Privacy Policy

Last Updated: 29 June 2026 Effective Date: 29 June 2026 Applicable Laws: DPDP Act 2023 (India), GDPR (EU), CCPA (California)

Plain-Language Summary

MYITMANAGER is a privacy and cybersecurity consultancy. We collect personal data only to serve you — namely your name, work email, company name, and how you interact with our website. We do not sell your data. We do not use it for advertising. You can ask us to access, correct, or delete your data at any time by emailing our Grievance Officer (details at the bottom of this page). We try to treat your data exactly the way we’d recommend our clients treat theirs.

1. Who We Are

MYITMANAGER is a cybersecurity and data protection consultancy based in India. We provide advisory and implementation services for the DPDP Act 2023, GDPR, CCPA, ISO 27001, SOC 2, HIPAA, and related frameworks. When you visit myitmanager.in, submit a form, or engage us as a consulting client, we act as the Data Fiduciary (DPDP Act terminology) or Data Controller (GDPR terminology) for your personal data.

Legal entity: MYITMANAGER
Registered address: Sector 54, Sun City, Gurugram, Haryana 122002, India
Contact email: help@myitmanager.in
Phone: +91 9711410789

2. What Personal Data We Collect

We collect only what we need. Here is the complete list:

CategoryWhat we collectWhen
Identity dataYour name, professional title, company nameWhen you submit a contact form, book a meeting, or download our checklist
Contact dataWork email, phone number (if you provide it)Same as above
Engagement dataService interest, message content, meeting notesWhen you communicate with us
Technical dataIP address (anonymised), browser type, device, pages viewed, scroll depth, time on page, referrerWhen you visit the site — only after you accept analytics cookies
Marketing dataEmail subscription status, content downloadedWhen you opt in to our communications
Client dataInformation shared during paid consulting engagements (covered by our consulting agreement, not this policy)During active consulting engagements

We do not collect:

  • Government identifiers (Aadhaar, PAN, passport, driver’s license)
  • Payment card information (we use third-party processors that handle this directly)
  • Health, biometric, financial, or other sensitive categories — unless explicitly required by a client engagement under separate agreement
  • Data from children under 18

3. How We Use Your Data

We use your personal data only for these specific purposes:

  • Respond to your inquiry — when you submit a contact form, we use your contact details to reply
  • Provide consulting services — for clients who engage us, we process data necessary to deliver assessments, reports, and advice
  • Send the resources you request — for example, the DPDP Compliance Checklist PDF
  • Improve our website — anonymised analytics data helps us understand which content is useful
  • Communicate updates — only if you opt in to our mailing list; you can unsubscribe anytime
  • Comply with legal obligations — including responding to lawful requests from Indian authorities, courts, or regulators

We do not:

  • Sell or rent your personal data to anyone
  • Use your data for behavioural advertising
  • Profile you for automated decision-making
  • Share your data with social media platforms for marketing

Under the DPDP Act 2023, we rely on these lawful bases:

PurposeLawful basis (DPDP)GDPR equivalent
Replying to your inquiryConsent (Section 6)Consent / Legitimate interest (Art. 6(1)(a)/(f))
Providing consulting servicesPerformance of contractContract (Art. 6(1)(b))
Marketing emailsSpecific consent (opt-in)Consent (Art. 6(1)(a))
Analytics cookiesConsent via Cookie BannerConsent (Art. 6(1)(a))
Legal compliance / court ordersSection 7 (legitimate uses)Legal obligation (Art. 6(1)(c))
Defending legal claimsSection 7Legitimate interest (Art. 6(1)(f))

5. Who We Share Your Data With

We share data only with these categories of recipients, and only as necessary:

  • Service providers (Data Processors) — Google Workspace (email, calendar), our hosting provider (GoDaddy), Google Analytics (for anonymised website traffic), Microsoft (Outlook, Teams). Each operates under a Data Processing Agreement (DPA).
  • Professional advisors — our lawyers, accountants, and auditors, bound by professional confidentiality obligations
  • Government authorities — only when legally compelled (court order, statutory notice, lawful investigation)
  • Business successors — if MYITMANAGER is acquired or merged, your data may transfer to the new entity under the same protections

We do not share data with advertising networks, data brokers, social media platforms, or any party for marketing purposes.

