DPDP Act, 2023 & IT Act, 2000 Compliance

Privacy Policy

Effective Date: August 23, 2026 • Forge Digital Technologies (FDT), a commercial brand of Student Forge Technologies Private Limited.

Statutory Compliance Notice

This Privacy Policy is published in accordance with the provisions of Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) under Section 43A of the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023).

1. Legal Entity & Data Fiduciary Details

This website and all related technical engineering and digital marketing services are operated by Student Forge Technologies Private Limited (hereinafter referred to as “Company”, “We”, “Us”, or “Our”), a private limited company incorporated under the laws of the Republic of India (Companies Act, 2013), operating under the commercial brand name Forge Digital Technologies (FDT).

For the purposes of the Digital Personal Data Protection Act, 2023, Student Forge Technologies Private Limited is the Data Fiduciary responsible for determining the purpose and means of processing your personal data.

2. Categories of Personal Data Collected

We may collect, transfer, store, and process the following categories of personal data from Data Principals (Users and Clients):

  • Identity & Contact Information: Full name, corporate email address, contact phone/WhatsApp number, designation, company name, and registered business address provided via contact forms, Cal.com calendar scheduling, or direct communication.
  • Project & Technical Requirements: Technical project briefs, design specifications, software repository credentials (GitHub/GitLab), staging server endpoints, and API tokens provided strictly for executing contracted engineering milestones.
  • Commercial & Billing Data: Permanent Account Number (PAN), Goods and Services Tax Identification Number (GSTIN), billing addresses, bank account transfer confirmation numbers, and transaction IDs. (Note: We do not directly collect or store sensitive credit/debit card details; all online payments are processed through RBI-authorized payment aggregators).
  • Technical & Device Data: Internet Protocol (IP) addresses, browser type, operating system version, time zone setting, and analytical usage logs collected through server log files and cookies.

3. Lawful Grounds & Purpose of Data Processing

Under Section 4 and Section 6 of the DPDP Act, 2023, we process personal data strictly under lawful bases including:

  • Performance of Contract: To prepare Statements of Work (SOW), execute bi-weekly engineering sprints, deploy software systems, deliver marketing assets, and provide technical support.
  • Statutory & Tax Compliance: To issue compliant Tax Invoices under the Central Goods and Services Tax (CGST) Act, 2017 and maintain audit trails required under the Income Tax Act, 1961 and the Companies Act, 2013.
  • Legitimate Uses: To safeguard network infrastructure, prevent fraudulent transactions, and secure client repositories against unauthorized access.
  • Express Consent: For sending project estimates, discovery call scheduling notifications, and newsletters where affirmative consent has been granted.

4. Cookies & Tracking Preferences

We use first-party and third-party cookies to facilitate site navigation, load page assets efficiently, and evaluate aggregate web traffic. You can choose to accept all cookies or restrict to essential cookies at any time via our persistent Cookie Consent preferences banner on the website.

5. Data Security & Storage Standards

In compliance with Rule 5 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we implement comprehensive technical and organizational security measures:

  • 256-bit Advanced Encryption Standard (AES-256) encryption for all database records and repository backups.
  • TLS 1.3 cryptographic protocols for all data in transit across web endpoints.
  • Strict Role-Based Access Control (RBAC) limiting employee access to client repositories on a need-to-know basis.
  • Routine vulnerability assessments and automated dependency scanning.

6. Data Retention Policy

Personal data collected for communication is retained only as long as necessary to fulfill the operational purpose. Financial, invoicing, and tax-related transaction records are preserved for a mandatory statutory period of 8 (eight) financial years in accordance with Section 128 of the Companies Act, 2013 and the Income Tax Act, 1961. Client staging credentials and temporary tokens are purged within 30 days following project sign-off.

7. Rights of Data Principals under DPDP Act, 2023

Under the DPDP Act, 2023, Indian citizens and clients enjoy the following statutory rights:

  • Right to Access: The right to obtain a summary of personal data being processed and identities of data fiduciaries/processors.
  • Right to Correction & Erasure: The right to request rectification of inaccurate data and erasure of data no longer required for statutory purposes.
  • Right of Grievance Redressal: The right to readily available grievance redressal mechanisms with our designated Grievance Officer.
  • Right to Nominate: The right to nominate an individual to exercise data rights in the event of death or incapacity.

8. Statutory Grievance Redressal Officer

In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 13 of the DPDP Act, 2023, the details of our designated Grievance Officer are set out below:

Designation: Grievance Officer, Student Forge Technologies Private Limited
Registered Office: HF2R+CCV, Devender Colony, Kompally, Hyderabad, Telangana 500100, India
Official Email: info@forgedigitaltechnologies.com
Direct Phone: +91 6309917327
Statutory Turnaround: Acknowledgment within 24 hours; resolution within 15 working days.

9. Governing Law & Jurisdiction

This Privacy Policy shall be governed by, construed, and enforced in accordance with the laws of the Republic of India. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the competent courts situated at Hyderabad, Telangana, India.