SunkaraOps
Privacy Policy
Last updated: 13 September 2026 · Effective upon publication by Dinesh Gopi Sunkara (sole proprietor trading as SunkaraOps — confirm registered name later)
1. Who we are
Dinesh Gopi Sunkara (sole proprietor trading as SunkaraOps — confirm registered name later) (“we”, “us”, “SunkaraOps”) is the controller of personal data collected through this website and during a sprint. Contact: dineshgopisunkara0228@gmail.com, Address on file — update before taking payment.
This policy explains what we collect, why, how long we keep it, and the processors we use (including Netlify Forms and Stripe). It is a template. After you fill the placeholders, have a qualified lawyer confirm it matches the law of India (laws of India; courts of competent jurisdiction) and any other country you target.
2. Data we collect
Lead form. When you use the form on the homepage we collect: name, email address, company or practice name, and the free-text answer to “biggest time-drain”. We also receive technical metadata the form processor attaches (approximate time of submit, and sometimes IP address or user-agent — see Netlify Forms below).
Email and scheduling. If you write to us or book a call, we keep the correspondence and any notes needed to run the sprint.
Payment. If you pay via a Stripe Payment Link, Stripe collects payment-card or wallet details, billing name, email, and transaction metadata. We receive confirmation of payment, the amount, currency, and the contact details you typed at checkout. We do not see or store full card numbers.
Sprint delivery. To install workflows we may see business emails, sample documents, process notes, and account structure you choose to share. We ask you to minimize personal data about your own clients (prefer samples and redactions).
Website logs. This static site does not run its own analytics by default. Your host (for example Netlify, Vercel, or GitHub Pages) may log IP addresses and request paths under that host’s policy. We do not set marketing cookies from this repo.
3. Why we use it (purposes and legal bases)
- Respond to inquiries and sell the sprint — steps at your request and, where required, legitimate interests in answering a business inquiry.
- Take payment and keep accounts — contract performance and legal bookkeeping duties in India (laws of India; courts of competent jurisdiction).
- Deliver the audit, workflows, SOPs, training, and support — contract performance.
- Operate and secure the site — legitimate interests in a working, abuse-resistant form.
- Defend legal claims and comply with law — legal obligation / legitimate interests.
We do not sell personal data. We do not use lead-form content to train a public foundation model.
4. Netlify Forms
The homepage lead form is handled by Netlify Forms (form name sunkaraops-leads). When you submit, the field values are posted to our Netlify-hosted site and stored in the Netlify Forms dashboard / notifications we configure. Netlify, Inc. acts as a processor / service provider for that transmission. Their terms and privacy notice apply: see netlify.com. Do not submit passwords, government ID numbers, health data, or your clients’ confidential files through the public form.
5. Stripe
Optional checkout uses a Stripe Payment Link. Stripe, Inc. and its affiliates process the payment as an independent controller or as our processor, depending on the data element and your location. Card data is handled inside Stripe’s infrastructure under the Stripe Privacy Policy (stripe.com/privacy). We use payment status to unlock kickoff and for tax/accounting records.
6. Other processors we may use
- Email (for example Google Workspace or a successor host) to read and reply to leads.
- Google Docs / Drive to deliver the prompt library and SOPs.
- Loom or a similar recorder for training videos.
- The static host you configured (Netlify, Vercel, GitHub Pages, or equivalent) for the website.
- Model interfaces you already use (ChatGPT, Gemini, Claude, and similar) when we work inside your accounts or on agreed samples. Prefer your workspace settings that disable vendor training.
We will not add a marketing pixel or email-sequence vendor without updating this policy.
7. Retention
- Unconverted leads: up to 18 months, then delete or anonymize, unless you ask us to delete sooner.
- Customers (form + sprint files + invoices): for the engagement and then for the period required to keep tax and contract records in India (laws of India; courts of competent jurisdiction) (often 6–8 years). Working copies of your client samples are deleted or returned within 30 days after the support window unless you ask us to keep them as a runbook.
- Payment records: as Stripe and tax law require.
- Copyright / legal notices: as long as needed to handle the dispute.
8. Sharing
We share personal data with the processors above, with professional advisers under confidentiality (accountant, lawyer), and with authorities if the law requires it. We may transfer the practice to a successor, who must continue to respect this policy or give you notice. We do not sell lists and we do not share leads with unrelated advertisers.
9. International transfers
Netlify, Stripe, Google, and similar vendors may process data in the United States and other countries. If you are in the EEA, UK, or another region with transfer rules, those vendors’ standard contractual clauses or equivalent safeguards are the intended mechanism. Ask dineshgopisunkara0228@gmail.com if you need a current subprocessors list before you buy.
10. Your rights
Subject to the law of India (laws of India; courts of competent jurisdiction) and, where they apply, GDPR / UK GDPR / similar regimes, you may request access, correction, deletion, restriction, objection, or portability of personal data we hold, and you may withdraw consent where consent was the basis. You may also lodge a complaint with your supervisory authority. To exercise rights, email dineshgopisunkara0228@gmail.com. We will need enough information to find your record (the email you used on the form is usually enough).
If you are a California resident, we do not “sell” or “share” personal information as those terms are used in the CPRA for cross-context advertising, because we do not run that advertising on this site.
11. Children
The site and sprint are for businesses and adult practitioners. We do not knowingly collect data from children under 16 (or under 18 where that is the local digital-consent age). If you believe we have, write to dineshgopisunkara0228@gmail.com and we will delete it.
12. Security
We use HTTPS on the deployed host, access-controlled email, and least-privilege sharing on Google Docs. No method is perfectly secure. Do not send passwords in the lead form. Prefer a live screenshare over handing us standing credentials.
13. Changes
We will post updates to this page and change the “Last updated” date. Material changes to how we treat existing customer data will also be emailed to the address we have on file when we have it.
14. Contact
Privacy requests: dineshgopisunkara0228@gmail.com
Dinesh Gopi Sunkara (sole proprietor trading as SunkaraOps — confirm registered name later)
Address on file — update before taking payment
Related: Terms of Service and Copyright.