
Compliance & Data Protection Summary
Document Version 1.0 | September 2026
1. Company Information
Legal Entity
Continex Tradeline India Private Limited
Brand Name
BrandStage
GST Number
33AADCC0301L1Z9
TIN
33061522910
Registered Address
Primus Building, No. SP-7A, 1st Floor, Guindy Industrial Estate, Chennai - 600032, India
2. Regulatory Compliance Status
| Regulation | Applicability | Status |
|---|---|---|
| India DPDP Act 2023 | Primary - Indian Operations | Framework Implemented |
| IT Act 2000 (India) | Primary - Indian Operations | Framework Implemented |
| GDPR (EU) | If serving EU customers | Applicable Where Relevant |
| PCI-DSS | Payment Processing | Via Razorpay |
| GST Compliance | Tax Compliance | Registered |
3. Data Collection & Processing
| Data Category | Data Fields | Purpose | Legal Basis |
|---|---|---|---|
| Account Data | Name, Email, Password (hashed), Phone, Country | Account management, Authentication | Contract performance |
| Company Profile | Company name, Address, Website, Social links, Logo | Profile creation, Public display | Consent |
| Video Content | Recorded videos, Testimonials | Service delivery, Profile enhancement | Consent |
| Payment Data | Transaction IDs only (card data via Razorpay) | Payment processing, Invoicing | Contract performance |
| Lead Data | Name, Email, Company, Message | Sales inquiries, Marketing | Legitimate interest |
4. Third-Party Service Providers
| Service | Provider | Data Location | Purpose |
|---|---|---|---|
| Video & Image Storage | Cloudinary | US / EU | Media storage & delivery |
| Database | MongoDB Atlas | Multi-region | Data storage |
| Payment Processing | Razorpay | India | Payment gateway (PCI-DSS certified) |
| Email Services | Resend | US | Transactional emails |
| AI Services | OpenAI | US | Content generation (opt-in) |
5. Data Subject Rights & Mechanisms
Right to Access
Users can view all their data in dashboard
Right to Rectification
Users can edit profile data anytime
Right to Erasure
"Delete Account" button in dashboard
Right to Data Portability
Export data via support request
Right to Withdraw Consent
Cookie banner + account deletion
Right to Lodge Complaint
Grievance officer appointed
6. Security Measures
BrandStage implements industry-standard security controls to protect your data:
- ✓Encryption: All data encrypted in transit and at rest using industry-standard protocols
- ✓Authentication: Secure password storage and session management
- ✓Access Control: Role-based permissions with least-privilege principles
- ✓Payment Security: No card data stored; payments processed by PCI-DSS certified providers
- ✓Monitoring: Security logging and incident detection in place
- ✓Assessments: Regular security reviews and vulnerability assessments
Detailed security controls documentation available upon request for enterprise customers.
7. Data Retention Schedule
We retain data only as long as necessary for the stated purpose or legal requirement:
| Data Type | Retention Period | Justification |
|---|---|---|
| Active account data | Duration of account | Service delivery |
| Deleted account metadata | 90 days post-deletion | Support queries, abuse prevention, accidental deletion recovery |
| Profile content (on deletion) | 30 days grace period, then purged | Recovery window for accidental deletion |
| Video content (on deletion) | Immediate removal from public, purged within 7 days | CDN cache propagation |
| Raw recordings / Retakes | 7 days after final publish | Quality assurance, re-processing if needed |
| Failed uploads | 24 hours | Temporary processing only |
| Testimonial recordings | Until removed by profile owner or contributor | Contributor consent-based |
| Lead/Enquiry data | 2 years from submission | Sales cycle, follow-up (consent-based marketing separate) |
| Payment/Invoice records | 7 years | Tax compliance, legal requirement |
| Security/Application logs | 180 days rolling | Regulatory requirement (CERT-In) |
| Verification documents | Duration of verified status + 1 year | Audit trail, dispute resolution |
Users may request earlier deletion of their data by contacting operations@brandstage-media.com. Certain data may be retained longer where required by law.
8. Cookie & Analytics Inventory
| Cookie/Tracker | Type | Purpose | Duration |
|---|---|---|---|
| access_token | Essential | User authentication session | 7 days |
| cookie_consent | Essential | Remember consent preferences | 1 year |
| Cloudinary | Functional | Video/image delivery optimization | Session |
| YouTube Embeds | Third-Party | Embedded video playback | Varies (Google policy) |
| Razorpay | Functional | Payment processing (on checkout) | Session |
Note: No advertising or marketing trackers are used. Analytics are server-side only.
9. Product-Specific Disclaimers
AI-Assisted Content
"AI-assisted content is generated from information supplied by the profile owner and/or authorised sources. The profile owner is responsible for reviewing and approving its accuracy before publication. AI-generated content is clearly labelled."
