PUBLIC & MEMBER PRIVACY POLICY AND DATA PROTECTION CHARTER
LAST UPDATED & EFFECTIVE DATE: July 24, 2026
OPERATIONAL ENTITY: The Cove & Kin LLP
APPLICATION & PLATFORM SCOPE: Public Website/Applications (thecoveandkin.club), Guest Checkout Services, and The Circle Member Portal (Progressive Web Application) and Associated Internet Domains (.in).
1. PREAMBLE, CORPORATE IDENTITY & DATA FIDUCIARY FRAMEWORK
1.1 Corporate Identity and Purpose
This Public & Member Privacy Notice and Data Protection Charter (“Privacy Charter”) governs all digital touchpoints, data collection mechanisms, proprietary web applications, and network infrastructure operated by The Cove & Kin LLP (hereinafter referred to as “The Cove & Kin,” “The Club,” “We,” “Us,” or “Our”).
The Cove & Kin operates as an exclusive, private, invitation-only sanctuary for high-net-worth families. Our brand philosophy is anchored in “Presence Over Pace”—facilitating unhurried, physical parent-child bonding, vulnerable peer-to-peer kinship, and mindful offline experiences. Our digital ecosystem, collectively referred to as “The Cove OS,” exists strictly to protect, automate, and streamline the logistical, security, and verification touchpoints of our physical community.
1.2 Statutory Capacity as Data Fiduciary
Under the provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, and applicable global data privacy regulations, The Cove & Kin LLP functions as a “Data Fiduciary” (or “Data Controller” under the General Data Protection Regulation – GDPR). As a Data Fiduciary, We determine the purpose and means of processing personal data provided by prospective visitors, guest event purchasers, applicant families, and active members.
We are committed to maintaining the highest standard of technical, organizational, and physical data protection measures. Privacy is not merely a legal compliance obligation for Our organization; it is an foundational operational boundary designed to safeguard the identities, family structures, physical security, and minor children of Our community members.
2. LEGAL TAXONOMY & GLOBAL STATUTORY BOUNDARIES
2.1 Geographic and Jurisdictional Scope
This Privacy Charter applies globally to any individual who accesses Our public domain names, interacts with Our guest ticketing interfaces, submits an alignment inquiry, or authenticates into The Circle Member Portal. The processing of all personal data is primary localized, stored, and processed within secure, enterprise-grade cloud server infrastructure physically located within the Republic of India (Mumbai Data Region).
2.2 Legislative Compliance Alignment
This Privacy Charter is architected to satisfy, align with, and enforce compliance across the following statutory and regulatory frameworks:
- DPDP Act, 2023 (India): Strict compliance with Section 6 (Notice Mechanisms), Section 8 (Duties of Data Fiduciaries), Section 9 (Processing of Personal Data of Children), Section 11 & 12 (Data Principal Rights and Erasure Protocols), and Section 13 (Grievance Redressal Mechanics).
- CERT-In Cyber Security Directions (2022/2023): Compliance with the mandatory retention of operational, security, and administrative system activity logs for a period of 180 days within Indian jurisdiction.
- PCI-DSS (Payment Card Industry Data Security Standard): Adherence to PCI-DSS SAQ-A standards via complete integration of tokenized, outsourced payment processing infrastructure, ensuring zero credit card or bank credentials touch Our primary application database.
- General Data Protection Regulation (GDPR / UK GDPR): Compliance with extra-territorial provisions for international members, enforcing lawful bases of processing under Article 6 and sensitive category processing under Article 9.
- Children’s Online Privacy Protection Act (COPPA) & California Consumer Privacy Act (CCPA/CPRA): Alignment with global gold standards regarding the prohibition of unauthorized child data collection, non-sale of personal data, and parental consent verification.
3. USER TAXONOMY & DATA CATEGORIZATION MATRIX
To ensure complete transparency and adhere to the principle of Data Minimization, The Cove & Kin categorizes all platform users into three distinct legal entities. Data processing is granularly restricted based on these user classifications.
