← Back
Terms Privacy DPDP Notice
Vishwamangal Marathi Foundation

Privacy Policy

Vishwamangal Marathi Foundation ("the Foundation", "we") · Vishwamangal Business Forum member portal · Last updated: 24 September 2026

1. Who We Are

The Foundation operates the Vishwamangal Business Forum portal to enable business networking among its members. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Foundation is the Data Fiduciary for personal data processed on the Portal.

2. Personal Data We Collect

(a) Identity & contact data: name, email address, phone number, photograph, postal address including country, state, district, city, and pincode.

(b) Business data: business name, business category, forum and region, business bio, and "ideal referral" description.

(c) KYC documents: personal identity documents (such as Aadhaar, PAN, passport, voter ID, driving licence) and business documents (such as GST certificate, registration certificates) that you upload for verification.

(d) Activity data: meeting attendance records, referrals given and received, TYFCB values, one-to-one meeting logs, membership applications, payments and receipts, support chat messages, consents given, and an audit log of significant actions (such as logins, uploads, downloads, and administrative changes).

(e) Technical data: essential cookies for login sessions and security, and standard server logs.

3. Purposes of Processing

We process personal data to: (i) create and administer member accounts; (ii) operate the member directory and referral system, which is the core purpose of the Portal; (iii) record attendance and produce forum reports; (iv) verify member identity and business through KYC review; (v) record fees and issue receipts; (vi) send service emails (welcome, password, referral, attendance, receipts, announcements); (vii) provide member support; (viii) maintain security, prevent misuse, and keep audit trails; and (ix) comply with legal and accounting obligations.

4. Lawful Basis and Consent

Processing is based on the consent you provide at first login and, where applicable, on legitimate uses recognised by the DPDP Act (such as compliance with law). You may withdraw consent at any time (see Section 9); withdrawal does not affect processing already carried out and may make continued membership impracticable, since the Portal cannot operate without core member data.

5. Who Can See Your Data

(a) Fellow members: your directory profile (name, photo, business name, category, forum, city, bio, ideal referral) is visible to logged-in members to enable networking. Your KYC documents, payments, address details, and support chats are never visible to other members.

(b) Forum leadership: attendance, referral statistics, and membership applications for their forum.

(c) Regional administrators: member records, KYC documents, payments, and support conversations for their region only.

(d) Foundation (HQ) administrators: records across the network, including the audit log and email outbox, for administration and support.

(e) Service providers: email delivery providers process names and email addresses to deliver Portal emails. We do not sell personal data, and we do not share it with third parties for their marketing.

6. How We Protect Your Data

Security measures include: passwords stored using strong one-way hashing; forced password change on first login; role-based access control enforced on the server; KYC files stored on private storage outside the web root, downloadable only through authorised, logged routes; automatic watermarking of uploaded KYC documents stating their restricted purpose; re-encoding of uploaded images to strip hidden metadata; and an audit log of significant actions including every KYC download.

7. Data Retention

We retain member records for the duration of membership and thereafter as needed for legal, tax, accounting, and audit purposes (generally up to 8 years for financial records). KYC documents of former members are deleted or anonymised once retention obligations lapse. Audit logs are retained for security purposes. You may request earlier erasure as described below, subject to legal requirements.

8. Your Rights (DPDP Act, 2023)

You have the right to: (a) access a summary of your personal data and the processing activities; (b) correction and updating of inaccurate or incomplete data (largely self-service via My Profile); (c) erasure of data no longer necessary, subject to legal retention; (d) grievance redressal; and (e) nominate an individual to exercise your rights in case of death or incapacity.

9. How to Exercise Rights / Grievances

Raise requests through the Portal's Support feature or in writing to the Foundation. We will acknowledge and respond within the timelines prescribed under the DPDP Act and its rules. If unsatisfied, you may escalate to the Foundation's Grievance Officer and thereafter to the Data Protection Board of India.

10. Children

The Portal is intended solely for adults aged 18 or above. We do not knowingly process children's data.

11. Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board and affected Data Principals as required under the DPDP Act.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be notified on the Portal or by email. The current version is always available on the Portal.