← CableConnect

Privacy Policy

Effective Date: [Effective Date] | Version 1.0 (Draft) | Prepared for DPDP Act 2023 alignment

Notofire Pvt Ltd ("we", "us", "our") operates CableConnect, a B2B marketplace platform (the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights available to you under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian law.

This is a draft prepared for internal review and must be finalised with qualified legal counsel before publication.

1. Data We Collect

1.1 Information you provide

  • Account details: name, email, mobile number, password/OTP verification data, and profile information.
  • Business & KYC data: GST certificate, PAN, business address(es), plant/warehouse locations, and related verification documents.
  • Transaction data: listings, inquiries, RFQs, quotes, orders, bids, payment and invoicing details.
  • Communications: chat messages, comments, reviews, support tickets, and content you post to the community feed.
  • Job & course data: resumes, applications, course enrolment and completion records.

1.2 Information collected automatically

  • Device and usage data: IP address, device identifiers, browser type, pages visited, and feature usage (for the usage-metering engine).
  • Location data: where you enable location features (e.g., supplier/factory map view).
  • Cookies and similar technologies used for session management and analytics.

1.3 Information from third parties

  • OAuth profile data from Google or LinkedIn when you sign up via SSO.
  • Payment confirmation data from our payment processor (Razorpay).
  • Test results from onboarded third-party testing agencies, where you request testing.

2. Purpose of Processing

We process personal data for the following purposes, each mapped to a lawful basis under the DPDP Act (consent, or a permitted legitimate use such as contract performance):

  • Account creation, authentication, and multi-device session management.
  • KYC verification and issuance of verification badges.
  • Facilitating inquiries, RFQs, quotes, transactions, auctions, and payments between users.
  • Sending transactional notifications via WhatsApp, SMS, email, and in-app alerts (inquiry updates, KYC status, payment confirmations, price alerts, etc.).
  • Operating the community feed, job board, courses, and consultation booking.
  • Fraud prevention, dispute resolution, and platform moderation.
  • Billing, GST-compliant invoicing, and statutory tax reporting.
  • Analytics to improve search relevance, feed ranking, and platform performance.
  • Compliance with legal obligations, including responding to lawful requests from authorities.

3. Consent

  • Where processing relies on consent, we present a consent dashboard listing each data category, its purpose, and its retention period before collection begins.
  • Consent is logged with a timestamp and is auditable; you may withdraw consent at any time through your account settings, subject to the effect withdrawal may have on features that depend on that data.
  • Granting consent for a given purpose is required before we begin the related data collection for that purpose.

4. Data Sharing & Disclosure

  • With counterparties: certain profile and transaction details (e.g., business name, verification badge, quote details) are shared with the other party to a transaction as necessary to complete it.
  • With service providers: payment processing (Razorpay), messaging delivery (WhatsApp Business API / Twilio SMS), e-signature (Leegality/Digio), cloud hosting, and analytics providers, each bound by contractual confidentiality and data-processing obligations.
  • With testing agencies: only the data necessary to fulfil a testing request you initiate.
  • With lead-generation package purchasers: verified buyer contact details are released to paid sellers only through the Platform's lead-gen mechanism and, where required, subject to applicable consent.
  • With authorities: where required by law, regulation, or valid legal process.
  • We do not sell personal data to third parties.

5. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Policy, including the duration of your account's active status, applicable statutory retention periods (e.g., for GST and financial records), and any period necessary to resolve disputes or legal claims. Specific retention periods per data category are set out in the in-app consent dashboard.

6. Your Rights Under the DPDP Act

  • Right to access a summary of the personal data we hold about you and the processing activities performed on it.
  • Right to correction and completion of inaccurate or incomplete personal data.
  • Right to erasure of personal data, subject to legal retention requirements and any active or disputed transactions.
  • Right to withdraw consent at any time, as easily as it was given.
  • Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Right to grievance redressal through our Grievance Officer (Section 9).

Deletion requests are actioned within a 30-day SLA, visible to you as a countdown. If an active or disputed transaction exists on your account, deletion of related records may be deferred until it is resolved, and you will be notified of the reason.

7. Data Security

  • Documents (KYC, contracts, test reports) are stored using access-controlled, encrypted storage.
  • Payment data is handled by our PCI-compliant payment processor; we do not store full card details.
  • Access to personal data within Notofire Pvt Ltd is role-restricted (e.g., KYC team, finance, moderation) and logged.
  • While we take reasonable technical and organisational measures to protect personal data, no system is completely secure, and we encourage users to safeguard their own account credentials.

8. Children's Data

The Platform is intended for business users aged 18 and above and is not directed at children. We do not knowingly collect personal data from individuals under 18.

9. Grievance Officer

In accordance with the DPDP Act, we have designated a Grievance Officer to address privacy-related concerns and requests:

  • Name: [Grievance Officer Name]
  • Email: [grievance officer email]
  • Address: [Registered Office Address]

The Grievance Officer's contact details are also published on a publicly accessible page linked from the in-app consent portal, as required under the DPDP Act.

10. Cross-Border Data Transfer

Where personal data is processed or stored outside India (e.g., by cloud infrastructure or service providers), such transfers are made in accordance with the DPDP Act and other applicable data protection requirements in force at the time.

11. Cookies & Tracking

We use cookies and similar technologies for authentication, session persistence, and usage analytics. You can control cookie preferences through your browser settings; disabling certain cookies may limit Platform functionality.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Platform, and where required, fresh consent will be sought. The "Effective Date" above reflects the latest revision.

13. Contact Us

For any questions about this Privacy Policy or our data practices, contact us at [privacy email] or through the in-app support channel.