This Privacy Policy explains how Navneet Trust, operating under the trade name Gala Intelligence, collects, uses, discloses, retains and protects Personal Data in connection with Gala Intelligence websites, accounts, applications, APIs, enterprise services, support channels and related services (collectively, the "Services").
This is the company-level privacy policy. Individual Gala Intelligence products may have product-specific privacy notices describing additional processing, permissions, data sources, retention practices, correction mechanisms or regulatory requirements. Where a product-specific notice expressly addresses a particular processing activity, that notice governs that product-specific activity and should be read together with this Privacy Policy.
This Privacy Policy applies to the processing described here across the jurisdictions in which Gala Intelligence operates. The privacy requirements applicable to that processing depend on the relevant Service, the processing activity and the jurisdiction concerned. Gala Intelligence will provide the notices, choices and safeguards required by applicable law, including additional protections as they become effective.
Nothing in this Privacy Policy is intended to create rights or obligations beyond those required by applicable law or expressly undertaken by Gala Intelligence.
Gala Intelligence is the trade name used by Navneet Trust. Our contact address is Cabin No. B-8, 12th Floor, Office-1204, Gala Empire, Opp. Doordarshan Center, Ahmedabad - 380059, Gujarat, India. Privacy enquiries may be sent to privacy@galaintelligence.com.
Gala Intelligence's legal role depends on the processing activity:
The role is assessed for each processing activity. Gala Intelligence does not become an independent controller merely because it selects technical tools, infrastructure, vendors, models or source categories necessary to perform a Customer-requested Service.
| Category | Examples | Typical use |
|---|---|---|
| Account & identity data | Name, username, work or personal contact details, account identifiers and profile information | Registration, authentication, account administration and communications |
| Business & organisation data | Company name, role, billing contact, organisation identifiers and authorised-user information | Enterprise administration, contracting, support and billing |
| Service & Customer-submitted data | Information submitted, connected, imported or queried through a product or API | Provide the requested Service and related support |
| Phone, contact & communications-related data | Phone numbers, caller/contact attributes, reports, labels, contact relationships or other supported communication signals | Where relevant to caller safety, verification, fraud detection, risk intelligence or data enrichment |
| Technical & device data | IP address, browser/app version, device type, operating system, language, session identifiers, diagnostic and crash information | Security, troubleshooting, service operation and analytics |
| API & security data | API/account identifiers, authentication events, timestamps, endpoints, request status, rate-limit events and audit logs | Service delivery, billing, abuse prevention, security and dispute investigation |
| Transaction & billing data | Plan, invoices, payment status, transaction references and tax information | Payments, accounting, subscriptions and fraud prevention support |
| Support, grievance & correction data | Tickets, correspondence, evidence submitted for correction, dispute history and verification information | Support, privacy rights, data quality and dispute handling |
| Analytics & derived data | Risk indicators, classifications, recommendations, enrichment, reputation, online-presence or other analytical outputs | Provide product functionality, quality assurance and permitted analytics |
| Website technologies | Cookies, local storage, session tokens and web analytics events | Website operation, preferences, security and analytics |
Gala Intelligence may obtain Personal Data from:
The exact source mix varies by product. Product-specific privacy notices may provide more detail where a particular source category is material to that product.
The availability of information from a Customer, community contributor, licensed provider or public source does not, by itself, authorise every subsequent use. Gala Intelligence assesses the permissions and restrictions applicable to the source and the intended processing, including any required notice or consent.
Depending on the Service and applicable law, Gala Intelligence may process Personal Data to:
For processing subject to Indian privacy requirements, Gala Intelligence relies on consent or another ground specifically permitted for the relevant processing. A commercial contract, a business interest or the availability of information online does not, by itself, replace a required permission. In other jurisdictions, applicable grounds may include consent, performance of a contract with the individual, legal obligations or legitimate interests where recognised and subject to the relevant conditions.
Where consent is required, Gala Intelligence provides a clear notice identifying the Personal Data involved, the specific purpose and the Service or feature it enables. Consent is requested through an affirmative action. Optional processing is distinguished from processing necessary for the requested Service. Acceptance of contractual terms or a device permission does not, by itself, constitute consent to unrelated processing.
