Privacy Charter
Gyanotsava (“the Sanctuary,” “we,” “us,” or “our”) is committed to the sacred principles of personal trust, confidentiality, and institutional integrity. This Privacy Charter is drafted in strict compliance with the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023 of the Parliament of India) and the Information Technology Act, 2000. It sets forth our duties as a Data Fiduciary and outlines the sovereign statutory rights of our guests, clients, and visitors as Data Principals.
1. Legal Framework & Data Fiduciary Identification
Under Section 2(i) of the DPDP Act 2023, Gyanotsava is the designated Data Fiduciary determining the purpose and means of processing digital personal data. Any person who engages with our acoustic sessions, workshops, community gatherings, or digital platform is designated as the Data Principal under Section 2(j).
Entity Name: Gyanotsava Learnning Hub Pvt Ltd
Registered Address: # 213, 2nd Floor, Ramanashree Arcade, No.18 MG Road, Bangalore-560001, Karnataka, India
Contact: support@gyanotsava.com | +91 7353965156 / +91 9513365531
Official Website: www.gyanotsava.com
Jurisdiction: Republic of India (Governed by DPDP Act, 2023)
2. Personal Data We Collect & Grounds of Processing
In strict alignment with the principle of Data Minimization (Section 6(1)), we collect only the digital personal data that is strictly necessary for the performance of our wellness offerings and administrative statutory obligations:
- Contact & Identity Data: Full Name, Email Address, and WhatsApp / Mobile Phone Number provided during inquiry, concierge booking, or event ticketing.
- Session Intention Notes: Personal wellness reflections, meditation goals, or acoustic preferences voluntarily shared to personalize your sound immersion.
- Tax & GST Identifiers (Commercial B2B): GSTIN and Company Entity Name where an official Tax Invoice / Input Tax Credit is requested.
- Technical & Transaction Metadata: Cryptographic Razorpay Order IDs, Payment Verification Signatures, and server access timestamps necessary to prevent fraud and maintain operational stability.
Lawful Grounds (Section 4 & 6): All processing of digital personal data is grounded in your free, specific, informed, unconditional, and unambiguous Consent provided via itemized notice upon booking or submitting an inquiry, or for Certain Legitimate Uses (such as issuing tax invoices mandated under Indian law).
3. Purpose Limitation & Permissible Processing
Under Section 5(1) of the DPDP Act 2023, your personal data is utilized strictly for the specific purpose for which it was shared:
- Scheduling, offering appointment slots, and coordinating private acoustic realignment sessions.
- Managing event guest rosters, issuing admittance confirmations, and recording physical attendee check-ins.
- Transmitting non-marketing transactional notices (slot confirmations, receipt downloads, reschedule notifications).
- Fulfilling statutory accounting, tax reporting (GST / Income Tax Act 1961), and dispute resolution requirements.
4. Payments, Bank Data & PCI-DSS Compliance
Gyanotsava executes digital payments via Razorpay Software Private Limited, an RBI-authorized Payment Aggregator and PCI-DSS Level 1 certified entity. Gyanotsava servers never receive, process, or store your credit/debit card numbers, CVVs, net-banking passwords, or UPI PINs. All financial interactions are encrypted end-to-end directly between your device and Razorpay.
5. Authorized Data Processors & Non-Disclosure
Gyanotsava does not sell, barter, or commercially trade your personal data. Under Section 8(2), we engage only vetted Data Processors bound by strict confidentiality and statutory compliance contracts:
- Razorpay Software Pvt Ltd: For payment transaction processing and refund execution.
- Zoho Corporation Pvt Ltd: For transactional email transmission and itinerary distribution.
- Statutory Authorities: Disclosed only when strictly mandated under a court order, summons, or valid regulatory directive under Indian Law.
6. Data Retention & Erasure Protocols
Under Section 8(7) of the DPDP Act 2023, personal data is retained only for the duration necessary to satisfy the purpose of collection or comply with statutory retention requirements:
- General Inquiry Logs: Erased or anonymized within 90 days of inquiry resolution unless converted to a booking.
- Session & Event Manifests: Retained for 180 days post-session to support follow-up care, after which it is archived or deleted upon request.
- Tax Invoices & Financial Ledgers: Retained for 7 years strictly as mandated under the Goods and Services Tax (GST) Act and Income Tax Act, 1961.
7. Technical Security Safeguards & Breach Mitigation
To fulfill our obligations under Section 8(5) of the DPDP Act 2023, Gyanotsava implements multi-layered technological and organizational measures:
- Edge Security & Route Shielding: Next.js edge proxy barrier protecting all administrative APIs and records.
- Cryptographic Verification: HMAC SHA-256 signatures for payment settlement and secure session tokens with HTTP-only flags.
- Breach Notification: In the unforeseen event of a personal data breach, Gyanotsava will notify the Data Protection Board of India and affected Data Principals in the form and manner prescribed under Section 8(6) of the Act.
8. Rights of the Data Principal under DPDP Act, 2023
As a Data Principal under Indian Law, you possess sovereign statutory rights enforceable against Gyanotsava:
Obtain a confirmation and summary of all personal data being processed, along with identities of third-party processors.
Correct inaccurate data, update incomplete profiles, or request the permanent erasure of your personal data.
Readily accessible mechanism to have your privacy complaints redressed within 30 statutory days.
Designate another individual to exercise your rights under the Act in the event of death or incapacity.
9. Processing Personal Data of Children (Section 9)
In strict accordance with Section 9 of the DPDP Act 2023, Gyanotsava does not knowingly collect or process digital personal data belonging to children (under 18 years of age) without the verifiable consent of a parent or lawful guardian. We do not conduct behavioral tracking, targeted advertisements, or any processing detrimental to the well-being of children.
10. Data Protection Officer & Grievance Redressal
In compliance with Section 13 of the DPDP Act 2023, Gyanotsava has appointed a designated Grievance Redressal Officer. For any inquiries, consent withdrawals, data access, or erasure requests, contact us:
11. Escalation to the Data Protection Board of India
Under Section 18 of the Digital Personal Data Protection Act, 2023, if you are not satisfied with the resolution provided by our Grievance Redressal Officer within the statutory period, or have reason to believe your data principal rights were infringed, you have the right to register a complaint with the Data Protection Board of India (DPBI) in the prescribed digital format.