Privacy at a Glance
No User Registration Required
You can read all 44 sections, explore all 100 guides, and use all 16 interactive tools completely anonymously without creating an account.
Stateless Tool Computation
Questionnaire answers, compliance checklists, and assessment scores are computed in your browser or in transient memory—never saved to our database.
Zero Tracking Pixels
We do not load Google Analytics, Meta Pixel, commercial ad networks, or behavioral fingerprinting scripts on any public page.
Minimal Functional Storage
Browser LocalStorage is used strictly to remember your light/dark theme preference. Session cookies are restricted to authenticated system administrators.
Scope & Purpose
This Privacy Policy governs the processing of information on DPDP Compliance Hub ("the Platform", "we", "us", or "our"), accessible at https://indiandpdp.com. This policy articulates our practices regarding the collection, handling, storage, and protection of information in alignment with the Digital Personal Data Protection Act, 2023 (DPDPA) and prevailing Indian digital data standards.
Our core objective is to deliver authoritative, educational, and decision-support materials on data protection law without collecting unnecessary personal identifiers from visitors.
Information We Explicitly Do NOT Collect
Unlike conventional SaaS platforms, DPDP Compliance Hub does not operate consumer user account portals for public browsing. We explicitly do NOT collect:
- Account Credentials: No public user registration, username creation, password hashes, or social login credentials.
- Financial & Payment Identifiers: No credit card numbers, debit cards, UPI IDs, billing addresses, or banking details (the entire educational portal is freely accessible).
- Sensitive Personal Data: No biometric identifiers, health records, genetic data, or religious/caste classifications.
- Behavioral Profiling Data: No cross-site browsing history, device fingerprinting graphs, or ad-targeting psychographic profiles.
Interactive Tools & Assessment Processing Architecture
DPDP Compliance Hub provides 16 specialized decision-support tools (e.g., DPDP Applicability Evaluator, Readiness Assessment, Notice Generator, DPIA Calculator, Vendor Evaluator).
When you complete questionnaires in our tools, your responses and organization parameters are never written to any database table. All calculations are executed dynamically in client-side JavaScript or via stateless server-side computation in transient memory.
Once you close or refresh your browser tab, your assessment selections and questionnaire answers are instantly cleared from memory.
On-Demand PDF Generation & Ephemeral Processing
Several interactive tools permit visitors to download a structured PDF report of their assessment results or generated privacy notice drafts.
When a PDF is requested via POST request:
- The parameters submitted in the request payload are processed in a temporary PHP memory buffer (
php://temp). - The binary PDF stream is returned directly to your browser with HTTP header
Content-Disposition: attachment. - The memory buffer is destroyed immediately upon completion of the HTTP stream. No PDF files or questionnaire inputs are saved to disk or retained in persistent server storage.
Technical Server Telemetry & Error Logging
In conformity with standard network security standards and Section 8(5) technical safeguards, our web hosting infrastructure automatically logs basic technical request metadata:
- Internet Protocol (IP) address of the requesting client;
- HTTP request timestamp, URI requested, and HTTP response code;
- Browser User-Agent header (for device layout compatibility and bot detection);
- Referring URL headers.
These technical logs are maintained strictly for cybersecurity defense, DDoS mitigation, rate-limiting, and error debugging. Logs are rotated on a standard 30-day retention schedule and are never combined with personal identities.
Contact Form & Voluntary Communications
If you voluntarily contact us via our /contact page or editorial desk email, we receive the details you submit:
- Full Name / Contact Name;
- Business or Personal Email Address;
- Subject and Message Body (including any citations or feedback).
Purpose Limitation: Contact information is utilized strictly to evaluate and respond to your inquiry, correct reported citation errors, or answer platform feedback. We never sell, lease, or distribute contact form submissions to commercial marketing firms.
Zero Third-Party Advertising & Tracking Trackers
DPDP Compliance Hub does not engage third-party behavioral advertising networks, programmatic ad exchanges, or commercial analytics trackers. Specifically:
- No Google AdSense or programmatic display banner networks;
- No Meta Pixel / Facebook conversion tracking tags;
- No commercial data aggregator SDKs or cross-site tracking beacons.
Technical & Organizational Data Security Controls
In alignment with reasonable security safeguards prescribed under Section 8(5) of the DPDP Act, 2023:
- Encryption in Transit: All HTTP traffic is enforced via HTTPS utilizing TLS 1.3 encryption protocols.
- Strict Server Privileges: Database access is confined to localhost connections with parameterized SQL queries preventing SQL injection.
- Zero Database Shell Execution: The platform codebase contains zero shell-execution endpoints accessible via client browsers.
External Links to Official Government Portals
Our platform includes direct reference links to official Government of India portals (e.g., meity.gov.in, egazette.gov.in, legislative.gov.in). When you navigate to an external website via an outbound link, your interaction is governed solely by the privacy practices of that respective government agency. We encourage visitors to review the privacy statements of all third-party sites.
Children's Privacy (Section 9 Compliance)
DPDP Compliance Hub is an educational and enterprise compliance resource designed for privacy professionals, legal practitioners, organizations, and adult data principals. We do not intentionally solicit or process personal data from individuals under 18 years of age.
Data Principal Rights Under the DPDP Act, 2023
If you have communicated with us via our contact channels, you retain statutory rights under Chapter III (Sections 11–14) of the DPDP Act:
- Right to Access Information (Section 11): Right to obtain a summary of personal data held regarding your contact inquiries.
- Right to Correction & Erasure (Section 12): Right to request correction of inaccurate contact records or erasure of historical inquiry messages.
- Right of Grievance Redressal (Section 13): Right to have grievances addressed by our designated Privacy Contact.
- Right to Nominate (Section 14): Right to designate a nominee to exercise rights in the event of death or incapacity.
Modifications & Version History
We may periodically update this Privacy Policy to reflect enhancements in platform functionality, revised statutory rules, or DPBI guidelines. When revisions occur, the updated policy will be published with a revised "Effective Date" at the top of this page.
Grievance Redressal & Privacy Contact
For inquiries, clarifications, or requests concerning this Privacy Policy, please reach out to our platform administration desk:
Platform: DPDP Compliance Hub
Designation: Data Protection & Editorial Desk
Online Portal: Contact Form / Grievance Redressal
Jurisdiction: Republic of India