Privacy Policy
How we collect, use, store and delete your data and identity documents. Published under Rule 4 of the SPDI Rules, 2011, with a named Grievance Officer and a 30-day response.
Privacy Policy: the short version
This policy is published as required by Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It tells you what we collect, why, who sees it, how long we keep it, how it is protected, and how to have it corrected or deleted. Your identity documents are sensitive personal data and are handled accordingly. We do not sell data and we never publish your name, photograph or case details.
Privacy Policy: key facts at a glance
| Why this page exists in law | Rule 4 of the SPDI Rules, 2011 requires a body corporate handling personal data to publish a privacy policy on its website. Section 43A of the IT Act, 2000 makes negligent handling of sensitive data actionable. |
|---|---|
| Who is responsible | Tatkal Court Marriage, Delhi. Contact: care@tatkalcourtmarriage.com / +91 93184 23172. |
| What we collect | Name, phone, email, city or locality, the route you need, your facts, and the documents you choose to send. |
| Sensitive personal data | Identity documents and any financial detail you share fall under Rule 3 of the SPDI Rules and get the higher standard of care. |
| Why we collect it | To advise on the correct route, prepare and check your file, coordinate with the concerned office, and follow up until the certificate is issued. |
| Do we sell data? | No. Never. Not to lead brokers, not to lenders, not to anyone. |
| Who we share with | Only the government office handling your file, the advocate on your matter, and a service you ask us to use (notary, translator, apostille agent). Nothing beyond that without your permission, unless the law compels it. |
| How long we keep it | Working documents until your matter closes plus a short reconciliation period. Anything longer only where a law requires it. |
| Your rights | Review your data, correct it, withdraw consent, ask for deletion. Rule 5(6) and Rule 5(7), SPDI Rules, 2011. |
| Grievance Officer | Published below under Rule 5(9). Written response within one month. |
| Cookies | Essential only. No advertising trackers. See the Cookie Policy. |
| Last updated | 10 September 2026 |
1. Why this policy exists, and why you should care about it more than usual
Most privacy policies are written to protect the company. This one has to do a second job, because of what you send us. To get a marriage registered in Delhi, a couple hands over Aadhaar, passport, school certificate, address proof, photographs, and often a divorce decree or a death certificate. That is one of the most complete identity packages a person will ever put in someone else's hands.
So this page is written to be checked. Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 requires a body corporate handling personal data to publish a privacy policy on its website, and to state five things in it: its practices and policies, the type of data collected, the purpose of collection, disclosure as permitted by Rule 6, and the security practices maintained under Rule 8. All five are below, in that order, so you can tick them off.
Section 43A of the Information Technology Act, 2000 backs this up: a body corporate that is negligent in implementing reasonable security practices while handling sensitive personal data, and thereby causes wrongful loss or wrongful gain, is liable to pay compensation. The Explanation to that section covers a firm and a sole proprietorship, so it applies to a service like ours.
2. The data we collect - the complete list
We collect only what a marriage matter genuinely needs. Here is everything, split by how sensitive it is.
| Category | What it includes | Why we need it | Kept for |
|---|---|---|---|
| Contact data | Name, phone number, WhatsApp number, email, city or Delhi locality | To reply to you and to work out which SDM sub-division your file goes to | Until the matter closes, then a short reconciliation period |
| Case data | Both partners' ages, religion where the route depends on it, marital history, ceremony status, urgency, preferred route | To identify the correct legal route and tell you the real timeline | Until the matter closes |
| Documents | Aadhaar, PAN, passport, voter ID, driving licence, birth or school certificate, address proof, photographs, divorce decree, death certificate, conversion certificate | To check the file against what the office actually requires, and to prepare and submit it | Until the certificate is issued plus a short period, then deleted on request or on schedule |
| Payment data | The fact and amount of a payment and its reference | Accounting and receipts | As long as tax and accounting law requires |
| Website data | Pages visited, approximate location from IP, device type, referring page | To see which guides are useful and to keep the site working | Aggregated; not linked to your file |
| Communications | WhatsApp messages, emails and call notes about your matter | So the next person who picks up your file knows what was already said | With the matter file |
3. Which of this is 'sensitive personal data' - and what that changes
Rule 3 of the SPDI Rules, 2011 defines sensitive personal data or information. It includes passwords, financial information such as bank account or card details, physical and mental health condition, sexual orientation, medical records, and biometric information.
