QuirkSphere Logo
QuirkSphere*
Legal

Privacy Policy

Version 1.0 · Last updated 27 July 2026

Status

This document is version 1.0, dated 27 July 2026. It is currently under legal review and has not been finalised. Some entity details in this document are still to be confirmed.

Table of contents

Privacy Policy


Plain-language executive summary

This policy has two parts because we play two different roles with data, and mixing them up is the most common mistake an agency makes.

Part A covers data where we decide why and how it is processed: our own website visitors, people who fill in our contact form or chat widget, our newsletter list, prospects we or a vendor find using enrichment tools like Apollo, our own vendors, and job applicants. Here, we are the "controller" (GDPR/UK) or "Data Fiduciary" (India). This is where our cold outbound work sits, and we treat it as our highest-risk activity: we are honest below that India's privacy law, once fully in force, has no "legitimate interests" ground at all, which means our own prospecting has no clean lawful basis under Indian law from the date that law fully commences, unless the individual has actually consented. We rely on a different, narrower route for the EU/UK (a documented legitimate-interests balancing test plus an Article 14 notice at first contact) and on opt-out rules for the US. We maintain a permanent suppression list: once you tell us to stop, we stop, everywhere, and we do not delete that suppression record even when we delete everything else about you, because deleting it would let you be recontacted.

Part B covers data that flows through our tools when we work for a client: managing their ad accounts, installing analytics or pixels on their site, running enrichment on their behalf, or building a site that collects their customers' data. There, the client is the controller and sets the purposes; we process on their documented instructions as a "processor." The substance of that relationship lives in our Data Processing Addendum, not here.

Across both parts: we tell you which legal basis applies to each activity, we tell you how long we keep your data and why, we name the categories of vendor we use (Vercel, Shopify, Resend, Upstash, Supabase, and others), and we are honest that we have not yet appointed an EU or UK representative, that our security programme is sized to a four-person company (no SOC 2, no ISO 27001, no 24/7 monitoring), and that two different breach-reporting clocks (six hours in India, seventy-two hours in the EU/UK) can both apply to the same incident at the same time.


PP-1. Who we are and what this policy covers

PP-1.1. This policy is published by QSP Infosolutions Private Limited, trading as QuirkSphere ("we", "us", "our"), of [TO BE CONFIRMED], for the website at quirksphereagency.com and our related marketing, sales, and recruitment activities.

PP-1.2. This policy describes two separate relationships with your personal data. Part A (PP-3 to PP-11) applies where we are the controller or Data Fiduciary. Part B (PP-12 to PP-13) applies where we process client data or client end-user data as a processor. PP-14 to PP-26 apply across both parts, and say where a rule is Part-A-only or Part-B-only.

PP-1.3. This policy does not cover our cookie and similar-technology practices in detail; see PP-21 and the cookie policy referenced there.

PP-2. Definitions

PP-2.1. Agency, we, us, our: QSP Infosolutions Private Limited trading as QuirkSphere.

PP-2.2. Client: a business that has engaged us under a Statement of Work or accepted our Terms of Service.

PP-2.3. Personal Data, Controller, Processor, Data Subject, Processing: as defined in the applicable data protection law. Where Indian law applies, "Controller" means Data Fiduciary, "Processor" means Data Processor, and "Data Subject" means Data Principal, and we use those Indian terms in the India-specific parts of this policy.

PP-2.4. Prospect: an individual whose business contact details we hold for the purpose of cold outbound marketing, sourced by us or a vendor rather than supplied by the individual.

PP-2.5. Enrichment Provider: a third-party service (for example Apollo.io and similar providers) that supplies, verifies, or appends business contact data.

PP-2.6. Suppression List: the permanent record of individuals and organisations who must not be contacted again, described at PP-11.

PP-2.7. Sub-processor: a third party we use to process personal data on our behalf, whether as a Data Fiduciary or a Processor.


