The short version. We collect what is needed to sign you in and to run your chapter's operations. We do not sell your data, there is no advertising in myChap, and the product contains no third-party analytics or tracking tools.
Two organisations are involved. We look after your sign-in account and the platform. Your chapter decides what it records about you and who inside it can see it. Section 2 explains which is which, because that decides who you ask when you want something changed or removed.
myChap is a product of ThetaZero Private Limited, a company incorporated in India, registered office No. 10, Manikandan Nagar, Hasthinapuram, Chennai, Tamil Nadu 600064, India, CIN U74999TN2022PTC157268. In this policy "we", "us" and "ThetaZero" mean that company; "myChap" means the product.
This policy is written primarily against India's Digital Personal Data Protection Act, 2023 (the DPDP Act). Section 13 sets out the additional rights that apply if the EU or UK GDPR covers you.
It does not cover what a chapter does with your data outside myChap, or the practices of the providers listed on our sub-processor page — each has its own policy.
This determines who you go to for access, correction or erasure, so it is up front rather than buried.
| Layer | What it contains | Who decides |
|---|---|---|
| Your account and the platform | Sign-in identity, one-time codes, session and security records, device and notification tokens, our billing relationship with chapters, correspondence with us | ThetaZero is the Data Fiduciary. Ask us. |
| Your chapter's workspace | Your membership record as the chapter maintains it, roles and portfolios, program registrations and attendance, payment history with the chapter, anything you upload there | Your chapter is the Data Fiduciary. We process it on the chapter's instructions. Ask the chapter's board. |
Under the DPDP Act we are a Data Fiduciary for the first layer and a Data Processor for the second. The GDPR calls these controller and processor.
myChap does not grant or end your chapter membership. You cannot become a member of a chapter through myChap. Your chapter imports its membership list from its own records, and myChap tracks which memberships are live and which have expired. Deleting your myChap account removes you from myChap — it does not resign your membership, and it does not affect any membership you hold with a professional body. To change or end your membership, contact your chapter.
In practice: send any request to us if that is easier. Where it concerns the chapter's layer, we pass it to the chapter and support them in answering, as described in section 12.
Much of the following is optional and chapter-dependent. A chapter decides which fields it asks for, and you decide what you fill in. A chapter running a job board will ask for a CV; a chapter that does not run one never collects one. The list below is everything the platform is capable of holding, not a list of what is held about you.
| Why | Basis |
|---|---|
| Creating your account and signing you in | Necessary to provide the service you asked for (GDPR: contract) |
| Running your chapter's workspace on its instructions | The chapter's own basis; we act as processor |
| Taking payments, issuing invoices, settling funds, keeping financial records | Contract, and legal obligation for tax and accounting |
| Service messages — sign-in codes, registration confirmations, receipts, reminders, billing notices | Contract, and our legitimate interest in operating the service |
| Push notifications to your device | Your consent, given when you allow notifications |
| Security — session records, IP and user agent, investigating abuse and fraud | Legitimate interest in keeping accounts and money safe |
| Diagnosing faults and improving myChap | Legitimate interest |
| Legal, tax and regulatory obligations | Legal obligation |
ThetaZero does not use your personal data for advertising, and does not sell it or share it with data brokers. We do not make automated decisions about you that produce legal effects. myChap embeds no third-party analytics, advertising, session-replay or A/B-testing tools.
Your chapter may analyse its own membership and engagement data to run the chapter — for example, reports on lapsed or inactive members. That analysis belongs to the chapter, under the chapter's own basis, and boards with the Advanced Analytics module can export reports containing member-level personal data.
The AI Assistant answers questions only from documents your chapter has uploaded, inside your chapter. Its content is not used to train general-purpose AI models, ours or anyone else's.
This is the most consequential thing for a member to understand, so we state it plainly.
The owner and administrators of a chapter you belong to can see the data that chapter holds about you: your profile and contact details as stored in its workspace, your registrations and attendance, payment and refund records for its programs, volunteer hours, content you post there, and — if it runs a job board — the profile and CV you submit.
We share personal data only:
Unless we are legally prevented, we will tell you and your chapter before disclosing data to an authority.
The third parties that process personal data on our behalf are listed, with what each one receives and where it operates, on our sub-processor page. That page carries its own effective date so it can be kept current.
We will give at least 30 days' notice before adding a new sub-processor that handles personal data, so chapters have time to object.
Our primary database and file storage are hosted in India. Some providers operate globally, so limited technical data — a push token, an IP address — may be processed outside India. The hosting region for each provider is shown on the sub-processor page.
