Legal
Privacy Policy
Effective date: 1 September 2026 · Calcutta Chamber of Trade
Calcutta Chamber of Trade ("CCT", "we", "us") operates the member directory portal at https://calcuttachamberoftrade.com (the "Portal"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules.
By using the Portal — whether as a visitor, a registered member, or an administrator — you acknowledge that you have read and understood this policy.
1. Who We Are (Data Fiduciary)
The Calcutta Chamber of Trade is the Data Fiduciary as defined under the DPDP Act 2023.
Grievance / Data Protection contact: [email protected]
2. Data We Collect and Why
2.1 Visitors (no account)
| Data | Detail | Legal basis / Role |
|---|---|---|
| Server logs | IP address, browser type, pages visited, referrer URL | Legitimate interest — security, abuse prevention, analytics |
| Cookies | Session cookie (authentication state), localStorage preference flags (e.g. ticker dismissed) | Strictly necessary for site function |
2.2 Members (registered accounts)
| Data | Detail | Legal basis / Role |
|---|---|---|
| Account credentials | Registered email address, bcrypt-hashed OTP tokens | Contract performance — enabling secure login |
| Business profile | Company name, owner name, trade type, membership tier, address, phone, website, GST number, product/service list, description | Contract performance — publishing your directory listing |
| Catalogue uploads | Product images and files you upload, titles | Contract performance — displaying your catalogue on your profile |
| Membership data | Tier, ad-tier (Gold/Silver/Bronze), application number, renewal dates | Contract performance — administering your membership |
| Edit history | Pending profile and catalogue change requests with before/after snapshots | Legitimate interest — audit trail, dispute resolution |
| Login activity | OTP attempt timestamps, IP address, success/failure | Legitimate interest — fraud and abuse prevention |
2.3 Membership applicants
| Data | Detail | Legal basis / Role |
|---|---|---|
| Application data | Name, email, business details submitted via the membership form | Pre-contractual steps at your request |
| Payment data | Stripe processes card details directly; we receive only a transaction reference and status | Contract performance — confirming payment |
2.4 Exit feedback (optional)
| Data | Detail | Legal basis / Role |
|---|---|---|
| Feedback widget | Emoji rating, optional comment, optional email address | Legitimate interest — improving the Portal; consent where email is provided |
3. How We Use Your Data
- To publish and maintain your business listing in the Members' Directory.
- To authenticate your login via email OTP and manage your session.
- To process membership applications and renewals.
- To send transactional emails — OTP codes, submission confirmations, approval/rejection notices — from [email protected].
- To allow the Chamber office to review and approve profile edits and catalogue changes before they go live.
- To send broadcast communications to members (e.g. notices, announcements) where you have not opted out.
- To detect and prevent fraud, abuse, and unauthorised access.
- To comply with legal obligations under Indian law.
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
4. Data Sharing
| Data | Detail | Legal basis / Role |
|---|---|---|
| GoDaddy (hosting & database) | Server infrastructure and MySQL database hosting | Data processor under contract |
| Stripe | Payment processing for membership fees | Independent data controller for card data; PCI-DSS compliant |
| GoDaddy Email Essentials (SMTP) | Transactional email delivery | Data processor under contract |
| Chamber administrators | Authorised staff who review pending approvals and manage the directory | Internal access, role-limited |
All processors are contractually bound to process data only on our instructions and to maintain appropriate security. We do not transfer personal data outside India except where the above processors operate infrastructure abroad, in which case standard contractual protections apply.
5. Public Visibility of Your Business Profile
Your business name, trade type, membership tier, address, phone number, website, GST number, product list, description, and catalogue are published publicly on the Portal and indexed by search engines. This is the core purpose of the directory. If you wish to remove or amend any publicly visible information, log in to your dashboard and submit an edit request, or contact us at [email protected].
Your email address and login credentials are never displayed publicly.
6. Data Retention
| Data | Detail | Legal basis / Role |
|---|---|---|
| Active member profile | Retained for the duration of active membership plus 3 years after lapse | |
| Pending approval records | Retained for 3 years from the date of decision | |
| OTP tokens | Deleted automatically after 15 minutes (used or expired) | |
| Login attempt logs | Retained for 90 days | |
| Membership applications (unpaid / rejected) | Retained for 1 year then deleted | |
| Exit feedback | Retained for 12 months in aggregate, anonymised thereafter | |
| Server access logs | Retained for 90 days |
7. Security
- All connections to the Portal use TLS encryption (HTTPS).
- The database connection uses SSL/TLS in transit.
- Passwords and OTP tokens are stored as bcrypt hashes — never in plain text.
- Admin access is protected by a separate credential layer and is not accessible to regular members.
- OTP login enforces a rate limit of 5 attempts per 15 minutes per email address.
- Database credentials are injected at runtime from a platform-managed secure config store and are not present in source code.
No system is perfectly secure. In the event of a data breach that is likely to result in harm to you, we will notify you and the relevant authority as required under applicable law.
8. Your Rights (DPDP Act 2023)
As a Data Principal under the DPDP Act 2023, you have the following rights:
| Data | Detail |
|---|---|
| Right to access | Request a summary of personal data we hold about you |
| Right to correction | Request correction of inaccurate or incomplete data |
| Right to erasure | Request deletion of your personal data (subject to legal retention obligations) |
| Right to grievance redressal | Lodge a complaint with our Grievance Officer (contact below) |
| Right to nominate | Nominate another person to exercise rights on your behalf in the event of death or incapacity |
To exercise any of these rights, email [email protected] with the subject line "DPDP Rights Request". We will respond within 30 days.
9. Cookies and Local Storage
| Data | Detail | Legal basis / Role |
|---|---|---|
| Session cookie | Keeps you logged in during your browser session | Strictly necessary — no consent required |
| localStorage: ticker_dismissed | Remembers if you closed the homepage notice ticker | Strictly necessary for UI function |
| localStorage: exit_feedback_suppressed | Suppresses the exit feedback widget for 45 days after submission | Strictly necessary for UI function |
We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify individuals.
10. Children's Privacy
The Portal is intended for business use by adults. We do not knowingly collect personal data from persons under 18 years of age. If you believe a minor has submitted data to us, please contact us immediately at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect the most recent revision. For material changes, we will notify registered members by email. Continued use of the Portal after the effective date constitutes acceptance of the revised policy.
12. Grievance Officer
10, Canning Street, 3rd Floor, Kolkata – 700001, West Bengal, India
Email: [email protected]
Phone: +91 33 4801 6855
Response time: within 30 days of receipt
If you are not satisfied with our response, you may approach the Data Protection Board of India once constituted under the DPDP Act 2023, or seek remedies under the Information Technology Act, 2000.