India addendum (DPDP Act 2023)
This addendum supplements our baseline Privacy Policy for Data Principals in India under the Digital Personal Data Protection Act, 2023, and any rules notified under it.
1. Roles
Galeira is a Data Fiduciary under the DPDP Act for account / billing data. For event content uploaded by hosts, the host is the Data Fiduciary and we act as Data Processor on their instructions.
2. Lawful processing
- Consent (§6) — freely given, specific, informed, unconditional, unambiguous, by clear affirmative action. Consent notices are in plain language. Withdrawable at any time.
- Certain legitimate uses (§7) — voluntary provision for the specified purpose where consent is not required (e.g. to comply with judgment, for medical emergency, employment).
3. Your rights (§§11–14)
- Right to access summary of personal data processed and processing activities, and identities of Data Fiduciaries with whom data has been shared.
- Right to correction, completion, updating, and erasure of personal data.
- Right of grievance redressal — easily-accessible mechanism.
- Right to nominate a person to exercise rights on your behalf in case of death or incapacity.
4. Grievance officer
Galeira's Grievance Officer for India under DPDP §8(9) can be contacted at [email protected] (subject "DPDP Grievance"). We respond inside the timeline notified under the Act (initially up to 30 days; revisable by Rules).
5. Consent manager
Where Consent Managers are registered with the Data Protection Board of India, you may also exercise your rights through a registered Consent Manager.
6. Children & persons with disabilities
We process personal data of children (under 18) and persons with disabilities (who have a lawful guardian) only with verifiable consent of the parent or lawful guardian, and do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
7. Cross-border transfer
We may transfer your data to countries outside India unless the Central Government notifies restrictions on a specific country. Our default storage is in the EU; processors include US-based services (Stripe, Sentry, Twilio) under contractual safeguards.
8. Data Protection Board complaints
If we cannot resolve a grievance, you may approach the Data Protection Board of India under DPDP Chapter VI. Contact information will be published at meity.gov.in/data-protection-framework as the Board is constituted.