DPDP Act 2023 & IT Act Compliant• Last Updated: September 2026

Privacy Policy & Data Protection Charter

Nirosha India Retail Ltd. is committed to transparent, principled data processing in strict adherence with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection (DPDP) Act, 2023.

1. Categories of Personal Data Collected

When you browse, register, or execute an order on Nirosha India, we collect only data strictly necessary to fulfill transactions and comply with Indian statutory requirements:

  • Contact & Identity Data: Full name, telephone/mobile number, and authenticated Clerk email address.
  • Delivery Coordinates: Complete physical shipping address, city, state, and 6-digit Indian PIN code for pan-India logistics routing.
  • Technical Telemetry: Anonymized IP addresses, browser user-agent strings, session cookies, and hardware operating system identifiers collected to prevent fraudulent checkout attempts.
  • GST Compliance Records: Business entity name and registered GSTIN (Goods and Services Tax Identification Number) where B2C/B2B tax invoices are requested.

2. Zero-Storage Payment Standard & PCI-DSS Compliance

Zero Cardholder Data Storage Guarantee

Nirosha India never stores, caches, or logs credit card numbers, debit card numbers, CVV codes, UPI PINs, or net banking passwords on our web servers or databases. All payment transactions are executed through RBI-regulated, PCI-DSS Level 1 certified payment aggregators (Stripe / Razorpay) using end-to-end 256-bit TLS encryption and tokenization.

3. Data Sharing Scope & Third-Party Disclosures

Nirosha India maintains a strict Zero Third-Party Marketing Sale Policy. Your personal data is never rented, monetized, or shared with advertisers. Disclosures occur solely in the following bounded contexts:

  • Logistics Couriers: Delivery names, addresses, and telephone numbers are shared with authorized courier networks (e.g. Blue Dart, Delhivery) strictly to complete physical dispatch.
  • Brand Warranty Networks: Tax invoices and serial numbers are shared with certified OEM brand service networks (Samsung, Apple, Sony) solely when you request warranty verification or DOA service.
  • Transactional Gateways: Order references and tracking updates are transmitted through transactional notification channels (SMS gateways, Resend).
  • Law Enforcement & Statutory Demands: Data may be disclosed only upon receiving formal statutory orders or subpoenas issued under Indian law.

4. Your Rights Under the DPDP Act, 2023

As a data principal under Indian data protection law, you possess the right to:

Right to Access: Request a summary of personal data held about your account and active orders.
Right to Correction: Update inaccurate or outdated shipping addresses or contact details.
Right to Erasure: Request deletion of your customer profile subject to mandatory Indian tax retention laws.
Right to Grievance Redressal: Direct escalation to our designated Data Protection Officer.

5. Statutory Data Protection & Grievance Officer

In compliance with Section 5(9) of the DPDP Act, 2023 and Rule 5(9) of the Information Technology SPDI Rules, 2011:

Designated Grievance OfficerData Protection & Grievance OfficerNirosha India Retail Ltd.
Physical Office Address
Level 8, Platina Tower, C-59, G Block, Bandra Kurla Complex (BKC), Bandra East, Mumbai, Maharashtra 400051, India.
Statutory Resolution Commitment: Mandatory acknowledgment within 48 business hours; final ticket resolution within 30 calendar days.

Review our Master Terms of Service

Explore our catalog pricing transparency, 7-day replacement protocol, and brand warranty coverage.

View Terms of Service