Compliance

DPDP Act Compliance

How CloudResolve complies with India's Digital Personal Data Protection Act, 2023.

1. Overview

CloudResolve Technologies is fully committed to compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025. This page outlines our compliance framework, data processing practices, and the rights of Data Principals under the Act.

2. Our Roles Under the DPDP Act

CloudResolve operates in two capacities depending on the context of data processing:

As a Data Fiduciary:

  • When we determine the purpose and means of processing personal data collected through our website, marketing activities, and direct business operations
  • Examples: Contact form inquiries, newsletter subscriptions, website analytics, recruitment data
  • In this capacity, we are responsible for ensuring all DPDP Act obligations are met, including notice, consent, and Data Principal rights

As a Data Processor:

  • When we process personal data on behalf of educational institutions (Institutions) under their instructions
  • Examples: Student data processed through Google Workspace for Education administration, classroom management tools, academic platforms
  • In this capacity, the Institution is the Data Fiduciary. We process data under a legally binding Data Processing Agreement (DPA) that specifies the nature, purpose, and duration of processing
  • Our processing is limited to what is contractually instructed by the Institution

3. Lawful Processing & Consent Framework

We ensure all personal data processing is lawful under one or more of the following grounds:

  • Consent: Where required, we obtain free, specific, informed, unconditional, and unambiguous consent with a clear affirmative action. Consent notices are provided in English and Hindi. Consent withdrawal is as easy as giving it.
  • Contractual Necessity: Processing required for service delivery under our agreements with Institutions
  • Legal Obligation: Processing required to comply with Indian laws and regulatory requirements
  • Legitimate Interests: Processing for specified legitimate purposes that do not adversely affect Data Principal rights

We maintain a consent register documenting what consent was given, when, and for what purpose. Consent can be withdrawn at any time through our privacy contact channels.

4. Notice Requirements (Section 5)

At the time of collecting personal data, we provide Data Principals with a clear, concise, and itemized notice containing:

  • The types of personal data being collected
  • The purpose of processing
  • The manner in which Data Principals can exercise their rights
  • The contact information of our Data Protection Officer and Grievance Officer
  • How to make a complaint to the Data Protection Board of India

5. Children's Data Compliance (Section 9)

Recognizing the special protections afforded to children under the DPDP Act, CloudResolve has implemented the following measures:

  • We do not process personal data of children (individuals under 18) without verifiable parental consent or authorization from the educational institution acting in loco parentis
  • We do not engage in tracking, behavioral monitoring, or targeted advertising directed at children
  • Student data processing is limited to bona fide educational purposes as determined by the Institution
  • We rely on the educational institution to obtain and manage parental consent for student data processed through our services
  • Our platforms and services are designed with privacy-by-default principles for child users
  • We comply with Schedule 4 of the DPDP Rules concerning exceptions for educational institutions

6. Data Localization & Storage

In compliance with the DPDP Act and Government of India directives:

  • All personal data collected directly by CloudResolve is stored on servers located within India
  • Data processed through Google Workspace for Education may be stored on Google's global infrastructure. We ensure Google is contractually bound as a sub-processor with appropriate safeguards
  • Cross-border data transfers, where applicable, are made only to jurisdictions that may be notified by the Central Government
  • We maintain data flow maps documenting where personal data is collected, processed, stored, and transferred

7. Security Safeguards (Section 8)

We implement reasonable security safeguards to prevent personal data breaches, including:

  • Technical Measures: Encryption (TLS 1.2+ in transit, AES-256 at rest), network firewalls, intrusion detection systems, regular vulnerability scanning, and penetration testing
  • Organizational Measures: Role-based access control, least-privilege data access, mandatory privacy training for all employees, background verification for staff handling sensitive data
  • Physical Measures: Secure data centers with biometric access, CCTV surveillance, and environmental controls
  • Procedural Measures: Data protection impact assessments for high-risk processing, vendor risk assessments, regular security audits by independent auditors

