Privacy Policy

CoralRidge Networks, having its registered office at Gurugram, India (“CoralRidge”, “we”, “us” or “our”), is committed to protecting the personal data of individuals who interact with our website and services. This Privacy Policy explains how we collect, use, share, retain and protect personal data, and describes the rights available to individuals, in accordance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”), as amended from time to time. For the purposes of the DPDP Act, CoralRidge acts as a Data Fiduciary in respect of the personal data described in this Policy.

1. Definitions

1.1 In this Policy, the following terms have the meanings given to them under the DPDP Act and the DPDP Rules:

(a) “Data Principal” means the individual to whom personal data relates, and, in the case of a child, includes the parent or lawful guardian, and, in the case of a person with a disability, includes the lawful guardian;

(b) “Data Fiduciary” means the person who alone or in conjunction with others determines the purpose and means of processing personal data;

(c) “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;

(d) “Personal Data” means any data about an individual who is identifiable by or in relation to such data;

(e) “Processing” means a wholly or partly automated operation or set of operations performed on personal data, including collection, storage, use, sharing, disclosure or erasure; and

(f) “Personal Data Breach” means any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability.

2. Scope and Applicability

2.1 This Policy applies to the processing of personal data in digital form, and to personal data in non-digital form that is subsequently digitised, collected by us within India, or collected outside India in connection with the offering of goods or services to Data Principals within India. By using our website or services, or by providing your personal data to us, you acknowledge that you have read and understood this Policy.

3. Personal Data We Collect

3.1 Information provided by Clients:

(a) name;

(b) company name;

(c) work email address;

(d) phone number;

(e) industry or project details;

(f) geographic focus; and

(g) type of expertise requested.

3.2 Information provided by Experts:

(a) full name;

(b) professional background;

(c) current and previous employment;

(d) areas of expertise;

(e) LinkedIn profile;

(f) contact information; and

(g) geographic location.

3.3 Information collected automatically:

(a) IP address;

(b) browser type;

(c) device information;

(d) website usage data; and

(e) pages visited.

3.4 We may use cookies and similar technologies to enhance user experience and to analyse website usage, as described in Clause 12.

4. Purposes of Processing and Lawful Basis

4.1 We process personal data for the following purposes:

(a) to connect Clients with relevant industry Experts;

(b) to facilitate Consultations;

(c) to improve our services and website functionality;

(d) to respond to inquiries; and

(e) to maintain compliance with Applicable Law.

4.2 We process personal data on the basis of your consent, or on the basis of such other legitimate uses as are permitted under the DPDP Act. Where processing is based on consent, we rely on the consent obtained in accordance with Clause 5. We do not sell personal data.

5. Notice and Consent

5.1 Where we process your personal data on the basis of consent, we will, at or before the time of seeking consent, provide you with a notice, in clear and plain language, itemising the personal data sought to be collected, the purpose of processing, the manner in which you may exercise your rights, and the manner in which you may make a complaint to the Data Protection Board of India. The notice will be made available in English and in such other languages as are specified in the Eighth Schedule to the Constitution of India, at your option.

5.2 Your consent will be sought through a clear affirmative action, and will signify an agreement that is free, specific, informed, unconditional and unambiguous, and limited to the personal data necessary for the specified purpose.

5.3 You may withdraw your consent at any time, and the ease of withdrawing consent will be comparable to the ease with which consent was given. The withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Upon withdrawal of consent, we will, within a reasonable time, cease to process your personal data and cause our Data Processors to do the same, unless retention is required or authorised under Applicable Law. Withdrawal of consent may affect our ability to provide the corresponding service to you.

6. Sharing of Personal Data

6.1 We may share personal data:

(a) with Clients, when introducing relevant Experts;

(b) with Experts, when evaluating Consultation opportunities;

(c) with trusted Data Processors and service providers who support our operations, under written contracts requiring them to protect personal data and to process it only on our instructions; and

(d) with courts, governmental or regulatory authorities, where required by Applicable Law.

