1. Who we are
Torodyn Technologies ("Torodyn", "we", "us" or "our") is a business-to-business marketing agency serving manufacturers and power systems companies. Our registered office is at No. 274, 14th Cross, Thyagarajanagar, Bengaluru 560028, Karnataka, India.
For personal data we collect for our own purposes, such as enquiries through this website, Torodyn is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and the controller for the purposes of the EU and UK GDPR. For personal data we handle on behalf of our clients during an engagement, we act as a Data Processor, as explained in section 5.
2. Scope of this policy
This policy applies to personal data we process when you:
- visit torodyn.xyz or any page, landing page or form we operate;
- contact us by email, phone, WhatsApp, LinkedIn or any other channel;
- register for, attend or speak at a webinar, roundtable or trade show meeting we organise;
- download a guide, report, template or other resource;
- work with us as a client, prospective client, supplier, freelancer or partner; or
- apply for a job or internship with us.
It does not cover websites, platforms or campaigns we build and run for clients under their own brand. Those are governed by the client's privacy policy.
3. Data we collect
We collect only what we need for the purposes in section 4. We do not intend to collect sensitive categories of data such as financial account details, health information, biometric data or government identity numbers through this website, and we ask you not to send them.
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, work email, phone number, company name, job title, city and country | You, through forms, email, calls or event registrations |
| Business information | Products you make, markets you sell into, team size, goals and challenges you share with us | You, in forms, discovery calls and workshops |
| Communications | Emails, messages, meeting notes, call recordings (only with notice at the start of the call) | You and our team |
| Event data | Registration details, attendance, questions asked, session feedback, dietary preferences for in-person events | You and our event platforms |
| Technical and usage | IP address, approximate location, browser, device type, pages viewed, referring site, time on page | Your browser, through cookies and server logs |
| Publicly available professional data | Business contact details and job titles published on company websites, LinkedIn or trade directories | Public sources and licensed B2B data providers |
| Commercial and billing | Billing contact, GSTIN, purchase order numbers, invoices and payment records | Clients and suppliers |
| Recruitment | CV, portfolio, work history, education, references and interview notes | Applicants, referees and job platforms |
4. Why we use it
Under the DPDP Act we process personal data either with your consent or for a legitimate use permitted by the Act, such as when you voluntarily provide data for a specified purpose. For visitors covered by the GDPR, we also rely on contract, legal obligation and legitimate interests, as listed below.
| Purpose | Basis |
|---|---|
| Responding to enquiries and pipeline review requests | Data you voluntarily provide for that purpose; legitimate interests (GDPR) |
| Preparing proposals and delivering contracted services | Performance of a contract; voluntary provision |
| Running webinars and events you register for | Voluntary provision; consent for sharing with co-hosts |
| Sending newsletters, insights and event invitations | Consent, which you can withdraw at any time |
| Measuring and improving the website | Consent for non-essential cookies |
| Business-to-business outreach to professionals in our industries | Legitimate interests (GDPR); consent where required by Indian law, with an opt-out in every message |
| Invoicing, tax records and accounting | Legal obligation, including the GST and Income Tax laws |
| Security, fraud prevention and protecting our legal rights | Legal obligation; legitimate interests |
| Assessing job applications | Voluntary provision; consent to retain your CV for future roles |
We do not use your personal data for automated decisions that produce legal or similarly significant effects on you.
5. Client data we process
When we run campaigns, manage CRMs or build target account lists for a client, we may handle personal data that belongs to the client's customers, prospects or distributors. In these cases:
- the client is the Data Fiduciary and decides why and how the data is used;
- we process it only on the client's documented instructions, under a written data processing agreement;
- we do not use it for our own marketing, combine it across clients, or keep it after the engagement ends, except where the law requires; and
- requests about that data should go to the client first. If you contact us, we will pass your request on to them promptly.
7. Who we share it with
We share personal data only when needed, and only under contracts that require the recipient to protect it and use it solely for the purpose we specify.
- Service providers who host our website and email, run our CRM, manage events and webinars, send newsletters, process payments, and provide analytics and advertising measurement.
- Freelancers and specialist partners, such as technical writers, designers and videographers, working on a specific engagement under confidentiality obligations.
- Event co-hosts and sponsors, only where the registration page clearly says so and you have agreed.
