Master Privacy & DPDP Compliance Blueprint (DPDP Act, 2023) Data Fiduciary: M/S Parul Sampada Ventures | Shivpuri, Madhya Pradesh 100% Domestic Data Localization & Indian Server Security Master Privacy & DPDP Compliance Blueprint (DPDP Act, 2023) Data Fiduciary: M/S Parul Sampada Ventures | Shivpuri, Madhya Pradesh 100% Domestic Data Localization & Indian Server Security
DPDP Act, 2023 Statutory Notice

Exhaustive Data Privacy, Protection, and Consent Management Policy

For M/S PARUL SAMPADA VENTURES | Master Privacy and DPDP Compliance Blueprint

Statutory Framework: DPDP Act, 2023 | IT Act, 2000 Jurisdiction: Shivpuri, Madhya Pradesh, India

I PART I: PREAMBLE AND LEGISLATIVE FRAMEWORK

1.1 Introduction and Legal Binding: This Exhaustive Data Privacy, Protection, and Consent Management Policy (hereinafter referred to as the "Privacy Policy" or "Policy") constitutes a legally binding electronic agreement between M/s Parul Sampada Ventures, an e-commerce food and agricultural commodity enterprise registered in Shivpuri, Madhya Pradesh (hereinafter referred to as the "Data Fiduciary", "Firm", "We", or "Us"), and the end-user, consumer, or visitor (hereinafter referred to as the "Data Principal", "User", or "You").

This document is engineered to provide an exhaustive, multi-layered framework governing the collection, processing, storage, retention, and erasure of digital personal data. It is drafted in absolute compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), alongside the Information Technology Act, 2000, and the Consumer Protection (E-Commerce) Rules, 2020.

1.2 Notice of Processing and Unambiguous Consent: In direct compliance with Section 5 (Notice) and Section 6 (Consent) of the DPDP Act, 2023, this Policy serves as the formal itemized Notice detailing what personal data is collected, the precise purpose for such collection, and the legal basis for processing. By registering an account, placing an order for our proprietary food products (including Makhana, Chana, Seeds, Murmura, and Edamame), or navigating our digital architecture, the Data Principal provides free, specific, informed, unconditional, and unambiguous consent to the processing of their personal data exactly as outlined in this massive framework.

II PART II: DEFINITIONAL MATRIX UNDER DPDP ACT, 2023

To ensure absolute legal clarity and prevent interpretative ambiguities in the competent courts of Shivpuri, Madhya Pradesh, the following terms are strictly defined in accordance with the DPDP Act, 2023:

  • "Data Fiduciary" means M/s Parul Sampada Ventures, the entity that alone determines the purpose and means of processing personal data.
  • "Data Principal" means the individual to whom the personal data relates. If the individual is a minor (under 18 years), it includes their parent or lawful guardian.
  • "Data Processor" means any third-party logistics company (e.g., delivery partners), payment aggregator, or cloud hosting provider that processes personal data on behalf of the Firm.
  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Processing" means a wholly or partly automated operation performed on digital personal data, including collection, recording, structuring, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.
  • "Personal Data Breach" means any unauthorized processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data.
  • "Board" means the Data Protection Board of India established under the DPDP Act.

III PART III: EXHAUSTIVE DATA COLLECTION ECOSYSTEM

3.1 Categorization of Personal Data Collected: The Firm acts as a Data Fiduciary and systematically collects specific data points to fulfill commercial transactions, ensure food safety traceability under FSSAI mandates, and validate GST invoicing. The data ecosystem is categorized as follows:

Data Category Specific Data Points Collected Legal Basis for Processing
Identity & Profile Data First name, last name, date of birth, account usernames, encrypted passwords, profile photographs. Consent (DPDP Sec 6) & Contractual Fulfillment
Contact Data Residential address, delivery coordinates, billing address, email ID, mobile telephone numbers. Contractual Fulfillment & Logistics Execution
Financial & Transaction Data Bank account masking, UPI ID, partial credit/debit card numbers (as permitted by RBI), order history, cart abandonment logs, refund status. Processing for Legitimate Purpose (DPDP Sec 7)
Corporate/B2B Data GSTIN, registered corporate entity name, PAN card (for transactions exceeding INR 2,00,000). Compliance with Law (GST Act / PMLA)
Technical & Device Data Internet Protocol (IP) address, browser type, operating system, MAC address, time-zone settings, device geolocation. Security, Anti-Fraud, & Platform Optimization
FSSAI Traceability Data Linkage of the Data Principal’s delivery address to specific product batch numbers (e.g., Makhana Batch #102) for targeted food safety recalls. Public Interest & Statutory Safety Mandates

3.2 Exclusion of Biometric and Highly Sensitive Data: M/s Parul Sampada Ventures explicitly declares that it does not process, collect, or store biometric data (fingerprints, retina scans), genetic data, caste/religious identifiers, or political affiliations. All data processed is strictly commercial, transactional, and logistical in nature.