In our work, the categories that bite are financial information and any biometric or health detail that appears inside a document you send. An Aadhaar is an identity document that also carries a biometric linkage; a medical certificate sometimes appears in an age-proof file; a bank statement sometimes appears as address proof.
What that changes in practice: sensitive personal data may be collected only for a lawful purpose connected with our function, only where it is necessary, and only with your consent in writing or by electronic communication - Rule 5(1). We must tell you what we are collecting, why, who will receive it and who is retaining it - Rule 5(3). And it must be kept under reasonable security practices - Rule 8. Every one of those is honoured below.
A practical request from us: do not send a document we have not asked for. If your address proof is a bank statement, mask the transactions. If we ask for a passport, we need the identity page and the relevant visa page, not the whole booklet. Less data with us is better for both of us.
4. Why we use your data - and the one thing we never do with it
Every use falls into one of these purposes, and we do not repurpose your data outside them:
- Answering your enquiry and advising on the correct legal route for your facts.
- Checking, preparing, drafting and correcting your file.
- Submitting to and coordinating with the concerned SDM office, Marriage Officer, Registrar or institution.
- Arranging services you asked for: notarisation, translation, apostille, witnesses.
- Following up until the certificate is issued, and afterwards for correction or a duplicate.
- Issuing receipts and meeting our own accounting and tax obligations.
- Improving this website in aggregate - which guides get read, where people drop off.
What we never do: we do not sell your data. We do not share it with lead-generation companies, loan or insurance sellers, wedding vendors, photographers or venue agents. We do not publish your name, photograph, testimonial or case details on this website or on social media - not even anonymised, not even as a success story, not even if you offer. Marriage matters in Delhi are often family-sensitive, sometimes dangerously so, and there is no version of publishing your case that is worth that risk to you.
5. Consent, and how to take it back
We collect your data on your consent, given when you submit the enquiry form, message us, or hand over documents for a matter you have asked us to take on. Rule 5(1) of the SPDI Rules requires that consent for sensitive personal data be in writing or by electronic communication - a WhatsApp message instructing us is exactly that, and it is retained on the file.
You are not obliged to give us anything. Rule 5(7) says you have the option not to provide the data sought, and to withdraw consent later in writing. If you withdraw consent while a matter is live, we will tell you plainly what we can no longer do - usually, everything, because a file cannot be prepared without the documents - and we will stop and return or delete what we hold, subject to anything we are legally required to keep.
Where we need to use your data for something outside the purposes listed in section 4, we come back and ask you first.
6. Who sees your data - disclosure under Rule 6
Rule 6 of the SPDI Rules provides that disclosure of sensitive personal data to a third party requires prior permission from the provider of that data, unless the disclosure was agreed in the contract or is necessary for compliance with a legal obligation. Applied honestly to our work, that means your data goes to exactly four kinds of recipient:
The government office handling your file. The SDM, Marriage Officer or Registrar receives what the statutory form and the office's checklist require. That is the whole point of the engagement and is covered by your instruction to us.
The advocate working on your matter, where drafting, an affidavit or an appearance is needed. Advocates are bound by their own professional confidentiality obligations.
A service you asked us to arrange: a notary, a translator, an apostille agent, a courier. Only the specific document that service needs, and only after you have asked for it.
A lawful authority, where a law, a court order or a government agency's lawful written request compels disclosure. Rule 6(1) proviso and Rule 6(2) permit this without your consent; we will tell you it happened unless we are forbidden from telling you.