BrandStage Verified Badge
"BrandStage verification establishes specified identity, organisation association and/or content provenance checks. It does not constitute an endorsement, credit assessment, certification of capability, or guarantee of products or services."
Digital Health Score (Pro)
"The BrandStage Digital Health Score is an indicative assessment based on defined digital-presence criteria and available information. It is not an SEO guarantee, credit rating, certification, or assurance of commercial performance. Scores are for guidance only."
Video Testimonials & Contributor Consent
"Testimonials represent the personal views and experiences of the contributor at the time of recording. BrandStage does not independently verify or warrant the claims made. All testimonial contributors provide explicit consent before recording, including acknowledgment that their video may be displayed on the profile owner's public profile. Contributors may request removal of their testimonial by contacting operations@brandstage-media.com."
BrandStage Connect
"Opportunities and introductions on BrandStage Connect are provided for business discovery purposes only. When contact information is shared between participants, both parties acknowledge that BrandStage acts solely as a facilitator. Publication or introduction does not constitute endorsement, due diligence, credit assessment, or assurance of commercial suitability. Participants must undertake their own legal, financial, and commercial assessment before entering into any transaction or agreement."
Profile Owner Content Warranty
"By publishing a profile on BrandStage, the profile owner warrants and represents that: (a) all information and media submitted are accurate to the best of their knowledge; (b) they have obtained all necessary rights, permissions, and consents to publish the content; (c) the content does not infringe any third-party intellectual property, privacy, or other rights; (d) they will promptly update or remove any content that becomes inaccurate or for which rights have been withdrawn. The profile owner assumes full responsibility for all content published under their profile."
10. CERT-In Cybersecurity Compliance
BrandStage maintains compliance with CERT-In Section 70B Directions (April 2022) for cybersecurity incident reporting and log management.
Incident Reporting
Qualifying cyber incidents reported to CERT-In within statutory timelines as required by law.
Log Management
ICT system logs maintained for 180 days with time synchronisation as per regulatory requirements.
Access Controls
Role-based access with least-privilege principles. Security controls continuously improved.
Security Assessments
Regular security reviews conducted. VAPT audits planned for enterprise scale.
CERT-In Point of Contact
Operations & Compliance Team
Email: operations@brandstage-media.com
11. Frequently Asked Questions
Common questions about how we handle your data
Q: Where is my data stored?
A: Data is stored in secure cloud infrastructure with encryption at rest and in transit. Media content is stored via Cloudinary's global CDN.
Q: Is AI used to generate content?
A: Yes, AI assists in generating profile narratives from information you provide. You review and approve all content before publication. AI-generated content is clearly labelled.
Q: What cookies does the site use?
A: Essential cookies only for authentication and consent preferences. No advertising or marketing trackers. Third-party cookies from YouTube embeds and payment processing only.
Q: Can I delete my data?
A: Yes. You can delete individual videos, testimonials, and your entire account from the Dashboard. Account deletion removes your data per our retention schedule.
Q: How are testimonial contributors protected?
A: Contributors must provide explicit consent before recording. They can request removal of their testimonial at any time by contacting us.
Q: Who can I contact with data protection questions?
A: Contact our Operations & Compliance team at operations@brandstage-media.com. We respond to all data protection enquiries within 30 days.
12. Grievance & Incident Handling
Different categories of concerns are handled through appropriate channels:
Privacy & Data Protection Concerns
Data access requests, correction, deletion, consent withdrawal under DPDP Act / GDPR
Email: operations@brandstage-media.com
Response: Within 30 days as per statutory requirement
Content, Copyright & IP Issues
Takedown requests, intellectual property claims, content disputes
Email: operations@brandstage-media.com
Response: Acknowledgment within 48 hours; Resolution within 15 days
Security Incidents & Vulnerabilities
Suspected breaches, account compromises, vulnerability reports
Email: operations@brandstage-media.com
Response: Immediate triage; Escalation per incident severity
Grievance Officer (DPDP Act 2023)
Continex Tradeline India Private Limited
Primus Building, No. SP-7A, 1st Floor, Guindy Industrial Estate
Chennai - 600032, Tamil Nadu, India
Email: operations@brandstage-media.com
Statutory Resolution: Within 30 days
Data Breach Notification Policy
In the event of a data breach affecting personal data:
- • Statutory Reporting: CERT-In notified within 6 hours for qualifying cyber incidents
- • Data Protection Authority: Notified as required under applicable law
- • User Notification: Affected individuals notified within 72 hours where required
13. Published Legal Documents
- Terms of Service: brandstage-media.com/terms
- Privacy Policy: brandstage-media.com/privacy
- Cookie Policy: brandstage-media.com/cookies
- Video Guidelines: brandstage-media.com/video-guidelines
This document is for internal reference and legal review purposes.
Last updated: September 2026 | Document version: 1.0