Legal

Privacy Policy

Effective date: 1 September 2026  ·  Calcutta Chamber of Trade

Calcutta Chamber of Trade ("CCT", "we", "us") operates the member directory portal at https://calcuttachamberoftrade.com (the "Portal"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules.

By using the Portal — whether as a visitor, a registered member, or an administrator — you acknowledge that you have read and understood this policy.


1. Who We Are (Data Fiduciary)

The Calcutta Chamber of Trade is the Data Fiduciary as defined under the DPDP Act 2023.

Registered address: 10, Canning Street, 3rd Floor, Kolkata – 700001, West Bengal, India
Grievance / Data Protection contact: [email protected]

2. Data We Collect and Why

2.1 Visitors (no account)

DataDetailLegal basis / Role
Server logsIP address, browser type, pages visited, referrer URLLegitimate interest — security, abuse prevention, analytics
CookiesSession cookie (authentication state), localStorage preference flags (e.g. ticker dismissed)Strictly necessary for site function

2.2 Members (registered accounts)

DataDetailLegal basis / Role
Account credentialsRegistered email address, bcrypt-hashed OTP tokensContract performance — enabling secure login
Business profileCompany name, owner name, trade type, membership tier, address, phone, website, GST number, product/service list, descriptionContract performance — publishing your directory listing
Catalogue uploadsProduct images and files you upload, titlesContract performance — displaying your catalogue on your profile
Membership dataTier, ad-tier (Gold/Silver/Bronze), application number, renewal datesContract performance — administering your membership
Edit historyPending profile and catalogue change requests with before/after snapshotsLegitimate interest — audit trail, dispute resolution
Login activityOTP attempt timestamps, IP address, success/failureLegitimate interest — fraud and abuse prevention

2.3 Membership applicants

DataDetailLegal basis / Role
Application dataName, email, business details submitted via the membership formPre-contractual steps at your request
Payment dataStripe processes card details directly; we receive only a transaction reference and statusContract performance — confirming payment

2.4 Exit feedback (optional)

DataDetailLegal basis / Role
Feedback widgetEmoji rating, optional comment, optional email addressLegitimate interest — improving the Portal; consent where email is provided

3. How We Use Your Data

  • To publish and maintain your business listing in the Members' Directory.
  • To authenticate your login via email OTP and manage your session.
  • To process membership applications and renewals.
  • To send transactional emails — OTP codes, submission confirmations, approval/rejection notices — from [email protected].
  • To allow the Chamber office to review and approve profile edits and catalogue changes before they go live.
  • To send broadcast communications to members (e.g. notices, announcements) where you have not opted out.
  • To detect and prevent fraud, abuse, and unauthorised access.
  • To comply with legal obligations under Indian law.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.


4. Data Sharing

DataDetailLegal basis / Role
GoDaddy (hosting & database)Server infrastructure and MySQL database hostingData processor under contract
StripePayment processing for membership feesIndependent data controller for card data; PCI-DSS compliant
GoDaddy Email Essentials (SMTP)Transactional email deliveryData processor under contract
Chamber administratorsAuthorised staff who review pending approvals and manage the directoryInternal access, role-limited

All processors are contractually bound to process data only on our instructions and to maintain appropriate security. We do not transfer personal data outside India except where the above processors operate infrastructure abroad, in which case standard contractual protections apply.


5. Public Visibility of Your Business Profile

Your business name, trade type, membership tier, address, phone number, website, GST number, product list, description, and catalogue are published publicly on the Portal and indexed by search engines. This is the core purpose of the directory. If you wish to remove or amend any publicly visible information, log in to your dashboard and submit an edit request, or contact us at [email protected].

Your email address and login credentials are never displayed publicly.


6. Data Retention

DataDetailLegal basis / Role
Active member profileRetained for the duration of active membership plus 3 years after lapse
Pending approval recordsRetained for 3 years from the date of decision
OTP tokensDeleted automatically after 15 minutes (used or expired)
Login attempt logsRetained for 90 days
Membership applications (unpaid / rejected)Retained for 1 year then deleted
Exit feedbackRetained for 12 months in aggregate, anonymised thereafter
Server access logsRetained for 90 days

7. Security

  • All connections to the Portal use TLS encryption (HTTPS).
  • The database connection uses SSL/TLS in transit.
  • Passwords and OTP tokens are stored as bcrypt hashes — never in plain text.
  • Admin access is protected by a separate credential layer and is not accessible to regular members.
  • OTP login enforces a rate limit of 5 attempts per 15 minutes per email address.
  • Database credentials are injected at runtime from a platform-managed secure config store and are not present in source code.

No system is perfectly secure. In the event of a data breach that is likely to result in harm to you, we will notify you and the relevant authority as required under applicable law.


8. Your Rights (DPDP Act 2023)

As a Data Principal under the DPDP Act 2023, you have the following rights:

DataDetail
Right to accessRequest a summary of personal data we hold about you
Right to correctionRequest correction of inaccurate or incomplete data
Right to erasureRequest deletion of your personal data (subject to legal retention obligations)
Right to grievance redressalLodge a complaint with our Grievance Officer (contact below)
Right to nominateNominate another person to exercise rights on your behalf in the event of death or incapacity

To exercise any of these rights, email [email protected] with the subject line "DPDP Rights Request". We will respond within 30 days.


9. Cookies and Local Storage

DataDetailLegal basis / Role
Session cookieKeeps you logged in during your browser sessionStrictly necessary — no consent required
localStorage: ticker_dismissedRemembers if you closed the homepage notice tickerStrictly necessary for UI function
localStorage: exit_feedback_suppressedSuppresses the exit feedback widget for 45 days after submissionStrictly necessary for UI function

We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify individuals.


10. Children's Privacy

The Portal is intended for business use by adults. We do not knowingly collect personal data from persons under 18 years of age. If you believe a minor has submitted data to us, please contact us immediately at [email protected].


11. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect the most recent revision. For material changes, we will notify registered members by email. Continued use of the Portal after the effective date constitutes acceptance of the revised policy.


12. Grievance Officer

Calcutta Chamber of Trade
10, Canning Street, 3rd Floor, Kolkata – 700001, West Bengal, India
Email: [email protected]
Phone: +91 33 4801 6855
Response time: within 30 days of receipt

If you are not satisfied with our response, you may approach the Data Protection Board of India once constituted under the DPDP Act 2023, or seek remedies under the Information Technology Act, 2000.