Digital Personal Data Protection Act 2023 (India)
Privacy Notice
Effective date: 1 August 2026 · Data Fiduciary: IFCR Chennai (International Fellowship of Cricket Loving Rotarians)
This notice explains what personal data IFCR Chennai collects, why, how it is protected, and the rights you hold under the Digital Personal Data Protection Act 2023 (DPDP Act) and its Rules.
1. Data we collect
When you subscribe, create a player profile, or use the member portal we collect:
- Full name
- Identity — required for roster and scorecards.
- Phone number
- Authentication (OTP) and member communications.
- Email address
- Transactional emails (confirmation, receipts).
- Date of birth
- Age verification; minor-protection rules apply for under-18 participants.
- Photograph
- Player profile and public roster display.
- Rotary club
- Roster grouping and league administration.
- CricHeroes profile
- Optional link to your public cricket statistics.
- Cricket role
- Batting/bowling preference for squad selection.
- Payment reference
- Subscription payment confirmation (amount, UTR/ref); card/UPI details are not stored by us.
- Consent record
- Timestamp, IP address, and version of consent given at the time of subscription.
We do not collect Aadhaar, PAN, financial account numbers, health data, biometrics, or any special-category data.
2. Purposes of processing
- Roster display
- Your name, club, photo, and cricket role appear on the public player directory.
- Stats publication
- Match scores and career statistics derived from IFCR scorecards are published on your public profile.
- Member communications
- Fixture reminders, subscription receipts, and IFCR announcements via email and/or SMS.
- Authentication
- Phone OTP to verify identity when accessing the member portal.
- Subscription admin
- Recording and renewing your IFCR membership.
- Legal compliance
- Maintaining consent logs, honouring data-subject rights requests, and responding to lawful authority orders.
We do not use your data for advertising, profiling, or any automated decision-making that produces legal or similarly significant effects.
3. Legal basis and consent
Processing rests on your explicit, informed consent obtained at the point of subscription. Consent is itemised by purpose (roster display, stats publication, communications) and recorded in an append-only log alongside the timestamp, IP address, and notice version in force at the time.
Scorecard statistics are retained after subscription expiry under legitimate interest (historical cricket records / archival) — only aggregated public stats, never raw PII.
Participants under 18 require an additional guardian-consent field; their PII is subject to stricter display restrictions.
4. Your rights (DPDP Act §§ 11–13)
As a Data Principal you have the right to:
- Access — obtain a summary of your personal data held by us and the purposes for which it is processed.
- Correction / completion — request correction of inaccurate or outdated data, or completion of incomplete data.
- Erasure — request deletion of your personal data. We will anonymise your record (name, phone, email, DOB, photo removed; stats retained under a pseudonymous ID) within the statutory window. Erasure does not affect published scorecard aggregates where your identity is not inferable.
- Data portability / export — request a JSON or CSV export of your data held by us.
- Nominate a nominee — designate a person to exercise your rights in the event of death or incapacity.
- Grievance redressal — lodge a complaint with our Grievance Officer (details in §8) or escalate to the Data Protection Board of India.
Exercise these rights through your Member Portal (self-service for correction and export) or by writing to the Grievance Officer. We fulfil requests within 30 days.
5. Withdrawing consent
You may withdraw consent at any time from your Member Portal under Settings › Manage consent, or by contacting the Grievance Officer. Withdrawal does not affect lawfulness of processing prior to withdrawal.
Withdrawing consent for roster display will remove your profile from the public directory within 72 hours. Historical scorecard data (match-level stats) may be retained in anonymised/pseudonymised form for archival purposes.
6. Retention
- Active member PII
- Retained for the duration of your subscription plus 1 year.
- Lapsed / non-renewing
- PII purged within 90 days of expiry, unless you renew or request archival.
- Consent log
- Retained for 7 years (regulatory requirement).
- Scorecard / match stats
- Retained indefinitely in pseudonymous form for historical record.
- Payment references
- Retained for 8 years (accounting / GST obligation).
A scheduled automated job enforces these retention windows. Records overdue for purge are flagged in the admin queue for review before deletion.
7. Security measures
- Row-Level Security (RLS): phone, email, and date of birth are never accessible to anonymous requests. Only authenticated members see their own PII; committee roles see limited fields.
- TLS Full-Strict: all traffic encrypted in transit (Cloudflare origin certificates).
- Encrypted backups: nightly snapshots stored in Backblaze B2 with server-side encryption; keys held in our secrets vault, not alongside backups.
- Secrets management: API keys and database credentials stored in Coolify’s encrypted vault; never committed to source control; rotated quarterly.
- Access logging: all admin actions on player records are logged with actor, timestamp, and change delta.
- Breach response: confirmed personal data breaches will be reported to the Data Protection Board of India and to affected individuals within the statutory window.
8. Data processors (sub-processors)
We share data with the following processors solely for the stated purpose and under written data processing agreements (DPAs):
| Processor | Purpose | Privacy policy |
|---|---|---|
| Resend Inc. | Transactional email (registration, notifications) | View |
| Twilio Inc. | Phone OTP authentication (member portal login) | View |
| Backblaze B2 | Encrypted cloud backup of database snapshots | View |
| Cloudflare Inc. | CDN, DDoS protection, TLS termination | View |
| DigitalOcean LLC | Cloud hosting (application and database server) | View |
No personal data is transferred outside India except where a processor’s services inherently involve cross-border transfer (e.g. Cloudflare edge nodes). We rely on standard contractual clauses / DPB-approved mechanisms for such transfers. [Confirm data-residency position with each processor before publication.]
9. Grievance Officer
For any privacy concern, data-subject rights request, or complaint, contact:
[Grievance Officer name]
Grievance Officer — IFCR Chennai
Email: [grievance-officer@ifcrchennai.org]
Response within 30 days of receipt.
If you are unsatisfied with our response you may escalate to the Data Protection Board of India once the Board is constituted and its complaints portal is notified.
10. Changes to this notice
We will update this notice when processing activities change materially. The effective date at the top of this page reflects the current version. Where changes affect how we use your data, we will notify you via email or SMS and, where required under the DPDP Act, seek fresh consent.