This Privacy Policy ("Policy") was updated on 01.04.2026 ("Effective Date").
Vardhman Appliances Limited, having our registered office at Plot No. 43, First Floor, Rajasthani Udyog Nagar, Adrash Nagar, North West Delhi, Delhi, India, 110033 (hereinafter referred to as "Vardhman", "Company", "we", "us", "our") is committed to respecting privacy and safeguarding the personal data of all individuals who interact with us, including customers, website visitors, dealers, distributors, vendors, employees, and all other stakeholders.
As a company engaged in the manufacture, marketing, distribution, and sale of consumer appliances, electronic products, and home solutions across India through its dealer/distributor network and e-commerce channels, the Company recognises the importance of transparency, informed consent, and robust data protection in building lasting trust with its customers and business partners.
The Company operates its e-commerce and informational website at https://vardhmanappliances.com/ (the "Website"), through which it collects and processes personal data for product sales, order fulfilment, customer support, dealer/distributor management, and related business activities.
The Company is committed to ensuring that all personal data is collected, stored, used, and shared in a secure, lawful, and fair manner. We believe in empowering our users with meaningful choices, data rights, and access to redressal mechanisms to protect their privacy interests.
This Privacy Policy has been designed in compliance with:
- The Digital Personal Data Protection Act, 2023 (DPDP Act/ "DPDPA");
- The Information Technology Act, 2000 (IT Act);
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules); and
- Applicable global privacy standards and industry best practices.
Vardhman Appliances Limited operates the website https://vardhmanappliances.com/ to sell, market, and distribute consumer appliances and electronic products, and is committed to protecting the personal data and privacy rights of its customers, dealers, distributors, and stakeholders in accordance with the highest standards of transparency, accountability, and ethical data governance.
The DPDP Act, the IT Act, and the SPDI Rules require data fiduciaries such as the Company to establish clear privacy practices, ensure security safeguards, and provide mechanisms for informed consent, user rights, and grievance redressal.
The Company acknowledges that personal data, including statutory documents such as Aadhaar Number, PAN, GSTIN/MSME details and certificates, and financial details, must be processed lawfully with consent or other valid legal basis, and handled in a manner that prevents misuse, loss, or unauthorised access.
The Company aims to foster user trust and ensure full legal compliance by establishing this comprehensive Privacy Policy, which informs all individuals interacting with the Company, whether as customers, dealers, distributors, vendors, service providers, or personnel, about their rights, the Company's obligations, and the mechanisms available for redressal and protection of their privacy.
Now therefore, Vardhman Appliances Limited hereby adopts this Privacy Policy to provide a clear, lawful, and user-centric framework for the collection, processing, storage, use, and protection of personal data, thereby reinforcing its commitment to privacy, compliance, and responsible data stewardship.
Definitions and Interpretation
In this Policy, except where the context otherwise requires, the following words and expressions shall bear the meaning assigned to them below:
- "Act" shall mean the Digital Personal Data Protection Act, 2023, including all applicable rules, notifications, and amendments relating to the collection, processing, storage, transfer, and protection of personal data in India, and shall include the Information Technology Act, 2000, and IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable.
- "Data Principal" shall mean the individual to whom the personal data relates, and includes any customer, dealer, distributor, website visitor, vendor, or individual whose personal data is processed by Vardhman Appliances Limited.
- "Data Fiduciary" shall mean Vardhman Appliances Limited, a public limited company registered under the Companies Act, 2013, which determines the purpose and means of processing personal data in its capacity as a data fiduciary under the Act.
- "Personal Data" shall mean any data about an individual who is identifiable by or in relation to such data, whether directly or indirectly, through reference to identifiers such as name, contact details, address, payment details, online identifiers, or any other characteristic or attribute of identity.
- "Sensitive Personal Data" shall mean personal data that relates to passwords, financial information such as bank account or payment instrument details, biometric data, health data, government-issued identification numbers (Aadhaar, PAN, GSTIN, MSME), and any other category of data notified as sensitive under applicable law.
- "Processing" shall mean any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- "Consent" shall mean any freely given, specific, informed, and unambiguous indication of the Data Principal's agreement to the processing of their personal data for the intended purpose, either through a clear affirmative action or through any other prescribed manner under applicable law.
- "Grievance Officer" shall mean the designated individual appointed by Vardhman Appliances Limited to address privacy-related grievances and ensure redressal in accordance with the timelines and procedures under the Act.
