Data Protection Policy
Last updated: July 28, 2026
1. Purpose
This Data Protection Policy establishes the principles, procedures and responsibilities that govern the collection, processing, storage, transfer and destruction of personal data by Dhimson Tradespot Private Limited. It is intended to ensure compliance with the Digital Personal Data Protection Act 2023, the Information Technology Act 2000 and Rules (including Section 43A and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011), GDPR and other applicable laws. It applies to all directors, employees, contractors and third parties who process personal data on our behalf across our services.
2. Roles and Responsibilities
- Data Protection Officer (DPO): Oversees compliance with data protection laws, advises management and employees, monitors data protection activities, serves as the contact point for regulators and data subjects, and manages data breach response.
- Senior Management and Directors: Ensure adequate resources are allocated for data protection, approve policies and monitor compliance.
- Employees and Contractors: Must follow this policy, complete mandatory training, implement security measures, and report any suspected data breaches or violations.
- Third-Party Processors: Service providers and partners that process personal data on our behalf must enter into written agreements containing data protection obligations and must notify us promptly of any incidents.
3. Lawful Collection and Data Minimisation
We collect and process personal data only for lawful purposes that are explicit and legitimate. We limit collection to what is necessary in relation to the purposes outlined in our Privacy Policy and Terms and Conditions. Sensitive personal data (e.g., passwords, financial information, health data, biometric information) is collected only when necessary and with explicit consent or another lawful basis.
4. Consent and Transparency
Where required by law or for processing sensitive personal data, we obtain clear and unambiguous consent from the individual providing the data. We provide transparent information about how the data will be used, stored and shared, and we honour withdrawal of consent where applicable.
5. Data Subject Rights
We respect data subjects' rights to access, rectify, erase, restrict, object to processing and obtain their data in a portable format. Requests should be submitted to our DPO and will be addressed within legally prescribed timeframes.
6. Data Classification
All personal data is classified based on sensitivity and risk impact. Categories include:
- Public Data — information available publicly;
- Internal Data — information used within the organisation;
- Confidential Data — e.g., contact information, course records; and
- Sensitive Personal Data — as defined under applicable law, such as passwords, financial data, health information, biometric data and any information relating to these categories.
Appropriate security measures are applied based on classification.
7. Security Measures
We implement technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit and at rest, pseudonymisation, multi-factor authentication, network segmentation, regular patching, secure development practices, and least-privilege access controls. We conduct regular risk assessments, penetration tests and security audits, and we maintain an information security management system aligned with recognised standards. Employees and contractors receive regular training on data protection and cyber security.
8. Data Breach Response
Any suspected or actual personal data breach must be reported immediately to the DPO. We maintain a Data Breach Response Plan that includes:
- Prompt investigation and containment of the incident;
- Assessment of the scope, risk and impact;
- Notification to the Data Protection Board of India within 72 hours of becoming aware of a breach, in accordance with Section 8 of the DPDP Act;
- Notification to CERT-In within six hours of detecting a cyber security incident, as required under CERT-In directions;
- Communication to affected data principals where there is a significant risk of harm; and
- Documentation of the breach and corrective actions taken.
9. Cross-Border Data Transfers
Transfers of personal data outside India occur only when necessary for service delivery or support. Such transfers are permitted unless the destination country is listed on the Government of India's restricted list under Section 16 of the DPDP Act. We enter into Data Transfer Agreements or employ binding corporate rules to ensure equivalent protection, and we assess destination jurisdictions' legal frameworks. Where the GDPR applies, we rely on adequacy decisions, standard contractual clauses or other approved mechanisms to safeguard international transfers.
10. Vendor and Third-Party Management
Before onboarding third-party service providers, we assess their data protection capabilities and require them to sign data processing agreements that incorporate confidentiality, security and breach notification obligations. Vendors must notify us promptly of any data breach involving Dhimson data to enable us to meet our own notification deadlines.
11. Data Retention and Disposal
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected or as required by law. After the retention period, data is securely deleted or irreversibly anonymised. Physical records are shredded and digital records are securely wiped.
12. Training and Awareness
All staff members and contractors undergo mandatory data protection and information security training when joining Dhimson and at regular intervals thereafter. Training covers legal obligations, security practices, recognising and reporting incidents, and proper handling of personal data.
13. Audits and Compliance
Compliance with this policy is monitored through periodic internal and external audits. Data Protection Impact Assessments are conducted for new projects or technologies that involve high risks. Findings from audits and assessments are reported to management and corrective actions are implemented.
14. Enforcement
Violations of this policy may result in disciplinary action, including termination of employment or contracts, and may expose the violator to civil or criminal penalties.
15. Contact
For data protection enquiries or to exercise your rights, contact our Data Protection Officer:
- Email: info@dhimson.com
- Phone: 9756797901