This notice is live because the website is already collecting personal data through the business listing form and the membership form. It is complete in substance, but a few details marked below still need to be filled in by the Society. It is not legal advice and should be reviewed by someone qualified.
1. Who we are
Ama Odia Parivar Social & Charitable Society (“we”, “the Society”) runs this website for the Odia community in Mumbai and Thane. Under the Digital Personal Data Protection Act, 2023 (DPDP) we are the Data Fiduciary for the personal data described here. If we hold data about you, the Act calls you a Data Principal.
To confirm. Registered name as on the society certificate, registration number, registered address, contact email and phone.
2. What we collect, and why
2.1 Business listings you submit
If you submit a business at List your business we collect the business name, service category, locality, proprietor name, phone, WhatsApp number, email, website, address, PIN code, year established, working hours, indicative rates and a description.
Please read this part carefully. A published listing is public. The business name, proprietor name, phone number, WhatsApp number, email address and full postal address appear on the open internet and can be read by anyone. They appear on the listing page, on directory search and locality pages twenty-four at a time with the phone number and address embedded in the links, and as machine-readable structured data for search engines. Anyone can therefore copy the contact details of every business in a locality without opening a single listing. Please do not enter a personal mobile number or a home address unless you are content for it to be public.
We also record your IP address when you submit, solely so a volunteer can trace an abusive or fraudulent submission while it is in the review queue. It is deleted automatically when your listing is approved. Separately we keep a one-way hash of your IP for one hour to limit each connection to three submissions per hour; that hash is deleted automatically and cannot be read back as an address.
If your submission fails validation, your answers are held briefly so the form can be shown back to you with your details still filled in. That copy is destroyed the first time the page is reloaded.
Nothing is published automatically. Every listing is created as pending and a volunteer reviews it. We may telephone the number you give to confirm it is genuine. We do not email you a confirmation — you are shown one on screen. Your business name, phone and email are emailed to a Society volunteer so the submission can be reviewed.
2.2 Membership applications
If you apply at Become a member we collect your name, father’s or spouse’s name, date of birth, gender, phone, email, address, locality, PIN code and occupation. None of it is published on this website. We hold it as the Society’s own record, to process your membership and to contact you about the Society.
Your IP address is recorded while the application is being reviewed and deleted once it is decided. Membership is for adults: we do not accept applications from anyone under 18, because the DPDP Act requires verifiable parental consent that a web form cannot honestly obtain.
2.3 Committee members
For office bearers we hold name, designation, section, tenure, photograph, a short biography and, where provided, an email address and phone number. Contact details are published only with that member’s explicit agreement, recorded per person and off by default. When a member is marked as past, their stored email and phone are deleted automatically.
2.4 Technical data
Our hosting provider keeps standard server logs — IP address, date and time, page requested, browser type — as a normal part of running and securing a website. Those logs also record the search terms and filters you choose in the directory, because they appear in the page address.
2.5 What we deliberately do not collect
- No analytics or tracking. No Google Analytics, no advertising pixels, no third-party trackers.
- No tracking cookies. The only cookies are those WordPress needs to keep an administrator signed in.
- No comments, so no commenter names, emails or IP addresses.
- No avatar service, so your address is not sent to any avatar provider.
- No external fonts, scripts or automatic embeds. Every public page loads entirely from our own domain, so browsing this site discloses your IP address to no third party other than our hosting provider. A video in the photo gallery is the one exception, and it is never automatic — see section 5.
3. Consent, and withdrawing it
Where we rely on your consent — publishing a business listing, publishing a committee member’s contact details, or processing a membership application — that consent is specific, informed and given by a deliberate act. For listings and membership applications we record when you consented and a fingerprint of the exact wording you agreed to, so we can show what you were told rather than merely assert it.
You can withdraw consent at any time, and it is as easy to withdraw as it was to give. Write to us and we will unpublish the listing or the contact details. Withdrawal does not affect anything lawfully done beforehand.
