Bisani GCC Center (“Firm”), having its principal office at 5/5, 3rd Floor, 4th Cross, Jayanagar 7th Block, Bengaluru – 560070, is the Data Fiduciary for personal data covered by this Policy. This Policy explains how we collect, use, share, protect, retain and erase personal data through www.bisanigcccenter.com (“Website”). It is a notice, not a contract. Browsing the Website does not constitute consent. Where consent is required, it will be obtained separately through clear affirmative action. This Policy applies only to the Website. Personal data received during client engagements is governed by applicable engagement terms, advocates’ confidentiality obligations and professional privilege under Section 132 of the Bharatiya Sakshya Adhiniyam, 2023.
This Policy is drafted to the standard of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), notified on 13 November 2025 and taking effect in phases, with the remaining substantive obligations commencing by 13 May 2027. Until those obligations commence, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to apply, and we comply with both. The Terms not defined here carry the meanings given in the DPDP Act and the DPDP Rules.
You are a “Data Principal” under the DPDP Act. We have chosen to operate this Website to the DPDP standard ahead of the final compliance date.
We collect only the personal data listed below, and only when you choose to provide it or when it is generated by your use of the Website.
We do not collect financial account data, government identifiers or biometric data through the Website, and the Website is not directed at the age group below eighteen years.
Every category of personal data is processed for a specified purpose and on a legal basis recognized by the DPDP Act, your consent under Section 6, or a legitimate use under Section 7, including Section 7(a), which covers personal data you voluntarily provide to us for a purpose you have indicated. We do not use your personal data for behavioral advertising, we do not sell or rent personal data, and we do not use it for any purpose incompatible with the purposes above.
Where we rely on consent, it is free, specific, informed, unconditional and unambiguous, and is given through a clear affirmative action such as ticking an unticked box or clicking subscribe. A notice accompanies every consent request, in clear and plain language, describing the personal data sought, the purpose, the manner of exercising your rights and withdrawing consent, and the manner of complaining to the Data Protection Board of India. On request, the notice is available in English and in the languages specified in the Eighth Schedule to the Constitution.
You may withdraw consent at any time, with the same ease with which you gave it: use the unsubscribe link in any newsletter, or write to the Grievance Officer (Section 15). Withdrawal operates prospectively; it does not affect the lawfulness of processing already carried out. On withdrawal we will stop the processing concerned, and cause our Data Processors to stop, within a reasonable time, unless retention is required by law.
The Website uses a small number of cookies. Strictly necessary cookies enable core functions such as security and load balancing and do not require consent. Analytics or preference cookies, if deployed, are set only with your consent through the cookie banner, and can be declined or withdrawn there without affecting your use of the Website. You can also control cookies through your browser settings.
We share personal data only as follows, and never by way of sale or rent:
Some of our service providers may store or process personal data on servers located outside India. Under Section 16 of the DPDP Act, transfers are permitted to any country other than those restricted by the Central Government by notification, and are subject to any conditions the Government specifies. Where personal data leaves India, it remains protected by this Policy and by our contracts with the recipients.
We apply reasonable security safeguards aligned to Rule 6 of the DPDP Rules to prevent personal data breach, including: encryption of data in transit and, where appropriate, at rest; access controls limiting personal data to personnel who need it; logging and monitoring to enable detection, investigation and remediation of unauthorised access, with logs retained for at least one year; data backups to maintain continuity; and contractual security obligations on every Data Processor. These measures are reviewed periodically against the nature of the data we hold.
If a personal data breach occurs, we will inform each affected Data Principal without delay, in clear and plain language, describing the breach, its nature, extent, timing and likely consequences, the measures we are taking, the steps you can take to protect yourself, and the contact details of a person who can answer your questions. We will also intimate the Data Protection Board of India in the manner and within the timelines prescribed under Rule 7 of the DPDP Rules, including the detailed report within seventy two hours, once those obligations are in force, and we will comply with the incident reporting directions issued by CERT-In under the Information Technology Act, 2000.
We retain personal data only for as long as it is necessary for the specified purpose, and thereafter only where retention is required by law, including limitation periods, taxation requirements and the professional record-keeping obligations of advocates. When neither the purpose nor a legal requirement supports retention, we erase the personal data or irreversibly anonymise it, and we cause our Data Processors to do the same.
The Website and our services are directed at adults. We do not knowingly collect personal data of persons under eighteen years of age, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided personal data to us, write to the Grievance Officer and we will erase it.
HOW TO EXERCISE THESE RIGHTS
Write to the Grievance Officer at the contact details in Section 15, stating the right you wish to exercise and quoting the email address or telephone number you used on the Website so that we can locate and verify your record. We may seek information reasonably necessary to verify your identity, and we will act only on verified requests. We will acknowledge your request within [7 days] and respond within [30 days], and in every case within the ninety day outer limit prescribed under the DPDP Rules.
If you are not satisfied with our response, or receive none within the stated period, you may complain to the Data Protection Board of India through its online portal, after first exhausting this grievance process as the DPDP Act requires. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal.
The DPDP Act also places duties on Data Principals. When dealing with us, you must not impersonate another person, must not suppress material information or furnish false particulars, must not register a false or frivolous grievance, and should provide only information that is authentic when exercising your right to correction or erasure.
Grievance Officer: [Saket Bisani, Advocate: confirm designation]
Bisani Legal, Advocates and Legal Consultants, 5/5, 3rd Floor, 4th Cross, Jayanagar 7th Block, Bengaluru 560070
Email: contact@bisanilegal.com, with escalation to saket@bisanilegal.com
The Grievance Officer is the person to whom questions about this Policy and about our processing of personal data may be addressed, and their details appear prominently on the Website as the DPDP Rules require.
We may revise this Policy to reflect changes in law, technology or our practices, including as the remaining DPDP obligations commence. The current version, its number and its effective date will always appear on this page, and material changes will be highlighted on the Website. Where a change requires fresh consent, we will seek it; continued browsing is never treated as consent.