Privacy notice
What we hold, why, and how to make us stop.
Version 2026-08-26. This notice is written to be read once and understood, which is also what the law asks for.
Who is responsible
Empirilex Private Limited, trading as The Charter, decides why and how your personal data is used. Under the Digital Personal Data Protection Act, 2023 (India) we are the Data Fiduciary; under the UK and EU GDPR we are the controller.
904, Trade World C, Kamala Mills, Lower Parel, Mumbai 400013, India
Data Protection Officer: Data Protection Officer,
[email protected]
Grievance Officer (DPDP s.13): Grievance Officer,
[email protected]
What we collect, and only that
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Membership request: name, email, city, company, what you have built, who referred you | To read your request, hold one conversation about it, and reply either way | Your consent (DPDP s.6) and steps taken at your request before entering a relationship (GDPR Art. 6(1)(b)) | 12 months |
| Partnership proposal: name, email, organisation, category, what you have in mind | To assess the fit and reply | Your consent, and our legitimate interest in ordinary business correspondence (GDPR Art. 6(1)(f)) | 24 months |
| Cookie choice: which categories you allowed, when, and a one-way hash of your network address | To honour your choice and be able to prove it was freely given | Legal obligation and our legitimate interest in demonstrating compliance | 5 years |
| Abuse control: a one-way hash of your network address and a timestamp | To stop automated submissions flooding the forms | Legitimate interest in keeping the site usable (GDPR Art. 6(1)(f)) | 7 days |
We do not ask for, and have no use for, any of the special or sensitive categories — health, beliefs, biometrics, financial account details, government identifiers. Please do not send them. We do not knowingly process the data of children, and the site is not directed at them.
How it is protected
- Names, email addresses and free text are encrypted at rest with authenticated encryption. A stolen database file is not readable without a key held separately.
- Network addresses are never stored. Where we need to recognise repeat traffic we store a salted one-way hash instead.
- The site is served over TLS with HSTS, a strict Content Security Policy, and CSRF protection on every form.
- Deletion is automatic. A scheduled job removes anything past its retention date, whether or not anyone remembers to ask.
Who else sees it
The people at The Charter who read applications and proposals, and our hosting and email providers, who process data on our written instructions and nothing else. We do not sell personal data, we do not share it for advertising, and there is no profiling or automated decision-making that produces a legal effect.
Where data moves outside India or the EEA, it is covered by the appropriate safeguard — Standard Contractual Clauses for EEA transfers, and transfers permitted under s.16 of the DPDP Act.
What you can ask for
Whichever law applies to you, the practical answer is the same: ask, and we do it.
- See it — a copy of what we hold about you, and a summary of how it is being used.
- Correct it — fix anything wrong, complete anything missing.
- Erase it — delete it, unless a specific law requires us to keep it.
- Withdraw consent — as easily as it was given, with no effect on what was lawful beforehand.
- Take it with you — a machine-readable copy (GDPR Art. 20).
- Object or restrict — where we rely on legitimate interest (GDPR Arts. 18, 21).
- Nominate someone — under DPDP s.14 you may name a person to exercise these rights if you die or become incapacitated.
If we get it wrong
Write to the Grievance Officer first — that is the route the DPDP Act asks you to take, and it is the fastest one. If you are not satisfied, you may complain to the Data Protection Board of India, or, in the EEA or UK, to your local supervisory authority or the Information Commissioner's Office.
Breach
If personal data is compromised we notify the Data Protection Board of India and every affected person without delay, and we notify the relevant supervisory authority within 72 hours where the GDPR applies.
Changes
Material changes are published here with a new version number and, where the change affects something you consented to, we ask again rather than assume.