Legal Framework · DPDP Act 2023 · IT Act 2000

Privacy Policy

The Literary Club of Anna University (“LitClub AU”) is committed to protecting the personal data of every participant, visitor, and stakeholder of the Ice Breaker 2026–2027 event platform. This document explains what we collect, why, and how you can exercise your rights under Indian law.

Effective: 12 September 2026Last Updated: 12 September 2026Version 1.0

This Privacy Policy should be read alongside our Terms & Conditions and Cookie Policy, which together govern your use of this platform.

Section 1

1. Who We Are & Scope of This Policy

This Privacy Policy (“Policy”) applies to all digital services operated by The Literary Club of Anna University (“LitClub AU”, “we”, “us”, or “our”) in connection with the Ice Breaker 2026–2027 festival, including but not limited to: the event website, participant registration portal, stall listings, sponsor pages, and the administrator dashboard hosted on this domain.

Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), LitClub AU acts as the Data Fiduciary — determining the purpose and means of processing personal data. Event participants are the Data Principals whose data is processed.

Registered Office & Correspondence Address:

The Literary Club of Anna University, Sardar Patel Road, Guindy, Chennai, Tamil Nadu — 600 025, India.
Official Contact Email: litclubau@gmail.com

This Policy does not apply to third-party websites or services to which we link, including but not limited to Instagram, Google Mail, and Cloudinary. Please review their independent privacy policies before providing them your data.


Section 2

2. Categories of Personal Data We Collect

We collect only the minimum personal data necessary for the specific purposes described in Section 3 below (data minimisation principle, Section 6(1) DPDP Act 2023):

2.1 Data You Provide Directly

  • Identity & Academic Data: Full legal name, Anna University Roll Number, Department, and Year of Study — used to verify bona fide campus enrollment.
  • Contact Data: Personal email address and mobile telephone number — used for account login, event communications, and emergency notifications.
  • Authentication Credentials: Passwords are immediately one-way hashed with a cryptographic salt using industry-standard bcrypt (cost factor ≥ 10). Plaintext passwords are never stored, logged, transmitted in clear, or accessible by any staff member.
  • Event & Team Registration Data: Selected event categories, team member compositions, team allocation codes, and event submission data.

2.2 Data Collected Automatically

  • Technical & Session Data: Internet Protocol (IP) address, browser user-agent string, operating system, HTTP request headers, session authentication tokens (JWT), and request timestamps — collected automatically for security auditing, abuse prevention, and system diagnostics.
  • Cookie & Local Storage Data: Functional cookies and browser local storage used to maintain login sessions. See Section 7 and our separate Cookie Policy for full details.

2.3 Data We Do Not Collect

  • We do not collect biometric data, financial payment card data, government identification numbers (Aadhaar, PAN), caste, religion, political views, health records, or any special category of sensitive personal data as defined under the DPDP Act 2023 and the IT (SPDI) Rules 2011.

Section 3

3. How We Use Your Personal Data

Personal data is processed only for specified, explicit, and legitimate purposes. We do not repurpose data beyond what was originally disclosed:

  1. Account Management: Creating and maintaining your secure participant account, enabling login and profile self-management at /users/me.
  2. Event Registration & Eligibility Verification: Verifying that you are a bona fide student of Anna University, processing your competition entries, assigning team tracking numbers, and enforcing per-event participant limits.
  3. Event Operations & Communications: Sending essential notifications about your registered events — including schedule changes, venue details, result announcements, or safety/emergency alerts.
  4. Platform Administration: Internal auditing, fraud prevention, abuse detection, and technical system maintenance.
  5. Legal Obligations: Complying with applicable Indian laws, court orders, or lawful directions from competent government authorities.

We will not use your personal data for unsolicited marketing communications, commercial profiling, automated individual decision-making, or any purpose incompatible with those listed above without obtaining fresh explicit consent.


Section 4

4. Consent & Lawful Basis for Processing

Under Section 6 and Section 7 of the DPDP Act 2023, we rely on the following lawful bases for processing:

  • Free, Specific & Informed Consent (DPDP Act, Section 6): When you create an account and register for events, you provide explicit consent to our collection and processing of your personal data as described in this Policy via a separate, checkbox-based affirmation during registration — distinct from and not bundled with acceptance of the Terms & Conditions. A cookie consent banner is separately provided at your first visit for non-essential cookie categories.
  • Legitimate Uses (DPDP Act, Section 7): Certain processing activities such as fraud prevention, technical security logging, and responding to lawful government directives are carried out under legitimate use grounds without requiring separate consent.
  • Consent Withdrawal: You may withdraw consent at any time by deleting your account or emailing our Grievance Officer (see Section 13 of this Policy). Withdrawal does not affect the legality of processing carried out before the withdrawal.

