Skip to content

Legal

Privacy Policy

Last updated 07 August, 2026

Privacy Policy

Effective date: 7 August 2026

Mindrolling operates the website situated at mindrollingtrusts.com together with the digital services accessible therethrough. The present Policy sets forth the manner in which personal data are collected, the purposes for which they are processed, the circumstances in which they may be disclosed, and the rights exercisable by the individuals to whom such data relate.

Mindrolling stands as the data fiduciary in respect of the processing herein described.

Use of the Site constitutes acknowledgement that the present Policy has been read. Those who do not accept its terms ought not to proceed further.

  1. Interpretation

Within this Policy the expression “personal data” denotes any information relating to an identified or identifiable natural person.

“Processing” encompasses any operation or set of operations performed upon personal data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure or destruction.

“User Content” signifies any comment, observation or other material posted, uploaded or otherwise submitted by a user upon the Site.

“Data Principal” means the natural person to whom the personal data relate.

“Data Fiduciary” means the person who alone or jointly with others determines the purposes and means of the processing of personal data. That person is Mindrolling.

  1. Scope of application

The Policy governs personal data processed in the course of visiting the Site, establishing or maintaining an account, submitting User Content, corresponding with us, or otherwise engaging with the facilities of the Site.

It has no application to websites or services operated by third parties and merely linked from the Site. Such third parties are governed by their own notices.

  1. Categories of personal data processed

Personal data are obtained only where requisite for the purposes later enumerated.

Data furnished by the individual
Upon registration of an account the following are recorded: name, electronic mail address, chosen username and password. The password is retained solely in hashed form. Additional profile particulars may be supplied at the individual’s election.
Where comments or other material are posted, that content is retained together with the temporal metadata of its submission.
The substance of any communication addressed to us is likewise retained.

Data generated through use of the Site
The Internet Protocol address, browser type and version, operating system, device characteristics and an approximate geographical indication derived from the Internet Protocol address are recorded.
Server logs capture the pages consulted, the dates and times of access, and the referring address.
Cookies and analogous technologies are confined to those strictly indispensable for the operation and security of the Site. Particulars appear in the Cookie Policy.

No deliberate collection is undertaken of special-category personal data, namely data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation. Inclusion of any such data within User Content remains the sole responsibility of the individual who posts it.

The Site is not directed to persons under the age of eighteen years. No personal data are knowingly collected from children beneath that age.

  1. Means of collection

The greater part of personal data reaches us directly from the individual upon registration, submission of content or correspondence.
The residue is generated automatically by the technical systems of the Site and by the strictly necessary cookies during the course of use.
Personal data are not acquired by purchase from external brokers or list providers.

  1. Purposes of processing

Personal data are processed exclusively for the ends hereunder stated.

They are processed in order to establish, maintain and secure user accounts and to enable the exercise of the facilities attached thereto.
They are processed in order to operate the Site and to render accessible the content appearing thereon, inclusive of material contributed by users.
They are processed in order to host, display and, where occasion requires, moderate User Content in conformity with the Terms.
They are processed in order to detect, investigate and counteract fraud, abuse and threats to security, and to uphold the Terms.
They are processed in order to respond to communications received and to transmit notices pertaining to the service itself.
They are processed where a legal obligation so requires or where a court or competent public authority issues a lawful demand.
Limited technical data are processed in order to preserve the proper functioning of the Site, to distribute load and to identify operational faults.

Where the applicable law conditions processing upon consent, such consent is obtained and must be free, specific, informed and unambiguous. Consent may be withdrawn at any subsequent time. Withdrawal leaves unaffected the lawfulness of processing already completed.

Personal data are not employed for automated decision-making productive of legal or similarly significant effects, nor for advertising predicated upon behavioural tracking.

  1. Cookies and kindred technologies

Solely those cookies and similar technologies that are strictly necessary for the Site to perform its essential functions and to maintain its security are deployed. The Cookie Policy, which forms an integral part of the present document, sets out the relevant particulars.

Control over cookies may be exercised through the settings of the browser. Refusal of the necessary cookies may render certain functions of the Site inoperable.

  1. Disclosure of personal data

Personal data are not sold.

