This privacy policy explains how grrajeshkumar.com may handle personal data supplied through enquiries and ordinary website use. It describes likely data categories, purposes, sharing, retention, security and user choices. It does not claim that the site collects information or uses tools that are not actually enabled.
Scope of this privacy policy
The policy applies to personal data handled through this website, including information a visitor chooses to provide when making an enquiry. Personal data means data about an identifiable individual. The website operator should keep this notice aligned with the site's real forms, analytics, hosting, email and service providers.
India's Digital Personal Data Protection Act 2023 establishes a framework for processing digital personal data for lawful purposes while recognising individual protection. Application of a particular duty can depend on commencement notifications, rules, the processing activity and the role of the person handling data. This page gives site information, not a substitute for a compliance assessment.
Personal data that may be collected
Information may be received directly when a visitor sends an email or uses an available contact method. This can include a name, email address, telephone number, organisation, selected service and the details placed in a message. Visitors should avoid sending passwords, one-time codes or unnecessary identity documents through a general enquiry.
Web hosting and security systems may record technical information needed to deliver and protect the service. Typical records can include an IP address, browser and device information, requested page, date and time, referring page and security events. The site should disclose any analytics, advertising or third-party tracking actually in use. This policy does not treat every possible browser technology as deployed.
Why information may be used
Personal data should be used for a clear and lawful purpose. Relevant purposes can include responding to an enquiry, arranging a requested consultation, maintaining website security, preventing abuse, diagnosing technical faults, keeping necessary business records and meeting a legal obligation.
Information supplied for an initial enquiry should not be repurposed for unrelated promotion without an appropriate basis. Where consent is relied on, the request should be clear enough for the person to understand the data and purpose. A person should also be told how to withdraw consent where that right applies.
Sharing and service providers
Information may pass to carefully selected providers that support hosting, email, security, backup or professional administration. Such access should be limited to the service required and governed by appropriate confidentiality and security terms. Data may also be disclosed when required by law, a valid court order or a competent authority.
The site should not describe information as never shared if routine hosting or email delivery requires a provider to process it. Nor should a link to another website be confused with data sharing by this site. External websites set their own privacy practices, which visitors should examine before submitting information.
Retention and information security
Personal data should be kept only as long as necessary for the stated purpose, a legal requirement, dispute management or a legitimate record. A fixed period may differ between an unanswered enquiry, an accepted professional engagement, billing records and security logs. When data is no longer required, it should be deleted, anonymised or securely archived as appropriate.
Reasonable administrative and technical safeguards can include access limits, secure credentials, software updates, backups, logging and restricted handling of enquiry records. No internet transmission or storage method is risk-free. If a visitor believes confidential material was sent to the wrong destination, prompt notice can help the operator investigate.
Cookies and linked services
A cookie is a small item of data stored or read by a browser for functions such as session continuity, preferences, security or measurement. The site should identify the categories it actually uses and provide a choice where law or the technology requires one. Browser controls can remove or block cookies, although some site functions may then work differently.
Links may lead to legal resources, courts, government bodies or third-party platforms. Their data practices fall under their own notices. Readers seeking advice on a privacy dispute can review the site's page on a cybersecurity and data privacy lawyer.
Access, correction and other requests
A person may ask what personal data is held about them, request correction of inaccurate information or seek erasure where applicable. Other rights and available remedies depend on the governing law and circumstances. A request should identify the person and the relevant interaction without sending more identity data than necessary.
The operator may need enough information to verify a request and protect another person's data. Some records may be retained when law, legal claims, security or professional duties require it. A response should explain the action taken or the reason a request cannot be fulfilled.
Updates and privacy enquiries
This policy may change when website functions, providers or legal requirements change. The current version should describe actual practice and carry a visible effective date in the page interface or publishing record. Material changes should be communicated in a proportionate way.
Site notices and service information may be posted through the announcements page. To raise a privacy question, use the website's published contact route and state which page or interaction concerns you. Do not include unrelated confidential material in the first message.
