Additional privacy policy clauses for NGO/CSR Document Management & Compliance Platform
These additional clauses supplement the general Privacy Policy and specifically address the processing, storage, and management of organizational compliance documents, financial records, and sensitive data on our platform.
Gracelist Technologies Pvt Ltd operates as a Data Processor under the Digital Personal Data Protection Act, 2023.
You (the registered NGO, organization, corporate entity, or CSR partner) act as the Data Controller and Data Owner of all information, documents, and personal data uploaded to the Platform.
We process data solely on your instructions and for the purposes of:
As Data Controller, you are responsible for:
By uploading any document, certificate, financial record, or organizational data to the Platform, you explicitly consent to:
You specifically acknowledge and consent that the Platform may process Sensitive Personal Data as defined under the Digital Personal Data Protection Act, 2023, including:
Financial information and banking details
Identity verification documents and certificates
Digital signature credentials and related proofs
Employment and organizational registration data
You warrant that you have obtained necessary consents from all individuals whose personal data appears in uploaded documents, including employees, directors, auditors, and beneficiaries.
For all Category A and Category B data, we implement:
With your explicit configuration and authorization, the Platform enables sharing of designated documents with:
We do NOT:
Our infrastructure utilizes cloud service providers with data centers in India. For any transfer outside India, we ensure:
IMPORTANT: The Platform functions as a document storage and management system. We do NOT:
Responsibility for document authenticity rests solely with the uploading Data Controller.
Unless explicitly engaged under a separate written agreement for audit or verification services, we do not independently verify compliance status with regulatory authorities or validate bank account ownership.
To the maximum extent permitted by law, we shall not be liable for indirect, incidental, special, or consequential damages, loss of profits, revenue, or business opportunities.
Our total liability shall not exceed the total fees paid by you to the Platform in the twelve (12) months preceding the claim.
In the event of a security incident:
The Platform maintains comprehensive audit logs including:
Upload, download, view, deletion events with timestamps
Login/logout events, IP address, device information
Backups, security alerts, configuration changes
We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and all applicable rules and regulations issued thereunder.
Obtain confirmation of processing and access personal data
Request correction or erasure of personal data
Register complaints and expect resolution within timeframes
Receive data in structured, machine-readable format
We have appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance.
Contact: info@gracelist.in
Any unauthorized access to Tier 1 data triggers immediate notification, automatic access suspension, mandatory password reset, and incident report to DPO within 4 hours.
Unless explicitly engaged under a separate written agreement, we do not independently verify content, validate legal status, authenticate certificates, or investigate legitimacy of uploaded materials.
We do not provide legal advice on compliance requirements, financial advisory services, regulatory filing assistance, or certification of compliance status.
You agree NOT to use the Platform for:
Violation may result in immediate account suspension and reporting to authorities.
All primary data storage occurs within India using cloud infrastructure with data centers located in Mumbai, Hyderabad, and Pune.
All providers maintain ISO 27001, SOC 2 Type II, and PCI-DSS certifications.
For any cross-border transfer, we implement Standard Contractual Clauses (SCCs), maintain encryption, limit access to personnel with legitimate need, and conduct regular audits.
Confirmation of processing, categories, purposes, recipients
Copy of personal data, sources, processing logic
Correction of inaccurate or incomplete data
Erasure when no longer necessary
Restrict processing in specific circumstances
Structured, machine-readable format transfer
To exercise these rights, data subjects should contact their organization (Data Controller) in the first instance. Valid requests are forwarded to us for implementation within 30 days.
Our Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children.
If we discover that a child's personal data has been uploaded without appropriate consent, we will notify the Data Controller immediately and assist in removing such data.
We may update this Privacy Policy periodically to reflect changes in legal or regulatory requirements, business practices, or security improvements.
Email: info@gracelist.in
Company: Piana IT Solutions Private Limited
Email: info@gracelist.in
Response Time: 30 days from complaint receipt
Data Protection Board of India - As established under the DPDP Act, 2023
By registering for and using the Platform, you acknowledge that you have:
Read and understood this Privacy Policy in its entirety
Understood your role as Data Controller and our role as Data Processor
Obtained necessary consents from data subjects
Agreed to the processing activities described herein
Accepted the limitations of liability and disclaimers stated herein
This Privacy Policy is a legal document. Please review carefully and retain for your records.