Statutory Legal Framework

    Privacy Policy & Data Protection Charter

    Effective Date: August 2026•Governing Law: DPDP Act 2023 & Companies Act 2013•Data Sovereignty: Republic of India
    1

    Introduction & Statutory Scope

    Welcome to Vote India Secure (accessible at https://www.shareholdervoting.in). We are dedicated to providing enterprise-grade, cryptographically secure electronic voting software tailored for Indian corporate governance.

    This Privacy Policy & Data Protection Charter governs the manner in which Vote India Secure collects, receives, processes, stores, protects, and de-identifies personal data and financial identifiers during shareholder voting sessions, Annual General Meetings (AGMs), Extraordinary General Meetings (EGMs), and postal ballots.

    Primary Statutory Compliance Anchors:
    • Digital Personal Data Protection Act, 2023 (DPDP Act) — Enacted by the Parliament of India.
    • Section 108 of the Companies Act, 2013 read with Rule 20 of the Companies (Management and Administration) Rules, 2014.
    • Regulation 44 of SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015.
    • Information Technology Act, 2000 & the SPDI Rules, 2011.
    • CERT-In Directions (April 2022) on cybersecurity log retention and incident management.
    2

    Data Roles: Data Fiduciary vs. Data Processor

    Under the statutory nomenclature of the DPDP Act 2023 and Indian corporate law, responsibilities are clearly partitioned:

    The Issuing Company (Data Fiduciary)

    The listed entity, corporate enterprise, or investment trust convening the general meeting acts as the Data Fiduciary. The company determines the purpose and means of processing shareholder records in fulfilment of its statutory AGM obligations under Section 108.

    Vote India Secure (Data Processor)

    Vote India Secure operates as a secure technology provider and Data Processor engaged by the Data Fiduciary. We process shareholder and meeting data strictly in accordance with statutory mandates, contractual data processing agreements (DPAs), and documented instructions.

    Individual shareholders whose records are processed are classified as Data Principals under Indian law.

    3

    Categories of Personal Data Collected

    In accordance with the principle of Data Minimisation under the DPDP Act 2023, Vote India Secure only processes information strictly required to establish voter eligibility, authenticate identity, and calculate weighted voting power:

    A. Depository & Shareholder Identification Data

    Permanent Account Number (PAN), Depository Participant ID (DP ID), Client ID (16-digit demat account number for NSDL/CDSL), Physical Folio Numbers, and legal entity names as provided by the RTA Benpos record.

    B. Entitlement & Holding Quantities

    Total number of equity/preference shares held as on the statutory Record Cut-Off Date, corresponding weighted voting rights, and share classification (Ordinary, Special Voting Rights).

    C. Contact & Authentication Metadata

    Registered email addresses and mobile telephone numbers used solely for delivering one-time voting credentials, meeting notices, and 2-Factor OTP verification tokens.

    D. Cryptographic Balloting Records

    Timestamped ballot submissions cryptographically encrypted with AES-256 and chained into a SHA-256 Merkle audit proof. Individual voter selections remain decoupled from voter identity until official scrutinizer unblocking.

    E. Technical Telemetry & Statutory Audit Logs

    IP addresses, browser user-agents, network port headers, session identifiers, and time-stamped activity logs recorded in compliance with CERT-In directions and Rule 20 audit mandates.

    4

    Legal Grounds & Purposes for Processing

    Personal data is processed on the basis of Statutory Obligation and Legitimate Uses under Section 7 of the DPDP Act 2023 and Section 108 of the Companies Act 2013 for the following exclusive purposes:

    • Shareholder Verification: Cross-referencing voter identity against depository Benpos rosters to prevent unauthorized ballot submissions and proxy fraud.
    • Ballot Tabulation: Calculating voting outcomes weighted by shareholding volume (Assent / Dissent / Abstain).
    • Scrutinizer Audit & Form MGT-13: Generating official scrutinizer audit packages for stock exchange disclosure and MCA corporate filings.
    • Dispute Resolution & Meeting Regularity: Providing mathematical proof of quorum and non-repudiation in corporate judicial proceedings before the NCLT.
    Explicit Non-Commercial Guarantee: Vote India Secure strictly prohibits the sale, rental, profiling, advertising, or commercial monetisation of personal or financial voter data.
    5

    Cryptographic Ballot Secrecy & De-identification

    Under Rule 20(4)(xii) of the Companies Rules, the register of votes cast cannot be accessed by the company, board of directors, management, or system administrators before the conclusion of voting at the general meeting.

    Architectural Ballot Decoupling

    When a shareholder casts their vote, the ballot payload is encrypted using AES-256 Galois/Counter Mode (GCM) and linked to a unique cryptographic receipt ID. The voter's identity is decoupled from their chosen resolution stance within the live database.

    The electronic vault containing encrypted tallies can only be unblocked post-meeting by the designated independent Scrutinizer in the presence of at least two independent witnesses through multi-party authorization keys.

