1Purpose
This policy sets out how we handle personal data in line with applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023, and good industry practice.
2Data protection principles
We aim to process personal data:
- Lawfully, fairly, and transparently.
- For specified, explicit, and legitimate purposes.
- In a way that is adequate, relevant, and limited to what is necessary.
- Accurately, and kept up to date where needed.
- Securely, using appropriate technical and organisational measures.
- For no longer than necessary, as set out in our Data Retention Policy.
3Roles and responsibilities
Our team members who handle personal data are responsible for following this policy and any related internal procedures. Access to personal data is limited to staff who need it to perform their role.
4Data breach procedure
In the unlikely event of a data breach affecting personal data, we will assess the risk, take steps to contain and remediate it, and notify affected individuals and relevant authorities where required by law.
5Training and awareness
We provide guidance to our team on handling client and website visitor data responsibly, including secure storage, safe communication practices, and recognising phishing or social engineering attempts.
Questions about this policy?
Reach out to our Mumbai team and we will get back to you.