Digital Personal Data Protection (DPDP) Policy

[Formulated under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025]
Policy adopted and approved in the Board Meeting dated 07/04/2026.

1. Introduction and Purpose

This Digital Personal Data Protection Policy (“Policy”) is formulated with reference to the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), as applicable to the Organisation from time to time.

Logix Built Solutions Limited (“Organisation”, “we”, “us”, or “our”) is committed to processing digital personal data lawfully, fairly, transparently, and securely. This Policy sets out the internal governance principles, technical safeguards, and operational obligations governing the processing of personal data of individuals (“Data Principals”).

This Policy is intended to:

  • Establish an internal framework for compliance with the DPDP Act, DPDP Rules, and other applicable privacy and data protection requirements, as applicable from time to time.
  • Protect and give effect to the statutory rights of Data Principals recognized under applicable law.
  • Define the roles, standards, and responsibilities of Personnel and Data Processors in handling personal data.
  • Foster an organisation-wide culture of data governance, security, and accountability.

2. Scope and Applicability

2.1 Applicability
This Policy applies to:

  • All processing of digital personal data carried out within the territory of India.
  • Processing of digital personal data outside India, where such processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India.
  • All directors, officers, employees, contractors, consultants, and other persons acting under the Organisation’s authority who are authorised to process personal data on behalf of the Organisation (“Personnel”), as applicable.
  • Personal data collected in non-digital form that is subsequently digitised.

Third-party service providers and Data Processors engaged by the Organisation shall be subject to appropriate contractual, confidentiality, security, and data protection obligations, as applicable under relevant agreements.

2.2 Exclusions
This Policy does not apply to:

  • Personal data processed by an individual for any personal or domestic purpose.
  • Personal data that is made or caused to be made publicly available by the Data Principal to whom such personal data relates, or by any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.

3. Definitions

Unless the context otherwise requires, terms used in this Policy shall carry the meaning assigned to them under the DPDP Act and the rules framed thereunder:

  • “Act” or “DPDP Act”: Means the Digital Personal Data Protection Act, 2023, as amended from time to time.
  • “Consent”: Means any freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes, signified through a clear affirmative action, agreeing to the processing of their personal data for a specified purpose.
  • “Consent Manager”: Means a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.
  • “Data Fiduciary”: Means any person who alone or in conjunction with other persons determines the purpose and means of processing personal data. For processing activities where the Organisation determines the purpose and means of processing, the Organisation shall act as the Data Fiduciary. Where the Organisation processes personal data solely on behalf of another Data Fiduciary and in accordance with its documented instructions, the Organisation shall act as a Data Processor, to the extent applicable under the DPDP Act and DPDP Rules.
  • “Data Principal”: Means the individual to whom the personal data relates, and includes the parent or lawful guardian in the case of a child, or the lawful guardian in the case of a person with disability.
  • “Data Processor”: Means any person who processes personal data on behalf of a Data Fiduciary.
  • “Personal Data”: Means any data about an individual who is identifiable by or in relation to such data.
  • “Personal Data Breach”: Means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data.
  • “Processing”: Means a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination, restriction, erasure, or destruction.
  • “Significant Data Fiduciary” or “SDF”: Means a Data Fiduciary, or class of Data Fiduciaries, notified as such by the Central Government under Section 10 of the DPDP Act, having regard to such factors as may be applicable under the DPDP Act, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.

4. Grounds for Processing Personal Data

The Organisation shall process personal data only in accordance with the DPDP Act and for a lawful purpose, based on the Data Principal’s consent or for certain legitimate uses recognised under the DPDP Act, as applicable.

4.1 Consent

  • Where consent is the applicable basis for processing, consent shall be free, specific, informed, unconditional, and unambiguous, obtained through a clear affirmative action. Pre-ticked boxes, default opt-ins, or bundled consent mechanisms are strictly prohibited.
  • A clear and standalone notice in plain English language shall accompany or precede the request for consent and shall provide the Data Principal with the information required under the DPDP Act and DPDP Rules, including an itemised description of the personal data to be processed, the specified purpose(s) of processing, and the manner in which the Data Principal may exercise applicable rights, withdraw consent, and make a grievance or complaint.
  • The request for consent shall be presented separately from other contractual terms, in an accessible format, ensuring that each specified purpose is identifiable independently.
  • The Data Principal may withdraw consent at any time, with the ease of doing so being comparable to the ease with which consent was given. Upon receipt of a valid withdrawal request, the Organisation shall cease processing based on that consent and cause its Data Processors to cease such processing within a reasonable time, unless processing without consent is otherwise required or authorised under applicable law.
  • Where the Organisation integrates with a registered Consent Manager, consent may also be given, managed, reviewed, or withdrawn by the Data Principal through that platform.
  • For Data Principals who are children (under 18 years of age) or persons with disabilities who have a lawful guardian, verifiable consent shall be obtained from the parent or lawful guardian prior to processing, in accordance with the prescribed verification mechanisms.

