Back to VIBE Platform
STATUTORY NOTICE — DPDP ACT, 2023 (NO. 22 OF 2023)

Digital Personal Data Protection Notice & Privacy Policy

This statutory notice is published in compliance with Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) by Rotaract District 3192 for the VIBE 2026 youth festival platform.

Act: No. 22 of 2023, dated 11th August 2023Jurisdiction: Bengaluru, IndiaLast Reviewed: September 2026
01

Identity of Data Fiduciary (Section 5(1))

§5 Notice Requirement

Data Fiduciary: Rotaract District 3192 (District Council & VIBE 2026 Committee)

District Secretariat, Bengaluru, Karnataka 560001, India

Data Protection Officer: dpo@vibe2026.rotaract.org

Grievance Officer: grievance@vibe2026.rotaract.org

Platform URL: vibe2026.rotaract.org

02

Categories of Personal Data Collected (Section 5(1)(i))

§5 — Data Minimisation

We collect only data strictly necessary for the specified purpose (principle of data minimisation):

Identity & Profile

Full Name, Username, VIBE ID (Accreditation Code), Profile Photograph

Contact & Affiliation

Email address, Phone number, College / University, Rotaract Club, Designation

Social & Networking

Instagram handle (optional), Bio, User-uploaded event photos, Captions, Comments, Post Likes

Gamification & Engagement

Arcade Game scores, XP progression, Level tier, Leaderboard ranking

03

Lawful Purpose of Processing (Sections 4 & 5(1)(i))

§4 — Lawful Basis

Event Accreditation: Issuing digital delegate badges (VIBE ID Pass) and scanning QR credentials at entry gates and activity zones.

Peer Networking: Enabling attendees to discover fellow delegates, send connection requests, view mutual profiles, and build their event network.

Festival Gamification: Maintaining XP scores, calculating tier milestones, and displaying community rankings on the live leaderboard.

Safety & Operational Notices: Transmitting essential schedule updates, stall alerts, security announcements, and connection notifications.

04

Consent & Right to Withdraw (Section 6)

§6 — Consent Requirements

Under Section 6(1), your consent is free, specific, informed, unconditional and unambiguous — given by affirmative action during registration. Consent is limited to data strictly necessary for the specified purpose.

§6(4) — Withdrawal of Consent:

You may withdraw your consent at any time from your Profile → Privacy Settings. The ease of withdrawal is comparable to the ease of giving consent (Section 6(4)). Upon withdrawal, your profile will be hidden from discovery. Processing that occurred prior to withdrawal remains lawful (Section 6(5)).

Consequences (§6(5)): Event QR accreditation may be revoked. To fully erase data, use the "Delete My Account" option.

05

Data Retention Period (Section 8(7))

§8(7) — Retention Limits

Personal data is retained only for the duration of the VIBE 2026 event and post-event activities (estimated: until 31 December 2026). After this, all personal data not required for legal compliance will be permanently erased or anonymised.

Financial transaction logs (XP audit trails) may be retained for up to 3 years as required by applicable accounting and audit laws in India.

06

Your Rights as a Data Principal (Sections 11–14)

Chapter III — Rights

Right to Access & Summary (§11)

You can download a portable copy of all personal data held about you. Use the "Download My Personal Data (DPDP Export)" tool in your Profile.

Go to Profile → Export Data

Right to Correction (§12(2))

You may correct inaccurate, incomplete or outdated data at any time via "Edit Profile" in your profile settings.

Go to Profile → Edit Profile

Right to Erasure (§12(3))

You may permanently erase all your personal data. Use "Delete My Account & Data" in Profile Settings. This erases all posts, connections, XP logs, and profile data from our servers.

Go to Profile → Delete Account

Right to Withdraw Consent (§6(4))

You may withdraw your data processing consent at any time. The withdrawal is effective immediately. Your profile will be hidden from discovery.