PART A: WHERE WE ARE THE CONTROLLER / DATA FIDUCIARY

PP-3. Scope of Part A

PP-3.1. Part A applies to: visitors to quirksphereagency.com; people who submit our enquiry or contact form; people who use our chat widget; people on our newsletter or marketing list; Prospects sourced through an Enrichment Provider or from public sources for our own cold outbound; our vendors and suppliers; and job applicants.

PP-3.2. For all of these categories, we decide the purposes and means of processing. We are the controller under GDPR/UK GDPR, the Data Fiduciary under India's Digital Personal Data Protection Act 2023 (DPDP Act), the "business" under US state comprehensive privacy laws, and (for cross-context behavioural advertising specifically, see PP-18) a "third party" rather than a service provider under the CCPA.

PP-4. What we collect, and where it comes from

PP-4.1. Website visitors. Standard technical data (IP address, browser and device information, pages visited, referrer) collected automatically through our website and the analytics and advertising tags described in our cookie policy, including Meta Pixel for our own marketing.

PP-4.2. Enquiry and contact form submissions. Name, business email, company, and whatever you choose to tell us in the message field.

PP-4.3. Chat widget users. The content of messages you send our chat widget. Today the widget returns pre-set responses to frequently asked questions; your message content is not currently sent to a third-party AI model. Your IP address is processed transiently, in memory, solely to apply a rate limit, and is not retained in a database.

PP-4.4. Newsletter and marketing list. Name and email address, supplied directly by you when you sign up, plus engagement data (opens, clicks, unsubscribes).

PP-4.5. Prospects sourced from enrichment tools and public sources. We expressly disclose here, plainly, that we obtain business contact data (name, job title, business email, phone number, employer, and similar professional details) about individuals who have not given it to us directly, from:

PP-4.5.1. third-party B2B enrichment and data providers, including Apollo.io and functionally similar providers (the exact provider in use may change; we do not hard-code a single provider name into our operational systems for this reason); and

PP-4.5.2. public sources, including company websites, professional networking profiles, and public business registries.

PP-4.6. Vendors. Business contact details of our own suppliers and service providers, supplied by them or by their employer.

PP-4.7. Job applicants. CV, cover letter, and any information you provide during a recruitment process.

PP-5.1. We record the basis we rely on for each activity below. Where a regime offers no equivalent basis for a given activity, we say so rather than papering over the gap.

ActivityGDPR / UK GDPRDPDP Act (India)US state comprehensive lawsNote
Website operation and securityArt. 6(1)(f), legitimate interests (site security and functioning)Consent under ss.4 to 6 where personal data is collected via a form; no processing of identifying data is required merely to load the siteNo consent generally required; opt-out rights apply where data is sold or shared, or used for targeted advertising (see PP-18)DPDP has no legitimate-interests basis; see PP-6
Enquiry and contact formArt. 6(1)(b), steps prior to a contract, or Art. 6(1)(a), consentConsent under ss.4 to 6 (you provide the data to us directly, for a specified purpose)Notice-based; no sale, share, or targeted advertising use of form data absent separate consent
Chat widgetArt. 6(1)(a), consent (submitting a message)Consent under ss.4 to 6Notice-based
Newsletter / marketing listArt. 6(1)(a), consentConsent under ss.4 to 6Opt-out model; CAN-SPAM opt-out rights apply to every send
Cold outbound to Prospects (enrichment-sourced)Art. 6(1)(f), legitimate interests, subject to a documented Legitimate Interests Assessment and the Art. 14 notice at PP-8No lawful basis currently identified once ss.3 to 17 of the DPDP Act commence (s.7's closed list of nine "certain legitimate uses" does not, on this analysis, cover unsolicited B2B prospecting, and s.7 confirms no general legitimate-interests ground exists)Opt-out model under CAN-SPAM (email) and applicable state law; no consent required to send a first commercial email, but strict opt-out and identification rules applySee PP-6 and PP-8
Vendor contactsArt. 6(1)(b)/(f)Consent under ss.4 to 6, typically given by voluntary exchange of business contact details in the course of the relationshipNotice-based
Job applicantsArt. 6(1)(b), pre-contractual stepsConsent under ss.4 to 6Notice-based

