Skip to main content
DATA GOVERNANCE · DPDP FRAMEWORK

Privacy Policy

How The Haldankar Method collects, processes, protects, and manages digital personal data in accordance with the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.

EFFECTIVE DATE: 14 August 2026
LAST UPDATED: 14 August 2026
DATA FIDUCIARY: Suraj Rohit Haldankar
01 / SECTION

Scope & Data Fiduciary Identity

This Privacy Policy applies to digital personal data processed through The Haldankar Method website (the “Website”), our research inquiry interfaces, direct email channels, and intellectual publishing workflows.

Under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Data Fiduciary responsible for determining the purpose and means of processing personal data is:

Suraj Rohit Haldankar
Independent Researcher, Author, and Creator of The Haldankar Method
Designated Privacy Dispatch: contact@haldankarmethod.com

02 / SECTION

Personal Data We Process

We adhere strictly to data minimization principles. We process personal data only when voluntarily provided by you or generated through standard network protocols:

  • Identity Data: Full name and institutional title or affiliation (when submitting research collaboration inquiries).
  • Contact Details: Email address provided for communication dispatch.
  • Inquiry Specifications: Selected inquiry topic (e.g., Research Collaboration, Institutional Research, Information Architecture Review, Decision-System Design, Speaking & Lectures) and message content.
  • Technical Telemetry: Standard server access telemetry automatically generated during web requests (IP address, browser User-Agent, and HTTP request timestamps) processed transiently for server integrity and DDoS mitigation.
03 / SECTION

How Personal Data is Collected

We collect personal data directly from you through the following specific points:

  • Collaboration Inquiry Form: When you complete the dispatch interface on our homepage or research briefs.
  • Direct Email Correspondence: When you transmit academic or institutional inquiries directly to contact@haldankarmethod.com.
  • Automated Hosting Protocols: Standard edge-network server logs generated upon accessing static web assets.
04 / SECTION

Specified Purposes of Processing

In accordance with Section 4 and Section 5 of the DPDP Act, personal data is processed solely for specific, legitimate, and clearly defined purposes:

  • Inquiry Evaluation & Response: Assessing, routing, and responding to academic collaboration proposals, institutional reviews, and speaking invitations.
  • Research Material Delivery: Transmitting requested monographs, white papers, or pre-release research briefs.
  • Platform Security & Fraud Prevention: Protecting web infrastructure against automated spam, denial-of-service attempts, and cyber threats.
  • Statutory Compliance: Complying with applicable legal, regulatory, and reporting obligations under Indian law.

We do not sell, rent, monetize, or broker personal information to commercial data brokers, advertising networks, or marketing aggregators.

05 / SECTION

Lawful Grounds for Processing (DPDP Act)

We process digital personal data under the following statutory grounds recognized by the DPDP Act 2023:

  • Certain Legitimate Uses (Section 7(a)): When you voluntarily provide personal data (name, email, message) for the specified purpose of seeking collaboration, asking questions, or requesting materials, and have not indicated non-consent.
  • Consent (Section 6): Where processing relies on affirmative consent accompanied by statutory notice under Section 5, which you provide when initiating formal correspondence.
  • Legal Obligations (Section 7(c)): Processing necessary to comply with any order, judgment, or decree issued under applicable law.
06 / SECTION

Cookies & Client-Side LocalStorage Notice

Zero Tracking Cookies: The Website does not use commercial tracking cookies, advertising beacons, behavioral analytics pixels, or third-party profiling identifiers.

We utilize browser localStorage (keys: haldankar_theme_v2 and thm_theme) solely to preserve your preferred visual contrast mode (Light Theme vs. True-Black Dark Theme) on your client device. This data is entirely functional, stored locally in your browser, and is never transmitted to our servers.

07 / SECTION

Service Processors & Third-Party Infrastructure

We engage trusted technical service providers necessary to operate the platform securely:

  • Form Relay Dispatch (Web3Forms): Contact form submissions are processed via Web3Forms API to securely route and deliver your message to our verified email inbox.
  • Web Hosting & Edge Delivery: Cloud hosting infrastructure and Content Delivery Networks (CDNs) deliver static assets and maintain server availability.
  • Typography Services (Google Fonts): Standard web fonts are delivered via Google Fonts edge caching servers.
08 / SECTION

External Platforms & Outbound Links

The Website contains links to external academic, code, and professional platforms, including Instagram, LinkedIn, GitHub, and ORCID.

When you navigate to an external platform, you leave our Website. We are not responsible for the privacy practices, cookie configurations, or terms of third-party platforms. We encourage you to review their respective privacy notices upon visiting.

09 / SECTION

Books, Publications & External Distribution

The Website showcases published and forthcoming books such as Architecture of Decision and Why Good People Struggle and Fail.

We do not collect payment card information, store billing addresses, or execute e-commerce checkout transactions on-site. When you purchase physical or digital book editions via third-party merchants (such as Amazon or external retail distributors), all transactions, payments, shipping, and tax processing are governed exclusively by the merchant's privacy policy.

