VERALIS Evidence PressVERALIS

Internal governance document — Compliance Manual

DPDP Act 2023 — Implementation & Compliance Manual

VERALIS EVIDENCE PRESS PRIVATE LIMITED — Digital Personal Data Protection Act, 2023

Internal — ConfidentialVersion 1.0Effective 25 July 2026

1. Purpose and Scope

This manual sets out how VERALIS EVIDENCE PRESS PRIVATE LIMITED (“VERALIS”, “we”) meets its obligations under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) as a Data Fiduciary. It is the operational counterpart to the public-facing Privacy Policy and DPDP Act Compliance page and is intended for staff, contractors, and our technology developer.

In scope

All digital personal data of Data Principals in India processed through the VERALIS publishing platform — authors, reviewers, editors, institutional users, and website visitors — across account management, manuscript submission and peer review, APC payment, communications, and analytics.

Out of scope

Purely non-personal or fully anonymised data, and personal data governed exclusively by another jurisdiction where the DPDP Act does not apply (GDPR handling is addressed in the Privacy Policy).

2. Key Definitions

TermMeaning under the DPDP Act (as applied at VERALIS)
Data PrincipalThe individual to whom the personal data relates (author, reviewer, editor, institutional contact, site visitor).
Data FiduciaryVERALIS — the entity that determines the purpose and means of processing.
Data ProcessorA third party that processes personal data on VERALIS’s behalf under contract (e.g., cloud host, payment gateway).
Personal dataAny data about an individual who is identifiable by or in relation to such data.
ProcessingAny operation on personal data — collection, storage, use, sharing, erasure, etc.
ConsentFree, specific, informed, unconditional, unambiguous agreement, given by a clear affirmative action, for a specified purpose.
Grievance OfficerThe person designated to receive and resolve Data Principal grievances.
Data Protection BoardThe Data Protection Board of India, the statutory adjudicatory body.

3. Roles and Responsibilities

  • Data Fiduciary accountability: VERALIS is accountable for compliance regardless of any processing carried out by a Data Processor on its behalf.
  • Grievance Officer: VERALIS designates a Grievance Officer, contactable at admin@veralispress.com, responsible for receiving Data Principal requests and grievances, coordinating responses within statutory timelines, and maintaining the registers in this manual.
  • Developer / platform team: responsible for implementing consent capture, rights-fulfilment tooling, security controls, logging, and erasure workflows described here.
  • Significant Data Fiduciary CONFIRM: if VERALIS is later notified as a Significant Data Fiduciary, additional duties apply — appointing a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments. Status to be reviewed annually.

4. Lawful Basis for Processing

VERALIS processes personal data only on a lawful basis under the DPDP Act — either the Data Principal’s consent or a recognised “legitimate use.” The basis for each activity is recorded in the Record of Processing Activities (Section 5).

  • Consent — obtained for marketing communications, non-essential cookies/analytics, and any processing not covered by a legitimate use.
  • Legitimate use — voluntary provision of data by the Data Principal for a specified purpose, compliance with legal obligations, and security/fraud prevention, as permitted by the Act.
  • Contractual necessity — core publishing services (account, submission, peer review, APC) provided to fulfil the service the Data Principal has requested.

5. Record of Processing Activities (RoPA)

Maintained and reviewed at each review cycle. Columns: purpose, data categories, Data Principals, lawful basis, processors, and retention (detailed in Section 11).

PurposeData categoriesLawful basisKey processors
Account & identityName, email, password hash, ORCID, affiliationContract / legitimate useCloud host, identity (ORCID)
Submission & peer reviewManuscript content, correspondence, reviewer identityContractCloud host, plagiarism screening
APC paymentBilling name, email, transaction refs (card data held by gateway)Contract / legal obligationPayment gateway
Scholarly metadataAuthor/contributor metadata, ORCID, DOILegitimate useCrossref, ORCID, indexers
CommunicationsEmail, message content, preferencesContract / consent (marketing)Email service provider
Analytics & cookiesUsage data, device/IP, cookie IDsConsent (non-essential)Analytics provider
Security & fraudLogs, IP, access recordsLegitimate useCloud host, monitoring

6. Notice to Data Principals

Before or at the point of collection, VERALIS provides a notice, in clear and plain language, stating the personal data to be collected, the purpose, how the Data Principal may exercise their rights, and how to complain to the Data Protection Board. Where consent was obtained before commencement of the Act for existing users, an updated notice is provided as soon as reasonably practicable.

Implementation: the notice is surfaced at sign-up, at manuscript submission, at payment, and via a persistent link to the Privacy Policy and DPDP Compliance page. A record of the notice version shown is stored against the account.

8. Data Principal Rights — Fulfilment Procedure

Requests are received at admin@veralispress.com, identity-verified against the account, logged in the Data Subject Request (DSR) register, and actioned within the target timelines below. Final statutory timelines follow the notified DPDP Rules; VERALIS adopts the targets below as internal SLAs.

RightWhat VERALIS doesTarget SLA
AccessProvide a summary of personal data processed and processing activities7 working days
Correction / completion / updateAmend inaccurate or incomplete data; notify processors7 working days
ErasureDelete data no longer needed and not subject to legal retention; instruct processors30 days
Grievance redressalAcknowledge, investigate, and respond via Grievance OfficerAcknowledge 48 hrs; resolve ≤ 30 days
NominationRecord a nominee to exercise rights on death/incapacityOn request
Withdraw consentStop consented processing; confirm to Data Principal≤ 72 hrs

Erasure and the scholarly record: erasure requests are honoured except where data forms part of the permanent version of record (published articles, author/contributor metadata, corrections and retractions) or where law requires retention (e.g., financial records). This limitation is disclosed to the Data Principal in the response.

