We build compliance tooling for a living, so we hold ourselves to the standard we assess others against. This notice is written to satisfy Section 5 of the Digital Personal Data Protection Act, 2023 (“the DPDP Act”) — it is itemised rather than general, it tells you how to exercise every right the Act gives you, and it tells you how to complain to the Data Protection Board of India if we get it wrong.
In this notice, “personal data” means any data about an individual who is identifiable by or in relation to that data. “You” and “Data Principal” mean the individual the personal data relates to. “We”, “us” and “JJPMS” mean JJP Meta Systems.
1. Who we are and how to reach us
JJP Meta Systems, of Main Street, National Colony, Bathinda, Punjab, India, operates the website at jjpmetasystems.com and the services offered through it.
For the personal data described in this notice, we act as a Data Fiduciary under the DPDP Act — that is, we determine the purpose and means of processing it. Where we process personal data on behalf of a client under a written contract (for example while delivering a compliance assessment or building software for them), we act as a Data Processor for that client, and the client’s own privacy notice governs that processing rather than this one.
Grievance Officer
Our Grievance Officer is the point of contact for any question about this notice, for exercising your rights, or for raising a grievance about how we have handled your personal data.
- Satnam Singh, Grievance Officer
- support@jjpmetasystems.com
- +91-7696938672
- JJP Meta Systems, Main Street, National Colony, Bathinda, Punjab, India
2. What personal data we collect, and why
We collect only what a given interaction actually requires. We do not buy personal data, and we do not collect it from data brokers. The table below itemises every collection point on this website.
| Where you give it | What we collect | Why we collect it |
|---|---|---|
| Contact enquiry form | First and last name, email address, phone number, service of interest, and the message you write | To answer your enquiry, to prepare a proposal if you ask for one, and to keep a record of the exchange |
| Internship application form | Name, email address, phone or WhatsApp number, college, course, year of study, languages known, preferred area of work, and your motivation statement | To assess your application, to contact you about it, and to administer the internship programme |
| DPDP rapid assessment | Organisation name, contact person’s name, work email address, phone number, industry (optional), and your answers to the assessment questions | To generate and show you your readiness result, to send a copy to our compliance team, and to follow up if you would like a specialist to walk you through the findings |
| Full assessment request | Organisation name, contact person’s name, email address, phone number, organisation size (optional), and any notes you add | To contact you and scope the engagement you have asked for |
| Automatically, when you browse | IP address, browser and device type, pages requested, referring page, and date and time — recorded in our web server logs | To keep the site running and secure, to diagnose faults, and to detect and prevent abuse |
| Automatically, on forms | A session identifier stored in a cookie | To make the anti-spam security question work. See our Cookie Policy |
We do not ask you for financial account details, government identifiers, health information, or biometric data through this website. Please do not send such information to us in a free-text field.
3. The lawful basis on which we process
Under the DPDP Act, personal data may be processed only for a lawful purpose, and only either with your consent or for a legitimate use specified in Section 7 of the Act.
- Consent. Every form on this website is submitted by you voluntarily, after this notice has been made available to you. Submitting a form is your consent to us processing the data in it for the purpose stated against that form in the table above — and for no other purpose.
- Legitimate uses. We rely on Section 7 for a narrow set of activities: keeping our website and systems secure, complying with a legal obligation or an order of a court or regulator, and responding where you have voluntarily provided data for a specified purpose and have not indicated that you object to its use for that purpose.
Our consent requests are specific, unbundled and limited to what the stated purpose needs. We do not make your use of this website conditional on consenting to processing that is not necessary for the purpose you came here for.
4. Withdrawing your consent
You may withdraw your consent at any time, and it must be as easy to withdraw as it was to give. To withdraw, email support@jjpmetasystems.com from the address you used, or write to our Grievance Officer, saying what you would like us to stop doing.
When you withdraw consent we will, within a reasonable period, stop the processing that relied on it, and we will require any Data Processor acting for us to do the same. Two things follow that you should know about:
- Withdrawal is not retrospective. It does not make unlawful anything we lawfully did with your data before you withdrew.
- We may still retain and process a limited amount of data where a law requires us to keep it, or to establish, exercise or defend a legal claim. Where that applies we will tell you which data and why.
5. Who we share personal data with
We do not sell your personal data, and we do not share it for anyone else’s advertising.
We share it only in these situations:
- Our own staff, on a need-to-know basis, to do the thing you contacted us about.
- Data Processors engaged by us under a valid written contract that binds them to process the data only on our instructions, to protect it, to report any breach to us, and to delete or return it when the engagement ends. Today this means our email and website hosting provider, and the provider that delivers our outbound email.
- Professional advisers — for example lawyers or auditors — where they need it and are bound by a duty of confidentiality.
- Government agencies, where we are required to disclose under a law in force in India, or under an order of a court or a competent authority.
- An acquirer, if our business or the relevant part of it is transferred — in which case we will notify you and the acquirer will be bound by this notice or one no less protective.
We do not use third-party advertising networks, analytics platforms, session recording, or social media tracking pixels on this website. See our Cookie Policy for the full detail.
6. Transfers outside India
Section 16 of the DPDP Act permits a Data Fiduciary to transfer personal data outside India, except to a country that the Central Government restricts by notification.
