Global NOC/SOC: Operational (24/7/365) | DPDPA 2023 Statutory Policy
DIGITAL PERSONAL DATA PROTECTION ACT, 2023 (INDIA)

Enterprise Privacy Policy

BitQube Technologies is committed to safeguarding the digital sovereignty and privacy of our Data Principals. This policy details our data processing practices, statutory legal bases, security safeguards, and grievance redressal mechanisms.

Version: 2.4 (October 2025)
Data Fiduciary: BitQube Technologies
Contact Grievance Officer

1. Corporate Identity, Legal Governance & Statutory Scope

This Enterprise Privacy Policy is published, administered, and maintained by BitQube Technologies (together with its operating corporate entities, branches, and affiliates, hereinafter collectively referred to as “BitQube”, “Company”, “we”, “us”, or “our”), a corporate entity organized and operating under the laws of the Republic of India.

CORPORATE JURISDICTION Republic of India
Statutory corporate registration and governance records maintained in accordance with applicable laws of India.
PRINCIPAL OPERATING CENTERS Hyderabad (Telangana) • Bengaluru (Karnataka), India
Supported by 24/7/365 remote Network & Security Operations Centers (NOC/SOC) serving enterprise clients worldwide.

Under India’s Digital Personal Data Protection Act, 2023 (“DPDPA”) and international data privacy benchmarks:

  • BitQube as Data Fiduciary (Section 2(i) DPDPA): We determine the purpose and means of processing digital personal data collected directly through our official corporate portal (bitqube.net), commercial consultation requests, enterprise procurement channels, candidate recruitment, and direct business correspondences.
  • BitQube as Data Processor (Section 2(k) DPDPA): Where BitQube provisions managed infrastructure, 24/7 cyber defense (MSSP), cloud migration, structured campus networks, or enterprise ERP hosting on behalf of client institutions (such as schools, universities, hospitals, or enterprises), BitQube acts strictly as a Data Processor under binding contractual obligations, and the contracting client organization serves as the Data Fiduciary.

2. Categories of Digital Personal Data Collected

In accordance with the principle of data minimization (processing only what is necessary), we collect and process the following categories of personal data:

Inquiry & Profile Data
  • Full name and job designation
  • Corporate email address
  • Telephone / mobile number
  • Company name and industry sector
  • Infrastructure scope & requirements
Technical & Telemetry Data
  • Internet Protocol (IP) address
  • Browser type, version & OS
  • Session timestamps and latency
  • URL referral strings
  • Cryptographic security tokens
Client Engagement Data
  • Service Level Agreement (SLA) records
  • Ticketing support chat history
  • Non-Disclosure Agreements (NDA)
  • Audit logs and authorized user IDs

3. Lawful Grounds for Processing under DPDPA

BitQube strictly processes digital personal data based on recognized statutory grounds provided in the DPDPA:

  • Consent (Section 6, DPDPA): When you submit a consultation request, request a callback, or opt in to performance cookies, you provide affirmative, informed consent. You retain the right to withdraw this consent at any time.
  • Certain Legitimate Uses (Section 7, DPDPA): Processing necessary for:
    • Responding to a service request initiated voluntarily by the Data Principal.
    • Complying with statutory reporting requirements or court orders issued in India.
    • Protecting system infrastructure from cybersecurity threats, DDoS attacks, or fraud under the Information Technology Act, 2000.

4. Itemized Purpose Notice (Section 5 DPDPA)

As required by Section 5 of the Act, personal data is processed exclusively for specified, lawful purposes:

Specific Purpose Data Category Used Legal Basis
Providing architectural assessments & quotes Name, Corporate Email, Phone, Company, Scope Consent (Sec 6) / Voluntary Request (Sec 7)
24/7 Remote NOC/SOC Monitoring & Incident Alerts Authorized contact emails, IP logs, incident notes Contractual Obligation / Legitimate Use
Platform Security, Firewall & DDoS Defense IP addresses, user-agent, session headers Cybersecurity Defense (Sec 7)
UI Customization (Dark/Light mode & settings) Local storage tokens (bitqube-theme) Consent (Sec 6)

