IT ADVISER

Portal Terms & Privacy Notice (DPDP)

Version 1.0 Effective 02 Apr 2026 Sign in to the portal
IT ADVISER
Customer Success & Compliance Desk, India
Grievance: grievance@itadviser.in
Phone: +91 90000 00000
Data protection: privacy@itadviser.in
Document Portal Terms & Privacy Notice (DPDP)
Version 1.0
Effective 02 Apr 2026
Printed 07 Oct 2026

Portal Terms & Privacy Notice (DPDP)

Terms of portal use and the processing of personal data under the Digital Personal Data Protection Act, 2023 · version 1.0 · Effective 02 Apr 2026

Who we are and what this notice covers

IT Adviser operates this Client Portal & vCIO Management System ("the portal") and is the Data Fiduciary for the personal data processed through it, within the meaning of the Digital Personal Data Protection Act, 2023 ("the DPDP Act"). This notice explains what personal data we hold, why we hold it, who we share it with, how long we keep it, and the rights you can exercise.

Two groups of people use the portal. Agency staff — our employees and authorised contractors — administer and deliver the services. Your organisation's users ("you") sign in to review services, health, credentials, meetings, invoices, tickets and notices. This notice is addressed to your organisation's portal users; our own staff are covered by separate internal policies.

  • Data Fiduciary: IT Adviser, Customer Success & Compliance Desk, India.
  • Grievance Officer: Grievance Officer, IT Adviser — grievance@itadviser.in, +91 90000 00000.
  • Data protection contact: Data Protection Contact, IT Adviser — privacy@itadviser.in.
  • Portal: /portal/privacy — every right described in this notice is exercised from the "Data & Consent" area of the portal.
  • Public copy: /privacy-notice — readable without signing in, so it can be shared with colleagues, auditors and your own advisers.

Terms of portal use

Portal access is provided to your organisation under the service agreement(s) you have engaged us for. By signing in you agree to use the portal only for its intended purpose: reviewing and managing your own organisation's services, billing, meetings and support records. These terms sit alongside — and do not replace — the master service agreement, statement of work, quotation or invoice that governs the services themselves; where they conflict, the signed service agreement prevails.

Documents generated by the portal — service health summaries, timelines, roadmaps, recommendations, quotations, offers, invoices, receipts, vCIO reports and exported archives — are prepared for your organisation's internal business use. Your organisation keeps ownership of its own data, files and content; the portal software, templates, methodologies and report formats remain our intellectual property and may not be resold or redistributed commercially.

  • Account and credentials: keep your portal password confidential, do not share a login between people, and change the password immediately if you suspect it has been compromised. Sign-ins, credential reveals and downloads are recorded against your account.
  • Acceptable use: do not attempt to reach another customer's records, probe or bypass access controls, upload unlawful or malicious files, or use the portal to send unsolicited bulk email.
  • Our rights: we may suspend, restrict or withdraw portal access for misuse, for non-payment, or where the law requires it, and we may add, change or retire portal features as the underlying services evolve.
  • Service availability: the portal depends on hosting, payment-gateway, email and monitoring providers outside our control. We work to keep the portal highly available, but we do not warrant uninterrupted availability of those third-party services and we are not responsible for outages that originate outside our own environment.
  • Support: portal issues, requests and questions are handled through the ticket module so they stay traceable, prioritised against your service levels and never lost in personal inboxes.

Personal data we process

The portal holds the minimum data needed to deliver, secure and bill the services your organisation has engaged us for. The categories below describe what is actually stored in this system.

  • Identity and contact data — the name, work email address, phone number, designation, portal role and account status of each user your organisation nominates.
  • Company and role data — your company's name, customer code, billing address, contacts, communication preferences, and the agency staff members assigned to your account.
  • Portal activity and login history — successful and failed sign-ins, IP address, browser user agent, the records acted upon, and the audit trail of material actions taken in the portal.
  • Support tickets and attachments — the requests you raise, our replies and internal notes, and any files you upload to a ticket.
  • Invoices, quotations, offers and payment references — billing documents issued to your organisation, engagement and offer records, and the payment references, status and reconciliation data reported back by the payment gateway. Card, UPI and net-banking credentials are entered on the gateway's systems and never reach the portal.
  • Service health and roadmap records — the periodic health status of each service we manage for you, service timeline entries, roadmaps, recommendations and renewal dates.
  • Encrypted credential vault entries — administrative credentials for the systems we operate on your behalf. The secret is stored as authenticated ciphertext and only a masked hint is ever displayed. Revealing a stored secret is a separate, permission-gated action, and every reveal is written to an immutable credential access log.
  • Communications and notices — the notifications, emails and notices the portal sends to your users, together with delivery status.

Purposes and lawful basis

We process personal data only for lawful purposes — with your consent, or under a legitimate use recognised by the DPDP Act. Each activity below is mapped to its basis.

We do not sell, rent or trade personal data, and we do not use personal data for advertising, behavioural targeting or third-party marketing. Promotional email goes only to people who have opted in, and every such message carries an unsubscribe link.

