Skip to content
GullySales

You can prove where every contact came from, and that you may write to them.

Consent capture, source records, retention rules and access control for your marketing data. Gully Sales sets the standard, corrects what is already stored, and hands your team a routine they can keep running.

  • Every contact record carries a source, a date and a permission.
  • Unsubscribe requests are actioned, not lost in somebody's inbox.
  • Your team knows which list may be used for which message.

Gully Sales Private Limited works with businesses across India. We are not a law firm and work alongside your own legal advisor.

In one paragraph

What is Marketing Data, Consent and Compliance Services?

Marketing data, consent and compliance is the control layer under your marketing: how permission is asked for and recorded, where each contact came from, what you may send them, how long you keep it, who can see it, and how unsubscribe and deletion requests are honoured. Gully Sales writes those rules, corrects what you already hold, and hands the routine to your team.

The problem

Nobody can say where half your marketing list came from.

Marketing lists in most Indian SMBs grow the way the business grows: an exhibition scan here, a website form there, a list someone bought and tried once, a WhatsApp group, three exports sitting on a laptop. Each addition made sense at the time. Nobody set out to build a list that cannot be explained. But when a customer asks how you got their number, or a platform asks you to show opt-in, or a large buyer asks how you store data, the answer has to come from records that were never kept.

You will recognise it as

  • You cannot say, for a given contact, which form or event they came from and on what date.
  • Unsubscribe requests arrive by reply email and get actioned by whoever happens to notice them.
  • The same list sits in a CRM, in a spreadsheet and in an agency account, all slightly different.
  • Nobody is sure whether the numbers you send WhatsApp messages to ever agreed to receive them.
  • A customer question about deleting their data has no owner and no process behind it.
  • The consent wording on your forms was written once, by whoever built the form.

What it costs the business

  • Decisions get made on a list nobody trusts, so campaigns go out narrower than they need to be, or wider than they should be.
  • Complaints and spam reports rise, which quietly damages the deliverability of every message you send afterwards.
  • One customer or buyer question about data handling stalls a deal while somebody hunts for an answer.
  • Sending accounts get restricted, and recovery takes weeks you had not planned for.

Why it persists. It persists because nothing breaks visibly. Data handling has no daily symptom; the list keeps sending and the reports keep arriving. It also sits between departments, so it belongs to nobody in particular: marketing owns the campaigns, sales owns the CRM, an agency owns the sending platform, and the owner assumes one of them has it covered. Most SMBs have nobody whose job description contains the words data or consent, so the work waits for a complaint to create it.

If it stays unresolved. Left alone, the gap grows with the list. Every month adds records nobody can explain and messages nobody agreed to receive. The clean-up gets larger, a restricted sending account gets more likely, and the first time it matters is usually a customer complaint, a platform block or a large buyer's vendor questionnaire. None of those arrive at a convenient moment.

What changes

What changes once permission is recorded properly.

In the first weeks

  • You know what marketing data you hold, where it sits and who can reach it.
  • Every form and capture point carries consent wording your team can stand behind.
  • Unsubscribe and deletion requests have a named owner and a working route.

In how the work runs

  • New records arrive with source, date and channel permission already attached.
  • Your team can tell in seconds which list may be used for which channel.
  • Agency and vendor access is listed, limited and reviewed.
  • Retention rules run to a schedule instead of by memory.

In sales and marketing

  • Campaigns go to people who agreed to hear from you, so replies and engagement improve.
  • Buyer and procurement questionnaires get answered from a document you already have.
  • Spend stops going to records that were never contactable in the first place.

In what management can see

  • A monthly data and consent report your directors can read in one page.
  • An audit trail showing, per record, how permission was obtained.

Over the longer term

  • Marketing data stays a business asset instead of an accumulating liability.
  • New tools and channels get added under a rule that already exists.

Gully Sales controls the rules, the records, the corrections and the routine. Whether a particular complaint, platform decision or legal outcome follows is outside our control, and we are not a law firm. We build the operational side and work alongside your legal advisor.