- "Third Parties" shall mean any external persons or entities, including service providers, payment gateways, logistics partners, contractors, consultants, technology vendors, and other business partners with whom personal data may be shared for business purposes, subject to appropriate safeguards.
- "Data Breach" shall mean any unauthorised or accidental disclosure, alteration, loss, access, or destruction of personal data that compromises its confidentiality, integrity, or availability.
- "Website" shall mean the online platform operated by the Company, currently accessible at https://vardhmanappliances.com/, including all sub-domains, web portals, and mobile applications operated by or on behalf of the Company.
- "User" shall mean any individual who accesses or uses the Website, registers as a customer, places an order, interacts with the services, downloads resources, or otherwise provides personal data to the Company.
- "Dealer/Distributor" shall mean any authorised dealer, distributor, retailer, or channel partner who is associated with the Company for the sale and distribution of its products and whose personal or business data may be collected and processed by the Company.
- "Nominee" shall mean a person appointed by a Data Principal under the Act to act on their behalf in the event of their death or incapacity.
- "Notice" shall mean a clear and accessible statement provided by the Company to the Data Principal, before collecting personal data, informing them of the purpose, method, legal basis, and rights in relation to such processing.
Interpretation: in addition to the terms defined above, certain terms may be defined elsewhere in this Policy, and wherever such terms are used, they shall have the meaning assigned to them. Section headings are for convenience only and shall not affect the construction or interpretation of any provision of this Policy. References to sections or annexures are, unless the context otherwise requires, references to sections or annexures of this Policy (if any). Where a word or phrase is defined, other parts of speech and the cognate variations of that word or phrase will have corresponding meanings. Words denoting singular shall include the plural and vice versa, and words denoting any gender shall include all genders unless the context otherwise requires. All references to this Policy shall include any amendments or updates to this Policy, as approved by the Data Protection Officer or the designated authority from time to time.
Purpose
This Policy applies to all Personal Data collected, received, processed, stored, disclosed, transferred, or otherwise handled by Vardhman Appliances Limited in the course of its operations through its website https://vardhmanappliances.com/, any associated mobile applications, communication platforms, or other digital interfaces owned, operated, or controlled by the Company (collectively, the "Platform"). This Policy governs the privacy practices of the Company in relation to:
- Individuals who visit, access, register on, or use the Platform, including without limitation customers, dealers, distributors, prospective buyers, and any person who browses the Platform, creates an account, places an order, or engages in any communication or transaction with the Company ("Users");
- All categories of Data Principals whose Personal Data is processed by the Company, including but not limited to registered Users, prospective customers, business partners, dealers, distributors, vendors, contractors, service providers, employees, consultants, and visitors who voluntarily provide their data;
- Personal Data collected through both online and offline channels (later converted digitally), including without limitation website contact forms, e-commerce checkout flows, email and phone customer service interactions, dealer/distributor onboarding processes, third-party vendor/partner channels, feedback forms, and business enquiries;
- Third parties acting on behalf of the Company (such as payment gateway providers, logistics partners, hosting partners, analytics providers, or marketing affiliates), to the extent that they process Personal Data under the Company's instructions and authority;
- Personal Data processed in India, subject to applicable local data protection laws. As of the effective date of this Policy, the Company does not transfer personal data internationally or cross-border.
This Policy shall apply regardless of the device, platform, or medium used to access the Company's services, including desktops, mobile phones, tablets, smart devices, and other digital channels.
This Policy does not apply to:
- Aggregated, anonymised, or de-identified information that does not, directly or indirectly, identify an individual;
- Third-party websites, platforms, or applications that may be linked from the Platform but are not owned, controlled, or operated by the Company. Users are encouraged to review the privacy policies of such third-party services independently;
- Data that is collected or processed for purely personal, household, or journalistic purposes by individuals and is exempted under the provisions of the Digital Personal Data Protection Act, 2023.
By accessing or using the Platform or otherwise providing Personal Data to the Company, the User expressly acknowledges and agrees to the terms of this Policy, and consents to the processing of their Personal Data in accordance with the terms stated herein.
In case of any conflict between this Policy and any contractual terms agreed between the Company and any Data Principal (such as dealers, distributors, vendors, or employees), the provisions offering higher privacy protection shall prevail, unless otherwise required by applicable law.
