1Introduction & Data Fiduciary Details
Welcome to Nisargshala Corporate Gateway (accessible at corp.nisargshala.in), an enterprise B2B platform operated by Nisargshala (“Nisargshala”, “we”, “us”, or “our”).
We are committed to protecting corporate commercial information and personal data of company representatives, HR professionals, and voucher recipients. We act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDPA) and adhere strictly to the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
2Categories of Data We Collect (Data Minimization)
Under our strict data minimization policy, we collect only information strictly necessary to fulfill corporate voucher orders, execute wilderness retreat bookings, issue statutory GST invoices, and maintain enterprise account security:
- Corporate Account & Business Data: Company Legal Name, Registered Billing Address, 15-character Goods and Services Tax Identification Number (GSTIN), Corporate PAN, and Corporate Identity details.
- Authorized Representative & HR Contact Data: Full Name, Official Work Email Address, Contact Mobile/Phone Number, and Designation.
- Transaction & Verification Data: Bank Transfer / NEFT / RTGS Unique Transaction Reference (UTR) numbers, payment dates, payment amounts, and generated tax invoices. (We do not collect or store credit/debit card numbers or net banking passwords).
- Voucher & Event Operational Details: Assigned employee names (optional, if bulk pre-assigned), recipient email addresses for certificate dispatch, retreat dates, attendee counts, and specific wilderness camp logistical requirements.
- Technical & Session Data: IP address, browser type, and cryptographically signed session tokens required exclusively for authenticated login sessions and CSRF protection.
3Lawful Basis & Purpose of Processing
We process your data exclusively for legitimate enterprise purposes, including:
Generating cryptographically unique vouchers, dispatching PDF packages, and coordinating wilderness retreats.
Generating compliant B2B Tax Invoices with buyer & seller GSTIN validation under Indian Goods and Services Tax laws.
Verifying bank UTR payments, preventing voucher duplication, and maintaining tamper-evident audit logs.
Maintaining safety rosters for wilderness first-responder protocols at Nisargshala campsites.
4Zero-Data-Sale Pledge & Third-Party Processors
Nisargshala does not sell, rent, monetize, or trade corporate or personal data to data brokers, ad networks, or marketing agencies under any circumstances.
We share data only with verified infrastructure processors bound by strict confidentiality and data protection agreements:
- Cloud Database & Hosting: Secured PostgreSQL database infrastructure with end-to-end encryption at rest (AES-256) and in transit (TLS 1.3).
- Transactional Email Services: Secure SMTP/API relays exclusively used for delivering invoices, voucher ZIP packages, and booking confirmations.
- Statutory & Legal Authorities: Disclosed solely when strictly required by applicable Indian law, court order, or governmental tax audit.
5Data Security & Retention Periods
We implement industry-standard administrative, physical, and technical safeguards. Passwords are never stored in plaintext and are protected using canonical salted scrypt key derivation. Administrative sessions use secure, HttpOnly, SameSite cookies.
Retention Periods:
- Tax & Accounting Records: Retained for a mandatory period of 8 years as required under Indian GST & Companies Act provisions.
- Active Voucher Instruments: Retained during the 12-month validity window plus 180 days post-expiry for redemption reconciliation.
- Enquiries: Retained for up to 24 months for corporate follow-up, after which they are securely archived or purged.
6Your Rights as a Data Principal (DPDPA 2023)
Under the Digital Personal Data Protection Act 2023, corporate representatives and individuals possess specific statutory rights:
Request a summary of personal data processed and identities of processors with whom data has been shared.
Correct inaccurate data, update contact details, or rectify corporate GSTIN records.
Request deletion of personal data when no longer necessary for the specified purpose, subject to tax retention laws.
Access readily available grievance redressal mechanisms with our designated Grievance Officer.
7Statutory Grievance Redressal Officer
In compliance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDPA 2023, the details of the designated Grievance Redressal Officer are as follows:
Grievances received will be acknowledged within 48 hours and redressed within 30 days as mandated by applicable statutory provisions.
