Skip to main content

Prabjit Kaur

Privacy Policy — written like a human, not a lawyer.

This page explains what data I collect, why I collect it, how I store it, who I share it with, and what rights you have. It applies to theprabjitkaur.com, TheKeterNauts agency engagements, the monthly newsletter, and any service I deliver under those brands.

Five sentences. No legalese.
01

Who I am & how to contact me

This policy is operated by Prabjit Kaur, Founder and Brand Strategist, doing business as TheKetNauts (a brand-led growth studio). All references to “I”, “me,” or “us” in this policy refer to that operating entity.

I am the data controller for any personal data I collect through this website, my newsletter, my client onboarding, and any direct conversation we have.

02

What I collect

I collect data in four contexts. Each is listed below with exactly what’s collected — nothing more.
2.1 When you fill the contact form
2.2 When you book a strategy call
2.3 When you subscribe to the newsletter
2.4 When you simply visit the website
SENSITIVE DATA
I do not knowingly collect “special category” data: health, biometrics, sexual orientation, political views, religious belief, trade union membership, or criminal history. If you accidentally share any of this in a message, I’ll redact and ask you to resend.
03

Why I collect it & legal basis

I collect data in four contexts. Each is listed below with exactly what’s collected — nothing more.
Data Privacy Table
Purpose Data Used Legal Basis
Reply to your enquiry Form fields Legitimate interest · Pre-contractual steps
Deliver the strategy call Booking data, payment via Stripe Contract performance
Send the monthly newsletter Email, name, engagement Consent (opt-in)
Improve the site Anonymised analytics Legitimate interest
Invoice & tax compliance Name, company, billing address, payment receipt Legal obligation (UAE VAT / Indian GST)
Prevent fraud / abuse IP, browser fingerprint, payment flags Legitimate interest

If a processing activity isn’t listed in the table, I’m not doing it. If you suspect otherwise, write to theprabjitkaur@gmail.com.

04

Who I share it with

I share the minimum data with the minimum number of processors. Every one listed below has signed a data processing agreement or operates under their own GDPR-aligned terms.
Data Privacy Table
Processor What They Handle Where Data Sits
Google Workspace Email, calendar, docs, Drive EU / US (SCCs)
Stripe Card payments, invoices EU / US (PCI-DSS, SCCs)
ConvertKit / Kit Newsletter subscriptions & sending US (SCCs)
Calendly Strategy call bookings US (SCCs)
Plausible Analytics Anonymised site analytics EU (Germany)
WhatsApp Business (Meta) Direct messaging EU / US (Meta's own DPA)
Hosting (Hostinger / Cloudways) Website hosting + CDN EU or Asia, depending on plan
WooCommerce / WordPress Site CMS, form handling Self-hosted on above

I never sell, rent, or trade your personal data. I share with law enforcement only when legally compelled (e.g. valid court order from a competent UAE, Indian, or EU authority).

05

Where it's stored & for how long

06

Cookies & tracking

I use the absolute minimum number of cookies. Here’s the full list:
Cookie Policy Table
Cookie Purpose Duration
plausible_* Privacy-friendly anonymised analytics Session only
wp_* WordPress login/session (only if you log in) 14 days
cookieconsent_* Remembers your cookie choice 12 months

I do not run Facebook Pixel, Google Ads remarketing, or third-party advertising cookies on this site. If you opt out of analytics via the banner, no Plausible cookie is set.

For more, see the Cookie Policy.

07

Your rights

You have the following rights over your personal data, regardless of where you live. To exercise any of them, email with the words “privacy request”
Response time: 30 calendar days. No charge for the first request per year.
UAE PDPL NOTE
If you’re a UAE resident, the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) gives you the same rights, plus the right to be informed about automated decision-making. I do not use automated decision-making.
INDIA DPDP ACT NOTE
If you’re an Indian resident, the Digital Personal Data Protection Act 2023 applies. You can nominate a representative to exercise your rights and ask for grievance redressal. I respond within 30 days.
08

Security

What I do to protect your data:
No system is unbreakable. If a breach occurs, I will notify affected users within 72 hours, as required by GDPR Article 33 and equivalent UAE/India rules.
09

Children’s data

This site and these services are intended for adults (18+) running businesses. I do not knowingly collect data from anyone under 18. If you believe a minor has submitted data here, email me immediately and I’ll delete it.
10

International transfers

Because some processors (Google, Stripe, ConvertKit, Calendly) operate in the US, your data may cross borders. I rely on:

Copies of relevant SCCs available on request.

11

Changes to this policy

If I update this policy materially, I’ll:
Minor edits (typos, link fixes) won’t trigger a notification.
12

Complaints & escalation

If you’re unhappy with how I’ve handled your data:
Authority Links Table
If You're In Authority Website
India Data Protection Board of India meity.gov.in
UAE UAE Data Office uaedataoffice.gov.ae
EU Your national DPA (see edpb.europa.eu) edpb.europa.eu
UK ICO ico.org.uk

One last thing. I treat your data the way I’d want mine treated: minimum, encrypted, deletable, and never sold. If anything on this page makes you uncomfortable, write to me directly. I’ll explain or change it.

Two ways to reach me — both go straight to me.

Most privacy questions get answered the same day. Anything that needs a written response gets one within 14 days, or 30 days at the absolute latest. No ticketing system, no auto-responders.

For briefs, proposals, NDAs

For quick clarifications