Home/Legal/Privacy Policy
STATUTORY COMPLIANCE SPECIFICATION

Data Privacy & Governance Policy

Markzin Young Private Limited is dedicated to transparent, ethical data management aligned with the Digital Personal Data Protection Act (DPDPA), 2023, the Information Technology Act, 2000, and global enterprise privacy standards.

Effective Versionv2.4 (2025 Release)
Last AuditedSeptember 2025
JurisdictionWest Bengal, India
Statutory EntityU62013WB2024PTC268521
Data Fiduciary: Markzin Young Private Limited
CIN: U62013WB2024PTC268521Registered in Hooghly, West Bengal
Clause 01.0

Categories of Personal Data Collected

We collect only the minimum necessary data to fulfill contractual and operational services, adhering strictly to purpose limitation principles.

Information Directly Provided by You

  • Contact and identity credentials (name, institutional designation, work email, contact telephone number) submitted through enquiry, registration, or recruitment channels.
  • Organisation metadata including corporate registration details, registered address, and departmental specifications for institutional procurements.
  • Touchstone programme enrollee data including educational qualifications, professional background, and delivery preference records.
  • Recruitment portfolio details, curriculum vitae, employment history, and academic transcripts submitted via the career application portal.

Technical & Telemetry Data Collected Automatically

  • Device and browser specifications (browser variant, operating system, display dimensions, locale configuration, IP address).
  • Network diagnostics and performance metrics including session duration, request latency, and HTTP response codes.
  • Strictly necessary technical cookies essential for session maintenance, theme state preferences, and localized routing.
Clause 02.0

Purpose & Lawful Basis of Data Processing

Under the Digital Personal Data Protection Act (DPDPA), 2023, data is processed solely under legitimate statutory grounds and explicit contractual mandates.

Operational Execution & Service Delivery

  • Evaluating technical requirements, architecting cloud and software solutions, and fulfilling commercial software contracts.
  • Scheduling, administering, and validating capacity-building cohorts and certifying trainees through The Touchstone.
  • Processing vendor engagements, procurement verifications, and compliance monitoring under statutory guidelines.

Security & Systems Integrity

  • Protecting infrastructure against unauthorized intrusion, denial-of-service attempts, and automated credential scraping.
  • Auditing cryptographic logs and maintaining immutable transaction verification records for financial platforms.
  • Fulfilling legal obligations mandated by the Ministry of Corporate Affairs, regulatory bodies, and law enforcement agencies.
Clause 03.0

Data Security & Cryptographic Safeguards

We enforce defense-in-depth architectural security protocols across our cloud repositories, databases, and client networks.

Encryption & Storage Protocols

  • All communication streams utilize modern TLS 1.3 encryption in transit with strict HSTS security policies.
  • Confidential data assets and operational databases are encrypted at rest using AES-256 cryptographic standards.
  • Granular Role-Based Access Control (RBAC) and mandatory multi-factor authentication for all engineering and administrative staff.

Data Retention & Destruction

  • Data is retained only as long as necessary to fulfill the original purpose or to satisfy statutory accounting and tax retention requirements (typically up to 7 years under Indian Company Law).
  • Upon expiration of retention schedules, digital records are purged using verified multi-pass cryptographic erasure.
Clause 04.0

Third-Party Processors & Data Transfers

Markzin Young Private Limited does not sell, rent, or trade personal data to advertising brokerages or external marketing networks.

Approved Infrastructure Sub-processors

  • Cloud infrastructure providers (AWS, Google Cloud, Microsoft Azure) maintaining SOC 2 Type II and ISO/IEC 27001 certifications.
  • Transactional email relay nodes and communications gateways operating under strict Non-Disclosure Agreements (NDAs).
  • Enterprise banking and payment gateway integrations compliant with RBI regulations and PCI-DSS Level 1 specifications.
Clause 05.0

Data Subject Rights & Access Requests

Individuals whose personal data is processed by Markzin retain explicit statutory rights under Indian and international privacy frameworks.

Recognised Data Rights

  • Right to Confirmation and Access: Request summary of personal data held and disclosure of third parties with whom data has been shared.
  • Right to Correction and Erasure: Correct obsolete records or request erasure of data no longer necessary for original business purpose.
  • Right to Grievance Redressal: Access readily accessible grievance redressal mechanisms with prompt resolution timelines.
  • Right to Nominate: Nominate another individual to exercise privacy rights in the event of incapacity or death.
Annual Governance & Policy Revisions

Regulatory Amendments & Notifications

Markzin Young Private Limited periodically assesses this policy against emerging jurisprudence, judicial rulings, and data protection authority directives. Significant revisions altering individual rights will be notified via our official communication channels 15 calendar days prior to enforcement.

Registered Postal Office: SWEETY MANSON 1, 4TH FLOOR, FL 403, 234/2, G.T. RD (MAHESH), LP 1/26 712202 Hooghly, West Bengal, IndiaRead Terms of Service