Privacy Policy
Last Updated: July 20, 2026
Guru Kirpa IT Solutions ("Guru Kirpa IT Solutions," "we," "us," or "our") provides web development and digital marketing services for businesses, with offices in Mohali (India), Berlin (Germany), and Coral Springs, FL (USA). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services, platforms, and applications — including our Meta Marketing API integration.
This policy is written to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable Indian data protection law. Sections that apply specifically to individuals in the EEA, the UK, or Switzerland are marked accordingly.
1. Information We Collect
We may collect the following types of information:
- Contact information — name, email address, phone number, business name, and address provided when you engage our services or fill out a form on a client website.
- Usage data — IP address, browser type, pages visited, time spent, and referring URLs collected automatically through cookies and analytics tools (including Google Analytics, Google Tag Manager, and Meta Pixel).
- Advertising data — ad impressions, clicks, conversion events, and audience segments used to measure and optimize advertising campaigns on Google and Meta platforms on behalf of our clients.
- Business data — business name, location, services, hours, and contact details provided by our clients to populate their websites and marketing materials.
We only collect the information needed to deliver our services. We do not collect or store sensitive personal data beyond what you choose to share with us.
2. How We Use Information
- To provide, operate, and improve our digital marketing and website services
- To measure advertising performance and optimize campaigns on behalf of clients
- To communicate with clients and prospective clients about our services
- To comply with legal obligations and enforce our terms
- To detect and prevent fraud or unauthorized use
3. Legal Bases for Processing (EU/EEA & UK)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data only where we have a valid legal basis under the General Data Protection Regulation (GDPR). Depending on the situation, our legal basis is one of the following:
- Consent (Art. 6(1)(a)) — where you have given clear, specific consent, such as opting in to non-essential cookies or marketing communications. You may withdraw consent at any time.
- Contract (Art. 6(1)(b)) — where processing is necessary to provide the services you or your organization have requested from us.
- Legal obligation (Art. 6(1)(c)) — where we must process data to comply with a legal or regulatory requirement.
- Legitimate interests (Art. 6(1)(f)) — where processing is necessary for our legitimate business interests (such as securing our systems, understanding how our services are used, and measuring advertising performance), provided those interests are not overridden by your rights and freedoms.
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Roles: Controller and Processor
For personal data we collect about our own clients, prospective clients, and visitors to our website, Guru Kirpa IT Solutions acts as the data controller.
When we build websites, run advertising, or manage lead-capture systems on behalf of a client, that client is the data controller for the personal data of their customers and website visitors, and Guru Kirpa IT Solutions acts as a data processor, processing that data only on the client’s documented instructions under a data processing agreement.
5. Meta Platform Data
We access the Meta Marketing API on behalf of businesses for the purpose of creating, managing, and measuring ad campaigns. Data obtained through the Meta API is used solely for these advertising management purposes and is not sold to third parties. We comply with Meta's Platform Terms and Data Policy.
If you are a Meta user who has interacted with ads we manage on behalf of a client, your data is handled in accordance with Meta's own Privacy Policy at facebook.com/privacy/policy.
6. Cookies and Tracking Technologies
Our website and our client websites use cookies and similar tracking technologies to analyze traffic and improve user experience. Strictly necessary cookies are required for the site to function. For non-essential cookies (analytics and advertising, including Google Analytics, Google Tag Manager, and the Meta Pixel), we rely on your consent where required by the GDPR and the ePrivacy Directive.
Where a cookie-consent banner is presented, non-essential cookies are not set until you accept them, and you may change or withdraw your choice at any time. You can also control cookies through your browser settings. Some features may not function correctly if cookies are disabled.
7. Data Sharing and Disclosure
We do not sell personal information. We may share information with:
- Service providers — third-party vendors who assist us in delivering our services (hosting, analytics, email), bound by confidentiality and data processing agreements.
- Advertising platforms — Google and Meta, as required to run campaigns on behalf of clients.
- Legal authorities — when required by law, court order, or to protect the rights and safety of our users.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with notice provided to affected parties.
8. International Data Transfers
We operate offices in India, Germany, and the United States, and we use service providers that may process data in these and other countries. This means personal data of individuals in the EEA, the UK, or Switzerland may be transferred to and processed in countries outside the EEA, including India and the United States, which may not provide the same level of data protection as your home country.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we put appropriate safeguards in place as required by the GDPR — in particular the European Commission’s Standard Contractual Clauses (SCCs), together with any additional measures needed to protect your data. You may request a copy of the safeguards we use by contacting us at info@gurukirpaitsolutions.com.
9. Data Retention
We retain information for as long as necessary to provide our services, fulfil the purposes described in this policy, and comply with legal obligations. Campaign data is typically retained for 24 months after a client relationship ends, unless a longer period is required by law. When data is no longer needed, we delete or anonymize it. You may request deletion of your data as described below.
10. Your Privacy Rights
Depending on where you live, you have rights over your personal data. If you are in the EEA, the UK, or Switzerland, the GDPR gives you the right to:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your data (the “right to be forgotten”) where there is no overriding reason to keep it.
- Restriction — request that we limit how we use your data in certain circumstances.
- Data portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent — withdraw any consent you have given, at any time, without affecting prior processing.
- Not be subject to solely automated decision-making that produces legal or similarly significant effects.
If you are a California resident, the CCPA/CPRA gives you rights to know, access, delete, and opt out of the “sale” or “sharing” of personal information, and not to be discriminated against for exercising those rights. To exercise any of these rights, contact us at info@gurukirpaitsolutions.com or gurukirpaitsolutions.com/contact. We will respond to verified requests within the timeframe required by applicable law (within one month under the GDPR; within 45 days under the CCPA). Verification may be required before we act on a request.
11. Right to Lodge a Complaint
If you are in the EEA, the UK, or Switzerland and believe we have handled your personal data unlawfully, you have the right to lodge a complaint with your local data protection supervisory authority. In Germany this is the data protection authority of the relevant federal state (Landesdatenschutzbehörde).
We would, however, appreciate the chance to address your concerns first — please contact us at info@gurukirpaitsolutions.com before approaching a supervisory authority.
12. Security
We use industry-standard security measures including encrypted connections (HTTPS), access controls, and regular security reviews to protect information in our care. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
13. Children's Privacy
Our services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy periodically. We will post the revised policy on this page with an updated "Last Updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or want to reach the person responsible for data protection, please contact the data controller:
Guru Kirpa IT Solutions
Offices: Mohali, India · Berlin, Germany · Coral Springs, FL, USA
Email: info@gurukirpaitsolutions.com
Website: gurukirpaitsolutions.com