DPDP Act 2023 · India

Privacy Policy

How brandsathi.in collects, uses, stores, and protects your Personal Data — compliant with the Digital Personal Data Protection Act, 2023. Your privacy is your right.

Version 4.0
Effective June 2026
Data Fiduciary Seekhobecho Enterprises
Jurisdiction Republic of India

Your data, your rights. brandsathi.in is operated by Seekhobecho Enterprises and is committed to protecting your privacy under the Digital Personal Data Protection Act, 2023. This Policy explains what data we collect, why, how we use it, who we share it with, how long we keep it, and how you can exercise your rights. By using the Platform, you confirm you have read and accepted this Policy.

1

About This Privacy Policy

brandsathi.in — operated by Seekhobecho Enterprises ("we," "us," "our," "Company") — respects your privacy and is committed to protecting your Personal Data. This Privacy Policy explains how we collect, use, store, share, and protect your data when you use our website and all associated services.

This Privacy Policy applies to:

  • The website at www.brandsathi.in and all subdomains;
  • All subscription plans: Silver, Gold, Titanium, Elite, Platinum, Platinum Plus, and Diamond;
  • All catalogues, ecommerce integrations and marketing tools provided through the Platform;
  • All communications between you and brandsathi.in.

By using the Platform, you confirm that you have read, understood, and consented to this Privacy Policy. If you do not agree, please do not use the Platform.

2

Legal Framework

This Privacy Policy is governed by and complies with the following laws and regulations applicable in India:

Law / RegulationApplication
Digital Personal Data Protection Act, 2023 (DPDP Act)Primary data protection law for Personal Data of Indian Data Principals
Information Technology Act, 2000 (as amended)Electronic records, digital signatures, intermediary liability
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021Grievance Officer designation, content takedown procedures
IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011Reasonable security practices for sensitive personal data
Consumer Protection (E-Commerce) Rules, 2020E-commerce transparency, grievance redressal
Bharatiya Nyaya Sanhita, 2023Penal provisions for data-related offences
Reserve Bank of India guidelines (where applicable)Payment data handling via authorised payment gateways
Primary Law — DPDP Act 2023

This Privacy Policy is principally governed by the Digital Personal Data Protection Act, 2023 — India's comprehensive data protection law. The DPDP Act establishes the rights of Data Principals (you), the obligations of Data Fiduciaries (us), and the framework for processing Personal Data within India.

3

Data Fiduciary & Roles

3.1.Data Fiduciary

For the purposes of the DPDP Act, 2023, Seekhobecho Enterprises is the Data Fiduciary responsible for the processing of your Personal Data on brandsathi.in.

DetailInformation
Legal EntitySeekhobecho Enterprises
GSTIN06LHJPK6374A1Z6
Registered Office27-28, Udyog Vihar Phase 4 Road, Church of The Epiphany, Gurugram, Haryana - 122001, India
Data Privacy Officer & Grievance OfficerVenjula — contactbrandsathi@gmail.com

3.2.You — the Data Principal

For the purposes of the DPDP Act, 2023, you are the Data Principal — the natural person whose Personal Data is processed by us.

3.3.Data Processors

We engage third-party Data Processors to provide infrastructure, payment processing, analytics, customer support, and marketing services. These processors handle your data only on our instructions and are bound by Data Processing Agreements.

4

Data We Collect

4.1.Categories of Personal Data

  • Identity Data: Full legal name, date of birth (18+ verification), gender, photograph (optional)
  • Contact Data: Mobile number (OTP-verified), email address, delivery address, alternate contact
  • KYC & Verification Data: Aadhaar (last 4 digits only), PAN (masked storage), GSTIN, IEC (for international plans), bank account (masked)
  • Transactional Data: Subscription payments, refund requests, GST invoices
  • Ecommerce & Selling Data: Product listings, marketplace orders (Amazon/Meesho/Flipkart), shipping data, returns, customer feedback
  • Device & Technical Data: Device model, OS version, IP address, advertising ID (if consented), crash logs, performance metrics
  • Behavioural & Usage Data: Website page views, click events, feature usage, session duration, site search queries
  • Communication Data: Support tickets, grievance submissions, chat with customer success, email correspondence
  • Marketing Preferences: Opt-in/opt-out status for promotional messages, WhatsApp updates, notifications

4.2.Sensitive Personal Data

We minimise the collection of Sensitive Personal Data. Where collected (e.g., for KYC), it is processed under explicit consent, stored with strong encryption, and retained only as long as legally required.

What We Do NOT Collect

Biometric data, health or medical records, sexual orientation, political affiliation, religious beliefs, caste/tribal/community data, genetic data, full Aadhaar numbers, unmasked bank account numbers, or children's data (the Platform is strictly 18+).