    6

    Handling of PAN, DP ID & Demat Records

    Permanent Account Number (PAN) and Demat Account numbers (DP ID / Client ID) are treated as Sensitive Financial Identifiers:

    • Zero Plain-Text Transmission: All demographic credentials transmitted over the public internet are encrypted using TLS 1.3 with Perfect Forward Secrecy.
    • One-Way Hash Masking: Sensitive identifiers are stored in salted, one-way hashed formats (SHA-256 / Argon2id) for audit cross-referencing.
    • No Permanent Storage of Ephemeral Tokens: 2FA OTP tokens expire automatically within 5 minutes and are purged from active memory upon successful verification.
    7

    Sovereign Data Residency (India Only)

    In compliance with national data sovereignty standards and CERT-In cyber frameworks:

    100% In-Country Infrastructure

    All primary database clusters, backup archives, application nodes, and audit logs are physically hosted inside sovereign Tier-4 data centers located in Mumbai and Bengaluru, India.

    Zero voter records or personal demat identifiers are routed, transferred, or stored in foreign jurisdictions.

    8

    Technical & Organizational Safeguards

    Our multi-layered defense-in-depth architecture enforces the highest enterprise security standards:

    PostgreSQL Row-Level Security (RLS)

    Granular database policies guarantee strict tenant isolation between disparate corporate issuers.

    Rate Limiting & Anti-Brute Force

    Automated IP throttling and progressive delays protect voter login endpoints from dictionary attacks.

    Continuous Integrity Checks

    SHA-256 Merkle tree verification ensures zero undetected tampering across all recorded ballots.

    DDoS Mitigation & WAF

    Edge-level Web Application Firewall filtering with automated bot traffic suppression.

    9

    Data Retention & Cryptographic Disposal

    Data retention timelines are strictly aligned with Indian statutory preservation mandates:

    • Meeting Register & Scrutinizer Audit Trail: Retained for the statutory duration mandated under Section 128 of the Companies Act 2013 (up to 8 financial years for company records) or until hand-over to the Chairman / Scrutinizer.
    • Cybersecurity Telemetry & System Logs: Retained for 180 calendar days as required by CERT-In Directions under the IT Act.
    • Cryptographic Disposal: Upon expiry of the statutory retention window and written confirmation from the Data Fiduciary, voter rosters and session data are cryptographically wiped using multi-pass overwrites.
    10

    Rights of Data Principals (DPDP Act 2023)

    Under Chapter III of the DPDP Act 2023, shareholders (Data Principals) possess the following enforceable rights:

    Right to Access Information (Section 11): Request a summary of personal data processed and identities of Data Fiduciaries with whom data has been shared.
    Right to Correction & Updation (Section 12): Request correction of inaccurate demographic data. (Note: Official depository records must be updated directly via your DP / RTA).
    Right to Nominate (Section 14): Nominate any individual to exercise data principal rights in the event of death or incapacity.
    Right of Grievance Redressal (Section 13): Access an easy and prompt grievance resolution mechanism with our Data Protection Officer.
    11

    Third-Party Sharing & Statutory Disclosures

    Vote India Secure only shares or discloses data to authorized third parties under strict statutory and operational necessity:

    • Appointed Scrutinizers: Delivery of encrypted tallies, register logs, and Form MGT-13 reports to the independent Practising Company Secretary (PCS) appointed under Rule 20.
    • Regulatory & Judicial Bodies: Compliance with lawful orders issued by SEBI, MCA, NCLT, or law enforcement agencies.
    • Transactional Communication Infrastructure: SMS gateways (DLT-registered in India under TRAI regulations) and email gateways for delivery of 2FA OTPs and statutory voting confirmation receipts.
    12

    Cookies, Telemetry & CERT-In Audit Logs

    We maintain a strict cookie and session posture:

    Strictly Necessary Cookies: We only utilize essential, encrypted HTTP-only session cookies required for maintaining authenticated states during live voting. We do not deploy third-party advertising cookies or cross-site tracking pixels.

    CERT-In Security Compliance: As required by the Indian Computer Emergency Response Team (CERT-In), system logs containing IP addresses, DNS queries, and time synchronisation (NTP) data are preserved securely for 180 days to enable cybersecurity forensic audits.

    13

    Data Protection Officer & Grievance Redressal

    In accordance with Section 13 of the DPDP Act 2023 and Rule 5(9) of the SPDI Rules, any Data Principal may direct privacy inquiries, rights enforcement requests, or grievances to our designated Grievance Officer:

    Data Protection & Grievance Redressal Officer
    Officer Name:Legal & Privacy Compliance Desk
    Designation:Data Protection Officer (DPO)
    Operations Office:Corporate Governance & Cloud Operations Support Desk, India

    Grievance Resolution Timeline: We acknowledge all grievances within 48 hours and provide substantive resolution within 30 calendar days. If unsatisfied, Data Principals may escalate to the Data Protection Board of India (DPBI).

    14

    Amendments & Regulatory Notifications

    Vote India Secure reserves the right to amend this Privacy Policy periodically to reflect technological enhancements, statutory revisions under the DPDP Act rules, SEBI circulars, or MCA notifications.

    Any material changes impacting shareholder data processing will be notified on our website and reflected in the updated Effective Date at the top of this document.