Privacy Policy

Last Updated: 5th June 2026

1 WHO WE ARE

mayaPRAXIS ("we", "us", "our") is the Data Fiduciary responsible for personal data collected through this Website. Registered address: 188, First Floor, 3rd Cross, Panduranga Nagar, Bangalore, Karnataka, India 560076 Contact: mayapraxis.com/contact The contact details of our Grievance Officer are provided in Section 14 of this Policy.

2 SCOPE OF THIS POLICY

This Privacy Policy applies to all personal data collected through our Website at mayapraxis.com (the "Website"), which is built and hosted on Webflow's platform. It covers:


• Data you voluntarily provide via our contact form;

• Data automatically collected when you browse the Website via cookies and similar tracking technologies; and


• Data collected by the third-party analytics and advertising tools we have integrated into the


Website. This Policy does not apply to third-party websites linked from our Website. We are not responsible for the privacy practices of those sites.

3 KEY DEFINITIONS

Personal Data: Any information that relates to an identified or identifiable natural person, whether provided directly by you or collected automatically. Data Fiduciary: Under India’s Digital Personal Data Protection Act, 2023 ("DPDPA"), the entity that determines the purpose and means of processing personal data — here, mayaPRAXIS. Data Principal: The individual whose personal data is being processed — that is, you. Cookies: Small text files placed on your device by a website, used to store information about your visit and preferences. Consent: Under the DPDPA, consent must be free, specific, informed, unconditional, and unambiguous. You give consent by a clear affirmative act, such as clicking "Accept" on our cookie banner or submitting our contact form. Website: The website accessible at mayapraxis.com, built and hosted on Webflow.

4 WHAT DATA WE COLLECT

4.1 Data You Provide via the Contact Form

When you complete and submit the contact form on our Website, we collect the following:


• Full name — to address you personally in our response

• Email address — to send you a reply to your inquiry

• Phone number — to follow up by phone where appropriate

• Your message or inquiry details — to understand and respond to your request


This data is used solely to respond to your inquiry, schedule an appointment, or provide support. You are not required to create an account or log in to use our Website, and we do not store payment or financial information of any kind.


4.2
Data Collected Automatically

When you visit our Website, we and our third-party service providers automatically collect the following technical data through cookies and similar technologies:


• IP address (anonymised before storage in Google Analytics — see Section 5)

• Browser type and version

• Operating system

• Pages visited, time spent on each page, and navigation path

• Referring URL (the page you came from before visiting our Website)

• Date and time of your visit

• Device type and screen resolution

• Geographic region (country and city-level approximation derived from IP address)


This data is used for website analytics and advertising measurement, and is governed by your cookie consent choices (see Section 5).


4.3
Data We Do Not Collect

We do not collect the following:

• Financial or payment information (we do not sell products or services through the Website)

• Login credentials (there is no account or login functionality on this Website)

• Sensitive personal data such as health information, biometric data, caste, religion, or political views

• Personal data from individuals we know to be under 18 years of age (see Section 12)

5 COOKIES AND TRACKING TECHNOLOGIES

5.1 Your Cookie Choices

When you first visit our Website, a cookie consent banner will appear with two options:


• Accept — All cookie categories below are activated, including analytics and marketing cookies.


• Decline — Only strictly necessary cookies are placed. No analytics or marketing data is

collected during your session. You may change your preference at any time by clearing your browser cookies and revisiting the Website, which will re-display the consent banner. You can also adjust cookie settings through your browser settings. Declining cookies will not prevent you from accessing or using any part of this Website. We do not use pre-selected options or deceptive design patterns to steer you towards accepting cookies. Your consent is obtained through a clear and equal Accept / Decline choice.

5.2 Strictly Necessary Cookies (No Consent Required)

These cookies are required for the Website to function and cannot be disabled through our cookie banner. Webflow hosting cookies: Required for load balancing, security, and basic session management. Cookie consent record: Remembers your Accept or Decline choice so the banner does not reappear on every page. This is a persistent cookie lasting up to 12 months.

5.3 Analytics Cookies (Consent Required)

With your consent, we use Google Analytics, deployed via Google Tag Manager, to understand how visitors interact with our Website. This data is used to improve our Website content and structure. Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Cookies set: _ga, _ga_[Property ID], and _gid (standard Google Analytics 4 cookies) Data collected: Page views, session duration, device type, browser type, approximate geographic region (city-level), and referral source. Full IP addresses are never stored — we have enabled IP anonymisation (anonymizeIp) in our Google Analytics settings. Data retention: 14 months (the minimum available setting, configured in our GA4 property). Privacy Policy: https://policies.google.com/privacy Opt-out tool: https://tools.google.com/dlpage/gaoptout Google Tag Manager (GTM) is the tag management system through which Google Analytics and other scripts are loaded. GTM itself does not collect personal data; it only fires the tags we configure based on rules we set. GTM Privacy Policy: https://policies.google.com/privacy

