Privacy Policy
Version 2.0 · Effective 20 September 2026 · Read the short Consent Notice →
Version 2.0 · Effective 20 September 2026 · Issued under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").
This Policy explains how AdminAdda collects, uses, shares, stores and protects your personal data when you use adminadda.com and its sub-domains, apps, APIs and communications (together, the "Platform"). The short, standalone Consent Notice that we show when we ask for your consent is at /consent-notice — this Policy is the detailed version.
1. Who we are (Data Fiduciary)
| Data Fiduciary | [Legal entity name], operating AdminAdda ("we", "us") |
| Registered address | [Address], India |
| Data Protection contact / Grievance Officer | [Name] · [email protected] · [phone] |
| Response time for privacy requests and grievances | Acknowledgement within 72 hours; resolution within 30 days (the DPDP Rules permit up to 90; we commit to 30) |
We decide the purposes and means of processing your personal data and are therefore the Data Fiduciary under the DPDP Act. Where we use vendors to process data on our behalf, they act as Data Processors under written contracts.
2. Scope
This Policy applies to digital personal data — data about an identifiable individual that we collect in digital form, or collect offline and then digitise. It applies to visitors, registered members, writers, event organisers, employers and business customers. It does not apply to personal data that you have made publicly available yourself (for example, a post you publish under your @handle) beyond the obligations that still attach to our own processing of it.
3. What we collect, why, and on what legal basis
The DPDP Act permits processing only (a) with your consent for a specified purpose, or (b) for certain legitimate uses listed in Section 7 of the Act. The table below is the itemised description we are required to give you.
| # | Personal data | Purpose (specified) | Legal basis | Retention |
|---|---|---|---|---|
| P1 | Name, email address, profile image received from your sign-in provider (Keycloak / auth.adminadda.com); account identifiers | Create and secure your account, sign you in, prevent fraud and abuse | Consent (at sign-up) | While the account is active; deleted within 30 days of closure |
| P2 | @handle, headline, bio, professional domain, experience level, location, website, photo you upload | Your public professional profile at adminadda.com/@handle | Consent (at onboarding; each field optional except @handle) | While the account is active |
| P3 | Content you write (posts, drafts, comments), tags, submission history, moderator notes | Publishing — review, publish, attribute and promote your writing | Consent (when you submit content) | Published content: until you delete it; drafts: until deleted or 12 months after last edit |
| P4 | CVE / product watch-list, alert channel (email; WhatsApp number if you add it) | Security alerts you subscribe to | Consent (per subscription; each alert can be switched off individually) | Until you unsubscribe |
| P5 | Assessment answers and scores, learning progress, XP, streak | Learning features — show your results, badges and leaderboard position | Consent (when you take an assessment while signed in) | While the account is active; anonymous attempts keep no identifier |
| P6 | Questions you type into AdminAI | AI assistant — generate an answer | Consent (each use); query text is sent to our AI model provider | Not stored beyond the request except aggregate usage counters |
| P7 | Email address, preferences | Newsletter / product updates | Consent (separate, unticked by default) | Until you unsubscribe |
| P8 | IP address, device and browser information, timestamps, server and security logs | Security safeguards, rate-limiting, abuse detection, breach investigation, legal compliance | Legitimate use — required by Rule 6 (security safeguards) and applicable law | 1 year (minimum log retention required by the DPDP Rules), then deleted |
| P9 | Name, email, company, message sent via the contact form | Responding to your enquiry | Legitimate use — data you voluntarily provided for that purpose (s.7(a)) | 24 months |
| P10 | Company name, GSTIN, billing contact, invoices (business customers) | Providing paid services, invoicing, tax compliance | Consent for account; legal obligation for tax records | Tax records 8 years as required by law |
We do not: sell personal data; use it for behavioural advertising; build advertising profiles; or process data about children (see §8).
Tools that handle sensitive inputs (password checkers, JWT decoders, hash generators) run entirely in your browser; nothing you enter in them reaches our servers.
4. Consent — how it works
- We ask for consent separately for each purpose in the table above. Nothing is pre-ticked and no purpose is bundled with another.
- Every consent request is accompanied by the Consent Notice, in plain language.
- You may withdraw any consent at any time from Dashboard → Profile → Privacy & consent, or by emailing [email protected]. Withdrawal is as easy as giving consent and takes effect immediately for future processing; we and our Processors stop processing for that purpose within 7 days, except where retention is required by law.
- Withdrawing consent for an essential purpose (P1) means closing your account.
- We keep a consent record (what you were shown, which purposes, when, and how) as evidence of your consent, and to honour withdrawals.
- You may also give or manage consent through a Consent Manager registered with the Data Protection Board once such managers are operational; consent given via a Consent Manager is treated as given to us directly.
- If you registered before this version of the Policy, we treat the consent you gave then as continuing and have served you this notice as required by Section 5(2); you may withdraw at any time.