You may withdraw consent through the relevant consent control or by emailing privacy@galaintelligence.com and identifying the processing concerned. Withdrawing consent will be as easy as giving it. Gala Intelligence will cease the affected processing and instruct its processors accordingly within a reasonable time, unless continued processing is required or authorised by applicable law. Withdrawal does not affect earlier lawful processing, but a feature that depends on the withdrawn permission may become unavailable. Any records retained after withdrawal remain subject to Section 13.
Certain Gala Intelligence Services allow business Customers to submit, connect, query or otherwise process Personal Data relating to their leads, customers, employees, contacts or other individuals.
Where Gala Intelligence processes such Personal Data solely on the Customer's documented instructions, the applicable Customer Agreement or product Data Processing Terms govern that processing. The Customer remains responsible for determining its lawful purpose, providing required notices, obtaining any required consent or authority, and responding to rights requests for processing it controls.
Gala Intelligence does not acquire ownership of Customer Personal Data merely because it is processed through a Service. Where Gala Intelligence separately processes information for an independently determined purpose, that separate processing is governed by this Privacy Policy, the relevant product notice and applicable law.
Where Gala Intelligence acts solely as a processor, Customer Personal Data is used only for documented Customer instructions or as required by applicable law. Submission through a Service does not itself authorise Gala Intelligence to add that information to an independently maintained intelligence database or use it for unrelated model training. Any separate processing requires its own applicable permission, notices and safeguards.
Some Gala Intelligence Services process Personal Data about individuals who do not have a Gala Intelligence account and may never have interacted directly with Gala Intelligence. This may occur when a Customer submits an identifier or record for a requested Service, when a user or community member provides information supported by a product, or when information relevant to a Service is obtained from permitted external sources.
Depending on the relevant Service, indirectly obtained Personal Data may include:
The information available for a particular person or identifier varies by product, requested purpose and the information lawfully available at the relevant time.
Gala Intelligence may process indirectly obtained Personal Data to provide the relevant Service, including caller safety, fraud detection, verification, risk intelligence, data enrichment, business/contact intelligence, security, abuse prevention, data-quality review, correction handling and related analytical functionality.
Advisory Outputs may help a user or Customer identify information that warrants additional review or verification. Product-specific notices and terms describe the nature, limitations and permitted uses of those Outputs.
Indirectly obtained information may originate from Customers and authorised users, Gala Intelligence proprietary information and historical service signals where lawfully maintained, licensed or contracted information providers, lawfully processed public sources, community or user reports where supported by the product, and other authorised sources or technical integrations used to provide the Service.
A community report, Customer submission or third-party publication is not treated as blanket permission for independent collection, matching or disclosure. Gala Intelligence assesses whether the intended activity has the required consent, other permission or applicable exemption. Publication of this Privacy Policy does not itself obtain consent from a non-user.
Gala Intelligence protects confidential source agreements, proprietary source weighting, analytical methodology and security-sensitive information. This does not restrict disclosures about Personal Data, sources, recipients or processing that an individual or competent authority is entitled to receive.
Where Gala Intelligence processes Personal Data solely on documented instructions from a business Customer, Gala Intelligence generally acts as a processor, Data Processor, service provider or equivalent role to the extent recognised by applicable law. The Customer determines the relevant business purpose and remains responsible for its controller obligations.
Where Gala Intelligence independently determines a separate purpose and essential means for processing Personal Data, Gala Intelligence is responsible for that independent processing to the extent required by applicable law.
Personal Data relating to non-users follows the retention periods and criteria in Section 13 and the relevant product-specific notice. The absence of an account does not justify indefinite retention. Independently maintained intelligence is reviewed for continuing relevance, accuracy, source permission and necessity.
Where Gala Intelligence acts solely as a processor, documented Customer instructions and the applicable processing terms govern return and deletion, subject to mandatory retention requirements.
Where applicable law requires additional transparency for Personal Data obtained indirectly, Gala Intelligence will provide the required information or use another legally permitted transparency mechanism, subject to applicable exceptions.
Individuals whose Personal Data is processed by Gala Intelligence may exercise the privacy rights described in Section 16 (Global Privacy Rights) and any applicable jurisdiction-specific rights described in Section 17.
