Privacy policy
This policy explains what personal data Dive X Marketing collects through this website, our client portal and our work with clients, why we collect it, who we share it with and what you can ask us to do about it. It is written to be read, not to be waded through.
Who we are
Dive X Marketing is a creative and marketing studio based in Surat, India, working with clients in India and in Dubai and the wider UAE. We are the data controller for the personal data described here.
- Address: FF-3, 4th Floor Aagam Emporio, Vesu, Surat, Gujarat 395007, India
- Email: divexclient@gmail.com
- Phone and WhatsApp: +91 82388 25885
Any question about this policy, or any request about your data, goes to divexclient@gmail.com.
What we collect
We only collect what we need to answer you, to run the studio and to deliver our work.
- Contact form: your name, company, email address, phone number, your message and the services you tick in the quiz.
- Call bookings: your name, email address, phone number, company, whether you are in India or the UAE, the topic of the call, the date and time you pick and any note you add.
- Free audit requests: your name, email address, phone number, company, your website and Instagram account, and the goals, budget range and services you tell us about.
- Price estimates: your name, email address, phone number, company, the services and quantities you choose in the price calculator, the estimated total and any message you add.
- Job applications: your name, email address, phone number, city, the role you apply for, your portfolio link, your message and the CV file you upload.
- Client portal: for clients we invite, your name, company and account email, and a password that we store only as a scrypt hash, never in readable form. We also keep the files, approvals, change requests and comments you add in the portal.
- WhatsApp: the conversations you start with us on +91 82388 25885, including any files you send there.
- Site analytics: pages viewed, approximate location, device, browser and referral source, measured with Umami, an analytics tool we host ourselves. It sets no cookies and does not store your IP address in the clear. It can also record session replays, with every form field masked so what you type is never captured, and heatmaps of where visitors click and scroll, so we can see where the site is hard to use.
- Google tags: if we switch on Google Tag Manager or Google Analytics, similar usage data is also collected by Google.
- Technical data: when you send a form or book a call we store the IP address and browser details of that request, to block spam and abuse.
- Client and portfolio media: photos, video, brand assets and campaign results you give us for a project. We publish these in our portfolio only with your consent.
We do not ask for sensitive categories of data, and we would rather you did not send them. We do not run any profiling or automated decision-making about you.
Cookies
The public pages of this site do not need cookies to work, and our own analytics sets none. We use two cookies, both strictly necessary, so they do not need your consent:
- The admin sign-in cookie, used only by our team to reach the admin panel. It lasts up to 7 days.
- The client portal sign-in cookie, set only when a client signs in to the portal. It keeps you signed in for up to 14 days, or until you log out.
Some pages remember small choices, such as sound on or off on the AI ads page, in your own browser storage. That stays on your device and is not sent to us. If Google tags are switched on, Google may set its own cookies.
Why we collect it
- To reply to your enquiry and understand what you need.
- To prepare free audits, price estimates, quotes, proposals and contracts.
- To schedule the calls you book, and to send the invitation and any cancellation.
- To review job applications and contact the people we would like to meet.
- To deliver the work you hired us for, share it with you in the client portal, record your approvals and invoice it.
- To understand how the site is used and make it better.
- To keep the site, the portal and our forms secure and free of spam.
- To show our work, when you have agreed to it.
Legal basis and applicable law
We process personal data under India’s Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 together with its rules. Where our client or the person contacting us is in the European Union, we also apply the GDPR.
Our legal bases are your consent when you send one of our forms (contact, free audit, price estimate, call booking or job application), message us or agree to a portfolio publication; the performance of a contract when we deliver a project, including the client portal; and our legitimate interest in keeping the site secure and working well.
Who we share it with
We do not sell your data and we do not rent it out for advertising.
- Resend, which delivers the emails sent by our forms, call bookings and the client portal.
- Google, through Tag Manager and Analytics, only if we switch them on for site measurement.
- Our own team, and only the people working on your enquiry, application or project.
- Authorities, if the law requires it of us.
Umami analytics runs on our own server, so that data is not passed to an analytics company. Resend and Google may process data on servers outside India. We rely on their contractual data-protection terms for those transfers.
How long we keep it
- Contact-form enquiries, free audit requests, price estimates, call bookings and WhatsApp conversations: 24 months from our last exchange.
- Job applications and CV files: up to 12 months, after which they are deleted.
- Analytics data: 13 months.
- Client project files and records, including your client portal account and the files and comments in it: for the life of the engagement, and afterwards only as long as tax and accounting rules require.
- Sign-in cookies: until you log out or they expire.
Security
Access to enquiries, applications and client files is limited to the people who need it, protected by individual accounts and strong authentication. Client portal passwords are stored only as scrypt hashes, and each client can only see the projects and files that belong to them. Data in transit is encrypted over HTTPS. No system is perfect, so if a breach ever affects your data we will tell you and the relevant authority without delay.
Your rights
You can ask us to:
- Give you a copy of the data we hold about you.
- Correct anything that is wrong or out of date.
- Erase your data, where we have no legal reason to keep it, including a job application or your client portal account.
- Withdraw a consent you gave us, including consent to show your project in our portfolio.
- Stop sending you anything you did not ask for.
Write to divexclient@gmail.com and we will answer within 30 days. That same address reaches our grievance officer, who handles complaints under the Digital Personal Data Protection Act, 2023. If we cannot resolve it between us, you may escalate to the Data Protection Board of India, or to your local supervisory authority if you are in the EU.
Children
This site and our services are meant for businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this policy
We update this page when our tools or our practices change. The date below always reflects the current version, and material changes will be flagged on the site.
Last updated: 27 September 2026

