Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Better Today. Resilient Tomorrow. • Making Sustainability Make Sense • Global Standards
Legal & Compliance

Data Privacy Policy - SUSTINT

Shivarth Consulting Services

Effective Date: July 25, 2026Version: 1.0

1. INTRODUCTION & SCOPE

SUSTINT ("Company", "we", "us", or "our") respects individual privacy and is committed to protecting personal data. This Data Privacy Policy explains how personal data is collected, processed, stored, disclosed, and erased by SUSTINT in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules notified thereunder (including the DPDP Rules, 2025).

This Policy applies to all individuals ("Data Principals") whose personal data is collected or processed by SUSTINT, including users of our website, clients, corporate representatives, vendors, contractors, embedded operational teams, and visitors across our digital platforms and service divisions (IntelliDecarb™ and IntelliSustain™).

This Policy should be read together with specific notices or consent requests provided at the time of collecting personal data.

2. APPLICABILITY & DEFINITIONS

For the purposes of this Privacy Policy, capitalized terms shall have the meanings assigned under the DPDP Act:

  • "Data Principal" means the individual to whom the personal data relates.
  • "Data Fiduciary" means SUSTINT, which determines the purpose and means of processing personal data.
  • "Data Processor" means any entity or person processing personal data on behalf of SUSTINT.
  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "IntelliDecarb™" refers to SUSTINT's Decarbonization as a Service (DaaS) offerings.
  • "IntelliSustain™" refers to SUSTINT's Sustainability as a Service (SaaS) offerings, including Operational Health & Safety (OHS) and ESG intelligence.

3. NOTICE AT THE TIME OF COLLECTION

At or before the time of collecting personal data, SUSTINT shall provide Data Principals with an itemized, clear, and accessible notice specifying:

  • The specific categories of personal data collected.
  • The exact purpose(s) for which such data will be processed.
  • The manner in which consent may be withdrawn at any time.
  • The consequences of withdrawing consent.
  • The procedure to exercise Data Principal rights under the DPDP Act.
  • Contact details of SUSTINT's Grievance Redressal Officer.

4. CATEGORIES OF PERSONAL DATA COLLECTED

Depending on your interaction with SUSTINT (e.g., website contact, deployment of DaaS/SaaS solutions, or executive resource placement), we collect:

  • Identity and Contact Data: Full name, corporate email address, designation, telephone number, and company name.
  • Account and Professional Data: User account credentials, organizational role, designated service focus (e.g., IntelliDecarb™, IntelliSustain™), and training/audit participation records.
  • Facility & Operational Data: Facility metrics, energy/sub-metering interaction logs, EHS shop-floor audit data, or contractor safety reports necessary to deliver our intelligence services.
  • Technical & Usage Data: Device IP address, browser type, cookies, and system diagnostic logs when accessing our web interfaces.
  • Communications Data: Feedback, inquiries, audit queries, or operational challenge disclosures submitted via forms or direct correspondence.

5. PURPOSES OF PROCESSING

SUSTINT processes personal data strictly for lawful, explicit, and specified purposes, including:

  • Operating, delivering, and optimizing our IntelliDecarb™ (DaaS) and IntelliSustain™ (SaaS) service suites.
  • Onboarding client representatives, executing contracts, managing subscriptions, and deploying embedded personnel (TalentIntel).
  • Responding to consultations, operational inquiries, and service requests.
  • Conducting ESG materiality assessments, EHS diagnostic audits, and training registrations.
  • Ensuring platform security, preventing fraud, and protecting physical/digital assets.
  • Fulfilling statutory, tax, or legal requirements under applicable Indian laws.

6. CONSENT, WITHDRAWAL & CONSEQUENCES

  • Consent Standards: Processing is based on free, specific, informed, unconditional, and unambiguous consent granted through an affirmative action by the Data Principal.
  • Withdrawal: Data Principals may withdraw consent at any time through our designated user interface or by contacting our Grievance Officer. Withdrawal operates prospectively.
  • Consequences: If consent is withdrawn or refused, SUSTINT may be unable to provide access to certain services, diagnostic portals, or platform features.

7. PROCESSING OF CHILDREN'S PERSONAL DATA

SUSTINT's services are strictly business-to-business (B2B) corporate and industrial solutions. We do not knowingly collect or process the personal data of children (individuals under the age of 18).

