Grievance Redressal Procedure

This Grievance Redressal Procedure was last updated on August 5, 2026. If there will be any update, amendment, or changes to our Grievance Redressal Procedure then these will be posted on this page

1. Purpose:
1.1.To establish a formal mechanism for external stakeholders (clients, vendors, visitors) to lodge and
resolve grievances related to data protection, privacy practices, or service delivery, ensuring
transparency, consistency, and compliance with ISO 27001:2022 and the Digital Personal Data
Protection Act (DPDPA) 2023.

2. Scope:
2.1 This procedure applies to all grievances raised by external parties regarding IDA Analytics’ products,
services, website privacy notice, consent mechanisms, or data handling.

3. References:
3.1 ISO/IEC 27001:2022 – Information Security, Cyber security, and Privacy Protection-Information
Security Management System- Requirements.
3.2.Digital Personal Data Protection Act, 2023 (DPDPA)

4. Acronyms:
4.1 HR: Human Resource
4.2 DPDPA – Digital Personal Data Protection Act, 2023
4.3 DGC – Data Governance Committee
4.4 COO – Chief Operating Officer
4.5 EGRC – External Grievance Redressal Committee

5. Definitions:
5.1 Data Principal: The natural person to whom the personal data relates.
5.2 Data Fiduciary: Any person, including the State, who alone or in conjunction with others
determines the purpose and means of processing personal data.
5.3 Data Processor: Any person who processes personal data on behalf of the Data Fiduciary.
5.4 Consent: Free, informed, specific, clear, and capable of being withdrawn agreement by the Data
Principal for processing their personal data.
5.5 Personal Data: Any data about an individual who is identifiable by or in relation to such data.
5.6 Processing: A wholly or partly automated operation or set of operations performed on digital
personal data, including collection, recording, organization, storage, use, sharing, disclosure,
retrieval, alignment, combination, indexing, erasure or destruction.
5.7 Personal Data Breach: Any unauthorized processing of personal data or accidental disclosure,
acquisition, sharing, use, alteration, destruction or loss of access to personal data that
compromises the confidentiality, integrity or availability of personal data.
5.8 External Stakeholder: Any client, customer, vendor, service provider, visitor, Data Principal or
other external party interacting with IDA.
5.9 Grievance: Any expression of dissatisfaction or concern raised by an external stakeholder
relating to IDA’s services, data protection, privacy practices, information security, processing of
personal data or other matters falling within the scope of this procedure

6. Roles and Responsibilities:

External Stakeholder Submit grievance with sufficient details and supporting evidence, where
available, and provide additional information reasonably required for
investigation
EGRC Chairperson Provide oversight of the grievance redressal process, lead committee
deliberations, ensure appropriate resolution and adherence to defined
timelines
Committee Secretary Acknowledge grievances, maintain the Grievance Register, coordinate
investigation and committee communication, track timelines, maintain records
and facilitate closure.
EGRC Members Review and investigate assigned grievances, obtain relevant information,
participate in deliberations and recommend corrective/remedial actions.
Risk & Compliance Provide oversight for grievances relating to privacy, personal data, information
security, regulatory or compliance matters and coordinate necessary
escalation.
Relevant Department
/ Process Owner
Support investigation, provide required information/evidence and implement
approved corrective or preventive actions within agreed timelines.
Appellate Authority –
COO
Independently review escalated/appealed grievances and communicate the
final internal decision.

6.1.1 The External Grievance Redressal Committee (EGRC) shall comprise representatives from
relevant business and support functions to ensure appropriate review, investigation and
resolution of external grievances.
6.1.2 The EGRC shall have representation from the following functions:

Committee Role Functional Representation
Chairperson Chief Operating Officer (COO)
Member Service Operations
Member IT & Compliance / Technical
Member Human Resources
Member / Committee Coordinator Risk & Compliance
Member Legal
Member Location Representative

6.1.3 The names of the nominated EGRC members shall be maintained separately through an
approved EGRC Committee Member Register/List and updated whenever there is a
change in committee membership.
6.1.4 Any addition, replacement or change in EGRC membership shall be approved by the
appropriate Management Authority. Changes to individual members shall not require
revision of this procedure, provided that the required functional representation is
maintained.

