictly necessary cookies may affect Platform functionality.
Cross-Border Data Transfer
The Platform primarily stores and processes data within India. Where any personal data is transferred to or processed in a country outside India (for example, through cloud infrastructure or third-party service providers whose servers may be located outside India), such transfer shall be carried out only in compliance with Section 16 of the DPDP Act, 2023 and any applicable government notifications or restrictions on cross-border data transfer.
The Platform shall ensure that any such cross-border transfer is subject to adequate data protection safeguards consistent with the obligations under the DPDP Act.
Third-Party Links
The Platform may contain links to external websites, payment gateways, or government portals (such as the Trade Marks Registry's IP India portal). The Platform is not responsible for the privacy practices or content of any third-party website or service. Users accessing third-party links do so at their own risk and are encouraged to read the privacy policies of such third-party platforms before providing any personal data.
Personal Data Breach
In the event of a personal data breach that is likely to result in harm to Data Principals, the Platform shall, in accordance with the DPDP Act, 2023 and applicable Rules:
- Take immediate steps to contain and remediate the breach;
- Notify the Data Protection Board of India (once operational) of the breach as required under applicable law;
- Notify affected Users of the breach and the nature of personal data affected, to the extent required under applicable law;
- Maintain a record of the breach and remedial action taken.
If you believe your personal data held by the Platform has been compromised, please contact support@trademarkcounselindia.org immediately.
Changes to This Policy
The Platform may update this Privacy Policy from time to time to reflect changes in law, regulatory requirements, or operational practices. Where material changes are made, the updated Policy will be published on the Platform with a revised effective date, and Users will be notified via registered email where practicable.
Continued use of the Platform following notice of changes constitutes acceptance of the revised Privacy Policy. Users who do not agree with changes should cease using the Platform and may request deletion of their data in accordance with Section 9 of this Policy.
Grievance Officer & Contact
In accordance with the DPDP Act, 2023 and the IT (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021, the Platform has designated a Grievance Officer for matters relating to personal data processing. Privacy-related requests, complaints, and grievances should be submitted in writing: