loader image

Privacy Policy

  • Introduction 

Bisani GCC Center (“Firm”), having its principal office at 5/5, 3rd Floor, 4th Cross, Jayanagar 7th Block, Bengaluru – 560070, is the Data Fiduciary for personal data covered by this Policy. This Policy explains how we collect, use, share, protect, retain and erase personal data through www.bisanigcccenter.com (“Website”). It is a notice, not a contract. Browsing the Website does not constitute consent. Where consent is required, it will be obtained separately through clear affirmative action. This Policy applies only to the Website. Personal data received during client engagements is governed by applicable engagement terms, advocates’ confidentiality obligations and professional privilege under Section 132 of the Bharatiya Sakshya Adhiniyam, 2023.

  • The Scope 

This Policy is drafted to the standard of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), notified on 13 November 2025 and taking effect in phases, with the remaining substantive obligations commencing by 13 May 2027. Until those obligations commence, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to apply, and we comply with both.  The Terms not defined here carry the meanings given in the DPDP Act and the DPDP Rules.

You are a “Data Principal” under the DPDP Act. We have chosen to operate this Website to the DPDP standard ahead of the final compliance date.

  • Data Collection

We collect only the personal data listed below, and only when you choose to provide it or when it is generated by your use of the Website.

  • Enquiry data: name, designation, organization, postal address, telephone number, email address and the content of your enquiry, when you write to us or use a contact form.
  • Career and internship application data: your curriculum vitae, qualifications, experience and the position you are interested in, when you apply to the Firm.
  • Newsletter data: name and email address, when you subscribe to our updates.
  • Technical data: IP address, browser and device information, and pages visited, generated through cookies and similar technologies as described in Section 6.

We do not collect financial account data, government identifiers or biometric data through the Website, and the Website is not directed at the age group below eighteen years. 

  • Objective 

Every category of personal data is processed for a specified purpose and on a legal basis recognized by the DPDP Act, your consent under Section 6, or a legitimate use under Section 7, including Section 7(a), which covers personal data you voluntarily provide to us for a purpose you have indicated. We do not use your personal data for behavioral advertising, we do not sell or rent personal data, and we do not use it for any purpose incompatible with the purposes above.

  • How Consent Works?

Where we rely on consent, it is free, specific, informed, unconditional and unambiguous, and is given through a clear affirmative action such as ticking an unticked box or clicking subscribe. A notice accompanies every consent request, in clear and plain language, describing the personal data sought, the purpose, the manner of exercising your rights and withdrawing consent, and the manner of complaining to the Data Protection Board of India. On request, the notice is available in English and in the languages specified in the Eighth Schedule to the Constitution.

You may withdraw consent at any time, with the same ease with which you gave it: use the unsubscribe link in any newsletter, or write to the Grievance Officer (Section 15). Withdrawal operates prospectively; it does not affect the lawfulness of processing already carried out. On withdrawal we will stop the processing concerned, and cause our Data Processors to stop, within a reasonable time, unless retention is required by law.

  • Cookies 

The Website uses a small number of cookies. Strictly necessary cookies enable core functions such as security and load balancing and do not require consent. Analytics or preference cookies, if deployed, are set only with your consent through the cookie banner, and can be declined or withdrawn there without affecting your use of the Website. You can also control cookies through your browser settings.

  1. Sharing of personal data

We share personal data only as follows, and never by way of sale or rent:

  • Within the Firm, on a need-to-know basis, to respond to your enquiry or application.
  • With Data Processors: providers of IT infrastructure, hosting, email and similar support services, who process personal data on our instructions under written contracts imposing security safeguards consistent with the DPDP Rules and requiring erasure when the engagement ends.
  • With professional collaborators, such as counsel, company secretaries or chartered accountants, where your enquiry becomes a matter that requires them, and always under obligations of confidentiality.
  • Where the law requires it: in response to a legal obligation, court order or lawful demand of a competent authority, in strict compliance with applicable law.
  1. Cross-border transfers

Some of our service providers may store or process personal data on servers located outside India. Under Section 16 of the DPDP Act, transfers are permitted to any country other than those restricted by the Central Government by notification, and are subject to any conditions the Government specifies. Where personal data leaves India, it remains protected by this Policy and by our contracts with the recipients.

