Skip to main content
Skip to main content

DPDP 2025 Policy

Last updated: 27 September 2026

This Digital Personal Data Protection (DPDP) Policy ("Policy") outlines how Manav Digital Services ("MDS," "we," "our," or "us") complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder. This Policy sets out the framework for the collection, processing, storage, transfer, and protection of personal data of all data principals (individuals) who interact with our platform, services, website manavdigitalservices.in, or any of our communication channels. We are committed to upholding the highest standards of data protection and respecting the privacy rights of every individual whose data we process.

01

Scope & Applicability

This Digital Personal Data Protection (DPDP) Policy applies to all personal data collected, processed, stored, transferred, or disclosed by Manav Digital Services ("MDS") in connection with our documentation, attestation, facilitation, and related services. It covers data collected through any channel of engagement including: (a) our website manavdigitalservices.in; (b) WhatsApp Business communications; (c) email correspondence; (d) telephone conversations; (e) in-person visits and consultations; (f) physical forms and agreements; (g) third-party platforms through which you may engage our services. This Policy applies to all data principals including clients, prospective clients, website visitors, service enquirers, business partners, and any individual whose personal data we process.
02

Definitions Under DPDP Act

For the purposes of this Policy, the following key terms as defined under the Digital Personal Data Protection Act, 2023 (DPDP Act) are explained: (a) Data Principal — the individual to whom the personal data relates, i.e., you, the client, website visitor, or service enquirer; (b) Data Fiduciary — Manav Digital Services, the entity that determines the purpose and means of processing personal data; (c) Personal Data — any data about an identifiable individual, including name, contact details, government-issued identifiers, documents, photographs, biometric data, and any other data that can directly or indirectly identify a natural person; (d) Data Processor — any person (including third-party service providers) engaged by MDS to process personal data on our behalf; (e) Consent Manager — a person registered with the Data Protection Board who enables a data principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable consent management platform; (f) Data Protection Board — the statutory body established under the DPDP Act to adjudicate data protection matters.
03

Lawful Basis for Processing

In compliance with the DPDP Act, 2023, MDS processes personal data only under the following lawful bases: (a) Consent — We obtain explicit, informed, specific, and freely given consent from data principals before collecting or processing their personal data for service delivery. Consent is obtained through clear affirmative action, such as checking a consent box on our website forms, signing a physical consent form, or providing written consent via email or WhatsApp. We maintain auditable records of all consents obtained, including the date, time, purpose, and scope of consent; (b) Legitimate Uses — As defined under Section 7 of the DPDP Act, we may process personal data without consent for certain legitimate purposes including: employment-related processing, compliance with court or legal proceedings, medical emergencies involving the data principal, public health emergencies, disaster management, and processing required by law. We rely on these exceptions only where strictly applicable and maintain appropriate documentation of such processing.
04

Consent Management

MDS maintains a comprehensive consent management framework that records the following for each data principal: (a) the specific categories of personal data being collected; (b) the precise purpose(s) for which the data is being collected and processed; (c) how the data will be used, stored, and processed; (d) categories of third parties (including government authorities and service providers) with whom data may be shared; (e) the intended retention period; (f) the data principal’s right to withdraw consent and the procedure for doing so; (g) the date and time of consent and the method by which it was obtained. Consent is obtained through clear, specific, and unambiguous affirmative action using checkboxes, signed consent forms, or recorded verbal consent. Data principals may withdraw consent at any time by providing written notice to our Data Protection Officer. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal. Upon withdrawal, we will cease processing the data principal’s personal data and delete it within a reasonable period, subject to legal retention requirements.
05

Data Collection & Purpose Limitation

MDS adheres to the principle of data minimisation and purpose limitation as mandated by the DPDP Act. We collect only that personal data which is directly necessary and relevant for the specific service requested by the data principal. The categories of data we may collect include: (a) Identity Data — full name, date of birth, gender, nationality, photograph, signature, parent/spouse names, and guardian details (for minor applicants); (b) Contact Data — email address, phone number, WhatsApp number, residential address, correspondence address, and emergency contact details; (c) Document Data — scanned copies of government-issued IDs (Aadhaar, PAN, passport, voter ID, driving licence), educational certificates, birth certificates, marriage certificates, affidavits, and any other documents required for your specific application; (d) Service Data — application details, reference numbers, case notes, transaction history, payment records, and communication logs; (e) Technical Data — IP address, browser type and version, operating system, device type, referring URLs, and usage data collected through cookies and analytics tools. Personal data is used solely for the purpose for which it was collected and is not repurposed for any incompatible purpose without obtaining fresh, specific consent from the data principal.
06

Data Retention & Erasure

MDS retains personal data only for the duration necessary to fulfil the purpose for which it was collected plus any statutory retention periods mandated by applicable Indian laws. Our specific retention schedules are: (a) Service-Related Documents — retained for 3 years after completion of service for legal compliance, audit, and dispute resolution purposes; (b) Financial Records — retained for 8 years as required under the Income Tax Act, 1961, for tax audit and assessment purposes; (c) Communication Records — retained for 2 years from the date of last communication for service quality and reference; (d) Website Analytics Data — anonymised after 26 months; raw analytics data is deleted upon expiry of this period; (e) Consent Records — retained for the duration of data processing plus 3 years thereafter to demonstrate compliance. Data principals may request early erasure of their personal data at any time by contacting our Data Protection Officer. Upon expiry of the applicable retention period, or upon a valid erasure request (subject to legal holds), personal data is securely deleted, destroyed, or permanently anonymised through irreversible technical processes.
07

