Scope and application
This policy applies to ByteWeb IT Solutions Private Limited, a company incorporated under the Companies Act, 2013 and having its registered office at Vadodara, Gujarat, India, and to all digital personal data processed by it, whether collected through its website, in the course of a client engagement, or in the ordinary conduct of its business.
The Act applies to digital personal data processed within India, and to processing outside India where it relates to offering goods or services to Data Principals in India. Where we process the personal data of individuals protected by other regimes, such as the UK GDPR or the GDPR, we apply those requirements in addition to this policy and not instead of it.
The words the Act uses. A Data Principal is the individual the personal data relates to. A Data Fiduciary decides why and how personal data is processed. A Data Processor processes personal data on a Data Fiduciary's instructions. A Consent Manager is a body registered with the Data Protection Board of India through which a Data Principal may give, manage and withdraw consent.
The two capacities in which we act
As a Data Fiduciary
We are the Data Fiduciary for personal data we decide the purpose of: enquiries sent through our website, subscriptions to our writing, correspondence with prospective clients, job applications, and the records we keep about the people we contract with. For that data, the obligations in this policy are ours directly.
As a Data Processor
When we design, build, migrate or support a system for a client, the client is the Data Fiduciary for the personal data held in it, such as their customers, subscribers or order history. We are their Data Processor. We process that data only under a contract with the client and only on their documented instructions, and we do not determine the purpose of it. Clause 9 sets out what we undertake in that capacity.
Notice
Before we seek consent, and at the point personal data is collected, we give the Data Principal a notice that states in clear and plain language:
- the personal data we propose to collect, itemised
- the purpose for which it will be processed
- how the Data Principal may exercise their rights under the Act
- how the Data Principal may withdraw consent, and that withdrawal is as easy as giving consent was
- how to make a complaint to the Data Protection Board of India
Our notices are available in English. Where a Data Principal asks for a notice in any language specified in the Eighth Schedule to the Constitution of India, we provide it.
Lawful basis for processing
We process digital personal data only for a lawful purpose, and only on one of the following bases:
- Consent. Freely given, specific, informed, unconditional and unambiguous, signified by a clear affirmative action, and limited to the personal data necessary for the stated purpose. Where you send us an enquiry or subscribe to our writing, this is the basis we rely on.
- Certain legitimate uses. Where the Act permits processing without consent, including where a Data Principal has voluntarily provided their personal data for a specified purpose and has not indicated that they object, and where processing is necessary to comply with a legal obligation or a judgment.
We do not rely on a general or bundled consent, and we do not make access to our website conditional on consent to processing that is not necessary for the purpose you came for.
Withdrawal of consent
A Data Principal may withdraw consent at any time, and the effort required to do so will never be greater than the effort required to give it. On withdrawal we stop the processing that relied on that consent within a reasonable time, and we cause our Data Processors to do the same, unless the law requires us to retain the data.
Withdrawal does not make unlawful any processing carried out before it, and does not affect processing we are required to continue under another law.
Purpose limitation, accuracy and erasure
We collect only the personal data necessary for the stated purpose. We take reasonable steps to ensure that personal data we process is complete, accurate and consistent, particularly where it may be used to make a decision affecting the Data Principal or is disclosed to another Data Fiduciary.
We erase personal data, and cause our Data Processors to erase it, as soon as the Data Principal withdraws consent or it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with a law in force.
Rights of Data Principals
A Data Principal whose personal data we hold as Data Fiduciary has the right to:
- Access information about processing. A summary of the personal data being processed, the processing activities undertaken, and the identities of other Data Fiduciaries and Data Processors with whom the data has been shared, together with a description of what was shared.
- Correction, completion, updating and erasure of their personal data.
- Grievance redressal. A readily available means of raising a grievance with us, which must be exhausted before approaching the Data Protection Board of India.
- Nomination. To nominate another individual to exercise these rights on their behalf in the event of death or incapacity.
To exercise a right, write to [email protected]. We respond within the period prescribed under the Act and the rules made under it. We may ask for information reasonably necessary to verify identity before acting, and we will not charge a fee.
