Your data, handled with care.
What personal data we collect, why, how we protect it, and the rights you have under India’s Digital Personal Data Protection Act, 2023 – in plain language.
In short: we collect only what we need to reply to you and to do the work you hire us for. We never sell personal data. We do not use analytics or advertising cookies. You can ask us to access, correct or erase your data, withdraw consent, or raise a grievance at any time by writing to support@y5media.com.
01Who we are and what this covers
This website, y5media.com, is operated by Y5MEDIA, the flagship brand of Raymond Cardoza Enterprises, a sole proprietorship registered in India and owned by Raymond Ronald Cardoza (“Y5MEDIA”, “we”, “us”, “our”). We are based in Mangaluru, Karnataka, India, and serve clients in India and abroad.
This Privacy Policy explains how we collect, use, store, share and protect personal data – any information about an identifiable individual – when you:
- visit or browse this website;
- contact us through the website form, email, phone or WhatsApp;
- request a free AI visibility report, an audit or a proposal; or
- engage us, or work for a business that engages us, for any of our services.
It should be read with our Terms & Conditions, Business Policy, Refund Policy and Disclaimer.
02The law that applies
We handle personal data in line with the Indian laws that apply to us, principally:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”); and
- the Information Technology Act, 2000 and the rules made under it, to the extent they continue to apply.
The DPDP Rules bring the DPDP Act’s obligations into force in phases. At the date of this policy, most obligations of Data Fiduciaries are scheduled to become enforceable on 13 May 2027. We have written this policy to meet the DPDP standard now, rather than waiting for that date. Where a particular obligation applies only from a later date, or only to certain kinds of businesses, we say so or describe it conditionally.
In this policy we use the DPDP Act’s terms in plain language: you are the Data Principal (the person the data is about); a Data Fiduciary decides why and how personal data is processed; and a Data Processor processes personal data on a Data Fiduciary’s behalf.
03Our role: Data Fiduciary or Data Processor
We are the Data Fiduciary for personal data we collect for our own purposes – for example, your enquiries, our communications with you, our client and billing records, and data about visitors to this website.
We act as a Data Processor when we handle personal data on a client’s behalf as part of a service – for example, contact lists for WhatsApp messaging, leads captured by a chatbot or website form we manage, customer data held in a website we build, host or migrate, the servers, mailboxes, user directories and backups we administer for managed IT clients, or audience lists used for outreach. In those cases the client decides the purpose and is the Data Fiduciary; it is responsible for giving notice, obtaining any consent required and responding to your requests. We process that data only on the client’s documented instructions and our agreement with it, and we will pass any request you send us to the relevant client.
04Personal data we collect
We collect only what we need for the purposes set out in section 5. We do not ask for, and ask you not to send us, sensitive information such as financial account or card numbers, passwords, health information or government identity numbers, unless a specific task genuinely requires it and we have agreed a secure method with you.
| Category | Examples | Source |
|---|---|---|
| Identity and contact details | Name, business name, job title, email address, phone or WhatsApp number | You, or a colleague who introduces you |
| Enquiry and communication content | Messages sent through the contact form, emails, WhatsApp chats, call notes, files and screenshots you share | You |
| Business information | Website address, brand and competitor names, markets and services you want to be found for (for a free AI visibility report, audit or proposal) | You; public sources |
| Client engagement records | Proposals, approvals, instructions, deliverables, reports, support requests | You and our work with you |
| Billing and payment records | Billing name and address, GST details where provided, invoices, payment confirmations and the payer details that appear in them | You; your bank or payment provider |
| Account access | User roles or access you grant us to your website, analytics, business profiles, social, messaging or advertising accounts | You |
| Technical and security data | IP address, browser and device type, pages requested, date and time, and security events recorded in server and firewall logs | Automatically, when you use the website |
05Why we use it and our grounds for processing
We process personal data only for a lawful purpose and on a ground permitted by the DPDP Act – either your consent, or a legitimate use recognised by the Act (such as where you voluntarily give us data for a specific purpose and have not said you do not consent to its use, or where processing is needed to comply with law).
