AVITAMO SOLUTIONS PRIVATE LIMITED ("Avitamo", "we", "us", or "our") operates the website avitamo.in and is committed to protecting the privacy and personal data of our users ("you", "your"). This Privacy Policy explains how we collect, use, store, share, and protect your information when you visit or make a purchase from our website.
This policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection (DPDP) Act, 2023, as applicable.
1. Information We Collect
1.1 Information You Provide Directly
When you place an order, create an account, contact us, or otherwise interact with our website, we may collect the following personal data:
- Full name
- Email address
- Phone number
- Shipping and billing address (including PIN code, city, and state)
- Order details and transaction history
- Messages or inquiries submitted through our Contact Us form
1.2 Information Collected Automatically
When you browse our website, we may automatically collect certain technical information, including:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited, time spent on pages, and navigation paths
- Referring website URL
- Cookies and similar tracking technologies (see Section 6)
1.3 Payment Information
We do not collect, store, or process credit card, debit card, or UPI PIN details on our servers. All payment transactions are processed securely through our third-party payment gateway partner (MMADPay) in compliance with RBI Tokenisation Guidelines. We may store the transaction reference number, payment status, and payment method type solely for order tracking and reconciliation purposes.
2. Purpose of Data Collection
We collect and process your personal data for the following lawful purposes:
- To process and fulfil your orders, including delivery and payment processing
- To send order confirmation, shipping updates, and delivery notifications via email
- To respond to your inquiries and provide customer support
- To verify your identity and prevent fraud
- To comply with applicable laws and regulatory requirements
- To improve our website, products, and services based on usage analytics
- To send promotional communications (only with your explicit consent, and with an option to opt out)
3. Legal Basis for Processing (DPDP Act Compliance)
Under the Digital Personal Data Protection Act, 2023, we process your personal data based on the following grounds:
- Consent: Where you voluntarily provide your data by placing an order, filling a contact form, or subscribing to communications. You may withdraw your consent at any time by contacting us.
- Legitimate Use: Where processing is necessary for performing a contract (e.g., fulfilling your order), complying with a legal obligation, or responding to a medical emergency.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties. We may share your data only in the following circumstances:
- Service Providers: We share necessary information with logistics and courier partners for order delivery, and with payment gateway providers for transaction processing.
- Legal Obligations: We may disclose your data if required to do so by law, regulation, court order, or government authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the business transaction, with prior notice.
All third-party service providers engaged by us are bound by confidentiality obligations and are required to process your data only for the purposes specified by us.
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Order Data: Retained for a period of 8 (eight) years from the date of the transaction for accounting, tax, and legal compliance purposes.
- Contact Inquiries: Retained for up to 1 (one) year from the date of the query resolution.
- Website Analytics Data: Aggregated and anonymised analytics data may be retained indefinitely.
Upon expiry of the retention period, or upon a valid erasure request, your personal data will be securely deleted or anonymised.
6. Cookies and Tracking Technologies
Our website uses cookies and similar technologies for the following purposes:
- Essential Cookies: Required for the website to function properly (e.g., shopping cart, session management).
- Analytics Cookies: We use Google Analytics (GA4, Measurement ID: G-09S9LG4TS3) to understand how visitors interact with our website. Google Analytics collects data in an aggregated and anonymised manner.
You can manage or disable cookies through your browser settings. Disabling essential cookies may impact website functionality, including the ability to add items to your cart or complete a purchase.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction, including:
- SSL/TLS encryption for all data transmitted between your browser and our servers
- Secure payment processing through PCI-DSS compliant payment gateway partners
- Access controls to restrict data access to authorised personnel only
- Regular security reviews and vulnerability assessments
While we take commercially reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
8. Your Rights
Under applicable Indian data protection laws including the DPDP Act, 2023, you have the following rights:
- Right to Access: You may request a summary of your personal data held by us and the processing activities related to it.
- Right to Correction: You may request correction of any inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal.
- Right to Nominate: You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, as permitted under the DPDP Act.
- Right to Grievance Redressal: You have the right to file a complaint with our Grievance Officer or with the Data Protection Board of India.
To exercise any of the above rights, please contact our Grievance Officer using the details provided below.
9. Children's Privacy
Our website is not intended for use by individuals under the age of 18 years. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor without verifiable parental consent, we will take steps to delete such data promptly.
10. Third-Party Links
Our website may contain links to external websites that are not operated by us. We are not responsible for the privacy practices or content of these third-party websites. We encourage you to review the privacy policies of any external site you visit.
11. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. Any material changes will be communicated by posting the updated policy on this page with a revised "Last Updated" date. Your continued use of the website after any changes constitutes acceptance of the updated policy.
12. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising under or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of Bengaluru, Karnataka, India.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:
Registered Address: 4th Floor, 133/2, Janardhan Towers, Residency Road, Richmond Town, Bengaluru, Karnataka – 560025
Business Email: info@avitamo.in
Grievance Officer: Mangala Narasimhulu
Phone: +91 95023 70743
Email: grievance@avitamo.in
Response Time: We shall acknowledge your query within 48 hours and resolve it within 30 days from the date of receipt.