PP-6. India: there is no "legitimate interests" ground

PP-6.1. Unlike the GDPR, the DPDP Act does not include a general "legitimate interests" lawful basis. Under s.7 of the DPDP Act, a Data Fiduciary may process personal data without consent only where it falls within one of nine closed, specifically listed "certain legitimate uses"; that list cannot be expanded by analogy or by contract.

PP-6.2. We say plainly: once the DPDP Act's substantive provisions (broadly, ss.3 to 17, s.27 other than s.27(1)(d), ss.28 to 34, s.36, and s.44(2)) come into force, our cold outbound prospecting to individuals sourced through enrichment tools or public sources, where those individuals have not consented and have no existing relationship with us, will not have an identified lawful basis under the DPDP Act. We are not aware of a workaround, and this document will not pretend otherwise.

PP-6.3. Until that commencement date, our outbound activity involving Indian residents is governed by the Information Technology Act 2000 (in particular s.43A and s.72A) and the Sensitive Personal Data or Information Rules 2011 (SPDI Rules), which do not impose an equivalent consent-or-basis requirement for ordinary business contact data (as opposed to "sensitive personal data" under those rules).

PP-7. GDPR/UK GDPR Article 14: notice where data was not obtained from you

PP-7.1. Where we hold your personal data because we or an Enrichment Provider found it, rather than because you gave it to us, and you are protected by the GDPR or UK GDPR, Article 14 (or the UK GDPR equivalent) requires us to give you a notice covering:

PP-7.1.1. our identity and contact details;

PP-7.1.2. the categories of personal data we hold about you;

PP-7.1.3. the purpose of processing and the specific legitimate interest we rely on, stated concretely (typically: identifying whether our marketing, creative, or growth services may be relevant to your organisation);

PP-7.1.4. the source of your data, including naming the Enrichment Provider or the public source where applicable;

PP-7.1.5. recipients or categories of recipients of the data;

PP-7.1.6. our international transfer arrangements (see PP-15); and

PP-7.1.7. your rights, including the absolute right to object described at PP-11.

PP-7.2. Timing. We provide this notice at the latest at the time of our first communication with you, which for cold outbound means the notice is built into the first email itself (a short paragraph plus a link to this policy), not buried in a general privacy page you would have to go looking for.

PP-7.3. We do not rely on the disproportionate-effort exemption. Article 14(5)(b) lets a controller skip individual notice where it would involve disproportionate effort. We do not invoke it for cold outbound, because by definition we already hold a working email address for every person we contact, and regulatory guidance treats direct contact as neither impossible nor disproportionate wherever a working contact address exists. We give the notice described above to every EU/UK individual we contact, at first contact, without exception.

PP-8. Opt-out, unsubscribe, and suppression

PP-8.1. Every marketing and cold outbound message we send carries a clear way to object or unsubscribe: a one-click link requiring no login, or a reply-based opt-out where a link is not technically available.

PP-8.2. What happens when you opt out. We add your email address, and any phone number we hold for you, to our Suppression List. Every future list, whether newly built, re-enriched, or reacquired from a different Enrichment Provider or public source, is checked against the Suppression List before use, and matches are automatically excluded.

PP-8.3. Suppression persists. We do not delete a Suppression List entry when we otherwise delete or age out a Prospect's data (see PP-9). We keep the fact that you objected for as long as we operate outbound marketing, because deleting that fact would be the one thing that lets you be recontacted by mistake. This is the sole exception to our general retention schedule at PP-16.

PP-8.4. For EU/UK individuals, the right to object under Article 21 is absolute and unconditional; we do not ask you to justify an objection to direct marketing, and we action it regardless of the legitimate interest we relied on.