Section 5

5. Data Retention & Deletion

We retain personal data only as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Indian law:

  • Active Accounts: Retained for the duration of the Ice Breaker 2026–2027 event cycle and for a reasonable post-event period to resolve any disputes or prize distribution.
  • Post-Event Purge: All personal data pertaining to individual participants will be reviewed and deleted or anonymised within 180 days following the conclusion of the Ice Breaker 2026–2027 event, unless retention is required to comply with a legal obligation or pending dispute.
  • Technical & Security Logs: Server request logs and audit trails are retained for up to 90 days for cybersecurity and fraud investigation purposes.
  • Deleted Account Data: Upon a valid erasure request, personal data is permanently deleted from active databases within 30 days. Residual copies in automated backup systems are purged within the next scheduled backup rotation cycle.

Section 6

6. Security Measures & Data Protection

In compliance with Section 43A of the Information Technology Act, 2000 (as applicable prior to the full operationalisation of the DPDP Act 2023 provisions), the DPDP Act 2023, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have implemented the following organisational and technical safeguards:

  • Encryption in Transit: All data exchanged between your browser and our servers is encrypted via HTTPS / TLS 1.2+.
  • Encryption at Rest: Passwords are stored exclusively as bcrypt hashes. No plaintext credentials exist in any database table, log file, or backup.
  • Role-Based Access Control (RBAC): Database access is segmented by role. Event administrators can only access participant lists for their assigned events. Superadmin privileges are scoped to a single seeded account.
  • Principle of Least Privilege: Application services connect to the database using credentials that grant only the minimum permissions required for their function.
  • Routine Monitoring: Server logs are monitored for anomalous activity. Any suspected unauthorised access attempts are investigated promptly.

While we implement industry-standard safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of data transmitted over the internet. Users are encouraged to maintain strong unique passwords and to report any suspected account compromise immediately to litclubau@gmail.com.


Section 7

7. Cookies & Tracking Technologies

When you visit this website, we and our third-party service providers may place cookies or use similar browser storage technologies on your device. Your cookie preferences are managed through the cookie consent banner displayed on your first visit, and you may update them at any time. For full details of every cookie category we use, its retention period, and how to opt out, please read our separate Cookie Policy.

Summary of cookie categories:

  • Strictly Necessary (always active): Session authentication tokens and CSRF protection tokens required for the platform to function. These cannot be disabled as the service would not work without them.
  • Functional (consent required): Browser local storage values that remember your UI preferences (e.g., saved scroll position, theme state) across visits.

We do not currently use advertising, analytics, or cross-site tracking cookies. Should this change, this Policy and our Cookie Policy will be updated and fresh consent will be sought before any such cookies are placed.


Section 8

8. Third-Party Processors & Non-Disclosure

We do not sell, rent, lease, or trade your personal data to commercial data brokers, advertising networks, or any unauthorised third party.

We engage the following sub-processors strictly for infrastructure purposes. Each is bound by data processing obligations consistent with Indian data protection requirements:

  • Cloudinary (Media Asset Delivery): Public event images, stall product photos, and sponsor logos are hosted on Cloudinary's content delivery network. Only non-personal media assets are intentionally transferred; however, Cloudinary's CDN infrastructure may incidentally process request metadata such as IP addresses. Cloudinary is a US-based entity; such incidental processing constitutes a cross-border data transfer under DPDP Act 2023, Section 16, covered by Cloudinary's own compliance framework.
  • Google (Fonts & Typography): Fonts are loaded from Google's servers, which automatically receives your IP address and browser User-Agent on each page load. This constitutes a transfer of personal data to Google LLC (USA). By using this platform you acknowledge this transfer. See Google's Privacy Policy.
  • Database Infrastructure (PostgreSQL): Our backend database stores participant and event records with encrypted connections and access controls as described in Section 6.
  • Government & Legal Authorities: We may disclose personal data to competent statutory authorities, law enforcement agencies, or courts of law if required to do so by a legally binding order or direction under Indian law, including the IT Act 2000 and the Code of Criminal Procedure.
  • Anna University Administration: In exceptional cases involving campus safety, disciplinary proceedings, or compliance with University regulations, relevant data may be disclosed to the University administration on a need-to-know basis.

Any disclosure under legal obligation will, to the extent permissible by law, be notified to the affected data principal before or promptly after disclosure. LitClub AU does not sell, rent, or trade personal data with commercial data brokers or advertising networks under any circumstances.


Section 9

9. Minors' Data

The Ice Breaker event is open to enrolled students of Anna University and affiliated colleges. In accordance with the DPDP Act 2023, we do not knowingly process personal data of children below the age of 18 years without verifiable parental or guardian consent.

By registering on this platform you represent that you are at least 18 years of age, or that you have obtained valid parental consent prior to registration. If we become aware that personal data of a minor has been collected without appropriate consent, we will delete such data without undue delay and notify the Grievance Officer.