Who it is for

This fits businesses whose marketing list grew faster than its rules.

The businesses it suits

  • Businesses running email, SMS or WhatsApp marketing to a list built over several years.
  • Companies whose CRM, spreadsheets and agency accounts each hold a different version of the data.
  • Firms selling to larger buyers who now ask data-handling questions during vendor onboarding.
  • Businesses in healthcare, education, finance or any sector handling sensitive customer detail.
  • Owners who received a complaint, a platform warning or a deletion request and had no process.
  • Teams adding marketing automation who want the data rules settled before it scales.

What usually prompts the call

  • A sending account was restricted, or deliverability dropped without an obvious explanation.
  • A customer asked how you got their contact details and nobody had an answer.
  • A large buyer sent a vendor data questionnaire you could not complete.
  • You are moving to a new CRM or platform and must decide what to carry across.
  • An agency relationship is ending and you need your data back, intact and accounted for.

What Gully Sales does

The work, component by component.

Data map and permission review

We list every place marketing data enters, sits and leaves your business: website forms, landing pages, exhibition scans, WhatsApp enquiries, bought or shared lists, the CRM, spreadsheets, email and SMS platforms, and agency accounts. For each one we record what is collected, why, on what permission, and who can reach it.

Why it matters:
You cannot set rules for data you have not counted. The map turns a vague worry into a specific, finite list of things to fix.
You receive:
A marketing data map covering every capture point, store and recipient, with owners named.
Business value:
The size of the problem becomes known and finite, so the work can be planned rather than feared.

Consent capture and form wording

We rewrite the permission text on every form, landing page, chat widget and offline capture sheet so it says plainly what the person is agreeing to receive and from whom. Separate consent for separate purposes, no pre-ticked boxes, and a record written at the moment of capture: the wording shown, the time, the page and the channel.

Why it matters:
Permission that was never recorded cannot be produced later, and wording nobody reviewed is the wording you will be judged on.
You receive:
Approved consent wording for each capture point, plus the field specification that records it.
Business value:
Every new record arrives with a permission you can show, instead of one you have to assume.

Source and channel permission standard

One agreed way of recording where each contact came from and which channels they may be contacted on. Source, campaign, capture date, capture point and channel permissions become mandatory fields, with values chosen from a fixed list instead of typed freely by whoever enters the record.

Why it matters:
Freely typed sources produce twenty spellings of one exhibition and no way to segment safely afterwards.
You receive:
A field specification and value list applied across your CRM, forms and sending platforms.
Business value:
Segments get built on permission rather than guesswork, and reporting by source finally adds up.

Preference centre and opt-out handling

One route for people to change what they receive or stop hearing from you, wired to every channel you send on. Requests arriving by reply, phone or WhatsApp are logged into the same place, so somebody who opts out of one list is not still receiving from another.

Why it matters:
Opt-outs handled inside personal inboxes get missed, and a missed opt-out is the complaint that follows.
You receive:
A preference and unsubscribe route, plus the process for requests arriving by other channels.
Business value:
Somebody who asks you to stop actually stops, across every list and every platform you use.

Retention, deletion and data requests

How long each type of marketing record is kept, what happens at the end of that period, and what your team does when somebody asks for a copy of their data or its deletion. Written as a schedule and a short script, with a named owner and a response time you set yourselves.

Why it matters:
These requests arrive rarely and urgently, which is exactly the moment when improvising goes wrong.
You receive:
A retention schedule by record type, and a request-handling procedure with owner, route and log.
Business value:
A request that used to cause a scramble becomes a routine task with a record at the end of it.

Access, vendors and data sharing

Who inside your business can export the marketing list, and which agencies, freelancers and platforms hold a copy of it. We reduce standing access to the people who need it, agree what each vendor may do with the data, and set what happens to their copy when the relationship ends.

Why it matters:
Most SMB data leaves through an ordinary export by somebody who no longer needs that access.
You receive:
An access register, a vendor list with agreed handling terms, and an off-boarding step.
Business value:
Your list stops travelling further than you intended, and comes back when a vendor leaves.

