Privacy Policy & Data Protection Charter
Nirosha India Retail Ltd. is committed to transparent, principled data processing in strict adherence with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection (DPDP) Act, 2023.
1. Categories of Personal Data Collected
When you browse, register, or execute an order on Nirosha India, we collect only data strictly necessary to fulfill transactions and comply with Indian statutory requirements:
- Contact & Identity Data: Full name, telephone/mobile number, and authenticated Clerk email address.
- Delivery Coordinates: Complete physical shipping address, city, state, and 6-digit Indian PIN code for pan-India logistics routing.
- Technical Telemetry: Anonymized IP addresses, browser user-agent strings, session cookies, and hardware operating system identifiers collected to prevent fraudulent checkout attempts.
- GST Compliance Records: Business entity name and registered GSTIN (Goods and Services Tax Identification Number) where B2C/B2B tax invoices are requested.
2. Zero-Storage Payment Standard & PCI-DSS Compliance
Zero Cardholder Data Storage Guarantee
Nirosha India never stores, caches, or logs credit card numbers, debit card numbers, CVV codes, UPI PINs, or net banking passwords on our web servers or databases. All payment transactions are executed through RBI-regulated, PCI-DSS Level 1 certified payment aggregators (Stripe / Razorpay) using end-to-end 256-bit TLS encryption and tokenization.
3. Data Sharing Scope & Third-Party Disclosures
Nirosha India maintains a strict Zero Third-Party Marketing Sale Policy. Your personal data is never rented, monetized, or shared with advertisers. Disclosures occur solely in the following bounded contexts:
- Logistics Couriers: Delivery names, addresses, and telephone numbers are shared with authorized courier networks (e.g. Blue Dart, Delhivery) strictly to complete physical dispatch.
- Brand Warranty Networks: Tax invoices and serial numbers are shared with certified OEM brand service networks (Samsung, Apple, Sony) solely when you request warranty verification or DOA service.
- Transactional Gateways: Order references and tracking updates are transmitted through transactional notification channels (SMS gateways, Resend).
- Law Enforcement & Statutory Demands: Data may be disclosed only upon receiving formal statutory orders or subpoenas issued under Indian law.
4. Your Rights Under the DPDP Act, 2023
As a data principal under Indian data protection law, you possess the right to:
5. Statutory Data Protection & Grievance Officer
In compliance with Section 5(9) of the DPDP Act, 2023 and Rule 5(9) of the Information Technology SPDI Rules, 2011:
Review our Master Terms of Service
Explore our catalog pricing transparency, 7-day replacement protocol, and brand warranty coverage.