8. DISCLOSURE OF PERSONAL DATA & DATA PROCESSORS

SUSTINT does not sell personal data. We may share personal data only with:

  • Data Processors / Service Providers: Third-party IT hosting providers, diagnostic software vendors, or analytics tools acting strictly on documented instructions under valid contracts imposing robust privacy obligations.
  • Affiliates & Group Entities: For internal administration and operational execution.
  • Legal & Regulatory Authorities: Where mandated under applicable Indian laws or valid governmental orders.

9. CROSS-BORDER TRANSFERS

SUSTINT may process or transfer personal data outside India only in accordance with Section 16 of the DPDP Act and governmental notifications. Personal data will not be transferred to any restricted country notified by the Central Government.

10. DATA RETENTION & ERASURE

SUSTINT retains personal data only for as long as necessary to fulfill the operational purpose for which it was collected or to comply with statutory legal mandates.

Personal data shall be erased upon completion of the purpose or withdrawal of consent.

Technical logs, associated traffic data, and system processing records are retained for a minimum period of one (1) year as prescribed under Rule 8 of the DPDP Rules, 2025, after which they are erased.

11. DATA PRINCIPAL RIGHTS

Under the DPDP Act, Data Principals possess the following statutory rights:

  • Right to Access: Obtain a summary of personal data processed, processing activities, and identities of third parties with whom data was shared.
  • Right to Correction & Erasure: Request correction of inaccurate/misleading data or erasure of data no longer required.
  • Right to Withdraw Consent: Revoke consent at any time.
  • Right to Grievance Redressal: Seek resolution for concerns regarding data handling.
  • Right to Nominate: Nominate an individual to exercise rights in the event of death or incapacity.

To exercise any of these rights, please contact our Grievance Redressal Officer using the details below.

12. GRIEVANCE REDRESSAL MECHANISM

In accordance with Section 8(10) and Rule 14 of the DPDP Rules, SUSTINT has established an effective grievance mechanism.

Data Principals are requested to direct all queries, rights requests, or complaints to:

Designated Contact Person: Neha Saini, Business Head

Email: feedback@sustint.com

Postal Address: 199-A, Hari Nagar Ashram, New Delhi - 110014

Phone Number: 8700955320

We will acknowledge your complaint within 24 hours of receipt and aim to resolve it within 7 working days, in accordance with the provisions of the DPDP Act, 2023 and DPDP Rules, 2025.

Note: Data Principals must exhaust SUSTINT's internal grievance redressal mechanism prior to approaching the Data Protection Board of India.

13. SECURITY SAFEGUARDS

SUSTINT implements reasonable technical, administrative, and organizational measures (including encryption, access controls, periodic audits, and risk profiling) to prevent unauthorized access, loss, alteration, or personal data breaches.

14. DUTIES OF DATA PRINCIPALS

Data Principals exercising their rights or submitting information to SUSTINT are required to:

  • Comply with applicable laws.
  • Avoid impersonating another person.
  • Avoid suppressing material information when submitting identity proofs.
  • Refrain from registering false or frivolous grievances.
  • Furnish only verifiably authentic information when requesting correction or erasure.

15. UPDATES TO THIS PRIVACY POLICY

SUSTINT reserves the right to modify or update this Privacy Policy to reflect changing legal, technical, or business developments. Material updates will be communicated through appropriate notices on our web platform.

ANNEXURE A: DATA RETENTION SCHEDULE (INDICATIVE)

Category of Personal DataRetention ApproachLegal / Operational Basis
Identity & Contact Data
(Name, Corporate Email, Designation)
Retained for the duration of the engagement/contract and erased thereafter.Contract fulfillment & Purpose limitation.
Client / Account Data
(Services requested, login logs)
Retained until account deletion or service cessation.Operational service delivery.
Financial & Billing DataRetained for period mandated by financial/tax laws (e.g., 7–8 years).Statutory legal obligation.
System & Processing LogsRetained for a minimum of one (1) year.Mandatory requirement under Rule 8, DPDP Rules, 2025.
Communications & Audit InquiriesRetained for a reasonable period following resolution.Grievance resolution & continuous auditability.