DPDP transparency notice

Privacy, in plain language.

Notice version dpdp-2026-07-13. Effective 13 July 2026.

Who is responsible

AshwiniSysTech is the Data Fiduciary for personal data collected on this website and in the client portal. Questions and grievances may be sent to privacy@ashwinisystech.com. We aim to respond to grievances within 90 days.

What we process and why

Business enquiriesFull name, work email, company, service interest and the message you choose to send.Purpose: respond to the enquiry you requested. Processing is based on your specific consent.
Client portalName, work email, organisation, assigned role/modules, login time and account status.Purpose: provision and operate the contracted service and enforce access control.
Security recordsPseudonymised login identifier, IP address, browser/user-agent, authentication outcome and auditable administrative actions.Purpose: prevent, detect, investigate and remediate unauthorised access and maintain service continuity.
Rights and grievancesYour identity/contact details, request, verification status, resolution and any nominee details you voluntarily provide.Purpose: verify and fulfil your DPDP rights and maintain compliance evidence.
On-device preferencesTheme is necessary display storage. Optional client-portal preferences use local storage only after Accept all.Purpose: remember your display choice and optional portal preferences. Preference values are not sent to our server and are cleared when optional storage is denied.

We do not ask for payment-card data, government identity numbers, precise location, health information, or other unrelated data through this website. Please do not place such information in free-text fields.

Sharing, processors and transfers

Access is limited by role and organisation. We disclose data only to authorised personnel and service providers needed for hosting, database, security, backup or communication services under confidentiality and security obligations, or where disclosure is required by law. Cross-border availability, if any, is controlled through the processor register and remains subject to restrictions notified by the Central Government. Contact the privacy address for the current processor and hosting-location summary relevant to your data.

Retention and protection

Business enquiries are normally retained for 365 days and then erased after closure unless law, contract or an active dispute requires a documented longer period. Security and processing logs are retained for at least one year. Closed rights requests and withdrawn consent evidence are retained for a documented compliance period and then purged. Account data is retained while the service is active and thereafter only as required for security, legal or contractual obligations.

Controls include AES-256-GCM encryption for public-form and rights-request content, password hashing, HttpOnly/Secure cookies, access control, input validation, rate limits, origin checks, audit logging, backups, retention automation and incident workflows. No security measure eliminates all risk.

Children

This is a business-to-business service for adults. We do not knowingly offer accounts or enquiry services to persons under 18 and ask users to confirm adulthood without collecting a date of birth or identity document. If you believe a child’s data was provided, submit an erasure grievance below.

Cookies and visit measurement

On your first visit, you can Accept all, Deny optional, or Use necessary only. Necessary storage remembers your choice, theme and secure portal authentication. It cannot be disabled through our panel because the requested features would not work reliably.

Optional analytics is off by default. If you accept it, we create a random HttpOnly visitor identifier and record page path, visit time, referrer origin, and broad browser/device class. We do not store an analytics IP address, precise location, advertising identifier or fingerprint. Analytics events are retained for no more than 365 days. Consent evidence is retained for the documented compliance period.

Use the “Cookie choices” button at the bottom-left of any page to withdraw or change consent with the same ease. Denying optional storage clears the analytics identifier and optional on-device portal preferences. The Drishti map demo necessarily requests Leaflet/Carto map resources when that demo is opened; those providers receive ordinary connection information such as IP address.

Your data rights

You may request access to a summary of your personal data and processing, correction or completion, erasure when retention is no longer required, withdrawal of consent with comparable ease, grievance redressal, or nomination of another individual to exercise rights in the event of death or incapacity. Portal users can also obtain an authenticated data export from their account.

We verify identity before disclosing or changing personal data. If you are dissatisfied after using our grievance process, you may complain to the Data Protection Board of India using the official channel made available by the Board.