quietlybuild

Privacy · Version 1.8 · Updated 26 September 2026

What I do with your details.

I do the work myself, so almost nobody sees your details but me. This page says what I collect, who else touches it, how long I keep it, and how to have it corrected or deleted.

The short version

  • I am Aditya Vashistha. I run quietlybuild, the website studio of GrowMint Media, from Phagwara in Punjab, India. Write to hello@quietlybuild.in.
  • This site sets no cookies, has no analytics and sends nothing about you to anyone. One small script, served from this domain, runs in your own browser and stores nothing. There is nothing to consent to, so there is no banner.
  • Booking a call happens on Cal.com, not here: “Book a video call” is a plain link that opens its page in a new tab. What you type there goes to Cal.com and to me, and nothing from Cal.com loads on this site (section 03).
  • I collect what you send me, by email or WhatsApp, and what I need to quote for the work, build it and invoice you. Mail to hello@quietlybuild.in is forwarded by Cloudflare to the studio’s inbox. I don’t sell anything to anyone, and I don’t advertise to you.
  • Software tools, including AI tools, help me draft and build. What you send me may pass through them; I read and check everything they produce, and nothing is sold.
  • Ask for a copy, a correction or a deletion whenever you like. It is free, and I reply within a month.

01 · Who is responsible

Me, and only me.

The controller of your personal data is Aditya Vashistha, the proprietor of GrowMint Media, a registered business in Phagwara, Punjab, India. quietlybuild is GrowMint Media’s website studio, and I run it myself. A sole proprietorship is not a company, so the controller is me, in person. Where this page says “I”, it means me.

Email
hello@quietlybuild.in. Put “Privacy request” in the subject line.
Post
Phagwara, Punjab 144401, India. Ask by email for the full postal address. It is printed in the agreement you sign.
Registration
GrowMint Media, GST number 03BSHPV8130J1ZH, registered in my name as its proprietor.
Questions
I answer them myself. I am the contact for questions about your data under India’s Digital Personal Data Protection Rules 2025 (rule 9); the grievance officer under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (rule 5(9)); and the privacy officer under section 201 of New Zealand’s Privacy Act 2020.
Data protection officer
None. The law does not require one for a business like mine: I do not monitor people at scale and I do not handle sensitive categories of data.UK and EU GDPR, Article 37
Representative
None in the UK or the EU at present. Section 12 explains why.

02 · What this website collects

Only what any web server logs.

This site sets no cookies, uses no local storage, and loads no fonts, images, films or scripts from anyone else’s server. Your browser keeps its usual copy of the files, as it does for any site. It has no analytics and no contact form that sends anything to me.

Every page runs one small script of my own, served from this domain, that works entirely inside your browser. It works out the call times and the studio hours in your own time zone from your browser’s clock; shows a guide to the price in your own currency, worked out from the same time zone; plays each client film only while it is on screen, and stops it when you press pause; draws the payments to scale and marks the section you are reading; writes a pre-filled email or WhatsApp message when you ask for a site review; copies my email address if you press the copy button; draws the grid the page is laid out on when you ask it to; suggests the page you probably meant when an address on this site does not exist; and closes the phone menu when you choose a link in it. Nothing it does is stored or sent. Every page works without it.

The films of client websites are screen recordings, kept on this site like its images. Your browser fetches a film from this domain only when you scroll to it, and it plays silently in the page. The walk-through in my own voice is fetched only when you press Play, with its captions, and plays with sound. Nothing is embedded from YouTube or any other video service, so nobody else learns that you watched it. The QR codes beside the live sites are images on this site too: scanning one opens that client’s own website on your phone, and nothing about the scan reaches me.

An email goes nowhere until you press send. The WhatsApp buttons put the message inside a link to WhatsApp, so WhatsApp may see it when you tap. It reaches me only if you press send there. The “Book a video call” buttons are plain links too (section 03).

Cloudflare, which serves the site, sees what any web server sees: your IP address, the page you asked for, your browser type and the time you asked. It uses those to deliver the page and to block attacks. I use no analytics tool on this site. Cloudflare’s dashboard shows me totals for the whole site: the number of requests, an estimate of distinct visitors counted by IP address, and the countries most requests came from. It does not show me who you are.

That is the whole of it. There is no tracking pixel, no session, no fingerprint and no profile.

03 · If you book a call

On Cal.com, then on video.

