Privacy Policy

Digital Personal Data Protection Act, 2023 Compliance • Last Updated: June 2026

1. INTRODUCTION AND SCOPE

This Privacy Policy explains how Dr John Mathews ("Data Fiduciary," "we," "us," "our," or the "Organization"), an individual consulting professional based in Mumbai, Maharashtra, India, collects, processes, uses, discloses, protects, and manages personal data in connection with the operation of this website and the delivery of anti-money laundering (AML) consulting services, educational content, AML strategy advisory, and indicative assessment reports based on the DAREM Model.

This Policy is established in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), which collectively form the applicable legal framework for the processing of personal data in India. This Policy applies to all data processing activities undertaken through this website, affiliated digital platforms, and email communications initiated through website contact mechanisms, regardless of the location of the data principal or the jurisdiction from which the website is accessed.

For the purposes of the DPDP Act, Dr John Mathews functions as a Data Fiduciary, meaning this individual determines the purposes and means of processing personal data and assumes all corresponding obligations and liabilities under the Act and Rules. This designation means personal data is collected, processed, and managed under direct control and responsibility, with full accountability to data principals and regulatory authorities.

This Policy applies globally, with particular emphasis on the rights and protections afforded under Indian law. The DPDP Act extends to all personal data collected from individuals residing in India or processed in connection with offering goods or services to such individuals, irrespective of where the data is stored or processed.

2. OUR COMMITMENT TO DATA PROTECTION

Dr John Mathews is firmly committed to the protection of personal data as a fundamental right and recognizes the importance of transparency, accountability, and respect for individual autonomy in all data processing activities. This commitment is reflected in the following foundational principles:

3. DATA FIDUCIARY IDENTIFICATION AND CONTACT

Data Fiduciary: Dr John Mathews
Location: Mumbai, Maharashtra, India
Jurisdiction: India (Primary)

Grievance Officer and Data Protection Contact:

Name: Dr John Mathews
Email: hello@drjohnmathews.com

Contact Escalation: Inquiries will be acknowledged within 7 calendar days and substantively addressed within 30 calendar days. Queries concerning data protection, privacy concerns, grievances, or requests for exercising data principal rights should be directed to the contact details above. Grievances will be handled in accordance with the timelines and procedures established under the DPDP Act.

For any questions, grievances, or to exercise your rights as a Data Principal, please contact the Grievance Officer using the contact details provided above.

4. CATEGORIES OF PERSONAL DATA COLLECTED

The Organization collects personal data only when it is necessary to provide services, respond to inquiries, or fulfill compliance obligations. Personal data collected through various touchpoints is categorized as follows:

4.1 Contact and Consulting Inquiry Forms

When a visitor or prospective client submits a contact form, consulting inquiry form, or similar communication mechanism available on this website, the following personal data may be collected:

Data principals are expressly cautioned against submitting passwords, personal identification numbers, passport numbers, Aadhaar numbers, government-issued identification document numbers, biometric data, health information, financial account details, or any information that would be classified as sensitive personal data under applicable law through unsecured contact forms or general inquiry mechanisms. If such information is submitted inadvertently, it will be deleted immediately upon discovery.

4.2 Dedicated DAREM Report Request Forms

The Organization offers an indicative DAREM assessment tool that generates educational reports based on input data. When a data principal requests a DAREM report, the following personal data is collected:

This data is processed exclusively to generate an indicative, educational report. The Organization conducts limited analysis of these business attributes for the purpose of improving the DAREM model methodology and analytical accuracy.

4.3 Technical and Usage Data (Automatic Collection)

When a visitor accesses, browses, or interacts with this website, certain technical information is automatically collected by website infrastructure, analytics systems, and security mechanisms. This technical data is collected without explicit action by the visitor and includes:

Technical data is collected through conventional web server logs, analytics packages (where consent-based analytics are enabled), and security monitoring systems necessary for website operations, fraud prevention, and cybersecurity.

5. LAWFUL GROUNDS FOR PROCESSING AND EXPLICIT CONSENT

The DPDP Act permits personal data processing based on either explicit consent or certain legitimate grounds recognized by the statute. The Organization processes personal data on the following lawful grounds:

5.1 Explicit Consent (Primary Basis)

Consent-Based Processing: The primary lawful ground for processing personal data is explicit, free, specific, informed, unconditional, and unambiguous consent obtained from the data principal through clear affirmative action. Consent is required before the processing of personal data in the following circumstances:

Withdrawal of Consent: A data principal may withdraw consent at any time by sending written communication to the Grievance Officer using the contact details in Section 3. Withdrawal of consent is effective immediately, and processing of personal data must cease. Where consent is withdrawn, the Organization will delete the relevant personal data within thirty (30) calendar days unless continued retention is permitted under another lawful ground (such as legal or regulatory obligation).

