IFCR Chennai logoIFCR ChennaiSubscribe

Digital Personal Data Protection Act 2023 (India)

Privacy Notice

Effective date: 1 August 2026 · Data Fiduciary: IFCR Chennai (International Fellowship of Cricket Loving Rotarians)

This notice explains what personal data IFCR Chennai collects, why, how it is protected, and the rights you hold under the Digital Personal Data Protection Act 2023 (DPDP Act) and its Rules.

1. Data we collect

When you subscribe, create a player profile, or use the member portal we collect:

Full name
Identity — required for roster and scorecards.
Phone number
Authentication (OTP) and member communications.
Email address
Transactional emails (confirmation, receipts).
Date of birth
Age verification; minor-protection rules apply for under-18 participants.
Photograph
Player profile and public roster display.
Rotary club
Roster grouping and league administration.
CricHeroes profile
Optional link to your public cricket statistics.
Cricket role
Batting/bowling preference for squad selection.
Payment reference
Subscription payment confirmation (amount, UTR/ref); card/UPI details are not stored by us.
Consent record
Timestamp, IP address, and version of consent given at the time of subscription.

We do not collect Aadhaar, PAN, financial account numbers, health data, biometrics, or any special-category data.

2. Purposes of processing

Roster display
Your name, club, photo, and cricket role appear on the public player directory.
Stats publication
Match scores and career statistics derived from IFCR scorecards are published on your public profile.
Member communications
Fixture reminders, subscription receipts, and IFCR announcements via email and/or SMS.
Authentication
Phone OTP to verify identity when accessing the member portal.
Subscription admin
Recording and renewing your IFCR membership.
Legal compliance
Maintaining consent logs, honouring data-subject rights requests, and responding to lawful authority orders.

We do not use your data for advertising, profiling, or any automated decision-making that produces legal or similarly significant effects.

4. Your rights (DPDP Act §§ 11–13)

As a Data Principal you have the right to:

  • Access — obtain a summary of your personal data held by us and the purposes for which it is processed.
  • Correction / completion — request correction of inaccurate or outdated data, or completion of incomplete data.
  • Erasure — request deletion of your personal data. We will anonymise your record (name, phone, email, DOB, photo removed; stats retained under a pseudonymous ID) within the statutory window. Erasure does not affect published scorecard aggregates where your identity is not inferable.
  • Data portability / export — request a JSON or CSV export of your data held by us.
  • Nominate a nominee — designate a person to exercise your rights in the event of death or incapacity.
  • Grievance redressal — lodge a complaint with our Grievance Officer (details in §8) or escalate to the Data Protection Board of India.

Exercise these rights through your Member Portal (self-service for correction and export) or by writing to the Grievance Officer. We fulfil requests within 30 days.

6. Retention

Active member PII
Retained for the duration of your subscription plus 1 year.
Lapsed / non-renewing
PII purged within 90 days of expiry, unless you renew or request archival.
Consent log
Retained for 7 years (regulatory requirement).
Scorecard / match stats
Retained indefinitely in pseudonymous form for historical record.
Payment references
Retained for 8 years (accounting / GST obligation).

A scheduled automated job enforces these retention windows. Records overdue for purge are flagged in the admin queue for review before deletion.

7. Security measures

  • Row-Level Security (RLS): phone, email, and date of birth are never accessible to anonymous requests. Only authenticated members see their own PII; committee roles see limited fields.
  • TLS Full-Strict: all traffic encrypted in transit (Cloudflare origin certificates).
  • Encrypted backups: nightly snapshots stored in Backblaze B2 with server-side encryption; keys held in our secrets vault, not alongside backups.
  • Secrets management: API keys and database credentials stored in Coolify’s encrypted vault; never committed to source control; rotated quarterly.
  • Access logging: all admin actions on player records are logged with actor, timestamp, and change delta.
  • Breach response: confirmed personal data breaches will be reported to the Data Protection Board of India and to affected individuals within the statutory window.

8. Data processors (sub-processors)

We share data with the following processors solely for the stated purpose and under written data processing agreements (DPAs):

ProcessorPurposePrivacy policy
Resend Inc.Transactional email (registration, notifications)View
Twilio Inc.Phone OTP authentication (member portal login)View
Backblaze B2Encrypted cloud backup of database snapshotsView
Cloudflare Inc.CDN, DDoS protection, TLS terminationView
DigitalOcean LLCCloud hosting (application and database server)View

No personal data is transferred outside India except where a processor’s services inherently involve cross-border transfer (e.g. Cloudflare edge nodes). We rely on standard contractual clauses / DPB-approved mechanisms for such transfers. [Confirm data-residency position with each processor before publication.]

9. Grievance Officer

For any privacy concern, data-subject rights request, or complaint, contact:

[Grievance Officer name]

Grievance Officer — IFCR Chennai

Email: [grievance-officer@ifcrchennai.org]

Response within 30 days of receipt.

If you are unsatisfied with our response you may escalate to the Data Protection Board of India once the Board is constituted and its complaints portal is notified.

10. Changes to this notice

We will update this notice when processing activities change materially. The effective date at the top of this page reflects the current version. Where changes affect how we use your data, we will notify you via email or SMS and, where required under the DPDP Act, seek fresh consent.