6.2 We require every Data Processor engaged by us to implement appropriate security safeguards and to process personal data only for the purposes for which it was shared.

7. Cross-Border Transfers

7.1 As CoralRidge operates globally, personal data may be processed in jurisdictions outside your country of residence. Any transfer of personal data outside India will be carried out in accordance with the DPDP Act and the DPDP Rules, and will be subject to any restrictions that the Central Government may notify in respect of transfers to particular countries or territories.

8. Data Retention and Erasure

8.1 We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required for recordkeeping or to comply with Applicable Law. When the purpose is no longer being served, and retention is no longer necessary or required under Applicable Law, we will erase the personal data and cause our Data Processors to do the same, unless you have withdrawn your consent earlier, in which case we will act in accordance with Clause 5.3.

9. Security Safeguards and Breach Notification

9.1 We implement reasonable technical and organisational security safeguards to protect personal data against Personal Data Breaches, including appropriate measures for confidentiality, integrity and availability. No system, however, can guarantee complete security.

9.2 In the event of a Personal Data Breach, we will intimate the Data Protection Board of India and each affected Data Principal, without delay, in the manner and within the timelines prescribed under the DPDP Rules, together with a description of the breach, its likely consequences, the measures taken to mitigate it, and the measures that the affected Data Principal may take to protect their interests.

10. Rights of Data Principals

10.1 Subject to the DPDP Act and the DPDP Rules, you have the right:

(a) to obtain a summary of the personal data being processed by us and the processing activities undertaken;

(b) to the correction, completion and updating of your personal data;

(c) to the erasure of your personal data, where retention is no longer necessary or required under Applicable Law;

(d) to readily available means of grievance redressal in respect of any act or omission of CoralRidge regarding your personal data; and

(e) to nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.

10.2 You may exercise these rights by contacting our Grievance Officer using the details in Clause 11. We may require verification of your identity before acting on a request.

11. Grievance Redressal and Contact

11.1 We have appointed a Grievance Officer to address questions and grievances relating to the processing of your personal data. You may contact the Grievance Officer at:

Grievance Officer:

Designation:

Email:

Address: __________, Gurugram, Haryana, India

11.2 We will respond to your grievance within the period prescribed under the DPDP Rules. The above person is also the person to whom you may address any question about the processing of your personal data.

12. Cookies and Automatically Collected Data

12.1 We use cookies and similar technologies to operate the website, to remember your preferences, and to analyse usage. You may manage cookies through your browser settings, although disabling certain cookies may affect the functionality of the website.

13. Children and Persons with Disabilities

13.1 Where we process the personal data of a child, or of a person with a disability who has a lawful guardian, we will obtain verifiable consent from the parent or lawful guardian in the manner prescribed under the DPDP Rules before such processing. We will not undertake any tracking, behavioural monitoring or targeted advertising directed at children, and we will not process the personal data of a child in a manner that is likely to cause any detrimental effect on the well-being of the child.

14. Third-Party Links

14.1 Our website may contain links to third-party websites. We are not responsible for the privacy practices or the content of any third-party website, and we encourage you to review the privacy policy of every website you visit.

15. Complaints to the Data Protection Board of India

15.1 If you are not satisfied with our response to your grievance, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and the DPDP Rules. An appeal against an order of the Board lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), in accordance with the DPDP Act.

16. Changes to this Policy

16.1 We may update this Policy from time to time to reflect changes in our practices or in Applicable Law. The updated Policy will take effect upon publication on our website, and, where required, we will notify you of material changes.

17. Governing Law

17.1 This Policy is governed by, and shall be construed in accordance with, the laws of India, including the DPDP Act and the DPDP Rules. Any grievance or complaint relating to the processing of personal data shall be dealt with through the grievance redressal mechanism in Clause 11 and, thereafter, through the Data Protection Board of India in accordance with Clause 15.

18. Contact Us

18.1 For any question relating to this Policy or to the processing of your personal data, please contact us at contact@coralridgeglobal.com.

Contact

Reach out to us at -

contact@coralridgeglobal.com

© 2025. All rights reserved.