- Professional advisers, including auditors, chartered accountants and lawyers.
- Government and regulatory authorities, law enforcement or courts, where we are legally required to disclose information.
- A buyer or successor in a merger, acquisition or sale of assets, who will be bound by this policy for the data transferred.
We do not sell personal data, and we do not share it with third parties for their own marketing.
8. Transfers outside India
Some of our service providers store data on servers in other countries, including the United States, the European Union and Singapore. We transfer data outside India only to countries not restricted by the Government of India under the DPDP Act. For data covered by the GDPR, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
9. How long we keep it
We keep personal data only for as long as the purpose requires, then delete or anonymise it.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to an engagement | 24 months from our last contact |
| Client contract and project records | Duration of the engagement plus 8 years |
| Invoices and tax records | As required by the GST and Income Tax laws, currently at least 8 years |
| Newsletter subscriptions | Until you unsubscribe; suppression record kept to honour your choice |
| Event registrations | 24 months after the event |
| Website server logs | At least 180 days and up to 12 months, for security |
| Unsuccessful job applications | 12 months, or longer only with your consent |
10. How we protect it
We maintain reasonable security safeguards in line with the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These include:
- encryption of data in transit (TLS) and at rest on our core systems;
- single sign-on and multi-factor authentication for all staff accounts;
- access limited to people who need it for their role, reviewed every quarter;
- confidentiality clauses in every employment and contractor agreement;
- security and privacy due diligence on service providers before we use them;
- regular backups and logged access to client systems; and
- annual privacy and security training for our team.
No system is completely secure. If you believe your data with us has been put at risk, please contact us immediately.
11. Your rights
Subject to the law that applies to you, you have the right to:
Access a summary of the personal data we hold about you, what we do with it, and who we have shared it with.
Correct and update data that is inaccurate, incomplete or out of date.
Erase data we no longer need, or that you no longer consent to us using, unless we must keep it by law.
Grievance redressal from our Grievance Officer, and then from the Data Protection Board of India.
Nominate another person to exercise your rights in case of death or incapacity.
Portability, restriction and objection, if you are in the EU or UK, including objecting to direct marketing at any time.
To exercise any right, email privacy@torodyn.xyz from the address we hold, or write to our Grievance Officer. We may ask for reasonable proof of identity. We aim to respond within 30 days, and within the time limit set by the applicable law if shorter. Exercising your rights is free, unless a request is clearly unfounded or excessive.
If you are in the EU or UK, you may also complain to your local data protection supervisory authority.
12. Consent and withdrawal
Where we rely on consent, we ask for it in clear, plain language, separately for each purpose, and it is never pre-ticked. You can withdraw consent as easily as you gave it: through the unsubscribe link in any email, the cookie settings link, or by writing to us. Withdrawal does not affect processing that already took place, and we will stop the related processing within a reasonable time. You may also manage consent through a Consent Manager registered with the Data Protection Board of India, once such managers are available.
13. Marketing emails and calls
We send insights, event invitations and service updates to business contacts. Every email includes an unsubscribe link, and we honour requests within 10 working days. We follow the Telecom Commercial Communications Customer Preference Regulations for calls and SMS, and do not call numbers registered on the National Do Not Call registry for promotional purposes.
14. Children
Our website and services are meant for business professionals and are not directed at anyone under 18. We do not knowingly collect personal data from children, and we do not track or target advertising at them. If you believe a child has given us personal data, contact us and we will delete it.
15. Data breaches
If a personal data breach occurs, we will contain it, assess the risk, and notify the Data Protection Board of India and affected individuals as required by the DPDP Act and its rules. We will also report cyber security incidents to CERT-In within the time required by its directions. For client data, we notify the client without undue delay so they can meet their own obligations.
16. Other websites
Our site links to third-party websites, including LinkedIn, YouTube, event platforms and trade show organisers. We are not responsible for their privacy practices. Please read their policies before sharing data with them.
17. Changes to this policy
We review this policy at least once a year and when the law changes. We will update the date at the top of the page, and for material changes we will notify people we have a relationship with by email before the change takes effect. Earlier versions are available on request.
18. Grievance officer and contact
For questions, requests or complaints about how we handle personal data, contact our Grievance Officer. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.