GA Project Exchange Portal

GA Project Exchange Portal

Privacy Policy

Welcome back — sign in to continue

DRAFT — REQUIRES LEGAL REVIEW. This template is provided as a starting point for compliance with the Digital Personal Data Protection Act, 2023 (India). It has not been reviewed by legal counsel and must not be published in its current form. A super-admin can edit and re-publish this policy at Admin → Privacy Policy.

Privacy Policy

Last updated: to be set on publication.

1. Who we are (Data Fiduciary)

This application ("ProjectComms") is operated by the Data Fiduciary named in the footer. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Data Fiduciary determines the purposes and means of processing your personal data.

2. What personal data we collect

  • Identity & contact: name, email address, phone number, job title, employer.
  • Authentication: hashed password, two-factor secrets, Microsoft Entra ID identifier (for SSO users), IP address and device fingerprint at login.
  • Usage: RFIs / submittals / drawings / meeting minutes you create or are named on, comments you post, files you upload, and email delivery / open / click events for notifications sent to you.
  • Auditing: a timestamped log of significant actions (creation, edits, status changes) is retained for legal-record and dispute-resolution purposes.

3. Purpose and legal basis of processing

We process your personal data on the following bases under DPDPA §7:

  • Consent for account creation and profile display.
  • Legitimate use for operating the collaboration platform your employer or client has engaged us to provide, including RFI / submittal workflow, notifications, security logging, and audit trail generation.
  • Legal obligation for records that must be retained under applicable construction, tax, or company law.

4. Sharing and cross-border transfers

Personal data is shared with the following categories of processors and, where applicable, transferred outside India. Cross-border transfers are made in compliance with DPDPA §16 and any restrictions notified by the Central Government.

Processor Region Purpose
Amazon Web Services ap-south-1 (Mumbai) primary; other regions for disaster recovery application hosting and object storage
Transactional email provider (Postmark / Resend / AWS SES) US / EU outbound notifications to your registered email address
Microsoft Entra ID (Azure AD) global Microsoft infrastructure single sign-on for internal staff (does not apply to external / client users)

5. How long we keep your data

Active account data is retained while your access to the platform remains active. Once your account is deactivated (soft-deleted), identifying personal data (name, email, phone) is overwritten with deterministic pseudonyms after the retention window configured by the Data Fiduciary (default: six months), while the underlying project records — which we are contractually and legally obliged to preserve — are retained with the pseudonymised attribution.

6. Your rights as a Data Principal

Under DPDPA §11–§14 you have the right to:

  • obtain a summary of the personal data we hold about you and the processing activities we perform;
  • request correction, completion, updating, or erasure of your personal data;
  • nominate another individual to exercise your rights in the event of your death or incapacity;
  • have any grievance heard by our Grievance Officer.

You can submit any of the above by signing in and visiting Settings → My Data, or by using the public Data Request form.

7. Grievance redressal

Our Grievance Officer — the contact of first resort under DPDPA §8(9) — is listed on the Data Request page. If your grievance is not resolved within the statutory timeframe, you may approach the Data Protection Board of India.

8. Security

We employ reasonable security safeguards, including encryption in transit, hashed credentials, two-factor authentication support, per-project access control, and detailed audit logging, to protect personal data against unauthorised or accidental access, disclosure, or loss.

9. Children's data

This platform is a business collaboration tool intended for professional use. We do not knowingly process personal data of individuals under 18 years of age. If we become aware that we have collected such data, we will promptly delete it.

10. Changes to this Policy

We may update this Privacy Policy from time to time. When we publish a new version, you will be prompted to review and accept the updated terms before continuing to use the application. The version history is retained for regulatory inspection.

By clicking “I Agree” on the invitation acceptance page you acknowledge that you have read, understood, and consent to processing of your personal data as described above.


Grievance Officer / Contact

A Grievance Officer has not yet been configured. Please contact the site administrator.

Submit a data request

Version 1 · published 19 Aug 2026