+---------------------------------------------------------------------------------------------------+
| DATA PROCESSING & USER TAXONOMY |
+---------------------------------------------------------------------------------------------------+
| |
| [ CLASS A: PUBLIC PLATFORM VISITORS ] |
| ├── Interaction: Unauthenticated browsing on public landing pages. |
| └── Data Scope: Anonymous IP telemetry, edge CDN headers, device metadata, essential cookies. |
| |
| [ CLASS B: GUEST EVENT PURCHASERS ] |
| ├── Interaction: Transient checkout for open community experiences. |
| └── Data Scope: Adult identity, contact info, Child Identifiable Info (CII), dietary preferences,|
| billing addresses, tokenized transaction identifiers, emergency contacts. |
| |
| [ CLASS C: HARBOUR APPLICANTS & ACTIVE HOUSEHOLD MEMBERS ] |
| ├── Interaction: Authenticated application & Progressive Web App (PWA) portal environment. |
| └── Data Scope: Complete Household Profile, Dual-Parent Relational Identifiers, Spouse Synced |
| Meta, Attendance Logs, Push Notification Tokens, Member Directory Toggles, Media Consents. |
| |
+---------------------------------------------------------------------------------------------------+
3.1 Class A: Public Platform Visitors (Unauthenticated Users)
- Definition: Any individual accessing public marketing pages at
thecoveandkin.clubor associated designated alias domains without logging in or initiating a transaction. - Collected Data Points: Technical IP telemetry, web browser type and version, operating system specifications, network routing data, HTTP request headers, edge Content Delivery Network (CDN) operational performance cookies, and session state identifiers.
- Purpose of Processing: To ensure network stability, enforce Web Application Firewall (WAF) security parameters, prevent Distributed Denial of Service (DDoS) attacks, and optimize digital asset delivery.
- Lawful Basis: Legitimate Interest and Technical Necessity.
3.2 Class B: Guest Event Purchasers (Transient Authenticated Users)
- Definition: Non-member individuals purchasing guest access passes or event tickets for public-facing experiences hosted by The Cove & Kin.
- Collected Data Points: Primary Purchaser First and Last Name, Email Address, Mobile Phone Number, Billing Street Address, City, Postal Code; Attending Child Name(s), Attending Child Date(s) of Birth (DOB); Household Dietary Preferences and Severe Allergy Notifications; Tokenized Transaction Pass/Fail Indicators; IP Address at Checkout; Emergency Contact Representative Name and Phone Number.
- Purpose of Processing: Event ticketing fulfillment, age-tiered price calculation, venue capacity limits, on-site emergency preparation, medical/allergy safety manifests, financial accounting, and fraud prevention.
- Lawful Basis: Performance of Contract, Verifiable Parental Authorization, and Legitimate Interest in Event Safety.
3.3 Class C: Circle Applicants & Active Household Members (Fully Authenticated Users)
- Definition: Individuals who have submitted an alignment inquiry, passed vetting, or maintain an active, paid annual or semi-annual household membership within The Circle environment.
- Collected Data Points:
- Primary & Spouse Accounts: Full Legal Names, Email Credentials, Encrypted Authentication Passwords, Phone Numbers, Residential Billing Addresses, Profile Photographs, 2-line Professional/Personal Bios, Partner Relational Mapping (Husband/Wife/Partner).
- Child Identifiable Information (CII): Up to four (4) named children per household, along with their verified Dates of Birth (DOB).
- Household Operational Meta: Designated Nanny/Caregiver Names, Emergency Contacts, Household Dietary Checkboxes (Vegan, Gluten-Free, Dairy-Free, Nut Allergy, Jain, Other custom notes), Member Directory Visibility Preferences, Member Photo Sharing Permission Toggles.
