Source revision:
This document separates verified website behavior from decisions that still require the responsible business owner and qualified legal adviser. It remains noindex and outside the XML sitemap.This factual review draft is not legal advice or an approved final policy. It records the approved controller name, owner-confirmed correspondence address, and current website workflows while keeping remaining provider, retention, transfer, and legal details visible as publication gates.
- Review the owner-confirmed correspondence address and any remaining identity requirements under the applicable regime; no registered-office status or jurisdiction is inferred.
- Confirm whether the EU GDPR, UK GDPR, or another data-protection regime applies to each relevant activity.
- Approve the lawful basis for each processing purpose before claiming that basis publicly.
- Complete the production hosting, email, security, Google Sheets, analytics, and other provider inventory, including access arrangements, processing locations, and any international-transfer mechanism.
- Establish the proposed six-month inactive-enquiry review coordinated by Anujeet, document separate client-record retention rules, and reconcile the source-defined operational-log expiry with production behavior.
- Obtain qualified legal review and approve the effective date before treating this draft as final.
Status and scope
This page applies only to personal data connected with the current Simpleweb.in website, direct project enquiries, and related business communication where an applicable GDPR regime governs the processing.
It does not claim that every visitor, enquiry, project, or business activity is governed by the EU GDPR or UK GDPR. Applicability depends on the people, location, offering, activity, and legal context involved.
The broader Privacy Policy describes the general website and project-data framework. This page focuses on GDPR-related transparency, rights, and the decisions that still require approval.
Controller identity and contact
AIDB Marketing Services operates the Simpleweb brand and is the controller for the personal data described in this notice. Privacy and GDPR-related requests may be sent to hello@simpleweb.in.
Simpleweb is the approved public operating name and https://simpleweb.in is the approved public website. The owner-confirmed business correspondence address is AIDB Marketing Services, S-531A, First Floor, Shakarpur, Laxmi Nagar, Delhi 110092. No registered-office status or legal jurisdiction is inferred from this address.
Privacy and GDPR-related questions can be sent to hello@simpleweb.in and are handled by Anujeet, following the owner's updated confirmation. This identifies the privacy-request handler, not a data-protection officer or billing representative. Deepak remains the enquiry contact. A request should identify the relevant enquiry or project without including unnecessary personal data.
Personal data covered
Personal data may be provided through the homepage project-enquiry form, email, phone, WhatsApp, or communication during a potential or active project. This can include contact details, organization details, message content, project requirements, correspondence, approvals, and files supplied by that person.
The owner confirms that enquiries are recorded in Google Sheets. This draft does not establish an automated website-to-Sheets integration, sharing or access settings, storage region, or deletion workflow.
Technical infrastructure may also process connection and security data needed to deliver and protect the website or email service. The production provider inventory and exact log fields must be verified before final approval.
Simpleweb does not intentionally request special-category personal data through the public website. A person should not send health, biometric, financial-account, government-identifier, or similarly sensitive information unless it is necessary, approved, and protected through an appropriate project process.
Purposes and lawful basis
Information received through the enquiry form and contact channels may be used to answer the enquiry, assess a proposed project, prepare a scope or proposal, administer an agreed engagement, maintain necessary business records, protect systems, and respond to legal or rights requests. Google Sheets is used for enquiry recordkeeping and follow-up; optional analytics is a separate website-measurement workflow.
The technical requirement for analytics permission is described above. That mechanism alone does not establish a complete GDPR lawful-basis assessment. The responsible controller must review the appropriate basis for each relevant processing purpose before treating this draft as final; no basis is assigned to all enquiry, project, security, or recordkeeping activity by this draft.
No public marketing-subscription workflow or automated profiling workflow is established by this draft. Landing contact-click measurement is optional and consent-based, separate from enquiry handling. Any added or changed measurement, marketing, recordkeeping, or form workflow must be reviewed for its actual purpose, data flow, retention, notice, and applicable consent or other requirements.
