Privacy Policy
This policy explains what NewsDunia collects when you read, subscribe, comment or write to us, why we collect it, how long we keep it and what you can ask us to do about it. It also sets out the heightened protection we give to anything capable of identifying a journalistic source.
The policy
NewsDunia is published by Catalyst Web Trendz Pvt. Ltd., D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for personal data processed through this website, our newsletters, our e-paper and our subscription systems. You are the Data Principal.
1. Scope of this policy
This policy applies to www.newsduniaa.com, the NewsDunia e-paper, our email newsletters, our reader comment and letters systems, our subscription and payment flows, and any survey or event registration we run under the NewsDunia name. It does not apply to third-party websites you reach from our links, to social media platforms where our stories are shared, or to services operated by other companies under their own terms — each of those has its own policy which you should read.
It applies alongside our Terms of Use and Disclaimer. Where a specific product notice (for example, a competition entry form) says something more specific about a particular set of data, that notice governs for that data only.
2. The personal data we collect
We collect four broad categories of data, and we try to collect as little of each as the purpose allows.
Data you give us. Your name and email address when you create an account or subscribe to a newsletter; billing name, address, GSTIN where you supply one, and the last four digits and card network of a payment instrument when you take a paid subscription; the content of letters, tips, comments and contact-form messages; and any postal address you give us for e-paper or print delivery.
Data generated by your use of the site. Pages and articles requested, referring page, approximate location derived from IP address at city level, device type, browser and operating system version, session duration and scroll depth, newsletter opens and link clicks where your email client reports them, and the article count used for metering.
Data from our partners. Payment confirmation and settlement status from our payment gateway; delivery, bounce and complaint signals from our email service provider; and aggregated, non-identifying campaign reports from advertising partners.
Technical data we cannot avoid. IP address and request headers reach our servers as a necessary part of the internet working. We use them for security, abuse prevention and error diagnosis, and we truncate or discard them on the schedule in section 11.
We do not knowingly collect data revealing your religion, caste, political affiliation, health status or sexual orientation, and we ask you not to send such information to us unless it is genuinely necessary for a story you are contacting us about.
3. Reader analytics and how we measure an audience
Journalism that nobody reads does not survive, so we measure readership. Our analytics answer editorial questions: which stories were read to the end, which explainer worked, which live blog held attention, whether a headline change helped. We run analytics on a first-party basis, we store identifiers in a pseudonymised form, and we do not attempt to build a profile of your interests for onward sale.
We do not sell personal data, and we do not disclose personal data to any party for consideration, as those terms are used in Indian consumer and data protection law. We publish aggregate audience figures — the kind you see on our impact page — and those figures are never traceable back to an individual reader.
If you choose “Essential only” in our cookie banner, analytics that are not strictly necessary to deliver the page are not loaded at all, and the site works exactly as it does otherwise, minus our ability to count you.
4. Paywall, metering and subscription data
Some NewsDunia articles are metered: you may read a set number of pieces in a rolling period before we ask you to subscribe. To operate the meter we store a counter and a rolling timestamp in your browser, and, if you are signed in, against your account. The counter records how many metered articles you have opened, not which ones, unless you are signed in and have not opted out of reading history.
For paid subscriptions we process the data needed to take money and give you access: your name, email address, billing address, GST details where applicable, plan and renewal date, invoice history, and the tokenised reference our payment gateway returns. We never see or store your full card number, CVV or UPI PIN. Those go directly to the payment gateway, which is certified for that purpose and which processes them under its own policy.
Invoices and GST records are retained for the period required by tax law, which is currently longer than our ordinary retention schedule; see section 11.
5. Cookies, advertising and our ad-tech partners
We use cookies and equivalent browser storage in four categories.
- Strictly necessary — session, sign-in, security, and the record of your cookie choice itself. These cannot be switched off without breaking the site.
- Preference — your language selection, your text-size setting and your dismissal of notices. These are stored locally in your browser and never sent to an advertising partner.
- Measurement — the pseudonymised analytics described in section 3.
