This statutory notice is published in compliance with Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) by Rotaract District 3192 for the VIBE 2026 youth festival platform.
Data Fiduciary: Rotaract District 3192 (District Council & VIBE 2026 Committee)
District Secretariat, Bengaluru, Karnataka 560001, India
Data Protection Officer: dpo@vibe2026.rotaract.org
Grievance Officer: grievance@vibe2026.rotaract.org
Platform URL: vibe2026.rotaract.org
We collect only data strictly necessary for the specified purpose (principle of data minimisation):
Full Name, Username, VIBE ID (Accreditation Code), Profile Photograph
Email address, Phone number, College / University, Rotaract Club, Designation
Instagram handle (optional), Bio, User-uploaded event photos, Captions, Comments, Post Likes
Arcade Game scores, XP progression, Level tier, Leaderboard ranking
Event Accreditation: Issuing digital delegate badges (VIBE ID Pass) and scanning QR credentials at entry gates and activity zones.
Peer Networking: Enabling attendees to discover fellow delegates, send connection requests, view mutual profiles, and build their event network.
Festival Gamification: Maintaining XP scores, calculating tier milestones, and displaying community rankings on the live leaderboard.
Safety & Operational Notices: Transmitting essential schedule updates, stall alerts, security announcements, and connection notifications.
Under Section 6(1), your consent is free, specific, informed, unconditional and unambiguous — given by affirmative action during registration. Consent is limited to data strictly necessary for the specified purpose.
§6(4) — Withdrawal of Consent:
You may withdraw your consent at any time from your Profile → Privacy Settings. The ease of withdrawal is comparable to the ease of giving consent (Section 6(4)). Upon withdrawal, your profile will be hidden from discovery. Processing that occurred prior to withdrawal remains lawful (Section 6(5)).
Consequences (§6(5)): Event QR accreditation may be revoked. To fully erase data, use the "Delete My Account" option.
Personal data is retained only for the duration of the VIBE 2026 event and post-event activities (estimated: until 31 December 2026). After this, all personal data not required for legal compliance will be permanently erased or anonymised.
Financial transaction logs (XP audit trails) may be retained for up to 3 years as required by applicable accounting and audit laws in India.
You can download a portable copy of all personal data held about you. Use the "Download My Personal Data (DPDP Export)" tool in your Profile.
→ Go to Profile → Export DataYou may correct inaccurate, incomplete or outdated data at any time via "Edit Profile" in your profile settings.
→ Go to Profile → Edit ProfileYou may permanently erase all your personal data. Use "Delete My Account & Data" in Profile Settings. This erases all posts, connections, XP logs, and profile data from our servers.
→ Go to Profile → Delete AccountYou may withdraw your data processing consent at any time. The withdrawal is effective immediately. Your profile will be hidden from discovery.
→ Go to Profile → Privacy SettingsYou have the right to file a grievance with our Grievance Officer. Statutory acknowledgment within 48 hours; resolution within 7 working days. If unresolved, you may approach the Data Protection Board of India.
→ Go to Profile → File a GrievanceYou may nominate an individual who shall, in the event of your death or incapacity (as defined in §14(2)), exercise your data rights on your behalf.
→ Go to Profile → Designate NomineeVIBE 2026 is designed for college delegates aged 18 and above. In compliance with Section 9(1), individuals below 18 years may only register with verifiable consent of a parent or lawful guardian. Self-declaration of age is collected at registration; parental consent verification is conducted by event staff for minors.
In compliance with Section 9(3), the platform does not undertake tracking or behavioural monitoring of children and does not direct targeted advertising at anyone under 18.
HTTPS / TLS 1.3 encryption for all data in transit
PostgreSQL Row Level Security (RLS) policies — users can only access their own data
Clerk-managed authentication with token isolation and session invalidation
Supabase service-role keys stored server-side only (never exposed to client)
Supabase Storage with signed URLs for media assets
Regular dependency vulnerability audits
In the event of a personal data breach, we shall notify the Data Protection Board of India and each affected Data Principal promptly, in the form and manner as may be prescribed under Section 8(6) of the DPDP Act, 2023. Notifications will be sent to your registered email address.
In exercising your rights under this Act, you are required to perform the following duties under Section 15:
Comply with all applicable laws while exercising your rights under the DPDP Act.
Not impersonate another person while providing personal data for any specified purpose.
Not suppress any material information while providing data for a document, unique identifier, proof of identity or proof of address.
Not register a false or frivolous grievance or complaint with the Data Fiduciary or the Data Protection Board.
Furnish only verifiably authentic information while exercising the right to correction or erasure.
Your personal data is processed and stored in India. Third-party services used (Clerk for authentication, Supabase for database) process data on Indian-region servers where available. No personal data is transferred to countries restricted by Central Government notification under Section 16 of the DPDP Act, 2023.
Grievance Redressal Officer
Rotaract District 3192 — VIBE 2026 Committee
Bengaluru, Karnataka 560001, India
Email: grievance@vibe2026.rotaract.org
Response: Acknowledgment within 48 hours; Resolution within 7 working days (Section 13(2)).
Data Protection Officer
Email: dpo@vibe2026.rotaract.org
If your grievance remains unresolved, you may approach the Data Protection Board of India established under Section 18 of the DPDP Act, 2023. Appeals against Board orders may be filed with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29 of the Act.
Breaches of the DPDP Act attract monetary penalties. As a platform, we are committed to full compliance to avoid the following prescribed penalties under the Schedule to the Act:
| Breach | Max Penalty |
|---|---|
| Failure of reasonable security safeguards (§8(5)) | ₹250 Crore |
| Failure to notify breach to Board / Data Principal (§8(6)) | ₹200 Crore |
| Breach of children's data obligations (§9) | ₹200 Crore |
| Breach of Significant Data Fiduciary obligations (§10) | ₹150 Crore |
| Breach of Data Principal duties (§15) | ₹10,000 |
| Breach of voluntary undertaking accepted by Board (§32) | Per extent of breach |
| Any other breach of Act / Rules | ₹50 Crore |