- Last updated: September 27, 2026
- For readers in the EU, EEA and UK
- Requests are free
If you’re in the European Union, the wider European Economic Area or the United Kingdom, the GDPR and the UK GDPR give you real control over your personal data. This page explains what DroidCrunch does with that data, which rights you have and exactly how to use them.
The short version
- DroidCrunch is the data controller for personal data collected on droidcrunch.com.
- You can access, correct, delete, restrict, move or object to the use of your data, and withdraw consent at any time.
- Requests are free, and we answer within one month.
- One email starts the process: [email protected] with “GDPR request” in the subject line.
- You can complain to your data protection authority at any time, though we’d welcome the chance to fix things first.
Who is responsible for your data
The controller of your personal data is DroidCrunch (droidcrunch.com), an independent publication run by Lokesh Kapoor in India. You can reach us at [email protected].
Our processing is small in scale and doesn’t involve sensitive categories of data, so we haven’t appointed a Data Protection Officer. Lokesh handles privacy matters personally, which also means your request goes straight to someone who can act on it.
What we process and why
The GDPR requires a legal reason, called a lawful basis, for every use of personal data. These are ours:
| Activity | Personal data | Lawful basis | Kept for |
|---|---|---|---|
| Running and securing the site | IP address, browser details, pages requested | Legitimate interests: keeping the site available and safe, Art. 6(1)(f) | Short-lived logs, rotated automatically |
| Analytics | Pages viewed, device, approximate location, cookie IDs | Legitimate interests: understanding which content helps readers, Art. 6(1)(f) | Up to 14 months |
| Affiliate click tracking | IP address, device details, referring page, visitor ID | Legitimate interests: measuring and verifying the referrals that fund the site, Art. 6(1)(f) | While useful for reporting and checking partner statements |
| Comments | Name, email, website, comment, IP address | Consent, given with the checkbox on the comment form, Art. 6(1)(a) | While the comment is published |
| Newsletter | Name, email, signup details, email activity | Consent, Art. 6(1)(a) | Until you unsubscribe |
| Enquiries and partnerships | Contact details and messages | Legitimate interests, Art. 6(1)(f), or steps before a contract, Art. 6(1)(b) | As long as the conversation needs, longer if the law requires |
| Spam prevention | Device and interaction data, through Google reCAPTCHA | Legitimate interests: protecting our forms, Art. 6(1)(f) | Handled by Google |
| Tax and accounting records | Business contact and payment details for partnerships | Legal obligation, Art. 6(1)(c) | As long as tax law requires |
Where we rely on legitimate interests, we’ve weighed our needs against your rights and kept the data to a minimum. You can object to any of these uses at any time, as explained below. Our Privacy Policy describes each activity in full.
Your rights under the GDPR
These rights apply to readers in the EU and EEA under the GDPR, and in the UK under the UK GDPR.
Access
Ask whether we hold personal data about you, get a copy, and learn how we use it. (Article 15)
Rectification
Have inaccurate data corrected or incomplete data completed, such as a misspelled name on a comment. (Article 16)
Erasure
Ask us to delete your data, such as a comment, your newsletter record or a message you sent. We’ll do it unless the law requires us to keep it. (Article 17)
Restriction
Ask us to pause using your data while you contest its accuracy or our reasons for using it. (Article 18)
Portability
Receive data you gave us, such as your comments or newsletter details, in a common machine-readable format. (Article 20)
Objection
Object to uses based on legitimate interests, including analytics and click tracking. We’ll stop unless we have compelling grounds to continue. (Article 21)
Withdraw consent
Withdraw consent at any time, for example by unsubscribing. It doesn’t affect anything done before you withdrew. (Article 7)
Automated decisions
We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects. (Article 22)
How to make a request
- Email [email protected] with “GDPR request” in the subject line.
- Tell us which right you want to use, and anything that helps us find your data: the email address you used, roughly when you commented or subscribed, or the page involved.
- Send it from the email address involved if you can. We’ll use it to confirm the data is yours and only ask for more if we can’t verify you another way. We won’t ask for ID documents unless there’s genuinely no alternative.
- We’ll respond within one month. If a request is unusually complex, we can extend that by up to two more months, and we’ll tell you why within the first month.
Requests are free. We may only charge a reasonable fee, or refuse, if a request is clearly unfounded or excessive, such as the same request repeated again and again, and we’d explain our reasons.
Some things you can do yourself right now: unsubscribe with the link in any newsletter, delete our cookies in your browser settings, or block Google Analytics with Google’s Analytics opt-out add-on.
Objecting to analytics and click tracking
Analytics and affiliate click tracking rely on legitimate interests, so you can object to both. The quickest ways:
- Analytics: block cookies for droidcrunch.com in your browser, or install Google’s Analytics opt-out add-on.
- Affiliate clicks: visit a product’s website directly instead of using our link, so no click is recorded.
- Past records: email us your IP address, or roughly when you clicked, and we’ll delete matching click records.
International transfers
DroidCrunch is run from India, and our website server is in the United States. The European Commission hasn’t recognised India as providing adequate protection, and US transfers are covered by the EU-U.S. Data Privacy Framework only for companies certified under it.
When our service providers transfer EU or UK personal data, they use recognised safeguards: the European Commission’s Standard Contractual Clauses, the UK’s International Data Transfer Addendum, or certification under the EU-U.S. Data Privacy Framework and its UK extension. Ask us, and we’ll tell you which safeguard applies to a specific provider.
Complaining to a regulator
If you think we’ve mishandled your data, please tell us first. Most problems can be fixed with one email. You also have the right to complain to a data protection authority, usually in the country where you live, work or where the problem happened:
- EU and EEA: find your national authority on the European Data Protection Board’s list of members.
- United Kingdom: contact the Information Commissioner’s Office (ICO).
If something goes wrong
If a personal data breach is likely to put your rights at risk, we’ll report it to the relevant supervisory authority within 72 hours of becoming aware of it, where the law requires. If the risk to you is high, we’ll also tell you directly and explain what you can do to protect yourself.
Make a GDPR request
Email [email protected] with “GDPR request” in the subject line. We’ll confirm we’ve received it and answer within one month.