Privacy Policy
What personal data Boznaw collects, why, how long it is kept, who it goes to, and the rights you can exercise over it.
This Privacy Policy explains how Placeholder, to be configured before publication: [FULL LEGAL NAME], sole proprietor trading as Boznaw (Boznaw, we, us, our) handles personal data when you use the Boznaw website and application (the Services).
It is written to be read, not skimmed past. Where a legal term matters, we define it. Where something does not apply to Boznaw, we say so plainly rather than leaving a hedge in place.
Contents16 sections
- 1. The short version
- 2. Who we are and who to contact
- 3. Definitions used across our policies
- 4. What personal data we collect
- 5. Why we process personal data, and on what basis
- 6. How long we keep it
- 7. Who your data is shared with
- 8. Transfers outside India
- 9. Security
- 10. Children and persons with a guardian
- 11. Your rights, and how to use them
- 12. Cookies and browser storage
- 13. Payments, advertising and profiling
- 14. Users outside India
- 15. Changes to this policy
- 16. Contact
1. The short version
This section is a summary. It does not replace the detail below, and where the two differ, the detailed sections govern.
- We collect what a discussion forum needs to work: an account identifier, the Content you choose to publish, the private messages you choose to send, and the technical data any website receives when a browser loads a page.
- Most of what we hold is data you chose to publish. Posts, comments, votes and profile details are visible in the way the Services are designed to make them visible.
- We do not sell personal data, we serve no advertising, we build no advertising profiles, and we do not train machine-learning models on your Content.
- We share data with the service providers that run the infrastructure, with the moderators of a Community you post in, and with authorities where a law requires it. Nothing else.
- You can see, correct, export and permanently delete your data from Settings, without asking us first.
- If something goes wrong, the Grievance Officer is a named person with published timelines, not a support queue.
2. Who we are and who to contact
Boznaw is operated by Placeholder, to be configured before publication: [FULL LEGAL NAME], sole proprietor trading as Boznaw, Placeholder, to be configured before publication: [BUSINESS ADDRESS WITH PIN CODE]. For the purposes of the Digital Personal Data Protection Act, 2023 (the DPDP Act) we are the Data Fiduciary for personal data processed through the Services, and you are the Data Principal.
For the purposes of the Information Technology Act, 2000, Boznaw is an intermediary: it stores and transmits Content created by its Users, and does not originate that Content.
Privacy questions and data-rights requests
Data protection contact
Placeholder, to be configured before publication: [FULL LEGAL NAME]
- privacy@boznaw.com
- Postal address
- Placeholder, to be configured before publication: [BUSINESS ADDRESS WITH PIN CODE]
Published under Section 5 of the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025. A Data Protection Officer under Section 10 becomes mandatory only if Boznaw is notified as a Significant Data Fiduciary.
Complaints
If a privacy request is not handled to your satisfaction, use the Grievance Redressal process. It is a separate, named channel with published statutory timelines.
3. Definitions used across our policies
These definitions are identical in every Boznaw policy. Where a document uses one of these words with a capital letter, it carries the meaning below.
- Services
- The Boznaw website and application, including communities, feeds, posts, comments, voting, polls, saved items, search, profiles, direct messages, notifications, reporting and moderation tools.
- User
- Any person who accesses or uses the Services, whether or not they hold an account. You means the User reading this document.
- Content
- Anything created, uploaded, posted, transmitted or otherwise made available through the Services. This includes posts, comments, votes, poll answers, community names, descriptions and rules, profile fields, display names, avatars, banners, images, videos, links and direct messages.
- Personal Data
- Any data about an individual who is identifiable by or in relation to such data, as defined in Section 2(t) of the DPDP Act.
- Processing
- Any operation performed on personal data, including collection, storage, use, sharing, alteration, indexing, disclosure and erasure, as defined in Section 2(x) of the DPDP Act.
- Community
- A member-run space within Boznaw, shown as c/name, with its own moderators and rules.
- Boznaw
- The Services, and where the context requires, Placeholder, to be configured before publication: [FULL LEGAL NAME], sole proprietor trading as Boznaw as the entity operating them.