5. Who we share personal data with
Data Processors (bound by contract to equivalent safeguards, breach notification without delay, erasure on instruction, and no onward sharing):
| Processor | What | Where |
|---|---|---|
| Nexovia Setu Cloud | Hosting, database, object storage, email delivery | India |
| Keycloak identity service (auth.adminadda.com) | Authentication | India |
| AI model providers (Google Gemini; Groq as fallback) | AdminAI answers and AI-assisted draft generation — query text only, no account data | May be outside India |
| Payment gateway (Razorpay) — business customers only | Card / UPI processing; we never see full card numbers | India |
Public by design: your @handle, profile fields you fill in, and content you publish are visible to anyone, including search engines and users of our free public API (which exposes only published content and public profile fields, never email or account data).
Legal disclosure: we disclose personal data when required by law, court order, or a lawful request from a government agency, or to prevent or investigate offences, and to protect the rights and safety of users and the Platform.
Business transfers: in a merger, acquisition or restructuring, personal data may be transferred to the successor, who must honour this Policy; we will notify you.
6. Cross-border transfers
Our primary hosting and databases are in India. Some Processors (notably AI model providers) may process limited data outside India. We transfer personal data outside India only where the destination is not restricted by the Central Government under Section 16, and we apply the same safeguards contractually. If you are a business customer subject to sector rules requiring localisation (for example RBI directions), those rules continue to apply to you.
7. Security safeguards
We implement the minimum safeguards required by Rule 6 of the DPDP Rules and more:
- Encryption in transit (TLS) and at rest; hashing/tokenisation where data need not be readable;
- Role-based access control, least privilege, and administrative actions logged;
- Logging and monitoring to detect and investigate unauthorised access, with logs retained for at least one year;
- Tested backups and a continuity plan to restore availability;
- Contractual flow-down of these safeguards to every Processor;
- Personal data masked in non-production environments.
Personal data breach. If a breach affects you, we will notify you without delay in plain language — what happened, the likely consequences, what we are doing, what you can do, and how to reach us — and intimate the Data Protection Board of India within the timelines in Rule 7 (initial intimation without delay; full report within 72 hours). Where the incident is also reportable to CERT-In, we report within the 6-hour window under the CERT-In Directions of 2022.
8. Children and persons with disabilities
The Platform is for professionals and is not available to persons under 18. We do not knowingly collect a child's personal data and do not track, behaviourally monitor, or target advertising at children. If we learn that an account belongs to a person under 18 without verifiable parental consent, we will delete it. Where a person with a disability acts through a lawful guardian, the guardian may exercise rights on their behalf.
9. Your rights as a Data Principal
| Right | What you can ask | How |
|---|---|---|
| Access (s.11) | A summary of your personal data we process, the processing activities, and the identities of Fiduciaries/Processors it was shared with | Dashboard → Profile → Download my data, or email us |
| Correction, completion, updating (s.12) | Fix inaccurate or incomplete data | Edit directly in Dashboard → Profile, or email us |
| Erasure (s.12) | Delete personal data no longer needed for the purpose, or on withdrawal of consent | Dashboard → Profile → Delete account, or email us; some records are retained where law requires (§3 table) |
| Grievance redressal (s.13) | Complain about our processing or a rights request | [email protected] or the contact form; acknowledged in 72 h, resolved in 30 days |
| Nominate (s.14) | Name a person who may exercise your rights if you die or become incapacitated | Dashboard → Profile → Nominee |
| Withdraw consent (s.6) | Stop any consent-based processing | Dashboard → Profile → Privacy & consent |
We may verify your identity before acting on a request. Requests are free of charge. If you are not satisfied with our response, or we do not respond within the stated period, you may complain to the Data Protection Board of India (the Board's digital portal is notified by MeitY). Appeals from the Board lie to the TDSAT.
10. Your duties as a Data Principal
Under Section 15 you must not impersonate another person, suppress material information when providing data for a document or identity proof, file false or frivolous grievances, or furnish false particulars when exercising rights. Breach of these duties can attract a penalty of up to ₹10,000 from the Board.
11. Cookies and similar technologies
We use only strictly necessary cookies: the session cookie that keeps you signed in, a CSRF token, and a preference cookie. We do not use third-party tracking or advertising cookies. If we introduce analytics in future, we will ask for your consent first and you will be able to refuse without losing access to the Platform.
12. Retention and deletion
We retain personal data only as long as needed for the purpose for which it was collected, or as required by law (see the table in §3). When you delete your account we remove your profile and personal data within 30 days; published content is unpublished immediately and removed from backups within 90 days; security logs are kept for 1 year; tax and invoicing records for the statutory period. We retain the record of your consent and its withdrawal for one year after the relationship ends, to demonstrate compliance.
13. Public API and third-party developers
Our free public API exposes only published content and public profile fields. Developers who use it agree to attribute AdminAdda, not to scrape personal pages, and not to re-identify or profile individuals. Report misuse to [email protected].
14. Changes to this Policy
We may update this Policy. Material changes are announced on the Platform at least 14 days before they take effect and, for registered members, by email. The version and effective date appear at the top; earlier versions are available on request.
15. Governing law and contact
This Policy is governed by the laws of India. Questions, requests and grievances: [email protected] · [postal address] · Grievance Officer: [Name].