  • Performance of the services you have engaged us for (legitimate use under Section 7 of the DPDP Act) — setting up and tracking your services, health reviews, appointments, roadmaps and reports, resolving tickets and meetings, renewals, and maintaining your organisation's contacts.
  • Your explicit consent (Section 6) — running the self-service portal itself: presenting your organisation's services, invoices, credentials, meetings and notices in one place, and contacting your users about activity on your account. Consent is captured here, timestamped against this notice version, and may be withdrawn at any time.
  • Legal obligation — tax, accounting, audit and statutory record keeping for invoices, payments and receipts, and the security, fraud-prevention and access logs we must keep to protect the portal.
  • Legitimate uses recognised by the DPDP Act — responding to your requests, service, security and renewal communications, voluntary communication you have asked for, compliance with a court order or a lawful direction of a competent authority, and medical emergency or safety situations where they apply.
  • Security and accountability — authentication, role-based access control, monitoring for misuse and the audit trail. These records exist to protect the portal and to answer "who did what, when"; they are never used for profiling.

Who we share it with

We share personal data only with the processors and recipients below, and only to the extent needed for the stated purpose. Every processor acts under a written contract that binds it to confidentiality, security, purpose limitation and the same standard of protection described in this notice, and none of them may use your data for their own purposes.

  • Payment gateway (PayU) — your organisation's name, contact email, invoice number and amount, so that online payments against your invoices can be initiated, confirmed and reconciled. Payment instruments are handled entirely by the gateway.
  • Email / SMTP provider — recipient name and email address, subject and body of transactional notifications such as invoices, receipts, ticket updates, meeting invitations and privacy notices.
  • Hosting and infrastructure provider — the servers, private file storage and encrypted backups on which the portal runs, under a data processing agreement.
  • Monitoring integration webhooks — where your organisation has enabled a monitoring integration, the payload we send carries service-health signals only (service reference, health status, timestamp and a short note). It is not a carrier for personal data about your users.
  • Sub-contractors and professional advisers — specialists, auditors, accountants and lawyers engaged to deliver the services or to comply with the law, each bound by confidentiality obligations.
  • Courts, regulators and authorities — where the law requires disclosure or a valid legal process compels it. Where we are permitted to do so, we will tell you about the request first.

How we keep it secure

Security controls are designed into the portal rather than added on top. The measures that matter most for your data are:

  • Encryption at rest — service credentials and secrets are held as authenticated ciphertext using application keys that never live in the database, and sensitive files and exported archives are kept on a private disk outside the web root.
  • Hashed passwords — portal passwords are stored only as adaptive hashes. They are never logged, exported or emailed, and nobody at the agency can read your password.
  • Role-based access control — every screen and action is checked server-side against the role assigned to the person (customer admin, customer user, or internal roles such as account manager, service engineer, support or billing). Hiding a button is never the only protection.
  • Customer-scoped authorisation — portal queries are scoped to your own organisation, so a user of one company cannot read or change another company's records.
  • Masked credentials with audited reveal — vault secrets are displayed masked; revealing one requires the reveal permission, is rate-limited, and is recorded with the person, the time and the reason.
  • Immutable audit trails — consent records, credential access, exports, deletions and administrative changes are written to append-only audit tables that cannot be edited or deleted from the interface.
  • Encrypted backups — database and private file backups are encrypted at rest, access-controlled, and restored only during a documented recovery exercise.
  • Operational safeguards — least-privilege administration, restricted production access, timely patching and prompt investigation of suspicious activity. If a personal data breach occurs, we notify the Data Protection Board of India and the affected users as the DPDP Act requires.
  • Tell us quickly — no system is entirely free of risk. Please protect your own login and contact us at grievance@itadviser.in immediately if you believe your account or your organisation's data has been compromised.

How long we keep personal data

We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires, and then we delete it or turn it into information that can no longer be linked to a person.

When a retention period ends, or when we accept an erasure request, we delete the data or irreversibly anonymise it — for example by removing names and contact details from a financial record whose totals we are legally required to keep. Deletions are logged, and residual copies disappear as encrypted backups rotate out. Aggregate statistics that cannot identify a person may be kept indefinitely.

  • Invoices, payment records, receipts and related tax documents — at least 8 years from the end of the relevant financial year, as required by tax and accounting law, even after an approved erasure request.
  • Audit logs, login history, credential access logs and security events — 3 years, because the value of a security record lies in being able to answer questions about the past.
  • Support tickets, replies, notes and attachments — 3 years after the ticket is closed, so we can prove what was done and resolve recurring problems.
  • Data exports you generate — your archive can be downloaded for 48 hours, after which the file is deleted automatically and only the request record remains.
  • Credential vault entries — kept until the credential is removed by your organisation or by the engineer responsible for the system. The encrypted secret is deleted with the record, while its access log is kept for the audit period above.
  • Portal user accounts and contact details — kept while the account is active and for a short hand-over period after your organisation stops using the portal, so records can be transferred or restored if needed.
  • Notices and notification logs — kept while the notice is live and for the notification retention window configured for the portal.

