Skip to main content
Legal

Privacy policy

Effective 29 April 2026

Who we are

Branding Pioneers is a healthcare-only marketing firm headquartered in Gurugram, India, with a US office in La Mesa, CA and a mental-health partner in Tampa, FL. We operate documented information-security controls — least-privilege access, encrypted storage and transport, and reviewed vendor access — and sign HIPAA Business Associate Agreements (BAAs) where engagements involve protected health information (PHI).

What we collect

On our website. Standard analytics (anonymised IP, referrer, page-views, device, country) via Google Analytics 4, and Microsoft Clarity where it is enabled. We run no advertising or conversion pixels on this site. Analytics storage is denied until you accept the cookie banner, and your choice is applied through Google Consent Mode.

From form submissions. Name, email, phone (if you share it), the company you represent, the message you typed, and the page you submitted from. We do not collect health information through public forms.

During engagements. Whatever your contract authorises us to access — typically Google Ads, Meta Business Suite, GA4, GSC, your CRM, your CMS. PHI access is rare; when present, it is governed by a signed BAA and segregated access logs.

How we use it

  • Respond to your inquiry within one business day.
  • Match you with the right senior strategist for a first call.
  • Send you the materials you asked for (benchmarks, audit, case files).
  • Run your campaigns under the scope your engagement authorises.
  • Aggregate (anonymised) reporting for our client-portfolio benchmarks.

We do not sell or rent your data. We do not retarget mental-health-condition site visitors. We do not share PHI with third parties beyond the platforms your engagement requires.

Where we store it

Data is stored in encrypted form on AWS infrastructure (us-east-1, ap-south-1) and Google Cloud (us-central1). Customer-relationship data lives in HubSpot (BAA-cleared tier). Marketing automation lives in our in-house WaCRS / Convi.AI stack.

Retention

  • Marketing inquiries: 24 months from last engagement, then deleted.
  • Active client data: duration of engagement + 7 years (statutory record-keeping).
  • Anonymised aggregate analytics: indefinite.
  • PHI: as defined in your BAA — typically deleted on termination plus 6-year HIPAA window.

Your rights

  • Access — email privacy@brandingpioneers.com for a data export. We respond within 30 days.
  • Correction — same channel, same SLA.
  • Deletion — same channel. We honour deletion requests except where statutory record-keeping requires retention; we will explain why.
  • Portability — JSON export of your data on request.
  • Opt-out of marketing — unsubscribe link in every email; or email us directly.
  • Lodge a complaint — contact your local data-protection authority (GDPR), the Data Protection Board of India, or the Federal Trade Commission (US).

Cookies

We use a strict-by-default consent model: analytics and advertising storage are set to denied before anything loads, and only switch to granted if you press Accept. Pressing Decline keeps them denied. Strictly-necessary cookies (auth, CSRF) always fire — without them the site doesn't work.

Subprocessors

We use the following sub-processors. Each is reviewed annually for compliance posture: AWS, Google Cloud (including Google Analytics), Microsoft (Clarity), HubSpot, Twilio, Google Workspace, Cloudflare, Vercel, GitHub, Notion. Full list with purposes available on request.

Changes

We update this policy when our practices change. The effective date at the top of this page is the date of the most recent change. Material changes are notified via email to active clients and the website.

Contact

privacy@brandingpioneers.com — for everything in this policy.

dpo@brandingpioneers.com — for GDPR / India DPDPA-specific matters.

security@brandingpioneers.com — to report a vulnerability or incident.

We respond same business day during business hours (Mon–Fri 09:00–19:00 IST).

Why choose us

Why healthcare brands choose us.

Six reasons hospitals, clinics, and doctors pick a healthcare-only firm over a generalist agency.

  • Healthcare-only

    It's all we do. No retail, no fintech — the whole team thinks in patient journeys, clinical trust, and the way people actually choose a doctor.

  • AI-first systems

    Receptionists, WhatsApp triage, and attribution built in-house — we answer patients in seconds and tie every click to a booked appointment.

  • Compliance built-in

    HIPAA-aware handling, ASCI-reviewed creative, and GDPR/DPDP sign-off on every campaign — our standard, not an upcharge or an afterthought.

  • Senior on every account

    The senior who pitched you stays on the engagement. No bait-and-switch to juniors learning on your budget.

  • Measured to the appointment

    Patient-level attribution across calls, forms, and walk-ins. Monthly reports show booked patients — not just clicks and impressions.

  • Receipts, not promises

    We name our clients and show the work. Quarterly reviews with the numbers attached, every cycle.

The Branding Pioneers healthcare-marketing team at work

Healthcare-only · since 2016

A team that does one thing well.

Practical notes & supporting evidence

More detail for your next decision.

A practical reference for this page
  1. Start herePrivacy policy

  2. Establish contextUse the published scope and relevant source material

  3. Choose the next stepFollow the linked resource and assign an owner

Putting Privacy policy into practice

This page focuses on Privacy policy. Start with its published information and the decision you need to make. Identify which details apply to your practice and which require further checking. Follow the relevant linked resources for implementation steps, source material or the current contact route, and keep your own constraints visible when turning the information into a brief.

Find the policy information relevant to your question

Read the headings and the full policy wording above before deciding which contact route to use. A question about published content is different from a question about an invoice, an engagement scope or a data request. Identify the page, document or transaction involved and keep its date with your question. The practical notes here help organise that enquiry; the published policy wording and any applicable agreement provide the relevant terms.

For a question about a case study, include its URL and the particular statement, image or figure you want clarified. If the page shows a source report, identify the reporting window as well as the number. For a question about a purchase or engagement, identify the order or agreement using the information you already have. Avoid sending patient records or unrelated confidential documents as part of an initial policy enquiry.

Read examples and projections in their stated context

A published resource may contain client artwork, engagement scope, an original report, an independent design concept or a planning scenario. The label attached to the item explains which kind of material it is. Preserve that label when quoting or sharing the resource. An image of campaign creative describes the creative shown; a screenshot of a report describes the measures and period recorded by its source. Those materials answer different questions.

Planning tools depend on the inputs and assumptions supplied. Keep those assumptions with the output and distinguish an example calculation from an observed client result. If a page refers to a signed scope of work or another agreement, read the actual document involved in your engagement. A general website explanation cannot establish the specific scope, account responsibilities or commercial terms that were agreed for a different project.

Prepare a clear question or correction request

Explain what you are asking the team to clarify and provide enough context to locate the relevant material. A URL, heading and short description of the issue are usually more useful than a general statement that a page is unclear. Where a published source appears inconsistent, identify the source and the statement together. For an attribution or permission question, identify the exact item and how you intend to use it.

Use the contact information stated in the relevant policy or agreement. The website contact page can help route a general enquiry when you are unsure which team owns it. Keep a copy of the original question and any supporting reference so the discussion can stay focused on the same issue. Check the policy page directly when returning to the topic, rather than relying on a quotation or screenshot that may omit surrounding context.