5.2 Legitimate Grounds for Processing Without Prior Consent

The DPDP Act recognizes certain legitimate grounds for processing personal data without obtaining prior explicit consent from the data principal. The Organization processes personal data without prior consent in the following circumstances:

6. PRIVACY NOTICE AND CONSENT REQUEST REQUIREMENTS

The DPDP Act and Rules mandate that a clear, plain-language privacy notice be provided to data principals before consent is sought. This Privacy Policy serves as the comprehensive notice document. Additionally, specific notices are displayed with each data collection mechanism as follows:

6.1 Contact Form Privacy Notice

The following notice is displayed prominently above the "Submit" button on all general contact and consulting inquiry forms:

"Privacy Notice: By submitting this contact form, you consent to the processing of your personal information (name, email address, telephone number, and the content of your inquiry) for the purposes of responding to your inquiry, providing information about our AML consulting services, and follow-up communication regarding the services or topics you inquire about. Your data will be processed in accordance with our Privacy Policy and the Digital Personal Data Protection Act, 2023. You may withdraw your consent at any time by sending written notice to our Grievance Officer. Your information will be deleted after resolution of your inquiry and our consultation response, unless you consent to continued communication or unless we are required to retain it for legal or regulatory purposes. No automatic professional relationship or consulting engagement is created by submitting this form. For detailed information about how we process your data, please review our complete Privacy Policy."

6.2 DAREM Form Privacy Notice

The following notice is displayed prominently near the "Generate Report" button on the DAREM request form:

"Consent Confirmation: I confirm that (1) I am authorized by my organization to submit the information contained in this form; (2) I have read and understood the Privacy Policy; (3) I consent to the processing of my personal information and my organization's business attribute data for the purposes of generating an indicative DAREM assessment report; and (4) I understand that the DAREM report is generated solely for educational and informational purposes and is not professional advice, audit finding, or regulatory guidance.

Educational Use Acknowledgment: I acknowledge and agree that the DAREM report is an auto-generated, indicative assessment based solely on the inputs I have provided and is intended for educational purposes only. I will verify the accuracy of my inputs and the reasonableness of the resulting assessment. I will consult with qualified AML compliance professionals, external auditors, or legal counsel before relying on the report for compliance decisions or regulatory matters."

7. PURPOSES OF PROCESSING

Personal data is processed only for the following specific, lawful, and explicit purposes. Processing for purposes other than those listed below is strictly prohibited:

7.1 Response to Inquiries and Delivery of Consulting Services

The Organization processes contact information (name, email, telephone) and inquiry content for the purpose of:

Processing for this purpose is necessary to fulfill the data principal's explicit request and to provide the services requested.

7.2 Generation of Indicative DAREM Assessment Reports

The Organization processes organizational business attribute data and professional information collected through the DAREM form for the purposes of:

The DAREM report is strictly educational and is not a professional audit, regulatory assessment, or basis for compliance decisions.

7.3 Website Maintenance, Security, and Improvement

The Organization processes technical and usage data for the following operational purposes:

7.4 Legal and Regulatory Compliance

The Organization may process personal data without prior consent to comply with:

7.5 Business Communication and Service Notifications

The Organization may process contact information to send:

7.6 Prohibited Uses

Personal data will NOT be used for the following purposes:

8. DATA SHARING AND RECIPIENTS

Personal data is shared with third parties only on a need-to-know basis, where necessary to fulfill the specified purposes of processing, and only where adequate safeguards are in place. The following categories of recipients may receive personal data:

8.1 Data Processors and Contractual Recipients

8.2 Professional Advisers

The Organization may disclose personal data to professional advisers including:

8.3 Regulatory and Law Enforcement Authorities

Personal data may be disclosed to:

8.4 Cross-Border Transfers

Personal data will be transferred outside India only in the following circumstances:

The Organization does NOT engage in the sale, rental, or commercial licensing of personal data to third parties.

9. DATA RETENTION, STORAGE, AND DELETION

Personal data is retained only for the period necessary to fulfill the purposes for which it was collected or to comply with applicable legal or regulatory retention requirements. Data that is no longer necessary is securely deleted or anonymized.

9.1 Retention Periods by Data Category

9.2 Deletion and Anonymization Process

Upon expiration of the retention period, or upon receipt of a deletion request from a data principal, personal data is deleted through one of the following methods:

9.3 Legal Hold and Litigation Preservation

Notwithstanding the above retention periods, where personal data is subject to a legal hold due to pending or threatened litigation, regulatory investigation, or law enforcement request, the data will be retained in a secure format until the legal matter is resolved or the hold is released.

10. COOKIES, TRACKING TECHNOLOGIES, AND ANALYTICS

10.1 Essential Cookies

The website uses essential cookies and similar tracking technologies necessary for core website functionality. These cookies are deployed without requiring consent and include:

Essential cookies do not track behaviour across websites and are deleted when the browser session ends or after a specified period.