The booking page is run by Cal.com, not by this site. What you type there goes to Cal.com and to me, and the call runs on Cal Video. I use it only to hold the call and to prepare for it. Nothing from Cal.com loads on quietlybuild.in.

  1. On this siteYou press “Book a video call”. It is a plain link to cal.com/quietlybuild/call: nothing is sent, and nothing from Cal.com has loaded.
  2. On Cal.comIts page opens in a new tab, under its own privacy policy and cookies. You choose a time and answer a few short questions.
  3. With meCal.com sends us both the booking and a video link, and reminds you before the call. Nobody records the call.
What Cal.com holds
Your name, your email address, the time you choose, your time zone and your answers to the booking questions. Cal.com, Inc. is in the United States.Cal.com says it relies on standard contractual clauses, or an adequacy mechanism such as the EU–US Data Privacy Framework, for transfers from the UK and the EU (its privacy policy, read 25 September 2026)
What I do with it
Hold the call, read your answers before it, and write to you afterwards if you asked me to. A booking is part of your enquiry, and I keep and delete it on the same terms (section 07).
The call itself
Half an hour on video in your browser, with nothing to install. Recording and transcription are switched off. If that ever changes, I will say so here first and ask you at the start of the call.
A walk-round of your premises
If I can’t visit, you walk me round on a video call, on WhatsApp or Cal Video. I take notes and a few still pictures of empty rooms, for my own reference: they never go on your site, and I delete the pictures the day your site launches. I ask you to show only people who have agreed. At a clinic, we walk only when no patient is there, and I never ask to see one. I record a walk-round only if you say yes in writing first, and then only the picture, with no sound, on my own laptop. The recording goes to no one and into no tool, and I delete it the day your site launches.
If you would rather not use it
WhatsApp or email me two or three times that suit you, and I send a video link.

04 · What you send me

What I collect, and why.

I collect what I need to quote for a website, build it and get paid for it. The legal bases named below are the ones under the UK and EU GDPR; the position under Indian, Australian and New Zealand law follows.

You visit this site
Your IP address, the page you asked for, your browser type and the time, seen by Cloudflare as it delivers the page. So that the site reaches you and stays safe from attacks.My legitimate interest in running a secure website, Art. 6(1)(f)
You book a call
What you give Cal.com: your name, email address, the time you chose and your answers. So that the call happens and I can prepare for it.Steps you ask for before a contract, Art. 6(1)(b) · or my legitimate interest in answering business enquiries, Art. 6(1)(f)
You email me
Your name, your email address and whatever you write or attach, so I can reply and quote for the work. Mail to hello@quietlybuild.in reaches me through Cloudflare’s forwarding (section 05).Steps you ask for before a contract, Art. 6(1)(b) · or my legitimate interest in answering business correspondence, Art. 6(1)(f)
You message me on WhatsApp
Your phone number, the name on your account and what you write, for the same reason.Art. 6(1)(b) or 6(1)(f)
We work together
The names, work emails and roles of the people I deal with; notes from our calls; notes and still pictures from a walk-round of your premises, and its recording if you agreed to one; your feedback and approvals; the text, photographs and files you send me; the Site plan; and the signed agreement. So that I can build the site and keep a record of what was agreed.Contract, Art. 6(1)(b), where you are my client personally · or my legitimate interest in delivering the contract your business signed, Art. 6(1)(f)
I invoice you
Your name, business name, billing address, tax number if you give me one, and the amounts, dates and payment references. Invoices come from GrowMint Media. So that I can invoice, keep accounts, and prove export income to the Indian tax and foreign-exchange authorities.Contract, then my legitimate interest in meeting Indian tax and foreign-exchange law, Art. 6(1)(f). Indian law is not a “legal obligation” in the GDPR’s sense, which is why this is legitimate interest

I do not buy contact lists. I do not collect health, religion, identity documents or anything else the law treats as sensitive. If you pay by card, I never see your card details. When you pay by bank transfer, the receiving bank’s record shows your name and may show your bank and account number. If you send me proof of payment, I keep it with the invoice.

Do you have to give me any of this? No. But I cannot quote, build or invoice without a name, a way to reach you and a payment reference.