- Technical & Device Telemetry: Progressive Web Application (PWA) local storage state, Service Worker installation status, Web Push Notification Subscription Endpoints (VAPID key pairs), Gated Media Cloud Check-in Verification Timestamps, Dynamic Event Ticket Pass Hashes, and Entry QR Generation Logs.
- Purpose of Processing: Complete membership administration, bidirectional household data synchronization, dynamic spousal account spawning, access control to gated physical and digital sanctuaries, distribution of transactional push notifications, generation of event manifests, and secure directory publishing.
- Lawful Basis: Explicit Performance of Membership Contract, Explicit Data Principal Consent, and Legal Obligation.
4. PROCESSING OF CHILD DATA & VERIFIABLE PARENTAL CONSENT
4.1 Statutory Protections for Minors
The Cove & Kin recognizes the extreme sensitivity surrounding the collection of Child Identifiable Information (CII). Under Section 9 of the DPDP Act, 2023 (India), a minor is defined as any individual under eighteen (18) years of age. Under global frameworks such as COPPA, additional protections govern minors under thirteen (13) years of age.
4.2 Verifiable Parental Consent Architecture
Children are strictly prohibited from creating independent accounts, purchasing tickets, or submitting alignment applications on The Cove OS. All processing of minor data is strictly contingent upon Verifiable Parental Consent obtained through the following technical mechanisms:
[ ADULT PARENT REGISTRATION / CHECKOUT INTERFACE ]
│
▼
┌─────────────────────────────────────────────────────────┐
│ MANDATORY PARENTAL AUTHORIZATION CHECKBOX │
└─────────────────────────┬───────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────┐
│ FINANCIAL ADULT VERIFICATION GATEWAY (RAZORPAY) │
│ Payment captured via adult credit/debit card, UPI, or │
│ net banking. Confirms lawful adult capacity. │
└─────────────────────────┬───────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────┐
│ SYSTEM METADATA STAMPING & SECURE DB ISOLATION │
│ Child metadata linked strictly to adult Household ID. │
└─────────────────────────────────────────────────────────┘
- Financial Identity Verification: Minor data can only be ingested alongside an adult financial transaction executed via an authorized payment gateway, proving adult legal capacity and financial guardianship.
- Explicit Consent Affirmation: During registration and guest checkout, the adult parent or legal guardian must actively check a mandatory, unselected consent toggle affirming: “I confirm that I am the parent or lawful guardian of the minor child(ren) listed above, and I hereby grant explicit consent for The Cove & Kin to collect and process their name, date of birth, and dietary requirements for event safety and operational purposes.”
- Prohibition of Behavioral Profiling: The Cove & Kin strictly covenants that child data will never be utilized for behavioral tracking, targeted advertising, developmental profiling, or commercial monetization. Child data is stored in restricted database structures and processed exclusively for age verification, safety manifests, and event pricing algorithms.
5. UNIFIED HOUSEHOLD ENGINE & DUAL-PARENT SYNCHRONIZATION
5.1 The Household Relational Architecture
Unlike conventional digital platforms that treat every user account as an isolated island, The Cove OS is engineered around a Unified Household Relational Model. When a Primary Member completes the alignment onboarding and checkout, the system binds accounts at the household level.
[ PRIMARY MEMBER ACCOUNT ]
(Holds Primary Credentials)
│
├───────────► Linked via Shared Household Relational ID
│ & Bidirectional Partner Pointers
▼
[ SPOUSE MEMBER ACCOUNT ]
(Holds Unique Credentials)
│
┌───────────────────────┴───────────────────────┐
│ │
▼ ▼
[ MIRRORED HOUSEHOLD DATA ] [ ISOLATED INDIVIDUAL DATA ]
* Child Names & DOBs • Encrypted Login Credentials
* Dietary & Allergy Directives • Individual Profile Photo & Bio
* Billing Address Data • Specific Event Attendance Logs
* Nanny & Emergency Contacts • Personal Directory Visibility Toggles
* Membership Expiry Status • Personal Notification Endpoints
5.2 Spousal Account Spawning Mechanics
Upon payment capture for a household membership:
- The system programmatically spawns a distinct Spouse Account utilizing the partner email provided by the Primary applicant.