| Purpose | Ground |
|---|---|
| Replying to your enquiry and preparing a free report, audit or proposal you asked for | Legitimate use – data you voluntarily provided for that purpose; or consent |
| Delivering, managing and supporting the services you engage us for, and communicating about them | Legitimate use – data provided for that purpose; or consent |
| Invoicing, collecting payment and keeping accounting and tax records | Compliance with law; data provided for that purpose |
| Keeping the website secure, preventing misuse and fixing faults | Legitimate use, to the extent permitted by law; consent where required |
| Sending newsletters, offers or other marketing | Consent only – you can withdraw at any time |
| Responding to legal requests, enforcing our terms and protecting our legal rights | Compliance with law; legitimate uses permitted by law |
We will not use your personal data for a new purpose that is unrelated to the one for which you gave it without telling you and, where required, obtaining your consent.
06Consent and how to withdraw it
Where we rely on consent, it must be free, specific, informed, unconditional and unambiguous, and given by a clear action – for example, choosing to subscribe to updates. We will not make a service conditional on consent to processing that is not needed for that service.
You can withdraw consent at any time, as easily as you gave it: reply “STOP” to a WhatsApp message, use the unsubscribe link in an email, or write to support@y5media.com. Once you withdraw, we will stop the processing that relied on consent within a reasonable time, and ask any Data Processor acting for us to do the same, unless the law requires or permits us to keep the data. Withdrawal does not affect processing carried out before it.
If withdrawing consent means we can no longer provide something you asked for, we will tell you. Where the DPDP framework allows consent to be given, managed or withdrawn through a registered Consent Manager, you may also use that route once such a service is available.
07Contact form, email and WhatsApp
- Contact form. Our contact page form asks for your name, email address, an optional phone number and your message. Submitting it sends your message to our business email inbox so that we can reply. We do not currently store form submissions in the website’s database. Please do not include sensitive information in the form.
- Email. Emails to support@y5media.com are held by our email service provider and kept as described in section 15.
- WhatsApp and phone. WhatsApp is operated by a third party (WhatsApp / Meta) under its own terms and privacy policy. When you message us on WhatsApp, your number, profile name and messages are processed by that platform as well as by us.
- Confidential IT consultation form. Our Premium Managed IT Services page has a consultation form. It asks for your name, work email, company, optional phone number, the service you are interested in and a description of your needs, and asks for your agreement before you submit it. We use these details only to respond and to prepare any proposal you request. Please do not include passwords, credentials or confidential business data in any form on this website.
08Free AI visibility reports and AI tools
To prepare a free AI visibility report or an audit, we put questions about your business, market and competitors to third-party AI assistants and search engines (for example, ChatGPT, Gemini and Google) and record their answers. These questions are about businesses, not individuals: we do not enter your personal contact details into those tools. We may also use AI-assisted tools in delivering services, such as drafting content or analysing data; where this involves personal data, we limit it to what is necessary and use it only for the agreed purpose.
09Cookies and similar technologies
Cookies are small files stored by your browser. At the date of this policy:
- Essential and security cookies. The website uses cookies and similar technologies needed for it to function and to stay secure, including those set by our website platform and security firewall.
- Embedded content. Our contact page includes an embedded Google map. When that page loads, Google may receive your IP address and set its own cookies under Google’s privacy policy. Some fonts or other page resources may also be delivered by third-party providers, which receive your IP address in the process.
- No analytics or advertising cookies. We do not currently use third-party analytics, advertising or tracking cookies on this website. If we introduce them, we will update this policy first and, where the law requires, ask for your consent before they are set.
You can block or delete cookies in your browser settings. The website will still work, though some features (such as the embedded map) may not.
