Privacy policy
How Distil collects, uses and protects personal data, and the rights you have over it.
Last updated 23 September 2026
In short
- We collect only what you send us, what we need to work with you, and basic server logs.
- We use no cookies, no advertising trackers and no analytics scripts on this site.
- We never sell personal data.
- You can ask us to see, correct or delete your data at any time. We answer within one month.
1. Who we are
This website and the Distil services are run by Inseva Digital Labs LLP ("Distil", "we", "us"), a limited liability partnership registered in India, LLPIN ACH-0988, registered office A-19, Ground Floor, Suite 1202, FIEE Complex, Kartar Tower, Okhla Phase 2, South East Delhi 110020, India.
For the personal data described in this policy we are the controller under the EU and UK General Data Protection Regulation (GDPR) and the data fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act). Where a client asks us to process personal data on its behalf, we act as its processor under a written agreement.
Privacy contact and Grievance Officer: Abhishek Anand, abhishek@distil.one.
2. What we collect, why, and on what basis
| Data | Why we use it | Legal basis | How long we keep it |
|---|---|---|---|
| Contact form and email: name, work email, organisation, role, the service you ask about, your message | To reply, and to prepare a proposal if you ask for one | Steps you ask for before a contract (GDPR Art. 6(1)(b)); our legitimate interest in answering business enquiries (Art. 6(1)(f)); under the DPDP Act, data you give us voluntarily for this purpose | Up to 24 months after our last contact, unless you become a client |
| Client records: names and business contact details of client staff, contracts, invoices, payment records | To deliver services, bill for them and keep accounts | Performance of a contract (Art. 6(1)(b)); legal obligations such as tax and accounting law (Art. 6(1)(c)) | For the contract, then as long as Indian tax and accounting law requires, currently up to 8 years |
| Business contact data of professionals we may approach: name, job title, employer, work email, public professional profile | To contact people whose role makes our services relevant to them | Legitimate interest in business-to-business outreach (Art. 6(1)(f)). You can object at any time and we stop immediately | Up to 12 months after the last contact, unless you engage with us. Objections are kept on a do-not-contact list |
| Feedback on deliverables from client staff | To correct and improve future editions for that client | Performance of a contract; legitimate interest in service quality | For the life of the engagement |
| Server logs kept by our host: IP address, browser type, page requested, date and time | To run the website securely and stop abuse | Legitimate interest in security (Art. 6(1)(f)) | Short periods set by our hosting provider |
Where we get business contact data from someone other than you, the sources are company websites, public filings, press coverage, professional networks and business contact data providers.
3. Data inside our intelligence products
Our reports, briefs and election trackers analyse publicly available content: news articles, broadcast transcripts and public social media posts, obtained through licensed media data providers.
- Our outputs are mostly aggregated: volumes, trends, share of conversation and sentiment.
- Where a deliverable shows an individual post, it is public content, usually from a public figure, journalist, organisation or high-reach account, shown with a link to its source.
- We do not build profiles of private individuals, we do not identify or target individual voters, and we do not infer sensitive traits about named private people.
- Political content can reveal political opinions, which the GDPR treats as special category data. Where GDPR applies, we rely on our client's and our legitimate interests (Art. 6(1)(f)), assessed against the rights of the people concerned, together with Art. 9(2)(e) for data the person has manifestly made public. Under the DPDP Act, personal data made publicly available by the person is outside the Act's scope.
- If you appear in a deliverable and want a post removed from future work, write to us. We will assess the request and tell you the outcome.
4. What we don't do
- We don't use cookies, advertising trackers or analytics scripts on this site. See our cookie policy.
- We don't sell or rent personal data.
- We don't make decisions about you by automated means that have legal or similarly significant effects.
5. Who we share data with
We share personal data only with service providers who process it on our instructions, under contracts that require them to protect it:
- Netlify, Inc. (United States): website hosting and contact form submissions.
- Google LLC (United States): business email and documents through Google Workspace.
- Licensed media data providers: the source of the public content we analyse. We do not send them your contact data.
- Banks and payment providers: to receive payment.
- Professional advisers such as accountants and lawyers, under a duty of confidence.
- Authorities, where a law or a valid legal order requires it.
6. International transfers
We are based in India, so data you send us from the European Economic Area, the United Kingdom or Switzerland is transferred to India, which does not have an adequacy decision. Where we transfer personal data under a client contract, we use the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant). For a one-off enquiry that you send us yourself, the transfer is necessary for steps you asked us to take before a contract (GDPR Art. 49(1)(b)).
Netlify and Google are certified under the EU-U.S. Data Privacy Framework, including its UK and Swiss extensions, which covers transfers to them in the United States.
7. How we protect data
Access is limited to the people who need it. Our accounts use two-factor authentication, the website is served only over encrypted HTTPS connections, and deliverables are shared through private links that search engines are told not to index. If a breach puts your data at risk, we will tell you and the relevant authority as the law requires, including within 72 hours where the GDPR or the DPDP Act applies.
8. Your rights
Under the GDPR and UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to you or another organisation in a portable format. You can object to our use of your data based on legitimate interests, and you can always object to direct marketing, in which case we stop. Where we rely on consent, you can withdraw it at any time.
Under the DPDP Act you can ask for a summary of your data and how we process it, and ask us to correct, complete, update or erase it. You can nominate another person to exercise your rights if you die or cannot act, and you can raise a grievance with our Grievance Officer.
To use any of these rights, email abhishek@distil.one. We may ask you to confirm your identity. We answer within one month and do not charge a fee.
If you are not satisfied, you can complain to your local data protection authority in the EU, to the Information Commissioner's Office in the UK, or to the Data Protection Board of India. We would appreciate the chance to put things right first.
9. Children
Our services are for businesses and organisations. They are not directed at children, and we do not knowingly collect personal data from anyone under 18.
10. Changes to this policy
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell clients directly.