10.2 Non-Essential Analytics Cookies

The Organization may deploy analytics cookies to understand visitor behaviour, content effectiveness, user journey, and website performance. These cookies are deployed only where a visitor has consented to non-essential cookies through a prominent cookie banner or preference management tool. Analytics cookies permit the Organization to:

Consent Mechanism: A clear, prominent cookie banner is displayed on the website permitting visitors to accept or decline non-essential cookies. Visitors may modify cookie preferences at any time through website settings or browser controls.

Third-Party Analytics: Analytics may be provided by third-party services (such as Google Analytics or similar platforms). These services are subject to their own privacy policies and terms. The Organization shares only aggregated, anonymized data with these services.

10.3 Managing Cookies

Visitors may manage cookies through their web browser settings, enabling or disabling all cookies (though this may impair website functionality) or selectively disabling specific categories. Most browsers provide instructions for managing cookies in their help sections.

11. SECURITY SAFEGUARDS AND DATA PROTECTION

The Organization implements comprehensive technical and organizational security measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, and disclosure. These measures include:

11.1 Technical Security Measures

11.2 Organizational Safeguards

11.3 Limitation of Liability for Security

While the Organization implements reasonable security safeguards, no security measure is absolute, and perfect security is technically impossible. The Organization cannot guarantee that personal data will never be subject to unauthorized access, loss, or disclosure despite reasonable precautions. Data principals acknowledge and assume this inherent risk of data processing.

12. CHILDREN'S DATA AND VULNERABLE PERSONS

12.1 Restricted Collection of Children's Data

This website and its services are not directed to individuals under the age of eighteen (18) years. The Organization does not intentionally collect personal data from children. Where data from an individual under eighteen (18) is inadvertently collected, such data will be deleted immediately upon discovery, and the parent or lawful guardian will be notified.

Should a data principal be under eighteen (18) years of age, consent to the processing of personal data must be provided by a parent or lawful guardian. The Organization will make reasonable efforts to verify that the consenting party is indeed the parent or lawful guardian before processing data of a child.

12.2 Vulnerable Persons

Where a data principal is a person with a disability or incapacity and is unable to provide legal consent independently, the Organization will require consent from a lawful guardian or representative authorized under applicable law. Verification of guardianship authority is required before processing proceeds.

13. RIGHTS OF DATA PRINCIPALS UNDER THE DPDP ACT

The DPDP Act grants the following rights to all data principals. The Organization will facilitate the exercise of these rights upon receipt of a documented request:

13.1 Right to Be Informed

Data principals have the right to receive clear, plain-language information about:

This right is fulfilled through this Privacy Policy and the privacy notices displayed with data collection mechanisms.

13.2 Right to Access

A data principal may request access to all personal data held by the Organization that relates to the data principal. Upon receipt of a valid access request, the Organization will provide, within ninety (90) calendar days:

Access will be provided in a commonly used, machine-readable electronic format, free of charge (unless the request is manifestly unfounded or excessive, in which case a reasonable fee may be charged).

13.3 Right to Correct and Complete

A data principal may request correction of personal data that is inaccurate, incomplete, or misleading. Upon receipt of a valid correction request, the Organization will:

13.4 Right to Erasure (Right to Be Forgotten)

A data principal may request deletion of personal data in the following circumstances:

Upon receipt of a valid erasure request, the Organization will delete the personal data within thirty (30) calendar days unless:

The Organization will notify the data principal of the status of the erasure request.

Limitation: Erasure may not be granted where personal data is necessary for the performance of a consulting engagement that is currently active or for which dispute resolution is pending.

13.5 Right to Withdraw Consent

A data principal may withdraw consent to processing at any time by submitting written notice to the Grievance Officer. Withdrawal is effective immediately. Upon withdrawal:

Withdrawal of consent does not affect the lawfulness of processing conducted prior to the withdrawal.

13.6 Right to Nominate a Representative

A data principal may authorize another individual to exercise the data principal's rights under the DPDP Act on their behalf. A formal nomination or power of attorney document must be provided, along with identity verification of both the data principal and the nominee.

13.7 Right to Lodge a Grievance

A data principal may lodge a grievance or complaint with the Organization concerning any aspect of data processing or alleged violations of the DPDP Act.

14. EXERCISING RIGHTS AND GRIEVANCE REDRESSAL MECHANISM

14.1 Data Subject Access Request Procedure

To exercise any of the rights described in Section 13, a data principal must submit a written request to the Grievance Officer at the contact details provided in Section 3, clearly identifying:

14.2 Grievance Officer Response Timeline

The Grievance Officer will:

15. POLICY AMENDMENTS AND UPDATES

This Privacy Policy is subject to periodic amendment to reflect changes in applicable law, regulatory guidance, business practices, or security standards. Material amendments to this Policy will be notified to affected data principals through:

Continued use of the website or services following notification of material amendments constitutes acceptance of the amended Policy. Data principals who do not accept amendments may request deletion of their personal data and termination of any consulting relationship.