10Marketing communications
We send marketing messages – newsletters, offers or promotional updates – only with your consent. Service messages about an enquiry or engagement you started (such as a proposal, a report, an invoice or a support reply) are not marketing and are sent to fulfil your request. You can opt out of marketing at any time as described in section 6, and we will not share your contact details with others for their own marketing.
11Payment information
This website does not take online payments and does not collect card, UPI or bank account credentials. Fees are paid against our invoices using the payment details stated on the invoice. When you pay, we receive confirmation of the payment and the payer details that your bank or payment provider includes with it. We keep these records for accounting and tax purposes. If you ever receive a request to pay into an account that differs from the one on our invoice, please confirm with us by phone before paying.
12Sharing and disclosure
We do not sell or rent personal data. We share it only as follows, and only as much as is needed:
- Service providers who act as our Data Processors (see section 13);
- Publishing, media and distribution partners, only where a service you engaged us for requires it – for example, submitting a press release you approved, which may include the spokesperson or contact details you asked us to publish;
- Professional advisers, such as accountants, auditors and lawyers, under a duty of confidentiality;
- Government authorities, courts and law-enforcement agencies, where we are required to by law or to protect our legal rights;
- A successor business, if our business or part of it is transferred, subject to the protections in this policy.
White-label work is kept confidential: we do not publicly identify clients whose work we deliver on a white-label basis.
13Service providers (Data Processors)
We use carefully chosen service providers to run our business. Depending on the service, they may process personal data on our behalf in the following categories:
- website hosting, content management and website security (including a web application firewall);
- business email and cloud file storage;
- messaging and calling (including WhatsApp);
- accounting, invoicing and banking;
- tools used to deliver specific client services, such as publishing, distribution, automation and AI tools.
We engage them under contracts or terms that require them to process personal data only for the services they provide to us and to protect it with reasonable security safeguards. You can ask us for the names of the Data Fiduciaries and Data Processors with whom we have shared your personal data, as part of your right of access (section 18).
14Transfers outside India
Some of our service providers, or the servers they use, may be located outside India. Under the DPDP Act, personal data may be transferred outside India except to a country or territory that the Central Government restricts by notification. We will not transfer personal data to any restricted country or territory, and we choose providers that offer reasonable safeguards for the data they handle.
15How long we keep personal data
We keep personal data only for as long as it is needed for the purpose for which it was collected, or for longer where the law requires it. Then we erase it, or anonymise it so it no longer identifies you, and ask our Data Processors to do the same.
- Enquiries and free reports that do not lead to an engagement: generally no longer than 24 months after our last contact with you.
- Client engagement records: for the duration of the engagement and afterwards for as long as needed to deal with any questions or claims about it.
- Invoices and accounting records: for the periods required by Indian tax and accounting laws.
- Access to your accounts: removed when the engagement ends, and we confirm this in writing.
- Security and access logs: for as long as needed for security purposes and for any minimum period the law requires.
- Marketing consent records: for as long as we rely on the consent, and afterwards for as long as needed to show that consent was given or withdrawn.
Where the DPDP Rules require us to notify you before erasing data because you have not engaged with us for a prescribed period, we will do so.
16Security safeguards
We take reasonable security safeguards to protect personal data in our possession or under our control against a personal data breach. These include encrypted (HTTPS) connections to this website, a web application firewall and login protection, access limited to people who need it, account-level access (rather than shared passwords) for client platforms wherever possible, and keeping software up to date. We also require our Data Processors to take reasonable safeguards.
No website, transmission or storage system is completely secure, so we cannot guarantee absolute security. Please help by keeping your own passwords private and by never sending passwords or sensitive data by ordinary email or chat.
How we handle client systems and information under our managed IT services is described in our Data Protection and Confidentiality Commitment.
17Personal data breaches
If we become aware of a personal data breach affecting personal data for which we are the Data Fiduciary, we will act promptly to contain it, assess its impact and reduce any harm. Where the DPDP Act and Rules require it, we will inform affected Data Principals without undue delay – describing what happened, the likely consequences, what we are doing about it, the steps you can take to protect yourself, and who to contact – and we will report the breach to the Data Protection Board of India within the prescribed time. If a breach affects data we process for a client, we will inform that client without undue delay so it can meet its own obligations.