If I wrote to you first

I never use a regulator’s public register to find people to write to. New Zealand’s register of immigration advisers, for one, says its information may be used only for the purpose it is published for, and I treat every register the same way. If I ever email a business first, it is at the business address that business publishes on its own website, about its website, once or twice. I hold your name, your firm’s name, that address, a one-line note of what I noticed on your website, and whether you replied. My legal basis is my legitimate interest in offering a business service to another business, Art. 6(1)(f). If I write first to businesses in the United Kingdom (see section 12), it will be only to limited companies and LLPs, never to sole traders or partnerships. In Australia and New Zealand I write first only to an address a business publishes itself, and not if its site says it does not want such messages. Reply “no”, or anything like it, and I stop. I then keep only your email address, on a do-not-contact list, so that I never write again. If you do not reply within six months, I delete what I hold.

Under Indian law

India’s Digital Personal Data Protection Act 2023 applies to me because I work in India. Its main duties and rights begin on 13 May 2027; until then the Information Technology Rules 2011 apply. From that date I rely on the data you give me for a stated purpose, such as an enquiry, where you have not objected (section 7(a)), and on your consent where I ask for it (section 6).

Under New Zealand and Australian law

I have a client in New Zealand, so I treat the Privacy Act 2020 as applying to me: it reaches an overseas business carrying on business in New Zealand whether or not it has a place of business there. Australia’s Privacy Act 1988 exempts most businesses turning over A$3 million or less, which includes mine, but I follow the Australian Privacy Principles anyway: access (APP 12), correction (APP 13), and an easy way to opt out of direct marketing (APP 7).

05 · Who else sees it

Who else sees it, and why.

Those marked processor act only on my instructions, under their own data processing terms. The payment firms are responsible for your data themselves, because the law makes them check who is paying whom.

Cloudflare
Serves this website and protects it. It also runs the mailbox forwarding: mail sent to hello@quietlybuild.in is received by Cloudflare Email Routing and forwarded straight on to the studio’s inbox, my GrowMint Media mailbox. Cloudflare says it does not store or read the content. Processor. Global network, headquartered in the United States.Transfers covered by the EU–US Data Privacy Framework and by standard contractual clauses in Cloudflare’s data processing addendum
GoDaddy
Hosts my business mailbox, on GrowMint Media’s domain, so every email you send me, and every reply and invoice I send, passes through it. United States.GoDaddy is certified under the EU–US Data Privacy Framework and its UK Extension
Cal.com
Runs my booking page and the video call, if you book one (section 03). United States.Standard contractual clauses, or the EU–US Data Privacy Framework, as its privacy policy says
WhatsApp · Meta
Carries our WhatsApp messages and calls, end-to-end encrypted, and holds the fact that we messaged. It acts under its own privacy policy, not mine.WhatsApp Ireland Limited if you live in the EEA; WhatsApp LLC if you live in the UK or anywhere else
AI and software tools that help me draft and build
They help turn our notes, still pictures from a walk-round, and what you send me into drafts of your pages, and help write and check the site’s code. I read and check everything they produce, and they decide nothing about you. No transcription service, and no machine translation service, is given anything of yours. Their providers may be in the United States or elsewhere outside India.For transfers from the UK and the EU, one of the two safeguards in section 06
Translator (Arabic)
Only if you order an Arabic version. A professional translator, whom I name to you in writing before they see anything, receives the approved English text of your pages, including the names and roles of any staff named on them, to translate it. They work only on my instructions, under a written confidentiality and data processing agreement, use no machine translation or AI tool, and delete their copies when the work is approved. They never see anything about your patients or customers. Processor. Where they work is named with them.If they work outside India, the safeguard for sending your text to them is named in your agreement before they see anything (section 06)
Google Drive
Only if you share files with me through it. Google holds them under your account, not mine.
GitHub
Holds the code, words and photographs of a site in a repository while I build it, where the project uses one. United States.GitHub is certified under the EU–US Data Privacy Framework and its UK Extension
Notion
Holds my list of enquiries and clients, my project notes and, once we work together, the private project page I share with you. United States.Notion Labs takes part in the EU–US Data Privacy Framework and its UK Extension
Razorpay and its partner banks
Run GrowMint Media’s local accounts in other currencies, so that a transfer in your own currency arrives as a domestic payment. They receive your payment, the name and bank details your bank sends with it, and the reference. India, and the partner bank for your currency. Independent controllers, regulated as payment firms.
Card payments
If you pay by card through the link on your invoice, Razorpay takes the payment and sees your card details. I never do. Independent controller, regulated as a payment firm.
Wise, and my bank in India
Wise, if you pay through it; and the bank in India that receives the money in rupees. Independent controllers under their own notices, regulated as payment firms and banks.
My chartered accountant
Prepares my accounts and tax filings from the invoices. A chartered accountant in India is bound by professional confidentiality, and your data stays in India.
Authorities
Indian tax and foreign-exchange authorities, through export declarations and filings, when the law requires it.

