Still Loading?
Check your
internet connection
Kidding
It's probably
the ozone layer disruption
Kidding again
We're just here
to distract you
So you don't shift
to YouTube or TikTok
We don't judge see
Almost there Count till 10 Is your WiFi on?
Talk to us Follow us on Facebook Follow us on Instagram

1. ABOUT THIS POLICY

This Privacy Policy ("Policy") is issued by and applies to all Indian entities forming part of the Havas India group, as listed in Schedule 1 to this Policy (collectively, "Havas", "we", "us" or "our"). This is a single, group-wide Policy governing the data protection practices of all entities listed in Schedule 1. Each such entity is a separate legal entity and acts as an independent Data Fiduciary in respect of the personal data it processes; however, for the convenience of Data Principals and operational efficiency, all such entities adopt this common Policy. Havas is a leading global communications group providing integrated media, creative, and digital marketing services to its clients.

This Policy explains how we, acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), collect, use, process, store, share, and protect your digital personal data. This Policy applies to all individuals ("Data Principals") whose personal data we process in connection with our services, business operations, recruitment activities, and our digital properties.

By interacting with our websites, applications, and services, or by providing us with your personal data, you acknowledge that you have read and understood this Policy. This Policy is hosted at a single canonical URL and linked from the website of each Havas India entity listed in Schedule 1. It is available in English and in all languages specified in the Eighth Schedule to the Constitution of India, upon request.

2. SCOPE AND APPLICABILITY

This Policy applies to the processing of digital personal data:

  • collected within the territory of India in digital form, or in non-digital form and subsequently digitised; and
  • processed outside the territory of India, where such processing is in connection with any activity related to offering our services to individuals within India.

This Policy does not apply to personal data processed solely for personal or domestic purposes, or to personal data that has been made publicly available by you or as required by applicable law.

3. WHO WE ARE

Each Havas India entity listed in Schedule 1 operates as an independent Data Fiduciary in relation to the personal data it processes for its own purposes. Although this Policy is shared across the group, each entity's processing activities are separate and governed by its own internal data governance framework consistent with this Policy. Where any Havas entity processes personal data on behalf of a client, it may act as a Data Processor, and the client's own privacy policy will apply to such processing.

The common Grievance Officer for all Havas India entities, and the entity-specific Points of Contact for each affiliate, are set out in Section 15 of this Policy.

4. PERSONAL DATA WE COLLECT

We collect personal data in connection with our business activities. Depending on your relationship with us, we may collect the following categories of personal data:

4.1 Data collected from clients, prospective clients, and their personnel:

  • Name, designation, and employer details;
  • Contact information, including email address, telephone number, and business address;
  • Business correspondence and communication records;
  • Financial and billing information necessary for invoicing and payment; and
  • Any other data you voluntarily share with us in the course of our engagement.

4.2 Data collected from visitors to our websites and digital platforms:

  • Device identifiers, IP addresses, and browser information;
  • Browsing behaviour, page visits, and interaction data through cookies and similar technologies;
  • Information submitted through contact forms, enquiry pages, or subscription sign-ups; and
  • Location data, where permitted and disclosed at the point of collection.

4.3 Data collected from job applicants and prospective employees:

  • Name, contact details, and identification information;
  • Resume, work history, educational qualifications, and professional credentials;
  • Reference check information; and
  • Any other data provided during the recruitment process.

4.4 Data collected from consumers and audiences for client campaigns:

Where we manage data-driven marketing or audience analytics on behalf of our clients, we may process personal data of consumers and target audiences. In these instances, we typically act as a Data Processor on behalf of our client (the Data Fiduciary), and the client's own privacy policy will govern such processing. We only process such data under a valid contract with the client and in accordance with their instructions.

5. HOW WE USE YOUR PERSONAL DATA

We process your personal data only for lawful purposes and only where we have a valid legal basis to do so under the DPDP Act. Our purposes and legal bases are as follows:

5.1 With your Consent:

We will request your free, specific, informed, unconditional, and unambiguous consent before processing your personal data for the following purposes:

  • Sending you marketing communications, newsletters, and updates about our services and industry insights;
  • Setting cookies and similar tracking technologies on our digital platforms (other than strictly necessary cookies);
  • Conducting surveys, market research, and analysis that may involve your personal data; and
  • Any other processing activity for which we are required by law to obtain your consent.

You have the right to withdraw your consent at any time, with the same ease with which it was given. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal. Please see Section 9 for how to exercise this right.

