Legal
Privacy Policy
How we collect, use, store, and protect your data on the 24Squad.in website. Last updated 14 July 2026 — about 8 minutes to read.
Read the policy1. Who we are
24Squad (24Squad) is a holding group managing startups across finance, real estate, digital technology, and HR across India. Our registered address is 24 Square, Nr. Hotel Nandini, Bhavnagar Road, Palitana 364270, Gujarat, India. For the purposes of this policy, we are the data fiduciary — the entity that determines the purpose and means of processing your personal data. This policy applies to every site, page, and form under the 24squad.in domain, including subdomains like git.24squad.in and gitea.24squad.in.
2. The short version
If you only have 60 seconds, here is what we do — and what we deliberately do not do:
- We collect only what we need. Email when you write to us, server logs for 90 days, and the cookies that keep the site working.
- We never sell your data. Not to advertisers, not to data brokers, not to anyone.
- We do not run third-party tracking. No Google Analytics, no Meta Pixel, no Hotjar, no advertising cookies.
- You can ask us to delete your data at any time, and we will action it within 30 days.
- We host in the EU and India. No cross-border transfers to the United States or China.
3. Information we collect
We collect information you provide directly (such as when you email us at [email protected]) and information collected automatically (such as server logs, cookies, and usage analytics).
- Email correspondence: name, email address, and message content you send us. We use this only to reply, never for marketing.
- Server logs: IP address, browser type, referring page, and timestamp. Used for abuse detection and rate limiting.
- Functional cookies: session cookies required for site functionality (admin sign-in, comment thread, language preference). No advertising cookies.
- Aggregated traffic counts: we self-host a privacy-respecting counter (Plausible-style, IP-truncated) to know which pages are read. No per-user profile is built.
4. Cookies and similar technologies
A cookie is a small text file your browser stores at our request. We use the minimum set required to run the site:
- Strictly necessary cookies — set when you sign in to the admin dashboard or to a comment thread. These cannot be disabled without breaking the feature.
- Preference cookies — remember your colour-scheme and locale choice. Optional; you can clear them at any time.
We do not use advertising cookies, third-party analytics pixels, cross-site tracking, or fingerprinting. If we ever change this — for example, to add a feature that requires analytics — we will update this clause and ask for your consent before placing a new cookie.
5. How we use your information
We use the information we collect to:
- Respond to your inquiries and messages.
- Improve our website and services (aggregate trends only).
- Monitor site performance and detect abuse.
- Comply with legal obligations under the IT Act 2000 and the Digital Personal Data Protection Act 2023.
- Maintain the security of our infrastructure.
We do not use your data for automated decision-making, profiling, or targeted advertising.
6. Data sharing and processors
We do not sell your personal information to third parties. We may share your data with the following categories of processors, each bound by a data-processing agreement:
- Hosting: an EU-region VPS provider that runs the site, the database, and our email server. Data stays in the EU.
- Email delivery: a transactional email provider used only for outbound mail you have triggered (verification emails, password resets). We do not subscribe you to a newsletter without an explicit opt-in.
- Domain registrar: for the WHOIS record required by ICANN. WHOIS privacy is enabled on all our domains.
We will never share your data with law enforcement on a voluntary basis. If we receive a legal order, we will challenge it on the merits, notify you unless explicitly prohibited from doing so, and publish the request in our annual transparency report.
7. Data retention
We retain different categories of data for different periods, chosen to be no longer than necessary:
- Email correspondence: up to 12 months from your last message, after which it is archived offline and accessible only to the founder.
- Server logs: 90 days for security monitoring, after which they are aggregated and the per-request fields are dropped.
- Cookies: session cookies expire when you close your browser; preference cookies expire after 12 months.
- Admin account data: deleted within 30 days of account closure. Backups are rotated within 60 days.
8. Your rights
Under the Digital Personal Data Protection Act 2023, the IT Act 2000, and applicable international frameworks (GDPR, where relevant), you have the right to:
- Access the personal data we hold about you, free of charge, once per calendar year.
- Correction of inaccurate or incomplete data.
- Erasure (the “right to be forgotten”) of data that is no longer necessary for the purpose it was collected.
- Withdrawal of consent where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Nomination of another individual to exercise your rights in the event of death or incapacity.
- Complaint to the Data Protection Board of India if you believe our processing is unlawful.
9. Children’s data
Our website is not directed at children under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, please email [email protected] and we will delete the record within 7 days.
10. Security
We protect your data with industry-standard controls:
- TLS 1.3 on every endpoint, with HSTS preload and automatic HTTP→HTTPS redirection.
- Content-Security-Policy headers restricting which scripts and resources can execute on our pages.
- Encrypted-at-rest database storage; backups are encrypted with a separate key.
- Two-factor authentication required for every admin account.
- Quarterly dependency audits to patch known vulnerabilities within 7 days of a CVE being published.
No system is perfectly secure. If you discover a vulnerability, please see our responsible-disclosure programme on the contact page.
11. Breach notification
If we suffer a personal-data breach that is likely to harm you, we will:
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required by the DPDP Act 2023.
- Notify affected individuals without undue delay, with a plain-English description of what was compromised and what we are doing about it.
- Publish a public incident post-mortem within 30 days, including root cause, scope, and remediation steps.
12. International transfers
Our primary hosting is in the European Union, with a secondary read-replica in India for latency. We do not transfer personal data outside these two jurisdictions. If a vendor we use does transfer data, we require them to use Standard Contractual Clauses or an equivalent safeguard approved by the European Commission.
13. Changes to this policy
We may update this policy from time to time. When we do, we will:
- Post the revised version on this page with a new “Last updated” date.
- Highlight material changes in a banner on the home page for at least 14 days.
- For significant changes that broaden what we collect or how we use it, email subscribers to our blog and ask for fresh consent before the change takes effect.
14. Contact and grievance officer
For any privacy-related inquiry — access request, deletion request, complaint, or general question — please email [email protected]. We typically respond within 2 business days.
Under Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our grievance officer is:
- Name: Renish Mithani
- Email: [email protected]
- Response time: within 15 days of receipt, per the IT Rules.
If you are unsatisfied with our response, you may escalate to the Data Protection Board of India or your local consumer forum.
Need help?
Questions about this policy?
We typically respond within 2 business days. For complex requests (access, deletion, portability), please email us directly so we can verify your identity and track the request. Please cite the section number you are asking about (for example, “Section 7 — Data retention”) — it helps us route the message to the right person faster.
Document version v2.0— published 14 July 2026