- Advertising — set only where you have accepted them. Advertising on NewsDunia is sold both directly and programmatically. Programmatic partners may set cookies or read identifiers to cap how often you see a creative, to measure whether an advertisement was viewable, and to avoid showing you an advertisement for something you have already bought.
Where advertising is served programmatically, the partner determines part of the processing itself and acts as an independent Data Fiduciary for that part. We require every partner under contract to honour the consent signal we pass, to refrain from combining NewsDunia data with data from other sources for profiling, and to keep no identifier longer than thirteen months. We publish the current partner list on request to the Grievance Officer, and we will name the partners on any specific page you ask about.
We do not permit advertising cookies on pages carrying investigations where we have flagged an elevated source-protection risk, on our tip-off and contact pages, or in the newsletter templates used for source correspondence.
You can change your cookie choice at any time by clearing site data for www.newsduniaa.com, which will cause the banner to appear again. Your browser also offers its own controls, including “Do Not Track” and Global Privacy Control signals; we treat a GPC signal as a withdrawal of consent for advertising and measurement cookies.
6. Newsletters and the e-paper
Newsletters are sent only to addresses that have asked for them. We record the date, time and source of your subscription so that we can show, if challenged, that you asked. Every edition carries a one-click unsubscribe link that works without signing in and takes effect on the next send cycle, normally within a few hours and always within seventy-two hours.
Our email service provider reports opens and link clicks. Open tracking depends on your email client loading a small transparent image; if you block remote images, we simply do not know. We use these signals in aggregate to decide send times and to retire newsletters nobody opens, and at an individual level only to stop sending to addresses that have been inactive for a long period.
The e-paper is delivered either in-app or as a download link tied to your account. We record which editions were downloaded so that we can restore your library if you change device, and for no other purpose. Print delivery, where offered, requires your postal address, which is shared with the delivery agent for that route and for the duration of the subscription only.
7. Comments, letters and reader contributions
To post a comment or send a letter for publication you must be signed in. We store the text, the timestamp, the account it came from and the moderation decision. If we publish your letter we publish the name on your account and, where you have given it and it is relevant, your city — nothing else. We never publish your email address.
Comments are moderated against the code of conduct in our Terms of Use. Moderation records, including comments we declined to publish, are kept for twelve months so that we can review a decision if you challenge it, and are then deleted.
If you send us a tip, a document or a correction, that correspondence is treated under section 8, not this section, whether or not you asked for it to be.
8. Source confidentiality — heightened protection
Data capable of identifying a journalistic source receives the highest level of protection we are able to give it, and it is handled differently from every other category described in this policy. This is not a courtesy. Confidential sourcing is a precondition of the reporting on which the public interest depends, and we treat a breach of it as the most serious failure this organisation can commit.
In practice this means the following. Source correspondence is stored separately from our ordinary systems, on infrastructure with a restricted access list held by the editor and the standards editor. Access is logged. Analytics, advertising and measurement scripts are excluded from our tip-off pages, and those pages are served without third-party requests of any kind. Where a source asks to be anonymous, identifying details are stripped at intake and the mapping is held offline. We do not retain server logs for tip-off submissions beyond the minimum period needed to keep the endpoint secure, and we delete drafts, notes and metadata associated with a source once a story is closed unless the source asks us to keep them.
We will not disclose source-identifying data to a commercial partner, an advertiser or an affiliate in any circumstances. Where disclosure is demanded under legal process we will, so far as the law allows, notify the source, seek to narrow or resist the demand, and publish an account of the demand and its outcome. We publish an annual transparency note recording the number of such demands received and how each was handled.
If you intend to send us sensitive material, please read the guidance on our contact page before you do. The safest first contact is the one that reveals least.
9. Lawful basis for processing
Under the DPDP Act we process personal data either on your consent or for a legitimate use permitted by the Act. Specifically:
- Consent — newsletters, advertising and measurement cookies, optional reading history, surveys and competitions. Consent is requested in clear language, is as easy to withdraw as it was to give, and withdrawal is effective going forward.
- Performance of a service you have asked for — delivering a subscription you have paid for, restoring your e-paper library, answering a message you sent us.
