Statutory Data Protection Notice

Privacy Policy & DPDP Notice

Compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act, Act No. 22 of 2023) and the Information Technology Act, 2000 of India.

Effective Date: October 01, 2025 • Last Revised: August 25, 2026 • Jurisdiction: Ahmedabad, Gujarat, India
Executive Summary of Data Principal Rights

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), you are the Data Principal and B A C Web Development & Cloud Solutions operates as the Data Fiduciary. We collect, store, and process only digital personal data that is strictly necessary for specified lawful purposes with your explicit, informed consent or legitimate statutory grounds. You retain absolute rights to access, correct, erase your personal data, withdraw consent at any time, and seek time-bound grievance redressal.

1 Data Fiduciary Identity & Scope of Policy

This Privacy Policy applies to all digital personal data collected or processed by B A C Web Development & Cloud Infrastructure (referred to as "B A C", "we", "us", or "our"), headquartered in Ahmedabad, Gujarat, India, through our website (officialbac.in), client portal, application deployment tools, subdomains, status matrices, and related API nodes.

This notice is published pursuant to Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act) and Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2 Categories of Personal Data We Process

We process the following specific categories of digital personal data provided directly by you or generated during system utilization:

Identity & Contact Data

Full Name, Email Address, Phone/WhatsApp number, Company Name, Billing Address, Country/State.

Deployment & Technical Metadata

Git repository URLs, custom domain mappings, server logs, Node.js runtime parameters, IP addresses, browser User-Agent.

Financial & Transaction Reference Data

Razorpay Order IDs, Payment Transaction Hashes, GST numbers, Invoice receipts. (Raw credit card/banking data is never stored on our servers).

Telemetry & Alert Subscriptions

Browser Web-Push VAPID tokens, selected monitored microservices, regional edge node preferences, notification event logs.

3 Lawful Grounds and Purposes of Processing

In strict accordance with Section 4 and Section 6 of the DPDP Act, 2023, personal data is processed solely for specified, lawful, and transparent purposes:

  • Execution of Service Contracts: To provision web development projects, initialize cloud hosting containers, build code packages, and manage custom domain edge routers.
  • Billing & Statutory Taxation: To generate GST-compliant invoices and securely process project payments through authorized payment gateways (Razorpay).
  • Service Telemetry & Reliability Monitoring: To dispatch automated alerts on system downtime, maintenance schedules, and security incidents.
  • Customer Support & Diagnostics: To resolve technical tickets, appeals, and system inquiries via authenticated channels.
  • Compliance with Legal Obligations: To adhere to applicable statutory regulations, tax filings, and directives from judicial or law enforcement authorities in India.

4 Consent Architecture & Right to Withdraw Consent

Consent is obtained through clear, affirmative actions (e.g., submitting forms, accepting client onboarding terms, or activating push subscriptions). Consent notices are presented in simple language.

Section 6(4) DPDP Act Notice: You hold the statutory right to withdraw your consent at any time as easily as giving it. You may withdraw consent by clicking "Unsubscribe" in alert emails, toggling permissions in the Client Dashboard, or submitting a formal withdrawal notice to [email protected].

5 Your Statutory Rights as a Data Principal (DPDP Act, 2023)

Under Chapter III (Sections 11 to 14) of the DPDP Act, you are entitled to the following enforceable statutory rights:

1. Right to Access Information (Section 11)

You may request a complete summary of your personal data being processed, processing activities conducted, and the identities of all third-party Data Processors with whom data has been shared.

2. Right to Correction and Erasure (Section 12)

You have the right to correct inaccurate data, complete incomplete information, update outdated details, and demand the complete erasure (deletion) of personal data when the original processing purpose is satisfied or consent is withdrawn.

3. Right of Grievance Redressal (Section 13)

You have the right to register complaints regarding any aspect of data processing with our designated Grievance Officer and receive time-bound redressal within 30 days.

4. Right to Nominate (Section 14)

You may nominate another individual who, in the event of your death or incapacity, shall exercise your Data Principal rights.

6 Reasonable Security Safeguards & Breach Protocols

Under Section 8(5) of the DPDP Act, we enforce stringent technical and organizational security controls to prevent unauthorized access, alteration, disclosure, or destruction:

  • Encryption Standards: AES-256 encryption at rest for sensitive configurations, bcrypt salting for passwords, and TLS 1.3 cryptographic protocols in transit.
  • Role-Based Access Control (RBAC): Principle of least privilege enforced across internal engineering and administrative dashboards.
  • Breach Notification Mechanism (Section 8(6)): In the unlikely event of a verified personal data breach, B A C will immediately notify the Data Protection Board of India and all affected Data Principals in the prescribed form and manner without undue delay.

7 Processing of Children's Personal Data (Section 9)

Our web development and cloud infrastructure services are directed exclusively to business clients and individuals aged 18 years or older. We do not knowingly process personal data of children below the age of 18 or persons with disabilities without verifiable parental or guardian consent. We strictly prohibit behavioral tracking or targeted advertising directed toward minors.

8 Third-Party Data Processors & Data Transfers

We engage trusted third-party Data Processors bound by contractual data processing agreements that mirror our statutory DPDP obligations:

Razorpay Software Pvt Ltd (India): Payment Gateway & Processing.
Brevo / Sendinblue: Transactional System Notifications & SMTP.
MongoDB Inc: Secure Multi-Region Database Infrastructure.
Cloudflare Inc: Edge Routing, CDN Caching, and DDoS Protection.

9. Statutory Data Protection & Grievance Redressal Officer

In compliance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 3(11) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the details of our designated Grievance Officer are set out below:

Grievance Officer Pushkar & Compliance Cell B A C Web Development & Cloud Services
Physical Registered Office Ahmedabad, Gujarat 380001, India
Response & Redressal Timeline Acknowledgment within 24 hours • Redressal within 30 days

If your grievance is not resolved within the statutory timeline, you retain the statutory right to file a complaint before the Data Protection Board of India.