Skip to content
Gurasis Media

Legal

Privacy Policy

What we collect when you visit this site or send us an enquiry, why we collect it, who else handles it, and how to see, correct or delete it.

Effective Last updated

The short version

  • We collect what you type into our enquiry forms so we can reply, plus which page you sent it from and which site sent you to us.
  • The public site sets no cookies and runs no advertising pixels. We count page views ourselves, without cookies.
  • We do not sell your details, and we do not add you to a mailing list.
  • Our database is in Mumbai, India. Our website host handles form submissions in the United States, and a copy of each enquiry goes to our automation server in Malaysia, which can message you about it.
  • To see, correct or delete your details, use our contact form or a message to @gurasis_media on Instagram (opens in a new tab). We reply within 30 days.

Who we are

Gurasis Media is a marketing, AI, software and creative studio run by Gurasis Singh and based in Amritsar, Punjab, India. We work with businesses in India and Canada.

In this policy, “we”, “us” and “our” mean Gurasis Media, and “you” means anyone who visits gurasismedia.com or sends us an enquiry through it. The policy covers this website and those enquiries. It does not cover the websites, ads or systems we build for our clients: each client is responsible for its own.

For any privacy question, use our contact form or a message to @gurasis_media on Instagram (opens in a new tab). The person who answers is named under Who to contact about privacy.

What we collect

When you send an enquiry

The site has two enquiry forms: one on our contact page and one on our Canada page. They ask for:

  • Contact page: your name, email address and message (required), your business name (optional), and which of our four services it is about: marketing, AI automation, software or creative.
  • Canada page: your name and email address (required), your phone number (optional), which service you need help with, and a message (optional).

Along with what you type, we save:

  • which form you used;
  • the page the form was on, such as /contact. We save just the page, not anything added to the end of its link;
  • the referring site: the one that sent you to us, as your browser reports it. This is usually just its address, such as google.com. If you came from another page of our own site, it can be that page’s full link. If your browser reports nothing, we save the full link of our form page instead. A full link can include tracking tags that an ad or a shared link added to it, like the ones Facebook adds;
  • the date and time.

After that, we may add a status (new, contacted, qualified, won or lost) and our own notes about the conversation.

You do not have to give us anything. The required fields are the minimum we need to reply; without them we cannot answer your enquiry. Leave out anything else you would rather not share.

When you browse the site

Pages on the main site send one small record to our own server each time you open a page. It holds:

  • the page, such as /work, without anything added to the end of its link;
  • the referring site, as your browser reports it (usually just its address, such as google.com);
  • a random ID that groups the pages viewed in one visit. Your browser makes it up, keeps it in that tab only and deletes it when you close the tab. It is not a cookie, and on its own it does not identify you;
  • which article or case study, if the page is one;
  • the date and time.

These records do not include your IP address, your browser details or your location. The Canada page does not send them.

When an enquiry is sent, we also save a separate “enquiry sent” record with the page, the referring site, the form and the service you picked. It contains no name, contact details or message, and it is not linked to your enquiry.

What our hosting provider sees

Like every website, ours runs on servers that see your IP address, your browser’s user agent (the text that names your browser and operating system) and the page you asked for whenever a page loads. Our host, Vercel, uses this to deliver the site and may keep it in request logs for a limited time under its own policies.

Our own code uses your IP address only to limit repeated form submissions and page-view records. It turns the address into a scrambled code and keeps that code only in the server’s memory. We never save your IP address, the code made from it or your user agent in our own database.

Messages, emails and calls

If we carry on the conversation by email, phone, Instagram, Facebook Messenger or WhatsApp, we keep those messages for as long as the conversation needs them (see How long we keep your details). They are also held by the email and messaging services involved.

Cookies and browser storage

The public website does not set any cookies.

It stores one item in your browser: the random visit ID described above, under the name gm_sid. It is kept in that tab only and deleted when you close the tab. If your browser blocks storage, the site still works and the page view is counted without it.

If an article includes an embedded YouTube or Vimeo video, that player may set its own cookies or similar storage when it loads (see Links to other sites).

The admin area, which only we use, sets a sign-in cookie when we sign in. Visitors never receive it.

What we don't do

  • Advertising pixels or outside analytics. There is no Meta Pixel, no Google Analytics, no Google Ads tag and no other advertising or retargeting tracker. We run our own ads on Meta, but this site sends Meta nothing about your visit.
  • Session recordings, heatmaps or browser fingerprinting.
  • Loading content from other companies. Everything on our pages, fonts and images included, loads from our own site, not from Google Fonts or any other outside service. The exceptions are our host, Vercel, which delivers every page, and any video embedded in an article.
  • Storing your IP address. We do not keep it in our own database in any form.
  • Posting your details. Our automation publishes posts to our social media accounts, but never your enquiry or anything you sent us.
  • Asking for sensitive information. We never ask for passwords, bank or card details, health information, biometrics or anything similar. Please do not put any of that in a message.