4. What personal data we collect
The tables below cover every category of personal data the Services handle. Mandatory means the Services cannot function for you without it; everything else is optional and can be left blank or turned off.
4.1 Account and authentication data
Data used to create, hold and secure an account
| Data | Mandatory? | Why we collect it |
|---|---|---|
| Username | Mandatory | Identifies you publicly, and addresses you in mentions, links, moderation records and notifications. |
| Email address | Mandatory for email sign-up; otherwise optional | Signing you in, resetting your password, verifying the address, and sending account, security and notification email you have not turned off. |
| Phone number | Mandatory only if you choose phone sign-up | Signing you in, and delivering the one-time passcode that verifies the number. |
| Password | Mandatory for email sign-up | Authenticating you. Stored only as a salted cryptographic hash — we cannot read your password and cannot tell it to you. |
| Google account identifier, email, name and profile picture | Only if you choose Continue with Google | Creating and signing in to your account without a Boznaw password. |
| Two-factor authentication settings and recovery data | Optional | Protecting your account with a second factor, if you turn it on. |
| Age confirmation | Mandatory at sign-up | Confirming you meet the minimum age in our Terms of Service. |
| Session and device records: sign-in times, IP address, browser and operating system | Mandatory | Keeping you signed in, showing you your active sessions, letting you sign out other devices, and alerting you to a sign-in you did not make. |
Username
- Mandatory?
- Mandatory
- Why we collect it
- Identifies you publicly, and addresses you in mentions, links, moderation records and notifications.
Email address
- Mandatory?
- Mandatory for email sign-up; otherwise optional
- Why we collect it
- Signing you in, resetting your password, verifying the address, and sending account, security and notification email you have not turned off.
Phone number
- Mandatory?
- Mandatory only if you choose phone sign-up
- Why we collect it
- Signing you in, and delivering the one-time passcode that verifies the number.
Password
- Mandatory?
- Mandatory for email sign-up
- Why we collect it
- Authenticating you. Stored only as a salted cryptographic hash — we cannot read your password and cannot tell it to you.
Google account identifier, email, name and profile picture
- Mandatory?
- Only if you choose Continue with Google
- Why we collect it
- Creating and signing in to your account without a Boznaw password.
Two-factor authentication settings and recovery data
- Mandatory?
- Optional
- Why we collect it
- Protecting your account with a second factor, if you turn it on.
Age confirmation
- Mandatory?
- Mandatory at sign-up
- Why we collect it
- Confirming you meet the minimum age in our Terms of Service.
Session and device records: sign-in times, IP address, browser and operating system
- Mandatory?
- Mandatory
- Why we collect it
- Keeping you signed in, showing you your active sessions, letting you sign out other devices, and alerting you to a sign-in you did not make.
4.2 Profile data
Information you choose to publish about yourself. All of it is optional.
| Data | Why we collect it | Who can see it |
|---|---|---|
| Display name | Shown beside your Content instead of your username. | Anyone who can see your profile. |
| Bio, pronouns, location, website | Shown on your public profile. | Anyone who can see your profile. Location is free text you type — the Services never read your device location. |
| Avatar and profile banner | Shown on your profile and beside your Content. | Anyone who can see your profile. Images are resized in your browser before upload. |
Display name
- Why we collect it
- Shown beside your Content instead of your username.
- Who can see it
- Anyone who can see your profile.
Bio, pronouns, location, website
- Why we collect it
- Shown on your public profile.
- Who can see it
- Anyone who can see your profile. Location is free text you type — the Services never read your device location.
Avatar and profile banner
- Why we collect it
- Shown on your profile and beside your Content.
- Who can see it
- Anyone who can see your profile. Images are resized in your browser before upload.
