Legal and governance

Privacy Policy

How IVSA collects, uses, shares, secures, retains, and responds to requests concerning personal data.

Effective 12 July 2026

1. Scope

This Privacy Policy explains how the Indian Venture Studio Association ("IVSA", "we", "us", or "our") processes digital personal data in connection with its websites, membership and program applications, events, research, newsletters, directories, surveys, communities, and other services (collectively, the "Services"). It applies to visitors, applicants, Members, participants, speakers, partners, vendors, and other individuals whose personal data we process.

A separate notice, consent request, event notice, research protocol, contract, or employment policy may supplement this Policy. If a supplemental notice conflicts with this Policy for a specific processing activity, the more specific notice applies.

2. Applicable framework and roles

We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules brought into force under it, as applicable from time to time. Terms such as Data Principal, Data Fiduciary, Data Processor, Consent Manager, and personal data have the meanings given by applicable law.

IVSA acts as the Data Fiduciary when it determines why and how personal data is processed. Where an event, program, survey, or research project is jointly delivered, the relevant notice will identify any other organisation responsible for the processing.

3. Personal data we collect

Depending on your relationship with IVSA, we may collect:

  • identity and contact data: name, email, telephone number, city, country, photograph, professional profile, and communication preferences;
  • organisation and professional data: employer, title, biography, expertise, work history, studio model, portfolio information, and publicly available professional information;
  • application and membership data: eligibility responses, supporting documents, authorised representatives, references, declarations, conflicts, dues status, participation, and disciplinary history;
  • account and security data: login identifiers, access logs, authentication information, and security events;
  • transaction data: invoices, tax information, payment status, refunds, sponsorships, grants, and expense records; payment-card details are ordinarily processed directly by payment providers and not stored by IVSA;
  • event and community data: registrations, attendance, accessibility or dietary requests, questions, feedback, photographs, audio-video recordings, and online-community posts;
  • research and survey data: responses, interview notes, recordings where agreed, case-study material, and consent or attribution preferences;
  • communications: enquiries, complaints, legal notices, support requests, and correspondence;
  • technical and usage data: IP address, device and browser information, timestamps, referring pages, pages viewed, and analytics events where optional analytics are accepted; and
  • data received from others: information supplied by an authorised representative, event partner, reference, Member, publicly available source, or service provider.

Please do not submit government identifiers, financial account credentials, health information, or other sensitive information unless IVSA specifically requests it through an appropriate and secure process.

4. How we collect data

We collect data directly from you, from your organisation or authorised representative, through website forms and accounts, through event and program participation, from cookies and similar technologies with the required choice, from service providers, and from lawful public sources. If you provide another person's data, you must be authorised to do so and ensure they receive any required notice.

5. Purposes of processing

We may process personal data to:

  1. respond to enquiries and take steps requested before entering an arrangement;
  2. assess, administer, renew, suspend, or terminate membership and applications;
  3. provide accounts, directories, communities, events, programs, research, and publications;
  4. process invoices, payments, refunds, sponsorships, grants, and statutory records;
  5. send service, governance, safety, and administrative communications;
  6. send newsletters or promotional communications where permitted and provide an unsubscribe mechanism;
  7. manage speakers, contributors, partners, suppliers, volunteers, and conflicts of interest;
  8. conduct research, surveys, benchmarking, and impact measurement, using aggregation or de-identification where reasonably possible;
  9. secure our systems, prevent fraud or misuse, investigate incidents, and enforce legal terms;
  10. comply with law, court or government directions, audit, tax, accounting, and governance obligations;
  11. establish, exercise, or defend legal claims; and
  12. improve the accessibility, performance, relevance, and integrity of the Services.

We will not process personal data for a new incompatible purpose without providing appropriate notice and obtaining consent where required.

6. Consent and other permitted processing

Where consent is required, we will seek consent through clear affirmative action and describe the relevant data and purpose. You may withdraw consent with comparable ease. Withdrawal does not affect processing already lawfully completed, and we may retain information where another legal requirement permits or requires it.

We may also process personal data without consent where applicable law permits, including for specified legitimate uses, performance of legal obligations, responding to medical emergencies or disasters, employment-related purposes, compliance with judgments or orders, and establishment or defence of legal claims.

7. Marketing choices

We send promotional email only where permitted. You may unsubscribe through the link in the message or by contacting us. We may still send non-promotional messages about an application, account, transaction, event, governance matter, safety issue, or legal change.

