This Data Retention Policy outlines how TTL Media Private Limited ("Oye Creators," "we," "us," or "our") collects, retains, archives, and deletes data through our online marketplace platform. We ensure compliance with Indian laws (Information Technology Act 2000, DPDP Act 2023) and international regulations (GDPR) and protect Oye Creators and its employees from legal liabilities.
1. Purpose and Scope
1.1 Purpose: Provide transparency about data lifecycle management, comply with legal obligations, and mitigate risks of unauthorized retention or deletion.
1.2 Scope: Applies to all data related to:
Users: Enterprise Clients (Brands/Businesses), Creators, and Platform Managers
Data Types: Personal Data, Non-Personal Data, User-Generated Content, Social Media Data, Transaction Records, Logs, Backups, Communications, Analytics, Cookies
Social Media Data: Information fetched from or about users on third-party social networks (e.g., profile insights, engagement metrics, follower demographics, public posts) via API integrations or manual reports.
Systems: Web and mobile applications, internal databases, third-party services, backups
2. Data Categories & Retention Periods
| Category | Examples | Retention | Legal Basis / Notes |
|---|---|---|---|
| Registration & Profile Data | Name, contact, identity proofs, KYC | Active + 3 years after account closure | Contractual necessity; Audit under IT SPDI Rule 3, DPDP transitional provisions |
| User-Generated Content (UGC) | Campaign posts, images, videos, scripts | Until campaign end + 2 years archive; deletable on request* | License lifecycle; dispute resolution; archived encrypted |
| Social Media Data | API-derived metrics (followers, reach, impressions), public posts | 1 year from collection or campaign end + 1 year archive | Platform insights; GDPR Art.5(1)(e) "storage limitation"; user consent where required |
| Transactions & Payments | Invoices, receipts, payout logs | 7 years | Income-tax Act requirements; RBI guidelines |
| Usage & Access Logs | Login/logout, API calls | 180 days (active); 1 year (archived) | Security monitoring; forensics; GDPR Art.5(1)(e) storage limitation |
| System Backups | Full & incremental backups | 30 days rolling | Disaster recovery; overwritten older backups |
| Cookies & Tracking Data | Session, preference, analytics cookies | As per Cookie Policy (session to 24 months) | User consent under GDPR Art.6(1)(a); cleared on opt-out |
| Support & Communications | Emails, chat transcripts, tickets | Resolution + 5 years | Customer dispute management |
| Marketing Consents & Preferences | Opt-in records, unsubscribes | Opt-out + 3 years | Consent record under GDPR Arts.7(1); DPDP consent framework |
| Legal & Compliance Records | Audit trails, compliance certificates | 10 years | Statutory requirements; legal defense |
*Creators may request earlier deletion of their UGC; if a client campaign is active, removal may be subject to contract terms.
3. Data Storage & Security Measures
Encryption:
- Data at rest: AES-256 on all databases and archives.
- Data in transit: TLS 1.2+ for all network communication.
Access Controls:
- Role-based access (RBAC) with least-privilege.
- Multi-factor authentication (MFA) for admins.
Network Security:
- Firewalls and intrusion detection.
- Regular vulnerability assessments and penetration tests.
Anonymization & Pseudonymization:
- Backup anonymization for analytics archives.
- Pseudonymization of user identifiers in research datasets.
4. Deletion & Archival Procedures
Automated Jobs:
- Daily: purge logs >180 days.
- Monthly: archive UGC and social media data >2 years to cold storage.
Manual Requests:
- DSARs handled within 30 days.
- Erasure requests completed within 60 days, subject to legal holds.
Exception Holds:
- Ongoing litigation, investigations, or audits—retention extended until resolution.
5. International Transfers
Primary processing and storage in India. Cross-border transfers to processors (e.g., AWS Singapore) follow:
- Standard Contractual Clauses (SCCs) under GDPR.
- Adequacy mechanisms per DPDP guidelines.
6. Data Subject Rights & Contact
Under GDPR and DPDP Act, individuals may:
Access, Rectify, Erase, Restrict, Object, Port their personal data.
Submit requests to:
Data Protection Officer
Email: dpo@oyecreators.in
Address: Quantum Works, CTS No. 177 p, metro station, S. No. 43/2, near Nal stop, Pandurang Colony, Erandwane, Pune, Maharashtra 411004
7. Compliance & Audits
- Annual external audits by certified firms.
- Quarterly internal compliance reviews.
- Policy versions logged; major updates trigger user notification and re-consent if required.
8. Liability & Indemnification
Limitation of Liability: Oye Creators not liable for data loss post-retention.
Indemnification: Users indemnify Oye Creators/employees for claims from data misuse or unlawful requests.
9. Policy Updates
We may revise this policy for new laws or practices. Updated versions will be published with a new "Last updated" date; major changes require user re-consent where mandated.