Categories of Personal Data Collected
In the course of providing its products, services, and operating its Platform, the Company may collect and process the following categories of Personal Data, either directly from the User or through third-party service providers acting on its behalf:
| Category | Examples of Data Collected | Purpose of Collection / Use |
|---|---|---|
| Identity Information | Name, date of birth, gender, photograph, user ID, government-issued identifiers (Aadhaar, PAN) where applicable | To register Users, verify identity, create and manage accounts, process KYC for dealers/distributors |
| Contact Information | Email address, mobile number, postal/delivery address | To communicate with Users, provide customer support, send service updates, facilitate order delivery |
| Payment & Financial Data | Bank account details, UPI IDs, payment card details, transaction records processed via RazorPay or bank transfer | To process payments, issue refunds, maintain financial records, fraud prevention |
| Order & Transaction Data | Order history, invoices, product details, shipping information, returns and exchange records | Order fulfilment, delivery tracking, customer service, product analytics and improvement |
| KYC & Statutory Documents | Aadhaar, PAN, GSTIN registration, MSME certificates, and other government-issued documents | Dealer/distributor onboarding, regulatory and legal compliance, identity verification |
| Account & Authentication Data | Login credentials, passwords, OTPs | To secure access to the Platform and ensure account integrity |
| Technical & Usage Data | IP address, browser type, device identifiers, operating system, cookies, crash reports, log files | To monitor performance, enhance Platform functionality, and prevent fraud |
| Marketing & Communication Preferences | Survey responses, feedback forms, marketing opt-ins, communication preferences | To send promotional offers, newsletters, and to improve services |
| Dealer/Distributor Business Data | Business name, trade licence details, GSTIN, territory allocation, sales performance data | Dealer/distributor onboarding, relationship management, business analytics |
| Customer Support Records | Complaint details, service request records, call logs, email correspondence | Complaint resolution, service improvement, quality assurance |
The above Personal Data may be collected at the time of account creation, while placing an order, during dealer/distributor onboarding, while subscribing to newsletters, interacting with the Platform or customer care, participating in surveys, or otherwise voluntarily provided by the User.
In addition to the above, the Company may collect certain Non-Personal Data (data that does not identify an individual directly or indirectly), which may include aggregated statistics, anonymised usage metrics, and analytics data, solely for internal research, service improvement, or marketing performance purposes.
The Company does not intentionally collect or process biometric data, health data, or location data, unless specifically required by law or consented to by the User for a legitimate purpose.
Purpose of Data Collection and Use
The Company collects and processes Personal Data only for specified, lawful, and legitimate purposes. Such processing is done either with the consent of the Data Principal or as reasonably necessary for the performance of a contract, compliance with legal obligations, or for purposes permissible under applicable law.
The Company processes Personal Data only for lawful and legitimate business purposes, in compliance with applicable data protection laws. The key purposes are outlined below:
| Purpose | Description of Use | Categories of Data Used |
|---|---|---|
| Order Fulfilment & Delivery | To process, confirm, ship, and deliver product orders placed on the Website or through dealer/distributor channels. | Identity Information, Contact Information, Payment & Financial Data, Order & Transaction Data |
| Payment Processing | To process payments through RazorPay, UPI, bank transfer, and other payment mechanisms, and to issue refunds and maintain transaction records. | Payment & Financial Data, Identity Information |
| Customer Service & Support | To respond to queries, resolve complaints, provide product support, handle returns and exchanges, and process warranty claims. | Contact Information, Order & Transaction Data, Customer Support Records |
| Marketing & Promotions | To send newsletters, promotional offers, product updates, and marketing communications via email, SMS, WhatsApp, push notifications, retargeting/display ads, and influencer/affiliate marketing, subject to User consent and opt-out rights. | Contact Information, Marketing Preferences |
| Product Analytics & Improvement | To analyse product performance, customer feedback, usage patterns, and market trends to improve product quality and service offerings. | Order & Transaction Data, Technical & Usage Data |
| Fraud Prevention & Security | To detect, prevent, and investigate suspicious activity, unauthorised access, or violations of Platform policies. | Technical & Usage Data, Identity Information, Payment Data |
| Legal & Regulatory Compliance | To comply with applicable legal requirements, tax obligations, regulatory filings, and to exercise or defend legal claims. | All relevant categories of Personal Data |
| Dealer/Distributor Onboarding & Management | To onboard, verify, and manage authorised dealers and distributors, including KYC verification, territory allocation, and performance tracking. | Identity Information, KYC & Statutory Documents, Dealer/Distributor Business Data |
The Company does not use Personal Data for any purpose other than those stated above without providing appropriate notice and, where applicable, obtaining specific and informed consent from the Data Principal.