4.3 Content and activity data
What you create and do on the Services
| Data | Why we collect it | Who can see it |
|---|---|---|
| Posts, comments, polls and poll answers | Publishing them is the purpose for which you supply them. | Public, or limited to a Community's members where that Community is restricted or private. |
| Votes | Ranking Content in feeds and community pages, and detecting vote manipulation. | Individual votes are never shown to other Users. Only the total is. |
| Saved posts | Your private reading list. | You only. |
| Community memberships and follows | Building your feed, and showing membership and follower counts. | Public on profiles and community pages, subject to your privacy settings. |
| Images and videos you attach | Publishing them with your Content. | The same audience as the Content they belong to. |
| Direct messages and message requests | Delivering the conversation to the person you addressed. | You and the other people in the conversation. See the note below. |
| Notification and read state | Keeping unread counts correct across your devices. | You only. |
| Search queries and recent searches | Returning results, and showing your recent searches back to you. | You only. |
| Drafts and unsent text | So a half-written post or message survives a navigation or a reload. | You only. Held in your browser, not on our servers, until you publish or send. |
Posts, comments, polls and poll answers
- Why we collect it
- Publishing them is the purpose for which you supply them.
- Who can see it
- Public, or limited to a Community's members where that Community is restricted or private.
Votes
- Why we collect it
- Ranking Content in feeds and community pages, and detecting vote manipulation.
- Who can see it
- Individual votes are never shown to other Users. Only the total is.
Saved posts
- Why we collect it
- Your private reading list.
- Who can see it
- You only.
Community memberships and follows
- Why we collect it
- Building your feed, and showing membership and follower counts.
- Who can see it
- Public on profiles and community pages, subject to your privacy settings.
Images and videos you attach
- Why we collect it
- Publishing them with your Content.
- Who can see it
- The same audience as the Content they belong to.
Direct messages and message requests
- Why we collect it
- Delivering the conversation to the person you addressed.
- Who can see it
- You and the other people in the conversation. See the note below.
Notification and read state
- Why we collect it
- Keeping unread counts correct across your devices.
- Who can see it
- You only.
Search queries and recent searches
- Why we collect it
- Returning results, and showing your recent searches back to you.
- Who can see it
- You only.
Drafts and unsent text
- Why we collect it
- So a half-written post or message survives a navigation or a reload.
- Who can see it
- You only. Held in your browser, not on our servers, until you publish or send.
4.4 Preference and accessibility data
Your theme, accent colour, text size, layout density, reduced-motion and high-contrast settings, link underlining, language, region, timezone, autoplay, data-saver, mature-content, muted words, notification and privacy preferences are all stored so the interface stays the way you left it. Accessibility preferences are treated exactly like any other preference: they are never used to infer anything about you, and never shared.
4.5 Technical and log data
Data generated by the act of loading and using the Services
| Data | Why we collect it | Notes |
|---|---|---|
| IP address, user-agent string, browser, operating system, requested URL, timestamp and referrer | Delivering pages, keeping the Services available, rate-limiting abuse, and investigating security incidents. | Recorded in ordinary server request logs. Boznaw runs no analytics or telemetry code of its own. |
| Approximate location inferred from IP address | Security only — flagging a sign-in from an unusual place, and applying regional legal requirements. | Approximate and city-level at best. The Services never request precise device location, and no permission prompt for it is ever shown. |
| Error and diagnostic information | Finding and fixing faults. | Errors surface in your own browser's console. No third-party crash-reporting service is integrated. |
| Device identifiers, advertising IDs and fingerprints | Not collected. | No device fingerprinting, advertising identifier or cross-site identifier is created or read. |
| Push notification tokens | Not collected. | The notification settings control what appears inside the Services and what is emailed to you. No push service is integrated, so no push token exists. |
IP address, user-agent string, browser, operating system, requested URL, timestamp and referrer
- Why we collect it
- Delivering pages, keeping the Services available, rate-limiting abuse, and investigating security incidents.
- Notes
- Recorded in ordinary server request logs. Boznaw runs no analytics or telemetry code of its own.
Approximate location inferred from IP address
- Why we collect it
- Security only — flagging a sign-in from an unusual place, and applying regional legal requirements.
- Notes
- Approximate and city-level at best. The Services never request precise device location, and no permission prompt for it is ever shown.
Error and diagnostic information
- Why we collect it
- Finding and fixing faults.
- Notes
- Errors surface in your own browser's console. No third-party crash-reporting service is integrated.
Device identifiers, advertising IDs and fingerprints
- Why we collect it
- Not collected.
- Notes
- No device fingerprinting, advertising identifier or cross-site identifier is created or read.
Push notification tokens
- Why we collect it
- Not collected.