I do not sell personal data, share it for advertising, or pass it to data brokers. No other person works on your project, except a translator you have agreed to in writing (above); the software I use to draft and build is listed above too. If that ever needs to change, because of illness or help you have asked for, I will tell you first, and that person will sign a confidentiality agreement before they see anything of yours.

06 · Where it goes

To India, and to the providers above.

I work from India. Neither the UK nor the EU has recognised India’s data protection as adequate. When you send me something yourself, such as an email, a message or a file, it comes straight to me, and European regulators do not treat that as a restricted transfer. The UK and EU GDPR still govern what I then do with it.

When your data reaches a provider outside the UK and EU, I rely on one of two safeguards: the EU–US Data Privacy Framework and its UK Extension where the provider is certified, or otherwise the European Commission’s standard contractual clauses with the UK Addendum, in that provider’s own terms. Ask me and I will send you the one that applies to you.

If you order an Arabic version, the approved English text of your pages also goes to the translator named in your agreement, and the agreement names the safeguard for that transfer before they see anything.

07 · How long I keep it

Long enough, and no longer.

An enquiry that doesn’t become a project
12 months after our last message, then deleted, so I have the context if you write again. A call you booked is part of the enquiry, and goes with it.
Project files, writing and correspondence
The length of the project, plus three years after it ends.Three years is the limit for contract claims in India: Limitation Act 1963, Schedule, Article 55
The signed agreement
And the copyright assignment in it: as long as the rights it grants last. Either of us may one day need to prove who owns the site.
Invoices and payment records
At least seven years after the end of the Indian financial year the invoice falls in, and longer while any tax inquiry or appeal is open.GST law requires 72 months from the due date of that year’s annual return; seven years covers it. CGST Act 2017, s.36
Walk-round pictures and recording
The still pictures, and a recording if you agreed to one: deleted on the day your site launches. If we go no further, 30 days after the Site plan reaches you. At once, if you ask.
WhatsApp messages
Kept with the rest of the thread on my phone, and deleted with the project files.
A firm I wrote to first that did not reply
Six months after my last email, then deleted from my list and from my sent mail.
My do-not-contact list
Your email address only, for as long as I write to firms first, so that I never write to you again.
Website requests
Cloudflare keeps its request logs only as long as its data processing terms allow, to deliver the site and keep it safe. My dashboard shows me totals. For a limited time it also shows the IP address and page of any request Cloudflare blocked as an attack.

08 · Your rights

Ask, and I do it.

Email hello@quietlybuild.in with “Privacy request” in the subject line. Say what you want and give the email address I would know you by. If I cannot be sure the request is really from you, I will ask you to confirm. It costs nothing, and I reply within one month. For a complicated request I may need up to two months more; if so I will tell you inside the first month and say why.

Wherever you are, you can ask me to:

  • send you a copy of your data, and tell you how I use it
  • correct it, or fill in what’s missing
  • delete it
  • stop or pause using it
  • send it to you, or someone else, in a common file format
  • never write to you again
  • withdraw a consent you gave, though that doesn’t undo what I did before

Some of these have limits. I have to keep invoices for as long as Indian tax law says. If I can’t do what you ask, I’ll tell you why.

UK and EU: Articles 15 to 21, with a reply inside one month (Art. 12(3)); an objection to direct marketing always succeeds (Art. 21(2)–(3)). India, from 13 May 2027, where the Act applies to your data: a summary of your data and who saw it (s.11), correction and erasure (s.12), a way to raise a grievance with me before you go to the Data Protection Board (s.13), and nominating someone to act for you (s.14). New Zealand: access and correction under principles 6 and 7 of the Privacy Act 2020.

09 · Cookies

There aren’t any.

This site sets no cookies at all, and the small script described in section 02 stores nothing on your device. That is why there is no banner: there is nothing to ask you about.

A few links here go somewhere else: the client websites in the work section and the QR codes that open them, the WhatsApp links, the public registers, the Instagram link in the footer, and the booking page on Cal.com. Those set their own cookies under their own policies, and nothing of theirs loads until you click or scan.