Checklist, audit trail and team routine

The controls become a routine your team runs without us: a pre-send checklist before any campaign, a monthly data and consent review, and an audit trail that can show how any individual record was obtained. Short enough that people actually follow it.

Why it matters:
Rules written once and filed away change nothing; a checklist attached to the send changes the send.
You receive:
A campaign pre-send checklist, a monthly review format and an audit trail specification.
Business value:
The standard holds after handover, because it is part of sending rather than a separate task.

What you will have at the end.

  • A marketing data map: every capture point, store, platform and vendor, with a named owner.
  • Approved consent wording for every form, landing page and offline capture sheet.
  • A field specification covering source, capture point, capture date and channel permissions.
  • A permission status applied to your existing records, with unevidenced ones separated rather than quietly used.
  • A preference centre and unsubscribe route wired to the channels you actually send on.
  • A retention and deletion schedule by record type, agreed and dated.
  • A written procedure for access, copy and deletion requests, with owner and response route.
  • An access register and vendor handling list, including what happens when a vendor leaves.
  • A campaign pre-send checklist your team runs before every send.
  • A monthly data and consent review format, with the first one completed together.
  • A one-page answer sheet for buyer and procurement data questionnaires.
  • A recorded handover session for marketing, sales and whoever administers your platforms.

How it runs

The engagement, step by step.

  1. 1

    Audit and data map

    We go through every place marketing data enters and sits: forms, sending platforms, spreadsheets, the CRM and agency accounts. We record what is held, where it came from, who can reach it and what permission exists. We also walk your current form wording and unsubscribe route the way a customer would meet them.

    You provide:
    Access to your CRM, marketing platforms and website forms, plus a list of agencies or freelancers holding data.
    We produce:
    A marketing data map and an audit of capture points, permissions, access and gaps.
    Done when:
    You can see on one page everything you hold and every route it arrived by.
  2. 2

    Rules and wording

    We agree the standard: what permission each channel needs, what the consent wording will say, which fields become mandatory, how long each record type is kept, who may access what, and who owns each decision. Where your legal advisor wants to review wording, we prepare it in a form they can review quickly.

    You provide:
    A decision-maker for marketing, and your legal advisor's input where you want wording reviewed.
    We produce:
    Consent wording, field specification, retention schedule and access rules, written and agreed.
    Done when:
    The rules are signed off by your side, not merely proposed by ours.
  3. 3

    Correcting what you already hold

    We apply the standard backwards across existing records: source and permission filled in where they can be evidenced, records separated where they cannot, copies across systems reconciled to one version, and anything you have decided not to keep removed on your written instruction.

    You provide:
    Sign-off on how records with no evidence of permission should be treated.
    We produce:
    A corrected database with a permission status per record, and a log of what changed and why.
    Done when:
    Every remaining record carries a status you chose deliberately.
  4. 4

    Capture and opt-out build

    We update the live capture points so new data arrives correct: form wording and fields, source capture, the preference centre and unsubscribe route, and the routes for requests that arrive by reply, phone or WhatsApp. Then we test each one by submitting through it ourselves.

    You provide:
    Website and platform access, or your developer's time to apply the changes we specify.
    We produce:
    Updated capture points, a working preference centre, and a test record proving each route.
    Done when:
    An enquiry submitted today arrives with source, date and permission attached.
  5. 5

    Controls and handover

    We turn the rules into the routine your team runs: the pre-send checklist, the monthly review, the request-handling procedure and the access register. We walk marketing, sales and your platform administrator through each one using your own records rather than examples.

    You provide:
    The people who will run it, present for the handover session.
    We produce:
    Checklists, procedures, the monthly review format and a recorded handover session.
    Done when:
    Your team runs a full campaign send through the checklist without us in the room.
  6. 6

    Review and adjustment

    We check how the standard is surviving contact with real work: whether new records are arriving complete, whether opt-outs are being actioned across channels, whether the checklist is used or quietly skipped. Where a rule is being ignored, we usually change the rule rather than repeat the training.