Under the DPDP Act, personal data may be transferred outside India except to territories the Central Government restricts; we monitor that list and comply with it. Where data covered by the GDPR leaves the EEA or the UK, we rely on the receiving provider's Standard Contractual Clauses or another approved mechanism.
| Data | Kept for |
|---|---|
| Your account and profile, while your account is open | Until you delete it |
| Your account and profile, after you delete | Removed from live systems immediately; purged from backups within 90 days |
| Chapter records after you delete — attendance, volunteer hours, payments | Anonymised immediately; the anonymised record is kept by the chapter under its own retention policy |
| Financial and tax records — invoices, payments, refunds, settlements | As long as tax and accounting law requires, typically up to 8 years, even after an account closes |
| Session and security records | 12 months |
| Correspondence with us | 24 months |
| Chapter data after a subscription is cancelled or expires | 30 days by default, then permanently deleted. The value applying to your chapter is shown in its billing screens. |
Why an issued invoice keeps your name. Indian tax law requires a tax invoice to carry the name of the person it was issued to, and requires it to be retained. We cannot anonymise a document a statute requires to bear a name. Those invoices stay in the chapter's financial records only. They do not appear in member directories, reports, dashboards or analytics, and are not used for any other purpose. Your membership number is retained for the same reason, so historical receipts can be reconciled.
What we do:
What we do not claim:
myChap sets no cookies. The web app keeps your sign-in token and your selected chapter in your browser's local storage. Nothing is stored for advertising, cross-site tracking or measurement.
As a Data Principal in India you have the right to:
Erasure is self-service. Go to Profile → Settings → Delete account, or follow the steps on our account deletion page. We email you a confirmation code; once you enter it, deletion happens immediately and cannot be undone.
If you belong to more than one chapter, myChap lists them after you verify your identity and you choose which ones to delete your data from. Selecting every chapter closes your account; selecting some leaves your account open and your other chapters untouched. Either way, your chapter membership itself is unaffected, because myChap does not hold it. We keep a record of your deletion so that a later membership import by your chapter cannot recreate your profile.
What survives, and why: your chapter keeps its financial and attendance records — payments, invoices, ledger entries and program history — because it is legally required to. Those records show Deleted User instead of your name, except for issued tax invoices as explained in section 9.
Other requests are handled manually. Email privacy@mychap.net or the Grievance Officer in section 17. We acknowledge within 48 hours and respond within 30 days. Where a request concerns data your chapter controls, we pass it to the chapter and help it respond.
We may need to verify your identity before acting, and we may decline a request the law requires or permits us to decline — we will tell you why. The Act also places duties on you, including not raising false or frivolous complaints and not impersonating another person. If we cannot resolve your grievance, you may complain to the Data Protection Board of India.
This section applies only where the EU or UK GDPR covers your data. It adds to section 12 rather than replacing it. You have the right to access and receive a copy of your data; to rectification; to erasure where a ground in Article 17 applies; to restriction while a dispute about accuracy or lawfulness is resolved; to portability; to object to processing based on legitimate interests; and to withdraw consent at any time.
We respond within one month, extendable by two further months for complex requests — we will tell you if that happens. You may complain to your local supervisory authority, or to the Information Commissioner's Office in the UK.
We have not appointed an Article 27 representative. myChap is operated from India. If your chapter is established in the EEA or the UK, it is likely the controller for its member data and its own privacy notice applies alongside this one.
myChap is not intended for anyone under 18, and we do not knowingly collect personal data from children.
The DPDP Act requires verifiable parental consent before a child's data is processed, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. myChap has no mechanism for obtaining verifiable parental consent, so chapters must not create member records for people under 18 or upload their personal data to the platform.
If you believe a child's data has been given to us, email privacy@mychap.net and we will delete it.
If a personal data breach occurs, we will notify the Data Protection Board of India and the affected Data Principals in the form and manner the DPDP Act requires. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware where feasible, and affected individuals where the risk to them is high. We will also inform the affected chapter, since it is the Data Fiduciary for its member data and has its own notification duties.
We update this policy when myChap changes. Where a change materially affects how your data is handled, we give notice by email and in-app at least 30 days before it takes effect, and the previous version stays available in our archive. The effective date at the top of this page is the authoritative version marker.
Grievance Officer (DPDP Act)
R. A. Madhan Ram, Chief Executive Officer
grievance@mychap.net
General privacy questions — privacy@mychap.net
Help with the apps — support@mychap.net
ThetaZero Private Limited
No. 10, Manikandan Nagar, Hasthinapuram, Chennai, Tamil Nadu 600064, India
We acknowledge every privacy complaint within 48 hours and resolve it within 30 days. Please use email — it is the channel we monitor and it gives us the written record we need to act.
For anything about your membership, dues, attendance or volunteer records, contact your chapter's board. Those records belong to the chapter.