If I ever add something that stores or reads anything on your device, such as analytics, an embedded video or an embedded booking calendar, then before it goes live I will ask you first, make refusing exactly as easy as agreeing, and list every cookie on this page with what it does and how long it lasts.

10 · How I keep it safe

Small surface, few keys.

  • Two-step sign-in on every account that holds anything of yours, and a password manager rather than remembered passwords.
  • An encrypted laptop, which is where your project files live.
  • No shared logins. Nobody else has a key to my mailbox, the booking page or the hosting.
  • This website has no database, no login and nothing that receives data, so there is nothing on it to break into.

If something goes wrong in a way that is likely to put you at risk, I will tell you and the relevant regulator inside the time the law sets: 72 hours to the regulator under the UK and EU GDPR (Article 33). Under New Zealand’s Privacy Act 2020, if a breach is likely to cause serious harm, I will tell the Privacy Commissioner and each person affected as soon as I can. From 13 May 2027 Indian rules will also require me to tell each person affected, and the Data Protection Board, without delay.

11 · Complaints

Tell me first.

Write to hello@quietlybuild.in. I deal with every complaint within one month and tell you what I have done about it. If you are still unhappy, the regulator where you live can take it further:

United Kingdom
Information Commissioner’s Office: ico.org.uk/make-a-complaint
EU and EEA
The authority where you live or work, or where the problem happened. The list is at edpb.europa.eu.GDPR Article 77
New Zealand
Office of the Privacy Commissioner: privacy.org.nz. It asks you to complain to me first.
Australia
As a small business I am exempt from the Privacy Act 1988, so the Office of the Australian Information Commissioner (oaic.gov.au) may not be able to act on a complaint about me. Tell me first, and I will deal with it under the Australian Privacy Principles as if the Act applied.
India
The Data Protection Board of India, from 13 May 2027, once you have used my grievance process. If you are outside India and your data came to me under a contract with a business outside India, the Act gives you fewer rights, so write to me first. I will still do everything section 08 promises. Until then, grievances come to me as grievance officer.DPDP Act 2023, s.13(3) and s.17(1)(d)
Anywhere else
Tell me first. If you are still unhappy, the privacy regulator where you live can advise you. In Canada, that is the Office of the Privacy Commissioner: priv.gc.ca.

12 · Representatives in the UK and the EU

None yet, and here is the honest reason.

A business outside the UK and EU that offers services to people there usually has to appoint a representative in each. There is an exception, in Article 27(2)(a), for processing that is occasional, involves no sensitive data at scale, and is unlikely to put anyone at risk.

I rely on that exception for now. What I hold from the UK and the EU today is a handful of enquiries and the business contact details behind them. Regulators read “occasional” narrowly, so this will not hold forever. I will appoint a UK representative before I write to anyone in the UK who has not written to me first, and an EU representative before I do the same in the EU. Their names will appear here. You can always write to me directly.

13 · Children, automated decisions, changes

Three short answers.

Children
I build websites for businesses, and nothing here is meant for anyone under 18. If a child writes to me, I delete what they sent. A client’s own photographs may show children at its events. Those stay part of that client’s project files, are used only with the client’s permission, and are deleted with the files.
Automated decisions
There are none. No decision about you here is made by software on its own.
Changes
When this page changes, the date at the top changes with it. If a change affects a current client’s data, I email that client before it takes effect. Version 1.8 describes the software tools, including AI tools, that help me draft and build. Version 1.7 describes the walk-round of your premises on video, our WhatsApp calls, and what happens to the still pictures and any recording; and it adds a professional translator, as a processor, only for a client who orders an Arabic version. Version 1.6 describes the tools I use for drafting and building, says how mail to hello@quietlybuild.in is forwarded to the studio’s inbox, names the booking link, and links the accessibility statement. Version 1.5 says that I never use a regulator’s register to find people to write to, and that a first email goes only to an address a business publishes itself. Version 1.4 names GrowMint Media, whose website studio quietlybuild is; moves my email address to hello@quietlybuild.in, which Cloudflare passes on to my business mailbox at GoDaddy, so Microsoft and Outlook.com are no longer on the list; adds the booking page on Cal.com (section 03), the firms that run GrowMint Media’s local accounts, and my chartered accountant; and describes what the script now does. Version 1.3 described the recorded films and the QR codes. Version 1.2 corrected who handles my email and WhatsApp messages, added the tools that handle what you send me, added what I hold if I wrote to you first, and brought the New Zealand, Australian and Indian sections up to date.