5

How We Collect Data

5.1.Direct Collection

You provide most data directly when you:

  • Sign up and create an account;
  • Complete KYC for your plan;
  • Make payments via the Platform;
  • List products, upload catalogues, or use selling tools;
  • Submit support tickets or grievances;

5.2.Automatic Collection

The Platform automatically captures the following through standard website technology:

  • Device identifiers (model, OS);
  • IP address and approximate geo-location (city/region level);
  • Website usage analytics and custom logging;
  • Crash and performance data;
  • Cookies and similar tracking on the website.

5.3.From Third Parties

We may receive Personal Data from:

  • Marketplace integrations (Amazon, Meesho, Flipkart) — your order data when you authorise the integration;
  • KYC verification services — Aadhaar/PAN verification status;
  • Referral sources.
6

Why We Process Data

6.1.Legal Bases for Processing (DPDP Act, 2023)

Under the DPDP Act, we process your Personal Data only on the following grounds:

Legal BasisApplication
ConsentMarketing communications, optional analytics, cookies (where consent required)
Contractual NecessitySubscription delivery, plan activation, payment processing, customer support
Legal ObligationGST compliance, TDS deduction, KYC requirements, regulatory reporting
Legitimate Use (DPDP §7)Fraud prevention, security monitoring, debt recovery, employer-employee processing (not applicable to users)
Court / Authority DirectionCompliance with valid legal orders from courts or regulators

6.2.Purposes of Processing

We process your data to:

  • Operate the Platform and deliver your subscription benefits;
  • Verify your identity (KYC) and process payments;
  • Integrate with marketplaces (Amazon, Meesho, Flipkart) and process orders;
  • Provide customer support and resolve grievances;
  • Send service notifications (renewal reminders, alerts, order updates);
  • Send marketing communications (only with your opt-in consent);
  • Improve the Platform via analytics and aggregated insights;
  • Detect and prevent fraud, abuse, and security threats;
  • Comply with applicable laws and respond to legal requests.
7

How We Use Your Data

7.1.Specific Use Cases

Below is a transparent map of how your data flows through the Platform:

Data CategoryUsed ForRetention Logic
Identity & ContactAccount creation, communicationActive account + 5 years for legal records
KYC documentsCompliance verification, regulatory filings10 years (Prevention of Money Laundering Act timeline)
TransactionalInvoicing, GST filing, refund/chargeback handling8 years (Income Tax Act)
Ecommerce & MarketplaceOrder fulfilment, returns, customer supportActive + 5 years
Device & TechnicalSecurity, debugging, abuse prevention180 days for raw logs; aggregated indefinitely
CommunicationSupport history, grievance trail3 years from ticket closure

7.2.We Never Sell Your Data

brandsathi.in does not sell, rent, or trade your Personal Data to any third party. We share data only as described in Section 8 — for operational, legal, or your explicitly consented purposes.

8

Sharing of Your Data

8.1.Categories of Recipients

We share your data only with:

Recipient CategorySpecific ExamplesPurpose
Payment Processors NPCI (for UPI)Process subscription payments,
Cloud InfrastructureAWS, Google Cloud, FirebaseHosting, app analytics, real-time data sync
Communication ToolsWhatsApp Business API, email service providers, SMS gatewaysOTPs, transactional alerts, opted-in marketing
Customer Support ToolsFreshdesk, HubSpot CRMSupport tickets, customer success outreach
Analytics & MonitoringFirebase, Looker Studio, BigQuery, Sentry, UptimeRobotWeb health, usage analytics, error monitoring
Marketplace PartnersAmazon, Meesho, Flipkart APIsWhere you authorise marketplace integration — order data flow
KYC VerificationAuthorised KYC service providers (Aadhaar/PAN verification)Identity verification for plan activation
Accounting & TaxZoho Books, Chartered Accountant (under NDA)GST filing, TDS compliance, financial audit
Legal & RegulatoryCourts, law enforcement, regulators — only on valid legal requestCompliance with applicable laws
Acquirers & SuccessorsIn the event of merger/acquisitionContinuity of services — subject to same data protection obligations
All Third Parties are Bound by DPAs

Every third-party processor of your data is bound by a Data Processing Agreement (DPA) requiring:

  • Processing only on our instructions and only for the specified purpose;
  • Implementing reasonable security measures including encryption;
  • Notifying us of any data breach within 24 hours;
  • Deleting or returning data within 30 days of contract end;
  • Audit and compliance verification rights for the Company.

8.2.No Sale, No Rental, No Trade

We do not sell, rent, lease, or trade your Personal Data to any third party for marketing or commercial purposes — including data brokers, advertising networks, or unrelated businesses.

