Legal · DPDP Act 2023 · DPDP Rules 2025

Privacy Policy

Version 2.0 · Effective 20 September 2026 · Read the short Consent Notice →

Version 2.0 · Effective 20 September 2026 · Issued under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").

This Policy explains how AdminAdda collects, uses, shares, stores and protects your personal data when you use adminadda.com and its sub-domains, apps, APIs and communications (together, the "Platform"). The short, standalone Consent Notice that we show when we ask for your consent is at /consent-notice — this Policy is the detailed version.

1. Who we are (Data Fiduciary)

Data Fiduciary[Legal entity name], operating AdminAdda ("we", "us")
Registered address[Address], India
Data Protection contact / Grievance Officer[Name] · [email protected] · [phone]
Response time for privacy requests and grievancesAcknowledgement within 72 hours; resolution within 30 days (the DPDP Rules permit up to 90; we commit to 30)

We decide the purposes and means of processing your personal data and are therefore the Data Fiduciary under the DPDP Act. Where we use vendors to process data on our behalf, they act as Data Processors under written contracts.

2. Scope

This Policy applies to digital personal data — data about an identifiable individual that we collect in digital form, or collect offline and then digitise. It applies to visitors, registered members, writers, event organisers, employers and business customers. It does not apply to personal data that you have made publicly available yourself (for example, a post you publish under your @handle) beyond the obligations that still attach to our own processing of it.

3. What we collect, why, and on what legal basis

The DPDP Act permits processing only (a) with your consent for a specified purpose, or (b) for certain legitimate uses listed in Section 7 of the Act. The table below is the itemised description we are required to give you.

#Personal dataPurpose (specified)Legal basisRetention
P1Name, email address, profile image received from your sign-in provider (Keycloak / auth.adminadda.com); account identifiersCreate and secure your account, sign you in, prevent fraud and abuseConsent (at sign-up)While the account is active; deleted within 30 days of closure
P2@handle, headline, bio, professional domain, experience level, location, website, photo you uploadYour public professional profile at adminadda.com/@handleConsent (at onboarding; each field optional except @handle)While the account is active
P3Content you write (posts, drafts, comments), tags, submission history, moderator notesPublishing — review, publish, attribute and promote your writingConsent (when you submit content)Published content: until you delete it; drafts: until deleted or 12 months after last edit
P4CVE / product watch-list, alert channel (email; WhatsApp number if you add it)Security alerts you subscribe toConsent (per subscription; each alert can be switched off individually)Until you unsubscribe
P5Assessment answers and scores, learning progress, XP, streakLearning features — show your results, badges and leaderboard positionConsent (when you take an assessment while signed in)While the account is active; anonymous attempts keep no identifier
P6Questions you type into AdminAIAI assistant — generate an answerConsent (each use); query text is sent to our AI model providerNot stored beyond the request except aggregate usage counters
P7Email address, preferencesNewsletter / product updatesConsent (separate, unticked by default)Until you unsubscribe
P8IP address, device and browser information, timestamps, server and security logsSecurity safeguards, rate-limiting, abuse detection, breach investigation, legal complianceLegitimate use — required by Rule 6 (security safeguards) and applicable law1 year (minimum log retention required by the DPDP Rules), then deleted
P9Name, email, company, message sent via the contact formResponding to your enquiryLegitimate use — data you voluntarily provided for that purpose (s.7(a))24 months
P10Company name, GSTIN, billing contact, invoices (business customers)Providing paid services, invoicing, tax complianceConsent for account; legal obligation for tax recordsTax records 8 years as required by law

We do not: sell personal data; use it for behavioural advertising; build advertising profiles; or process data about children (see §8).

Tools that handle sensitive inputs (password checkers, JWT decoders, hash generators) run entirely in your browser; nothing you enter in them reaches our servers.

4. Consent — how it works

  • We ask for consent separately for each purpose in the table above. Nothing is pre-ticked and no purpose is bundled with another.
  • Every consent request is accompanied by the Consent Notice, in plain language.
  • You may withdraw any consent at any time from Dashboard → Profile → Privacy & consent, or by emailing [email protected]. Withdrawal is as easy as giving consent and takes effect immediately for future processing; we and our Processors stop processing for that purpose within 7 days, except where retention is required by law.
  • Withdrawing consent for an essential purpose (P1) means closing your account.
  • We keep a consent record (what you were shown, which purposes, when, and how) as evidence of your consent, and to honour withdrawals.
  • You may also give or manage consent through a Consent Manager registered with the Data Protection Board once such managers are operational; consent given via a Consent Manager is treated as given to us directly.
  • If you registered before this version of the Policy, we treat the consent you gave then as continuing and have served you this notice as required by Section 5(2); you may withdraw at any time.