- Notes
- The notification settings control what appears inside the Services and what is emailed to you. No push service is integrated, so no push token exists.
4.6 Safety, reporting and moderation data
Data created when the safety tools are used
| Data | Why we collect it | Who can see it |
|---|---|---|
| Reports you submit: the Content reported, the reason chosen, and any note you add | So a moderator can assess the Content against the Content Policy. | Moderators of the Community concerned, and Boznaw where a report is escalated. The author is never told who reported them. |
| Reports about your Content, and the outcome | Enforcing the rules consistently, and assessing repeat violations. | Moderators and Boznaw. |
| Blocks and mutes you apply | Keeping the other User's Content and messages away from you. | You only. The blocked User is not notified. |
| Enforcement records: removals, restrictions, strikes, suspensions and appeals | Applying escalating consequences fairly, answering appeals, and responding to legal requests. | Boznaw and, where relevant, the Community's moderators. |
| Signals used to detect spam, ban evasion and vote manipulation | Protecting Users and the integrity of the Services. | Boznaw only. We do not publish these signals, because publishing them would defeat them. |
Reports you submit: the Content reported, the reason chosen, and any note you add
- Why we collect it
- So a moderator can assess the Content against the Content Policy.
- Who can see it
- Moderators of the Community concerned, and Boznaw where a report is escalated. The author is never told who reported them.
Reports about your Content, and the outcome
- Why we collect it
- Enforcing the rules consistently, and assessing repeat violations.
- Who can see it
- Moderators and Boznaw.
Blocks and mutes you apply
- Why we collect it
- Keeping the other User's Content and messages away from you.
- Who can see it
- You only. The blocked User is not notified.
Enforcement records: removals, restrictions, strikes, suspensions and appeals
- Why we collect it
- Applying escalating consequences fairly, answering appeals, and responding to legal requests.
- Who can see it
- Boznaw and, where relevant, the Community's moderators.
Signals used to detect spam, ban evasion and vote manipulation
- Why we collect it
- Protecting Users and the integrity of the Services.
- Who can see it
- Boznaw only. We do not publish these signals, because publishing them would defeat them.
4.7 Communications with us
When you write to support, to the data protection contact, to the Grievance Officer or to the copyright contact, we keep your message, our reply, and the records needed to show how the matter was handled. Grievance correspondence is retained because the IT Rules, 2021 require a documented, auditable grievance process.
4.8 Data we do not handle at all
For the avoidance of doubt, the Services do not collect, and we do not process:
- Payment card numbers, bank details, UPI identifiers or any financial information — Boznaw takes no payments. See Section 13.
- Government identifiers such as Aadhaar, PAN, passport or voter ID numbers.
- Biometric data, health data, or data about your sexual life.
- Precise device location.
- Your contact list, call logs, SMS messages, photo library, or anything else from your device. The only files that reach the Services are the ones you deliberately choose in a file picker.
- Data bought, rented or scraped from data brokers or other platforms.
5. Why we process personal data, and on what basis
Under the DPDP Act, personal data may be processed on the basis of your consent (Section 6) or for one of the certain legitimate uses listed in Section 7. Boznaw does not rely on any equivalent of a general balancing test — Indian law does not provide one.
Purpose, category and lawful basis
| Purpose | Category | Basis under the DPDP Act |
|---|---|---|
| Creating and operating your account, and signing you in | Necessary to provide the Service | Your consent, given at sign-up, for the specified purpose of providing the Services. |
| Publishing, storing and displaying your Content to the audience you chose | Necessary to provide the Service | Your consent. Publication is the purpose for which you supply the Content. |
| Building your feed from your memberships, follows and preferences | Necessary to provide the Service | Your consent. |
| Delivering direct messages to the person you addressed | Necessary to provide the Service | Your consent. |
| Sending account, verification and security email or SMS | Necessary to provide the Service | Your consent, and our obligation to keep your account secure. These messages cannot be turned off while the account exists. |
| Sending notification and digest email you have opted into | Optional | Your consent, withdrawable at any time in Settings → Notifications. |
| Remembering optional profile details and interface preferences | Optional | Your consent, withdrawable by clearing the field or resetting preferences. |
| Reviewing reports, enforcing the Content Policy, and handling appeals | Moderation and legal compliance | Compliance with our due-diligence obligations under Rule 3 of the IT Rules, 2021 — a legitimate use under Section 7(c) of the DPDP Act. |
| Detecting and preventing spam, fraud, impersonation, ban evasion and account compromise | Security and fraud prevention | Compliance with law, and protection of Users. Processed no more widely than the purpose requires. |
| Responding to grievances, and to lawful orders from a court or authorised government agency | Legal compliance | Sections 7(b) and 7(c) of the DPDP Act, read with Section 79(3)(b) of the IT Act, 2000. |
| Keeping the Services available, and investigating outages and attacks | Security | Legitimate use for maintaining the security of the Services. |
Creating and operating your account, and signing you in
- Category
- Necessary to provide the Service
- Basis under the DPDP Act
- Your consent, given at sign-up, for the specified purpose of providing the Services.