5.2 For Certain Legitimate Uses (without requiring consent):

We may also process your personal data without obtaining explicit consent in the following circumstances, as permitted under Section 7 of the DPDP Act:

  • Performance of a contract: to provide our services to clients and to fulfil obligations arising from client engagements where you have voluntarily provided your data;
  • Employment and HR purposes: to manage employment relationships, maintain confidentiality of our business, prevent corporate espionage, and provide services or benefits to our employees;
  • Compliance with legal obligations: where we are required by law, court order, or regulatory obligation to process or disclose your personal data; and
  • Safety and emergency: to respond to a medical emergency or to provide assistance during a public health emergency or disaster.

6. NOTICE TO DATA PRINCIPALS

In accordance with Section 5 of the DPDP Act and Rule 3 of the DPDP Rules, we will provide you with a clear and plain language notice before or at the time of requesting your consent. Such notice will:

  • describe in an itemised manner the personal data we seek to process and the specific purpose(s) of such processing;
  • be understandable independently of any other information we provide; and
  • provide you with a specific communication link to exercise your rights, withdraw consent, and make a complaint to the Data Protection Board of India ("Board").

Where we have processed your personal data prior to the commencement of the DPDP Act, we will, as soon as reasonably practicable, provide you with the above notice and continue processing only if you do not withdraw consent.

7. SHARING OF PERSONAL DATA

We may share your personal data with third parties in the following circumstances:

  • Group entities: with other Havas group companies within India where necessary for the delivery of our services or for internal administrative purposes;
  • Service providers and Data Processors: with third-party vendors, technology providers, analytics companies, and other service providers who process personal data on our behalf under a valid contract that requires them to maintain appropriate security safeguards;
  • Clients: where we are engaged to manage campaigns on their behalf, we may share relevant audience data with the instructing client, acting in our capacity as a Data Processor;
  • Legal and regulatory disclosures: where required by applicable law, court order, or the direction of a competent authority or the Board; and
  • Corporate transactions: in connection with a merger, acquisition, or restructuring of our business, to the extent permitted by law.

We will ensure that any personal data shared with third parties is limited to what is necessary for the specified purpose, and that such parties maintain appropriate data protection standards.

8. TRANSFER OF PERSONAL DATA OUTSIDE INDIA

As part of our global operations, personal data may be transferred to, stored in, or processed by Havas group entities or service providers located outside India. Any such transfer will be subject to the restrictions and requirements prescribed by the Central Government under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules.

We will not transfer your personal data to countries that are notified by the Central Government as restricted jurisdictions for cross-border data transfers. We will implement appropriate contractual and technical safeguards when transferring data internationally, in accordance with the requirements specified by the Central Government from time to time.

9. YOUR RIGHTS AS A DATA PRINCIPAL

Under the DPDP Act (Sections 11 to 14) and the DPDP Rules, you have the following rights in respect of your personal data that we process:

9.1 Right to Access Information (Section 11)

You have the right to obtain from us, upon request:

  • a summary of the personal data we are processing about you and the processing activities undertaken;
  • the identities of all Data Fiduciaries and Data Processors with whom your personal data has been shared, along with a description of the data shared; and
  • any other information related to your personal data and its processing as may be prescribed.

9.2 Right to Correction, Completion, Updating, and Erasure (Section 12)

You have the right to request that we:

  • correct inaccurate or misleading personal data;
  • complete incomplete personal data;
  • update your personal data; and
  • erase your personal data, unless retention is necessary for the specified purpose or for compliance with applicable law.

9.3 Right to Withdraw Consent (Section 6(4))

Where consent is the basis of processing, you may withdraw your consent at any time. The ease of withdrawing consent will be comparable to the ease with which it was given. Withdrawal will not affect the lawfulness of any processing carried out prior to withdrawal, and we will, within a reasonable time, cease further processing based on that consent.

9.4 Right to Grievance Redressal (Section 13)

You have the right to readily available means of grievance redressal in respect of any act or omission by us regarding the processing of your personal data. We will respond to your grievance within 90 (ninety) days of receipt. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

9.5 Right to Nominate (Section 14)

You have the right to nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity.

How to exercise your rights: To exercise any of the above rights, please contact our Data Protection contact point at the details provided in Section 15. We will acknowledge your request and respond within the applicable statutory timeframe. We may require you to provide sufficient information to verify your identity before processing your request.

10. SECURITY SAFEGUARDS

In accordance with Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, we implement reasonable and appropriate technical and organisational measures to prevent personal data breaches and to protect your personal data. These measures include, at a minimum:

  • encryption, obfuscation, masking, or use of virtual tokens to protect stored and transmitted personal data;
  • access controls restricting access to personal data to authorised personnel only;
  • logging, monitoring, and regular review to detect and investigate unauthorised access;
  • data backup and business continuity measures to ensure continued availability;
  • retention of processing logs for a minimum period of one year; and
  • appropriate security provisions in contracts with our Data Processors.