5. Who we share personal data with

Data Processors (bound by contract to equivalent safeguards, breach notification without delay, erasure on instruction, and no onward sharing):

ProcessorWhatWhere
Nexovia Setu CloudHosting, database, object storage, email deliveryIndia
Keycloak identity service (auth.adminadda.com)AuthenticationIndia
AI model providers (Google Gemini; Groq as fallback)AdminAI answers and AI-assisted draft generation — query text only, no account dataMay be outside India
Payment gateway (Razorpay) — business customers onlyCard / UPI processing; we never see full card numbersIndia

Public by design: your @handle, profile fields you fill in, and content you publish are visible to anyone, including search engines and users of our free public API (which exposes only published content and public profile fields, never email or account data).

Legal disclosure: we disclose personal data when required by law, court order, or a lawful request from a government agency, or to prevent or investigate offences, and to protect the rights and safety of users and the Platform.

Business transfers: in a merger, acquisition or restructuring, personal data may be transferred to the successor, who must honour this Policy; we will notify you.

6. Cross-border transfers

Our primary hosting and databases are in India. Some Processors (notably AI model providers) may process limited data outside India. We transfer personal data outside India only where the destination is not restricted by the Central Government under Section 16, and we apply the same safeguards contractually. If you are a business customer subject to sector rules requiring localisation (for example RBI directions), those rules continue to apply to you.

7. Security safeguards

We implement the minimum safeguards required by Rule 6 of the DPDP Rules and more:

  • Encryption in transit (TLS) and at rest; hashing/tokenisation where data need not be readable;
  • Role-based access control, least privilege, and administrative actions logged;
  • Logging and monitoring to detect and investigate unauthorised access, with logs retained for at least one year;
  • Tested backups and a continuity plan to restore availability;
  • Contractual flow-down of these safeguards to every Processor;
  • Personal data masked in non-production environments.

Personal data breach. If a breach affects you, we will notify you without delay in plain language — what happened, the likely consequences, what we are doing, what you can do, and how to reach us — and intimate the Data Protection Board of India within the timelines in Rule 7 (initial intimation without delay; full report within 72 hours). Where the incident is also reportable to CERT-In, we report within the 6-hour window under the CERT-In Directions of 2022.

8. Children and persons with disabilities

The Platform is for professionals and is not available to persons under 18. We do not knowingly collect a child's personal data and do not track, behaviourally monitor, or target advertising at children. If we learn that an account belongs to a person under 18 without verifiable parental consent, we will delete it. Where a person with a disability acts through a lawful guardian, the guardian may exercise rights on their behalf.

9. Your rights as a Data Principal

RightWhat you can askHow
Access (s.11)A summary of your personal data we process, the processing activities, and the identities of Fiduciaries/Processors it was shared withDashboard → Profile → Download my data, or email us
Correction, completion, updating (s.12)Fix inaccurate or incomplete dataEdit directly in Dashboard → Profile, or email us
Erasure (s.12)Delete personal data no longer needed for the purpose, or on withdrawal of consentDashboard → Profile → Delete account, or email us; some records are retained where law requires (§3 table)
Grievance redressal (s.13)Complain about our processing or a rights request[email protected] or the contact form; acknowledged in 72 h, resolved in 30 days
Nominate (s.14)Name a person who may exercise your rights if you die or become incapacitatedDashboard → Profile → Nominee
Withdraw consent (s.6)Stop any consent-based processingDashboard → Profile → Privacy & consent

We may verify your identity before acting on a request. Requests are free of charge. If you are not satisfied with our response, or we do not respond within the stated period, you may complain to the Data Protection Board of India (the Board's digital portal is notified by MeitY). Appeals from the Board lie to the TDSAT.

10. Your duties as a Data Principal

Under Section 15 you must not impersonate another person, suppress material information when providing data for a document or identity proof, file false or frivolous grievances, or furnish false particulars when exercising rights. Breach of these duties can attract a penalty of up to ₹10,000 from the Board.

11. Cookies and similar technologies

We use only strictly necessary cookies: the session cookie that keeps you signed in, a CSRF token, and a preference cookie. We do not use third-party tracking or advertising cookies. If we introduce analytics in future, we will ask for your consent first and you will be able to refuse without losing access to the Platform.

12. Retention and deletion

We retain personal data only as long as needed for the purpose for which it was collected, or as required by law (see the table in §3). When you delete your account we remove your profile and personal data within 30 days; published content is unpublished immediately and removed from backups within 90 days; security logs are kept for 1 year; tax and invoicing records for the statutory period. We retain the record of your consent and its withdrawal for one year after the relationship ends, to demonstrate compliance.

13. Public API and third-party developers

Our free public API exposes only published content and public profile fields. Developers who use it agree to attribute AdminAdda, not to scrape personal pages, and not to re-identify or profile individuals. Report misuse to [email protected].

14. Changes to this Policy

We may update this Policy. Material changes are announced on the Platform at least 14 days before they take effect and, for registered members, by email. The version and effective date appear at the top; earlier versions are available on request.

15. Governing law and contact

This Policy is governed by the laws of India. Questions, requests and grievances: [email protected] · [postal address] · Grievance Officer: [Name].