Where Gala Intelligence processes Personal Data solely on behalf of a business Customer, Gala Intelligence may refer the request to that Customer and provide reasonable assistance as required by the applicable contract and law. Where Gala Intelligence is independently responsible for the relevant processing, Gala Intelligence will handle the request directly to the extent required by applicable law.
Privacy, correction or other rights requests may be submitted to privacy@galaintelligence.com.
Certain Gala Intelligence Services use statistical models, automated matching, rules, machine learning or other analytical methods to generate classifications, recommendations, indicators or other Outputs.
Automated Outputs may be incomplete, inaccurate, outdated or incorrectly attributed. Product-specific terms may require human review and restrict the use of advisory Outputs for legally regulated or materially significant decisions.
Where applicable law imposes specific requirements on profiling or automated decision-making, Gala Intelligence will implement appropriate safeguards according to Gala Intelligence's role in the relevant processing.
Describing an Output as advisory does not remove applicable responsibilities for lawful processing, data quality or individual rights. Requests concerning inaccurate Personal Data or an incorrectly attributed Output may be submitted under Sections 14 and 16. Where applicable, Gala Intelligence provides the safeguards required for automated decisions, including an opportunity to contest the decision or obtain human review.
Gala Intelligence is based in India and may use service providers or infrastructure in India and other jurisdictions. As a result, Personal Data may be processed outside the country where the individual or Customer is located.
Where applicable law restricts international transfers, Gala Intelligence will use an applicable transfer mechanism, contractual safeguard, adequacy framework, localisation arrangement or other legally permitted method. A Customer requiring a hosting-location commitment beyond applicable mandatory requirements must obtain that commitment in the relevant Customer Agreement or product plan. Mandatory localisation, destination restrictions and transfer safeguards apply regardless of whether a separate hosting-location commitment has been purchased.
Where Gala Intelligence acts as a processor, international-transfer responsibilities are also governed by the applicable Customer Agreement or product Data Processing Terms.
Gala Intelligence maintains reasonable technical and organisational safeguards appropriate to the nature, scope and risk of the processing. Depending on the Service and deployment, measures may include authentication and access controls, secure transmission, restricted administrative access, logging and monitoring, backup and recovery measures, secure-development practices, vulnerability management, personnel confidentiality and incident-response procedures.
No information system can be guaranteed to be absolutely secure. Gala Intelligence does not represent that cyberattacks, service failures or unauthorised access are impossible.
If Gala Intelligence becomes aware of a Personal Data Breach, it will investigate, contain and remediate the incident. Where notification is required, affected individuals will be informed without delay through an available registered contact channel. The notice will explain the known nature and timing, likely consequences, protective measures, recommended actions and a contact for questions.
Required initial notifications to the competent authority will also be made without delay. Where applicable, further details will be supplied within 72 hours of awareness, unless an extension is permitted. Shorter applicable reporting deadlines take priority. For Customer-controlled processing, Gala Intelligence will notify and assist the relevant Customer in accordance with its processing obligations.
Gala Intelligence retains Personal Data only for the period necessary for its permitted purpose, subject to applicable recordkeeping requirements. The following schedule describes ordinary retention. Information may be deleted earlier when its purpose ends, consent is withdrawn or a valid deletion request applies, unless continued retention is legally required or otherwise permitted.