Section 10

10. Your Rights as a Data Principal

Pursuant to Chapter III (Sections 11–14) of the DPDP Act 2023, you have the following enforceable rights with respect to your personal data:

  • Right to Access & Summary (DPDP Act, Section 11): Request a summary of the personal data held about you and the processing activities carried out. Basic access is available via your account dashboard at /users/me. We will respond to formal access requests within 30 days of identity verification, as required under the DPDP Rules 2025.
  • Right to Correction & Completion (DPDP Act, Section 12): Request correction of inaccurate, incomplete, or outdated personal data. Minor profile fields (name, contact, department, year) can be updated directly from your account.
  • Right to Erasure & Consent Withdrawal (DPDP Act, Sections 12–13): Request permanent deletion of your personal data and account. Requests are honoured within 30 days except where retention is required by applicable law or an ongoing legitimate dispute.
  • Right to Grievance Redressal (DPDP Act, Section 14): Lodge a complaint with our Grievance Officer (see Section 13 of this Policy). If unresolved, you may escalate to the Data Protection Board of India once constituted under the DPDP Act 2023.
  • Right to Nominate (DPDP Act, Section 14(3)): Nominate another individual to exercise rights on your behalf in the event of death or incapacity, as provided under the DPDP Act 2023.
  • Right to Data Portability: Subject to rules notified by the Central Government under the DPDP Act 2023, you may have a right to receive your personal data in a machine-readable format. This Policy will be updated when portability rules are operationalised.

To exercise any right above, email our Grievance Officer at litclubau@gmail.com with the subject line “Data Rights Request — [Your Full Name] — [Roll No]”. We will verify your identity before processing any request.


Section 11

11. Data Breach Notification Procedure

In the event of a personal data breach that is reasonably likely to result in harm to data principals, we will take the following steps in line with emerging DPDP Act 2023 obligations and international best practices:

  1. Contain and assess the breach internally within 24 hours of discovery.
  2. Notify affected data principals as soon as reasonably practicable, and no later than 72 hours after confirmed discovery, via the registered email address on file.
  3. Report the breach to the Data Protection Board of India (once operational) or applicable authority as required by law.
  4. Document the nature of the breach, data categories affected, approximate number of individuals, and remedial actions taken.

Section 12

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, our data practices, or the services we provide. When we make material changes:

  • The “Last Updated” date at the top of this page will be revised.
  • Registered users will be notified via their registered email address at least 15 days before the changes take effect, providing an opportunity to review and, if necessary, withdraw consent.
  • Continued use of the platform after the effective date of changes constitutes acceptance of the revised Policy.

We recommend reviewing this page periodically. Archived versions of prior policies are available upon request from the Grievance Officer.


Section 13

13. Grievance Officer & Contact

In accordance with Rule 5(9) of the IT (SPDI) Rules, 2011 and Section 13 of the DPDP Act 2023, LitClub AU has designated the following Grievance Officers to address any privacy-related concerns, requests, or complaints:

Designated Grievance Officers

Organisation: The Literary Club of Anna University (LitClub AU)
Officers: Tanvi — +91 99620 74219 · Abhinav — +91 99402 19278
Official Email: litclubau@gmail.com
Campus Address: The Literary Club of Anna University, Sardar Patel Road, Guindy, Chennai, Tamil Nadu — 600 025, India.
Office Hours: Monday – Saturday, 10:00 AM – 5:00 PM IST (excluding public holidays and university examination periods)

  • Complaints must be submitted in writing (email) with subject line: “Privacy Grievance — [Full Name] — [Roll No]”.
  • Acknowledgement of receipt will be provided within 48 hours (excluding Sundays and public holidays).
  • The grievance will be resolved or a substantive response will be provided within 15 working days of receipt, as mandated under Rule 5(9) of the IT (SPDI) Rules, 2011 and the DPDP Act 2023.
  • If you are dissatisfied with the resolution, you may escalate your complaint to the Data Protection Board of India (once operational under the DPDP Act 2023) or to the competent court of jurisdiction.

Section 14

14. Governing Law & Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India. The principal statutes governing this Policy include but are not limited to:

  • The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023)
  • The Information Technology Act, 2000 (Act No. 21 of 2000) and amendments thereto
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

Any legal action, dispute, or proceeding arising out of or relating to this Policy or the processing of personal data shall be subject to the exclusive jurisdiction of the competent civil courts in Chennai, Tamil Nadu, India.


Legal Disclaimer

This Privacy Policy has been prepared by The Literary Club of Anna University in good faith to comply with applicable Indian data protection law as currently understood. It is not a substitute for professional legal advice. LitClub AU is a student-run, non-commercial organisation operating the Ice Breaker 2026–2027 event within Anna University. Nothing in this Policy creates or implies any commercial relationship, legal entity separate from Anna University, or warranty of any kind. This Policy may be amended without prior notice for non-material corrections (e.g., typographical errors, updated contact information); material changes will follow the notification procedure in Section 12. All references to the DPDP Act 2023 are to the Act as enacted and as may be amended or supplemented by rules notified by the Central Government from time to time.