Publishing, storing and displaying your Content to the audience you chose
- Category
- Necessary to provide the Service
- Basis under the DPDP Act
- Your consent. Publication is the purpose for which you supply the Content.
Building your feed from your memberships, follows and preferences
- Category
- Necessary to provide the Service
- Basis under the DPDP Act
- Your consent.
Delivering direct messages to the person you addressed
- Category
- Necessary to provide the Service
- Basis under the DPDP Act
- Your consent.
Sending account, verification and security email or SMS
- Category
- Necessary to provide the Service
- Basis under the DPDP Act
- Your consent, and our obligation to keep your account secure. These messages cannot be turned off while the account exists.
Sending notification and digest email you have opted into
- Category
- Optional
- Basis under the DPDP Act
- Your consent, withdrawable at any time in Settings → Notifications.
Remembering optional profile details and interface preferences
- Category
- Optional
- Basis under the DPDP Act
- Your consent, withdrawable by clearing the field or resetting preferences.
Reviewing reports, enforcing the Content Policy, and handling appeals
- Category
- Moderation and legal compliance
- Basis under the DPDP Act
- Compliance with our due-diligence obligations under Rule 3 of the IT Rules, 2021 — a legitimate use under Section 7(c) of the DPDP Act.
Detecting and preventing spam, fraud, impersonation, ban evasion and account compromise
- Category
- Security and fraud prevention
- Basis under the DPDP Act
- Compliance with law, and protection of Users. Processed no more widely than the purpose requires.
Responding to grievances, and to lawful orders from a court or authorised government agency
- Category
- Legal compliance
- Basis under the DPDP Act
- Sections 7(b) and 7(c) of the DPDP Act, read with Section 79(3)(b) of the IT Act, 2000.
Keeping the Services available, and investigating outages and attacks
- Category
- Security
- Basis under the DPDP Act
- Legitimate use for maintaining the security of the Services.
6. How long we keep it
Section 8(7) of the DPDP Act requires personal data to be erased once the purpose it was collected for is no longer served, and retention is no longer required by law. The table sets out how that works here.
| Data | Kept for | What ends it |
|---|---|---|
| Account, profile and preference data | While your account exists | Deleting your account. See the Account & Data Deletion Policy. |
| Posts, comments, votes, saves, memberships and follows | Until you delete the item, or delete your account | Your own deletion, a moderation removal, or account deletion. |
| Uploaded images and videos | Until the Content they belong to is deleted | Deletion of that Content, or of your account. Copies are purged from the media store and its caches within 30 days. |
| Direct messages | Until deleted by a participant, or until the account is deleted | Deleting your account removes your copy. A message already delivered remains in the recipient's inbox — we cannot unsend it on your behalf. |
| Session and device records | 90 days after the session expires | Signing out, signing out other devices, or expiry of the period. |
| Server request logs | 90 days | Expiry of the retention period. |
| Backups | 30 days | Backups age out on their own cycle. Deleted data persists in a backup until that cycle completes, and is never restored to live systems — if a backup is restored, the deletion is reapplied. |
| Registration information after you delete your account | 180 days | This one is not our choice: Rule 3(1)(g) of the IT Rules, 2021 requires an intermediary to retain a user's registration information for 180 days after the registration is withdrawn or cancelled. It is held in isolation and used for nothing else. |
| Moderation and enforcement records | 3 years after the enforcement action, and longer only where a law requires | Expiry of the period, or conclusion of any proceeding the record relates to. |
| Strikes against an account | 12 months without a further breach | Expiry of the period, after which the strike no longer counts towards escalation. |
| Records of a terminated account kept to prevent the person returning | The minimum needed to recognise a ban evasion attempt, and no Content | Expiry of the enforcement period. |
| Grievance and legal correspondence | 3 years, to evidence a compliant grievance process | Expiry of the period. |
| Data preserved because of a legal order | The period the order specifies | Expiry or withdrawal of the order. |
Account, profile and preference data
- Kept for
- While your account exists
- What ends it
- Deleting your account. See the Account & Data Deletion Policy.