- A unique, alphanumeric Household Relational Identifier is stamped to both the Primary and Spouse account metadata profiles.
- A direct, bidirectional pointer links the account identifiers of both partners.
- The system dispatches temporary login credentials directly to the Spouse’s email address.
- First-Login Consent Gate: Upon the Spouse’s initial authentication into The Circle Portal, an unskippable modal overlay presents this Privacy Charter and the Club Charter. The Spouse must explicitly accept these terms before gaining access to portal functionality.
5.3 Real-Time Bidirectional Mirroring and Conflict Resolution
To maintain data integrity across co-parenting structures, changes made to shared household parameters by either parent are processed through a real-time mirroring hook:
- Shared Household Fields: Child Names, Child Dates of Birth, Household Dietary Restrictions, Nanny/Caregiver Name, Emergency Contacts, Parental Photo Consent Preferences, and Household Billing Addresses are mirrored across both account records.
- Recursion & Collision Prevention: The synchronization engine utilizes internal memory blocks to prevent infinite mirroring loop crashes between coupled accounts.
- Dynamic Timestamp Healing: If partners update household data asynchronously, the system compares microsecond execution timestamps. The database record bearing the newer timestamp dynamically overwrites older records across both profiles.
6. PROGRESSIVE WEB APPLICATION (PWA), PUSH NOTIFICATIONS & STORAGE
6.1 Progressive Web Application Architecture
The Member Circle environment operates as a cross-platform Progressive Web Application (PWA) accessible via mobile and desktop browsers. The PWA architecture utilizes client-side caching and hardware access APIs to deliver a seamless native-like user experience.
6.2 Service Workers, IndexedDB, and Local Storage
- Service Workers: The PWA installs background Service Workers on the user’s local device to cache static user interface assets (CSS, JavaScript, SVG graphics) and manage background data synchronization.
- Local Storage & IndexedDB: Non-sensitive operational application states, offline session tokens, and cached interface structures are stored locally within the user’s device browser cache. No raw payment credentials or unencrypted personal child data are ever written to browser local storage.
6.3 Proprietary Web Push Notification Subsystem
The Cove OS incorporates a self-coded, proprietary Web Push Notification Subsystem designed to deliver instant transactional alerts, booking confirmations, and sanctuary updates directly to member devices.
- VAPID Encryption Standard: The push notification engine utilizes Voluntary Application Server Identification (VAPID) key pairs under RFC 8292. The application server signs notification payloads using an asymmetric elliptic-curve key-pair.
- Subscription Endpoints: When a member grants notification permissions, the client browser generates a unique subscription endpoint URL and cryptographic authentication secret managed by the native push service (such as Apple Push Notification service – APNs, or Firebase Cloud Messaging – FCM).
- Token Retention: Subscription endpoints are encrypted and stored in our database linked to the specific User Account. Members can revoke push notification permissions at any time via native browser site settings or within their Circle Account profile controls.
7. COOKIES, CDN, FIREWALLS & STATUTORY LOGGING
7.1 Cookie Taxonomy
The Cove & Kin utilizes cookies and similar tracking technologies to ensure platform functionality, enhance security, and manage user authentication sessions.
