Privacy Notice
Version 2026-08-15.1 · Madad
Who we are
Madad (“we”, “us”) operates this platform. For the purposes of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
What we collect, and why
We collect only what each purpose below actually needs. You choose the optional ones when you sign up, and you can change your mind at any time.
Create and operate my account
RequiredStore my name, email, phone and password so I can sign in, and contact me about my account.
Verify my identity and referral
RequiredLet the Madad admin team review my details and my referrer’s details to confirm I am a genuine member of the community before my account is approved.
Matrimony matching (optional)
OptionalUse my matrimony profile — including photos, age, education and community details — to suggest matches to other verified members, and to show my profile to them.
We no longer accept applications for financial aid or scholarships, and no longer collect income details or supporting documents. Records of decisions made on applications received before this closed are kept for the period shown in the retention table below.
Where your data is stored, and who processes it
We do not run our own servers. 3 companies process data on our behalf, and we name them so you know exactly who holds what:
- Neon — Our database — your account, your profiles, your applications and your messages all live here. Held in the United States.
- Cloudflare — The website itself, and the storage holding the photographs, résumés and documents you upload. Held in data centres around the world, which can include locations outside India.
- Resend — The service that delivers our emails to you, such as sign-in codes and notifications. It necessarily handles your email address and the contents of the messages we send you. Held in the United States.
So: your personal data is processed outside India. Section 16 of the DPDP Act permits this, except to any country the Central Government restricts by notification. If a provider we use falls under such a restriction, we will move away from it. Each of these providers encrypts data in transit and at rest, and each is engaged on terms that allow them to process your data only to run this platform, not for their own purposes.
We do not sell your data, and we do not share it with advertisers. The only sharing that happens is the sharing you chose when you signed up — showing your matrimony profile to other verified members.
How long we keep it
We keep your data for as long as your account is active, and then only for the periods below. These are maximums, not targets — you can have your data deleted sooner at any time by using Delete my account, and we act on that immediately rather than waiting for a period to run out.
| What | How long |
|---|---|
| Expired password-reset codesThe one-time code sent when someone asks to reset their password. | Until it expires — 15 minutes — and cleared from the account on the next purge run |
| Expired email-verification linksThe token behind the "confirm your email address" link sent at signup. | Until it expires, then cleared on the next purge run |
| Rejected signupsThe account of someone whose application to join was turned down: their name, email, phone, date of birth, referral details and, for an under-18 applicant, their parent or guardian’s details. | 6 months |
| Aid and scholarship decisionsThat an application was made, by whom, for how much, and what the admin decided. | 8 years from the end of the financial year — PROVISIONALProvisional — we are still confirming this period. |
| Enquiries and donation enquiriesMessages sent through the contact and donate forms, and how an admin answered them. | 3 years |
| Grievances and how they were answeredA complaint raised with the Grievance Officer: the complainant’s name, email and phone number, up to 5,000 characters describing what went wrong, which category it was filed under, and the answer the admin gave. | 3 years after the grievance is answered |
| Verification historyThe record that a named admin approved or rejected a named member, and when. Holds the member’s name and email even after their account is gone. | 3 years |
| Signup review notesWhat an admin wrote after ringing an applicant’s karyakar — the call outcome and any note, which frequently names and quotes a third party who never used this platform. | 2 years |
| Administrative activity logsThe admin’s internal notification log — new signup, new listing, new aid request — whose message text usually names the member concerned. Breach records are written to the same table and are NOT covered here; they are the entry below. | 12 months |
| Records of a personal data breachThe written record of a breach: what was exposed, how it came to light, who wrote it down, when the admin became aware, and the reporting deadlines that started running from that moment. | Kept — never deleted by a purge run |
| Consent recordsThe append-only trail of every consent granted, updated or withdrawn, with the version of the notice the person was shown at the time. | For as long as the account exists, and for 3 years after it is deleted |
| Consent evidence for deleted accountsThe consent trail of an account that has been deleted, copied out of consent_records at the moment of deletion so the cascade from users cannot destroy it. | 3 years from the date the account was deleted |
| The address and browser on a security log entryThe IP address and browser recorded alongside every entry in the sign-in and security log — including entries that are themselves kept for years. | 12 months from the event |
| Sign-in and security logEvery sign-in, failed sign-in and lockout on your account; every time you signed out or the Trust signed you out; and every change to your password, your two-step verification, or the email address or telephone number you sign in with. | 12 months from the event |
| The disposal registerOne row for every account this platform has destroyed; since September 2026, one for every matrimony profile deleted on its own, whether by the member or by a trustee; and one for each SWEEP - a clearing-out belonging to no single member, such as the disposal of the records left by a closed portal, or the removal of files whose owning account is long gone. Each row says when, by whom, on what stated reason, what was destroyed, and what was retained under this schedule. The mode column separates them: a profile deletion leaves the account, its login and its consent record intact, and a sweep names no member at all. | Kept indefinitely |
Schedule last reviewed 2026-08-04. We review it at least once a year and whenever we start collecting something new.
