Privacy Notice
What we collect, why, and what you can do about it.
This notice is given under Section 5 of India's Digital Personal Data Protection Act, 2023 (the DPDP Act). It explains, in plain language, the personal data Dairy Diaries processes and the rights you have as a Data Principal.
Version 2026-08-14.1 · Effective 14 August 2026
1. Who is responsible for your data
Dairy Diaries is the Data Fiduciary for the personal data described below — meaning we decide why and how it is processed, and we are accountable for it.
- Trading name
- Dairy Diaries
- Legal entity
- Dairy Diaries
- Privacy contact
- privacy@dairydiaries.com
2. What we collect, why, and for how long
We collect only what a specified purpose actually needs. Where the basis is consent, you gave it by ticking a box — never by simply using the site.
| Category | What it includes | Why we process it | Legal basis | How long we keep it |
|---|---|---|---|---|
| Account identity | Name, email address, password (stored only as a salted hash by Supabase Auth), optional phone number and avatar. | Creating and operating your account and signing you in. | Consent (s.6) — given at registration. | For as long as your account is open, then 90 days after you ask us to close it. |
| Purchase and payment records | Order and purchase records, amount paid, payment status, and the payment reference IDs returned by Razorpay. We never receive or store your card, UPI or bank details. | Taking payment, granting access to what you bought, refunds, invoicing and tax records. | Consent (s.6), and retention thereafter as a legal obligation. | 8 years from the end of the financial year in which the transaction took place, to meet statutory tax record-keeping duties. |
| Access and entitlement records | Which books and workshops you have access to, when access was granted or revoked. | Making sure you can open what you paid for, and only that. | Consent (s.6). | For as long as your account is open, then 90 days. |
| Device registration | A random device identifier stored in your browser, a device name derived in your browser from your browser and operating system (for example "Chrome on Android"), and first/last seen timestamps. We do not store your full browser user-agent string or your screen resolution. | Enforcing the two-device limit on purchased books, and alerting you by email when a new device is registered to your account. | Consent (s.6) — this is part of the account service you sign up for. | For as long as your account is open, then 90 days. |
| Reading activity | Which chapter or page you last read, reading progress percentage, bookmarks and any notes you save. | Restoring your place in a book across devices and showing your progress. | Consent (s.6). | For as long as your account is open, then 90 days. |
| Workshop registrations | Which workshops you registered for, payment status, attendance check-in, and refund status. | Admitting you to workshops and managing capacity, refunds and materials. | Consent (s.6). | 8 years, alongside the associated payment record. |
| Enquiries | Name, email address, enquiry topic and the message you write in the contact form. | Replying to you. | Consent (s.6) — given on the contact form. | 24 months from the last message in the thread. |
| Security and audit logs | Records of security-relevant events: device registered, device limit reached, entitlement granted or revoked, payment webhook received. Includes your user ID and event metadata with passwords, tokens and signatures redacted. | Detecting misuse of paid content, investigating incidents, and meeting our security obligations. | Legitimate use (s.7) — security of the service. | 24 months. |
| Consent records | Each consent you give or withdraw, the purpose, the version of this notice shown, and when. | Demonstrating that valid consent was obtained, as s.6 requires. | Legal obligation under the DPDP Act. | 3 years after the related consent is withdrawn or the account is closed. |
3. Consent, and how to take it back
Under Section 6 of the DPDP Act your consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. That is why every consent box on this site starts empty, and why optional purposes are separate from the ones the service needs.
The purposes we ask about are:
- Required — Creating and running your account, granting access to purchased books and workshops, registering your reading devices, and sending transactional messages such as receipts, access links and security alerts.
- Optional — Sending optional updates about new books, workshops and practice guidance.
- Required — Reading and replying to an enquiry you send through the contact form.
- Optional — Following up after your enquiry is resolved with related guidance.
- Optional — Measuring aggregate site usage so we can improve the catalogue and the reader. Not currently active.
- Optional — Measuring the effectiveness of campaigns that bring people to the site. Not currently active.
We keep a record of each consent you give or withdraw, including which version of this notice was on screen at the time, because the DPDP Act requires us to be able to demonstrate that your consent was validly obtained.
6. Your rights
The DPDP Act gives you the following rights. All of them are exercised through the same form, and none of them cost anything.
Access (s.11)
Ask for a summary of the personal data we hold about you, what we are doing with it, and which processors we have shared it with.
Correction and completion (s.12)
Have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated. You can edit your own name, phone and avatar at any time from your profile.
Erasure (s.12)
Ask us to delete your personal data. We will do so unless we are required by law to keep specific records — payment and tax records being the usual reason — in which case we will tell you what we kept and why.
Withdraw consent (s.6)
Turn off any optional purpose at any time, as easily as you turned it on.
Nominate (s.14)
Nominate someone to exercise these rights on your behalf if you die or become incapable of doing so yourself.
Grievance redressal (s.13)
Complain to our Grievance Officer about how we have handled your data or your request. You must give us the chance to resolve it before escalating to the Data Protection Board.
Exercise any of these rights
Use the request form — it records your request, gives you a reference code, and routes it to the Grievance Officer.
Open the data rights formWe will verify your identity before acting on a request, so that nobody else can obtain or delete your data by pretending to be you. Where a request is refused we will tell you why.
7. Children and persons with a guardian
Dairy Diaries is intended for practising and student veterinarians, dairy farmers and other adults. It is not directed at children.
Section 9 of the DPDP Act requires verifiable parental consent before processing the personal data of anyone under 18, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has registered, contact the Grievance Officer and we will delete the account and its data.
8. How we protect your data
Section 8(5) of the DPDP Act requires reasonable security safeguards. The measures currently in place include:
- All traffic served over HTTPS, with the database reached only over TLS.
- Passwords are never stored by us in a readable form — authentication is handled by Supabase Auth, which stores only a salted hash.
- Row Level Security on the database, so one customer's account, purchases, entitlements and reading data are not reachable from another customer's session.
- Purchased book files are held in a private bucket and released only after an entitlement and a registered-device check.
- Structured logging that redacts passwords, tokens, signatures, email addresses, phone numbers and payment identifiers before anything is written.
- Audit logging of security-relevant events such as device registration and entitlement changes.
- Rate limiting in front of sign-in, registration, checkout and the contact form.
If a personal data breach occurs we will notify the Data Protection Board of India and every affected person, in the form and within the timeframes the DPDP Act and its Rules require.
9. Grievance Officer
Under Section 13 of the DPDP Act you may complain to our Grievance Officer about anything to do with your personal data. Please give us a reasonable opportunity to resolve your complaint before escalating it.
The Grievance Officer, Dairy Diaries
We aim to respond within 30 days of receiving a complaint.
If you are not satisfied with our response, you may complain to the Data Protection Board of India in accordance with the DPDP Act and the rules made under it.
10. Changes to this notice
When we change this notice we increase its version number. Where a change affects a purpose you previously consented to, your recorded consent no longer covers the new wording and we will ask you again — the cookie banner, for instance, reappears automatically after a version change.
This notice is version 2026-08-14.1, effective 14 August 2026. See also our Terms of Service.