11

Children's Data

brandsathi.in is strictly intended for users aged 18 years and above. We do not knowingly collect, process, or store Personal Data of children (any person under 18 years).

If we discover that an account has been created by or on behalf of a minor, we will:

  • Immediately suspend and terminate the account;
  • Delete all Personal Data of the minor (subject to legal retention requirements);

11.1.Reporting a Minor's Account

If you believe a minor has created an account on brandsathi.in, please report immediately to contactbrandsathi@gmail.com with details. We will investigate and take action within 48 hours.

11.2.DPDP Act Position

The DPDP Act, 2023 requires verifiable parental consent for processing children's data. Since brandsathi.in is an adult platform with explicit 18+ eligibility, we do not engage with children's data at all. This is a structural compliance choice, not an operational one.

12.1.Cookies on the Website

The website www.brandsathi.in uses cookies and similar technologies. We use the following cookie categories:

Cookie TypePurposeConsent
Strictly NecessarySession management, login, security, fraud preventionNo consent required — essential
FunctionalRemembering preferences (language, display)Implied consent on continued use
AnalyticsGoogle Analytics, Hotjar — usage patterns, performanceExplicit opt-in via cookie banner
Marketing / AdvertisingRetargeting (where applicable)Explicit opt-in only
13

Data Security

13.1.Security Measures

We implement reasonable security practices and procedures as required by Section 8 of the DPDP Act, 2023 and the IT Rules, 2011, including:

  • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256);
  • Access Control: Role-based access (RBAC) with quarterly reviews; Multi-Factor Authentication for all admin and production systems;
  • Network Security: Firewalls, intrusion detection, vulnerability scanning;
  • Website Security: Secure coding practices, code review, dependency scanning;
  • Monitoring: Real-time error monitoring (Sentry), uptime monitoring (UptimeRobot), payment fraud monitoring;
  • Vendor Security: All third-party processors bound by DPAs and security requirements;
  • Employee Training: Mandatory cybersecurity training; access only on need-to-know basis;
  • Incident Response: Documented breach response plan with 72-hour DPDP Act notification protocol.

13.2.User Responsibility

While we implement strong security on our side, you are responsible for:

  • Maintaining confidentiality of your login credentials and OTPs;
  • Not sharing your account access with others;
  • Reporting unauthorised access immediately to contactbrandsathi@gmail.com;
  • Using a secure network and device (not public Wi-Fi for sensitive transactions).

14.1.Retention Principle

We retain your Personal Data only as long as necessary for the purposes set out in this Policy or as required by applicable law. After the retention period, data is either deleted, anonymised, or archived per the matrix below:

Data CategoryActive SubscriptionPost-Closure RetentionLegal Basis
Identity & Contact (PII)Throughout subscription5 years post-closureGeneral record retention
KYC documents (Aadhaar/PAN/GSTIN/IEC)Throughout subscription10 years post-closurePMLA 2002, IT Act
Transactional & InvoicesThroughout subscription8 years post-closureIncome Tax Act §44AA / GST
Marketplace OrdersThroughout subscription5 years post-closureConsumer dispute resolution
Device/Technical Logs (raw)180 days rollingDeleted after 180 daysSecurity, debugging
Aggregated AnalyticsThroughout subscriptionRetained indefinitely (anonymised)Business intelligence
Support & Grievance TicketsThroughout subscription3 years from ticket closureCustomer service records
Marketing Consent StatusThroughout subscription3 years post-withdrawalDemonstration of compliance

14.2.Earlier Deletion on Request

Where you exercise the right to erasure (Section 15), we will delete data earlier than retention periods wherever legally permissible. Data we are legally required to retain (e.g., GST records, KYC under PMLA) cannot be deleted until the legal retention expires.

15

Your Rights Under DPDP Act

15.1.Your Five DPDP Rights

As a Data Principal under the DPDP Act, 2023, you have the following rights with respect to your Personal Data:

RightWhat You Can DoHow to Exercise
Right to Access (§11)Request a summary of what Personal Data we process about you and how it is usedEmail contactbrandsathi@gmail.com
Right to Correction (§12)Correct inaccurate or incomplete dataProfile settings in web OR email contactbrandsathi@gmail.com
Right to Erasure (§12)Request deletion of Personal Data (subject to legal retention)Email contactbrandsathi@gmail.com— see Section 14
Right to Grievance Redressal (§13)Raise a complaint about how we handle your dataEmail contactbrandsathi@gmail.com
Right to Nominate (§14)Nominate another individual to exercise your rights in case of death or incapacityEmail contactbrandsathi@gmail.com

15.2.Right to Withdraw Consent

Where processing is based on your consent (e.g., marketing communications), you may withdraw consent at any time. Withdrawal does not affect processing that is based on other legal grounds (contractual necessity, legal obligation).