Posts, comments, votes, saves, memberships and follows
- Kept for
- Until you delete the item, or delete your account
- What ends it
- Your own deletion, a moderation removal, or account deletion.
Uploaded images and videos
- Kept for
- Until the Content they belong to is deleted
- What ends it
- Deletion of that Content, or of your account. Copies are purged from the media store and its caches within 30 days.
Direct messages
- Kept for
- Until deleted by a participant, or until the account is deleted
- What ends it
- Deleting your account removes your copy. A message already delivered remains in the recipient's inbox — we cannot unsend it on your behalf.
Session and device records
- Kept for
- 90 days after the session expires
- What ends it
- Signing out, signing out other devices, or expiry of the period.
Server request logs
- Kept for
- 90 days
- What ends it
- Expiry of the retention period.
Backups
- Kept for
- 30 days
- What ends it
- Backups age out on their own cycle. Deleted data persists in a backup until that cycle completes, and is never restored to live systems — if a backup is restored, the deletion is reapplied.
Registration information after you delete your account
- Kept for
- 180 days
- What ends it
- This one is not our choice: Rule 3(1)(g) of the IT Rules, 2021 requires an intermediary to retain a user's registration information for 180 days after the registration is withdrawn or cancelled. It is held in isolation and used for nothing else.
Moderation and enforcement records
- Kept for
- 3 years after the enforcement action, and longer only where a law requires
- What ends it
- Expiry of the period, or conclusion of any proceeding the record relates to.
Strikes against an account
- Kept for
- 12 months without a further breach
- What ends it
- Expiry of the period, after which the strike no longer counts towards escalation.
Records of a terminated account kept to prevent the person returning
- Kept for
- The minimum needed to recognise a ban evasion attempt, and no Content
- What ends it
- Expiry of the enforcement period.
Grievance and legal correspondence
- Kept for
- 3 years, to evidence a compliant grievance process
- What ends it
- Expiry of the period.
Data preserved because of a legal order
- Kept for
- The period the order specifies
- What ends it
- Expiry or withdrawal of the order.
8. Transfers outside India
Section 16 of the DPDP Act permits transfer of personal data outside India, except to a country the Central Government restricts by notification. We monitor those notifications and will stop a transfer that becomes restricted.
Where each provider processes your data:
| Data | Processed by | Where |
|---|---|---|
| Account records, profiles, Content, messages and uploaded media | Supabase, Inc. | In the region configured for the Boznaw Supabase project. To confirm the current region, write to the data protection contact — we will tell you, and we will publish it here once the deployment region is fixed. |
| Request logs | Cloudflare, Inc. | At the Cloudflare edge location nearest the person making the request, which for most Users in India is inside India. |
| Email we send you | Plus Five Five, Inc. (Resend) | United States — a transfer outside India. |
| SMS verification codes | Walkover Web Solutions Private Limited (MSG91) | India. |
| Font requests, and Google sign-in if you use it | Google LLC | Outside India. |
Account records, profiles, Content, messages and uploaded media
- Processed by
- Supabase, Inc.
- Where
- In the region configured for the Boznaw Supabase project. To confirm the current region, write to the data protection contact — we will tell you, and we will publish it here once the deployment region is fixed.
Request logs
- Processed by
- Cloudflare, Inc.
- Where
- At the Cloudflare edge location nearest the person making the request, which for most Users in India is inside India.
Email we send you
- Processed by
- Plus Five Five, Inc. (Resend)
- Where
- United States — a transfer outside India.
SMS verification codes
- Processed by
- Walkover Web Solutions Private Limited (MSG91)
- Where
- India.
Font requests, and Google sign-in if you use it
- Processed by
- Google LLC
- Where
- Outside India.
None of these countries is currently restricted by notification under Section 16. We monitor those notifications and will stop a transfer that becomes restricted.
9. Security
Section 8(5) of the DPDP Act requires reasonable security safeguards to prevent a personal data breach, and Rule 6 of the DPDP Rules, 2025 sets out what those safeguards must include. Section 43A of the IT Act, 2000 and the Sensitive Personal Data Rules, 2011 continue to apply to sensitive personal data until they are omitted on 13 May 2027.
The safeguards we apply:
- All traffic between your browser and the Services is encrypted in transit using TLS.
- Passwords are stored only as salted cryptographic hashes, never in a form we can read.
- Server functions are protected against cross-site request forgery.
- Access to production data is restricted to the people who need it for a stated purpose, and access is logged.
- Two-factor authentication is available on your account, and sign-in alerts can be turned on.
- You can review your active sessions and sign out other devices from Settings → Account & security.
9.1 If there is a breach
If we become aware of a personal data breach, we will notify each affected Data Principal without delay, in clear language, describing what happened, what data was involved, the likely consequences, what we have done, and what you can do. We will also report to the Data Protection Board of India in the form and within the time the DPDP Rules require, including the detailed report due within 72 hours.
9.2 Your part
Use a password you do not use anywhere else, turn on two-factor authentication, and tell us immediately if you think someone else has access to your account.
10. Children and persons with a guardian
Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child — a person under 18 — and prohibits tracking, behavioural monitoring and advertising directed at children.
Boznaw's Terms of Service set a minimum age of 18. The Services are not directed at children, and we do not knowingly process a child's personal data. Because we serve no advertising and do no behavioural tracking of anyone, the tracking and advertising prohibitions are satisfied by design rather than by configuration.
The same protections apply to a person with a disability who has a lawful guardian, and we will process such a person's data only with that guardian's consent.
11. Your rights, and how to use them
Sections 11 to 14 of the DPDP Act give you the rights below. Most of them you can exercise yourself, immediately, without asking us.
| Right | What it covers | How to use it |
|---|---|---|
| Access to information — Section 11 | A summary of the personal data being processed, what it is processed for, and the identities of anyone it has been shared with. | Settings → Account & security → Download your data produces a machine-readable export. For a summary of sharing beyond that, write to the data protection contact. |
| Correction and updating — Section 12 | Correcting inaccurate or misleading data, completing incomplete data, and updating data. | Edit your profile and preferences in Settings → Profile. Posts and comments can be edited or deleted from their own menus. |
| Erasure — Section 12 | Erasing personal data we no longer need for the purpose it was collected for. | Delete individual items from their menus, or Settings → Account & security → Delete account to erase everything. See the Account & Data Deletion Policy. |
| Withdrawal of consent — Section 6(4) | Withdrawing consent as easily as it was given. | Turn off the setting, clear the field, or delete your account. Withdrawal takes effect at once, but does not undo processing that already lawfully happened. |
| Grievance redressal — Section 13 | Complaining to us about how your data has been handled, before approaching the Board. | Use Grievance Redressal. This right is available whether or not you have first used another right. |
| Nominating another person — Section 14 | Nominating someone to exercise your rights if you die or become incapacitated. | Write to the data protection contact with the nominee's name and contact details, and we will record the nomination against your account. |
| Complaining to the Board | Approaching the Data Protection Board of India if our response does not resolve the matter. | The Board has been constituted with effect from 13 November 2025. Please complain to us first — the DPDP Act expects that. |
Access to information — Section 11
- What it covers
- A summary of the personal data being processed, what it is processed for, and the identities of anyone it has been shared with.
- How to use it
- Settings → Account & security → Download your data produces a machine-readable export. For a summary of sharing beyond that, write to the data protection contact.
Correction and updating — Section 12
- What it covers
- Correcting inaccurate or misleading data, completing incomplete data, and updating data.
- How to use it
- Edit your profile and preferences in Settings → Profile. Posts and comments can be edited or deleted from their own menus.