PP-8.5. To opt out or unsubscribe outside of a specific message, contact business@quirksphereagency.com.

PP-9. Retention of prospect data

PP-9.1. We retain Prospect data (enrichment-sourced or public-source cold outbound contacts) for 24 from the date we acquire it, unless you engage with us (reply, click, book a call, or otherwise interact) within that period, in which case we retain the data for as long as the resulting relationship continues, reviewed periodically for accuracy.

PP-9.2. If we do not hear from you within that period, we delete or re-verify the record before any further use.

PP-9.3. Retention of Prospect data may be overridden by a mandatory minimum-retention rule under Indian law once in force; see PP-16.5.


PART B: WHERE WE ARE THE PROCESSOR

PP-10. Scope of Part B

PP-10.1. Part B applies where we handle personal data as part of delivering services to a Client: managing the Client's advertising accounts, installing analytics or tracking pixels on the Client's behalf, running enrichment or list-building on the Client's instructions, or building or maintaining a website or application that collects the Client's own customers' or end users' data.

PP-10.2. In every case covered by this Part, the Client is the controller (or Data Fiduciary) and sets the purposes and means of processing. We process only on the Client's documented instructions, we do not determine why the data is processed, and we do not use it for our own purposes.

PP-10.3. The substance of this relationship, including our security obligations, sub-processor authorisation, audit rights, deletion and return of data on termination, breach-notification timelines, and international transfer mechanisms, is set out in our Data Processing Addendum (06-data-processing-addendum.md, clause prefix DPA), which forms part of every engagement where we touch personal data on a Client's behalf. This policy does not restate that content.

PP-10.4. If you are an individual whose data reaches us through a Client's use of our services (for example, a visitor to a Client's website, or a contact in a Client's CRM or ad-audience data), you should direct any request about your data to that Client in the first instance. We will assist the Client in responding, as required by the DPA, but we will not act on your request directly unless the Client instructs us to.

PP-10.5. We are also, separately, a joint controller with Meta under GDPR Article 26 in respect of event data collected through Meta Pixel implementations we install, to the extent Meta's own terms characterise that relationship as joint controllership. Where this applies to a Client's site, the DPA addresses the allocation between us and the Client; this fact does not change PP-10.2.


PP-11. Data subject / Data Principal rights

PP-11.1. Depending on where you live and which regime applies to you, you may have rights to: access your data; correct or complete it; delete it; port it to another provider; object to processing, including direct marketing; restrict processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit use of sensitive data; and, under Indian law once relevant provisions commence, nominate another individual to exercise your rights on your death or incapacity.

PP-11.2. How to exercise these rights. Email business@quirksphereagency.com describing your request. We verify identity by matching the details you provide against the details we hold (for example, confirming a request comes from the same email address the data concerns); we may ask for further confirmation only where our records are ambiguous or the request concerns a category of data warranting extra care, and we do not require you to create an account to make a request.

PP-11.3. Response deadlines by jurisdiction.

JurisdictionStandard deadlineExtensionSource
EU / UK (GDPR, UK GDPR)One month from requestUp to two further months for complex or numerous requests, provided we tell you within the first month, with reasonsGDPR Art. 12(3)
California and most other US comprehensive state privacy laws45 days from a verified requestOne further 45 days, with notice given within the initial 45-day periodCal. Civ. Code s.1798.130; materially similar structures apply in most other US states with comprehensive privacy laws, though thresholds and exact wording vary by state
Brazil (LGPD)15 days for a full, itemised response (an immediate simplified confirmation is also available)No general extension identified in the researchLGPD Art. 19
India, today (SPDI Rules 2011, in force)Approximately one month, via our Grievance OfficerNot confirmedSPDI Rules Rule 5; exact wording UNVERIFIED, register item U3
India, once the DPDP Act's rights provisions commence (not yet in force)The grievance-redressal period we publish, statutorily capped at 90 daysWe commit to publishing a period materially shorter than the 90-day capDPDP Act ss.11 to 15; DPDP Rules 2025, Rule 14(3)
Canada, Quebec (Law 25)30 daysNot confirmed in the research (register item U105 flags the underlying statutory text as not independently verified)Reported in secondary research as the applicable Quebec deadline
Canada, federal (PIPEDA)No fixed statutory number confirmed in the research; PIPEDA's general standard is a reasonable timeCONFIRM before publishing a specific figure