IV PART IV: PURPOSE LIMITATION AND PROCESSING MECHANICS

In strict adherence to the Purpose Limitation Principle of the DPDP Act, 2023, the Firm shall only process Personal Data for the specific, lawful purposes explicitly consented to by the Data Principal.

4.1 Fulfillment of E-Commerce Transactions:

  • Processing orders for Makhana, Chana, Seeds, Murmura, and Edamame.
  • Transmitting delivery coordinates to third-party Data Processors (logistics and courier partners).
  • Executing payment processing, generating digital GST invoices, and managing the financial ledger.

4.2 Food Safety, Legal Metrology, and FSSAI Compliance: Maintaining strict batch traceability. If a batch of Mix Seeds or Chana Bhuna is found to possess moisture defects or FSSAI standard deviations, the Firm uses Personal Data to directly contact the specific Data Principals who received the affected batch to issue immediate consumption warnings and initiate product recalls.

4.3 Anti-Fraud, Security, and Asset Protection:

  • Deploying machine learning algorithms to map IP addresses and device IDs against payment histories to prevent chargeback fraud, identity theft, and malicious returns (e.g., substituting rocks for premium Edamame).
  • Complying with the Prevention of Money Laundering Act (PMLA) by validating PAN data for high-volume transactions.

V PART V: DATA PRINCIPAL RIGHTS UNDER THE DPDP ACT, 2023

The DPDP Act, 2023 confers powerful, actionable rights upon the Data Principal. The Firm provides a dedicated digital interface (and Grievance Officer routing) to honor these rights within the legally mandated timelines.

5.1 Right to Information about Personal Data (Section 11)

The Data Principal has the right to obtain from the Firm a comprehensive summary of personal data being processed and the processing activities undertaken, as well as the identities of all Data Processors (logistics partners, payment gateways) with whom the personal data has been shared, along with a description of the data shared.

5.2 Right to Correction, Completion, and Updating (Section 12)

The Data Principal holds the absolute right to command the Firm to correct any inaccurate or misleading personal data (e.g., a misspelled delivery address in Shivpuri), complete any incomplete personal data, and update personal data across all active databases.

5.3 Right to Erasure / Right to be Forgotten (Section 12)

The Data Principal may request the absolute erasure of their personal data when it is no longer necessary for the purpose for which it was processed.

Crucial Exception: The Firm shall refuse the erasure request if the retention of data is required for compliance with any law in force (e.g., preserving GST invoices for 72 months as per the CGST Act, 2017, or FSSAI traceability logs).

5.4 Right to Nominate (Section 14)

A unique provision of the DPDP Act, 2023 allows the Data Principal to nominate any other individual who shall, in the event of the Data Principal's death or permanent physical/mental incapacity, exercise the Data Principal’s rights under this Act. The Firm provides a dedicated nomination form within the User Account Dashboard to facilitate this legal mandate.

VI PART VI: DUTIES OF THE DATA PRINCIPAL (SECTION 15)

The DPDP Act balances rights with strict duties. To protect the Firm from malicious data requests and corporate sabotage, the Data Principal is bound by the following statutory duties:

  • No False Grievances: The Data Principal shall not register a false or frivolous grievance or complaint with the Data Fiduciary or the Data Protection Board.
  • Accuracy of Information: The Data Principal shall furnish only verifiably true personal data when demanding the erasure or correction of records.
  • No Impersonation: The Data Principal shall not impersonate another person while establishing an account, making a purchase, or submitting a data rights request.

Penalty for Breach of Duty: Under the DPDP Act, 2023, failure to observe these duties may result in financial penalties levied directly against the Data Principal by the Data Protection Board.

VII PART VII: OBLIGATIONS OF THE DATA FIDUCIARY (FIRM)

7.1 Reasonable Security Practices: The Firm guarantees the implementation of robust organizational and technical measures to safeguard Personal Data. This includes end-to-end encryption of payment data, hashing of user passwords, secure API routing, and restricted, role-based access for our internal staff operating out of the Shivpuri headquarters.

7.2 Data Processor Accountability: When the Firm shares Personal Data with Data Processors (e.g., Delhivery, Razorpay, AWS), it does so only under a valid, legally binding contract that explicitly restricts the Data Processor from utilizing the data for any purpose other than the specific task delegated by the Firm. The Firm remains ultimately accountable to the Data Principal for the actions of its Data Processors.

7.3 Data Minimization and Retention Timelines: Personal data is retained only as long as is necessary to satisfy the purpose for which it was collected.

  • Inactive Accounts: If an account remains dormant for 36 consecutive months, non-essential profiling data will be automatically purged.
  • Statutory Holds: Financial transaction data, GST profiles, and FSSAI product recall linkage data are quarantined and retained for a minimum of 7 years to satisfy the auditing requirements of the Government of India.