To withdraw consent:

  • Marketing emails: click "Unsubscribe" in any marketing email;
  • WhatsApp updates: reply "STOP" to any marketing message;
  • Push notifications: disable in app settings;
  • All other: email contactbrandsathi@gmail.com.

15.3.Response Timelines

We will respond to your rights requests within:

  • Access requests: Within 30 days;
  • Correction requests: Within 7 business days;
  • Erasure requests: Within 30 days (subject to legal retention);
  • Grievances: Acknowledged within 48 hours, resolved within 30 business days.

15.4.Verification of Your Identity

To protect your data, we may require you to verify your identity before responding to a rights request. We will verify using the registered mobile number (OTP) and email on file.

15.5.Right to Approach Data Protection Board

If you are not satisfied with our response, you may approach the Data Protection Board of India (when constituted under the DPDP Act, 2023) with your grievance. Details will be published on the Board's official portal.

16

Cross-Border Transfers

16.1.Default — Data Stored in India

By default, your Personal Data is processed and stored on servers located within India. Our primary cloud infrastructure (AWS Mumbai region / Google Cloud Mumbai region) keeps data within Indian borders.

16.2.Limited Cross-Border Transfers

Some processing may require limited cross-border transfer where:

  • A specific service requires global infrastructure (e.g., WhatsApp Business API, certain analytics);
  • Marketplace integrations (Amazon.com USA for Platinum Plus plan) inherently involve international data flow;
  • You voluntarily use international features (cross-border ecommerce).

Such transfers occur only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and with appropriate contractual safeguards (DPAs, standard contractual clauses).

16.3.Your Consent for Transfers

Where required, we will obtain your explicit consent before any cross-border transfer of your Personal Data.

72-Hour Data Breach Notification — DPDP Act Compliance

In the event of a Personal Data breach, we will:

  • Notify the Data Protection Board of India within 72 hours of becoming aware of the breach, per Section 8(6) of the DPDP Act, 2023;
  • Notify affected Data Principals as soon as practicable, with information about:
  • Nature of the breach,
  • Categories and approximate number of affected users,
  • Likely consequences,
  • Measures we have taken and will take to mitigate.

17.1.Our Incident Response

Our Cybersecurity Policy CY-02 (Data Breach Response & Incident Management) governs internal incident response. Key elements:

  • Severity classification (P1/P2/P3/P4) within 1 hour of detection;
  • Containment within 2 hours for P1 incidents;
  • Post-Incident Report (PIR) within 14 days of resolution;
  • Records retained for 5 years from incident date.

17.2.Reporting a Suspected Breach

If you suspect your account has been compromised or that a Personal Data breach has occurred, please report immediately to:

contactbrandsathi@gmail.com and contactbrandsathi@gmail.com

18.1.Updates to This Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes in applicable law (DPDP rules, IT Act amendments);
  • New Platform features or processing activities;
  • New third-party processors or integrations;
  • Operational improvements in data handling.

18.2.Notification of Changes

Material changes will be communicated through:

  • Email to your registered address;
  • Banner on the website;
  • Minimum 7 days advance notice before changes take effect, where feasible.

18.3.Version Control

The version number and "Last Updated" date at the top of this document indicate the currently active version. Historical versions are archived and available on request at contactbrandsathi@gmail.com.

19

Grievance Officer & Contact

19.1.Grievance Officer — IT Rules 2021

In compliance with Rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Company has designated a Grievance Officer:

DetailInformation
NameVenjula
DesignationGrievance Officer, Seekhobecho Enterprises
Primary Emailcontactbrandsathi@gmail.com
Response CommitmentWithin 48 hours of receipt
Resolution Target30 business days
Working Hours9 AM – 7 PM IST, Monday to Saturday
Office Address27-28, Udyog Vihar Phase 4 Road, Church of The Epiphany, Gurugram, Haryana - 122001

19.2.Data Privacy Officer

For all DPDP Act 2023 related queries — including rights requests, data deletion, consent withdrawal, or breach reporting:

contactbrandsathi@gmail.com

Reach Us at the Right Channel

For any question, concern, or grievance related to your Personal Data and privacy:

19.3.Statutory Authorities

  • Data Protection Board of India — once operational under DPDP Act, 2023;
  • National Consumer Helpline: 1800-11-4000 (toll-free) | consumerhelpline.gov.in;
  • Cyber Crime Helpline: 1930 | cybercrime.gov.in (for cyber-related crimes only).