That is the entire list. There is no analytics partner receiving your documents, no CRM vendor reselling your number, and no marketing list.
7. How your data is protected - Rule 8
Rule 8 requires reasonable security practices proportionate to the information held, and treats compliance with the IS/ISO/IEC 27001 standard, or a code approved by an industry association, as one way of demonstrating it. We are a small professional service, not a data centre, so what matters is that our controls are real rather than impressive-sounding. These are the ones we actually operate:
Access is limited to the people working on your matter. Documents are held on password-protected devices and cloud storage with two-factor authentication, not on shared drives or open folders. Physical papers are held in a locked cabinet and originals are returned to you at the earliest, not retained. Documents are transmitted only over the channel you chose, and we ask you not to post them into any group chat. When a matter closes and retention is over, digital files are deleted and paper is shredded rather than binned.
We are honest about the limits. WhatsApp and email are third-party channels and their security is theirs, not ours. No system is immune. If a breach ever affects your data, we will tell you what happened, what was exposed and what to do about it, rather than stay quiet and hope.
8. Your rights over your own data
You can exercise any of these by writing to care@tatkalcourtmarriage.com or calling +91 93184 23172. We do not charge for any of them.
- Review. Ask what we hold about you. Rule 5(6) of the SPDI Rules gives you the right to review the information you provided.
- Correct. Tell us anything inaccurate or deficient and we will correct it. Same rule. This matters more than usual in marriage files, because a wrong spelling propagates into a certificate.
- Withdraw consent. In writing, at any time, under Rule 5(7).
- Deletion. Ask us to delete what we hold once your matter is closed. We will confirm in writing what was deleted and what, if anything, we are legally required to retain.
- Get your file back. Ask for copies of what you gave us and what was filed on your behalf.
- Complain. To our Grievance Officer below, and beyond that to the appropriate authority.
One request we cannot honour: we cannot delete anything already filed with a government office. Once a document is on a government record it is part of that record, and only that office can act on it.
9. Grievance Officer - published under Rule 5(9)
Rule 5(9) of the SPDI Rules requires a body corporate to designate a Grievance Officer, publish that officer's name and contact details on its website, and redress a grievance expeditiously and in any case within one month of receipt.
Grievance Officer, Tatkal Court Marriage
Email: care@tatkalcourtmarriage.com
Phone: +91 93184 23172
Address: as published on our Contact page
Hours: Monday to Saturday, working hours
Response: acknowledged within 48 hours, resolved in writing within 30 days.
Please put 'Privacy grievance' in the subject line and tell us your name, your phone number, the matter it relates to and what you want done. If you would rather speak first, call and ask for the grievance to be escalated. Our full escalation ladder is set out on the Grievance Redressal page.
10. Cookies, analytics and this website
This site is deliberately light. It uses essential cookies to keep the site working and may use basic aggregate analytics to see which guides people read. It does not run advertising trackers, does not build a profile of you across other websites, and does not require you to log in.
The enquiry form on this site sends your message to us. Nothing typed into it is shared with a third-party marketing platform. The detail, and how to control cookies in your browser, is on the Cookie Policy page.
11. Children
This site and our service are for adults. The minimum ages for a valid marriage are set by statute - 21 for the man and 18 for the woman under section 4(c) of the Special Marriage Act, 1954 - and we do not knowingly take instructions from, or collect data about, anyone below the age at which they could lawfully marry.
If you believe a minor's data has reached us, write to the Grievance Officer and we will delete it.
12. What changes in 2027 - the DPDP Act, and why this page is already shaped for it
India's data protection regime is mid-transition, and it is worth knowing where it stands so you are not misled by a policy that claims more than the law currently requires.