7. Procedure Steps:
7.1 Lodging a Grievance: External stakeholders may submit grievances to the External Grievance
Redressal Committee through the dedicated email address: [email protected]
The grievance should contain the following information, where applicable:
7.1.1. Description of the grievance, including relevant date(s), event(s), affected service, process
or personal data.
7.1.2 Full name and contact details of the complainant.
7.1.3 Relevant client, vendor, transaction, service or other reference details, where applicable.
7.1.4 Preferred resolution or expected outcome, if any.
7.1.5 Supporting documents or evidence, if available.
7.1.6. Personal data submitted as part of a grievance shall be processed only to the extent
necessary for investigating, resolving, documenting and complying with applicable legal,
regulatory or contractual requirements relating to the grievance, in accordance with
applicable data protection requirements and IDA’s Privacy Policy.
7.2.Acknowledgement – The Committee Secretary/Coordinator shall acknowledge receipt of the
grievance within 3 business days of receipt. The acknowledgement shall, where applicable, include
the grievance reference number, date of receipt, next steps and expected resolution timeline.
7.3.Review & Investigation – The External Grievance Redressal Committee will convene to:
7.3.1 Upon receipt, the grievance shall be reviewed and classified based on its nature, including
where applicable:
7.3.1.1. Service Delivery
7.3.1.2. Data Protection / Privacy
7.3.1.3. Information Security
7.3.1.4. Data Principal Rights
7.3.1.5. Contractual / Client-related
7.3.1.6. Vendor-related
7.3.1.7. Website / Privacy Notice / Consent-related
7.3.1.8. Other External Grievance
7.3.2 Grievance shall be assigned an appropriate severity of High, Medium or Low based on its
impact, urgency, sensitivity of information involved, number of affected individuals,
contractual implications and regulatory/compliance risk.
7.3.3 Appropriate EGRC members, department(s) or process owner(s) shall be assigned to
investigate the grievance and gather relevant information and evidence.
7.3.4 Relevant business functions, vendors, service providers, clients or other third parties may
be consulted where necessary for investigation, subject to applicable confidentiality and
need-to-know requirements.
Any EGRC member having an actual or potential conflict of interest in relation to
grievance shall disclose the conflict and shall not participate in the investigation or
decision-making for that grievance.
7.3.5. Grievances relating to personal data, privacy, regulatory compliance or information
security shall be escalated to Risk & Compliance and/or the Data Governance Committee,
as applicable, for assessment and necessary action.
7.3.6. Where a grievance indicates or is suspected of involve an information security incident or
personal data breach, the matter shall be immediately escalated and handled in
accordance with IDA’s applicable Information Security Incident Management and Data
Breach Management procedures. The grievance process shall not delay any required
containment, investigation, notification, regulatory or contractual action.
7.4 Decision & Communication – Within 30 calendar days of the acknowledgement, the Committee
will:
7.4.1 The EGRC shall review the investigation findings and determine the appropriate response,
corrective action, preventive action or other remedial measures, as applicable.
7.4.2 The outcome and applicable remedial measures shall be communicated in writing to the
complainant within 30 calendar days from receipt of the grievance, subject to the nature
and complexity of the matter.
7.4.3 Where resolution within the defined timeline is not reasonably possible due to
complexity, dependency on the complainant, third-party involvement or other justified
reasons, the complainant shall be informed of the status and revised expected resolution
timeline.
7.4.4 Where corrective or preventive actions are identified, the responsible
department/process owner shall implement the actions within agreed timelines and
provide appropriate evidence of closure.
7.4.5 Significant findings may be considered for risk assessment, process improvement,
policy/procedure changes, training or other appropriate corrective measures.
7.5 Appeal Process – If the complainant is dissatisfied with the resolution, they may request an
internal review by the Appellate Authority (COO) by responding to the decision communication
within 15 calendar days of receiving the outcome.
7.5.1. The Appellate Authority shall review the grievance, investigation findings, decision and
any additional information submitted by the complainant.
7.5.2. The final internal decision shall ordinarily be communicated within 15 calendar days from
receipt of the appeal.
7.6 Closure – Grievance shall be considered closed when the resolution has been communicated to
the complainant and all applicable corrective/remedial actions have been completed or appropriately
tracked.
7.6.1. Where an appeal has been raised, the grievance shall be closed following communication
of the Appellate Authority’s final internal decision and completion/tracking of applicable
actions.
7.6.2. The closure status, closure date, outcome, supporting evidence and applicable
CAPA/reference numbers shall be recorded in the Grievance Register.
7.7 Confidentiality:
7.7.1. All grievances, supporting evidence, investigation records and communications shall be
treated as confidential and shall be accessible only to personnel having a legitimate
business need.
7.7.2. Personal data collected or generated during the grievance process shall be limited to what
is reasonably necessary for investigation, resolution, documentation and compliance
purposes.
7.7.3. Grievance records shall be appropriately protected against unauthorized access,
disclosure, alteration, loss or destruction in accordance with IDA’s information security
and data protection requirements.
7.7.4. Information relating to grievance only is shared internally or externally where necessary
for investigation, resolution, legal/regulatory compliance or contractual requirements
and subject to appropriate confidentiality controls.