Duties of Data Principals: we remind requesters that the Act requires them to provide authentic information and not to file false or frivolous grievances.

9. Children’s and Guardianship Data

  • The service is directed at researchers and professional users; we do not knowingly process personal data of children (under 18) without verifiable parental/guardian consent.
  • We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
  • Where a Data Principal has a lawful guardian, verifiable guardian consent is obtained in the manner the Act prescribes.
  • If we become aware that a child’s data was collected without valid consent, we erase it promptly.

10. Sub-Processor / Data Processor Register

VERALIS engages Data Processors only under a valid contract requiring DPDP-consistent safeguards, purpose limitation, and deletion on termination. The register below is maintained and reviewed each cycle. CONFIRM vendor names and locations

CategoryProviderPurposeLocation
Cloud hostingCONFIRMPlatform & data storageCONFIRM
Payment gatewayCONFIRMAPC processingCONFIRM
Email deliveryCONFIRMTransactional & notice emailCONFIRM
Plagiarism screeningCONFIRMIntegrity checksCONFIRM
Identity / metadataORCID, CrossrefScholarly identifiers & metadataGlobal
AnalyticsCONFIRMUsage analytics (consented)CONFIRM

11. Data Retention and Erasure Schedule

Personal data is retained only as long as necessary for the purpose or as required by law, then erased or anonymised. Automated retention rules are configured in the platform. CONFIRM periods with counsel/finance

Data setRetentionTrigger for erasure
Active account dataLife of accountAccount closure + grace period
Closed account data12 months after closure CONFIRMEnd of grace period
Submission / review records (unpublished)2 years after decision CONFIRMElapse of period
Published version of recordPermanentNot erased (scholarly record)
Financial / APC recordsAs required by tax law (e.g., 8 years) CONFIRMStatutory period elapses
Marketing consent dataUntil withdrawal + short bufferConsent withdrawn
Server & security logs6–12 months CONFIRMRolling deletion
Analytics / cookie dataPer consent & provider policyConsent withdrawn / expiry

12. Security Safeguards

  • Encryption of personal data in transit (TLS) and at rest.
  • Role-based access control, least privilege, and unique credentials; MFA for administrative access.
  • Audit logging and monitoring of access to personal data.
  • Segregation of environments; secrets management; regular patching.
  • Backups with tested restore, and secure deletion on retirement of media.
  • Contractual security obligations flowed down to all processors.
  • Periodic access reviews and vulnerability assessment CONFIRM cadence.

13. Personal Data Breach Response

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data. VERALIS follows the steps below and notifies the Data Protection Board of India and affected Data Principals in the manner and timeline required by the DPDP Act and Rules.

StepActionOwner / timing
1. Detect & logRecord the incident in the breach register; assign severityWhoever detects / Grievance Officer — immediately
2. ContainIsolate systems, revoke credentials, stop the exposureDeveloper / platform — immediately
3. AssessScope: data, individuals, likely impactGrievance Officer — within 24 hrs
4. Notify BoardReport to the Data Protection Board of IndiaGrievance Officer — per Rules timeline
5. Notify Data PrincipalsInform affected individuals: nature, consequences, mitigation, contactGrievance Officer — per Rules timeline
6. Remediate & reviewFix root cause; update controls; post-incident reviewPlatform + Grievance Officer

Breach register fields: incident ID, date/time detected, description, data & individuals affected, severity, containment actions, Board notification date, Data Principal notification date, root cause, corrective actions, closure date.

14. Cross-Border Transfers

The DPDP Act permits transfer of personal data outside India except to countries restricted by Government notification. Where processors store or process data outside India (e.g., cloud regions), VERALIS confirms the destination is not restricted, applies contractual safeguards, and records the transfer in the sub-processor register. CONFIRM data-residency choice for hosting

15. Grievance Redressal

  • Channel: admin@veralispress.com, monitored by the Grievance Officer.
  • Acknowledge within 48 hours; resolve within 30 days (internal SLA, subject to final Rules).
  • If unresolved or the Data Principal is dissatisfied, they may approach the Data Protection Board of India.
  • All grievances and outcomes are logged for audit.

16. Training, Review, and Accountability

  • Staff and contractors with access to personal data receive DPDP awareness briefing at onboarding and annually.
  • This manual and all registers are reviewed at least annually and upon notification of the DPDP Rules or material change to processing.
  • The Grievance Officer maintains evidence of compliance (RoPA, consent logs, DSR register, breach register, vendor contracts).
  • Significant Data Fiduciary duties (DPO, independent audit, DPIA) are activated if VERALIS is so notified.

17. Appendices — Register Templates

A. Data Subject Request (DSR) log

FieldNotes
Request ID / date received
Data Principal & verification method
Right requestedAccess / correction / erasure / withdrawal / nomination / grievance
Action taken & date
Outcome & closure date
Within SLA? (Y/N)

B. Consent record (see Section 7)

Fields: Data Principal ID, purpose, consent text & version, timestamp & source, status, withdrawal timestamp.

C. Breach register (see Section 13)

Fields: incident ID, detected date/time, description, data & individuals affected, severity, containment, Board notification date, Data Principal notification date, root cause, corrective actions, closure date.

End of document. This manual is provided for VERALIS internal governance and should be finalised with legal counsel and the notified DPDP Rules.