Privacy Policy
Policies
On this page
- Who We Are (Data Fiduciary)#
- Personal Data We Collect#
- How and Why We Use Your Data (Purposes)#
- Consent#
- Children's Data#
- How We Share Your Data#
- Data Storage, Location & Security#
- Your Rights (Data Principal Rights under the DPDP Act)#
- Data Retention#
- Cookies & Tracking#
- Third-Party Links#
- Changes to this Policy#
- Contact & Grievances#
- Related Legal Documents#
EnthiosHub — Privacy Policy
Operating Entity: [ENTITY LEGAL NAME] (CIN [CIN]), registered office at [REGISTERED ADDRESS] (the "Company", "we", "us", "our"). Version: 1.0 · Effective Date: [EFFECTIVE DATE] · Last Updated: [DATE] Data Protection / Grievance Officer: privacy@enthioshub.com · grievance@enthioshub.com
This Privacy Policy explains how EnthiosHub collects, uses, shares, stores, and protects Your personal data when You use our Services, and Your rights in relation to that data. It is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"). By using the Services, You consent to the practices described here.
1. Who We Are (Data Fiduciary)#
For personal data processed through the Platform, the Company acts as the Data Fiduciary (equivalent to a data controller). Where the Company processes data on behalf of an Organizer for the Organizer's own purposes, the Organizer is an independent Data Fiduciary and this Policy does not govern the Organizer's independent use of Your data.
2. Personal Data We Collect#
We collect only the data reasonably necessary to provide the Services.
2.1. Data You provide directly:
- Account & profile: name, email address, phone number (with country code), date of birth, city, country, profile photo/avatar, bio, education/occupation details (where provided).
- Event registration: information you submit in Event registration forms (which may include custom fields set by the Organizer).
- Communications: messages, chat, reviews, feedback, support and contact-form submissions.
- User-Generated Content: submissions, ideas, projects, files, and media you upload.
2.2. Data collected automatically:
- Technical/usage data: IP address, device/browser information, session identifiers, and activity logs, collected for security, fraud prevention, audit, and service operation.
- Cookies: a first-party session cookie necessary for authentication (see the Cookie Policy).
2.3. Payment data:
- Payments are processed by our Payment Partner (Razorpay). We do not collect or store your full card, bank account, or UPI credentials. We store only transaction references, payment status, invoices, and gateway metadata necessary for records and reconciliation.
2.4. Identity verification (Organizers):
- Organizer identity and bank verification (KYC) is performed by our Payment Partner as part of connected-account onboarding. The Company does not collect or store Organizer Aadhaar numbers, PAN, or bank-account documents for this purpose. We store only a verification status flag and the Payment Partner's account reference. Any limited in-house verification (e.g., institutional or email/phone confirmation) collects only the minimum data required, as described in the KYC & Identity Verification Policy.
2.5. Sensitive personal data:
- We minimize collection of sensitive personal data. Where any sensitive data (e.g., financial verification status) is processed, it is handled with additional safeguards and encryption.
3. How and Why We Use Your Data (Purposes)#
We process personal data for the following purposes, each with a lawful basis under the DPDP Act (your consent, or "legitimate uses" such as performing the service you requested, security, and legal compliance):
| Purpose | Examples |
|---|---|
| Providing the Services | Creating your account, registering you for Events, issuing tickets/certificates, processing payments and refunds |
| Communications (transactional) | OTPs, booking confirmations, Event reminders, account and payment notifications |
| Marketing (consent-based) | Newsletters and promotional messages — only if you opt in |
| Security & fraud prevention | Authentication, detecting fraud/abuse, protecting Users and the Platform |
| Legal compliance | Tax, accounting, grievance redressal, responding to lawful requests |
| Improvement & analytics | Aggregated, internal analytics to improve the Services |
We do not use children's data for behavioural tracking or targeted advertising.
4. Consent#
4.1. We obtain your consent at the point of collection (e.g., an affirmative, unticked checkbox at registration) and record the consent type, policy version, date/time, and IP address.
4.2. Marketing consent is optional and separate from your acceptance of these Terms. You may withdraw any consent at any time (see Section 8), without affecting the lawfulness of prior processing or your ability to use core Services that do not depend on that consent.
4.3. For transactional communications essential to the Services (e.g., OTPs, payment receipts), we rely on the necessity of performing the requested service rather than separate marketing consent.
5. Children's Data#
5.1. The Services are intended for users aged 18 and above. We do not knowingly collect personal data of Minors (under 18) for independent accounts.
5.2. Where a Minor participates through a parent, guardian, or registering institution, that adult/institution is responsible for providing verifiable consent and for the Minor's data. We do not undertake behavioural monitoring or targeted advertising directed at Minors.
5.3. If we learn that we have collected a Minor's data without appropriate consent, we will delete it promptly. Report such instances to privacy@enthioshub.com.
