Effective date: March 31, 2026
This notice describes Kootami’s data governance commitments aligned to the Digital Personal Data Protection Act, 2023 (India) and applicable subordinate rules. It should be read with ourPrivacy PolicyandTerms and Conditions.
Kootami supports organizations operating in India and globally. DPDP obligations apply to digital personal data processed in scope of the Act and related legal requirements.
In tenant-managed workflows, organizations may act as data fiduciaries while Kootami operates platform infrastructure as a service provider/processor. For platform-level security and operational functions, Kootami may act as data fiduciary.
Kootami is designed to process data needed for membership operations, event participation, governance workflows, and security administration. Unnecessary processing is restricted through role and workflow controls.
Subject to law and context, data principals may request:
Where processing involves children, Kootami and tenant organizations are expected to implement age-appropriate controls, including authorization and consent requirements as applicable by law.
Kootami maintains incident response procedures to investigate, contain, and remediate security events. Notifications are handled in accordance with legal obligations and risk assessment outcomes.
Retention is governed by operational need, tenant policy, audit requirements, and legal obligations. Deletion or anonymization is applied when data is no longer lawfully required.
Cross-border processing, where required, is controlled through governance, contractual safeguards, and platform security mechanisms aligned to applicable legal requirements.