Privacy Policy
Last updated: June 2026 · Compliant with GDPR (EU) 2016/679 and India DPDP Act 2023
This Privacy Policy explains how Deemona Global News Agency ("Deemona", "we", "us", "our") collects, uses, stores, and protects your personal data when you use our website, mobile application, and related services (collectively, the "Service").
1. Data Controller
Deemona Global News Agency is the data controller for personal data processed through this Service. For all privacy-related enquiries, contact: privacy@deemona.com
2. Data We Collect
2.1 Data you provide directly:
- Email address (when you create an account)
- Password (stored as a one-way cryptographic hash — we cannot read your password)
- Display name or username (if provided)
- Contact form submissions (name, email, message)
2.2 Data collected automatically:
- IP address (for security, fraud prevention, and rate limiting — not stored long-term)
- Browser type and version (for compatibility)
- Session tokens (stored in secure HTTP-only cookies)
- Login timestamps and session duration (for security audit logs)
2.3 Data we do NOT collect:
- We do not use advertising tracking cookies or third-party analytics scripts
- We do not track your reading history or article clicks
- We do not collect location data
- We do not collect device identifiers for advertising purposes
- We do not sell, rent, or share your personal data with advertisers
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
Contract
Processing your email and account data is necessary to provide the Service you have signed up for.
Legitimate Interests
We process security logs and IP addresses to protect our platform from abuse, fraud, and unauthorised access.
Consent
Where we send optional marketing communications, we rely on your explicit consent, which you may withdraw at any time.
Legal Obligation
We may process data where required by applicable law, court order, or regulatory authority.
4. How We Use Your Data
- To create and manage your user account
- To send password reset and account security emails
- To respond to support and contact form enquiries
- To detect and prevent fraud, abuse, and unauthorised access
- To comply with legal obligations
- To send service announcements (not marketing) where necessary
We will never use your data for targeted advertising, profiling, or sale to third parties.
5. Data Retention
- Account data is retained for as long as your account remains active
- Upon account deletion, all personal data is permanently deleted within 30 days
- Security logs (IP addresses, login timestamps) are retained for 90 days, then deleted
- Contact form data is retained for 12 months, then deleted
- Legal hold: where required by law, we may retain certain data for up to 7 years
7. Third-Party Services
Deemona uses the following third-party infrastructure providers:
None of these providers are authorised to use your personal data for their own purposes beyond what is necessary to provide services to Deemona.
8. Your Rights
Under GDPR and the India DPDP Act 2023, you have the following rights:
To exercise any of these rights, submit a Data Subject Request to privacy@deemona.com. We will respond within 30 days (GDPR) or as required by applicable law.
9. Security
- All connections are encrypted using TLS 1.3
- Passwords are hashed using bcrypt (cost factor 12) — we cannot recover your password
- Database access is restricted by IP allowlist and requires SSL
- Security logs are monitored for suspicious activity
- In the event of a personal data breach affecting your personal data, we will notify affected users without undue delay and in any event within 72 hours of becoming aware of the breach, as required by GDPR Article 33
- Where the breach involves personal data of users in India, we will additionally report the breach to the Data Protection Board of India in the manner and timeline prescribed under the Digital Personal Data Protection Act 2023 and its rules
- Our breach notification to affected users will, where reasonably possible, describe the nature of the breach, the categories of data involved, the likely consequences, and the measures taken or proposed to address it
10. International Data Transfers
Our servers are located in Singapore (Render.com Asia-Pacific region). By using the Service, you consent to your data being transferred to and processed in Singapore. We ensure appropriate safeguards are in place in accordance with GDPR Chapter V and applicable data protection law.
11. Children's Privacy
The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact privacy@deemona.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 14 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.