Where consent is the legal basis for processing, the User may withdraw such consent at any time by contacting the Grievance Officer or using the mechanisms provided on the Platform. However, withdrawal of consent may affect the ability to deliver certain products or services.
The Company ensures that all processing of Personal Data is proportionate, limited to the extent necessary for the stated purposes, and in accordance with the principles of fairness, transparency, and accountability under applicable law.
The Company does not use automated decision-making or customer profiling in relation to Personal Data.
Legal Basis for Processing
The Company processes Personal Data only where there exists a lawful basis for such processing under the Digital Personal Data Protection Act, 2023, or other applicable laws. Each processing activity is mapped against at least one valid legal ground.
Performance of a Contract: the Company may process Personal Data where such processing is necessary to fulfil its obligations under a contract with the Data Principal or to take steps at their request before entering into a contract, for example: processing a product order placed by a customer on the Website; facilitating payment processing and order delivery; onboarding and managing dealer/distributor relationships; and providing customer service and technical support.
Compliance with Legal Obligations: the Company may process Personal Data where it is legally required to do so under applicable laws, court orders, or regulations, including requirements imposed by government or law enforcement agencies, for example: maintaining statutory records for tax and GST compliance; responding to lawful requests from regulators or law enforcement agencies; and retaining records for statutory audits or dispute resolution.
Legitimate Interests: the Company may process Personal Data where such processing is necessary for its legitimate business interests, provided such interests do not override the fundamental rights and expectations of the Data Principal.
| Legitimate Use Category | Illustrative Example |
|---|---|
| Voluntary Data Provided by User | Customer submits contact details for order placement or product enquiry |
| Provision of Service / Benefit | Delivering product warranties, after-sales service, or customer support |
| Legal Proceedings / Disputes | Defending legal claims or enforcing terms of use |
| Public Interest / Public Order | Co-operating with regulators in fraud, cybersecurity, or unlawful activity investigations |
| Employment / Internal Admin | Processing employee, consultant, or vendor data for HR and compliance purposes |
| Dealer/Distributor Management | Onboarding dealers, verifying KYC documents, managing trade relationships and sales performance |
Vital Interests: in exceptional circumstances, the Company may process Personal Data where it is necessary to protect the vital interests of the Data Principal or another individual, such as in emergencies or public health situations.
The Company maintains detailed internal records of the legal basis applicable to each processing activity, and such records are reviewed periodically to ensure compliance.
In cases where the legal basis for processing changes (e.g., from contract to consent), the Company shall notify the Data Principal and, where required, obtain fresh consent before proceeding.
Consent Management
Obtaining Consent: the Company shall obtain the free, specific, informed, unconditional, and unambiguous consent of the User (Data Principal) before collecting or processing any Personal Data, unless such processing is permitted under legitimate use or legal obligation in accordance with this Policy.
Points of Consent Collection: consent is obtained in a clear and granular manner at the point of data collection, such as during:
| Stage of Interaction | Examples of Data Collected | Consent Mechanism |
|---|---|---|
| Account Registration / Checkout | Name, email, phone number, delivery address, payment details | Explicit acceptance of Terms of Use & Privacy Policy at sign-up or checkout |
| Dealer/Distributor Onboarding | Business details, KYC documents (Aadhaar, PAN, GST), bank account details | Consent checkbox and declaration prior to onboarding form submission |
| Subscription to Updates | Marketing communications, newsletters, promotional offers | Explicit opt-in checkbox at the time of subscription |
| Contact Forms & Enquiries | Name, email, phone, query details | Notice displayed at the time of form submission with link to Privacy Policy |
| Cookies & Tracking | Browsing behaviour, usage metrics, preferences | Cookie banner with accept/reject/manage options |
| Customer Support Interactions | Contact information, complaint details, call/email logs | Notice provided prior to recording interactions |
No pre-ticked boxes, bundled consent, or inferred consent mechanisms are used. All consent is affirmative, granular, and documented.
Layered Notices: all consent requests are accompanied by a layered privacy notice that includes:
- The purpose of data collection;
- The categories of data collected;
- Whether the data will be shared with third parties;
- A link to this Privacy Policy;
- Contact details of the Grievance Officer.