Disclosure occurs only in the following contingencies:

Third-party processors engaged for hosting, security or electronic-mail delivery receive such data as are requisite for the performance of their contracted functions. They are bound by written agreements imposing duties of confidentiality and of protection commensurate with those herein and with the law.
Disclosure is made when mandated by statute, regulation, judicial order or a lawful requisition emanating from a competent public authority.
Disclosure may be made where there exists a good-faith belief that it is necessary for the protection of the rights, property or safety of Mindrolling, of the users of the Site, or of the public, or for the investigation of fraud or of security incidents.
In the event of a sale, merger or reorganisation of the undertaking, personal data may pass to the successor entity, which shall remain bound by obligations of protection no less rigorous than those contained in this Policy.

User Content placed in the public areas of the Site is accessible to other visitors and may be reproduced or indexed by parties beyond our control. Responsibility for any personal data embedded in such content rests with the individual who posted it.

  1. Cross-border transfers

The predominant part of processing is conducted within India. Certain processors maintain facilities in other jurisdictions, with the consequence that personal data may be transferred outside India.

Upon any such transfer the contractual or other safeguards prescribed by applicable law are instituted.

  1. Duration of retention

Personal data are retained only for so long as the original purpose of collection continues or as the law obliges retention.

Account data endure for the subsistence of the account and for a circumscribed period thereafter, sufficient to permit restoration of the account if required or to satisfy residual legal duties.
User Content remains accessible upon the Site until deleted by the individual or until the account is terminated. Residual copies may persist for a limited technical interval within secure backup systems.
Log and security records are conserved for the period demanded by security considerations and legal compliance, following which they are erased or rendered anonymous.
Correspondence is retained whilst the matter remains current and for a brief interval after its conclusion.

Once personal data cease to be required for any lawful purpose they are deleted or irreversibly anonymised.

  1. Measures of security

Technical and organisational measures proportionate to the character of the data and to the risks attendant upon their processing are applied. Access is controlled. Data in transit are encrypted where the circumstances render encryption appropriate. Arrangements are subject to periodic review. Processors are held to contractual standards.

No method of transmission or of storage can be rendered wholly invulnerable. Absolute security cannot be assured.

  1. Rights of the Data Principal

Pursuant to the Digital Personal Data Protection Act, 2023 and to other applicable law, the Data Principal enjoys the following rights, subject always to the conditions and limitations imposed by that law:

to obtain confirmation whether personal data concerning him or her are being processed and to receive a copy of such data;
to require rectification of inaccurate or incomplete personal data;
to require erasure of personal data in the circumstances which the law permits;
to withdraw consent where processing rests upon consent;
to present a grievance concerning the manner in which personal data have been handled;
to nominate another person to exercise the foregoing rights in the event of death or incapacity, where the law so provides.

Any exercise of these rights is to be effected by written communication addressed to the contact particulars published upon the Site. Verification of identity may be required. A response will be furnished within the period prescribed by law.

Certain of the rights may be curtailed where retention is mandated by law or where the data are required for the establishment, exercise or defence of legal claims.

Should the response prove unsatisfactory, recourse may be had to the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023.

  1. Personal data of children

The Site is not directed to persons under the age of eighteen years. Personal data of such persons are not knowingly collected.

Upon discovery that personal data of a child under eighteen have been obtained without proper authority, the data will be deleted without delay.

A parent or legal guardian who believes that a child has furnished personal data should communicate with us forthwith.

  1. Revision of the Policy

The Policy may be amended when alterations occur in practices, in the applicable law, or in the features of the Site.

The amended text will be published upon the Site bearing a revised effective date. Material amendments will be signalled by notice upon the Site.

Continued use of the Site after publication of the revised Policy is treated as acceptance of the alterations, save where the law demands the obtaining of fresh consent.

  1. Communication and redress

Enquiries concerning this Policy, requests for the exercise of rights, and grievances are to be directed to the contact address appearing upon the Site.

Grievances will be acknowledged and will be addressed within the periods fixed by law.

Should a grievance remain unresolved, the Data Principal may refer the matter to the Data Protection Board of India under the procedure established by the Digital Personal Data Protection Act, 2023.

  1. Governing law and forum

The present Policy is governed by the laws of India.

Subject to any rights rendered mandatory by the law of the Data Principal’s place of residence, disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at New Delhi, India.

This Policy is to be construed in conjunction with the Terms and Conditions and the Cookie Policy.