Privacy Policy
Last updated: 16 July 2026
The Goa IT Business Association (“GIBA”, “we”, “us”) respects your privacy. This policy explains what personal information we collect, why, how we use and protect it, and the choices and rights you have — in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who we are
GIBA is a member-based association for the IT business community in Goa, India. For any privacy matter we are the data fiduciary responsible for your personal data. You can reach us at secretariat@giba.in.
2. Information we collect
- Membership & profile data — name, business name, designation, postal address, e-mail, phone, and the company/promoter details you provide when joining or updating your profile.
- Event data — registrations, the associates or family members you bring, attendance, feedback responses, and gift-collection status.
- Account data — your login username and a securely hashed password. We never store passwords in plain text.
- Media you upload — logos, photos, and documents you choose to add to your profile or an event.
- Technical data — basic, non-identifying information your browser sends (such as device and page-view data) needed to run and secure the website.
3. How we use your information
- To administer your membership, renewals, and account.
- To run events — registration, approvals, entry passes, feedback, and return-gift collection.
- To display your business in the public members’ directory and your member page, only where you have chosen to make it public.
- To send you service communications (membership reminders, event notices, feedback and gift-collection e-mails).
- To keep the platform secure and to meet our legal obligations.
4. Legal basis & consent
We process your data on the basis of your consent (given when you sign up, register for an event, or make your profile public) and to fulfil our obligations to you as a member. You may withdraw consent at any time (see “Your rights” below); this does not affect processing already carried out.
5. Sharing your information
We do not sell your personal data. We share it only:
- Publicly, the business/profile details you have explicitly chosen to publish in the members’ directory.
- With service providers that help us operate — for example our e-mail delivery provider — under confidentiality obligations, and only as needed to provide the service.
- When required by law, or to protect the rights and safety of GIBA, our members, or the public.
6. Cookies
We use only the cookies necessary to keep you signed in and to keep the site secure. We do not use third-party advertising or cross-site tracking cookies.
7. Data retention
We keep your personal data for as long as you remain a member and for a reasonable period afterwards to meet legal, audit, and record-keeping needs, after which it is deleted or anonymised.
8. Security
Access to member data is restricted to authorised administrators, passwords are stored only as secure hashes, and uploaded files are served through controlled endpoints. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
9. Your rights
Under the DPDP Act you may, by contacting us:
- Access the personal data we hold about you.
- Ask us to correct or update inaccurate data.
- Withdraw consent and request erasure of your data.
- Nominate another person to exercise your rights in your absence.
- Raise a grievance about how your data is handled.
To exercise any of these rights, e-mail secretariat@giba.in. Much of your profile can also be updated directly from your member dashboard.
10. Children
The platform is intended for business members and is not directed at children. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. The “last updated” date above reflects the latest revision; material changes will be communicated to members.
12. Contact
Questions about this policy or your data? Write to secretariat@giba.in.
