Daril Lighting Pvt Ltd (referred to as "the Company," "we," "us," or "our") operates the www.darillighting.com (the “Website”) and is committed to protecting the privacy of its users. This Privacy Policy outlines our procedures for collecting, using, disclosing, and protecting the Digital Personal Data (DPD) and Sensitive Personal Data or Information (SPDI) you provide.

Last Updated: [20-11-2025]

Effective Date: [20-11-2025]

1. Legal Framework and Consent

This Privacy Policy is published in compliance with:

  • The Information Technology Act, 2000.
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
  • The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its accompanying rules, as they become operational.

1.1 Consent: By using our Website, placing an order, or providing your information, you provide your free, specific, informed, unconditional, and unambiguous consent to the collection, storage, processing, and transfer of your personal data as described in this Policy.

2. Information Collected

We collect both Personal Data and Sensitive Personal Data or Information (SPDI), defined under the IT Act and DPDP Act, when you interact with us.

2.1 Personal Data (PD)

Data categories and purposes
Category Data Elements Collected Purpose
Identity & Contact Name, Email Address, Mobile Number, Gender Account creation, communication, marketing, and customer service
Shipping & Location Delivery Address, Billing Address, Pincode, City Order fulfillment, logistics, and delivery
Transaction & Usage Products purchased, order history, returns/cancellations, product reviews Transaction records, compliance, and product improvement
Website Usage IP address, browser type, device ID, operating system, and pages viewed Site optimization, analytics, and security

2.2 Sensitive Personal Data or Information (SPDI)

We may collect the following SPDI:

  • Financial Information: Bank account details, credit/debit card details, or other payment instrument details.
  • Note: This data is generally processed by a PCI-DSS compliant payment gateway and is not stored on our servers.

3. Purpose of Processing (Purpose Limitation)

We will only collect and process your Personal Data for the following specified, lawful purposes (in compliance with Section 6 of the DPDP Act):

  • To Fulfill Your Orders: Processing payments, shipping, delivery, and providing order updates.
  • To Provide Services: Managing your account, responding to inquiries, and handling returns or warranty claims.
  • For Marketing: Sending promotional information, newsletters, and offers (you can opt-out at any time).
  • To Improve Our Website: Analyzing user behaviour to optimize site function, product catalogue, and user experience.
  • For Legal Compliance: Detecting and preventing identity theft, fraud, and other illegal acts; complying with court orders and regulatory requests.

4. Disclosure and Sharing of Data

Your Personal Data is a crucial part of our business and we will not sell, rent, or trade your data to third parties for commercial gain. Disclosure is strictly limited to the following:

Recipient Purpose of Disclosure
Service Providers Courier and logistics partners, payment processors, cloud storage providers, and IT support services.
Group Companies Sharing with our affiliates/subsidiaries for internal administration and data analysis, subject to confidentiality agreements.
Legal Authorities Disclosing information where required by law, court order, or when necessary to protect our rights, property, or safety, or that of our users.

Prior Permission: We will obtain your prior written consent before disclosing your SPDI to any third party, unless mandated by law.

5. Your Rights as a Data Principal

Under the DPDP Act, you, as the Data Principal, have the following rights:

  • Right to Information: The right to request a summary of the Personal Data being processed and the processing activities.
  • Right to Correction & Erasure: The right to seek correction of inaccurate or misleading Personal Data, and to seek the erasure of Personal Data when it is no longer necessary for the specified purpose.
  • Right of Access: The right to access your Personal Data held by us.
  • Right to Withdraw Consent: The right to withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.

6. Data Security and Retention

6.1 Security Measures

We implement Reasonable Security Practices and Procedures as per the SPDI Rules and the DPDP Act to protect your data from unauthorized access, loss, misuse, or alteration. These measures include:

  • Encryption (SSL): Securing data transmission with standard encryption technology.
  • Access Control: Restricting access to Personal Data to authorized employees, contractors, and agents only.
  • Regular Audits: Performing periodic security and data protection compliance audits.

6.2 Data Retention and Erasure (Storage Limitation)

We will retain your Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law.

Inactivity Rule (DPDP Act): If you remain inactive on our Website for a period of [e.g., three consecutive years] (or the period specified under the DPDP Rules), we will provide you with a 48-hour advance notice before deleting your Personal Data from our systems.

7. Grievance Redressal Mechanism

In compliance with the DPDP Act and the IT Rules, we have appointed a Grievance Officer to address your queries or complaints regarding the processing of your Personal Data.

Grievance Officer:

  • Name: Yogesh patel
  • Designation: [Grievance Officer Designation]
  • Email: info@darillighting.com
  • Address: 1,2,3 abhishek complex,Akshar chowk,old padra road,Vadodara-390020

We are obligated to acknowledge receipt of your complaint and endeavour to resolve it within 30 days from the date of receipt.

8. Policy Updates

We reserve the right to change or update this Policy at any time. Any changes will be effective immediately upon being posted on the Website. We will also notify you of material changes via email or a prominent notice on the Website.

Please contact our Grievance Officer if you have any questions or wish to exercise your data rights.