Last updated: [DATE OF PUBLICATION]
This Privacy Policy explains how [ORGANIZATION LEGAL NAME] ("SIH," "we," "us"), registered at [REGISTERED ADDRESS], collects, uses, stores, and protects personal data through the SIH Platform (the "Platform"). It is written to reflect how the Platform actually behaves, not generic boilerplate, and is intended to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") for users in [JURISDICTION].
We collect only what the Platform needs to function. Specifically:
We do not use cookies for tracking or advertising, and we do not sell personal data to any third party.
Your builder profile and identity fields are private by default and visible only to you. If you choose to opt in to a public Portfolio view, only the fields you explicitly enable are shown — your real name and other identity fields are never shown to another person unless you are viewing your own record. Your earnings are always private; the Platform never displays your financial figures on any view another person can see.
The Platform has no composite reputation score, ranking, or leaderboard of any kind. Reputation signals shown to others (if you opt in) are qualitative bands, never a single number you could be ranked by.
We process personal data only for the following purposes:
As a Data Principal, you have the right to:
To exercise any of these rights, contact our Grievance Officer at [SUPPORT / GRIEVANCE CONTACT EMAIL]. We will respond within the timeframe required by applicable law.
When we approve an erasure request, here is exactly what happens — described accurately, not in generic terms:
An erasure request is reviewed and approved by an accountable member of our team, with a stated reason recorded — it is never processed silently. Erasure requests can be declined only where retention is required by law or is necessary to complete an active, disputed decision; we will explain the reason if this applies to you.
Account and profile data is stored in a managed relational database. Uploaded documents (resumes, evidence, images) are stored using S3-compatible object storage; access to a stored document is only ever granted through a short-lived, signed download link generated on demand — documents are never served from a public URL.
We retain personal data for as long as your account is active, and for institutional-record fields (see Section 5), for as long as necessary to preserve the integrity of the accountability history that data is part of, even after your identity fields are erased. Public inquiry submissions that do not result in a client relationship are retained only as long as necessary for our review process, after which they may be deleted or, on request, anonymized.
Passwords are never stored in plaintext. Session tokens are held in memory in your browser only — never in a cookie or in persistent browser storage — and are cleared when you close or reload the page. Sensitive one-time secrets (verification codes, account-setup invitation links) are never stored in recoverable form; only a cryptographic hash is kept, and each is single-use and time-limited. Object storage and outbound email delivery are both configured through standard, provider-agnostic infrastructure with credentials held only in server-side configuration, never in application code or client-side storage.
The Platform is not directed at children. If you believe a child has provided us personal data without appropriate consent, contact us at [SUPPORT / GRIEVANCE CONTACT EMAIL] and we will address it promptly.
We will update this page if how we handle your data changes, and update the "Last updated" date above. Material changes will be communicated to you through the Platform.
For any question about this policy or your data, contact us at [SUPPORT / GRIEVANCE CONTACT EMAIL], or write to us at [REGISTERED ADDRESS].