4.2 Certain Legitimate Uses

The Organisation may process personal data without consent where such processing is permitted as a “certain legitimate use” under Section 7 of the DPDP Act, as applicable to the Organisation and the relevant processing activity. Such legitimate uses may include, where applicable:

  • Processing for the specified purpose for which the Data Principal has voluntarily provided their personal data, and has not indicated that they do not consent to its use.
  • Performance of any function under law or provision of any subsidy, benefit, service, certificate, or licence by the State or its instrumentalities.
  • Compliance with any judgment, decree, or order issued under any law in India, or any judgment/order relating to contractual or civil claims under law outside India.
  • Responding to a medical emergency involving a threat to the life or immediate health of the Data Principal or any other individual.
  • Taking measures to provide health services or ensure safety during epidemics, public health threats, disasters, or breakdowns of public order.
  • Purposes related to employment, including safeguarding the employer from loss or liability, prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, or provision of employee benefits.
  • Other uses expressly permitted or notified under Section 7 of the DPDP Act.

5. Processing of Children’s Data and Data of Persons with Disabilities

Before processing personal data of a child or a person with disability who has a lawful guardian, the Organisation shall obtain verifiable consent from the parent or lawful guardian, using reasonable verification measures prescribed under applicable rules.

The Organisation shall not undertake tracking, behavioural monitoring, or targeted advertising directed at children, or process children’s personal data in a manner likely to cause a detrimental effect on their wellbeing, except to the extent expressly permitted under the DPDP Act, DPDP Rules, or any applicable exemption or lawful purpose.

Where the Organisation qualifies for any class- or purpose-based exemption under the DPDP Act or DPDP Rules, such exemption shall be relied upon only to the documented extent permitted and subject to all applicable conditions and safeguards.

6. Obligations of the Organisation

6.1 Purpose Limitation and Data Minimisation

Personal data shall be collected and processed strictly for the specified purpose(s) disclosed at or before the time of collection, and limited to such personal data as is reasonably necessary for that specified purpose.

6.2 Data Accuracy, Completeness and Consistency

The Organisation shall take reasonable steps to ensure that personal data processed by it or on its behalf is accurate, complete, and consistent, particularly where such data is likely to be used to make a decision affecting the Data Principal or is disclosed to another Data Fiduciary.

6.3 Storage Limitation and Erasure

Personal data shall not be retained beyond the period necessary for the specified purpose, or beyond any applicable retention period prescribed under the DPDP Act, DPDP Rules, or other applicable law, unless further retention is required or permitted by law.

Where the Organisation is subject to a prescribed retention/erasure period under the DPDP Rules that requires prior notice to the Data Principal, the Organisation shall provide such notice in the manner and within the timeframe prescribed under applicable law.

Where processing is based on consent, upon withdrawal of consent, or where the specified purpose is no longer being served, whichever is earlier, the Organisation shall erase the relevant personal data and, where applicable, cause its Data Processors to erase such personal data, unless retention is required or permitted under applicable law.

Where the Organisation acts as a Data Processor, erasure shall be undertaken in accordance with the applicable Data Fiduciary’s documented instructions and the applicable contractual and legal requirements.

6.4 Reasonable Security Safeguards

The Organisation shall implement reasonable technical and organisational measures appropriate to the nature, scope, context, and risks of the processing, including appropriate access controls, encryption or equivalent safeguards, monitoring and logging, measures for detecting, preventing, addressing, and mitigating unauthorised access or personal data breaches, and measures to support business continuity and recovery.

6.5 Personal Data Breach Management

On becoming aware of a personal data breach, the Organisation shall notify the Data Protection Board of India and affected Data Principals without undue delay and in the form, manner, and within the timelines prescribed under the DPDP Act and DPDP Rules, as applicable.

The Organisation shall maintain a documented incident response process and designate appropriate personnel or an incident response team, as appropriate to the nature and severity of the incident, to contain, investigate, remediate, and document personal data breaches. Records of material personal data breaches and related actions shall be maintained in accordance with applicable law.

Where the Organisation is separately subject to incident reporting obligations under CERT-In directions or sectoral regulatory frameworks, such intimations shall be made in parallel.

6.6 Grievance Redressal Mechanism

The Organisation shall maintain an effective and readily accessible grievance redressal mechanism through its Grievance Officer / Authorised Privacy Contact Person, and shall respond to grievances within the statutory timelines prescribed under the DPDP Rules.

6.7 Data Processor Oversight and Processing Engagements

Where the Organisation engages Data Processors to process personal data on its behalf, it shall do so under appropriate written contractual arrangements requiring confidentiality, compliance with applicable data protection and security requirements, appropriate technical and organisational safeguards, and notification of personal data breaches within the timeframe specified in the applicable agreement and law.

Where the Organisation acts as a Data Processor for another Data Fiduciary, processing shall be undertaken in accordance with the applicable Data Fiduciary’s documented instructions, the relevant contractual arrangements, and applicable law.