10 / SECTION

Data Retention & Purpose-Based Erasure Schedule

Under Section 8(7) of the DPDP Act, personal data is retained only for as long as is reasonably necessary to fulfill the specific purpose for which it was collected:

  • Active Collaboration Inquiries: Retained for the duration of active project evaluation and collaborative correspondence, plus 180 days following completion.
  • General Reader Inquiries: Retained for 90 days following final reply, after which correspondence is archived or securely deleted.
  • Server Telemetry Logs: Automatically rotated and erased on a rolling 30 to 90-day cycle.

When the retention window expires or upon receiving a valid erasure request, personal data is permanently deleted or irreversibly anonymized.

11 / SECTION

Technical & Organizational Security Safeguards

In accordance with Section 8(5) of the DPDP Act, we implement reasonable technical and organizational security measures to prevent personal data breaches:

  • Encrypted Transit: Enforced HTTPS/TLS 1.3 encryption across all website pages and API transmission channels.
  • Access Control: Strict authentication controls and access restrictions governing administrative email accounts.
  • API Key Isolation: Hardened API tokens and client-side input validation to prevent unauthorized transmission.
12 / SECTION

Personal Data Breach Protocol

In the unlikely event of a personal data breach affecting digital personal data processed by the platform, we maintain an internal incident response protocol.

Under Section 8(6) of the DPDP Act and the relevant implementing rules, upon confirming a personal data breach, the Data Fiduciary shall intimate the Data Protection Board of India and each affected Data Principal in the form and manner prescribed by statutory regulations.

13 / SECTION

Statutory Rights of Data Principals

Under Chapter III (Sections 11–14) of the DPDP Act, 2023, you have the following enforceable rights as a Data Principal:

  • Right to Access Information (Section 11): The right to obtain confirmation of processing, a summary of personal data being processed, and the identities of any Data Fiduciaries or Processors with whom data has been shared.
  • Right to Correction & Erasure (Section 12): The right to request correction of inaccurate or misleading data, completion of incomplete data, updating of obsolete data, and erasure of personal data that is no longer necessary for the specified purpose.
  • Right of Grievance Redressal (Section 13): The right to have readily available means of grievance redressal regarding any act or omission of the Data Fiduciary.
  • Right to Nominate (Section 14): The right to nominate an individual who, in the event of death or incapacity, shall exercise the rights of the Data Principal.
  • Right to Withdraw Consent (Section 6(4)): The right to withdraw previously given consent at any time, with ease comparable to giving consent.
14 / SECTION

How to Exercise Your Rights

To exercise any of your statutory rights under the DPDP Act, please email our designated privacy correspondence channel:

Data Principal Rights Request
Email: contact@haldankarmethod.com
Subject Line: Data Principal Request — [Access / Correction / Erasure / Withdrawal]

We will verify your identity before processing the request to ensure personal data is protected against unauthorized access. Requests are processed without fee within the statutory response window.

15 / SECTION

Privacy Inquiries & Grievance Redressal Mechanism

In accordance with Section 13 of the DPDP Act and the DPDP Rules, 2025, if you have any questions, concerns, or grievances regarding our data practices:

The Haldankar Method — Grievance Redressal
Attention: Suraj Rohit Haldankar (Data Fiduciary)
Email: contact@haldankarmethod.com
Acknowledgement Window: Within 48 hours of receipt.
Resolution Period: Within 30 days of receipt.

If a grievance remains unresolved after exhausting our internal grievance redressal mechanism, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP framework.

16 / SECTION

Children's Privacy Notice

The Website is an independent academic and intellectual research platform intended for adult researchers, practitioners, and reflective readers. In accordance with Section 9 of the DPDP Act:

  • We do not knowingly collect personal data from individuals under the age of eighteen (18).
  • We do not conduct tracking, behavioral monitoring, or targeted profiling directed at children.

If we become aware that personal data of a minor has been inadvertently submitted without verified parental or legal guardian consent, we will take immediate steps to delete that data.

17 / SECTION

Cross-Border Data Processing

Under Section 16 of the DPDP Act, personal data may be transferred outside India subject to any restrictions or blacklists notified by the Central Government.

Because our platform utilizes global cloud infrastructure (such as form dispatch APIs and edge content delivery networks), information you voluntarily submit may transit servers located in jurisdictions outside India. All such transfers are conducted under secure transmission protocols (TLS encryption) for the sole purpose of delivering website functionality and fulfilling inquiry dispatch.

18 / SECTION

Revisions & Policy Updates

We may update this Privacy Policy from time to time to reflect operational modifications, technological updates, or statutory enactments under the DPDP framework.

All revisions are effective upon posting to this page, and the “Last Updated” timestamp at the top of the document will indicate the effective revision date.

19 / SECTION

Official Contact Details & Effective Date

For all formal privacy correspondence, data protection inquiries, or statutory notices, please contact:

The Haldankar Method — Privacy Office
Attention: Suraj Rohit Haldankar
Email: contact@haldankarmethod.com
Effective Date: 14 August 2026
Last Updated: 14 August 2026

The Haldankar Method · Data Governance Framework
Home Terms of Service Contact