Wave City Connect

Community Portal · Ghaziabad
← Return to Site
Legal Document

Privacy Policy & Data Protection Notice

📅 Effective Date: 4 June 2026 🔄 Version: 2.0 📍 Jurisdiction: Republic of India ⚖️ Governed by: DPDPA 2023 & IT Act 2000
This Privacy Policy ("Policy") constitutes a legally binding document between Wave City Connect, operated by Ms. Neha Sharma ("Data Fiduciary," "We," "Us," or "Our"), and any individual ("Data Principal," "You," or "User") who accesses, browses, or submits information through the platform located at wavecityconnect.co.in. By accessing or using the Platform, you acknowledge that you have read, understood, and consent to the practices described herein.
Article I Definitions & Interpretation

Unless the context otherwise requires, the following terms shall bear the meanings ascribed to them hereunder. Words importing the singular shall include the plural and vice versa.

TermDefinition
"Act"The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), as amended from time to time, along with rules and regulations framed thereunder.
"Board"The Data Protection Board of India, established under Section 18 of the Act.
"Consent"A free, specific, informed, unconditional, and unambiguous indication of the Data Principal's agreement to the processing of their Personal Data, as defined under Section 6 of the Act.
"Data Fiduciary"Ms. Neha Sharma, operating Wave City Connect, who determines the purpose and means of processing of Personal Data, as defined under Section 2(i) of the Act.
"Data Principal"Any natural person to whom the Personal Data relates, as defined under Section 2(j) of the Act.
"Data Processor"Any person who processes Personal Data on behalf of the Data Fiduciary, as defined under Section 2(k) of the Act.
"Personal Data"Any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the Act. This includes names, phone numbers, email addresses, and other identifying information submitted through the Platform.
"Platform"The website accessible at wavecityconnect.co.in and all subpages, features, and services made available thereon.
"Processing"Wholly or partly automated operation(s) performed on Personal Data, including collection, recording, storage, use, disclosure, or erasure, as defined under Section 2(x) of the Act.
"Sensitive Personal Data"Categories of personal data specified by the Central Government under Section 2(ae) of the Act, including financial data, health data, biometric data, and data relating to children.
Article II Identity of the Data Fiduciary & Grievance Officer
2.1 Data Fiduciary

The Data Fiduciary in respect of all Personal Data collected and processed through the Platform is:

  • Name: Ms. Neha Sharma
  • Platform: Wave City Connect (wavecityconnect.co.in)
  • Address: Wave City, Ghaziabad, Uttar Pradesh — 201015, India
  • Email: nehas9470@gmail.com
2.2 Grievance Officer

In accordance with Section 13 of the Act and Rule 7 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following individual is designated as the Grievance Officer for this Platform:

  • Name: Ms. Neha Sharma
  • Designation: Data Fiduciary & Grievance Officer
  • Email: nehas9470@gmail.com
  • Response Time: Within thirty (30) days of receipt of grievance, as mandated under the Act.
Article III Scope and Applicability

This Policy applies to all Personal Data collected from Data Principals who:

Territorial Scope: This Policy governs the processing of Personal Data of individuals located within the territory of India. Processing of data is conducted in accordance with the Act and applicable Indian law.
Article IV Categories of Personal Data Collected
4.1 User-Submitted Data

The Platform collects only such Personal Data as is voluntarily furnished by the Data Principal through submission forms. The following table sets forth the categories of data collected, the lawful purpose, and visibility status thereof:

Submission Form Personal Data Collected Lawful Basis Publicly Visible
Business ListingBusiness name, category, description, phone number, WhatsApp numberConsent (Form submission)YES — post approval
Property ListingProperty type, price, area, description, contact phoneConsentYES — post approval
Job PostingJob title, description, salary, contact phoneConsentYES — post approval
Buy / Sell (Classifieds)Category, title, price, description, contact phoneConsentYES — post approval
Helper RecommendationName, service category, phone, descriptionConsentYES — post approval
Lost & FoundType, title, description, area, contact phoneConsentYES — post approval
Community EventsTitle, date, venue, organiser name, descriptionConsentYES — post approval
Society PostsPost content, display nameConsentYES — immediately
Scrap ListingsItem type, quantity, expected price, seller name, phoneConsentYES — immediately
TestimonialsAuthor name, role, content, ratingConsentYES — post approval
Feedback / ContactName, email address or phone, message contentLegitimate InterestNO — admin only
Poll ParticipationAnonymous vote option (no identifying data)ConsentNO — aggregate only
IMPORTANT NOTICE REGARDING TELEPHONE NUMBERS: Any telephone number submitted in connection with a public-facing listing (businesses, helpers, jobs, classifieds, lost & found, events, or scrap) shall be visible to all visitors of the Platform upon approval. Data Principals are strongly advised to submit only such telephone numbers as they are willing to disclose publicly. The Data Fiduciary assumes no liability for unsolicited communications received as a result of such public disclosure.
4.2 Automatically Collected Technical Data