Personal data you give us is stored on servers operated by our hosting and email providers. Some of that infrastructure, and some of the third-party resources this website loads (web fonts and icon libraries served from content delivery networks), may be located outside India. Where a resource is loaded from a content delivery network, that network receives your IP address as a technical necessity of serving the file.
We also work with a partner organisation in London, United Kingdom. Where a project requires personal data to be shared with that partner, it is shared under a written contract carrying the same protections described in this notice.
We do not transfer personal data to any country that the Central Government has restricted under Section 16, and we monitor that list for changes.
7. How long we keep it
Section 8(7) of the DPDP Act requires us to erase personal data once you withdraw consent, or once the purpose we collected it for is no longer being served — whichever is earlier — unless a law requires us to keep it. Our retention periods reflect that.
| Category | We keep it for | Then |
|---|---|---|
| Contact enquiries that do not become engagements | 24 months from your last contact with us | Erased |
| Assessment submissions and results | 24 months from submission | Erased |
| Internship applications that are unsuccessful | 12 months from the decision | Erased |
| Client and engagement records | For the engagement, then as long as any statutory, tax or limitation period requires | Erased at the end of that period |
| Web server logs | Up to 12 months | Erased or aggregated so no individual is identifiable |
| Session cookie | Until you close your browser | Deleted by your browser |
If you ask us to erase your data earlier, we will do so unless we are required to keep it — see Your rights.
8. How we protect it
Section 8(5) of the DPDP Act requires us to take reasonable security safeguards to prevent a personal data breach. The measures we maintain include:
- Encryption of data in transit, using HTTPS across the whole website and authenticated, encrypted connections for outbound email.
- Access control on a least-privilege basis, so that staff can reach only the personal data their role requires.
- Anti-automation controls on public forms, to limit scripted abuse.
- Logging and monitoring, so that unusual activity can be detected and investigated.
- Backups, so that personal data can be restored if it is lost or corrupted.
- Contractual security obligations on every Data Processor we engage.
9. Your rights as a Data Principal
Chapter III of the DPDP Act gives you the following rights over personal data we hold about you.
- Right to access information (Section 11). To obtain a summary of the personal data we are processing about you, the processing activities we are undertaking, and the identities of the other Data Fiduciaries and Processors we have shared it with, along with a description of what was shared.
- Right to correction, completion, updating and erasure (Section 12). To have inaccurate or misleading data corrected, incomplete data completed, out-of-date data updated, and data erased where it is no longer needed for the purpose it was collected for.
- Right of grievance redressal (Section 13). To have a readily available means of raising a grievance with us, which we must respond to within the period the DPDP Rules prescribe. You must exhaust this route before approaching the Data Protection Board.
- Right to nominate (Section 14). To nominate another individual who may exercise these rights on your behalf in the event of your death or incapacity.
How to exercise them
Email support@jjpmetasystems.com with the words “DPDP rights request” in the subject line, telling us which right you are exercising and enough detail for us to find your data. There is no charge. We may need to verify your identity before we act, and we will only ask for what is necessary to do so.
We will respond within the period prescribed under the DPDP Rules. If we cannot act on your request, we will tell you why and how to escalate.
Your duties
Section 15 of the Act also places duties on you: not to impersonate another person, not to suppress material information when providing personal data, and not to register a false or frivolous grievance. Breaching those duties can attract a penalty on you of up to ₹10,000.
10. Children's and guardianship data
This website and our services are directed at businesses and professionals. They are not intended for children under the age of 18, and we do not knowingly collect the personal data of a child, or of a person with a disability who has a lawful guardian, through this website.
Consistent with Section 9 of the DPDP Act, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children — and because we run no advertising or behavioural tracking on this site at all, that holds for every visitor.
Our internship programme may attract applicants who are under 18. Where we become aware that an applicant is a child, we will obtain verifiable consent from a parent or lawful guardian before processing the application further. If you believe a child has given us personal data without that consent, contact our Grievance Officer and we will erase it.
11. Complaining to the Data Protection Board
If you have raised a grievance with our Grievance Officer and you are not satisfied with our response — or we have not responded within the prescribed period — you may complain to the Data Protection Board of India, established under Chapter V of the DPDP Act.
The Board receives complaints, inquires into breaches of the Act, and may impose monetary penalties under the Schedule to the Act. Complaints are made in the manner and form prescribed by the DPDP Rules; details are published by the Board and by the Ministry of Electronics and Information Technology.
12. Languages
Section 5(3) of the DPDP Act entitles you to receive this notice in English or in any language listed in the Eighth Schedule to the Constitution of India.
This notice is published in English. If you would like it in Hindi, Punjabi or any other Eighth Schedule language, email support@jjpmetasystems.com and we will provide a translation at no cost. Where a translation and this English version differ, the English version governs the legal relationship, but we will honour any interpretation that is more favourable to you.
13. Changes to this notice
We review this notice at least annually, and whenever we change how we handle personal data or when the DPDP Rules change. The “last updated” date at the top of this page always reflects the current version.
Where a change materially affects you — for example a new purpose, a new category of recipient, or a longer retention period — we will bring it to your attention, and where the change relies on consent we will ask for fresh consent rather than assuming the old one carries over.