11. PERSONAL DATA BREACH NOTIFICATION

In the event of a personal data breach, we will, in accordance with Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules:

  • notify you promptly through your registered contact details or user account, describing the nature, extent, and timing of the breach, its likely consequences for you, and the measures we are taking to mitigate risk; and
  • notify the Data Protection Board of India without delay and, in any event, provide a detailed report within 72 (seventy-two) hours of becoming aware of the breach.

12. RETENTION OF PERSONAL DATA

We retain personal data only for as long as is necessary to fulfil the specified purpose for which it was collected, or as required by applicable law. In accordance with Section 8(7) and (8) of the DPDP Act and Rule 8 of the DPDP Rules:

  • We will erase your personal data once the specified purpose is no longer being served, which will be deemed to occur if you have not approached us or exercised your rights for a continuous period of [THREE YEARS] (or such period as may be prescribed for our class of Data Fiduciary);
  • We will notify you at least 48 hours before erasure of your data, giving you an opportunity to re-engage or exercise your rights before the data is deleted; and
  • Processing logs and associated traffic data will be retained for a minimum period of one year from the date of processing for audit and security purposes, after which they will be erased unless further retention is required by law.

Where retention is required by applicable law (for example, under tax, accounting, or employment legislation), we will retain the relevant data for the period mandated by law.

13. CHILDREN'S DATA

Our services are not directed at children below the age of 18 years. We do not knowingly collect or process personal data of children without obtaining verifiable parental consent, as required under Section 9 of the DPDP Act and Rules 10 and 12 of the DPDP Rules.

We do not undertake any tracking or behavioural monitoring of children, nor do we direct targeted advertising at children. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will take immediate steps to erase such data.

For any digital platform or service that may be accessed by children, we will implement appropriate age-verification and parental consent mechanisms before processing a child's personal data.

14. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies on our websites and digital platforms. Cookies help us understand how users interact with our platforms and enable us to improve our services.

Categories of cookies we use:

Category Purpose Consent Required?
Strictly Necessary Essential for the operation of our platforms; cannot be disabled. No
Functional Remember your preferences and settings. Yes
Analytics Understand user behaviour and improve our platforms. Yes
Marketing / Targeting Deliver relevant advertising and measure campaign effectiveness. Yes

You can manage your cookie preferences through the cookie consent tool available on our website. Withdrawal of consent for non-essential cookies will not affect your access to the core functionality of our platforms.

15. CHANGES TO THIS POLICY

We reserve the right to update or modify this Policy at any time to reflect changes in law, regulatory requirements, or our business practices. Any material changes to this Policy will be communicated to you through our website and, where appropriate, by direct notification to your registered contact address. The revised Policy will take effect from the date specified in the updated version.

We encourage you to review this Policy periodically to remain informed about how we are protecting your personal data.

16. GOVERNING LAW AND JURISDICTION

This Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Any disputes arising in connection with this Policy shall be subject to the jurisdiction of competent courts in India and, where applicable, the Data Protection Board of India.

ANNEXURE A: NOTICE TO INTERNATIONAL WEBSITE VISITORS

For Data Principals Located Outside India

This Annexure applies to individuals accessing our global website (www.havas.com) or Havas' international digital platforms from territories outside India. This Annexure supplements, and does not replace, the main body of this Policy which governs the processing of data by Havas' Indian entities.

If you are located in a territory outside India and provide personal data to Havas India (for example, to engage Havas India for services), your personal data may be transferred to and processed within India. Such processing will be governed by the DPDP Act and this Policy.

If you are an individual located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with its own data protection laws, additional protections may apply to you under the laws of your jurisdiction. Havas' global privacy practices for non-India territories are governed by separate privacy policies published by the relevant Havas entity in those jurisdictions.

If you have questions about how Havas processes your data in a specific territory, please contact the Havas entity or representative responsible for your territory, or write to us at the address set out in Section 15 of this Policy.

ANNEXURE B: GLOSSARY OF KEY TERMS

Term Meaning under the DPDP Act 2023
Data Fiduciary Any person who alone or in conjunction with others determines the purpose and means of processing personal data.
Data Principal The individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian.
Data Processor Any person who processes personal data on behalf of a Data Fiduciary.
Personal Data Any data about an individual who is identifiable by or in relation to such data.
Processing Wholly or partly automated operations performed on digital personal data, including collection, storage, use, sharing, erasure, and all related activities.
Personal Data Breach Any unauthorised processing, accidental disclosure, acquisition, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity, or availability.
Consent Free, specific, informed, unconditional, and unambiguous agreement by the Data Principal to the processing of their personal data for a specified purpose.
Board The Data Protection Board of India, established under Section 18 of the DPDP Act.