| Cookie Category | Technical Duration | Operational Purpose | Mandatory vs Optional |
|---|---|---|---|
| Strictly Necessary / Authentication | Session to 14 Days | Maintains authenticated login states across pages and validates user role privileges within The Circle Portal. | Mandatory (Core Functionality) |
| Security & Anti-Forgery | Session | Stores cross-site request forgery (CSRF) tokens and validates form submissions to prevent unauthorized data injection. | Mandatory (Security Shield) |
| PWA & Performance Caching | Persistent (Up to 1 Year) | Remembers user interface preferences, service worker registration states, and cached asset versions. | Optional (Configurable) |
| Edge CDN Analytics | 30 Days | Collects aggregated, non-identifying technical routing performance and latency telemetry. | Optional (Performance) |
7.2 Edge CDN and Web Application Firewall (WAF)
To protect our high-net-worth member community against unauthorized intrusion, cyber attacks, and data exposure, all incoming platform traffic routes through an integrated Edge Content Delivery Network (CDN) and Enterprise Web Application Firewall (WAF):
- Edge Inspection: Incoming HTTP/HTTPS requests are analyzed at edge servers located around the world before reaching our core server infrastructure.
- Real-Time Threat Mitigation: The WAF automatically evaluates incoming traffic against real-time threat intelligence rules, blocking SQL injections (SQLi), Cross-Site Scripting (XSS), automated brute-force credential stuffing, and malicious bot scraping.
- IP Filtering & Rate-Limiting: Strict rate-limiting protocols automatically ban IP addresses demonstrating suspicious behavior or making unauthorized requests to administrative endpoints.
7.3 Statutory 180-Day Audit Logging (CERT-In Compliance)
In strict accordance with the Cyber Security Directions issued by the Indian Computer Emergency Response Team (CERT-In), The Cove & Kin maintains an automated, immutable audit logging subsystem within our localized database infrastructure:
- Logged Parameters: System administrative actions, user authentication attempts (successful and failed), password resets, privilege changes, profile updates, ticket generation, QR code entry scanning events, and source IP addresses with corresponding HTTP access timestamps.
- Time Synchronization: All logs are strictly synchronized using Network Time Protocol (NTP) servers mapped to Indian Standard Time (IST).
- Mandatory Retention Period: All audit and operational logs are securely retained within an isolated database table for a minimum of one hundred and eighty (180) days before being subjected to automated cryptographic purge protocols.
8. PAYMENT PROCESSING & PCI-DSS SAQ-A COMPLIANCE
8.1 Total Payment Outsourcing
All financial transactions executed through Website – including annual membership dues, semi-annual membership dues, event ticket purchases, and cancellation adjustments – are processed through our authorized payment gateway sub-processor, Razorpay Software Private Limited (“Razorpay”) being our primary processor in addition to other processors applicable as per technical feasibility.
8.2 PCI-DSS Level 1 Security Guarantee
The Cove & Kin operates under the PCI-DSS SAQ-A (Self-Assessment Questionnaire A) compliance framework:
- Zero Local Card Storage: At no point during the checkout process do raw Credit/Debit Card Numbers (PAN), Card Verification Values (CVV), Expiry Dates, or Banking Passwords enter or touch The Cove & Kin’s server infrastructure or database systems.
- Tokenization Mechanics: Financial instruments are tokenized entirely within Razorpay’s PCI-DSS Level 1 compliant secure vault. Razorpay returns an encrypted transaction token and payment ID string back to our application server via SSL/TLS 1.3 encrypted webhooks to update order statuses.
- Payment Data Localization: All transaction metadata processed by Razorpay complies strictly with the Reserve Bank of India (RBI) directives on Payment System Data Localization, ensuring financial data resides exclusively within Indian data centers.
9. THIRD-PARTY SUB-PROCESSORS & DATA LOCALIZATION
9.1 Authorized Sub-Processor Taxonomy
To deliver our digital ecosystem, The Cove & Kin engages a select number of enterprise third-party vendors (“Sub-processors”). Each sub-processor is thoroughly vetted and legally bound to process data strictly under our instructions and in alignment with global privacy regulations.
