Privacy Policy & Data Protection
Institutional framework governing the lawful collection, processing, protection, and rights concerning personal and enterprise data across the Entrepreneurship Development Council of India portal.
🏛️ Official Council Statutory Policy
Effective Date: September 2026 | Last Revised: September 21, 2026 | Governing Legislation: Digital Personal Data Protection (DPDP) Act, 2023 and Information Technology Act, 2000 | Jurisdiction: Bhopal, Madhya Pradesh, India
1. Institutional Framework & Purpose
The Entrepreneurship Development Council of India (EDCI) is committed to protecting the privacy, confidentiality, and sovereign data rights of entrepreneurs, mentors, institutional partners, and general public visitors. This Privacy Policy outlines our transparent protocols for collecting, storing, processing, and safeguarding personal and enterprise information in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000.
2. Categories of Information Collected
EDCI collects data strictly necessary to deliver verified portal services:
- Account & Signatory Identity: Full Name, verified Email Address, 10-digit Indian Mobile Number, account credentials (cryptographically hashed), and administrative communication preferences.
- Enterprise & Compliance Records: Business / Trade Name, Legal Entity Type (Pvt Ltd, LLP, Partnership, Proprietorship, Section 8), Sector classification, Business Stage, and state/district of operation.
- Geographic Derivation Data: District and State inputs used exclusively by our backend deterministic mapping engine to assign your enterprise to India’s 6 Zones and 36 State Chapters.
- Billing & Transaction Audit Logs: WooCommerce Order IDs, transaction timestamps, payment method references, and membership validity dates (₹10,000/year). Note: EDCI never stores raw credit card numbers or UPI MPINs. All payment transactions are securely handled by PCI-DSS certified gateways (Razorpay).
- Technical & Security Metadata: Client IP addresses, browser user-agent strings, and session timestamps captured strictly for rate-limiting (5 requests/hr) and anti-spam verification.
🔒 Privacy Shield: Raw Personal Contact Masking in Public Directory
In accordance with EDCI’s privacy-first architecture, direct personal phone numbers and personal email addresses are NEVER publicly rendered in the National Entrepreneur Directory. Public trade inquiries and buyer RFPs are routed exclusively through the verified, encrypted on-page enquiry modal, protecting our members against data scraping, unsolicited spam, and identity compromise.
3. Lawful Grounds for Processing
We process your data strictly under valid lawful grounds recognized under Section 4 of the DPDP Act 2023:
- Explicit Consent: Granted by you during account onboarding and business portfolio submission.
- Contractual Necessity: Required to fulfill our annual membership obligations, issue valid receipts, and manage your verified directory profile.
- Legal Compliance: Fulfilling statutory records retention under Indian tax, corporate, and cybersecurity laws.
4. Data Security Architecture & Server Perimeter
The EDCI portal operates an institutional-grade, multi-layered defensive perimeter:
- Transport Layer Security: Enforced HTTPS with 100% TLS 1.3 encryption and HTTP Strict Transport Security (HSTS).
- Server-Level Perimeter Hardening: Direct PHP execution in media uploads directories is blocked at the web server layer via root and upload .htaccess rules.
- Cache Isolation: Authenticated member sessions, checkout, and dashboard endpoints emit strict no-cache control headers (
litespeed_control_set_nocache), preventing data leakage into public CDN or server caches. - Atomic Webhook Concurrency Locks: Dedicated MariaDB locking table (
wp_edci_webhook_locks) guarantees idempotency and eliminates race conditions during payment gateway callbacks.
5. Rights of Data Principals under DPDP Act 2023
As a registered entrepreneur or portal user, you possess fundamental statutory rights:
- Right of Access & Summary: You may request a complete summary of your personal data processed by EDCI.
- Right to Correction & Updating: You may update inaccurate or obsolete business information anytime via your Logged-in Dashboard.
- Right to Erasure & Account Closure: You may request account deactivation and data erasure, subject to mandatory statutory financial retention requirements.
- Right of Grievance Redressal: Direct access to the Council Grievance Officer with guaranteed resolution within 15 calendar days.
6. Data Retention Policy
Active member records are retained for the duration of membership plus 3 years of inactivity. Financial transaction logs and WooCommerce order histories are retained for 8 years in accordance with Section 128 of the Indian Companies Act and statutory GST compliance requirements. Unsuccessful registration drafts and temporary OTP transients are purged automatically within 10 minutes.
7. Data Protection Desk & Grievance Contact
Data Protection & Grievance Officer
Council Secretariat: Entrepreneurship Development Council of India (EDCI)
Registered Address: Lake View Ansals Apartment, Shyamla Hills, Bhopal, Madhya Pradesh 462013, India
Privacy & Data Desk Email: privacy@edci.in
Statutory Grievance Email: grievance@edci.in
Resolution Turnaround SLA: Acknowledged within 24–48 hours; resolved within 15 calendar days.
Questions Regarding Council Policies or Statutory Compliance?
Our National Secretariat and statutory desks are available to address your inquiries within 24–48 business hours.