PP-11.4. Regardless of the applicable statutory deadline, our internal target is to acknowledge every rights request within 5 working days and to complete straightforward requests well inside the shortest deadline in the table above.

PP-11.5. India, additional detail. Under the DPDP Act (once in force), you must generally raise a grievance with us first, and we must resolve it within our published period, before you can escalate a complaint to the Data Protection Board of India.

PP-12. International transfers

PP-12.1. We are based in Mumbai, India, and process personal data there. Depending on the service, we and our Sub-processors may also process data in other countries, including the United States and the European Union.

PP-12.2. India has no EU or UK adequacy decision. We say this plainly: the European Commission has not found India to provide an adequate level of data protection under GDPR Article 45, and the UK has not made an equivalent finding. Remote access to data from our team in India counts as a transfer even where the underlying data is hosted inside the EEA or UK.

PP-12.3. How we transfer data lawfully.

RouteMechanism
EU personal data to us in India (as controller or processor)The 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), module selected to match the flow, executed as part of our Data Processing Addendum, supported by a documented Transfer Impact Assessment
UK personal data to us in IndiaThe ICO's International Data Transfer Agreement or UK Addendum to the EU SCCs
Data to our US-based Sub-processors (hosting, email, and similar infrastructure)Standard Contractual Clauses (Module Two or Three as applicable); we do not rely on the EU-US Data Privacy Framework alone for any US sub-processor, given the pending legal challenge to that framework's adequacy finding noted in our research
Data within India, or to Indian Sub-processorsNo transfer mechanism required under current Indian law; the SPDI Rules impose a contractual/consent-based condition on cross-border transfer of sensitive categories only, and that condition itself falls away once the DPDP Act's substantive provisions commence
Brazil, UAE (DIFC/ADGM), and other regimes reached through a specific engagementAddressed in the jurisdiction-specific schedule to the Data Processing Addendum, using that regime's own mandatory clauses, unamended

PP-12.4. If a transfer mechanism we rely on is invalidated or withdrawn, we will put a replacement mechanism in place within 30 days and will not continue the affected transfer in the meantime if no safeguard is available.

PP-13. Sub-processors

PP-13.1. We use the following categories of Sub-processor. Named providers reflect our stack as described in our engineering documentation as at 27 July 2026; the current, complete list is maintained at our current sub-processor list, available on request from business@quirksphereagency.com because our AI creative model providers in particular change on a roughly monthly basis and we do not want this policy to go stale the moment a model provider changes.

CategoryNamed provider(s) (where known)
Hosting and deploymentVercel
E-commerce platformShopify
Transactional and marketing email deliveryResend
Rate limiting / caching infrastructureUpstash
Database and backend servicesSupabase
Business contact enrichmentApollo.io and functionally similar Enrichment Providers
Generative AI creative models (image, video, audio)A changing roster of third-party model providers; see our current sub-processor list, available on request from business@quirksphereagency.com rather than this document for the current list
AI coding assistance (for our own development work, not client data unless separately agreed)A changing roster of AI coding agent providers; see our current sub-processor list, available on request from business@quirksphereagency.com
Advertising and analytics platforms (our own marketing)Meta, and other platforms as used
Website analytics / pixelsMeta Pixel and comparable tags, gated by cookie consent as described in our cookie policy

PP-13.2. Change notification. We give at least 30 days' advance notice before adding a new Sub-processor that will process Client personal data, via the list at our current sub-processor list, available on request from business@quirksphereagency.com or direct notice under the relevant Data Processing Addendum, and Clients have an objection right as set out in that Addendum. This policy addresses our own Part A processing; Part B sub-processor governance is primarily a DPA matter.