4. How long we keep it
| Data | Kept for | Enforced |
| IP recorded with a submission or application | Until it is approved or decided | Automatic |
| Anti-spam hash of your IP | 1 hour | Automatic |
| Replay copy after a failed submission | Destroyed on first reload | Automatic |
| A submission or application we decide not to accept | 30 days from the decision, then deleted | Automatic |
| A submission nobody reviews | Moved to rejected after 120 days, deleted 30 days later | Automatic |
| Contact details on a removed listing | Deleted the moment it is removed | Automatic |
| A past committee member’s email and phone | Deleted when marked as past | Automatic |
| Published business listing | While the listing is live | Manual |
| Member record | While the membership is current | Manual |
| Server logs | As set by our hosting provider | Hosting provider |
5. Who we share it with
We do not sell your personal data, and we do not share it for anyone else’s marketing. We share it only with:
- Hostinger, our hosting provider, which stores the website and its database and serves our pages.
- Our email provider. Submission and application notifications are currently delivered to a Gmail mailbox, so those details reach Google’s systems.
- Anyone at all, for the parts of a business listing that are published — see the warning in section 2.1.
- Search engines, which read the structured data we publish for each listing.
- Authorities, where we are required by law to disclose.
Photo albums may contain a video. Nothing at all is requested from YouTube or Vimeo until you press play — until then the page shows only a button, and each one says which service it will load from. When you do press play, the video loads from that service under its own privacy policy and it will see your IP address. We use YouTube’s no-cookie address, which reduces what is stored but does not eliminate it.
Listings show a WhatsApp button and a directions link. Those do nothing until you click them. If you do, your request goes to Meta or Google under their own privacy policies. Your browser tells them you came from this website, but not which listing you were viewing, and we send them nothing about you unless you click.
To confirm. Confirm the Hostinger data-centre region. If the servers are outside India this is a cross-border transfer and must be stated here. Consider moving notifications off Gmail to a mailbox on the Society’s own domain.
6. Security
Submissions are protected against cross-site forgery, rate limited, screened for automated abuse, and re-validated on our server rather than trusted from your browser. Committee contact details and member records are excluded from the website’s programming interface, and that interface does not list our staff accounts or member records to anonymous visitors. Administrative access is limited to volunteers who need it.
No website can promise perfect security. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.
7. Your rights
- Access a summary of the personal data we hold about you, what we do with it, and who else we have shared it with
- Correct data that is inaccurate, and complete data that is incomplete
- Erase your data where we no longer need it for the purpose you gave it for
- Withdraw consent (section 3)
- Nominate someone to exercise these rights for you if you die or become incapacitated
- Complain to us, and then to the Data Protection Board of India
These requests are handled by a person, not automatically. We may ask you to confirm your identity first, so that we do not disclose someone’s details to the wrong person.
8. Grievance Officer
The DPDP Act requires us to publish a contact for grievances. Please raise any concern with us first — the Act expects that before you approach the Data Protection Board of India.
To confirm. Name, designation, email and address of the Grievance Officer, and the period within which you will respond. This is a statutory requirement, not a formality.
9. Your responsibilities
The DPDP Act also places duties on individuals. Please do not impersonate anyone else when submitting a listing, applying for membership or making a request; do not submit details for a business you are not authorised to represent; and give us authentic information when asking us to correct a record.
10. Children
We do not knowingly collect personal data from anyone under 18. The Act requires verifiable consent from a parent or guardian before a child’s data is processed, and forbids tracking or targeted advertising directed at children. Business listings and membership are for adults. Where a Society activity involves children, we obtain parental consent separately and in writing.
If you believe we hold a child’s data without proper consent, write to us and we will delete it.
11. Language
This notice is published in English. Under section 5(3) of the DPDP Act you may ask for it in Odia or any other language in the Eighth Schedule to the Constitution, and we will provide it. As we serve the Odia community, we intend to publish an Odia version alongside the English one.
12. Not yet in use
The following are planned but not built, and we collect none of it today. This notice will be updated before any of it goes live:
- Blood donor registry — blood group and last donation date, which is health data and will need its own separate explicit consent
- Donations — a payment provider and, for 80G receipts, PAN numbers
- Member accounts and logins, member reviews of listings, event RSVPs, and contact or partnership enquiry forms
- Photographs of members or beneficiaries
13. Changes
We will post any change on this page and update the date below. If a change materially affects how we use data you have already given us, we will tell you directly.
Last updated: 23 August 2026.