5.4 Marketing Cookies (Consent Required)

With your consent, we use the following tools to measure the effectiveness of our marketing campaigns and to show relevant advertisements to previous visitors of our Website on third-party platforms. We do not display advertisements on our Website itself; these tools are used solely to run our own campaigns on external platforms. Meta Pixel (Facebook / Instagram) The Meta Pixel is a tracking script provided by Meta Platforms, Inc. that records visitor actions on our Website. It enables us to measure campaign conversions and show our own advertisements to people who have previously visited our Website on Facebook and Instagram. Provider: Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA Data collected: Page view events, button click events, IP address (hashed), and browser identifiers including the Facebook cookie (_fbp). How Meta uses it: Meta may combine this data with information it holds about your Facebook or Instagram account to serve you our advertisements on those platforms. Privacy Policy: https://www.facebook.com/policy.php Ad preferences opt-out: https://www.facebook.com/settings?tab=ads Industry opt-out: https://www.youronlinechoices.eu/ or https://optout.aboutads.info/ The Meta Pixel is only activated after you have accepted marketing cookies. If you decline, the Meta Pixel does not fire. Google Ads (Conversion Tracking and Remarketing) We use Google Ads conversion tracking and remarketing tags, deployed via Google Tag Manager, to measure the effectiveness of our advertising and to show our own ads to visitors of our Website through Google’s advertising network (Google Search, YouTube, and Display Network). Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Data collected: Ad interaction data, page visit data, and Google cookie identifiers (_gcl_au, _gcl_aw). How Google uses it: Google may match this data with your Google account or browsing profile to serve you our advertisements across Google properties. Privacy Policy: https://policies.google.com/privacy Ad preferences: https://adssettings.google.com/ Industry opt-out: https://optout.aboutads.info/ Google Ads tags are only activated after you have accepted marketing cookies. If you decline, no remarketing or conversion tracking data is collected.

5.5 Third-Party Cookie Disclosure

Google and Meta each set cookies on your device directly when their tags fire. These companies may use the data collected to build profiles about you across multiple websites and services. We do not control how these companies use that data once it leaves our Website. You can manage your preferences directly with each company using the links provided above.

Under the DPDPA 2023 and other applicable data protection law, we rely on the following bases for processing your personal data: Responding to contact form submissions: Your consent, given by voluntarily submitting the form, and/or our legitimate interest in responding to business and client inquiries. Analytics (Google Analytics via GTM): Your consent, activated only if you click Accept on the cookie banner. Marketing and remarketing (Meta Pixel, Google Ads via GTM): Your consent, activated only if you click Accept on the cookie banner. Security, fraud prevention, and site integrity: Our legitimate interest in protecting our Website and users from security threats. Compliance with legal obligations: Where applicable law requires us to retain or disclose data. Where we rely on consent, you may withdraw it at any time (see Section 10). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7 HOW WE USE YOUR PERSONAL DATA

We use your personal data only for the purposes described below. We do not use your data for any purpose incompatible with the original purpose of collection.

• To respond to inquiries, schedule appointments, and provide support in relation to contact

form submissions.

• To analyse Website usage and improve the Website’s content and performance using

aggregated analytics data.

• To measure the effectiveness of our advertising campaigns (conversion tracking).
• To show our own advertisements to past visitors of our Website on Facebook, Instagram, and

Google’s advertising network (remarketing) — only where you have consented to marketing cookies.

• To comply with applicable legal obligations.
• To protect our rights, property, and the safety of our users and the public.

We do not sell your personal data to any third party. We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. We do not use contact form data for marketing without your separate consent.

8 SHARING YOUR PERSONAL DATA

We do not sell your personal data. We share it only in the limited circumstances below.

8.1 Service Providers

We share data with the following trusted third-party service providers who process data on our behalf under written agreements that restrict them from using your data for any other purpose: Webflow, Inc. (USA): Website hosting. Contact form submissions are received and stored by Webflow on our behalf. Google LLC (USA): Google Analytics (website analytics), Google Tag Manager (tag deployment), and Google Ads (conversion tracking and remarketing). Meta Platforms, Inc. (USA): Meta Pixel (conversion tracking and remarketing on Facebook and Instagram).

8.2 Business Transfers

If mayaPRAXIS is involved in a merger, acquisition, restructuring, or asset sale, your personal data may be transferred to a successor entity. We will provide prominent notice on our Website before your data becomes subject to a materially different privacy policy.

8.3 Legal and Regulatory Disclosure

We may disclose your personal data if required by applicable law or in response to a valid order from a court or government authority, or where we in good faith believe such disclosure is necessary to:

• Comply with a legal obligation;
• Protect and defend the rights or property of mayaPRAXIS;
• Prevent or investigate possible wrongdoing in connection with the Website;
• Protect the personal safety of users or the public; or
• Protect against legal liability.