PP-14. Retention schedule

Data categoryRetention periodTriggerJustification
Website analytics and server logsTypically 12 to 24 months, or shorter where a provider's default appliesCollection dateSecurity monitoring, troubleshooting, proportionality
Enquiry / contact form submissionsDuration of any resulting relationship, or 24 months from last contact if none developsSubmission dateResponding to and following up on enquiries
Chat widget transcriptsNot persisted server-side beyond the transient rate-limiting window described at PP-4.3N/ANo database storage in the current architecture
Newsletter / marketing listUntil you unsubscribe, plus the Suppression List entry described at PP-8.3 (indefinite)UnsubscribeHonouring your objection permanently
Prospect data (cold outbound)24 absent engagement; see PP-9Acquisition dateProportionate use of enrichment-sourced data
Vendor contact dataDuration of the vendor relationship, plus our standard financial-record retention belowRelationship startContract administration
Job applicant data12 for unsuccessful applicantsDecision dateRecruitment record-keeping, response to future queries
Suppression List entriesIndefiniteOpt-out / objectionSee PP-8.3; deletion would defeat the objection
Invoices, tax, and financial recordsAt least 7 years from the end of the relevant financial yearFinancial year-endIndian tax record-keeping norms, including the CGST Act's 72-month retention rule with a working margin, extended where any proceeding is pending
Security incident and breach recordsAt least 24 months from the incidentIncident detectionBreach register commitment at PP-17; demonstrating compliance over time
CERT-In-relevant ICT system logs (our own systems, India)180 days, retained within Indian jurisdictionOngoingCERT-In Directions dated 28 April 2022, Direction (iv); this is a fixed data-location mandate we cannot waive, and it applies to systems under our own control, not to logs held by our hosting, database, or analytics Sub-processors
Personal data, traffic data, and logs generally, once the DPDP Act's substantive provisions commenceA minimum of 1 year, even where you have asked us to delete your dataCollection / most recent accessDPDP Rules 2025, Rule 6(1)(e) and Rule 8(3), a mandatory minimum-retention floor that overrides a "delete on request" instruction; see PP-14.1 below
Client and client end-user data (Part B)As instructed by the Client, subject to the same Indian minimum-retention floor for any data processed in IndiaPer the Data Processing AddendumClient instruction governs; Indian statutory minimums cannot be contracted away

PP-14.1. Where retention and deletion conflict. Once the DPDP Act's Rule 6(1)(e)/Rule 8(3) minimum retention applies, if you ask us to delete your personal data before that minimum period has run, we will restrict the data (holding it securely, access-limited, and not using it for any purpose other than compliance) rather than delete it, and we will delete it once the statutory minimum is satisfied. We tell you this here so a deletion request is not met with a surprise.

PP-15. Security measures

PP-15.1. We are a four-person company. Our security programme is real but proportionate to that size, and we do not claim certifications or capabilities we do not have.

PP-15.2. What we do: multi-factor authentication on administrative and Client account access wherever the platform supports it; delegated access mechanisms (platform-native collaborator or partner access) rather than shared passwords, wherever a platform supports them; least-privilege access, limited to the individual actually working on a given engagement; encrypted connections (TLS) for data in transit; reliance on our infrastructure Sub-processors' own encryption at rest; a named password manager for any access that cannot be delegated; and prompt revocation of access when an engagement or personnel change ends.

PP-15.3. What we do not claim: we do not hold and do not represent that we hold SOC 2 or ISO 27001 certification; we do not provide 24/7 monitoring; we do not commit to a defined recovery time or recovery point objective; and we do not conduct contracted penetration testing unless a specific engagement requires and pays for it.