5. Special Provisions for Children’s & Educational Data

Under Section 9 of the DPDPA, Data Fiduciaries must observe heightened obligations regarding children (defined as individuals under 18 years of age):

Educational Campuses & Student ERP Hosting

When BitQube provisions school ERP systems, student portals, and smart campus networks, we operate as a Data Processor. We enforce strict contractual safeguards: we do not conduct behavioral tracking, targeted advertising, or profile profiling of children, and we ensure that parental/guardian verification is administered by the respective school or university in accordance with DPDPA guidelines.

6. Cross-Border Transfers of Personal Data

Under Section 16 of the DPDPA, digital personal data may be transferred outside India for processing, subject to restrictions issued by the Central Government. BitQube hosts production databases primarily within India-based Tier-3 data centers (AWS Mumbai/Hyderabad, Microsoft Azure Central/South India). Where cross-border transmission occurs for global OEM support or cloud synchronization, it is governed by standard contractual clauses, ISO 27001 controls, and encryption standards.

7. Technical & Organizational Safeguards (SOC Operations)

Under Section 8(5) of the DPDPA, Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches:

Cryptographic Standards
Data in transit is secured via TLS 1.3 encryption. Stored backups and client records are encrypted using AES-256 with hardware security module (HSM) key rotation.
Zero-Trust Architecture
Role-based access controls (RBAC), multi-factor authentication (MFA), network micro-segmentation, and continuous 24/7 SOC log analysis.

8. Data Retention & Erasure Schedule

Under Section 8(7) of the DPDPA, personal data is retained only for as long as necessary to fulfill the specific purpose or to comply with statutory retention requirements (e.g., taxation, corporate audit laws). Once the purpose is exhausted, or upon receiving a valid erasure request from the Data Principal, data is irreversibly anonymized or securely purged using DoD 5220.22-M sanitization standards.

9. Rights of the Data Principal under DPDPA

As a Data Principal, you possess statutory rights protected under Chapter III of the DPDPA:

Right to Access (Section 11)
Obtain a summary of personal data being processed, identity of Data Processors, and the nature of processing.
Right to Correction & Erasure (Section 12)
Correct inaccurate data, complete incomplete information, or request permanent erasure of data no longer required.
Right of Grievance Redressal (Section 13)
Register a formal grievance with our designated Grievance Officer and receive resolution within prescribed timelines.
Right to Nominate (Section 14)
Nominate another individual to exercise your rights under the Act in the event of death or incapacity.
To exercise any of the above statutory rights, email our designated Grievance Office at dpo@bitqube.net or grievance@bitqube.net.

10. Designated Grievance Redressal Officer & DPO

In strict adherence to Section 12 and Section 13 of the Digital Personal Data Protection Act, 2023 read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, BitQube Technologies has constituted an Office of Data Privacy and designated a Data Protection Officer & Grievance Redressal Officer:

Statutory Governance Officer Data Protection Officer (DPO) & Grievance Redressal Officer Office of Data Privacy & Information Governance, BitQube Technologies Statutory Electronic Channels
Corporate Operations & Jurisdiction BitQube Technologies • Republic of India Principal Operations Base: Hyderabad, Telangana, India Regional Technology Center: Bengaluru, Karnataka, India Corporate Contact & Grievances +91 94900 89578 Mon – Sat, 09:30 – 18:30 IST
Statutory Acknowledgment: Formal electronic acknowledgment within twenty-four (24) to forty-eight (48) working hours.
Resolution Mandate: Definitive determination within thirty (30) calendar days as prescribed under Indian law.

11. Escalation to Data Protection Board of India (DPBI)

If your grievance is not resolved to your satisfaction by our Grievance Officer within thirty (30) days, you possess the statutory right under Section 13(3) of the DPDPA to register a complaint with the Data Protection Board of India (DPBI) in the manner prescribed by the Central Government rules.