Legal

Privacy Policy

Effective Date: 1 January 2026  ·  Last Updated: 15 May 2026

This Privacy Policy describes how Pandonix Technologies Pvt Ltd ("Pandonix", "we", "us", or "our") collects, uses, and protects your personal data when you use our website (pandonix.com) and services, in compliance with India's Digital Personal Data Protection Act, 2023.

1. Information We Collect

When you browse pandonix.com, make a purchase, submit an enquiry, or register an account, we may collect the following information: • Personal Identifiers: Full name, email address, mobile number, and billing/shipping address. • Device & Usage Data: IP address, browser type, operating system, pages visited, and session duration via cookies and analytics tools. • Transaction Data: Order details, payment method type (we do not store full card numbers), and GST details if provided. • Communication Data: Messages, enquiries, and support tickets you send us. We do not collect sensitive personal data (such as Aadhaar number, PAN, or health information) unless explicitly required and consented to.

2. How We Use Your Information

Your data is used strictly for the following purposes: • Processing and fulfilling orders, including generating GST-compliant invoices. • Communicating order updates, shipping notifications, and support responses. • Personalising your experience and displaying relevant products. • Sending promotional communications — only where you have opted in. • Improving our website, products, and services through aggregated analytics. • Complying with legal obligations under Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act).

3. Legal Basis for Processing (DPDP Act 2023)

Under India's Digital Personal Data Protection Act, 2023, we process your personal data based on: • Consent: For marketing communications and personalised advertising. You may withdraw consent at any time. • Contractual Necessity: For processing orders and fulfilling the product/service contract you entered into with us. • Legitimate Interests: For fraud prevention, security, and improving our services. • Legal Obligation: Where required by Indian law, including GST compliance and court orders.

4. Data Sharing & Third Parties

We do not sell your personal data. We may share it only with: • Payment Processors: Razorpay and other RBI-licensed payment gateways, solely to process transactions. • Logistics Partners: BlueDart, Delhivery, and similar carriers — only your name, address, and mobile number for delivery. • IT Service Providers: Cloud hosting, CRM, and analytics tools operating under strict data processing agreements. • Legal Authorities: When required by a court order or government authority under applicable Indian law. All third parties are bound by confidentiality obligations and are prohibited from using your data for their own purposes.

5. Cookies & Tracking Technologies

Pandonix.com uses the following types of cookies: • Strictly Necessary Cookies: Required for core site functionality such as cart management and login sessions. • Analytics Cookies: Google Analytics 4 (anonymised IP) to understand site usage patterns. • Marketing Cookies: Used only if you have opted in to personalised advertising. You can manage cookie preferences via your browser settings. Note that disabling strictly necessary cookies may affect site functionality.

6. Data Storage & Security

All data is stored on servers located in India, in compliance with data localisation norms. We use industry-standard security measures including: • TLS 1.3 encryption for all data in transit. • AES-256 encryption for data at rest. • Regular security audits and penetration testing. • Role-based access controls limiting employee data access to need-to-know basis. While we take all reasonable precautions, no internet transmission is 100% secure. Please use strong passwords and do not share account credentials.

7. Data Retention

We retain your personal data only as long as necessary: • Order & Transaction Data: 7 years, as required under the GST Act. • Account Data: Until you close your account, plus 1 year for audit purposes. • Marketing Consent Records: 3 years from the date of consent. • Support Communications: 2 years. After the retention period, data is securely deleted or anonymised.

8. Your Rights Under the DPDP Act 2023

As a data principal under India's DPDP Act, you have the right to: • Access: Request a summary of the personal data we hold about you. • Correction: Request correction of inaccurate or incomplete data. • Erasure: Request deletion of your personal data where there is no overriding legal obligation to retain it. • Withdraw Consent: Withdraw marketing consent at any time without affecting past processing. • Grievance Redressal: Lodge a complaint with our Data Protection Officer or the Data Protection Board of India. To exercise any of these rights, email privacy@pandonix.com with your registered email address and request.

9. Children's Privacy

Our services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted data to us, please contact privacy@pandonix.com immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in law, business practices, or data handling. Material changes will be notified via email to registered users and a notice on our website for 30 days prior to taking effect. Continued use of our services after the effective date constitutes acceptance of the revised policy.

11. Contact & Grievance Redressal

Data Protection Officer Pandonix Technologies Pvt Ltd Bengaluru, Karnataka, India — 560001 Email: privacy@pandonix.com Phone: +91 (800) PANDONIX Response time: Within 72 hours If you are unsatisfied with our response, you may approach the Data Protection Board of India at the contact details published on their official portal.