The Platform does not actively collect cookies or device fingerprints. However, the following technical data may be incidentally collected by infrastructure providers:

4.3 Data Not Collected

The Data Fiduciary expressly confirms that the Platform does not collect:

Article V Purpose of Processing & Lawful Basis

Pursuant to Section 4 and Section 6 of the Act, the Data Fiduciary processes Personal Data solely on the following lawful bases and for the following specified purposes:

Processing ActivityLawful BasisSpecified Purpose
Publishing community listingsConsentTo display approved user-submitted listings to Platform visitors for community benefit
Approval workflow managementLegitimate InterestTo review and moderate submissions prior to public display; to prevent spam, fraud, or abusive content
Feedback processingLegitimate InterestTo receive, review, and respond to user queries, complaints, and advertising enquiries
Poll and engagement featuresConsentTo operate interactive community features and display aggregate results
Platform security and integrityLegitimate InterestTo detect, prevent, and mitigate fraudulent, abusive, or unlawful activity
Legal complianceLegal ObligationTo comply with applicable laws, court orders, or directions from competent authorities
Article VI Data Processors & Third-Party Services

In accordance with Section 8 of the Act, the Data Fiduciary engages the following Data Processors who process Personal Data solely on the instructions of and on behalf of the Data Fiduciary. These entities are not authorised to use, share, or disclose Personal Data for any purpose other than as directed by the Data Fiduciary.

Data ProcessorCapacityData AccessedProcessing LocationPrivacy Reference
Supabase, Inc. Database, backend infrastructure, and authentication service provider All user-submitted Personal Data (stored in relational database); authentication tokens for administrator access USA / EU (AWS infrastructure) supabase.com/privacy
Google LLC (OAuth) Authentication service provider (administrator access only) Administrator's email address and basic Google profile information; not accessible to general users USA policies.google.com/privacy
Namecheap, Inc. Web hosting and domain registrar Standard web server access logs (IP address, request timestamp, user agent string) USA namecheap.com/legal/general/privacy-policy
Google LLC (Fonts) Typography/CDN service IP address processed transiently upon font file request; no Personal Data retained by Google for this purpose USA / Global CDN policies.google.com/privacy
6.1 Cross-Border Data Transfers

Data Principals are hereby informed that Personal Data submitted through the Platform is stored on servers operated by Supabase, Inc., which are located outside the territory of India (United States of America and/or European Union). Such cross-border transfer is necessitated by the technical infrastructure of the Platform. The Data Fiduciary confirms that:

6.2 Non-Disclosure

The Data Fiduciary shall not sell, lease, trade, or otherwise transfer Personal Data to any third party for commercial purposes. Personal Data shall not be disclosed to any person other than the Data Processors identified in this Article, unless required by applicable law or by order of a competent court or authority.

Article VII Data Retention & Destruction

Personal Data shall be retained only for so long as is necessary to fulfil the specified processing purpose, or as required under applicable law, whichever is longer. The following retention schedule applies:

Data CategoryRetention PeriodDestruction Method
Approved public listingsUntil deletion is requested by the Data Principal, or until removed by the Data Fiduciary in exercise of editorial discretionPermanent deletion from database
Rejected / pending submissionsDeleted immediately upon rejection by administratorPermanent deletion from database
Feedback and contact messagesSix (6) months from date of receipt, unless subject to an ongoing dispute or legal matterPermanent deletion from database
Poll participation recordsDuration of poll's active period; anonymised aggregate data may be retained indefinitelyRecord deletion upon poll closure
Administrator session tokensUntil logout or session expiry (automatically cleared after 30 minutes of inactivity)Browser local storage clearance
Web server access logsAs per Namecheap's standard retention policy (typically 30–90 days)Automated purge by hosting provider
Article VIII Security Measures & Safeguards

In accordance with Section 8(5) of the Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Data Fiduciary has implemented the following technical and organisational measures:

Limitation of Security Warranty: Notwithstanding the foregoing, no system of data security is impenetrable. The Data Fiduciary does not warrant that unauthorised access, disclosure, or modification of Personal Data will never occur. In the event of a Personal Data Breach as defined under the Act, the Data Fiduciary shall notify the Board and, where applicable, affected Data Principals, in accordance with applicable provisions of the Act.
Article IX Rights of Data Principals

Pursuant to Chapter III (Sections 11–14) of the Act, Data Principals are entitled to exercise the following rights with respect to their Personal Data. All requests should be addressed to the Grievance Officer identified in Article II with the subject line: "Privacy Rights Request — [Your Name]".

