Legal Register
Legal & Governance
Section 5 & Rule 3 Compliant Notice Baseline: 15 September 2026

Privacy Policy & Data Processing Notice

This Privacy Notice describes how Dhristhi System Pvt. Ltd. ("Dhristhi", "we", "us", or "our") processes digital personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.

1. Data Fiduciary Identity & Contact Details

Section 8(9) & Rule 9

The entity determining the purpose and means of personal data processing under this notice is the Data Fiduciary:

Data Fiduciary
Dhristhi System Pvt. Ltd.
Bengaluru, Karnataka 560001, India
Website: https://dhristhi.com
Data Protection Officer (DPO) Designated
Office of the Data Protection Officer
Email / Grievance: office@dhristhi.com

2. Itemized Personal Data Categories & Specified Purposes

Section 5 & Rule 3

In strict adherence to the statutory notice requirements under Section 5(1) and Rule 3 of the DPDP Rules 2025, the following table itemizes every category of personal data processed, its precise purpose, and the underlying lawful basis:

Data Category Specified Processing Purpose Statutory Lawful Basis Retention Period
Advisory Inquiry Information
Name, work email, organization, title, inquiry notes
Responding to enterprise consulting requests, scheduling architecture audits, and providing requested proposals. Section 7(a) (Voluntary provision) / Section 6 (Consent) Duration of engagement + 180 days after inactivity
Technical Telemetry & Log Data
IP address, user-agent, access timestamp, error codes
Maintaining reasonable security safeguards under Section 8(5), defending against DDoS attacks, and ensuring server availability. Section 8(5) & Rule 6 (Security Safeguards Duty) 90 days automated rolling log purge
Local UI Preferences
Theme mode ('light' | 'dark'), sidebar state
Preserving user interface display preferences across visits on the user's local device. Client-side storage only (localStorage) Persistent on client until cleared by user

3. Zero-Knowledge Client-Side Decision Tools

Privacy by Design
No Server-Side Data Ingestion from Decision Engines:

When you use the Applicability Wizard, Dual-Clock Breach Simulator, Vendor Evaluator, or Interactive Checklists, all calculations, answers, and data evaluations execute 100% client-side in your local browser JavaScript runtime.

None of your organizational answers, sector classifications, volume metrics, or vendor scores are transmitted to or logged on our backend servers.

4. Reasonable Security Safeguards (Section 8(5) & Rule 6)

Security Controls

In accordance with Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules 2025, Dhristhi deploys technical and organizational safeguards to prevent personal data breaches:

Transport Layer Security

Mandatory TLS 1.3 encryption with strict HTTPS redirection across all endpoints.

Edge Perimeter Isolation

CloudFront/WAF boundary protection with automated rate limiting and bot detection.

Strict Access Controls

Least-privilege role-based access controls (RBAC) and multi-factor authentication for administrators.

5. Retention Schedule & Purpose-Completion Erasure

Section 8(7) & Rule 8

Under Section 8(7) of the DPDP Act and Rule 8 of the subordinate Rules, personal data must be erased as soon as the specified purpose has been fulfilled or upon withdrawal of consent.

Dhristhi enforces an automated retention policy: inquiry contact data is permanently scrubbed or anonymized within 180 days of project inactivity, unless statutory retention obligations (such as tax or financial compliance laws) require longer retention under Section 8(8).

6. Data Principal Statutory Rights (Sections 11–14)

Enforced Rights

As a Data Principal under the DPDP Act 2023, you are entitled to exercise the following statutory rights at any time without fees:

Right to Access Information Section 11

Obtain a summary of personal data being processed and the identities of all third-party processors.

Right to Correction & Erasure Section 12

Request correction of inaccurate data, completion of incomplete data, or erasure upon purpose completion.

Right to Grievance Redressal Section 13

Access an easily available grievance redressal mechanism with statutory resolution timelines.

Right to Nominate Section 14

Nominate any individual to exercise rights on your behalf in the event of death or incapacity.

7. Grievance Redressal & DPBI Complaint Pathway

Section 13 & Section 28

If you have any grievance regarding the processing of your personal data or the exercise of your statutory rights, please follow our two-tier resolution procedure:

Step 1: Internal Fiduciary Grievance Officer

Email our Grievance Officer at office@dhristhi.com. We will acknowledge your grievance within 48 hours and provide a complete written resolution within 14 business days.

Step 2: Statutory Escalation to the Data Protection Board of India (DPBI)

If you receive no response within the prescribed timeline or are dissatisfied with the resolution provided by our Grievance Officer, you have the statutory right under Section 28(1) of the DPDP Act 2023 to register a formal complaint with the Data Protection Board of India (DPBI).