We do not sell or rent your details, and we do not share them with anyone for their own marketing.

How we use your details

We use your details to:

  • reply to your enquiry and talk with you about the marketing, AI automation, software or creative work you asked about, including preparing a proposal or a quote;
  • carry on that conversation by email, or by phone, WhatsApp or Instagram if you prefer it. Our automation tool may send some of these messages for us, such as a note that your enquiry arrived or a follow-up if we have not heard back;
  • keep a record of each enquiry: its status, our notes, and which form, page and referring site it came from, so we know which pages and channels bring enquiries;
  • keep the site working and safe: limit repeated submissions, catch spam with a hidden form field, and protect the database;
  • count page views, so we know which pages and articles people read.

We do not use your details for anything else. Whether we work together is always decided by us, not by the automation.

Why we’re allowed to use them

Indian and Canadian privacy law both treat sending the form as agreeing to the uses described here. You can take that back at any time (see Your rights). Counting page views and protecting the forms are part of running a website safely, and neither is used to build a profile of you.

The laws behind this: in India, section 43A of the Information Technology Act, 2000 and the IT Rules, 2011, which apply today. When the main parts of the Digital Personal Data Protection Act, 2023 come into force (expected from May 2027), we will rely on section 7(a) of that Act: you gave us your details yourself, for a specific purpose. In Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA).

Who else handles your details

A small number of service providers run parts of the site for us. They handle your details on our behalf and only for the purposes above.

Supabase
Our database. Stores enquiries and page-view records.
Where: Mumbai, India
Vercel
Hosts the website and runs the code that receives the forms and page-view records. Sees your IP address and browser details whenever a page loads.
Where: United States. Forms and page-view records are processed in Washington, D.C.; pages are delivered from the Vercel location nearest you.
n8n
Our automation tool, which also runs our social media posts and messages. It receives a copy of each enquiry (your name, email, business, phone, service and message, the form, page and referring site, and the time) so it can alert us and send you messages about your enquiry. It runs on a server we rent from Hostinger.
Where: Kuala Lumpur, Malaysia
Meta
Carries the messages we or our automation exchange with you on Instagram, Facebook Messenger or WhatsApp, if we talk there.
Where: Meta's data centres, including in the United States

If we email you, the email services on both ends hold those emails. If we talk by phone, your phone company carries the call.

Apart from these, we share your details only where the law requires it, for example a lawful request from a government agency or a court order.

Where your details are processed

We work from India, and your enquiry is stored in our database in Mumbai, India. On the way there it passes through Vercel’s servers in the United States, and a copy goes to our automation tool (n8n) on a server in Kuala Lumpur, Malaysia. Messages on Instagram, Facebook Messenger or WhatsApp pass through Meta, including in the United States.

So if you are in Canada, including Quebec, your details leave Canada. They are handled in India, the United States and Malaysia. If you are in India, they are processed in the United States and Malaysia as well as in India.

While your details are in another country, that country’s laws apply to them, and its courts, police and national security authorities may be able to access them.

We remain responsible for your details while our providers handle them, and we use established providers that publish their own security and data protection commitments.

How long we keep your details

  • Enquiries, and the emails and messages about them: up to 24 months after our last contact with you, then deleted. If you become a client, we keep them with your client records for as long as we work together, and afterwards for as long as tax and accounting law requires.
  • Page-view and “enquiry sent” records: up to 24 months, then deleted.

If you ask us to delete your details sooner, we will, unless the law requires us to keep them. Deleted data can remain in our database provider’s backups for a short time, until those backups are replaced. Vercel keeps its request logs for the period its own policy sets.

How we keep your details safe

  • The whole site is served over HTTPS only, so what you send is encrypted on its way to us.
  • In our database, only an administrator signed in to our admin area can read enquiries. The database itself enforces this: the public website can add an enquiry but cannot read one back.
  • The admin area needs an email address and password, plus an administrator role that only we can grant.
  • Every copy of an enquiry sent to our automation tool carries a secret key, so the tool can reject anything that did not come from our site.
  • A hidden form field and a limit on repeated submissions help keep spam out of the forms.

No system is perfectly secure. If a breach affects your details, we will tell you, and the authorities, as the law requires.

Your rights

Wherever you are, you can ask us to:

  • show you the details we hold about you and how we use them;
  • correct, complete or update them;
  • delete them;
  • stop using them, by withdrawing your consent.