PP-16. Breach notification

PP-16.1. If a personal data breach occurs, we will notify affected individuals and, where required, regulators, in line with the fastest applicable legal deadline, and in any event without undue delay.

PP-16.2. India: 6-hour CERT-In duty. Under the CERT-In Directions dated 28 April 2022, we must report specified cyber incidents to CERT-In within 6 hours of becoming aware of them. This duty has no materiality threshold and cannot be extended by any agreement between us and anyone else, including a Client.

PP-16.3. EU/UK: 72-hour GDPR duty. Under GDPR/UK GDPR Article 33, a controller must notify its supervisory authority within 72 hours of becoming aware of a breach likely to result in a risk to individuals, where we act as a controller (Part A), or notify the affected Client without undue delay so the Client can meet its own 72-hour duty, where we act as a processor (Part B).

PP-16.4. These two duties coexist; they are not alternatives. A single incident affecting both an Indian dataset and EU/UK personal data can trigger both the 6-hour CERT-In duty and the 72-hour GDPR duty at the same time, on different clocks, to different regulators, with different content requirements. We do not treat compliance with one as satisfying the other.

PP-16.5. As a processor, our own contractual commitment to Clients (set out in full in the DPA) is to notify without undue delay and in any event within 24 hours of becoming aware of an incident affecting their data, a deliberately shorter internal target than either statutory clock, so a Client is never the one racing our compliance deadline.

PP-17. Children's data

PP-17.1. Our floor: under 18. We do not knowingly direct our own marketing, our website, or our cold outbound activity (Part A) at anyone under 18. This is a deliberately higher floor than several other regimes use, set to match the DPDP Act's definition of a "child" as anyone under 18.

PP-17.2. India. Once s.9 of the DPDP Act is in force (not yet in force as at this document's date; substantive commencement expected in the window described in our research log), s.9(3) prohibits tracking, behavioural monitoring, and targeted advertising directed at anyone under 18, with no advertising or marketing carve-out. We commit now, ahead of that date, not to build this into our own practices, and we will not knowingly enable it for a Client either without a documented, separately reviewed exemption.

PP-17.3. United States: COPPA (client sites, Part B). Where we build, host, or run marketing technology for a Client's website or app, and that property is directed to children under 13 or we have actual knowledge it is used by children under 13, the Children's Online Privacy Protection Act applies. Responsibility for determining whether a Client's property is child- directed, and for obtaining any required verifiable parental consent, sits with the Client as controller; we will implement whatever the Client's documented COPPA compliance instructions require, including suspending third-party advertising and analytics tags where instructed, and this is addressed further in the Data Processing Addendum.

PP-18. US state privacy rights

PP-18.1. Do not sell or share; do not track. We honour opt-out requests, including via the Global Privacy Control signal where technically supported, for any sale or sharing of personal information and for cross-context behavioural advertising.

PP-18.2. Sensitive personal information. We do not use sensitive personal information (where applicable law defines a category as sensitive) beyond what is reasonably necessary to provide the service you requested, and we honour requests to limit its use where that right applies.

PP-18.3. Your rights. Subject to the applicable state law and its thresholds, you may have the right to know what we collect, delete it, correct it, opt out of sale/share/targeted advertising, and limit use of sensitive personal information, exercised as described at PP-11.

PP-18.4. Appeals. Some US states (for example, Colorado and Connecticut) require an appeal route if we decline a rights request. Where that applies to your request, we will tell you how to appeal, and, if the appeal is unsuccessful, how to escalate to the relevant state Attorney General.