| Category | General retention approach |
|---|---|
| Account & profile data | While needed for the active account or relationship. Following closure or a valid deletion request, active copies are removed within 30 calendar days, subject to the exceptions below. Inactive accounts are reviewed after 24 months without activity to determine whether a continuing purpose remains. |
| Billing, transaction, tax & contract records | Necessary records are retained for 8 financial years from the end of the financial year to which the relevant records relate, or for any longer period required under applicable tax, accounting, audit, investigation or legal requirements. Unnecessary payment or profile information is removed earlier. |
| Contract records | During the contractual relationship and for 8 years after its end, where necessary for applicable recordkeeping or establishing, exercising or defending legal claims. |
| Security, authentication, API & access logs | 12 months from the recorded event, subject to applicable minimum retention and localisation requirements. |
| Support, privacy, grievance & correction records | Up to 3 years after the matter closes, where needed for follow-up, service administration or a lawful claim. Excess identity-verification material is removed within 30 days after verification or case closure, as appropriate. |
| Customer-submitted service data | For the instructed Service and the periods specified in the relevant product notice or processing agreement. Those documents specify any post-termination export window, deletion deadline and backup period. |
| Independently maintained intelligence and enrichment data | Reviewed at least every 12 months for accuracy, relevance, source permission and continuing necessity. Information without a continuing permitted purpose is removed. Records are not kept indefinitely merely because they continue to receive queries. Product notices specify any applicable maximum active-retention period. |
| Suppression records | Only the minimum information needed to honour a continuing objection, restriction or delisting choice and prevent inappropriate reintroduction. Necessity is reviewed every 24 months. Suppression is distinct from deletion. |
| Optional website analytics and marketing records | Analytics records are retained for 24 months from collection. Marketing contact details are retained until withdrawal or 24 months without engagement, whichever is earlier, subject to necessary suppression records. |
| Backups | Ordinary backup copies expire within 90 days after removal from active systems. They remain protected and are not used for routine queries. Deletions and restrictions are reapplied if a backup is restored. |
| Legal-hold records | Relevant records are retained for a specific lawful preservation need. Holds are reviewed every 6 months, and records are removed within 30 days after the hold ends unless another permitted retention requirement applies. |
From the date an applicable retention obligation takes effect, Gala Intelligence retains covered Personal Data, associated traffic data and processing logs for the required minimum period, including at least one year from the relevant processing where required. These records may remain after account closure or a deletion request. Their use and access are restricted to the purposes supporting retention, and they are erased when the obligation ends unless further retention is legally required.
At the end of the applicable period, Gala Intelligence deletes the Personal Data or irreversibly anonymises it where permitted. Removing information from display, suppressing a record or replacing an identifier with a reversible or linkable value does not, by itself, amount to deletion or anonymisation.
Gala Intelligence does not extend retention solely because information might be commercially useful in the future. Where a requested deletion cannot be completed in full, Gala Intelligence explains the relevant exception and retention period or criteria unless disclosure is prohibited.
Gala Intelligence takes appropriate steps to maintain the accuracy, completeness and consistency of Personal Data, particularly where it is used to make a decision affecting an individual or disclosed to another organisation. These steps may include source review, freshness checks, correction handling and marking or restricting disputed information while it is assessed.
Depending on applicable law and Gala Intelligence's role in the processing, individuals may request correction, completion, updating or erasure of Personal Data relating to them. Gala Intelligence may take reasonable steps to verify identity and authority before acting on a request.
Where Gala Intelligence processes Personal Data solely on behalf of a business Customer, Gala Intelligence may refer the request to that Customer and provide reasonable assistance as required by the applicable contract and law. Product-specific privacy notices may provide additional correction, review, dispute or removal mechanisms.
Where a correction is established, Gala Intelligence takes appropriate action in the records it controls and communicates the correction to relevant recipients where required. Gala Intelligence may be unable to alter an independent external source directly, but this does not remove its responsibilities for its own processing.
The Gala Intelligence parent website and general B2B Services are intended for adults. For Indian use, a child is a person under 18. Any supported child or family feature is subject to the relevant product-specific notice and safeguards.
Before processing a child's Personal Data, Gala Intelligence obtains verifiable parental or lawful-guardian consent where required. Child tracking, behavioural monitoring and targeted advertising remain subject to applicable prohibitions and specific exemptions; parental consent alone does not override a prohibition.
Business Customers must not submit children's Personal Data unless the relevant processing is expressly supported and lawfully authorised. Where required safeguards cannot be met, the affected processing is not enabled.
Where a person with a disability has a lawful guardian authorised to act for them, Gala Intelligence verifies that authority and obtains the required consent. Disability alone is not treated as incapacity.
Depending on your location, the nature of the processing and applicable law, you may have rights concerning your Personal Data. These may include the right to:
Certain jurisdictions may provide additional rights relating to automated decision-making, information about sources or recipients, sale or sharing of Personal Data, targeted advertising, sensitive Personal Data, appeals or nomination.
To exercise a right, email privacy@galaintelligence.com with the relevant product, the account email, mobile number or other identifier concerned, the request you wish to make and a way to contact you. An account or paid subscription is not required.
