Website policy
PRIVACY POLICY
This Privacy Policy explains how NitishJindal.com receives, uses, stores, protects and may disclose personal data, including information submitted through the Website’s public-interest reporting service and information sent for professional correspondence.
Nitish Jindal is the operator of this Website and the contact for privacy and reporting-data matters. Questions, requests or grievances may be sent to nj@nitishjindal.com.
1. SCOPE AND STATUS OF THE WEBSITE
This Policy applies to NitishJindal.com, including its public pages, correspondence routes, public-interest reporting service, technical security systems and Website features that process personal data. It should be read with the Terms of Use and Disclaimer.
The Website is an independent platform. It is not a statutory complaint portal, emergency service, law-enforcement service, protected whistleblower system, legal practice, medical service, financial advisory service or government reporting system.
2. PERSONAL DATA WE MAY RECEIVE
The Website may receive:
- Public-interest reporting data: the matter submitted, country, optional name, optional mobile number, optional email address, report reference, status, review-related event information and limited technical data needed to operate, secure and rate-limit the service.
- Correspondence data: information voluntarily sent by email or another authorised route, such as name, organisation, country, email address, enquiry type, subject, message and information reasonably necessary to understand or respond.
- Technical and security data: information that hosting, network or security providers may process, such as IP address, browser or device information, request time, requested URL, security signals and error information.
File uploads and attachments are disabled at the public-interest reporting form and server.
Do not send passwords, banking credentials, trade secrets, privileged documents, highly sensitive personal data or confidential commercial information through general correspondence. Do not submit another person’s personal data unless it is reasonably necessary for a lawful report and you have a lawful basis to provide it.
3. PURPOSES AND LAWFUL PROCESSING
Personal data may be processed, where reasonably necessary and lawful, to:
- receive, review and assess a public-interest report;
- assess credibility, safety, urgency or possible next steps;
- seek clarification where contact details were voluntarily supplied;
- respond to professional or general correspondence;
- prevent abuse, spam, fraud, malicious activity or security threats;
- maintain service integrity, rate limiting, troubleshooting and operational records;
- comply with law, lawful process or a competent authority;
- protect the rights, safety or legitimate interests of the operator or another person;
- prepare a responsible referral where lawful and considered appropriate; or
- establish, exercise or defend legal claims.
Where processing depends on consent, consent will be sought through clear affirmative action and may be withdrawn by contacting nj@nitishjindal.com. Withdrawal does not affect processing already lawfully undertaken and does not require deletion where retention remains necessary or authorised by law.
Personal data is not sold. Reports are not automatically emailed, published, forwarded or referred to an authority. Submission does not guarantee investigation, referral, response or any outcome.
4. PUBLIC-INTEREST REPORTING AND ANONYMITY
Name, mobile number and email address are optional. Optional contact details are stored separately from the main report and linked by the report reference. This technical separation is not independent organisational separation and does not prevent access by an authorised Website administrator where reasonably necessary.
No online service can guarantee absolute anonymity or confidentiality. Hosting, network and security providers may process technical request information even when a reporter provides no name or contact details.
The reporting service is not an emergency service or a formally protected whistleblower channel. Anyone facing immediate danger should contact the appropriate emergency or law-enforcement authority. If disclosure could create a serious safety, legal, employment, retaliation or security risk, use an appropriate official or specialist protected-reporting channel.
5. STORAGE, SECURITY, LOGGING AND RETENTION
The reporting form uses HTTPS POST and the Website enforces HSTS. Reports are stored in access-restricted database tables within the Website’s managed WordPress hosting environment. Optional contact details are held in a separate linked table. Hosting, infrastructure and security providers may have administrative access under their own systems, contracts and controls.
Reasonable administrative and technical safeguards are used to reduce the risk of unauthorised access, misuse, loss, alteration or disclosure. The reporting application exposes no public route intended to read report or contact records. No internet-connected service can guarantee complete security.
The reporting endpoint may use a short-lived pseudonymous value derived from network and browser request data to limit repeated submissions. Minimal operational event records may contain a report reference, event type and time. Report text and optional contact details are not intended to be copied into ordinary application log messages. Hosting, network and security providers may maintain request or security logs under their own retention controls.
New reports and linked optional contact details are assigned a 180-day retention end. Expired records are deleted during a subsequent reporting-service operation or maintenance cycle, so deletion may occur after the exact retention time. Provider backup, recovery or security copies may remain for the applicable provider-controlled recovery period.
Data may be retained longer where reasonably necessary to comply with law, respond to lawful process, protect a person, preserve evidence for a responsible safety or legal process, investigate abuse, or establish or defend legal rights. Professional correspondence may be retained for as long as reasonably necessary for the purpose for which it was received.
If a personal-data breach occurs, affected persons and the competent authority will be informed where required by applicable law.
6. DISCLOSURE AND INTERNATIONAL PROCESSING
Personal data may be disclosed only where reasonably necessary and lawful, including:
- to hosting, infrastructure, security, email or technology providers supporting the Website;
- to professional advisers for legal, security or compliance purposes;
- to an appropriate authority, organisation or responsible recipient where a referral is lawful and considered appropriate;
- where required by law, court order, lawful process or a competent authority;
- to prevent serious harm, fraud, abuse or security threats; or
- to establish, exercise or defend legal rights.
Some providers may process or store data outside the user’s country. Such processing remains subject to applicable law and the provider’s contractual, privacy and security arrangements.
7. COOKIES, MEASUREMENT AND EXTERNAL SERVICES
The Website may use technologies that are strictly necessary for operation, security and abuse prevention. If non-essential analytics or measurement technologies are enabled, the Website will provide any notice or consent required by applicable law and update this Policy where appropriate.
The Website may display, embed or link to market-information, social-media, news and other external services. Those organisations operate under their own privacy policies, cookies, security controls and terms. The Website operator does not control their independent processing practices.
8. PRIVACY RIGHTS, WITHDRAWAL AND GRIEVANCES
Subject to applicable law, a person may request:
- access to a summary of personal data and relevant processing information;
- correction, completion or updating of personal data;
- deletion of personal data;
- withdrawal of consent where consent is the basis of processing;
- grievance redressal; or
- nomination of another individual to exercise applicable rights in the event of death or incapacity.
Requests or grievances should be sent to nj@nitishjindal.com. For a public-interest report, include the report reference and enough information to assess and securely process the request. Identity or authority may need to be verified. A request may be restricted or refused where permitted or required by law, including where retention is necessary for safety, evidence, legal process or legal claims.
The operator will respond within the period required by applicable law. Where applicable, a person may complain to the Data Protection Board of India after first using the Website’s grievance route.
9. CHILDREN AND SAFEGUARDING
The public-interest reporting form is intended for persons aged 18 or over. A person under 18 should not use the general reporting form or submit personal data through it.
Where a matter concerns the safety or welfare of a child, contact the competent child-protection, police, emergency or other authorised service. An adult making a lawful report concerning a child should provide only information reasonably necessary for the matter. Nothing in this Policy requires a child to contact a parent or guardian where doing so could place the child or another person at risk.
10. CHANGES AND CONTACT
This Policy may be revised to reflect changes in the Website, technology, service providers, law or operating practices. The revised date will be displayed below. Material changes should ordinarily operate prospectively unless applicable law requires otherwise.
Privacy questions, requests and grievances: nj@nitishjindal.com
Effective: 2 August 2026 Revised: 7 September 2026