GDPR & DPDP Compliance.
Puniyo is committed to complying with the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (EU). This page explains how we do it.
1. Laws We Comply With
Digital Personal Data Protection Act, 2023 (India)
The DPDP Act governs the processing of digital personal data in India. It gives Data Principals (you) specific rights and places obligations on Data Fiduciaries (Puniyo).
General Data Protection Regulation (EU)
GDPR protects EU residents' personal data, even when processed outside the EU. If you are an EU resident using Puniyo, GDPR applies to your data.
Other Laws
- Information Technology Act, 2000 and IT Rules, 2011 (India).
- Rights of Persons with Disabilities Act, 2016 (accessibility).
- Consumer Protection Act, 2019 (customer rights).
2. Data Processing Principles
Puniyo processes personal data on these core principles:
| Principle | What It Means |
|---|---|
| Lawfulness | We process data only with consent or other lawful basis. |
| Purpose Limitation | Data is used only for the purpose it was collected for. |
| Data Minimization | We collect only what is necessary. |
| Accuracy | We keep data accurate and up to date. |
| Storage Limitation | Data is deleted after the retention period. |
| Integrity & Confidentiality | Data is secured against unauthorized access. |
| Accountability | We can demonstrate compliance. |
3. Legal Basis for Processing
We process data based on the following legal grounds:
- Consent — For sharing your enquiry with vendors, marketing emails, and analytics cookies.
- Contract — To provide the service you requested (submitting an enquiry).
- Legal Obligation — To comply with tax and financial record-keeping laws.
- Legitimate Interest — For fraud prevention, security, and platform improvement.
You can withdraw consent at any time — see Consent Management.
4. Your Rights Under Both Laws
| Right | DPDP (India) | GDPR (EU) |
|---|---|---|
| Access your data | Yes | Yes |
| Correct your data | Yes | Yes |
| Delete your data | Yes | Yes ("Right to Erasure") |
| Withdraw consent | Yes | Yes |
| Data portability | Yes | Yes |
| Object to processing | Yes | Yes |
| Nominate a person | Yes | No (EU specific) |
| Non-discrimination | Yes | Yes |
| Grievance redressal | Yes | Yes |
To exercise any right, email privacy@puniyo.com or use the forms on our:
5. Security Measures
We implement industry-standard security controls:
- Encryption in transit (HTTPS/TLS 1.2+) for all traffic.
- Encryption at rest for databases storing personal data.
- OTP verification for all customer enquiries.
- Access controls — only authorized staff can access personal data.
- Logging and monitoring of all data access.
- Regular audits of infrastructure and code.
- Vendor security reviews before onboarding.
6. International Data Transfers
Puniyo primarily stores data in India. If we need to transfer data outside India:
- We only transfer to countries approved by the Indian Government.
- For EU data, we rely on Standard Contractual Clauses (SCCs).
- We use encryption in transit and at rest for all transfers.
- We ensure the receiving party meets GDPR and DPDP standards.
7. Children's Data
Puniyo is not intended for children under 18. We do not knowingly collect data from children.
Under DPDP Act 2023:
- We do not process data of children without verifiable parental consent.
- We do not use children's data for tracking, behavioral monitoring, or targeted advertising.
If you believe we hold data of a child under 18, contact privacy@puniyo.com for immediate removal.
8. Breach Notification
In the event of a personal data breach, Puniyo will:
- Notify the Data Protection Board of India without undue delay (within 72 hours where required).
- Notify affected users in plain language if the breach poses risk.
- Notify EU supervisory authorities if GDPR applies.
- Document the incident including cause, impact, and remediation.
9. Data Protection Officer
Puniyo has appointed a Data Protection Officer (DPO) responsible for:
- Monitoring compliance with DPDP and GDPR.
- Handling data subject requests.
- Conducting Data Protection Impact Assessments.
- Training internal teams on data protection.
- Acting as point of contact for regulators.
10. Complaints & Redressal
If you are not satisfied with our response:
Under DPDP Act (India)
You may file a complaint with the Data Protection Board of India. Contact details are available on the Government of India's official portal.
Under GDPR (EU)
You may file a complaint with your local EU supervisory authority (e.g., ICO in the UK, CNIL in France, etc.).
Our Grievance Officer
Before escalating externally, please contact our Grievance Officer first:
Email: grievance@puniyo.com
We respond within 7 working days.
Contact
Data Protection Officer: dpo@puniyo.com
Grievance Officer: grievance@puniyo.com
Privacy Team: privacy@puniyo.com