The Digital Personal Data Protection Act, 2023 was enacted but is being brought into force in phases. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The substantive Data Fiduciary obligations under those Rules - notice, consent management, security safeguards, breach reporting, erasure, the Consent Manager framework - commence on 14 May 2027. Until then, the SPDI Rules, 2011 continue to govern, and that is the framework this page is written under.
We have nonetheless drafted this policy in the shape the DPDP Act will require: a clear notice of purpose, consent that can be withdrawn, defined retention, a named grievance route, and a right of erasure. When the DPDP obligations commence, this page will be updated to name the Data Fiduciary formally and to add the statutory rights of a Data Principal, including the right to nominate. You will not have to re-consent to anything you have already agreed to here.
13. Changes to this policy
We will update this page when our practices change or when the law changes. The 'last updated' date at the top tells you when. A material change will be flagged on the page for a reasonable period.
If you engaged us under an earlier version and a change materially reduces your protection, the version in force when you engaged us continues to apply to that matter.
Frequently asked questions
Do you sell or share my phone number with anyone?
No. We do not sell data and we do not pass your number to lead brokers, loan or insurance sellers, or wedding vendors. Your number goes to the people working on your file and nowhere else.
Will my name or photo appear anywhere on your website?
No. We do not publish client names, photographs, testimonials or case details, even anonymised, even with permission. Marriage matters are family-sensitive and there is no version of publishing your case that is worth the risk to you.
What legally requires you to have this policy?
Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 requires a body corporate handling personal data to publish a privacy policy on its website. Section 43A of the IT Act, 2000 makes negligent handling of sensitive data actionable in damages.
Is my Aadhaar 'sensitive personal data'?
Identity and financial documents are treated by us at the higher standard set for sensitive personal data under Rule 3 of the SPDI Rules, 2011, which expressly covers financial information and biometric information. In practice that means restricted access, encrypted storage, and deletion on request.
How long do you keep my documents after my certificate is issued?
Only for a short reconciliation period, and then they are deleted or shredded. You can ask for deletion earlier and we will confirm in writing what was deleted. Anything a tax or accounting law requires us to keep is kept for that period and nothing longer.
Can I ask you to delete everything you hold about me?
Yes. Write to the Grievance Officer at care@tatkalcourtmarriage.com. We will confirm what has been deleted. The one thing we cannot delete is anything already filed with a government office - that is part of their record, not ours.
Who is your Grievance Officer and how fast must they reply?
The Grievance Officer's contact details are published on this page as Rule 5(9) of the SPDI Rules requires. We acknowledge within 48 hours and give a written resolution within 30 days, which is the outer limit the rule allows.
Is WhatsApp safe for sending my documents?
It is convenient and widely used, and it is a third-party service whose security is not ours to guarantee. Send only the pages we ask for, never post documents into a group chat, and if you would rather hand them over in person, tell us and we will arrange it.
Does your site track me with advertising cookies?
No. The site uses essential cookies and at most basic aggregate analytics. There are no advertising trackers and no cross-site profiling. Details are on the Cookie Policy page.
What is the DPDP Act and does it apply to my data right now?
The Digital Personal Data Protection Act, 2023 is India's new data law, being brought into force in phases. The DPDP Rules, 2025 were notified on 13 November 2025 and the substantive Data Fiduciary obligations commence on 14 May 2027. Until then the SPDI Rules, 2011 govern - which is what this policy is written under - but we have already drafted it in the shape DPDP will require.
Do you share my file with the SDM office?
Yes - that is the purpose of the engagement. The office receives what the statutory form and its own checklist require for your file, and nothing extra. Rule 6 of the SPDI Rules permits disclosure that is necessary for the purpose you engaged us for.
What happens if you have a data breach?
We tell you: what happened, which of your data was involved, and what you should do. We do not stay quiet about it. Section 43A liability and, from May 2027, the DPDP breach-reporting duty both point the same way, and so does basic decency.
Our other policy pages
Everything that governs how we work with you, in one place.