VIII PART VIII: PERSONAL DATA BREACH NOTIFICATION PROTOCOL (SECTION 8)

Despite military-grade security architectures, digital breaches can theoretically occur. In the event of a Personal Data Breach (e.g., a cyber-attack exposing user delivery addresses), the Firm is bound by strict statutory notification protocols:

  1. Immediate Containment: The Firm will immediately sever compromised server connections and initiate an internal forensic audit.
  2. Notification to the Board: The Firm shall notify the Data Protection Board of India in the legally prescribed electronic format, detailing the nature of the breach, the volume of data compromised, and the mitigation strategies deployed.
  3. Notification to the Data Principal: Simultaneously, the Firm shall directly notify every affected Data Principal via their registered email and SMS, advising them on the nature of the breach and the protective measures they must independently take (e.g., changing passwords).

IX PART IX: CROSS-BORDER DATA TRANSFER AND LOCALIZATION

Absolute Data Localization Protocol:

M/s Parul Sampada Ventures operates exclusively within the domestic borders of the Republic of India. In alignment with sovereign data protection principles, 100% of the Personal Data collected by the Firm is hosted, processed, and stored on physical and cloud servers located exclusively within the territory of India.

The Firm strictly prohibits the transfer of any Data Principal’s personal data to foreign jurisdictions, international servers, or cross-border processors, thereby ensuring the data remains entirely under the protective umbrella of the DPDP Act, 2023 and the jurisdiction of Indian courts.

X PART X: COOKIE POLICY, TRACKING PIXELS, AND BEHAVIORAL ANALYTICS

10.1 Mechanism of Action: The Platform utilizes temporary session cookies, persistent tracking cookies, and web beacons to optimize the e-commerce interface. These text files are injected into the Data Principal's browser environment to remember cart contents (e.g., retaining Makhana Peri Peri in the cart across sessions), maintain login states, and accelerate loading times for recurring visitors.

10.2 Analytics and Third-Party Modules: The Firm may utilize analytics engines to assess which snack categories receive the most digital traffic. These analytics are performed on highly aggregated, mathematically anonymized data sets that cannot be reverse-engineered to identify a specific Data Principal.

10.3 Consent Manager Interface: The Data Principal is presented with a clear Consent Manager popup upon their first visit to the Platform, allowing them to granularly accept or reject non-essential tracking cookies. Rejecting essential cookies may result in the degradation of Platform functionality (e.g., the inability to proceed to the checkout gateway).

XI PART XI: VERIFIABLE PARENTAL CONSENT FOR CHILDREN (SECTION 9)

The DPDP Act, 2023 imposes stringent regulations on the processing of personal data belonging to children (defined as individuals under the age of 18 years).

  • Prohibition on Tracking: The Firm strictly does not undertake tracking, behavioral monitoring, or targeted advertising directed at children.
  • Verifiable Consent: The Platform is engineered for adult consumers capable of forming valid contracts. If the Firm discovers that a minor has created an account and provided personal data without the verifiable, documented consent of their lawful parent or legal guardian, the Firm shall instantly terminate the account and irreversibly erase the associated data points.

XII PART XII: DISPUTE JURISDICTION AND INDEMNITY SHIELDS

12.1 Exclusive Jurisdictional Lock: This exhaustive Privacy Policy is governed entirely by the laws of India. As established in the overarching Terms of Use, any litigation, legal dispute, or data grievance that escalates beyond the Data Protection Board's purview shall be subject exclusively to the jurisdiction of the competent judicial courts located in Shivpuri, Madhya Pradesh, to the absolute exclusion of all other national or international legal venues.

12.2 Indemnity against Data Principal Misconduct: The Data Principal agrees to indemnify and hold harmless M/s Parul Sampada Ventures from any fines, legal fees, or damages arising out of the Data Principal's violation of their statutory duties under Section 15 of the DPDP Act, including the submission of fraudulent data, impersonation, or the filing of frivolous, extortionate complaints with the Data Protection Board.

XIII PART XIII: CONSENT MANAGER AND GRIEVANCE REDRESSAL MECHANISM

To facilitate the rapid, transparent execution of Data Principal rights (Access, Erasure, Correction, Nomination) and to address any concerns regarding data processing, the Firm has established a dedicated Grievance Redressal framework.

Any Data Principal wishing to exercise their rights under the DPDP Act, 2023, or wishing to report a suspected data violation, must initiate contact via the following designated authority:

Designation: Data Protection & Grievance Officer

Corporate Entity: M/s Parul Sampada Ventures

Registered Office Address: Shivpuri, Madhya Pradesh, India.

Compliance Email ID: privacy@parulsampada.com / grievance@parulsampada.com

Statutory Response Time: The Grievance Officer is legally mandated to acknowledge receipt of the request within forty-eight (48) hours and shall provide a comprehensive resolution or action report within thirty (30) days from the date of the formal query.

End of Exhaustive DPDP Compliance Privacy Policy.

By continuing to navigate this Platform, the Data Principal acknowledges total, informed, and specific agreement to this legal architecture.

Order via WhatsApp