    You provide:
    Continued access to the same systems, and an honest account of what is being skipped.
    We produce:
    A review against the opening baseline and a short list of adjustments.
    Done when:
    The controls fit the way your team actually works.

Ways to work with us

Choose how far you want the consent work taken.

Marketing data and consent audit

A review of what you hold, how it was captured and where it sits, ending in a written map, a gap list and a prioritised plan you can act on with us or without us.

Full standard and clean-up

The audit, plus the rules, the corrected database, updated capture points, the preference centre and handover to your team. The usual choice where a list has been running for years.

Capture and opt-out build

For businesses whose stored data is broadly sound but whose forms, source capture and opt-out routes are not. We fix the capture side and leave the historic database as it stands.

Ongoing review retainer

A recurring review after handover: the monthly data and consent check run with your team, and the standard extended as you add channels, tools or campaigns.

Why Gully Sales

What you are actually choosing when you choose us.

We build the operation, not an opinion.

Gully Sales is not a law firm and does not give legal advice. What we build is the operational side: capture, records, routes, access and routine. These are the things your advisor will ask whether you have.

Marketing and sales are treated as one system.

Consent breaks at the joins: a form that feeds a CRM that feeds an agency's sending platform. We work across marketing, sales and revenue operations, so the rules survive the handoffs between them.

Written for Indian SMB reality.

WhatsApp enquiries, exhibition scans, a list inherited from a previous agency, and a team with no data specialist in it. The controls we write assume that situation rather than a large enterprise's.

Your team keeps it after we leave.

Every rule becomes a checklist attached to work that already happens. We hand over the documents, the routines and a recorded session, and we would rather simplify a rule than watch it get ignored.

Nothing is changed without your sign-off.

Records with no evidence of permission are separated and shown to you before anything is suppressed or removed. You decide what happens to your own data, and we record what was decided and why.

Where it applies

The same service, in different businesses.

Manufacturing and industrial supply

The situation:
Years of exhibition scans, dealer lists and enquiry forms collected into spreadsheets held by different salespeople.
How it applies:
We map every list, agree the permission standard, reconcile the spreadsheets into the CRM, and set how future exhibition data is captured and recorded.
Likely benefit:
One accountable list instead of several private ones, and exhibition spend that produces records the whole team can use.

Healthcare and clinics

The situation:
Patient enquiry data and marketing data sit in the same systems, and staff are unsure what may be used for campaigns.
How it applies:
We separate the two, define what marketing may use, tighten who can export, and write the consent wording for appointment and enquiry forms.
Likely benefit:
Marketing runs on the data it is meant to use, and sensitive records stop travelling into campaign tools.

Education and training

The situation:
Enquiry lists arrive from portals, agents, referral sheets and walk-ins, and messaging goes to all of them by SMS and WhatsApp.
How it applies:
We record source and permission per channel, split the lists by what each person agreed to, and build one opt-out route across channels.
Likely benefit:
Messaging reaches people who chose to hear from you, and your sending accounts stay in better standing.

Real estate and construction

The situation:
Bought and shared lists have been used for broadcast campaigns, and complaints have started arriving from recipients.
How it applies:
We identify which records can be evidenced, stop the ones that cannot from being used, and rebuild capture so future enquiries carry consent.
Likely benefit:
Campaigns run on a smaller list you can stand behind, instead of a large one you cannot explain.

D2C and e-commerce

The situation:
Customer data flows between the store, an email tool, an SMS provider and two agency accounts, with nobody sure who holds what.
How it applies:
We map the flows, reduce standing access, agree what each vendor may hold, and set the off-boarding step for when a tool or agency changes.
Likely benefit:
Your customer list stops accumulating inside accounts you no longer control.

Financial and professional services

The situation:
Larger clients send vendor data questionnaires during onboarding, and answering them takes days of internal chasing.
How it applies:
We assemble the data map, access register and retention schedule into one answer sheet, kept current through the monthly review.
Likely benefit:
Questionnaires get answered from an existing document, so onboarding stops stalling on paperwork.

Questions buyers ask

Before you enquire, the answers you will want.

