Home/Privacy Policy
LegalPrivacy Policy.
Version 2026-07 · Effective 1 July 2026 · Framed under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000
Next Imaginations (“we”, “us”, the “Studio”), an independent IT and digital studio based in Chandigarh, India, is the Data Fiduciary for the personal data described in this policy. We collect the minimum we need, we tell you plainly why, and we give you working controls, not just promises — over your data.
01What we collect, and why
- Enquiries: your name, email, company (optional), area of interest and message, so we can respond to you. Legal basis: your explicit consent, given via the checkbox on the form.
- Accounts: your name, email, phone and company (both optional), and a securely hashed password — to operate your client account. Legal basis: consent given at registration.
- Orders & payments: project titles, values, payment methods and references — to run your engagement and meet our accounting obligations. Legal basis: performance of contract and legal obligation.
- Technical data: IP address and browser identifier on enquiries and sign-ins — for security, fraud prevention and rate-limiting. Legal basis: legitimate use for security.
We do not buy, sell, rent or trade personal data. We do not use advertising trackers or analytics cookies. We do not profile you.
02Consent, and withdrawing it
We process your personal data on the basis of consent that is free, specific, informed and unambiguous, requested in clear language at the moment of collection. You may withdraw consent at any time — by deleting your account from your dashboard, or by writing to us, and withdrawal is as easy as giving consent was. Withdrawal does not affect processing already carried out, or data we must retain by law.
03Cookies
We set exactly one cookie: an essential, httpOnly session cookie that keeps you signed in to your account. It contains no personal data, is not readable by scripts, and is not used for tracking. No third-party cookies are set by this website.
04One-time codes and email
We send one-time codes to your email for verification, sign-in, two-step verification and account deletion. Codes are stored only as cryptographic hashes, are valid for 10 minutes, allow five attempts, and are single-use. If you opt in to updates, you can opt out at any time from your profile or via any such email.
05Your rights
Under the DPDP Act, 2023 you have the right to:
- Access — a summary of your personal data and how it is processed. Your dashboard offers a one-click JSON export.
- Correction & completion — edit your details directly from your profile at any time.
- Erasure — delete your account yourself, instantly, from the dashboard. Personal data is erased immediately; orders and payments are anonymised (all identifiers removed) because Indian tax law requires transaction records to be retained.
- Grievance redressal — raise a concern with us as described below, and escalate to the Data Protection Board of India if unresolved.
- Nominate — nominate a person to exercise these rights on your behalf in the event of death or incapacity, by writing to us.
06How long we keep data
- Enquiries: up to 24 months from last contact, then deleted or anonymised.
- Accounts: for as long as your account exists. Deletion is immediate on your request.
- Orders & payments: retained (anonymised after account deletion) for 8 years, as required under Indian tax and GST law.
- One-time codes: purged on use or expiry; sign-in sessions expire after 30 days.
07Security
Reasonable security safeguards protect your data: passwords hashed with bcrypt, one-time codes stored as hashes, httpOnly cookies, TLS in transit, strict rate-limiting on all authentication endpoints, and access limited to the people who need it to serve you. In the unlikely event of a personal data breach, we will notify the Data Protection Board of India and affected users as the Act requires.
08Sharing and transfers
Your data is shared only with the infrastructure providers that host this website and deliver email, bound by their own contractual safeguards, and with authorities where the law compels us. We do not transfer personal data to any country restricted by the Central Government under the DPDP Act.
09Children
Our services are intended for people aged 18 and over. We do not knowingly process the personal data of children, and account registration requires confirmation of age. If you believe a child’s data has been provided to us, contact us and we will erase it.
10Grievance Officer
Concerns and rights requests are handled by our Grievance Officer at the founder’s desk:
Email: nextimaginations@gmail.com (subject line “Privacy”) · Phone: +91 89300 06242
We acknowledge grievances promptly and resolve them within 30 days. If you remain unsatisfied, you may approach the Data Protection Board of India.
11Changes to this policy
If we change this policy, we will update the version and effective date above and, for material changes affecting account holders, notify you by email. Continued use after notice constitutes acceptance; where fresh consent is required by law, we will ask for it.