Data Security & Breach Notification

MDS implements comprehensive technical, physical, and organisational security measures as mandated by the DPDP Act to protect personal data against unauthorised access, processing, erasure, disclosure, or damage. Our security measures include: (a) Encryption — all personal data at rest is encrypted using AES-256, and all data in transit is protected using TLS 1.3 or higher; (b) Access Controls — strict role-based access controls (RBAC) with multi-factor authentication (MFA) for all employees and systems that process personal data; (c) Security Audits — quarterly vulnerability assessments, annual penetration testing, and periodic security audits by qualified external auditors; (d) Staff Training — mandatory annual data protection and privacy training for all personnel handling personal data, with quarterly refreshers; (e) Data Anonymisation — personal data used for analytics and reporting is anonymised through irreversible de-identification techniques. In the event of a data breach: (i) we will notify the Data Protection Board of India within 72 hours of becoming aware of the breach; (ii) we will inform affected data principals without undue delay; (iii) we will provide details of the nature and extent of the breach, a reasonable assessment of potential impact, and the remedial actions taken or proposed.
08

Data Principal Rights

Under the DPDP Act, 2023, every data principal is entitled to the following rights, which MDS respects and facilitates: (a) Right to Access (Section 11) — request a summary of personal data held by MDS, the processing activities undertaken, the categories of data processed, and the identities of data processors with whom data has been shared; (b) Right to Correction (Section 12) — request correction of any inaccurate, incomplete, misleading, or outdated personal data, and we will make the correction within a reasonable period; (c) Right to Erasure (Section 13) — request deletion of personal data, subject to legal retention requirements. Upon a valid erasure request, we will delete the data and instruct all data processors to delete it as well; (d) Right to Grievance Redressal (Section 14) — file a complaint with our Grievance Officer regarding any aspect of data processing, which we will acknowledge within 24 hours and resolve within 30 days; (e) Right to Nominate (Section 15) — nominate a person to exercise your data rights after your incapacity or death by providing their name and contact details in writing. To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We will respond to all valid requests within 30 days from the date of receipt, free of charge for reasonable requests.
09

Data Sharing & Transfer

MDS shares personal data only on a strict need-to-know basis with the following categories of recipients, each bound by contractual data protection obligations: (a) Government Authorities — including but not limited to the Ministry of External Affairs (MEA), municipal corporations, state HRD departments, embassies, consulates, passport offices, and other statutory bodies as required for processing your specific application; (b) Logistics Partners — Blue Dart, DHL, FedEx, India Post, and other courier services, under strict data processing agreements (DPAs) that prohibit use of data beyond the purpose of delivery; (c) Payment Processors — RBI-authorised payment gateways and acquiring banks, with tokenization and PCI DSS Level 1 compliance, shared only to the extent necessary for transaction processing; (d) Legal & Regulatory Authorities — when required by law, regulation, court order, or government direction. International data transfer, where necessary (e.g., for embassy attestation or apostille services involving foreign countries), occurs only to countries that the Government of India has deemed adequate under the DPDP Act or where we have implemented appropriate safeguards through standard contractual clauses and DPAs. In all cases, MDS ensures that recipients provide a level of data protection equivalent to that mandated under the DPDP Act.
10

Grievance Redressal

MDS has appointed a qualified Data Protection Officer (DPO) as required under Section 9 of the DPDP Act, 2023. The DPO is responsible for monitoring compliance with this Policy, handling data principal complaints, and acting as the point of contact for the Data Protection Board of India. For any data-related complaints, concerns, or requests to exercise your rights, please contact: Data Protection Officer, Manav Digital Services, Email: [email protected], Phone: +91 7566444402 (Monday to Saturday, 10:00 AM to 6:00 PM IST). Our grievance redressal process follows these timelines: (a) Acknowledgment — we acknowledge receipt of your complaint within 24 hours of submission; (b) Investigation — we conduct a thorough investigation of the matter, engaging relevant teams as necessary; (c) Resolution — we communicate our decision and any remedial actions within 30 days of receiving the complaint. If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India through their designated online portal or by writing to their registered address.
11

Policy Review & Updates

This DPDP Policy is subject to periodic review and revision to ensure continued compliance with the DPDP Act, 2023, its evolving rules and regulations, and changes in MDS’s data processing practices. The policy will be reviewed: (a) at least once every 12 months; (b) upon any material change in our data processing activities; (c) upon enactment of any new rules, regulations, or amendments under the DPDP Act; (d) following any data breach incident or security audit finding. Data principals will be notified of any material changes to this Policy through: (i) an email notification to the registered email address; (ii) a prominent notice on our website; (iii) an update to the "Last Updated" date at the top of this policy. The current version is Version 2.0, effective 17th July 2025. Previous versions of this Policy are maintained and available upon request from our Data Protection Officer. Continued use of our services after any revision constitutes acceptance of the updated policy.

Exercise Your Data Rights

File a grievance or request under Sections 11–15 of the DPDP Act, 2023

Acknowledged within 24 hoursResolved within 30 daysFree of charge

Directly reach our DPO at [email protected] or +91 7566444402.

Have Questions?

Our team is here to help clarify any concerns about our policies.

We value your privacy

We use essential cookies to run this site. Analytics and marketing cookies load only with your consent, as required under the DPDP Act, 2023.

Read our Privacy Policy and DPDP 2025 Policy