6. How Long We Keep Your Data

Data typeRetention periodWhy
Inquiry data (forms, emails)3 years from last contactTo respond to follow-ups and maintain context
Client engagement records7 years after engagement endsIncome Tax Act + professional liability defense
Marketing email subscribersUntil you unsubscribe + 30 daysConfirmation of unsubscribe request
Analytics data (Google Analytics)14 monthsYear-over-year trend analysis
Website cookies365 days maximumDefault consent cookie expiry
Server access logs180 daysCERT-In cybersecurity directions compliance

After the retention period ends, we delete or anonymise the data so it can no longer identify you.

7. Your Rights as a Data Principal

The DPDP Act 2023 gives you the following rights. We honour all of them at no charge.

  • Right to access — request a summary of the personal data we hold about you and how we use it
  • Right to correction — ask us to fix inaccurate or incomplete data
  • Right to erasure — ask us to delete your data when the purpose is fulfilled or you withdraw consent (subject to legal retention obligations noted in Section 6)
  • Right to grievance redressal — file a complaint with our Grievance Officer (see Section 13) and receive a response within 30 days
  • Right of nomination — nominate another person to exercise these rights in case of your death or incapacity
  • Right to withdraw consent — at any time, without penalty
  • Right to complain — escalate to the Data Protection Board of India if you are unsatisfied with our response

If you are in the EU/EEA, you also have GDPR rights including data portability and the right to object to processing. Email our Grievance Officer to exercise either set of rights.

How to exercise these rights: Send an email to help@myitmanager.in with the subject line “DPDP Rights Request”. Include enough detail to identify your data (the email address you used to contact us is usually sufficient). We will respond within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar technologies. None of these fire on your browser until you accept them in the cookie banner shown on your first visit. For complete details — including what each cookie does, its retention period, and who sets it — see our Cookie Policy.

Summary:

  • Essential cookies — required for the site to function. No consent needed under DPDP.
  • Statistics cookies — Google Analytics 4, anonymised IP, no Google Signals, no Ads Personalization. Fires only after you accept.
  • Marketing cookies — we do not use these.

You can change your cookie preferences any time by clicking the floating “Manage Consent” button at the bottom of any page.

9. How We Protect Your Data

We apply the same reasonable security safeguards we recommend to our clients:

  • Encryption of data at rest and in transit (TLS for all web traffic)
  • Role-based access controls — only authorised staff access personal data
  • Multi-factor authentication on all administrative accounts
  • Regular vulnerability assessments and penetration testing (VAPT)
  • CERT-In compliant incident response procedures
  • 180-day server log retention per CERT-In directions
  • Vendor risk assessment for all third-party data processors

If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act.

10. Children’s Data

This website and our services are not intended for individuals under 18. We do not knowingly collect personal data from children. If we discover that we have collected data from a child under 18 without verifiable parental consent, we will delete it promptly. Parents or guardians who believe their child has provided us with personal data should email help@myitmanager.in.

11. Cross-Border Data Transfers

Some of our service providers (Google, Microsoft) process data outside India. We take reasonable safeguards including:

  • Using providers who themselves comply with GDPR and equivalent international frameworks
  • Executing Standard Contractual Clauses or Data Processing Agreements with each cross-border processor
  • Restricting transfers to countries that are not on any future DPDP-restricted-jurisdictions list once notified

We will update this policy promptly if the Government of India notifies any country-specific restrictions under DPDP Rules.

12. Changes to This Policy

We may update this policy as our practices or applicable law evolves. Material changes will be:

  • Posted on this page with an updated “Last Updated” date at the top
  • Communicated by email to active subscribers and clients where the change is material

For minor changes (clarifications, formatting, broken-link fixes), we will simply update the date at the top.

13. Grievance Officer & Contact

Under the DPDP Act 2023, we have designated the following individual as our Grievance Officer. You can contact this person to:

  • Exercise any of your data principal rights (access, correction, erasure, nomination)
  • Withdraw consent for any specific purpose
  • File a grievance about our handling of your data
  • Ask any question about this Privacy Policy

Grievance Officer

Name: Saurabh Gupta
Title: Founder & Grievance Officer
Email: help@myitmanager.in
Phone: +91 9711410789
Postal address: Sector 54, Sun City, Gurugram, Haryana 122002, India

Response time: We respond to all data principal requests within 30 days of receipt.

Escalation to the Data Protection Board of India

If you are not satisfied with our response to your grievance, you can escalate to the Data Protection Board of India under Section 13(3) of the DPDP Act 2023. Details of the DPB and its complaint procedure will be published by the Government of India.


This privacy policy is published by MYITMANAGER under the Digital Personal Data Protection Act 2023 (India), the General Data Protection Regulation 2016/679 (EU), and the California Consumer Privacy Act (USA). For a downloadable PDF copy, email help@myitmanager.in.