One period above is marked provisional. That means we have published our current working answer while we confirm it. We would rather show you a figure marked unconfirmed than a confident one we cannot yet stand behind. What is still open:
- Aid and scholarship decisions — The admin’s auditor must confirm the correct statutory period before this figure is relied on. Until they do it is published as provisional rather than stated as fact.
2 further periods are written down but not yet running. These are not on the table above, because the table is what we actually do. We are still telling you about them: a rule we intend but cannot yet carry out is a different promise from one we keep, and leaving it off the page entirely would let it stay that way indefinitely.
- The record of who looked at your details — Every time a trustee or another member was shown one of your personal details — your telephone number, your address, your family contact number — and every time the platform itself had to unlock your email address in order to send you a message. Also every decision recorded about your data: consent given or withdrawn, a role changed, a matrimony profile put beyond use.What we intend: The life of the account, then 3 years. What stops us today: The log records WHO LOOKED in a column and who was LOOKED AT inside a JSON field, so there is no reliable way to find the entries belonging to one member.
- Dormant accounts — An approved member who has not signed in for a long time.What we intend: 24 months of inactivity, after a warning email. What stops us today: Nothing in the database records when a member was last active, and no warning email exists yet.
Deletions under this schedule are carried out by an admin reviewing the data, not by an automatic process. We prefer a person to check before anything is destroyed, because a deletion is not reversible.
Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you, and how we use it. You can do this yourself at any time: sign in, open Account & data from the menu on the portal page, and press Download under Download my data. The file covers everything we hold about you on this platform and lists the photographs you uploaded.
- Have inaccurate or incomplete data corrected or updated.
- Have your data erased, subject to any legal obligation we have to retain it. You can delete an individual portal profile or your entire account from the same screen, and the photographs and documents you uploaded are deleted from our storage with it.
- Withdraw any optional consent at any time — it is as easy to withdraw as it was to give. Withdrawing does not affect processing that already happened.
- Nominate someone to exercise these rights on your behalf.
- Raise a grievance with us, and escalate it if you are not satisfied.
Children
You must be 18 or over to have an account here. Madad is a matrimony platform, and under the Prohibition of Child Marriage Act, 2006 nobody under 18 may marry in India. Signup refuses a date of birth that makes you younger than that, and there is no way round it — we no longer take a parent or guardian’s details, because we no longer create accounts that would need them.
This means the DPDP Act’s rules for children (section 9) do not arise: we hold no child’s data to process, with or without a guardian’s consent. We do not use anyone’s data for advertising or for anything that tracks their behaviour.
The legal minimum age of marriage is higher for men than the age of majority: 21 for men and 18 for women, under the same Act. A matrimony profile cannot be created below that age, which is checked against the date of birth given at signup rather than an age typed on the form.
Some accounts created before this rule was introduced recorded a parent or guardian’s name, relationship, email and phone number. Those details are no longer collected or used, and are being disposed of under the retention rules set out above. If you are a parent or guardian and you want your child’s account and data removed, tell us using the details below and we will do it.
If something goes wrong with your data
A personal data breach means your data being seen, copied, changed or destroyed by someone who should not have been able to. If that happens here, the law requires us to tell both you and the Data Protection Board of India, and there is no minimum size below which we may keep quiet about it.
We will contact you without delay — as soon as we know you are affected, not after we have finished working out what happened. We will tell you what was involved, what we have done about it, and what you can do. We report the full details to the Board within 72 hours of becoming aware.
One thing worth knowing in advance: we will never contact you to ask for your password, a one-time code, or a payment — not during an incident and not at any other time. Anyone who does is not us.
Grievance redressal
If you have a concern about how your data is handled — including anything in this notice — tell us through the grievance form. An admin reads it and replies to you within 30 days, which is the maximum the law allows us; in practice we aim to be much quicker.
We do not send an automatic acknowledgement. Instead, a reference number appears on the screen the moment your complaint is recorded — please write it down or photograph it before closing the page, because it is how you can ask us later what happened to it. We send no confirmation email on purpose: anyone at all can raise a grievance without signing in, which is deliberate, and it means an automatic reply could be aimed at an address the sender does not own. The next thing you hear from us is our answer, written by the admin who dealt with it.
If you raise it another way instead — by telephone, or directly with the contact below — nothing is sent to you automatically in that case either, so please ask whoever you speak to for your reference number and note it down. The 30-day deadline runs from when we receive your complaint, whichever way you send it.
If you are not satisfied with our response, you may complain to the Data Protection Board of India. We have deliberately not printed a postal address or web link for the Board here, because the correct route changes and a stale one would send your complaint nowhere — please look it up on the Board’s own official website, or ask us and we will find the current details for you.
Changes to this notice
If we change how we use your data, we will publish an updated notice with a new version number and ask you to review it. The version you agreed to is recorded against your account.