Privacy Policy
This policy explains how personal and business inquiry information is collected, processed, and safeguarded across this website and consulting practice.
Table of Contents (14 sections)
1. Introduction & Scope
This Privacy Policy applies to the personal and business information collected through the website darpanmishra.com and associated consulting communication channels operated by Darpan Mishra (“we,” “us,” or “our”).
We respect your privacy and are committed to transparency. This policy outlines our actual data handling practices in plain language, describing what information we collect when you browse the site, submit a consulting inquiry, or subscribe to our newsletter.
By using this website, submitting an inquiry form, or subscribing to strategic insights, you acknowledge the information practices described in this policy.
2. Information We Collect
We collect only the information that you voluntarily provide to us, as well as minimal technical data required for core functionality and site security:
- Consulting & Contact Inquiries: When you complete our consultation intake or contact form, you may provide your full name, email address, telephone number (optional), company or organization name (optional), website URL (optional), primary consulting area of interest, estimated business size, operational challenges, and message details.
- Newsletter Subscriptions: When you subscribe to our newsletter, we collect your email address, optional name, subscription source indicator, and subscription timestamp.
- Technical & Security Information: When you access our website or submit forms, our servers and automated bot-mitigation tools (such as Cloudflare Turnstile and server-side rate limiters) temporarily process request metadata, including your IP address and browser user-agent. This data is used strictly for abuse prevention, security verification, and rate limiting.
- Aggregated Analytics Data (Optional): If you grant analytics consent, we collect aggregated, non-personally-identifiable usage statistics (such as pages visited, content categories viewed, and non-sensitive interaction events like strategy call CTA clicks). This data contains zero personal information, inquiry messages, or subscriber emails.
- Client Preference Storage: We use local browser storage (
localStorage) to remember your visual theme preference (theme) and your analytics consent preference (analytics_consent).
What We Do NOT Collect: We do not collect credit card details, banking credentials, government identification numbers, biometric data, precise geolocation, browser canvas fingerprints, session replay recordings, or third-party commercial advertising tracking identifiers.
3. How We Use Information
We use collected information solely for legitimate business and operational purposes:
- Reviewing, qualifying, and responding to your consulting inquiries and messages.
- Evaluating operational compatibility and strategic fit for potential consulting advisory engagements.
- Maintaining internal communication records and business correspondence history.
- Delivering written strategic insights, case analyses, and platform announcements to active newsletter subscribers.
- Protecting the website, administrative infrastructure, and public forms against automated spam, bot attacks, and denial-of-service attempts.
- Administering core website features and maintaining system stability.
We do not sell, rent, lease, or trade your personal information to third parties. We do not engage in automated profiling for commercial behavioral advertising.
4. Consulting & Lead Inquiries
When you submit an inquiry through our consultation or contact form, your submission is recorded in our secure database as a business lead record. This record includes your contact details, self-reported business context, submission timestamp, and source attribution.
Authorized administrators may record internal notes within this record regarding discussion status, qualification criteria, and follow-up milestones. These notes are strictly internal and are never shared publicly.
7. Third-Party Service Providers
We rely on trusted infrastructure and service providers to operate this platform. These providers process data only to the extent necessary to fulfill their designated infrastructure functions:
- Web Analytics (Conditional): Google Analytics 4 (Google LLC) is used to evaluate public site navigation patterns and consulting conversion flows when configured and consented to. All events are stripped of personally identifiable information (such as names, emails, and message text), and IP anonymization is enforced.
- Database Hosting: MongoDB Atlas infrastructure is used for persistent, access-controlled database storage of lead records, subscriber records, published insights, and administrative settings.
- Bot & Abuse Prevention: Cloudflare Turnstile may be utilized on public forms to verify human submissions and protect against automated spam without presenting intrusive visual CAPTCHA puzzles.
- Transactional Email Infrastructure: Standard SMTP / Nodemailer email services are used to transmit internal notifications when new consulting inquiries or subscriber requests are submitted.
- Media Storage: Cloudinary infrastructure may be used to host and serve optimized static media assets such as case study graphics and article images.
These providers are bound by their respective data privacy standards and are prohibited from utilizing your information for independent commercial purposes.
8. Data Retention
We retain personal and inquiry information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including:
- Responding to your inquiries and conducting ongoing consulting communications.
- Maintaining legitimate business records, engagement history, and tax/accounting compliance documentation.
- Preserving suppression lists of unsubscribed email addresses to ensure we do not inadvertently contact you again.
- Protecting our legal rights and enforcing website terms.
When data is no longer required for these legitimate purposes, it is deleted or anonymized in accordance with our routine system maintenance practices.
9. Data Security Measures
We implement reasonable technical and organizational safeguards to protect your personal information against unauthorized access, loss, alteration, or disclosure:
- Encrypted data transmission across the entire platform via HTTPS / TLS protocols.
- Restricted administrative CMS access secured by credential-based authentication and secure session tokens.
- Cryptographic hashing of sensitive operational tokens (such as newsletter unsubscribe identifiers).
- Strict server-side schema validation, input sanitization, and request rate limiting.
Please note, however, that no method of electronic transmission over the internet or method of digital storage can be guaranteed to be 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
10. Your Rights & Choices
Depending on your location and applicable privacy laws, you have specific rights regarding your personal data:
- Unsubscribe from Communications: You may unsubscribe from newsletter communications at any time by clicking the unsubscribe link in any email or visiting our Unsubscribe page.
- Access & Inquiries: You may request confirmation of whether we hold personal information about you and request a summary of that information.
- Correction: You may request corrections to any inaccurate or incomplete inquiry details you have previously submitted.
- Deletion: You may request the deletion of your personal information, subject to our ongoing need to retain certain records for legal, regulatory, or legitimate business recordkeeping purposes.
To exercise any of these choices, please email us directly at hello@darpanmishra.com or submit an inquiry via our Contact Form.
11. External Links & Social Platforms
Our website contains links to external platforms, including professional social profiles (LinkedIn, YouTube, X, Instagram) and third-party reference sources. We have no control over the content, privacy policies, or practices of external websites and assume no responsibility for their handling of your personal data. We encourage you to review the privacy policies of any third-party websites you visit.
12. Children's Privacy
This website and our consulting advisory services are designed exclusively for business executives, founders, and professional operators. We do not knowingly solicit or collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected information from a minor, we will take prompt steps to delete such data from our records.
13. Changes to This Policy
We may revise this Privacy Policy periodically to reflect updates to our operational practices, consulting service offerings, or legal obligations. When changes are made, we will update the “Last Updated” date at the top of this page. Your continued use of the website following the posting of an updated policy constitutes your acknowledgment of the revisions.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to:
Darpan Mishra
Business Strategy & AI Systems Consultant
Email: hello@darpanmishra.com
Website: https://darpanmishra.com/contact