We do not sell personal data. We do not use personal data for third-party behavioural advertising without the required notice and choice.

8. Cookies and analytics

The website stores an essential preference recording whether optional analytics were accepted or rejected. Google Analytics and Meta Pixel technologies remain disabled unless you accept optional analytics. If enabled, these providers may receive online identifiers and usage events under their own terms. You can reject or change your preference at any time. See the Cookie Policy.

Browser signals such as "Do Not Track" are not uniformly standardised. We honour the choices made through our cookie preference control and any mandatory browser-based mechanism required by applicable law.

9. Sharing and disclosure

We may disclose the minimum necessary personal data to:

  • hosting, cloud, CRM, email, analytics, security, survey, event, payment, accounting, and professional-service providers acting under appropriate obligations;
  • event, program, research, or publication partners where identified and lawfully authorised;
  • auditors, insurers, banks, legal advisers, accountants, and governance bodies;
  • regulators, courts, law-enforcement agencies, tax authorities, or other recipients where disclosure is legally required or reasonably necessary to protect rights and safety; and
  • a successor or reorganised entity in connection with a lawful restructuring, merger, transfer, or dissolution, subject to required safeguards and notices.

We do not permit processors to use personal data for unrelated purposes. Public Member directories, speaker profiles, testimonials, photographs, recordings, or attributed research will be published only under an applicable notice, permission, agreement, or lawful basis.

10. International processing

Some service providers may process data outside India. We will use providers and contractual, technical, or organisational safeguards consistent with applicable Indian restrictions and government notifications. Data may not be transferred to a jurisdiction prohibited by applicable law.

11. Retention

We retain personal data only for as long as reasonably necessary for the stated purpose, legal obligations, dispute periods, security, and governance. Indicative periods are:

  • unsuccessful enquiries and applications: ordinarily up to 24 months;
  • active Member, partner, vendor, and account records: for the relationship plus up to seven years where needed for legal, tax, audit, or claims purposes;
  • financial and statutory records: for the period required by applicable law, ordinarily at least eight financial years where applicable;
  • newsletter data: until unsubscribe, invalidity, or suppression, with limited suppression data retained to honour the opt-out;
  • security logs: ordinarily up to 12 months unless an incident requires longer retention;
  • complaints and investigations: for the matter and a proportionate period thereafter; and
  • consent and publication records: for as long as the associated use continues and a reasonable evidentiary period.

We may retain de-identified or aggregated information that no longer identifies an individual.

12. Security and personal-data breaches

We use proportionate administrative, technical, and physical safeguards, which may include access controls, least-privilege permissions, encryption in transit, backups, logging, vendor diligence, confidentiality obligations, and incident-response procedures. No system is completely secure.

We will assess suspected personal-data breaches, take reasonable containment and remediation steps, maintain required records, and notify affected Data Principals and the Data Protection Board of India when and as required by applicable law.

13. Your rights and duties

Subject to applicable law, you may have the right to:

  • obtain a summary of personal data being processed and processing activities;
  • request correction, completion, updating, or erasure;
  • withdraw consent;
  • nominate another individual to exercise rights in the event of death or incapacity;
  • access a grievance-redressal mechanism; and
  • complain to the Data Protection Board of India after using the available grievance process where required.

Requests may require reasonable identity verification. Rights may be limited where retention or processing is required or permitted by law.

Data Principals must not impersonate another person, suppress material information, make false or frivolous grievances, or provide inauthentic information when exercising rights.

14. Children

The Services are directed primarily to professionals and organisations and are not intended for children. We do not knowingly process a child's personal data for behavioural monitoring, targeted advertising, or processing likely to cause detrimental effects. Where processing a child's data is necessary, we will obtain verifiable consent from a parent or lawful guardian and comply with applicable exemptions and requirements.

15. Automated decision-making

IVSA does not currently make decisions producing legal or similarly significant effects solely through automated processing. If this changes, we will provide an appropriate notice and safeguards.

16. Grievance and contact

To exercise a privacy right, withdraw consent, report a concern, or ask a question, email privacy@ivsa.in or use the Contact page with the subject "Privacy Request". Please provide enough information to identify the relevant record and request.

We aim to acknowledge privacy grievances within 10 business days and resolve them within a reasonable period, subject to complexity and applicable legal timelines. Details of the designated grievance contact will be updated if required by law.

17. Changes

We may update this Policy to reflect legal, operational, or technological changes. Material changes will be highlighted through the website or direct notice where appropriate. The effective date displayed on the page identifies the current version.