Data Protection and Information Security Policy

Last Updated: November 9, 2025

Scope: This Data Protection and Information Security Policy applies to synapseconclave.in and all digital platforms operated by Lucid Lines Productions Private Limited, including synapseconclave.com. This policy outlines our commitment to protecting your personal information and maintaining the highest standards of data security.

1. Purpose and Commitment

Our Uncompromising Commitment to Data Protection

Lucid Lines Productions Private Limited is committed to:

This policy demonstrates our adherence to:

2. Governance and Accountability

2.1 Data Protection Officer (DPO)

2.2 Organizational Responsibility

3. Data Collection and Processing Principles

3.1 Lawfulness, Fairness, and Transparency

3.2 Data Minimization

3.3 Purpose Limitation

3.4 Accuracy

4. Categories of Personal Data Processed

Data Category Purpose Legal Basis Retention Period
Identity Data (name, title, ID) Event registration, entry verification Contract, Legal obligation 3 years post-event
Contact Data (email, phone) Communication, updates Contract, Consent Until consent withdrawal
Financial Data (payment info) Transaction processing Contract, Legal obligation 7-10 years (tax law)
Professional Data (company, role) Networking, event customization Contract, Legitimate interest 3 years post-event
Health Data (dietary, accessibility) Accommodation provision Explicit consent Deleted after event
Technical Data (IP, cookies) Website functionality, analytics Consent, Legitimate interest Variable (see Cookie Policy)

5. Information Security Framework

5.1 Technical Security Measures

Encryption and Secure Transmission
Access Controls
Infrastructure Security

5.2 Organizational Security Measures

5.3 Network Security

5.4 Application Security

6. Payment Security

6.1 PCI DSS Compliance

6.2 Transaction Security

7. Data Sharing and Third-Party Processing

7.1 No Sale of Data

Absolute Commitment: We will NEVER sell, rent, or trade your personal information to any third party for any purpose.

7.2 Limited Third-Party Sharing

We share data only with trusted service providers who assist in:

7.3 Data Processing Agreements

8. Data Retention and Disposal

8.1 Retention Principles

8.2 Secure Disposal

9. Rights of Data Subjects

9.1 Right to Access

9.2 Right to Rectification

9.3 Right to Erasure (Right to be Forgotten)

9.4 Right to Restriction

9.5 Right to Data Portability

9.6 Right to Object

9.7 Right to Withdraw Consent

10. Data Breach Response

10.1 Incident Detection

10.2 Breach Response Procedure

  1. Containment: Immediate action to contain the breach
  2. Assessment: Evaluate scope and impact
  3. Notification: Notify affected individuals within 72 hours (if high risk)
  4. Reporting: Report to relevant authorities as required
  5. Remediation: Implement fixes and preventive measures
  6. Documentation: Maintain detailed incident records

10.3 User Notification

11. International Data Transfers

12. Children's Data Protection

13. Cookies and Tracking Technologies

14. Vendor and Partner Security

15. Physical Security

16. Business Continuity and Disaster Recovery

17. Monitoring and Compliance

18. Employee and Contractor Obligations

19. Transparency and Accountability

20. Policy Review and Updates

21. Contact Information

Data Protection Inquiries

Data Protection Officer
Lucid Lines Productions Private Limited

Response time: Within 30 days for all legitimate requests

22. Regulatory Compliance

This policy demonstrates our compliance with:

Our Promise: We are committed to maintaining the trust you place in us by protecting your personal information with the highest standards of security, transparency, and ethical data handling. Your privacy is not just our policy—it's our principle.

© 2025 Lucid Lines Productions Private Limited. All rights reserved.
synapseconclave.in is part of the Synapse Conclave digital ecosystem.