- Compliance with law — retaining invoices and GST records, responding to a lawful order, and the record-keeping required of a publisher of news and current affairs content under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Journalistic purpose — researching, verifying and publishing news. Where the DPDP Act or its rules provide a journalistic exemption, we rely on it only to the extent necessary for publication and never as a general excuse to hold data we do not need.
Our processing also proceeds within the framework of the Information Technology Act, 2000 and the rules made under it, and, where you buy a subscription, the Consumer Protection Act, 2019 and the E-Commerce Rules made under it.
10. Sharing and transfers
We share personal data only with processors who need it to deliver something you have asked for, and only under a written contract that restricts them to our instructions. The categories are: payment gateway and banking partners; email delivery provider; cloud hosting and content delivery; customer support tooling; delivery agents for physical editions; auditors and legal advisers; and, where you have consented, advertising partners.
Some of these providers operate infrastructure outside India. Where personal data is transferred abroad, it goes only to jurisdictions not restricted for such transfers under the DPDP Act, and under contractual terms requiring protection equivalent to this policy. We do not transfer source-identifying data outside our own controlled infrastructure at all.
We may disclose data where we are required to by law, by a court of competent jurisdiction, or by an authority acting within its powers — subject always to section 8 where sources are involved. If NewsDunia or its publishing business is transferred to another entity, personal data may transfer with it; you would be told before that happened and given the opportunity to delete your account first.
11. Retention
We keep personal data only for as long as it serves the purpose it was collected for, and then we erase it. Our current schedule is:
- Account data — for the life of the account, then 90 days after a deletion request, to allow reversal of a mistaken deletion.
- Subscription, invoice and GST records — eight financial years, as required by tax law, in a restricted finance system.
- Analytics events — 14 months in identifiable form; aggregate counts indefinitely.
- Newsletter engagement — 24 months, or until you unsubscribe, whichever is sooner.
- Comments and moderation records — published comments remain with the article; declined comments and moderation notes, 12 months.
- Contact and support correspondence — 24 months.
- Server and security logs — 90 days, IP addresses truncated after 30.
- Source correspondence — as long as the source wishes, and no longer; deleted on request without a waiting period.
12. Your rights, and how to delete your account
As a Data Principal you may ask us for a summary of the personal data we hold about you and the processing we carry out; ask us to correct data that is inaccurate, or complete data that is incomplete; ask us to erase data we no longer have a lawful basis to keep; withdraw a consent you previously gave; nominate another person to exercise these rights if you die or become incapacitated; and complain to us and, if unsatisfied, to the Data Protection Board of India.
You can delete your account yourself from Account → Settings → Delete account, or by writing to the Grievance Officer. Deletion removes your profile, reading history, newsletter subscriptions and comment authorship attribution. It does not remove invoices we are legally required to keep, published letters where removal would misrepresent a public exchange, or the text of comments other readers have replied to — in that last case we anonymise rather than delete, and we tell you so.
We respond to rights requests within thirty days. We may ask you to verify your identity first, and we will not use that verification data for anything else.
13. Children’s data
NewsDunia is a general news publication intended for a general adult audience. We do not knowingly create accounts for, or direct advertising at, anyone under eighteen. Where we know or reasonably believe a user is a child, we process their data only with verifiable consent from a parent or lawful guardian as required by the DPDP Act, we do not carry out tracking or behavioural advertising directed at them, and we do not use their data for profiling.
If you believe a child has given us personal data without that consent, write to the Grievance Officer and we will delete it. Schools and educational institutions using our classroom access should note that we ask them, not their pupils, to hold the account.
14. Security, breaches and changes to this policy
We protect personal data with access controls tied to job role, encryption of data in transit and at rest, separated environments for editorial and commercial systems, logged administrative access, and an annual review of who can reach what. No system is perfect, and we do not claim otherwise. If a personal data breach occurs we will notify the Data Protection Board of India and every affected Data Principal in the manner and within the timelines the DPDP Act requires, and we will say plainly what happened.
We update this policy when our practices change or the law does. The date at the top of this page is the date of the current version. Material changes are announced on the site and, for account holders, by email at least fourteen days before they take effect. We keep previous versions and will send you one on request.