8. Contact Us:
8.1 If you have any concerns or complaints related to our services, data processing practices, or any
conduct pertaining to IDA Analytics Pvt Ltd, you may contact our External Grievance Redressal
Committee by emailing: [email protected] All submissions will be treated
confidentially and addressed within 30 working days as per IDA’s grievance resolution guidelines.

9. Non-Compliance:
9.1 Failure to comply with the External Redressal procedure may result in disciplinary action as per
IDA Policy.

Contact Us

Give us a call or fill in the form below and we will contact you. We endeavor to answer all inquiries within 24 hours on business days.






    ×

    Privacy Policy

    Please read and tap Accept at the end

    1. Policy:
    1.1 This Privacy Policy describes how IDA Automation Private Limited (https://idaautomation.com/) (“Company,” “we,” “us,” or “our”) collects, uses, and protects the personal data of users (“Data Principals”) in accordance with the Digital Personal Data Protection Act (DPDPA), 2023.

    1.2 Eligibility:
    The IDA website is intended solely for people aged 18 years or older. By registering, you confirm you meet this age requirement. We do not knowingly collect data from “children”.

    1.3 The Personal Data We Collect & Purposes of Processing:
    In accordance with the principle of “Purpose Limitation,” we collect only the data necessary for the following

    Sl. No. Data Category Purpose of Processing
    1 Registration Information (Name, Contact Details) To fulfil service requests, create accounts, and facilitate services.
    2 Technical Data (IP Address, Browser Type) To ensure software compatibility, site security, and improve web design/functionality.
    3 Cookies & Usage Data To track preferences, analyse site activity, and personalize “IDA Offers & Services.”

    1.4 Disclosure and Sharing of Data:
    We do not sell or rent your personal information. We share data only under the following conditions:

    • Service Providers: With third-party vendors (e.g., email hosting, recruitment partners) bound by strict confidentiality and DPDPA-compliant data processing agreements.

    • Legal Necessity: When required by law, subpoena, or to prevent illegal activities and enforce our Terms of Use.

    [A cookie is a data file that sits on your computer hard disk. The cookie is placed there by a remote web server that you have visited using a browser like Netscape or Internet Explorer. It is used to uniquely identify you during web interactions with a website and contains data parameters that allow the remote HTML server to keep a record of who you are, and what actions you take at the remote web site. You have the option to disable the cookie function in your browser but will be restricted from accessing many sites as a result.]

    1.5 Lawful Basis of Processing:
    Your Personal Data can be processed on the following lawful basis:

    Consent: Based on the explicit consent provided by you.
    Legal Basis: To comply with legal obligations i.e. required by laws and regulations
    Contractual Obligation: To fulfil a contract to which you are a party, such as a contract with you, or as needed to fulfil a contract or agreement between you and IDA.
    Legitimate Interest: Personal Data may be processed based on legitimate interest, as permitted by applicable laws.

    1.6 Use of Personal Data:

    IDA Automation Pvt. Ltd. may on occasion use your personal information to contact you about promotional offers; advise you of matters relevant to service provision and in some cases solicit your feedback. However, IDA Automation Pvt. Ltd. will provide you with an option within every communication to opt out of receiving any communications of this nature or you can contact our customer services representatives to ensure that you do not receive such promotional information.

    IDA Automation Pvt. Ltd. collects and shares aggregated user data with business partners, sponsors or other third parties for the purposes of developing content and ensuring relevant advertising and content, such user data will never be used to identify individual users. These business partners and affiliated companies do not have any independent right to share this information.

    IDA Automation Pvt. Ltd. may log onto the websites you visit; collect IP addresses and information about your operating system and the type of browser you use for the purposes of network/system administration; to report aggregate information to our advertisers, and to audit the use of our site. This data however will not be used to identify individual users who will at all times remain anonymous.

    • Any information IDA Automation Pvt. Ltd. collects from you through correspondence with us, whether via e-mail, telephonically or by written letter, will only be used to address the matters within that correspondence. If this requires referring such correspondence within IDA Automation Pvt. Ltd. or to a third party to ensure customer service, your personal information will only be disclosed to the point necessary to address your queries or concerns and will otherwise be kept confidential.

    1.7 Rights of Data Principals (As per DPDPA):
    As per the Digital Personal Data Protection Act (DPDPA), individuals (Data Principals) are entitled to exercise the following rights:

    Right to Access: Request access to their personal data and details on how it is processed.

    Right to Correction and Erasure: Request correction of inaccurate data or deletion of personal data no longer required.

    Right to Grievance Redressal: You have the right to register a grievance regarding any act or omission by us regarding your data. If you wish to make a complaint or are unhappy with the way we process your personal data or handle the exercise of your rights under applicable data protection laws, you may submit your grievance by contacting us as indicated below.

    Right to Withdraw Consent: You may withdraw consent at any time. Please note that withdrawing consent may impair the functionality of our services.