| Sub-Processor Entity | Data Handled / Processing Function | Physical Server Location | Compliance Certifications |
|---|---|---|---|
| Enterprise Cloud Infrastructure Provider | Application hosting, relational database storage, local activity logs, user profile meta. | Mumbai, Maharashtra, India | ISO 27001, SOC 2 Type II, DPDP Aligned. |
| Razorpay Software Pvt. Ltd. | Billing details, tokenized payment IDs, transaction amounts, UPI/Banking tokens. | Bengaluru / Mumbai, India | PCI-DSS Level 1, RBI Compliant. |
| Google Cloud Platform | Professional event photographs, emails, gated folder structures, stream delivery tokens. | Global / India Edge Nodes | ISO 27017, ISO 27018, SOC 2 Type II. |
| Global Edge CDN & Network Security Subsystem | Incoming IP routing telemetry, WAF security filters, SSL/TLS termination, edge caching. | Global Distributed Network | SOC 2 Type II, ISO 27001. |
9.2 Cross-Border Transfer Restrictions
In compliance with Section 11 of the DPDP Act, 2023, The Cove & Kin maintains personal data strictly within approved geographic jurisdictions. Personal data collected from Indian data principals is hosted locally within Indian data centers. Transfers of data to external cloud APIs (such as streaming event imagery via Google Cloud infrastructure) are executed over encrypted TLS 1.3 pipelines subject to enterprise data protection agreements.
10. DATA PRINCIPAL RIGHTS & SELF-SERVICE CONTROLS
The Cove & Kin provides members and guest users with comprehensive, transparent controls over their personal data in accordance with the DPDP Act 2023, GDPR, and global privacy standards.
10.1 Summary of Rights
- Right to Access & Information (Section 11, DPDP Act): The right to obtain a summary of personal data being processed, the identities of sub-processors processing such data, and the processing purposes.
- Right to Correction & Completion (Section 12, DPDP Act): The right to request the correction, updating, or completion of inaccurate or misleading personal data across household profiles.
- Right to Erasure / “Right to be Forgotten” (Section 12, DPDP Act): The right to request the complete, permanent purge of personal profile data, subject to statutory retention obligations (e.g., accounting or CERT-In logs).
- Right to Withdraw Consent: The right to revoke previously granted processing consent at any time without impacting the lawfulness of processing undertaken prior to withdrawal.
- Right of Grievance Redressal (Section 13, DPDP Act): The right to have data privacy complaints resolved efficiently by an designated internal Grievance Officer.
10.2 Self-Service Data Portability Engine
Members can independently exercise their right to data portability directly inside The Circle Portal:
- Data Export Mechanism: Navigating to the
/circle-accountmanagement portal provides a dedicated “Download My Personal Data” control. - Export File Structure: Clicking this trigger executes an automated script that packages the user’s complete profile, household relational metadata, linked child profiles, emergency contacts, dietary preferences, and event attendance logs into a structured, machine-readable export file delivered directly to the user’s browser.
10.3 Automated Recursive Erasure Protocol
When a user submits a formal account deletion request through the portal or via email to the Grievance Officer, the system initiates a Recursive Purge Cascade:
[ ACCOUNT ERASURE TRIGGER SUBMITTED ]
│
▼
┌──────────────────────────────────────────────────────────┐
│ LOCATE UNIQUE HOUSEHOLD RELATIONAL ID │
└─────────────────┬────────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ EXECUTE RECURSIVE DATABASE CASCADE │
│ • Purge User Account & Metadata Records │
│ • Purge Linked Spouse Metadata Pointer │
│ • Purge Child Profiles & Dietary Restrictions │
│ • Purge Service Worker Caching & Push Tokens │
│ • Purge Event Order Custom Identifiers │
└─────────────────┬────────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ STATUTORY RETENTION EXCEPTION ANONYMIZATION │
│ Anonymize transaction logs for financial audits. │
│ Retain raw security audit logs for CERT-In 180-day gate. │
└──────────────────────────────────────────────────────────┘
10.4 Member Photo Sharing Toggle & “No Law Override” Clause
Inside the Member Circle Profile settings, active members are provided with a granular privacy toggle:
- Toggle Definition: “Do you consent to other members non-commercially sharing photos containing your child’s face?“
- THE NO LAW OVERRIDE STATEMENT: This member media toggle operates strictly as a voluntary, intra-community courtesy preference governing private member communications. Selecting “Yes” or “No” on this preference toggle shall not override, supersede, or alter any applicable statutory laws or regulations, including the Protection of Children from Sexual Offences (POCSO) Act, 2012, the Digital Personal Data Protection Act, 2023, or Indian criminal jurisprudence. The Cove & Kin strictly prohibits the commercial exploitation, public redistribution, or social media publishing of any minor child’s image.
