Privacy & data protection
This notice explains how this community page handles personal data, in line with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 with its Reasonable Security Practices rules. Last updated 8 September 2026.
1. Who is responsible
The organisers of this community page act as the Data Fiduciary for any personal data handled through it. Any privacy question or request can be raised through the form at the end of this page and is routed to the person responsible for data matters.
2. What we collect
- Residents: nothing. No account, no login, no tracking or advertising cookies. We do not run analytics profiling on visitors.
- Contributors: only if you choose to give it — your name, the amount, the date and the payment mode, so the books balance. Names are stored privately and shown on the public page only as "Community contribution" unless you tell us in writing that you are happy to be named.
- Committee members: name, email and password (stored only as an encrypted hash by our authentication provider), the role granted to you, and the entries you make.
- Anyone using the form below: name, email and the message you send.
3. Why we use it (purpose)
Only to run the festival and keep an honest, auditable account of money collected and spent, and to answer your queries. We never sell, rent or share personal data for marketing, and we do not use it for any purpose you have not been told about here.
4. Consent
Giving your name with a contribution is voluntary and you may decline or withdraw it at any time using the form below; the contribution stays in the books as an anonymous entry. Withdrawing consent does not affect anything lawfully done before.
5. Your rights
- Ask what personal data of yours we hold and how it is used.
- Have inaccurate or incomplete data corrected or completed.
- Ask for erasure, unless we must keep the entry for the year's accounts.
- Withdraw consent, and nominate someone to act for you if you cannot.
- Raise a grievance with us first; you may then approach the Data Protection Board of India.
6. Children
We do not knowingly collect personal data of anyone under 18. Photographs of the celebration, if ever published, are only group images and are removed on request from a parent or guardian.
7. How long we keep it
Festival accounts are kept for the year and its archive so residents can audit past years. Contributor names and payment references are deleted once the year's accounts are closed and any grievance period has passed. Form messages are deleted once resolved.
8. Security
Data is stored on managed cloud infrastructure with encryption in transit, row-level access rules and role-based permissions. Personal payment details and receipts are kept in private storage that the public page cannot read. Only approved committee members with a role granted by an admin can see them.
9. Sharing and transfers
We share nothing with third parties except our hosting and authentication provider, which processes data on our instructions. No data is sold. Any cross-border storage by that provider is limited to territories permitted under Indian law.
10. Breach notification
If a personal data breach occurs, we will inform the affected people and the Data Protection Board of India as required by the DPDP Act.
Grievance & data request form