These notices are drafted in clear, plain, and concise language to ensure that Users understand what they are agreeing to.
Proof and Record of Consent: the Company maintains verifiable records of the consent obtained from each Data Principal, including the time, method, and purpose for which consent was granted. These records are stored securely and may be made available to the Data Protection Board or other authorities in the event of a lawful request or audit.
Refusal or Conditional Consent:
- Users may refuse consent for optional features (such as newsletters or promotional updates) without affecting their access to the core services of the Platform (such as placing orders or creating an account).
- Consent is never tied to unrelated services or benefits, unless reasonably necessary for the operation of the Platform.
Withdrawal of Consent: the Data Principal may withdraw consent at any time, without any adverse consequences, by:
- Using the unsubscribe or opt-out links in emails or messages;
- Emailing the privacy contact / Grievance Officer;
- Changing settings in the self-service account settings on the Platform.
Upon withdrawal of consent:
- The Company shall cease processing the concerned Personal Data within a reasonable time, unless required to retain it under law;
- Certain services may become unavailable to the User where such services are dependent on the withdrawn data.
Consent for Minors:
- The Company does not knowingly collect Personal Data from individuals below the age of 18 years without verifiable parental or guardian consent as required under Section 9 of the DPDPA.
- If the Company becomes aware that Personal Data of a minor has been collected without lawful parental consent, such data shall be promptly deleted.
Cookies and Tracking Consent:
- The Company uses cookies and similar technologies for enhancing User experience, analytics, and targeted advertising.
- Consent for cookies is obtained through a cookie banner that allows Users to accept all cookies, manage preferences by category, or reject non-essential cookies.
Children's Data
The Company is committed to protecting the privacy of children and complying with the provisions of Section 9 of the Digital Personal Data Protection Act, 2023, which restricts the processing of personal data of children without verifiable parental or guardian consent.
- For the purposes of this Policy, a child is defined as an individual who has not completed the age of 18 years, unless a different age threshold is prescribed by applicable law.
- The Company does not knowingly collect, process, or store Personal Data from children unless verifiable parental or guardian consent has been obtained through acceptable means, such as a digitally signed declaration or validated OTP-based consent process.
- If it comes to the Company's attention that Personal Data of a child has been collected without lawful consent, the Company shall promptly delete such Personal Data from its systems and notify the parent or guardian, if identifiable, of such deletion.
- The Company does not engage in behavioural tracking, profiling, or targeted advertising towards children, directly or indirectly, in compliance with the prohibitions under Section 9 of the DPDPA.
Data Sharing and Third-Party Transfers
Internal Access and Sharing: Personal Data collected by the Company may be accessed only by authorised internal teams, including customer service executives, sales team, finance and accounts team, IT/system administrators, and marketing team. Such access is limited strictly on a need-to-know basis and governed by confidentiality undertakings, access control protocols, and principles of data minimisation.
Third-Party Disclosures: the Company may share Personal Data with carefully selected third-party service providers, contractual partners, and business associates ("Third Parties") solely to enable the delivery of products and services. These Third Parties act under the Company's instructions and are bound by contractual obligations to use the data only for authorised purposes, maintain confidentiality, and comply with applicable data protection laws.
Categories of Third Parties may include:
| Category of Third Party | Purpose of Sharing |
|---|---|
| Payment Gateway Providers (RazorPay, UPI/Bank Transfer) | To securely process customer payments, issue refunds, and maintain transaction records. |
| Logistics & Delivery Partners | To facilitate order delivery by sharing customer name, delivery address, and contact number. |
| Cloud Hosting & IT Infrastructure Providers | To securely host Platform data, enable uptime, and ensure disaster recovery on-premises, cloud (AWS/Azure/GCP), and hybrid infrastructure. |
| Marketing & Analytics Providers | To analyse website traffic, run targeted marketing campaigns via email, SMS, WhatsApp, push notifications, retargeting/display ads, and influencer/affiliate marketing. |
| Auditors, Legal Counsel, Tax Advisors | For statutory compliance, audit obligations, or legal disputes. |
| Regulatory or Government Authorities | To comply with applicable laws, court orders, or lawful government requests. |
| Dealer/Distributor Network Partners | To facilitate order processing, product distribution, and channel management. |
Cross-Border Transfers: as of the effective date of this Policy, the Company does not transfer Personal Data internationally or cross-border. All Personal Data is stored and processed on servers located within India. In the event that cross-border transfers become necessary in the future, such transfers shall be conducted in accordance with Section 16 of the Digital Personal Data Protection Act, 2023, and any applicable rules or government-issued notifications.
