1. Scope & Governance Authority
This Privacy Policy governs the collection, processing, protection, and disposal of personal and corporate data by Brandonline Reputation (“we”, “us”, or “our”), operating from New Delhi, India.
As an executive online reputation management, statutory search de-indexing, and brand protection consultancy, we recognize that our clients often face sensitive legal, commercial, and personal reputation challenges. We treat all information with the highest standard of legal discretion, bilateral non-disclosure protections, and end-to-end encryption.
2. Information We Collect
We collect information strictly necessary to evaluate, execute, and deliver reputation defense and statutory de-indexing services:
- Client Contact Data: Full name, corporate title, enterprise name, email address, telephone/WhatsApp contact details.
- Forensic Case Dossiers: Defamatory URLs, offending search query terms, screenshots of defamatory articles, social media smear links, hostile review identifiers, and expunged court docket details provided for remediation.
- Authentication & Security Data: Cloudflare Turnstile bot verification tokens, submission origin URLs, IP address hashes, and browser user-agent strings collected strictly for DDoS mitigation and intake fraud prevention.
- Legal Documentation: Proof of identity, authorization mandates, and Power of Attorney instruments required by search engines and platform intermediaries for statutory takedowns.
3. Purpose & Legal Basis of Processing
We process data under lawful and transparent statutory bases, including contractual necessity, legitimate interest in legal remediation, and compliance with judicial directives:
4. Forensic Case Data & Mutual Non-Disclosure Protections
We enforce an institutional policy regarding confidentiality:
- Bilateral Mutual NDA: Prior to examining proprietary case details, confidential court orders, or unreleased corporate records, we execute a bilateral, legally binding Non-Disclosure Agreement.
- Restricted Need-to-Know Access: Only designated senior forensic directors and legal counsel assigned to your matter are granted access to case dossiers.
- Encrypted Transmission: Form submissions and electronic file exchanges utilize TLS 1.3 in transit and AES-256 at rest.
5. Zero-Data Retention & Cryptographic Purge Protocols
Unlike generic marketing agencies, we do not monetize or maintain unnecessary client data. Clients can invoke our Zero-Data Retention Protocol:
Upon the verified de-indexing of agreed-upon URLs or completion of the contracted SLA window, all client case materials, target lists, and draft filings are cryptographically shredded from our active storage upon written client instruction.
6. Third-Party Disclosures & Intermediary Platforms
We do not sell, rent, or trade client information to any data brokers, advertising networks, or third parties. Disclosures occur strictly in the following authorized scenarios:
- Search Engines & Platform Hosts: When filing statutory de-indexing petitions with Google Inc., Microsoft Bing, Meta, X, Reddit, or hosting registrars under statutory mandates.
- Trusted Infrastructure Vendors: Secure transaction providers, transactional email relays (Brevo / Sendinblue) for case intake dispatch, and Cloudflare Turnstile for anti-abuse protection.
- Judicial & Legal Mandates: When legally compelled by a court of competent jurisdiction under applicable laws of India.
7. Cookies, Turnstile & Telemetry
Our website utilizes privacy-preserving cookies and security technologies:
- Essential & Security Cookies: Necessary for session maintenance, security token validation, and page routing.
- Cloudflare Turnstile: We use privacy-friendly Cloudflare Turnstile captcha challenges to prevent automated spam and DDoS vectors without tracking users across unrelated websites.
- Cookie Preferences: Users can adjust cookie preferences through their individual browser settings at any time.
8. Global Statutory Frameworks (DPDPA, IT Act & GDPR)
Our data handling practices comply with major international and domestic data protection frameworks:
Indian DPDPA (2023) & IT Act
Adherence to Digital Personal Data Protection Act (DPDPA 2023) standards, reasonable security practices under Section 43A of the IT Act, and Intermediary Guidelines.
GDPR & Right to be Forgotten
Assisting European and global entities in exercising Article 17 Right to Erasure and judicial search de-listing petitions with search index providers.
9. Your Statutory Privacy Rights
Under applicable data protection laws, you retain the following enforceable rights:
- Right to Access & Confirmation: Request confirmation of what personal data is being held or processed.
- Right to Correction & Rectification: Request correction of inaccurate or incomplete records.
- Right to Erasure & Withdrawal of Consent: Instruct us to delete your consultation records or withdraw marketing consent at any time.
- Right to Grievance Redressal: File a formal grievance regarding data processing directly with our Grievance Officer.
10. Data Protection Officer (DPO) & Grievance Redressal
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details of our Data Protection Officer & Grievance Officer are published below:
