Data Protection & Grievance
How to exercise privacy rights, raise a grievance and understand Portalwiz data-handling principles.
Our approach
Portalwiz aims to apply privacy-by-design and data-minimisation principles to website operations and client delivery. The exact role Portalwiz plays—data fiduciary/controller, processor or service provider—depends on the engagement and applicable contract.
India DPDP implementation
The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with phased commencement. As of 22 August 2026, certain foundational provisions are already in force, Consent Manager-related provisions are scheduled for November 2026, and many core operational obligations—including notices, data-principal rights, security safeguards and breach-related duties—are scheduled for May 2027. Portalwiz is using the implementation window to prepare its website and operating controls rather than waiting for the final phase.
Portalwiz follows a privacy-by-design approach and updates its practices as applicable legal requirements evolve. References to data-protection practices do not imply independent certification unless expressly stated.
How to make a request
Email contact@portalwiz.com with the subject “Data Protection Request”. Include enough detail for us to understand the request and verify identity or authority. Please do not send unnecessary sensitive information in the first email.
Grievance handling
Privacy grievances may be submitted to the same contact with the subject “Privacy Grievance”. Portalwiz will review the matter and respond through the contact details provided. Where applicable law provides a right to escalate to a regulator or the Data Protection Board of India, that right remains available.
Client data and delivery
For client projects, data-handling responsibilities should be documented in the applicable contract, NDA, data-processing addendum or project security requirements. Client production data should not be reused for unrelated purposes without authorisation.
International data
Where project or website information crosses borders, Portalwiz seeks to use lawful transfer mechanisms, contractual commitments and practical security controls appropriate to the engagement.
Security practices
Depending on the solution and agreed scope, controls may include role-based access, least privilege, credential management, encryption in transit, backups, logging, environment separation, code review, QA, incident escalation and controlled access to production systems.
Responsible AI and ML
AI and machine-learning work should use authorised data, appropriate evaluation, human oversight where needed and controls proportionate to business risk. See Responsible AI.