Data Protection Policy
Last updated: 15 July 2026
1. Introduction
Sankalpath is committed to protecting the personal data of everyone who interacts with us — whether you are a client, a partner, or a visitor to our website. This Data Protection Policy outlines the principles, practices, and organisational measures we follow to ensure that personal data is handled responsibly, lawfully, and securely.
This policy applies to all personal data processed by Sankalpath, whether collected through our website, email, contact forms, or any other channel.
2. Our Data Protection Principles
We adhere to the following core principles when processing personal data:
- Lawfulness, fairness, and transparency: We process data only on valid legal grounds and communicate clearly about how and why we use it.
- Purpose limitation: Data is collected for specific, legitimate purposes and is not processed in a manner incompatible with those purposes.
- Data minimisation: We collect only the data that is necessary for the stated purpose — nothing more.
- Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
- Storage limitation: Personal data is retained only for as long as necessary to fulfil its purpose, after which it is securely deleted or anonymised.
- Integrity and confidentiality: We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, or damage.
- Accountability: We take responsibility for our data handling practices and can demonstrate compliance.
3. Applicable Legal Frameworks
Sankalpath's data protection practices are designed to comply with:
- Digital Personal Data Protection Act, 2023 (India): India's primary data protection legislation governing the processing of digital personal data.
- Information Technology Act, 2000 and IT Rules: Including the Reasonable Security Practices and Procedures rules applicable to handling sensitive personal data in India.
- General Data Protection Regulation (GDPR): For personal data of individuals located in the European Economic Area, where applicable.
- Other regional laws: We respect the data protection rights granted under the laws of the jurisdictions where our users are located.
4. Data We Process
In the course of our operations, we may process the following categories of personal data:
a) Website visitors
- IP address and approximate geographic location
- Browser type, device information, and operating system
- Pages visited and interaction patterns
b) Contact form respondents
- Name, email address, and organisation
- Enquiry type and message content
c) Partners, volunteers, and collaborators
- Contact information shared during partnerships or volunteer engagements
- Communication records related to project work
We do not process special category data (such as health, biometric, or genetic data) unless explicitly required for a specific project and with appropriate consent.
5. Data Processing Activities
| Activity | Data involved | Legal basis | Retention |
|---|---|---|---|
| Website hosting and operation | IP address, device/browser data | Legitimate interest | Server logs: 30 days |
| Responding to enquiries | Name, email, message | Consent | Up to 24 months after last contact |
| Partnership management | Contact details, communications | Legitimate interest / Contract | Duration of partnership + 12 months |
| Volunteer coordination | Contact details, skills, availability | Consent | Duration of engagement + 12 months |
6. Technical and Organisational Safeguards
We employ a range of measures to protect personal data:
Technical measures
- All data transmitted to and from our website is encrypted using TLS/HTTPS.
- Access to systems containing personal data is restricted to authorised personnel only.
- We use secure, reputable third-party services (such as Web3Forms) that maintain their own security certifications.
- Regular reviews of our website and infrastructure for security vulnerabilities.
Organisational measures
- Team members with access to personal data are made aware of their data protection responsibilities.
- We maintain a record of processing activities as required by applicable law.
- Data access is granted on a need-to-know basis aligned with roles and responsibilities.
- We periodically review and update our data protection practices.
7. Third-Party Processors
We engage a limited number of third-party service providers who may process personal data on our behalf:
- Web3Forms: processes contact form submissions to deliver messages to us.
- Hosting provider: stores and serves our website files and may process server access logs.
We select processors that provide sufficient guarantees regarding data protection. Where required, we enter into data processing agreements to ensure your data is handled in compliance with applicable law.
8. International Data Transfers
Some of our third-party processors may be located outside India. Where personal data is transferred internationally, we ensure that appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions, to maintain the level of protection required by applicable law.
9. Data Breach Response
In the event of a personal data breach, Sankalpath will:
- Assess the nature, scope, and potential impact of the breach as soon as it is identified.
- Take immediate steps to contain the breach and mitigate any harm.
- Notify the relevant data protection authority (such as the Data Protection Board of India) within the timeframe required by applicable law.
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Document the breach, response actions taken, and lessons learned to prevent recurrence.
10. Your Data Protection Rights
Depending on your jurisdiction, you may exercise the following rights:
- Right to access: Obtain confirmation of whether we process your data and request a copy.
- Right to correction: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your data where there is no compelling reason for continued processing.
- Right to restriction: Request that we limit how we process your data in certain circumstances.
- Right to data portability: Receive your data in a structured, commonly used format.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Right to grievance redressal: Under Indian law, you may file a complaint with the Data Protection Board of India.
To exercise any of these rights, contact us at Admin@sankalpath.com. We will respond within a reasonable timeframe in accordance with applicable law.
11. Policy Updates
This policy is reviewed periodically and updated as necessary to reflect changes in our practices, services, or legal requirements. Material changes will be communicated through our website. We encourage you to review this policy regularly.
12. Contact
For questions or concerns about data protection at Sankalpath:
- Email: Admin@sankalpath.com
- Location: Mumbai, India
See also our Privacy Policy and Cookie Policy for additional information about how we handle your data.