Processors and international transfers
The current workflows include Google Sheets enquiry recordkeeping, optional Google Analytics 4, website hosting and form protection, and email, phone, and WhatsApp communication. Service roles must be assessed for the actual activity rather than assuming that every named provider acts in the same capacity.
The named services are not a complete approved provider inventory. The mail-provider identity, account access and sharing arrangements, processing locations, sub-processors, contractual arrangements, and any relevant transfer safeguards remain to be confirmed. No storage region or international-transfer mechanism is inferred from this draft.
Portfolio links and a user-initiated live preview can open or load another website. That destination may receive standard connection data and is governed by its own privacy information.
Retention and security
Personal data should be kept only for as long as needed for the approved purpose, project administration, security, dispute handling, accounting, or another applicable legal requirement.
Existing Google Analytics event-level retention is configured for 14 months. Separately, the website source defines a 30-day time-to-live for operational log records. This source-defined setting does not verify live expiry or determine the retention of other provider logs, messages, or client records.
Anujeet coordinates the proposed six-month review of inactive enquiries. It is not an established or enforced process, automatic deletion, or a maximum retention promise. It does not promise deletion of Google Sheets rows, emails, WhatsApp messages, backups, or client records after six months.
The review trigger, treatment of follow-up activity, review outcomes, and retention and deletion decisions for client records and other copies remain to be documented. Those records may require different decisions for project administration, accounting, security, disputes, or applicable obligations.
Reasonable administrative and technical safeguards should reflect the data, systems, access, providers, and project risk. No website or transmission method can be represented as completely secure, and this page does not claim a certification, audit result, or absolute protection.
Rights under an applicable GDPR regime
Where an applicable GDPR regime grants the right and its conditions are met, a person may ask for information about processing and exercise relevant data-subject rights.
These rights are not absolute. Identity verification, the rights and freedoms of other people, legal claims, contractual records, security needs, and applicable exemptions may affect the response.
- Be informed about how personal data is processed.
- Request access to personal data.
- Request correction of inaccurate or incomplete data.
- Request erasure in circumstances where the right applies.
- Request restriction of processing in relevant circumstances.
- Object to certain processing, including direct marketing.
- Request data portability where the legal conditions apply.
- Withdraw consent for future processing where consent is the relied-upon basis.
- Ask not to be subject to a decision based solely on automated processing where the applicable right exists.
Rights requests and complaints
Send a GDPR-related request to hello@simpleweb.in, where Anujeet handles privacy requests for AIDB Marketing Services, operating the Simpleweb brand. Include enough context to identify the relevant communication or project. Do not send additional identity documents unless they are requested through an appropriate verification process.
Simpleweb may need to verify identity, clarify the request, search relevant records, protect information about other people, and preserve records required by law or an active agreement.
A valid request should be handled within the period required by the applicable law. A person may also have the right to complain to the competent data-protection supervisory authority for their circumstances.
Automated decisions and children
The inspected website source does not select a workflow that makes decisions producing legal or similarly significant effects solely through automated processing.
Simpleweb.in is directed to businesses and professional project enquiries. It is not designed as a service for children, and the public website does not intentionally request children's personal data.
If either statement changes, the relevant notice, safeguards, consent or authorization requirements, and rights process must be reviewed before the new workflow is released.
Policy updates
This page should be reviewed whenever the website adds or changes a form endpoint, analytics or advertising technology, CRM, email workflow, hosting provider, content-delivery dependency, project tool, retention rule, transfer arrangement, or rights-request process.
A final version must state an approved effective date and reflect the actual production system. Material changes should be published before the affected processing begins where applicable.
The July 16, 2026 source revision date records this page's earlier source history. These September 17, 2026 factual updates are not an approved effective date. Analytics descriptions must remain consistent with deployed consent-based behavior, and the six-month inactive-enquiry review remains proposed until established.