Who we are
Branding Pioneers is a healthcare-only marketing firm headquartered in Gurugram, India, with offices in La Mesa, CA and Tampa, FL. We operate documented information-security controls — least-privilege access, encrypted storage and transport, and reviewed vendor access — and sign HIPAA Business Associate Agreements (BAAs) where engagements involve protected health information (PHI).
What we collect
On our website. Standard analytics (anonymised IP, referrer, page-views, device, country) via Google Analytics 4, and Microsoft Clarity where it is enabled. We run no advertising or conversion pixels on this site. Analytics storage is denied until you accept the cookie banner, and your choice is applied through Google Consent Mode.
From form submissions. Name, email, phone (if you share it), the company you represent, the message you typed, and the page you submitted from. We do not collect health information through public forms.
During engagements. Whatever your contract authorises us to access — typically Google Ads, Meta Business Suite, GA4, GSC, your CRM, your CMS. PHI access is rare; when present, it is governed by a signed BAA and segregated access logs.
How we use it
- Respond to your inquiry within one business day.
- Match you with the right senior strategist for a first call.
- Send you the materials you asked for (benchmarks, audit, case files).
- Run your campaigns under the scope your engagement authorises.
- Aggregate (anonymised) reporting for our client-portfolio benchmarks.
We do not sell or rent your data. We do not retarget mental-health-condition site visitors. We do not share PHI with third parties beyond the platforms your engagement requires.
Where we store it
Data is stored in encrypted form on AWS infrastructure (us-east-1, ap-south-1) and Google Cloud (us-central1). Customer-relationship data lives in HubSpot (BAA-cleared tier). Marketing automation lives in our in-house WaCRS / Convi.AI stack.
Retention
- Marketing inquiries: 24 months from last engagement, then deleted.
- Active client data: duration of engagement + 7 years (statutory record-keeping).
- Anonymised aggregate analytics: indefinite.
- PHI: as defined in your BAA — typically deleted on termination plus 6-year HIPAA window.
Your rights
- Access — email [email protected] for a data export. We respond within 30 days.
- Correction — same channel, same SLA.
- Deletion — same channel. We honour deletion requests except where statutory record-keeping requires retention; we will explain why.
- Portability — JSON export of your data on request.
- Opt-out of marketing — unsubscribe link in every email; or email us directly.
- Lodge a complaint — contact your local data-protection authority (GDPR), the Information Commissioner of India, or the Federal Trade Commission (US).
Cookies
We use a strict-by-default consent model: analytics and advertising storage are set to denied before anything loads, and only switch to granted if you press Accept. Pressing Decline keeps them denied. Strictly-necessary cookies (auth, CSRF) always fire — without them the site doesn't work.
Subprocessors
We use the following sub-processors. Each is reviewed annually for compliance posture: AWS, Google Cloud, HubSpot, Twilio, Google Workspace, Cloudflare, Vercel, GitHub, Notion. Full list with purposes available on request.
Changes
We update this policy when our practices change. The effective date at the top of this page is the date of the most recent change. Material changes are notified via email to active clients and the website.
Contact
[email protected] — for everything in this policy.
[email protected] — for GDPR / India DPDPA-specific matters.
[email protected] — to report a vulnerability or incident.
We respond same business day during business hours (Mon–Fri 09:00–19:00 IST).