Duties of Data Principals
The Act also places duties on Data Principals: to comply with applicable law when exercising rights, not to impersonate another person, not to suppress material information when providing personal data, not to register a false or frivolous grievance, and to furnish only information that is authentic when seeking correction or erasure.
Personal data of children and persons with disability
Our website and services are directed at businesses, not at children. Before processing the personal data of a child or of a person with a disability who has a lawful guardian, we obtain the verifiable consent of the parent or lawful guardian as the Act requires.
We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. We do not knowingly process personal data likely to cause a detrimental effect on the well-being of a child. If we learn that we hold a child's personal data without the required consent, we erase it.
Our undertakings as a Data Processor
Where we process personal data on behalf of a client, we undertake that:
- we process only under a valid contract with the client and only on their documented instructions
- we do not engage a sub-processor without the client's authorisation, and any sub-processor is bound to terms no less protective than ours
- we request the least access that allows the work to be done, and use anonymised, masked or test data in place of live records wherever the work permits
- our personnel are bound by confidentiality obligations that survive the engagement
- we assist the client in responding to requests from their Data Principals
- we notify the client without undue delay on becoming aware of a personal data breach affecting their data
- on completion or termination we return or erase the personal data, and any copies of it, at the client's direction, unless retention is required by law
Nothing in a client engagement makes us the Data Fiduciary for that client's data, and we do not use it to improve our own services or for any purpose of our own.
Security safeguards
We implement reasonable security safeguards to prevent a personal data breach, taking account of the nature of the data and the risk involved. These include encryption of data in transit, access control on a need-to-know basis, individual credentials with multi-factor authentication where the system supports it, logging of access to production systems, and review of access when a person's role changes or they leave.
We require our Data Processors and sub-processors to maintain comparable safeguards, and our contracts say so.
Personal data breach
On becoming aware of a personal data breach we contain it, assess what data and which Data Principals are affected, and record the incident. We give intimation of the breach to the Data Protection Board of India and to each affected Data Principal in the form and within the time prescribed under the Act and the rules made under it. Where we are acting as a Data Processor, we notify the client without undue delay and support their own notification obligations.
Retention
We retain personal data only for as long as the specified purpose requires, or for as long as a law in force requires us to keep it, whichever is longer. Records we are obliged to keep for company, tax and accounting purposes are retained for the statutory period and then erased. Where the purpose has been served and no retention obligation applies, we erase the data and cause our Data Processors to do the same.
Transfer of personal data outside India
We may transfer personal data outside India, for example where a service we rely on stores data abroad. We do not transfer personal data to any country or territory that the Central Government restricts for that purpose by notification, and we take reasonable steps to see that transferred data continues to be protected to the standard described in this policy. Where a client's contract restricts the location in which their data may be held, we observe that restriction.
Status under the Act
We have not been notified by the Central Government as a Significant Data Fiduciary. If we are so notified, we will appoint a Data Protection Officer based in India and answerable to our board, appoint an independent data auditor, carry out periodic Data Protection Impact Assessments and audits, and update this policy to say so.
Grievance redressal
If you are not satisfied with how we have handled your personal data or your request, raise a grievance with us first. We acknowledge every grievance on receipt and respond within the period prescribed under the Act.
- Email: [email protected], marked for the attention of the Grievance Officer
- Phone: +91 85110 00222
- Address: The Grievance Officer, ByteWeb IT Solutions Private Limited, Vadodara, Gujarat, India
If your grievance remains unresolved after you have exhausted this route, you may complain to the Data Protection Board of India in the manner provided under the Act.
Governing law and jurisdiction
This policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the rules made under it. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the courts at Vadodara, Gujarat, India.
Review of this policy
This policy shall be reviewed at least once annually, and upon any material amendment to the said Act, the rules made thereunder, or the processing undertaken by the Company. The effective date and the date of last revision are stated at the head of this document. Related documents: the Company's privacy policy, its Terms & Conditions, and its refund and cancellation policy.