Your rights and how to exercise them

As a Data Principal you have the following rights under the DPDP Act. Every one of them can be exercised from inside the portal, and each request is logged with its outcome so the process stays auditable.

What happens if you withdraw consent: we stop the consent-based processing (self-service portal access and contacting your users about account activity), but we continue the processing that the services you have engaged require — service delivery and support, invoices, payments and billing, renewals, security and breach notifications — and we keep the tax, accounting and security records the law compels us to keep. You will still receive essential transactional messages about those services.

  • Right to access — see what we hold and receive a copy. In the portal open Data & Consent → "Download My Data" and request an export; the archive is prepared for you and stays downloadable for 48 hours.
  • Right to correction — ask us to correct inaccurate, incomplete or outdated data. Raise it from Data & Consent or from any ticket; operational data is corrected directly and the change is recorded in the audit trail.
  • Right to erasure — ask us to delete personal data we no longer need. Use Data & Consent → "Request Deletion". We answer within the timelines below and, where we must retain something (tax, accounting or security records), we tell you exactly which records and why.
  • Right to withdraw consent — use Data & Consent → "Consent" to withdraw the consent you gave for portal processing. Withdrawal takes effect immediately for consent-based processing and does not affect the lawfulness of processing carried out before it.
  • Right to grievance redressal — raise any concern with the Grievance Officer at grievance@itadviser.in or +91 90000 00000, or through a portal ticket addressed to the privacy team. Complaints are recorded, investigated and answered in writing.
  • Right to nominate — you may nominate another person to exercise your rights in the event of your death or incapacity by writing to the Grievance Officer.
  • Right to complain to the Data Protection Board of India — if you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India in the manner prescribed by the DPDP Act and its rules.

Cookies and local storage

The portal uses a deliberately small set of browser technologies to keep you signed in and to protect the forms you submit. It does not use advertising trackers, third-party analytics cookies or cross-site profiling.

You can view, block or clear cookies at any time in your browser settings. Blocking the session cookie ends your portal session; blocking the rest does not affect access to your data.

  • Session cookie — identifies your signed-in session. It is essential; the portal cannot be used without it, and it is removed when you sign out.
  • CSRF token — held in the session and mirrored into each page so a form can prove it came from the portal, protecting you against cross-site request forgery.
  • Remember-me cookie — set only if you tick "Remember me" at sign-in, so that this browser does not ask for your password again for the configured period.
  • Interface preferences — small values such as the last list filter or a dismissed notice may be kept so the portal behaves consistently between visits.
  • No advertising or tracking cookies — no third-party advertising pixels, social plug-ins or behavioural analytics are used, and cookie identifiers are never shared with anyone.

Changes to this notice

We review this notice when the way the portal processes data changes, when the law changes, and at least periodically. Every change is published as a new version.

  • Each version carries a version number and an effective date, and the current version is always shown at the top of this notice.
  • Material changes — a new category of data, a new purpose or a new recipient — are published as a new version and require your fresh acceptance before consent-based portal processing continues.
  • The version you accepted, and when, is recorded for you: open Data & Consent → "Consent" to see your own consent history.
  • Version history is maintained in the portal's consent register, and superseded versions are available from the privacy team on request.
  • Where the law requires notice before processing begins, we will tell you about the change first and will not begin the new processing until it is covered by this notice.

Contact and response timelines

Grievance Officer: Grievance Officer, IT Adviser, IT Adviser, Customer Success & Compliance Desk, India — grievance@itadviser.in, +91 90000 00000. The Grievance Officer handles every matter raised under this notice: access, correction, erasure, withdrawal of consent, nominations, complaints and general privacy questions.

Data protection contact: Data Protection Contact, IT Adviser — privacy@itadviser.in.

Where to write: the fastest route is inside the portal — /portal/privacy — which records your request, tracks its progress and keeps our reply with it. You may also email the Grievance Officer directly; write from the email address registered to your portal account so we can verify you.

  • We acknowledge every privacy request within 7 days of receiving it, and tell you the reference number we are tracking it under.
  • We complete requests within 30 days, and sooner where the law or the circumstances require it.
  • If a request genuinely needs more time — for example because it spans a large volume of records or a legal hold — we tell you why and give you a new date in writing.
  • Security incidents affecting your personal data are notified to the Data Protection Board of India and to you without undue delay, together with what happened and what we have done about it.
  • If you are dissatisfied with the outcome you may complain to the Data Protection Board of India, and we will give you the details you need to do so.
  • This notice is provided in English. Where it is translated for convenience, the English text governs.
Printed on 07 Oct 2026 12:48 from https://vcio.gjtechsoft.in/privacy-notice · grievances: grievance@itadviser.in

© 2026 IT ADVISER. This notice is also available to signed-in users inside the customer portal under Privacy → Portal Notice.