WhatsApp Support
Set Themes
Icon
Themes
Light
Dark

DPDP Act (India) Compliance Policy

Effective Date: September 20, 2026

This Digital Personal Data Protection Compliance Policy outlines the practices and safeguards implemented by Hosticky (operated by LiteLink Consultancy LLP, "we", "our", "us") in strict compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India, the Information Technology Act, 2000, and applicable statutory guidelines.

1. Scope and Applicability

This Policy applies to the processing of digital personal data within the territory of India where such personal data is collected in digital form or collected in non-digital form and digitized subsequently. It also applies to processing of personal data outside India if such processing is in connection with offering goods or services to Data Principals within India.

2. Roles: Data Fiduciary and Data Principal

  • Data Fiduciary: LiteLink Consultancy LLP (Hosticky) acts as the Data Fiduciary regarding personal information (such as contact information, account credentials, and billing details) collected from our customers to provide hosting, domain, server, and web services.
  • Data Principal: The individual to whom the personal data relates (our client, website visitor, or authorized account user).
  • Data Processor: Any third-party service provider (such as payment gateways, server infrastructure providers, and licensing partners) engaged by Hosticky to process data strictly under lawful contracts.

3. Notice & Lawful Grounds for Processing (Section 4, 5 & 6)

Hosticky processes digital personal data exclusively under lawful grounds recognized by the DPDP Act:

  • Clear Consent: Prior to or at the time of collecting personal data, we present an itemized notice explaining the exact categories of data collected, the business purpose, how to exercise your rights, and how to register a grievance. Consent given to Hosticky is free, specific, informed, unconditional, and unambiguous.
  • Legitimate Uses: Processing necessary for fulfilling contracts (such as provisioning ordered web hosting, executing domain registrations, generating invoices, and enforcing network cybersecurity).

4. Rights of Data Principals (Section 11, 12, 13 & 14)

Under the DPDP Act, Indian citizens and customers have well-defined statutory rights which Hosticky actively honors:

  • Right to Access Information (Section 11): You may request a summary of the personal data being processed, the processing activities undertaken, and the identities of any Data Processors with whom data has been shared.
  • Right to Correction & Erasure (Section 12): You have the right to correct inaccurate or misleading data, complete incomplete records, update outdated information, and request the erasure of your personal data when it is no longer required for the purpose for which it was collected or mandated by law.
  • Right of Grievance Redressal (Section 13): You have the right to readily available grievance redressal provided by our designated Grievance Officer.
  • Right to Nominate (Section 14): You may designate an individual who, in the event of your death or incapacity, shall exercise your rights under the DPDP Act.
  • Right to Withdraw Consent (Section 6(4)): You may withdraw your consent at any time through your Client Portal. Withdrawal of consent does not affect the legality of processing done prior to withdrawal.

5. Protection of Children & Minors (Section 9)

Hosticky does not knowingly solicit or collect personal data from individuals under the age of 18 without verifiable consent from their parent or lawful guardian. In accordance with Section 9 of the DPDP Act, Hosticky does not undertake tracking or behavioral monitoring of children, nor do we serve targeted advertisements directed at minors.

6. Security Safeguards & Obligations of Data Fiduciary (Section 8)

Hosticky enforces reasonable technical and organizational security safeguards to prevent personal data breaches, including:

  • End-to-end transport layer encryption (TLS 1.3 / 256-bit SSL) across all web portals and API endpoints.
  • Cryptographic hashing of authentication passwords using industry-standard bcrypt algorithms.
  • CageFS virtualization and strict access privilege boundaries to prevent inter-account data leaks.
  • Automated threat monitoring, hardware-level DDoS protection, and regular security audits.

7. Data Retention & Automated Erasure (Section 8(7))

Personal data is retained only for as long as your account remains active or as required to fulfill the business and legal purpose of collection. Upon service termination and verification of all outstanding balances, hosted server files and databases are destroyed immediately. Core billing and accounting transaction logs are retained strictly in compliance with applicable Indian tax and corporate regulatory requirements (e.g., GST Act, Income Tax Act), after which they are permanently expunged.

8. Personal Data Breach Notification (Section 8(6))

In the unlikely event of any personal data breach affecting our infrastructure, Hosticky maintains a dedicated Incident Response Plan. We will promptly notify:

  • The Data Protection Board of India (DPBI) in the prescribed form and manner.
  • Each affected Data Principal without undue delay, outlining the nature of the breach, potential consequences, and mitigation measures taken.

9. Statutory Grievance Redressal Mechanism

In accordance with Section 8(10) and Section 13 of the DPDP Act, 2023, Hosticky has appointed a designated Grievance Redressal Officer to handle inquiries, complaints, and requests from Data Principals:

Designation: Grievance Redressal Officer

Operating Entity: LiteLink Consultancy LLP

Email: grievance@hosticky.com (cc: support@hosticky.com)

Support Desk: Submit a high-priority ticket in the Client Area Helpdesk

Response Timeframe: Acknowledgement within 48 business hours; complete resolution within 15 calendar days.

Escalation to Data Protection Board: If you are not satisfied with the resolution provided by our Grievance Officer, or if a grievance remains unaddressed beyond thirty (30) days, you have the statutory right under the DPDP Act to submit a formal complaint directly to the Data Protection Board of India (DPBI).

Your privacy matters

We use cookies to provide our services and for analytics and marketing. To find out more about our use of cookies, please see our Privacy Policy and Cookie and Tracking Notice. By continuing to browse our website, you agree to our use of cookies.