8. Data Breach Notification Protocol

In compliance with Section 8(5) of the DPDP Act and Rule 14 of the DPDP Rules, 2025, CloudResolve has established a data breach response protocol:

  • Detection & Assessment: Automated monitoring systems and incident response team identify and assess potential breaches within 24 hours
  • Notification to Data Protection Board: Report submitted to the DPBI within 72 hours of breach discovery, including nature of breach, types of data affected, number of Data Principals impacted, and remediation measures
  • Notification to Data Principals: Affected individuals notified without delay with details of the breach, potential consequences, and recommended mitigation steps
  • Documentation: All breaches are documented, investigated, and reviewed to prevent recurrence
  • Penalty: We acknowledge that breach of this obligation may result in penalties up to ₹250 crore under Section 33 of the DPDP Act

9. Data Principal Rights

We fully support the rights granted to Data Principals under Chapter III of the DPDP Act:

  • Right to Access (Section 11): Request a summary of personal data held and processing activities
  • Right to Correction (Section 12): Request correction of inaccurate or misleading personal data
  • Right to Erasure (Section 13): Request deletion of personal data once the purpose of processing is served
  • Right of Nomination (Section 14): Designate a nominee to exercise rights in the event of death or incapacity
  • Right to Grievance Redressal (Section 15): Lodge grievances regarding data processing
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise any right, contact us at info@cloudresolve.org. We respond to all requests within 30 days of receipt. Where requests are from Data Principals whose data is processed on behalf of an Institution, we will coordinate with the Institution to fulfil the request appropriately.

10. Grievance Redressal Mechanism

In compliance with Section 15 of the DPDP Act and Rule 5 of the DPDP Rules:

  • CloudResolve has appointed a Grievance Officer to address Data Principal concerns
  • Grievances are acknowledged within 24 hours of receipt
  • Final resolution is provided within 90 days as mandated by the DPDP Act
  • Data Principals unsatisfied with the resolution may file a complaint with the Data Protection Board of India

Grievance Officer
CloudResolve Technologies
Email: grevience@cloudresolve.org

11. Data Protection Officer

CloudResolve has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy, DPDP Act compliance, privacy impact assessments, and serving as the point of contact for Data Principals and the Data Protection Board.

Data Protection Officer
CloudResolve Technologies
Email: office@cloudresolve.org

12. Data Processing Agreements

When CloudResolve processes personal data as a Data Processor on behalf of an Institution, we enter into a legally binding Data Processing Agreement (DPA) that specifies:

  • The nature, purpose, and duration of processing
  • The types of personal data and categories of Data Principals
  • Our obligations and the Institution's obligations under the DPDP Act
  • Sub-processor arrangements (including Google as a sub-processor)
  • Security measures implemented
  • Data breach notification responsibilities
  • Data retention and deletion procedures
  • Audit rights for the Institution

13. Data Retention & Erasure

We implement purpose-specific data retention policies:

  • Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected
  • Upon fulfilment of the purpose or withdrawal of consent, data is securely deleted or anonymized within a reasonable period
  • Data processed for Institution clients is deleted or returned upon termination of the service agreement, in accordance with the DPA
  • Retention periods are documented in our Data Retention Schedule, which is reviewed annually

14. Accountability & Governance

CloudResolve maintains the following governance measures to demonstrate compliance:

  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities
  • Data inventory and data flow mapping
  • Regular privacy and security training for all employees
  • Annual third-party security audits
  • Privacy-by-design principles in product development
  • Vendor due diligence for all data processors and sub-processors
  • Documented data protection policies and procedures

15. Updates & Review

This compliance page is reviewed and updated periodically to reflect changes in our processing activities, the DPDP Act, and DPDP Rules. Material changes will be communicated through our website and directly to affected Data Principals where appropriate.

16. Contact & Complaints

General Inquiries: info@cloudresolve.org
DPO Contact: office@cloudresolve.org
Grievance Redressal: grevience@cloudresolve.org
Data Protection Board of India: www.dataprotectionboardindia.gov.in

Last Updated: July 2026