No Sale of Personal Data: the Company does not sell, rent, trade, or otherwise monetise Personal Data of its users or customers to any third party for direct commercial gain.
Aggregated and Anonymised Data: the Company may share anonymised or aggregated data (which does not identify an individual directly or indirectly) with business partners or research agencies for the purpose of market analysis, trend detection, or improving services. Such data is outside the scope of "Personal Data" as defined under applicable law.
Due Diligence and Oversight: the Company undertakes vendor due diligence and executes appropriate data processing agreements or confidentiality undertakings with all Third Parties who receive or process Personal Data, ensuring that:
- Data is processed only for legitimate and stated purposes;
- Adequate security measures are in place to prevent misuse or unauthorised access;
- Processing ceases upon completion of the contractual purpose or termination of engagement.
Data Retention and Storage
Retention Principle: the Company retains Personal Data only for as long as is reasonably necessary to:
- Fulfil the purpose for which it was collected (order fulfilment, customer support, dealer management);
- Comply with legal or regulatory obligations;
- Resolve disputes, enforce contracts, or defend legal claims;
- Maintain records for auditing, taxation, or business continuity purposes.
Data Retention Timelines:
| Category of Data | Typical Retention Period | Legal/Operational Basis |
|---|---|---|
| Customer Contact Information | 3 years from last order or interaction | Service continuity, statutory limitation for consumer claims |
| Payment & Transaction Data | As required under applicable tax and financial regulations (typically 7–8 years) | GST compliance, Income Tax Act, financial audit obligations |
| Order History & Invoices | 7–8 years from date of transaction | Tax and regulatory compliance, dispute resolution |
| Marketing Preferences / Opt-in Data | Until consent is withdrawn or inactivity beyond 2 years | Consent-based processing under DPDP |
| Customer Support Records | 3 years from last correspondence | Dispute resolution, compliance monitoring |
| Dealer/Distributor KYC & Business Data | Duration of relationship + 7 years | Regulatory compliance, contractual obligations |
| Cookie & Tracking Data | 12–18 months from collection | Service performance and analytics optimisation |
| Website Analytics & Usage Data (pseudonymised) | 12–18 months from collection | Service performance and optimisation |
| Dormant Accounts | 2 years of inactivity (with prior 30-day notice before deletion) | Data minimisation and compliance |
| Anonymised or Aggregated Data | Retained indefinitely (non-personal) | Outside DPDPA scope, industry research |
Note: the above periods are subject to change in case of any legal proceedings, enforcement actions, or statutory directions.
Deletion and Disposal: upon expiration of the applicable retention period, Personal Data is disposed of through the following methods:
- Physical destruction of records;
- Vendor-managed deletion for data stored with third-party providers;
- Immediate deletion upon manual review and action.
The Company ensures that deletion is performed in a secure manner using industry-standard sanitisation or erasure methods.
Right to Request Deletion: a Data Principal may request deletion of their Personal Data where the data is no longer necessary for the purpose for which it was collected, consent has been withdrawn and there is no other legal basis for retention, or the data has been unlawfully processed. Such requests will be honoured subject to legal and contractual retention obligations.
Storage Location: Personal Data is stored on secure infrastructure including on-premises servers, cloud platforms (AWS/Azure/GCP), hybrid infrastructure, and third-party data centres, all located within India. Periodic encrypted backups are maintained to ensure data recoverability in case of system failure.
Reasonable Security Practices
The Company is committed to ensuring the security, integrity, and confidentiality of the Personal Data it collects and processes. In line with Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Section 8(5) of the Digital Personal Data Protection Act, 2023, the Company implements appropriate technical, organisational, and administrative security measures to protect Personal Data against accidental loss, unauthorised access, destruction, misuse, alteration, or disclosure.
The Company adopts industry-standard safeguards including, but not limited to:
- Encryption of sensitive data during transmission (SSL/TLS protocols);
- Encryption of data at rest;
- Firewalls and intrusion detection systems for network monitoring;
- Role-based access control policies based on need-to-know principles;
- Secure APIs and encrypted payment gateways (RazorPay);
- Multi-factor authentication (MFA) for administrative and system access;
- Logging and monitoring of access to sensitive systems;
- Regular vulnerability assessments and penetration testing;
- Frequent security patching and system updates.
