Data processing notice
Version 1 · last updated
This notice sets out how Pawnanigans handles personal data under India's Digital Personal Data Protection Act, and who to contact if something has gone wrong. It sits alongside the privacy policy rather than replacing it.
Who is responsible
Pawnanigans is the Data Fiduciary for the personal data described in the privacy policy. That means we decide why and how it is processed, and we answer for it.
| Role | Contact |
|---|---|
| Data Fiduciary | Pawnanigans, 123 Furry Avenue, Pet Haven District |
| Grievance Officer | [email protected] — marked “Grievance Officer” |
| Response time | Acknowledged within 72 hours, resolved within 30 days |
What we process, and why
Every purpose is listed in the privacy policy with the data it uses. In DPDP terms, processing rests either on your consent — which you gave in the banner or the preference centre, and can withdraw in the same place — or on a legitimate use, such as keeping the service secure and meeting a legal obligation like tax records.
Your rights as a Data Principal
- Access — a copy of everything we hold, from Settings → Privacy. It arrives as a downloadable archive.
- Correction — edit your profile, pets and records in the app; write to us for anything you cannot reach.
- Erasure — request deletion from Settings → Privacy. We confirm by email, wait a grace period, then anonymise the account.
- Withdrawal of consent — the preference centre, at any time, with immediate effect.
- Grievance redressal — the officer above. If you are not satisfied, you may complain to the Data Protection Board of India.
- Nomination — you may nominate someone to exercise these rights if you are unable to. Write to us and we will record it.
How long we keep it
Personal data is erased when the purpose it was collected for is finished, unless the law requires us to keep it. Two exceptions are deliberate and recorded on every erasure: invoices, which tax law requires, and moderation decisions, which stay reviewable.
Where the data goes
Our processors — payments, media storage, email, push and hosting — are named in the privacy policy. Some are outside India, and personal data is transferred to them only where the transfer is permitted and under contracts that hold them to the same standards.