Go to Profile → Privacy Settings

Right of Grievance Redressal (§13)

You have the right to file a grievance with our Grievance Officer. Statutory acknowledgment within 48 hours; resolution within 7 working days. If unresolved, you may approach the Data Protection Board of India.

Go to Profile → File a Grievance

Right to Nominate (§14)

You may nominate an individual who shall, in the event of your death or incapacity (as defined in §14(2)), exercise your data rights on your behalf.

Go to Profile → Designate Nominee
07

Protection of Children (Section 9)

§9 — Minors under 18

VIBE 2026 is designed for college delegates aged 18 and above. In compliance with Section 9(1), individuals below 18 years may only register with verifiable consent of a parent or lawful guardian. Self-declaration of age is collected at registration; parental consent verification is conducted by event staff for minors.

In compliance with Section 9(3), the platform does not undertake tracking or behavioural monitoring of children and does not direct targeted advertising at anyone under 18.

08

Data Security Safeguards (Section 8(5))

§8(5) — Security Obligations

HTTPS / TLS 1.3 encryption for all data in transit

PostgreSQL Row Level Security (RLS) policies — users can only access their own data

Clerk-managed authentication with token isolation and session invalidation

Supabase service-role keys stored server-side only (never exposed to client)

Supabase Storage with signed URLs for media assets

Regular dependency vulnerability audits

09

Personal Data Breach Notification (Section 8(6))

§8(6) — Breach Intimation

In the event of a personal data breach, we shall notify the Data Protection Board of India and each affected Data Principal promptly, in the form and manner as may be prescribed under Section 8(6) of the DPDP Act, 2023. Notifications will be sent to your registered email address.

10

Your Duties as a Data Principal (Section 15)

§15 — Data Principal Duties

In exercising your rights under this Act, you are required to perform the following duties under Section 15:

§15(a)

Comply with all applicable laws while exercising your rights under the DPDP Act.

§15(b)

Not impersonate another person while providing personal data for any specified purpose.

§15(c)

Not suppress any material information while providing data for a document, unique identifier, proof of identity or proof of address.

§15(d)

Not register a false or frivolous grievance or complaint with the Data Fiduciary or the Data Protection Board.

§15(e)

Furnish only verifiably authentic information while exercising the right to correction or erasure.

11

Cross-Border Data Transfer (Section 16)

§16 — Transfer Restrictions

Your personal data is processed and stored in India. Third-party services used (Clerk for authentication, Supabase for database) process data on Indian-region servers where available. No personal data is transferred to countries restricted by Central Government notification under Section 16 of the DPDP Act, 2023.

12

Grievance Redressal Officer & Data Protection Officer (Sections 8(9) & 13)

§8(9) Published Contact

Grievance Redressal Officer

Rotaract District 3192 — VIBE 2026 Committee

Bengaluru, Karnataka 560001, India

Email: grievance@vibe2026.rotaract.org

Response: Acknowledgment within 48 hours; Resolution within 7 working days (Section 13(2)).

Data Protection Officer

Email: dpo@vibe2026.rotaract.org

If your grievance remains unresolved, you may approach the Data Protection Board of India established under Section 18 of the DPDP Act, 2023. Appeals against Board orders may be filed with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29 of the Act.

13

Penalty Framework (Section 33 & Schedule)

§33 — Penalties

Breaches of the DPDP Act attract monetary penalties. As a platform, we are committed to full compliance to avoid the following prescribed penalties under the Schedule to the Act:

BreachMax Penalty
Failure of reasonable security safeguards (§8(5))₹250 Crore
Failure to notify breach to Board / Data Principal (§8(6))₹200 Crore
Breach of children's data obligations (§9)₹200 Crore
Breach of Significant Data Fiduciary obligations (§10)₹150 Crore
Breach of Data Principal duties (§15)₹10,000
Breach of voluntary undertaking accepted by Board (§32)Per extent of breach
Any other breach of Act / Rules₹50 Crore
Rotaract District 3192 • VIBE 2026 • DPDP Act No. 22 of 2023