Personal Data is stored in secure servers hosted on reputable cloud platforms that are compliant with industry frameworks such as ISO/IEC 27001 and SOC 2, where applicable. All third-party service providers processing Personal Data on the Company's behalf are contractually bound to adhere to similar or higher levels of security and confidentiality.
Notification of Personal Data Breach
The Company adopts a proactive and structured approach to identifying, mitigating, and responding to any personal data breach. A personal data breach refers to any unauthorised or accidental disclosure, alteration, loss, destruction, or access to Personal Data that compromises its confidentiality, integrity, or availability — whether caused by technical failures, malicious attacks, human error, or organisational gaps.
Data Breach Response Procedure and Timelines: in the event of a suspected or confirmed data breach, the Company shall activate its internal Data Breach Response Procedure, which comprises the steps and timeframes as detailed below:
| Stage | Action | Timeline |
|---|---|---|
| 1. Detection & Containment | Identify and verify the breach, isolate affected systems | Within 6 hours of detection |
| 2. Preliminary Risk Assessment | Assess scope, type of data affected, sensitivity, and potential impact | Within 12 hours of detection |
| 3. Internal Escalation | Notify Data Protection Officer, Compliance Officer, and senior management | Within 12 hours |
| 4. Reporting to Authorities | Notify CERT-In and/or the Data Protection Board of India, where applicable | Within 6 hours of confirming the breach (as per CERT-In guidelines) |
| 5. Notification to Individuals | Inform affected Data Principals of the nature of the breach, risk, and mitigation steps | Within 48 hours, where the risk of harm is high |
| 6. Remedial Action | Contain breach, patch systems, reset credentials, and prevent recurrence | Immediate, completed within 72 hours |
| 7. Documentation & Audit Trail | Record breach details, investigation logs, and corrective measures taken | Within 7 days of the incident |
| 8. Final Report & Policy Update | Root cause analysis and review of internal policies/training | Within 15 days of breach |
The Company has established an internal escalation tree for data breach incidents, with defined timelines for notifying authorities and affected individuals.
Information Included in Notifications: any notification to the Data Protection Board of India, CERT-In, or affected individuals (Data Principals) shall include:
- Nature and categories of Personal Data affected;
- Number of individuals impacted;
- Date and time of the breach (estimated and confirmed);
- Likely consequences or harm;
- Actions taken to mitigate risks and limit damage;
- Contact information of the Grievance Officer or point of contact;
- Instructions for Users on how to protect themselves.
Breach Severity Categorisation: the Company classifies data breaches into three severity levels:
- Level 1 — Minor: no sensitive data involved, minimal or no risk;
- Level 2 — Moderate: involves contact or identity data, limited exposure;
- Level 3 — Critical: involves sensitive personal data, financial data, or a large number of individuals, with potential for significant harm.
Only Level 2 and Level 3 breaches require mandatory external notification.
User Cooperation: Users who become aware of any potential compromise of their account, such as unauthorised login attempts, phishing emails, or suspicious transactions, must report the same immediately to the Grievance Officer. The Company will investigate such reports on priority and take appropriate action.
Rights of Data Principals
As a Data Principal under the Digital Personal Data Protection Act, 2023, you are entitled to exercise the following rights in relation to your Personal Data collected and processed by the Company. These rights are subject to reasonable limitations and applicable legal requirements.
| Right | Description | How to Exercise |
|---|---|---|
| Right to Access / Portability | To know whether the Company processes your Personal Data and request details such as categories, purpose, recipients, and retention period; and to receive data in a structured, commonly used format. | Email the Grievance Officer or use your account dashboard (if available). |
| Right to Correction | To request correction, updating, or completion of inaccurate, outdated, or incomplete Personal Data. | Submit a correction request with valid supporting documents to the Grievance Officer. |
| Right to Erasure | To request deletion of Personal Data that is no longer necessary, has been unlawfully processed, or after consent withdrawal. | Send a deletion request via email to the Grievance Officer with identity verification. |
| Right to Restrict Processing | To request restriction of processing of your Personal Data in certain circumstances. | Email the Grievance Officer specifying the restriction requested. |
| Right to Object | To object to the processing of your Personal Data on grounds relating to your particular situation. | Email the Grievance Officer with details of the objection. |
| Right to Withdraw Consent | To withdraw previously given consent for specific data processing activities. | Use opt-out/unsubscribe links, self-service account settings, or email the Grievance Officer. |
| Right to Grievance Redressal | To file a complaint regarding delay, denial, misuse, or mishandling of Personal Data. | Email your grievance to the Grievance Officer. |
| Right to Nominate | To nominate another individual to exercise your rights under this Policy in the event of your death or incapacity. | Send a signed nomination form or declaration to the Grievance Officer. |
| Right to Be Informed | To receive clear, accessible information on data collection, legal basis, purpose, rights, third-party disclosures, and policy changes. | Review this Privacy Policy regularly and subscribe to update notifications. |
Grievance Redressal Mechanism
The Company is committed to addressing all privacy-related concerns, complaints, and requests in a transparent, secure, and time-bound manner. In accordance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the IT Rules, 2011, the Company has appointed a Grievance Officer / Data Protection Officer to ensure proper handling of grievances related to Personal Data.