6. How We Share Your Data#
We share personal data only as necessary:
6.1. With Organizers — when you register for an Event, we share the registration data the Organizer needs to deliver the Event (e.g., name, contact, registration answers). Organizers must use this data only for the Event and in compliance with law.
6.2. With service providers / processors (Data Processors): payment processing (Razorpay), email delivery (Resend/AWS SES/SMTP providers), SMS delivery (Fast2SMS, where enabled), cloud hosting and storage (AWS), error monitoring (Sentry), and authentication (Firebase/social login, where used). These parties process data on our instructions under contractual safeguards.
6.3. Legal & safety: to comply with law, court orders, or lawful requests; to enforce our Terms; and to protect the rights, safety, and property of Users, Organizers, the public, or the Company.
6.4. Business transfers: in connection with a merger, acquisition, or asset sale, subject to this Policy.
6.5. We do not sell your personal data.
7. Data Storage, Location & Security#
7.1. Data is stored on secured servers. Sensitive fields (including verification status and any financial identifiers we hold) are encrypted at rest; transport is secured via HTTPS.
7.2. We implement reasonable security practices consistent with the SPDI Rules and industry standards, including access controls, audit logging, and role-based permissions.
7.3. Data is primarily stored in India / [HOSTING REGION]. Where any processor stores or processes data outside India, we take steps to ensure protection consistent with Applicable Law.
7.4. No system is perfectly secure. In the event of a personal-data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act.
8. Your Rights (Data Principal Rights under the DPDP Act)#
Subject to Applicable Law, you have the right to:
8.1. Access — obtain a summary of the personal data we process about you and the processing activities.
8.2. Correction & updating — correct or complete inaccurate or incomplete data.
8.3. Erasure — request deletion of your personal data where it is no longer necessary for the purpose or where you withdraw consent, subject to our legal retention obligations.
8.4. Withdraw consent — withdraw previously given consent (e.g., marketing) at any time.
8.5. Grievance redressal — raise a complaint with our Grievance Officer.
8.6. Nominate — nominate another individual to exercise your rights in the event of death or incapacity.
To exercise these rights, contact privacy@enthioshub.com. We may verify your identity before acting. We support data export via an automated request mechanism where available.
9. Data Retention#
9.1. We retain personal data only as long as necessary for the purposes described, or as required by Applicable Law (e.g., tax, accounting, and financial records are retained for the statutory period, typically up to 8 years).
9.2. Where retention is no longer required, data is deleted or anonymized in accordance with our Data Retention Policy. Certain audit and security logs (including IP addresses) are retained for a limited period for fraud prevention and legal compliance.
10. Cookies & Tracking#
We use a first-party session cookie strictly necessary for authentication. We do not currently use third-party advertising or tracking cookies. Any analytics are internal and, where third-party analytics are enabled, they operate on an opt-in basis. See the Cookie Policy for details.
11. Third-Party Links#
The Services may contain links to third-party websites or Organizer materials. We are not responsible for the privacy practices of third parties. Review their policies before providing data.
12. Changes to this Policy#
We may update this Policy from time to time. Material changes will be notified through the Platform or by email, and the "Last Updated" date will be revised. Continued use after an update constitutes acceptance.
13. Contact & Grievances#
- Data Protection / Privacy queries: privacy@enthioshub.com
- Grievance Officer: [GRIEVANCE OFFICER NAME], grievance@enthioshub.com, [REGISTERED ADDRESS]
- We acknowledge grievances within 48 hours and resolve them within the timelines prescribed under Applicable Law. See the Grievance Redressal Policy for escalation steps.
- Legal notices, registered office details, and related notices are set out in Contact & Legal Notices.
- Identity verification practices are described in the KYC & Identity Verification Policy.
- This Privacy Policy should be read together with our Terms & Conditions and Cookie Policy.
14. Related Legal Documents#
This Privacy Policy forms part of the EnthiosHub legal framework. The current published versions of all related documents are available below:
- Terms & Conditions
- Refund & Cancellation Policy
- Cookie Policy
- Organizer Agreement
- Vendor Agreement
- Community Guidelines
- Code of Conduct (unavailable)
- Acceptable Use Policy
- Copyright Policy
- Intellectual Property Policy
- Payment & Settlement Policy
- KYC & Identity Verification Policy
- Data Retention Policy
- Content Moderation Policy
- Ticketing Terms
- Event Organizer Responsibilities
- User Responsibilities
- Limitation of Liability
- Dispute Resolution Policy
- Grievance Redressal Policy
- Contact & Legal Notices
- Platform Disclaimer
- Signup Consent (unavailable)
- Organizer Registration Consent (unavailable)
- Identity Verification Consent (unavailable)
- Marketing Email Consent (unavailable)
- SMS Consent (unavailable)
- WhatsApp Consent (unavailable)
This Privacy Policy should be reviewed and approved by a licensed advocate before publication. Complete all [BRACKETED] placeholders before going live.