Gala Intelligence uses proportionate verification and requests additional evidence only where necessary. Do not send passwords, OTPs, API keys or unnecessary identity documents. A representative must establish authority to act for you. Where Gala Intelligence acts solely on Customer instructions, it may refer the request to that Customer and provide appropriate assistance.
Where nomination rights apply, you may use the same email address to register, change or withdraw a nomination. Provide your relevant identifier, the nominee's name and contact details, and the scope of the nomination. Before acting on a nomination, Gala Intelligence verifies the nomination, the nominee's identity and the relevant death or incapacity. Nomination does not transfer account ownership.
Requests are handled within the applicable legal period. If a permitted extension is necessary, Gala Intelligence explains the reason and revised deadline. Verification requests do not automatically restart an applicable deadline. Requests are normally free; any legally permitted fee or refusal will be explained. Grievance and escalation arrangements appear in Section 18.
Gala Intelligence will not discriminate against an individual for exercising a privacy right where such discrimination is prohibited by applicable law.
Where applicable Indian privacy requirements are in force, individuals may exercise rights concerning information about processing, correction, completion, updating, erasure, grievance redressal and nomination, subject to applicable conditions.
Required consent notices are available in English or a language recognised for that purpose in India. Contact privacy@galaintelligence.com for assistance accessing a notice in your chosen language. Where applicable, Gala Intelligence recognises valid consent instructions communicated through an authorised consent-management service.
For processing based on consent obtained before new notice requirements take effect, Gala Intelligence provides the required updated notice within the applicable period.
Where Gala Intelligence acts as a Data Processor for a business Customer, the Customer remains the Data Fiduciary for Customer-controlled processing and Gala Intelligence will provide processor assistance as required by the applicable contract and law.
Where applicable European Economic Area, United Kingdom or Swiss privacy requirements apply to Gala Intelligence's processing, individuals may have rights including access, rectification, erasure, restriction, portability, objection and withdrawal of consent, together with rights relating to certain automated decisions and the right to complain to a competent supervisory authority.
Where Gala Intelligence relies on legitimate interests under applicable law, Gala Intelligence balances those interests against the rights and freedoms of affected individuals. Where Personal Data is obtained indirectly and Gala Intelligence acts as controller, Gala Intelligence will comply with applicable transparency requirements and available exceptions.
Where required for transfers to India or another non-adequate jurisdiction, Gala Intelligence will use applicable transfer safeguards such as approved contractual mechanisms or another lawful transfer basis.
If a U.S. state privacy law applies to Gala Intelligence and to the relevant processing, residents may have rights provided by that law, which can include rights to know/access, correct, delete, obtain a portable copy, opt out of certain sale, sharing, targeted advertising or profiling, limit certain uses of sensitive Personal Data, and appeal certain privacy decisions.
Where applicable law requires recognition of a valid opt-out preference signal or another rights mechanism, Gala Intelligence will implement the required process for processing to which that law applies.
If privacy or data-protection law in another jurisdiction applies to Gala Intelligence and grants additional mandatory rights or imposes additional obligations, Gala Intelligence will honour those rights and obligations to the extent required by applicable law.
To submit a grievance, explain the issue, identify the relevant Service and provide a contact address and any existing request reference. Include only information reasonably necessary to investigate the matter.
Gala Intelligence will respond to grievances within 90 calendar days of receipt, or sooner where required by applicable law. Where additional information or verification is reasonably necessary to process the grievance, Gala Intelligence may request proportionate information or evidence. Any verification process will be limited to what is reasonably necessary and will not be used to improperly delay the handling of a grievance.
If you are dissatisfied with the response, reply to the same address requesting review. You may also approach the competent authority through its published complaint mechanism, after completing any prior grievance process required for that complaint.
Gala Intelligence may update this Privacy Policy to reflect changes in Services, processing activities, security practices, business operations or applicable requirements. The last-updated date identifies the latest revision. Material changes are communicated through an appropriate channel, such as the relevant Service, website notice or registered email address. The communication identifies when the changes take effect and any action required from you. Advance notice is provided where required.
Where a new or materially different processing purpose requires fresh consent, Gala Intelligence obtains that consent before beginning the affected processing. Publication of an updated policy or continued use of a Service does not, by itself, replace required consent.