Erasure — Section 12
- What it covers
- Erasing personal data we no longer need for the purpose it was collected for.
- How to use it
- Delete individual items from their menus, or Settings → Account & security → Delete account to erase everything. See the Account & Data Deletion Policy.
Withdrawal of consent — Section 6(4)
- What it covers
- Withdrawing consent as easily as it was given.
- How to use it
- Turn off the setting, clear the field, or delete your account. Withdrawal takes effect at once, but does not undo processing that already lawfully happened.
Grievance redressal — Section 13
- What it covers
- Complaining to us about how your data has been handled, before approaching the Board.
- How to use it
- Use Grievance Redressal. This right is available whether or not you have first used another right.
Nominating another person — Section 14
- What it covers
- Nominating someone to exercise your rights if you die or become incapacitated.
- How to use it
- Write to the data protection contact with the nominee's name and contact details, and we will record the nomination against your account.
Complaining to the Board
- What it covers
- Approaching the Data Protection Board of India if our response does not resolve the matter.
- How to use it
- The Board has been constituted with effect from 13 November 2025. Please complain to us first — the DPDP Act expects that.
Section 15 of the DPDP Act also places duties on you: do not impersonate another person when exercising a right, do not suppress material information, and do not file a false or frivolous grievance. The Act provides penalties for breach of these duties.
13. Payments, advertising and profiling
Boznaw accepts no payments, sells no subscriptions, issues no credits, and serves no advertising. There is no payment processor, no billing record and no advertising identifier. No refund or advertising policy is published, because neither would describe anything real.
If Boznaw ever introduces paid features or advertising, we will publish the corresponding policies and update this one before that change takes effect.
14. Users outside India
Boznaw is built for and operated from India, and this policy is drafted India-first. The DPDP Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to Data Principals in India.
If you use Boznaw from outside India, your data is handled under this policy and under Indian law. Other jurisdictions impose requirements Boznaw has not implemented — for example the EU and UK GDPR, which require a documented lawful basis in their own terms, transfer safeguards, a representative or data protection officer in some cases, and rights on different timelines; and the comprehensive privacy statutes of several US states.
15. Changes to this policy
We update this policy when the Services change, when the law changes, or when we find something here that could be clearer. Every version carries a version number, an effective date and a last-updated date, and the change history at the foot of this page records what changed.
For a change that materially affects how your personal data is processed, we will give notice in the Services before it takes effect, and will not apply it retrospectively to processing already completed under an earlier version.
16. Contact
Data protection contact
Placeholder, to be configured before publication: [FULL LEGAL NAME]
- privacy@boznaw.com
- Postal address
- Placeholder, to be configured before publication: [BUSINESS ADDRESS WITH PIN CODE]
Published under Section 5 of the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025. A Data Protection Officer under Section 10 becomes mandatory only if Boznaw is notified as a Significant Data Fiduciary.
Details for every legal contact are on the Legal Contact page. For a formal complaint, use Grievance Redressal.
Drafted against
- Digital Personal Data Protection Act, 2023
- Digital Personal Data Protection Rules, 2025
- Information Technology Act, 2000, Section 43A
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
Citing a statute is not a claim of compliance with it. Boznaw makes no claim to be certified, accredited or approved by any authority.
Related
Cookie Policy
Every cookie and browser-storage item Boznaw uses, what each one does, how long it lasts, and how to clear it.
Data & Account Deletion
What deactivating and deleting your Boznaw account each do, what is erased, what necessarily remains, and what cannot be undone.
Terms of Service
The agreement between you and Boznaw: who may use the Services, what you may post, what rights you keep, and how accounts are suspended, terminated and appealed.
Grievance Redressal
Boznaw's statutory complaint channel: who the Grievance Officer is, what they handle, what a complaint must contain, the timelines that bind us, and how to escalate.
Change history
- v1.0.0·11 September 2026
First published version. Drafted against the DPDP Act, 2023, the DPDP Rules, 2025, and the IT Rules, 2021 as amended in 2026.
This document is published for Users of Boznaw. It is not legal advice, and it does not create a relationship of advocate and client. If you need advice about your own position, consult a qualified lawyer.