18Your rights
Subject to the DPDP Act and Rules and the dates on which the relevant provisions apply, you have the right to:
- Access – obtain a summary of the personal data we process about you and the processing activities, and the identities of the other Data Fiduciaries and Data Processors with whom we have shared it, with a description of what was shared;
- Correction, completion and updating of inaccurate, incomplete or outdated personal data;
- Erasure of personal data that is no longer needed for the purpose for which it was processed, unless we must keep it to comply with law;
- Withdraw consent where we rely on consent (section 6);
- Grievance redressal – have a complaint about our handling of your personal data addressed by us (section 24);
- Nominate another individual to exercise your rights if you die or become incapable of doing so.
If we process your data only as a Data Processor for a client (section 3), please direct your request to that client; if you send it to us, we will forward it.
19How to make a request
- Email support@y5media.com with the subject line “Personal data request”, saying which right you want to exercise. You can also contact us on WhatsApp and we will confirm the request by email.
- We may ask for information to verify your identity (or the authority of anyone acting for you). We will ask only for what is necessary and use it only to handle your request.
- We aim to acknowledge requests within two working days and to resolve them within 30 days. Where a request is complex, we will explain why and when to expect a response, and in any event we will respond within the period prescribed under the DPDP Rules.
There is no charge for making a request. If we cannot fully act on a request – for example, because the law requires us to keep certain records – we will tell you why.
20Your duties as a Data Principal
The DPDP Act also sets out duties for Data Principals. When you share personal data with us or exercise your rights, please provide information that is accurate and authentic, do not impersonate another person, do not suppress material information when providing personal data for an official document or identifier, and do not file false or frivolous complaints.
21Children and persons with disabilities
Our website and services are intended for businesses and adults. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has sent us personal data, contact us and we will delete it.
If a service we provide for a client requires processing the personal data of children (for example, for an educational institution), the client, as Data Fiduciary, is responsible for obtaining verifiable consent from a parent or lawful guardian where the law requires it, and we process that data only on the client’s instructions. The same applies to persons with disabilities who have a lawful guardian.
22Significant Data Fiduciary status
The DPDP Act allows the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries, with additional obligations such as appointing a Data Protection Officer and carrying out periodic audits. Y5MEDIA has not been notified as a Significant Data Fiduciary, so those additional obligations do not currently apply to us. If that changes, we will update this policy.
23Third-party websites and platforms
This website links to, and our services use, third-party websites and platforms – for example WhatsApp, Google, social networks, AI assistants, media portals and client websites. Their own privacy policies apply to them, and we are not responsible for their practices. Please read their policies before sharing personal data with them.
24Grievance Officer and contact
For any question, request or complaint about this policy or our handling of personal data, please contact our Grievance Officer:
Y5MEDIA (Raymond Cardoza Enterprises)
C/o 2-439, R. R. Cardoza House, Near Petrol Pump, Bajpe,
Mangaluru, Karnataka – 574142, India
Email: support@y5media.com (subject: “Grievance” or “Personal data request”)
Phone: +91 7902024242 · WhatsApp: +91 7902024242
Hours: Monday to Saturday, 9:30 AM – 6:30 PM IST
We aim to acknowledge grievances within two working days and resolve them within 30 days, and in any event within the period prescribed under the DPDP Rules. If you are not satisfied with our response, once the relevant provisions are in force you may complain to the Data Protection Board of India, after first using our grievance process as the DPDP Act requires.
25Changes to this policy
We may update this policy to reflect changes in our services, our service providers or the law. The “Last updated” date at the top shows when it last changed. If we make a significant change, we will highlight it on this page and, where the law requires or it is otherwise appropriate, notify you directly or seek fresh consent.
Questions about your data?
Write to our Grievance Officer and a real person will reply – usually within two working days.