What information and internal involvement does this need from us?

We need access to your CRM, marketing platforms and website forms, plus a list of agencies or freelancers holding a copy of your data. From your side, one decision-maker for marketing and whoever administers your platforms. Expect a few working sessions: one to walk through the audit, one to agree the rules, and one for handover. Most of the effort is ours. The decisions have to be yours.

How long does an engagement like this take?

It depends on how many systems hold your data and whether the historic database is in scope. A single platform with tidy capture points is a short piece of work. Five systems, an inherited list and a vendor exit take considerably longer. We give you a scoped plan after the audit rather than before it, because guessing at the size of a database nobody has counted helps nobody.

Is Gully Sales giving us legal advice on data protection?

No. We are not a law firm and we do not issue legal opinions or certifications. What we build is the operational side: what is captured, how permission is recorded, who can access the data, how long it is kept and how requests are handled. Many businesses have their own advisor review the consent wording we prepare, and we write it in a form that makes that review quick.

What happens to records where we cannot show consent?

We separate them rather than quietly deleting them or quietly using them. You then decide: suppress them from marketing, attempt a re-permission message where that is appropriate for the channel, or remove them. Whatever you choose is recorded with the date and the reason, so the decision can be explained later. We never remove data from your systems without written instruction from you.

What inputs should we have ready before we start?

Login access to your CRM and marketing platforms, a list of your website forms and landing pages, any offline capture sheets your team uses, and the names of vendors or agencies holding your data. If lists are sitting on individual laptops, gathering them is usually the first useful task. Nothing needs to be tidy beforehand, because untidy is exactly what the audit is for.

How is success measured on this work?

Against the baseline recorded before anything changes. The main figures are the share of records carrying a source and an evidenced permission, how quickly opt-out requests are actioned across channels, how many campaigns clear the pre-send checklist without rework, and how long it takes to answer a buyer's data questionnaire. Bounce and complaint rates on sends are watched alongside them.

What does this work not cover?

Legal opinions, certifications and representation are excluded, as is anything covering financial, payroll or product data outside marketing. We do not audit your IT security or configure your network. Content production, campaign management and paid media buying are separate services. Where a change needs your website developer, we specify it precisely, but we do not rebuild your website.

Will this make our marketing list smaller?

Often it will, and that is usually the point. A list carrying people who never agreed to hear from you costs money to message, produces complaints, and drags down the deliverability of everything else you send. A smaller permissioned list generally performs better for each message sent. We show you the numbers before anything is suppressed, and the decision stays yours.

3 more questions

We use WhatsApp and SMS heavily. Does this cover those channels?

Yes. Channel permission is recorded separately for email, SMS, WhatsApp and phone, because agreeing to one is not agreeing to all of them. Opt-out routes are built per channel and connected, so somebody who stops on WhatsApp is not still receiving SMS. We also record what each platform's own sending rules require of you and reflect that in the capture wording.

Can you work alongside our existing agency?

Yes, and it is common. The agency usually holds part of the data and runs part of the sending, so they belong in the audit and the handover. We set what they may hold and do, and what happens to their copy if the relationship ends. We do this without taking over their campaign work, unless you separately ask us to.

What if a customer asks us to delete their data?

After this work there is a written procedure: a named owner, a route for the request to reach that person, a checklist covering every system holding the record, a log entry, and a reply back to the customer. Before the work, most SMBs handle this by asking around the office. The procedure matters more than the software, because these requests are rare and arrive urgently.

Talk to us

Find out what your marketing list can and cannot be used for.

It is a conversation about how your marketing data is captured and held today, not a sales pitch. If your capture points and opt-out routes are already in order, we will tell you so.

  • No obligation and no sales script
  • A reply from someone who does the work
  • Your details are never sold or shared

Your details are used only to reply to this enquiry. We do not add enquirers to marketing lists without asking, we do not share your information with third parties, and you can ask us to delete it.

Protected by reCAPTCHA — Google’s privacy policy and terms apply.

Get a free audit of how you sell, and a scored report of where the work is.

Book a free audit