Lodging a Grievance: if you have any concerns or grievances regarding:
- Denial or delay in fulfilling your data rights;
- Misuse, unauthorised access, or mishandling of your Personal Data;
- Withdrawal of consent not being respected;
- Violation of any terms of this Privacy Policy;
- Any breach of applicable data protection laws;
You may raise a grievance by sending an email to the designated Grievance Officer:
- Grievance OfficerDinesh Malik
- Emaildinesh.malik@lazerindia.com
- DesignationData Protection Officer, Vardhman Appliances Limited
- AddressPlot No. 43, First Floor, Rajasthani Udyog Nagar, Adrash Nagar, North West Delhi, Delhi, India, 110033
- Working DaysMonday to Saturday
Grievance Handling Procedure and Timelines:
| Stage | Action | Timeline |
|---|---|---|
| Acknowledgement | The Grievance Officer will acknowledge receipt of your complaint. | Within 48 hours |
| Initial Review | Assess completeness and legitimacy of the grievance. | Within 2 working days |
| Investigation and Resolution | Conduct internal inquiry, coordinate with relevant departments, resolve issue. | Within 7 working days |
| Notification of Outcome | Communicate resolution decision or status update to the complainant. | Within 10 working days total |
If you are dissatisfied with the resolution provided by the Grievance Officer or if no response is received within the prescribed period, you have the right to escalate the matter to the Data Protection Board of India under Section 13(2) of the Digital Personal Data Protection Act, 2023.
Force Majeure
The Company shall not be held liable for any failure or delay in performing its obligations under this Privacy Policy, including the processing of rights requests or breach notifications, due to circumstances beyond its reasonable control. Such events may include natural disasters, war, civil unrest, pandemic, governmental actions, electricity or internet outages, cyberattacks, or other force majeure events. During such periods, the Company will take reasonable steps to mitigate the impact and restore normal operations as soon as practicable.
Governing Law and Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Delhi, India, without regard to conflict of law principles.
Change in Ownership or Control
In the event of a merger, acquisition, reorganisation, or sale of all or a portion of the Company's assets or business, Personal Data held by the Company may be transferred to the successor entity. Such transfer will continue to be governed by the terms of this Privacy Policy unless and until it is amended by the successor with due notice to Users.
Policy Updates and Notification
The Company may update or modify this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or technological advancements. Any material changes will be notified to Users through:
- Prominent notices on the Platform;
- Email communication to registered Users (where applicable); and
- Updates to the "Last Updated" date at the top of this Policy.
Users are encouraged to periodically review this Policy to stay informed of how their Personal Data is protected.
Contact Us
If you have any questions, concerns, or require clarification regarding this Privacy Policy, the processing of your Personal Data, or your rights as a Data Principal, you may contact our designated:
- Grievance OfficerDinesh Malik
- Emaildinesh.malik@lazerindia.com
- EntityVardhman Appliances Limited
- AddressPlot No. 43, First Floor, Rajasthani Udyog Nagar, Adrash Nagar, North West Delhi, Delhi, India, 110033
- Working DaysMonday to Saturday
By continuing to access or use the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. Your continued use of the services constitutes your consent to the collection, processing, and disclosure of your Personal Data in accordance with this Policy.
This Privacy Policy is issued on behalf of Vardhman Appliances Limited and governs all personal data processing activities carried out through the Website https://vardhmanappliances.com/ and associated channels.
This Privacy Policy shall remain in effect until it is updated, superseded, or revoked by the Company.