8.4 With Your Consent

We may share your data for any other purpose with your explicit prior consent.

9 INTERNATIONAL TRANSFERS OF PERSONAL DATA

Our third-party service providers — Webflow, Inc., Google LLC, and Meta Platforms, Inc. — are incorporated in the United States. When we share your personal data with them, it is transferred to and stored in the United States and potentially other countries whose data protection standards may differ from those in India. We take the following steps to help ensure your personal data is handled appropriately during international transfers:

• We select service providers who have published strong data protection commitments and,

where applicable, participate in recognised frameworks such as the EU-US Data Privacy Framework;

• We rely on contractual protections such as Data Processing Agreements where required by

applicable law;

• We only share the minimum personal data necessary for the services provided; and
• We conduct reasonable due diligence on the data protection practices of our service

providers.

10 YOUR PRIVACY RIGHTS

10.1 Rights Under India’s DPDPA 2023

If you are in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023: Right to Access Information: You may request a summary of the personal data we hold about you and the purposes for which it has been processed. Right to Correction: You may request that we correct inaccurate or incomplete personal data we hold about you. Right to Erasure: You may request deletion of your personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations. Right to Grievance Redressal: You have the right to have any grievance about our processing addressed by us within a reasonable time. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India once it is operational. Right to Nominate: You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. To exercise any of these rights, please contact us using the details in Section 14. We will acknowledge your request within 3 business days and aim to resolve it within 30 days.

10.2 Withdrawing Consent

You may withdraw consent you have previously given at any time:

• Cookie consent: Clear your browser cookies and revisit the Website to be shown the

consent banner again, or use your browser’s settings to block or delete our cookies.

• Contact form data: Contact us to request deletion of the personal data you submitted,

subject to our legal retention obligations. Withdrawal of consent does not affect the lawfulness of processing that took place before withdrawal.

10.3 Note for Visitors Outside India

If you are accessing our Website from the European Economic Area, the United Kingdom, or any other jurisdiction with applicable data protection laws, you may have additional rights under those laws. We will endeavour to honour such requests. Please contact us for further information.

11 RETENTION OF YOUR PERSONAL DATA

We retain your personal data only for as long as necessary for the purposes set out in this Policy, or as required by applicable law. The following maximum retention periods apply: Contact form submissions (name, phone, email, message): Up to 24 months from the date of submission, to manage follow-up inquiries and resolve any disputes. Website analytics data (Google Analytics cookies): Up to 14 months, which is the minimum retention setting available in GA4. Server logs (IP addresses, access times): Up to 12 months for security monitoring and troubleshooting. Cookie consent records: Up to 12 months, aligned with the consent cookie lifetime. Marketing event data (Meta Pixel, Google Ads): As per Meta’s and Google’s own retention policies, which are outside our direct control. Please refer to their respective privacy policies. We may retain personal data beyond the above periods only where required by applicable law, where the data is necessary to establish or defend legal claims, or where you have made an explicit request to retain specific information. When retention periods expire, personal data is securely deleted or anonymised.

12 SECURITY OF YOUR PERSONAL DATA

We implement commercially reasonable technical and organisational measures to protect your personal data, including TLS/SSL encryption for all data transmitted between your browser and our Website, and Webflow’s enterprise-grade hosting infrastructure with industry-standard security practices. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law.

13 CHILDREN’S PRIVACY

Our Website is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from minors. Under India’s DPDPA 2023, processing the personal data of a child (anyone under 18) requires verifiable parental consent, which we do not currently facilitate. If you are a parent or guardian and believe your child has submitted personal data through our Website, please contact us immediately using the details in Section 14 and we will delete that data promptly.

14 GRIEVANCE OFFICER AND CONTACT

In accordance with India’s DPDPA 2023 and the Information Technology Act, 2000, we have designated a Grievance Officer to address complaints and queries about our data handling practices. For a business of our size, the owner of mayaPRAXIS serves as the Grievance Officer.
Grievance Officer: Elsa Anna Simon
Organisation: mayaPRAXIS
Address: 188, First Floor, 3rd Cross, Panduranga Nagar, Bangalore, Karnataka, India – 560076
Contact form: mayapraxis.com/contact We will acknowledge your complaint within 3 business days and endeavour to resolve it within 30 days. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India once it is operational.

15 CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and post a prominent notice on our Website before the change becomes effective. We encourage you to review this Policy periodically to remain informed about how we handle your personal data.

Our Website may contain links to third-party websites that are not operated by us. Clicking such a link will direct you to that third party’s site. We strongly advise you to review the Privacy Policy of every website you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services.