If you withdraw consent, we stop using your details and delete them within 30 days, unless the law requires us to keep them, and we ask our service providers to do the same. That does not undo what we did before, and it means we can no longer continue the conversation about your enquiry. You can also refuse to give us information in the first place; we just cannot reply without a name and an email address.

In India

Under the IT Rules, 2011, which apply today, you can review and correct the information you gave us, and have a grievance resolved by our Grievance Officer.

The Digital Personal Data Protection Act, 2023 will add further rights once its main parts come into force, expected from May 2027. We already offer them now. You can:

  • get a summary of your details and of what we do with them, with a list of every organisation we have shared them with;
  • nominate someone to use these rights for you if you die or become unable to act yourself.

Once those parts of the Act are in force, you can also complain to the Data Protection Board of India if our Grievance Officer does not resolve your grievance. The Act asks you to use our grievance process first.

In Canada

Under PIPEDA, you can ask for access to your personal information and have it corrected. If you are not satisfied with how we handle a request or a complaint, you can complain to the Office of the Privacy Commissioner of Canada (opens in a new tab).

If you live in Quebec, you can also ask for a copy of your information in a common file format, such as a spreadsheet. Our person in charge of the protection of personal information is named under Who to contact about privacy. If we refuse a request or do not resolve a complaint, you can go to the Commission d’accès à l’information du Québec (opens in a new tab).

In the EU and UK

Our services are aimed at businesses in India and Canada. If you are in the European Union or the United Kingdom, your local law may give you further rights, such as to restrict or object to how we use your details or to receive a copy of them, and you can complain to the data protection authority in your country. Contact us and we will help.

Where those laws apply, we use your details to do what you asked (reply to your enquiry), and because we have a legitimate interest in running a secure website.

How to make a request

Send us a request through our contact form or a message to @gurasis_media on Instagram (opens in a new tab). Start with “Privacy request” and tell us what you want:

  • a copy of your details;
  • a correction;
  • deletion;
  • for us to stop using your details;
  • to make a complaint;
  • to name someone who can act for you (tell us their name and how to reach them).

One line is enough, and it costs nothing.

Give the same email address you used in your enquiry: that is how we find your details. If you contact us some other way, we may ask you to confirm the request from that address, only so that we never hand your details to someone else.

We reply within 30 days of receiving your request. For a Canadian request, if we need longer, we tell you within those 30 days and explain why. We also remind you that you can complain to the Privacy Commissioner. We never take more than 30 extra days.

Who to contact about privacy

One person is responsible for how we handle your details, and answers every privacy question, request and complaint:

Name
Gurasis Singh
Title
Founder, Gurasis Media
Contact
Use our contact form or a message to @gurasis_media on Instagram (opens in a new tab)
Based in
Amritsar, Punjab, India

Gurasis Singh is our Grievance Officer under Indian law, and the person responsible for privacy under Canadian and Quebec law.

To make a complaint, contact us the same way and say what went wrong. Gurasis Singh looks into it and replies with the outcome and anything we have changed. We resolve grievances within one month of receiving them. If you are not satisfied, you can go to the regulator for where you live, listed under Your rights.

Children

This site and our services are for businesses. They are not directed at anyone under 18, which is how India’s Digital Personal Data Protection Act defines a child, and we do not knowingly collect children’s details. If you believe someone under 18 has sent us their details, contact us and we will delete them.

Marketing messages

We only contact you about your enquiry. Some of those messages may come from our automation, such as a note that your enquiry arrived or a follow-up if we have not heard back. Tell us to stop at any time and we will.

We have no newsletter or mailing list, and we will not add you to any list or broadcast.

If that ever changes, we will ask for your permission first, separately from the enquiry form. Every marketing message would then say who sent it and give you a simple way to stop them, which we would act on within 10 business days.

Links to other sites

Our site links to other websites: our Instagram (opens in a new tab) (@gurasis_media), our founder’s Instagram, LinkedIn, X and GitHub profiles and personal site, and the websites of clients in our case studies. These are plain links, not embedded widgets, so those sites learn nothing from your visit to ours unless you click through. Once you do, their own privacy policies apply.

An article may include an embedded YouTube or Vimeo video. When one does, the player loads from YouTube’s privacy-enhanced service or from Vimeo as you reach it, and that service’s privacy policy applies to it.

Changes to this policy

When we change how we handle your details, we update this page and the “last updated” date at the top. Before we switch on any new analytics or advertising tool, or start collecting anything new, we update this policy first. If a change materially affects details we already hold about you, we will tell you directly, where we still have your contact details.