Data Privacy & Security Policy
How Maximum Solution India collects, uses, protects, and manages client data across Website Development, Digital Marketing, Google Ads, Meta Ads, and SEO services.
Table of Contents
1. Data We Collect
Data ControlsWe collect only the essential data required to perform contracted web development, marketing, and business account management services:
- Business Information Company name, GST/registration numbers, physical office address, billing contacts, and authorized team designations.
- Personal Contact Info (PII) Contact names, business email addresses, direct phone numbers, and WhatsApp communication details.
- Technical Assets Website domain credentials, hosting server details, DNS records, Google Analytics tags, ad account IDs, and e-commerce platform access permissions.
- Communication Records Inquiry form submissions, project scope briefs, technical emails, WhatsApp discussions, and support requests.
Zero Unnecessary Data Collection: We do not store payment card numbers, banking PINs, or personal government IDs unless explicitly required for formal domain/account registrations authorized by you.
2. How We Use Your Data
All data collected is strictly used for fulfilling contracted business services, including:
- Building, deploying, and maintaining custom corporate websites and e-commerce platforms
- Configuring and optimizing performance ad campaigns across Google Ads and Meta Ads
- Integrating conversion tracking tags, Google Analytics 4, and lead generation routing
- Managing local search engine optimization (SEO) and business profile visibility
- Providing technical client support, performance reporting, and strategy consultations
We do NOT sell, rent, trade, or monetize your business or personal data under any circumstances.
3. Data Retention & Deletion
Retention Schedules- Active Services Client project files, analytics configurations, and contact PII are maintained for the active duration of the contract engagement.
- Post-Contract Deletion Upon written contract completion or termination, technical passwords and administrative access credentials are permanently purged within 30 days.
- Legal Tax Invoices Essential financial accounting records and tax receipts are retained for up to 90 days as mandated by Indian tax regulations.
- Automated Backups Encrypted server backup archives follow standard expiration schedules and are permanently erased within 30 days of deletion requests.
Clients may request immediate, written confirmation of data deletion by emailing info@maximumsolutionindia.com.
4. Credential Security & Access Controls
Access Protocol- AES-256 Encryption All client login credentials, API keys, and server passwords are encrypted using AES-256 password management software. Plaintext password storage is strictly forbidden.
- Role-Based Access Access to client website administrative panels or ad manager portals is restricted to team members directly assigned to your project.
- Delegated Invites Preferred Where supported (e.g. Google Tag Manager, Meta Business Manager, Search Console), we utilize delegated user invitations rather than requesting master logins.
- Monthly Audits Access permissions are audited monthly by our technical lead to ensure access rights remain current.
5. Technical Protection & Encryption
Security Standard- Encryption in Transit All website communications and data transfers are protected via HTTPS / TLS 1.3 encryption.
- Encrypted Workstations All workstations used by our team are password-protected, encrypted at rest, and protected by endpoint security software.
- Private Networks Team members access client accounts strictly over secure private networks. Use of public Wi-Fi to access client systems is strictly prohibited.
6. Incident Response & Breach Protocol
- 24/7 Monitoring We monitor our systems for unauthorized access attempts or suspicious activity.
- 48-Hour Notification In the event of a confirmed security breach affecting client data, we notify impacted clients via email within 48 hours with actionable details.
- Immediate Isolation Compromised credentials and access tokens are immediately revoked and rotated to prevent breach expansion.
7. Third-Party Sharing & Integrations
Data is shared only with essential infrastructure providers required for project delivery, including:
- Web hosting infrastructure (Hostinger, AWS, Vercel)
- Domain registrars and SSL certificate providers
- Analytics & ad networks (Google Ads, Meta Ads, Google Analytics)
- WhatsApp Business API tools (where requested for direct lead routing)
8. Client Rights & Privacy Contact
Clients maintain full rights over their data, including the right to inspect, update, export, or request deletion of their records.
To exercise any privacy rights, reach out to our team:
Questions About Our Privacy Practices?
Contact our team directly. We are committed to full transparency regarding your business and client data.