NAVRITU DIGITAL
INDIA DPDP ACT COMPLIANCE
Effective Date: August 22, 2026
This page explains how NavRitu Digital (“we,” “us,” or “our”) processes personal data in accordance with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), in our role as a Data Fiduciary.
1. Our Role
We act as a Data Fiduciary under the DPDP Act for personal data collected through our own website and business forms, and as a processor acting on a client's instructions where we handle personal data on their behalf under a Data Processing Agreement. We have not been designated a “Significant Data Fiduciary” by the Central Government.
2. Consent
Where we rely on consent to process personal data, we seek clear, specific, informed, and unconditional consent, presented in plain language, before or at the time of collection. You may withdraw consent at any time, as easily as it was given, by contacting us at legal@navritu.digital — though withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3. Children's Data
The DPDP Act defines a “child” as anyone under 18 years of age. Our services are directed at businesses and professionals, not children. We do not knowingly collect personal data from children, do not track or behaviorally monitor children, and do not direct targeted advertising at children.
4. Your Rights as a Data Principal
- Right to Access a summary of the personal data we hold about you and the processing activities carried out
- Right to Correction and Erasure of inaccurate, incomplete, or no-longer-necessary personal data
- Right to Grievance Redressal through our designated Grievance Officer
- Right to Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Right to Withdraw Consent at any time, where processing is based on consent
5. Grievance Officer
Our Privacy Officer serves as the Grievance Officer for DPDP Act purposes and can be reached at legal@navritu.digital. We aim to acknowledge and address grievances consistent with our Grievance Redressal Mechanism.
6. Data Retention & Erasure
We retain personal data only as long as necessary for the purpose it was collected, or as required by law, and erase or anonymize it thereafter, consistent with our Global Privacy Policy.
7. Security Safeguards
We implement reasonable technical and organizational security safeguards to protect personal data against unauthorized access, use, or disclosure, and to detect and respond to breaches, as described in our Incident Response & Breach Notification Policy.
8. Breach Reporting
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act and its rules, consistent with our Incident Response & Breach Notification Policy.
9. Cross-Border Transfers
The DPDP Act permits the transfer of personal data outside India except to countries specifically restricted by the Central Government. As of the effective date of this page, we are not aware of any such restriction affecting our current transfers. See our Cross-Border Data Transfer page for details of where data actually flows.
10. Contact Us
Questions about our DPDP Act compliance: legal@navritu.digital.