11. DATA RETENTION SCHEDULES & PURGE PROTOCOLS
The Cove & Kin enforces strict retention limits to ensure personal data is destroyed when it is no longer required for operational, legal, or statutory purposes.
+---------------------------------------------------------------------------------------------------+
| DATA LIFECYCLE & RETENTION MATRIX |
+---------------------------------------------------------------------------------------------------+
| DATA CATEGORY RETENTION DURATION PURGE ACTION |
+---------------------------------------------------------------------------------------------------+
| Public Web Analytics 30 Days Automated Edge Cache Flushing |
| Transient Guest Ticket Logs 1 Year Post-Event Anonymization of Child & Health Data |
| Active Member Household Data Duration of Membership Live Database Storage |
| Terminated Member Profiles 90 Days Post-Expiry Recursive Deletion Cascade Executed |
| Financial & Invoice Records 7 Years (Tax Statutory) Secure Financial Archive Storage |
| CERT-In Security System Logs 180 Days (Cyber Mandate) Cryptographic Log Destruction |
+---------------------------------------------------------------------------------------------------+
SECTION 12: STATUTORY GRIEVANCE REDRESSAL & REGULATORY ESCALATION
12.1 Designated Grievance Officer
In accordance with Section 13 of the DPDP Act, 2023 and the Rules framed thereunder, The Cove & Kin LLP has designated an internal Officer responsible for overseeing data protection compliance and addressing data principal grievances.
If you have questions, concerns, requests to exercise your statutory rights, or complaints regarding the processing of your personal data or your child’s data, please contact our Grievance Officer:
- Designated Grievance Officer: Aakruti Khanna
- Corporate Entity: The Cove & Kin LLP
- Official Privacy & Grievance Email:
support@thecoveandkin.club - General Operations Email:
info@thecoveandkin.club - Primary Web Portal:
https://thecoveandkin.club/circle/
12.2 Grievance Resolution Timeline
- Acknowledgement: The Grievance Officer will acknowledge receipt of any data protection complaint within seventy-two (72) working hours.
- Investigation & Response: The organization will investigate and issue a formal resolution or status report within fifteen (15) business days of receipt.
12.3 Escalation to Regulatory Authorities
If a Data Principal is dissatisfied with the resolution provided by our Grievance Officer, or believes that their personal data has been processed in violation of applicable laws, they retain the statutory right to escalate the matter to the appropriate supervisory authority:
- Data Protection Board of India (DPB): Complaints under the DPDP Act, 2023 may be submitted directly to the Data Protection Board of India via its designated online dispute portal.
- CERT-In Cyber Incident Reporting: Cybersecurity breaches or unauthorized data access incidents may be reported to the Indian Computer Emergency Response Team at
incident@cert-in.org.in.
13. CHARTER REVISIONS & NOTIFICATION MECHANISMS
The Cove & Kin reserves the right to update, amend, or modify this Privacy Charter at any time to reflect technical upgrades, statutory amendments, or evolving legal precedents.
When material changes are made to this Privacy Charter:
- The “Last Updated & Effective Date” at the top of this page will be updated.
- An active notification will be dispatched to all members via our proprietary Web Push Notification Subsystem and email communication channels.