This Privacy Policy and Notice explains how MITCON Credentia Corporate Support ("we", "us") processes personal data in the MITCON Credentia — Corporate Support portal, as required by the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it. We are the Data Fiduciary for this processing.
1. Who this covers
- Portal users: employees and authorised staff who sign in (Administrators, Relationship Managers, Accountants).
- Other people whose details are entered by users: contact persons at clients and prospective clients, references, meeting attendees, and recipients of reminder emails.
2. Personal data we process
- About portal users: name, email ID, mobile number, role, sign-in codes (valid for a few minutes), sign-in history, IP address, browser and device, a record of actions taken in the portal (audit log), team chat messages, and privacy choices.
- About other people: name, designation, organisation, email IDs, phone numbers, business addresses, what was discussed in meetings, and documents they share with us (for example engagement letters and their acceptance).
We do not ask for, and users must not enter, sensitive details that the business does not need, such as health information, financial account numbers or government identity numbers, unless required for a specific engagement.
3. Why we process it
- To give authorised staff secure access, using one-time sign-in codes sent by email and SMS.
- To manage our business with clients: inquiries, quotations, engagement letters, meetings, follow-ups and reminders.
- To communicate with clients and colleagues, including scheduled reminder emails and internal team chat.
- To keep the portal secure: preventing misuse, investigating incidents, and keeping an audit trail of who did what and when.
- To meet legal, regulatory and record-keeping obligations.
For portal users, we rely on your consent and on the legitimate uses allowed under Section 7 of the DPDP Act, including purposes of employment and compliance with law. For other people, users must enter their details only for the purposes above, and only where they were provided for the business relationship.
4. Who we share it with
We do not sell personal data. It is shared only with service providers who process it for us, under our instructions:
- Hosting and email: our web host and our email provider (Hostinger), to run the portal, send sign-in codes and send emails from our mailboxes.
- SMS: our SMS gateway, to send sign-in codes to registered mobile numbers, when SMS is switched on.
- Optional AI fill: only when this feature is switched on and a user chooses to use it, the text the user types or dictates about a meeting, with the names of that client's contacts and locations and of our team members, is sent to Anthropic (Claude) to suggest form entries. It is not used when switched off.
- Voice dictation: when a user presses a microphone button, the browser (for example Google Chrome or Microsoft Edge) sends the audio to its own speech-recognition service.
- Authorities: where the law requires us to.
Some of these providers may process data outside India. Any such transfer is made only as permitted under Section 16 of the DPDP Act.
5. How long we keep it
We keep personal data only as long as needed for the purposes above or as required by law. Sign-in codes expire within minutes. User accounts are deactivated when access is no longer needed; business records such as quotations and engagement letters, and the audit log that protects their integrity, are kept for the periods required by law and our record-keeping policy. When data is no longer needed, we erase it or remove what identifies a person.
6. How we protect it
Sign-in by one-time codes, access limited by role, encrypted storage of mailbox passwords, private storage of uploaded files, an audit log of actions, and restricted administrator access. Please sign out on shared computers: signing in keeps you signed in on that browser until you sign out. If there is a personal data breach, we will inform the Data Protection Board of India and the affected people as the DPDP Act requires.
7. Your rights
As a Data Principal, you can:
- ask for a summary of your personal data we process and who we have shared it with;
- ask us to correct, complete, update or erase your personal data (erasure may be limited where the law requires us to keep records);
- withdraw your consent at any time, as easily as you gave it, from My privacy consent in the portal. Withdrawal stops the processing that relies on consent from then on; the portal cannot be used without it. It does not affect processing already done;
- have your grievances addressed by our Grievance Officer, and then approach the Data Protection Board of India if you are not satisfied;
- nominate another person to exercise these rights if you die or become incapable.
You also have duties under Section 15 of the DPDP Act: give authentic information, do not impersonate anyone, and do not file false or frivolous complaints.
8. Grievance Officer and contact
Grievance Officer, MITCON Credentia Corporate Support
1st Floor, Kubera Chambers, Shivajinagar, Pune 411005, Maharashtra (India)
Email: contact@mitconcredentia.in
We will acknowledge your request and respond within the period required under the DPDP Act and its rules.
9. Children
The portal is for our staff only and is not meant for children. We do not knowingly process children's personal data through it.
10. Changes to this policy
When we change this policy, we will publish the new version here and ask every portal user to read and accept it again before continuing.