7. Rights of Data Principals

The Organisation recognizes and facilitates the following statutory rights of Data Principals under the DPDP Act:

  • Right to Access Information: To obtain, in the manner prescribed under applicable law, a summary of the personal data being processed and the processing activities undertaken, together with the identities of other Data Fiduciaries and Data Processors with whom the personal data has been shared and a description of the personal data so shared, subject to applicable legal exceptions.
  • Right to Correction, Completion, Updating and Erasure: To request correction of inaccurate or misleading personal data, completion of incomplete personal data, updating of personal data, and erasure of personal data where applicable under the DPDP Act and DPDP Rules, subject to the specified purpose, applicable legal requirements, and prescribed procedures.
  • Right to Grievance Redressal: To access readily available grievance redressal mechanisms in respect of any act or omission of the Organisation regarding its obligations under the DPDP Act.
  • Right to Nominate: To nominate another individual to exercise statutory rights on behalf of the Data Principal in the event of death or incapacity, in the prescribed manner.
  • Right to Withdraw Consent: To withdraw consent at any time, with the same ease as it was given, where processing is based on consent, without affecting the legality of processing prior to withdrawal.

The Organisation shall acknowledge and respond to valid requests for the exercise of these rights within the timelines prescribed under the DPDP Rules.

8. Duties of Data Principals

In accordance with Section 15 of the DPDP Act, Data Principals shall:

  • Comply with the provisions of all applicable laws for the time being in force while exercising statutory rights.
  • Ensure not to impersonate another person while providing personal data for a specified purpose.
  • Ensure not to suppress any material information while providing personal data for any document, unique identifier, proof of identity, or proof of address issued by the State or its instrumentalities.
  • Ensure not to register false or frivolous grievances or complaints with the Organisation or the Data Protection Board of India.
  • Furnish only such information as is verifiably authentic while exercising the right to correction or erasure.

9. Cross-Border Transfer of Personal Data

The Organisation may transfer personal data outside India, including to Data Processors, where permitted under applicable law. Any such transfer shall be subject to applicable restrictions or requirements prescribed by the Central Government, contractual and technical safeguards, and other applicable legal and regulatory requirements. Such transfer shall not affect the applicability of Indian law or the rights of Data Principals under applicable law.

10. Additional Obligations of Significant Data Fiduciaries

If the Organisation is notified as a Significant Data Fiduciary by the Central Government under Section 10 of the DPDP Act, it shall fulfill the following additional statutory obligations:

  • Appoint a Data Protection Officer based in India, who shall represent the Organisation, be responsible to the Board of Directors, and act as the point of contact for grievance redressal.
  • Appoint an independent data auditor to carry out periodic data audits of its processing activities and compliance.
  • Undertake Data Protection Impact Assessments and audits at the intervals and in the manner prescribed under the DPDP Act and DPDP Rules, including in relation to applicable algorithmic software, and undertake such other measures as may be prescribed.

11. Grievance Officer / Authorised Privacy Contact Person

The Organisation has designated the following person as its Grievance Officer / Authorised Privacy Contact Person to oversee compliance with this Policy, receive communications from Data Principals, and act as the primary contact:

Name: Mr. Chirag Patel | Designation: Chief Technology Officer

Email: cp@logixbuilt.com

Address: Sh. 314 - 322, Sahaj Icon, Near Prime Arcade, A M Road, Adajan, Surat - 395009, Gujarat, India

12. Training and Awareness

The Organisation shall conduct periodic training and awareness sessions for Personnel on data protection principles, individual operational obligations, and statutory requirements under the DPDP Act and DPDP Rules, including during the onboarding of new personnel.

13. Phased Implementation and Alignment

The Organisation recognises that the DPDP Act and DPDP Rules are subject to the applicable commencement and implementation schedule notified by the Central Government. The Organisation shall align its systems, contracts, policies, and processes with each applicable requirement by the relevant statutory commencement date and shall update this Policy as necessary to reflect amendments, notifications, directions, or changes in applicable law.

14. Policy Review, Governance and Updates

This Policy shall be reviewed whenever necessitated by changes in data protection legislation, regulatory directions, or corporate operational models. Amendments to this Policy shall be approved in accordance with the Organisation's applicable corporate governance and delegation framework and communicated to relevant stakeholders, as appropriate.

15. Consequences of Non-Compliance and Statutory Penalties

Non-compliance with this Policy by any Personnel may result in disciplinary action, up to and including termination of employment or contract, subject to applicable law and the terms of employment or contract, without prejudice to any statutory or contractual consequences applicable to the Organisation or the concerned person.

The Data Protection Board of India may impose monetary penalties and take such other action as may be prescribed under the DPDP Act, DPDP Rules, and other applicable law, as amended from time to time, for breaches of statutory obligations.

Want a Discuss with Project?

Looking for tailored solutions to get the most from the digital landscape? We are here to help you. Connect now, and let’s explore how Logix Built Solutions Limited can bring your vision to life with innovative and customized digital solutions!

compny-img

Get in Touch!

Let's make something amazing together!

Note: Business inquiry only, check our Career page for jobs.