    Right to Nominate: You have the right to nominate another individual who can exercise your rights in the event of your death or incapacity. If you would like to designate a nominee, please send an email from your registered email address providing the nominee’s full name, contact number, email address, and relationship to you. We will respond to the nominee’s requests using both your email address and the nominee’s email address. We aim to complete the verification process and respond to your request in a manner and within the timeframe required by law. If additional time is needed,we will inform you of the reason and the expected timeframe for completion.

    Data Retention and Deletion: IDA may retain personal data in accordance with its Data Retention Policy and applicable legal or regulatory requirements and may archive such data to meet statutory or legal obligations. To exercise data subject rights, including requests for data retention, deletion, or withdrawal of consent, individuals may contact IDA at [email protected]

    2. Public Space:
    (Bulletin Boards, Chat Rooms and Third-Party Sites)
    2.1 Any information that customers disclose in a public space, including on any bulletin board, chat room or any site IDA Automation Pvt. Ltd. may host for you, is available to anyone else who visits that space. IDA Automation Pvt. Ltd. cannot safeguard any information you disclose there.

    3. Site Linking:
    3.1 IDA Automation Pvt. Ltd.’s websites contain many links to sites that belong to third parties unrelated to us. IDA Automation Pvt. Ltd. cannot be held responsible for any use of your personal information arising from you disclosing such personal information on third party sites. IDA Automation Pvt. Ltd. cannot protect any information you may disclose on these sites and recommends that you review the privacy policy statements of those sites you visit.

    4. Minors:
    4.1 IDA Automation Pvt. Ltd. will not enter into a service subscription contract with a minor unless such minor has explicit written consent from a parent or guardian to do so. IDA Automation Pvt. Ltd. undertakes not to contact minors about promotional offers or for marketing purposes without parental consent.

    5. Reservation of Rights:
    5.1 IDA Automation Pvt. Ltd. reserves the right to disclose information about customers where required in good faith, to do so by law or to exercise our legal rights or defend ourselves against legal claims.

    5.2 IDA Automation Pvt. Ltd. further reserves the right to share information with law enforcement to investigate or prevent illegal activities being committed over our network.

    5.3 IDA Automation Pvt. Ltd. reserves our rights to disclose your personal information where you have given us explicit legal written consent to do so.

    5.4 IDA Automation Pvt. Ltd. reserves the right to monitor user and network traffic for site security purposes and prevent any unauthorized attempts to tamper with our site or cause damage to our property.

    5.5 IDA Automation Pvt. Ltd. reserves the right to make changes to this privacy policy or update it. Where a major change is made, customers will be informed by e-mail notification or through a notice on our website. Customers and site visitors bear the responsibility to ensure that they have read the changes or updates as the case may be.

    6. Cookie Policy:
    6.1 Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with good experience when you browse our website and also allows us to improve our site. By continuing to browse the site, you are agreeing to our use of cookies.

    6.2 A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your
    computer if you agree. Cookies contain information that is transferred to your computer’s hard drive.

    6.3 We use analytical/performance cookies. They allow us to recognize and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.

    6.4 Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies.

    6.5 You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site.

    7. Grievance Redressal Mechanism:
    7.1 In compliance with DPDPA, if you have any concerns or complaints related to our services, data processing practices or requests to exercise your rights, or any conduct pertaining to IDA Automation Pvt Ltd, you may contact our External Grievance Redressal Committee at: [email protected]

    7.2 You may also reach out to the Compliance Officer directly:
    Name: Mr. Tushar B Sheth
    Designation: Risk & Compliance Manager
    Email id: [email protected]
    Group Compliance DL: [email protected]

    All submissions will be treated confidentially and addressed within 30 working days as per IDA’s grievance resolution guidelines.

    8. Breach Notification and Escalation:
    8.1 Data Breach Incident: In the event of a data breach involving your personal information, we will notify you and the Data Protection Board of India in an expedient manner and without unreasonable delay. Notifications will be provided in the form and manner prescribed by the regulatory body. The notification will include a description of the incident, the types of personal data affected, the measures we have taken to address the breach, and how you can contact us for more information.

    8.2 Any suspected or actual breach involving personal data must be reported immediately to the Compliance and IT teams to their email address Compliance External.Grievance [email protected] & IT Support [email protected]

    9. Consent Affirmation:
    9.1 By clicking “I Agree” or by continuing to use the IDA Platform, you provide your free, specific, informed, unconditional, and unambiguous consent to the processing of your personal data for the purposes mentioned above.

    9.2 I confirm that I am not a minor or otherwise disqualified to enter into contracts and in providing this consent, I am acting on behalf of myself or as guardian of the data principal.

    10. Non-Compliance:
    10.1 Failure to comply with the External Privacy Policy may result in disciplinary action as per IDA Policy.