Regulatory Basis: This policy is framed in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the IT (Amendment) Act, 2008. We are committed to the highest standards of data protection.
1. Introduction
Panchtatvam Global Solutions Private Limited ("Company") recognises that the protection of personal data is a fundamental right and a critical business obligation. This Data Protection Policy sets out our principles, obligations, and procedures for the lawful, fair, and transparent processing of personal data.
2. Data Protection Principles
We adhere to the following data protection principles in all our data processing activities:
- Lawfulness, fairness, and transparency: Personal data is processed lawfully, fairly, and in a transparent manner
- Purpose limitation: Data is collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes
- Data minimisation: Only data that is adequate, relevant, and limited to what is necessary is collected
- Accuracy: Personal data is kept accurate and up to date
- Storage limitation: Data is kept in a form that permits identification for no longer than necessary
- Integrity and confidentiality: Data is processed with appropriate security to protect against unauthorised access, loss, or destruction
- Accountability: The Company is responsible for and able to demonstrate compliance with these principles
3. Roles and Responsibilities
3.1 Data Fiduciary
Panchtatvam Global Solutions Private Limited is the Data Fiduciary as defined under the DPDP Act, 2023. We determine the purposes and means of processing personal data.
3.2 Data Processors
Third-party service providers who process personal data on our behalf (e.g., cloud hosting, email services, payment processors) are Data Processors. We ensure all Data Processors are bound by appropriate data processing agreements.
3.3 Data Protection Officer
We have designated a Data Protection Officer (DPO) responsible for overseeing data protection compliance. Contact: [email protected]
4. Lawful Basis for Processing
We process personal data only where we have a lawful basis to do so:
- Consent: The data principal has given consent for a specific purpose
- Contractual necessity: Processing is necessary for the performance of a contract
- Legal obligation: Processing is required to comply with a legal obligation
- Vital interests: Processing is necessary to protect the vital interests of the data principal
- Legitimate interests: Processing is necessary for legitimate interests pursued by the Company, provided these are not overridden by the rights of the data principal
5. Data Security Measures
We implement appropriate technical and organisational security measures, including:
5.1 Technical Measures
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Multi-factor authentication for access to systems containing personal data
- Regular security patching and vulnerability assessments
- Intrusion detection and prevention systems
- Secure backup and disaster recovery procedures
- Access logging and audit trails
5.2 Organisational Measures
- Role-based access controls — data access is limited to authorised personnel on a need-to-know basis
- Employee training on data protection obligations and security awareness
- Data protection impact assessments (DPIAs) for high-risk processing activities
- Vendor due diligence and data processing agreements with all processors
- Clear desk and screen policies
- Incident response and breach notification procedures
6. Data Breach Management
In the event of a personal data breach:
- The breach is identified and contained as quickly as possible
- The DPO is notified immediately
- The breach is assessed for risk to data principals
- Where required by the DPDP Act, the Data Protection Board of India is notified within the prescribed timeframe
- Affected data principals are notified where the breach is likely to result in harm
- The breach is documented and a post-incident review is conducted
7. Data Retention and Deletion
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our retention schedule includes:
- Customer account data: Duration of account + 3 years
- Transaction records: 8 years (Income Tax Act / GST requirements)
- KYC records: 5 years after end of business relationship (PMLA)
- Employee records: As required by labour laws
- Marketing data: Until consent is withdrawn
Upon expiry of the retention period, personal data is securely deleted or anonymised.
8. Cross-Border Data Transfers
As an international trading company, we may transfer personal data outside India. Such transfers are made in compliance with the DPDP Act and applicable regulations, including:
- Transfers to countries notified by the Government of India as providing adequate protection
- Transfers under appropriate contractual safeguards
- Transfers necessary for the performance of international trade contracts
9. Rights of Data Principals
Under the DPDP Act, 2023, data principals have the following rights:
- Right to access: Obtain a summary of personal data held and processing activities
- Right to correction and erasure: Request correction of inaccurate data or erasure of data no longer needed
- Right to grievance redressal: Lodge a complaint with our Grievance Officer
- Right to nominate: Nominate another person to exercise rights in case of death or incapacity
To exercise these rights, contact: [email protected]
10. Third-Party Processors
We work with third-party processors for services including cloud hosting, email delivery, payment processing, and analytics. All processors are:
- Subject to due diligence before engagement
- Bound by data processing agreements that impose equivalent data protection obligations
- Prohibited from processing personal data for their own purposes
- Required to assist us in meeting our obligations to data principals
11. Policy Compliance and Enforcement
Compliance with this policy is mandatory for all employees and contractors. Violations may result in disciplinary action, up to and including termination of employment or contract. Serious violations may be reported to relevant authorities.
12. Contact
Data Protection Officer: [email protected]
Privacy queries: [email protected]
Post: Panchtatvam Global Solutions Pvt. Ltd., Plot No. 20, Block H-1/A, Sector 63, Noida, UP – 201301, India