§11 — Right to Access Information

You have the right to obtain a summary of Personal Data processed and the processing activities undertaken in respect thereof.

§12(a) — Right to Correction

You have the right to have inaccurate or incomplete Personal Data corrected or completed.

§12(b) — Right to Erasure

You have the right to have Personal Data erased when the purpose for processing no longer subsists, subject to legal retention obligations.

§13 — Grievance Redressal

You have the right to have grievances relating to the processing of your Personal Data redressed within the timelines prescribed under the Act.

§6(4) — Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time. Withdrawal shall not affect the lawfulness of processing prior to such withdrawal.

§14 — Right to Nominate

You have the right to nominate another individual to exercise your rights in the event of your death or incapacity.

The Data Fiduciary shall respond to all valid rights requests within thirty (30) days of receipt. In exceptional circumstances, this period may be extended by a further thirty (30) days, with prior written notification to the Data Principal.

Right of Recourse: If you are dissatisfied with the Data Fiduciary's response to your grievance, you may lodge a complaint with the Data Protection Board of India, once formally constituted and operational under the Act.
Article X Processing of Children's Personal Data

In accordance with Section 9 of the Act, the Data Fiduciary does not knowingly process Personal Data of children below the age of eighteen (18) years. The Platform is not directed at minors, and no features are specifically designed for use by children.

If the Data Fiduciary becomes aware or has reason to believe that Personal Data of a child has been submitted without appropriate parental or guardian consent, such data shall be deleted without undue delay. Parents or guardians who believe that Personal Data of a minor has been processed through the Platform are requested to contact the Grievance Officer at nehas9470@gmail.com immediately.

Article XI Limitation of Liability & Indemnification
11.1 Limitation of Liability

To the fullest extent permitted by applicable law, the Data Fiduciary shall not be liable for any indirect, incidental, consequential, or punitive damages arising out of or in connection with:

  1. Unauthorised access to or alteration of Personal Data by third parties despite reasonable security measures being in place;
  2. Actions taken by Data Processors in contravention of their contractual obligations to the Data Fiduciary;
  3. Unsolicited communications received by Data Principals as a result of publicly visible contact information voluntarily submitted by such Data Principals;
  4. Any inaccuracy in user-submitted content relied upon by third parties.
11.2 User Responsibility

Data Principals are solely responsible for ensuring the accuracy, legality, and appropriateness of all Personal Data they submit through the Platform. By submitting information pertaining to a third party (such as a contact telephone number), the submitting Data Principal warrants that they have obtained all necessary consents from such third party for the disclosure and publication of their Personal Data.

Article XII Amendments to this Policy

The Data Fiduciary reserves the right to amend, modify, or update this Policy at any time, in order to reflect changes in applicable law, processing practices, or operational requirements. The following procedure shall apply to material amendments:

Continued use of the Platform following the publication of an amended Policy shall constitute acceptance of such amendments. If a Data Principal does not agree with any amendment, they should cease use of the Platform and exercise their right to erasure under Article IX.

Article XIII Governing Law, Jurisdiction & Dispute Resolution
13.1 Governing Law

This Policy shall be governed by and construed in accordance with the laws of the Republic of India, including but not limited to:

  1. The Digital Personal Data Protection Act, 2023;
  2. The Information Technology Act, 2000 and rules made thereunder;
  3. The Consumer Protection Act, 2019;
  4. Any other applicable central or state legislation.
13.2 Jurisdiction

Subject to the exclusive jurisdiction of the Data Protection Board of India for matters falling within its statutory purview, all disputes, controversies, or claims arising out of or relating to this Policy shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction situated at Ghaziabad, Uttar Pradesh, India.

13.3 Severability

If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid provision shall be replaced with a valid provision that most closely approximates the intent of the original provision.

Article XIV Entire Agreement & Interpretation

This Policy, read together with the Terms of Service of the Platform, constitutes the entire agreement between the Data Fiduciary and the Data Principal with respect to the subject matter hereof and supersedes all prior understandings, representations, or agreements, whether written or oral, relating to the processing of Personal Data through the Platform.

In the event of any conflict or inconsistency between this Policy and the Terms of Service, the provisions of this Policy shall prevail with respect to matters relating to Personal Data and privacy.

Headings and article titles are for convenience of reference only and shall not affect the construction or interpretation of this Policy.

Executed on behalf of the Data Fiduciary

This Policy has been approved and adopted by the Data Fiduciary as of the Effective Date stated herein.

Ms. Neha Sharma
Data Fiduciary & Grievance Officer — Wave City Connect
Effective Date: 4 June 2026 | Version 2.0

For privacy requests and grievances: nehas9470@gmail.com