Privacy notice

Your information, used for a clear purpose.

Who handles your information

Code Commit is the student-run tech club at BIET Davangere. The club organisers handle information collected through this website. This notice is dated 6 October 2026. An official privacy contact has not yet been provided; use the Contact form or the signed-in privacy request form to reach the organisers.

What we collect and why

Account: email and sign-in information for authentication and account security. Membership: name, college/personal email, phone, USN, branch, semester, professional profile links, skills, projects, and motivation to assess eligibility and communicate decisions. Events: name, email, phone, optional USN/semester, payment reference and screenshot to manage attendance and verify fees. Contact: name, email, topic and message to respond. We record consent choices, policy versions, timestamps, privacy requests, and review decisions for accountability.

Consent and email choices

Membership and event forms ask for affirmative consent to their stated processing purpose. Optional marketing is a separate, unticked choice and is never a condition of approval. Switch marketing off at any time in My account. Essential sign-in, application, safety and event messages are not marketing. No marketing mailing service is connected at present; choosing yes records permission, not a promise that a campaign will be sent.

Access, sharing and publication

Authorised organisers see only the dashboard sections assigned to them. Application and registration details are not public. Cloud hosting, authentication, private image storage and email delivery providers process data needed to run the site. LinkedIn, GitHub and other external websites have their own policies. We do not sell personal data or grant sponsors access to applications. Public team, alumni or partner entries must be published only with the relevant person’s permission.

Security and retention

Access is checked on the server and protected by data-access policies. Photos and payment proofs use private storage and temporary signed links. Consent and decision history are recorded. No system can guarantee absolute security. Organisers should review records when an application, event or membership purpose ends, erase data no longer needed, and retain only what is required for legal obligations or unresolved disputes. Automatic retention deletion and a fixed retention schedule are not configured yet.

Your choices and requests

In My account you can change marketing choices and submit access, correction, erasure, consent withdrawal, grievance or nomination requests. Organisers verify identity and respond through the request record. Withdrawing consent for necessary processing may prevent continuing the related application or registration; it does not invalidate processing already carried out. Erasure requests are reviewed, not automatically executed, because legal obligations or disputes may require some records to be retained. Do not include passwords or identification documents in a request.

People under 18

The online membership and event forms are restricted to people confirming they are 18 or older. This is self-declaration, not age verification. Under-18 participants should contact organisers without sending personal or payment information to arrange an appropriate guardian-assisted process. Verifiable parental consent is not implemented here. We do not run targeted advertising or behavioural tracking for children.

India’s digital personal data framework

This notice is designed around the Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025, including purpose-specific notices, affirmative consent, withdrawal, limited access and grievance handling. The 13 November 2025 notifications phase in the framework: core notice, consent and data-principal rights provisions are scheduled for 13 May 2027, and the consent-manager stage for 13 November 2026. As of 6 October 2026, core obligations have not yet commenced. Other applicable laws may still impose obligations. This website does not claim legal certification or complete DPDP compliance. The club must confirm its legal responsibilities, privacy contact, retention schedule, incident response arrangements and any guardian-consent process with qualified counsel.

Changes and complaints

Material changes to processing purposes require an updated notice and fresh consent where required. Previous consent versions remain in history. Raise a concern with the club first through Contact or a privacy grievance request. Any statutory escalation to the Data Protection Board of India is subject to the applicable provisions and procedures being in force.

Official references: Act commencement notification, DPDP Rules, 2025, and the DPDP Act, 2023.