  1. Security safeguards

We apply reasonable security safeguards aligned to Rule 6 of the DPDP Rules to prevent personal data breach, including: encryption of data in transit and, where appropriate, at rest; access controls limiting personal data to personnel who need it; logging and monitoring to enable detection, investigation and remediation of unauthorised access, with logs retained for at least one year; data backups to maintain continuity; and contractual security obligations on every Data Processor. These measures are reviewed periodically against the nature of the data we hold.

  1. Personal data breach

If a personal data breach occurs, we will inform each affected Data Principal without delay, in clear and plain language, describing the breach, its nature, extent, timing and likely consequences, the measures we are taking, the steps you can take to protect yourself, and the contact details of a person who can answer your questions. We will also intimate the Data Protection Board of India in the manner and within the timelines prescribed under Rule 7 of the DPDP Rules, including the detailed report within seventy two hours, once those obligations are in force, and we will comply with the incident reporting directions issued by CERT-In under the Information Technology Act, 2000.

  1. Retention and erasure

We retain personal data only for as long as it is necessary for the specified purpose, and thereafter only where retention is required by law, including limitation periods, taxation requirements and the professional record-keeping obligations of advocates. When neither the purpose nor a legal requirement supports retention, we erase the personal data or irreversibly anonymise it, and we cause our Data Processors to do the same.

  • Enquiry data: erased within [24 months] of the enquiry closing, unless it has become part of a client matter.
  • Application data: erased within [12 months] of the position closing, unless you consent to a longer talent-pool retention.
  • Newsletter data: retained until you unsubscribe, then removed from the mailing list.
  • Security logs: retained for at least one year, in line with Rule 6 of the DPDP Rules.
  1. Children

The Website and our services are directed at adults. We do not knowingly collect personal data of persons under eighteen years of age, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided personal data to us, write to the Grievance Officer and we will erase it.

  1. Your rights as a Data Principal
  • Access (Section 11): obtain a summary of the personal data we process about you, the processing activities, and the identities of the Data Fiduciaries and Data Processors with whom it has been shared, with a description of what was shared.
  • Correction, completion, updating and erasure (Section 12): have inaccurate data corrected, incomplete data completed, outdated data updated, and personal data erased where retention is no longer necessary for the purpose or required by law.
  • Grievance redressal (Section 13): a readily available means of registering grievances with us, answered within the timelines in this Section.
  • Nomination (Section 14): nominate another individual to exercise your rights in the event of your death or incapacity.
  • Withdrawal of consent (Section 6): as described in Section 5.

HOW TO EXERCISE THESE RIGHTS

Write to the Grievance Officer at the contact details in Section 15, stating the right you wish to exercise and quoting the email address or telephone number you used on the Website so that we can locate and verify your record. We may seek information reasonably necessary to verify your identity, and we will act only on verified requests. We will acknowledge your request within [7 days] and respond within [30 days], and in every case within the ninety day outer limit prescribed under the DPDP Rules.

If you are not satisfied with our response, or receive none within the stated period, you may complain to the Data Protection Board of India through its online portal, after first exhausting this grievance process as the DPDP Act requires. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal.

  1. Your duties

The DPDP Act also places duties on Data Principals. When dealing with us, you must not impersonate another person, must not suppress material information or furnish false particulars, must not register a false or frivolous grievance, and should provide only information that is authentic when exercising your right to correction or erasure.

  1. Grievance Officer and contact

Grievance Officer: [Saket Bisani, Advocate: confirm designation]

Bisani Legal, Advocates and Legal Consultants, 5/5, 3rd Floor, 4th Cross, Jayanagar 7th Block, Bengaluru 560070

Email: contact@bisanilegal.com, with escalation to saket@bisanilegal.com

The Grievance Officer is the person to whom questions about this Policy and about our processing of personal data may be addressed, and their details appear prominently on the Website as the DPDP Rules require.

  1. Changes to this Policy

We may revise this Policy to reflect changes in law, technology or our practices, including as the remaining DPDP obligations commence. The current version, its number and its effective date will always appear on this page, and material changes will be highlighted on the Website. Where a change requires fresh consent, we will seek it; continued browsing is never treated as consent.


Cookie Consent with Real Cookie Banner