PP-18.5. Are we "the business"? This depends on the activity, and we say so rather than giving a single blanket answer:

PP-18.5.1. for our own website, our own marketing list, and our own cold outbound, we are the "business" (or controller) in our own right;

PP-18.5.2. for services we perform on a Client's documented instructions, the Client is the "business," and we are its service provider or contractor;

PP-18.5.3. for cross-context behavioural advertising, retargeting, and similar activity carried out on a Client's behalf, applicable California regulations (11 CCR s.7050) treat us as a third party, not a service provider, regardless of what our contract with the Client says; this affects what a Client can lawfully ask us to do with their customers' data, and is addressed in the DPA.

PP-19. Cookies

PP-19.1. Our use of cookies, pixels, and similar technologies on quirksphereagency.com, including consent management, is described in full in our cookie policy at https://quirksphereagency.com/cookies (05-cookie-policy.md, clause prefix CP), not repeated here.

PP-20. Automated decision-making and AI

PP-20.1. What we do not do. We do not use your personal data to make a decision that produces a legal effect or similarly significant effect on you using solely automated means, without human involvement, in respect of our own Part A processing. Our chat widget returns pre-set responses; it does not build a profile of you or make a decision about you.

PP-20.2. AI-generated content. Some content on our website and in our marketing may be produced or assisted by generative AI tools, and a substantial part of the creative work we deliver to Clients uses third-party generative AI models. We do not represent that AI-generated content is unique, original, or free of any third party's rights; the reasons for this are explained in our AI Delivery Rider (07-ai-delivery-rider.md), and the same honesty applies to our own website and marketing copy where AI-assisted.

PP-20.3. Client deliverables. Where a Client asks us to build a system that makes an automated decision about their own end users (for example, automated lead scoring or audience construction), that is governed by the relevant Statement of Work and the DPA, not by this policy.

PP-21. Grievance Officer and DPDP contact person

PP-21.1. Today, under the SPDI Rules 2011. Our Grievance Officer is:

Name:    **[TO BE CONFIRMED]**
Email:   **[TO BE CONFIRMED]**
Address: **[TO BE CONFIRMED]**

PP-21.2. Once the DPDP Act's relevant provisions commence. Our published contact person for the purposes of the DPDP Act is:

Name:  **[TO BE CONFIRMED]**
Email: business@quirksphereagency.com

PP-21.3. We publish these details on this page and will name the relevant contact in every reply we send to a rights request, as both the SPDI Rules and (once in force) DPDP Rule 9 require.

PP-22. Complaint routes

PP-22.1. We would rather resolve a concern directly; contact business@quirksphereagency.com first.

PP-22.2. India. Today, escalate an unresolved grievance to our Grievance Officer (PP-21.1). Once the DPDP Act's Board-related provisions are in force, and after exhausting our internal grievance process, you may complain to the Data Protection Board of India.

PP-22.3. European Union. You may complain to the supervisory authority of your EU member state of residence, place of work, or the place of the alleged infringement.

PP-22.4. United Kingdom. You may complain to the Information Commissioner's Office (ICO).

PP-22.5. United States. Depending on your state, you may complain to your state Attorney General, and California residents may also complain to the California Privacy Protection Agency.

PP-22.6. Canada. You may complain to the Office of the Privacy Commissioner of Canada, or, if you are a Quebec resident, to the Commission d'accès à l'information du Québec.

PP-23. EU and UK representative status

PP-23.1. We say this plainly, because it matters: as at 27 July 2026, we have not yet appointed an Article 27 GDPR representative in the EU, nor an equivalent representative under the UK GDPR.

PP-24. Changes to this policy

PP-24.1. We may update this policy as our practices, our vendor stack, or the law changes. We will update the version number and date below and, for a material change, take reasonable steps to bring it to your attention (for example, a notice on our website or an email to our newsletter list).

PP-24.2. Where a change affects Client data governed by a Data Processing Addendum, the DPA's own change-control terms govern, not this policy.


Version 1.0 | Dated 27 July 2026 | Next scheduled review 27 January 2027

Cookie settings

We use cookies to run the site and, only with your permission, to measure traffic and ad performance. Read our Cookie Policy for detail.