Privacy Policy
This disclosure outlines the data governance protocols of V Chaitanya Chowdari ("the Controller") in accordance with the Digital Data Accountability and Privacy Act (DDAPA) of 2026. This policy applies to chowdari.in and all associated Lab services.
1. Data Minimization & Collection Mandate
In accordance with DDAPA § 301, the Controller adheres to a strict data minimization mandate. We collect only the information "reasonably necessary and proportionate" to provide our services. We do not engage in speculative data harvesting.
A. Affirmative Express Consent (Opt-In)
Collection of sensitive data—including precise geolocation or biometric identifiers—requires your affirmative express consent. We do not collect such data by default.
B. Categories of Information Collected
- Direct Identifiers: Name, professional email address, and contact number provided via encrypted forms for service delivery.
- Transaction Data: Facilitated via Razorpay; the Controller maintains records of transaction status without storing raw financial credentials.
- Technical Metadata: Anonymized log data, including IP addresses and user-agent strings, used solely for cybersecurity and load balancing.
2. AI & Automated Processing Disclosures
Pursuant to the 2026 AI Transparency Requirements:
- Synthetic Media: This site does not currently utilize synthetic performers or AI-generated deepfakes for representative purposes.
- Algorithmic Processing: AI may be used to categorize Lab resources or optimize site performance. No user data is used to train third-party LLMs without explicit, granular authorization.
3. Data Retention & Disposal Schedule
Under the SECURE Data Act frameworks of 2026, the Controller maintains a rigorous disposal schedule:
- Active Data: Retained only for the duration of the service relationship.
- Inactive Data: All non-essential personal information is permanently deleted or irreversibly de-identified within 60 days of it no longer being necessary for its original purpose.
4. Universal Opt-Out & Global Privacy Control (GPC)
This Site natively recognizes and honors Global Privacy Control (GPC) signals. If your browser transmits a GPC signal, our systems automatically treat it as a request to opt-out of all non-essential data processing and "sales" (as defined under federal and state law).
5. Third-Party Disclosures & Data Brokerage
We do not "sell" your data to data brokers. Sharing is restricted to essential Service Providers:
- Payment Processing: Razorpay (Encrypted/PCI-DSS Compliant).
- Communication: Resend (Transactional only).
- National Deletion Portals: Users may also exercise their rights via the California DROP platform or equivalent federal deletion registries.
6. Comprehensive Data Rights
Under the unified 2026 standards, you possess the following enforceable rights:
- Right to Portability: Obtain a structured, machine-readable copy of your data.
- Right to Correction: Rectify inaccuracies in our records.
- Right to Deletion: Request immediate erasure of your data profile.
- Right to Contest AI Decisions: (See Terms of Service for ADMT rights).
7. Cybersecurity & Accountability
The Controller implements state-of-the-art encryption (AES-256) and periodic Privacy Impact Assessments. In the event of a verified breach, notifications will be issued within 72 hours in compliance with DDAPA § 502.
8. Contact & Enforcement
For data requests or to exercise your private right of action, contact the Data Privacy Officer:
Email: vchaitanya@chowdari.in
Legal Jurisdiction: Disclosures governed by the laws of India and applicable Federal Data Protection standards of 2026.