Fluidmate

Privacy Policy

 INTRODUCTION

The Company is committed to protecting the privacy and personal data of individuals who visit, access or interact with the Website, including customers, prospective customers, dealers, distributors, suppliers, business partners, job applicants and other visitors (“User”, “you” or “your”).

This Policy is intended to set out the Company’s privacy practices and, to the extent applicable and upon commencement of the relevant provisions, comply with the requirements of the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable data protection, information technology and privacy laws in India.

The DPDP Act establishes a framework for processing digital personal data while recognising the right of individuals to protect their personal data and the lawful purposes for which such data may be processed.

 

LEGAL AND REGULATORY FRAMEWORK

This Policy shall be interpreted with reference to applicable Indian laws and regulations concerning privacy and data protection, including, as applicable:

  1. Digital Personal Data Protection Act, 2023 (“DPDP Act”);
  2. Digital Personal Data Protection Rules, 2025 (“DPDP Rules”);
  3. Information Technology Act, 2000 (“IT Act”);
  4. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent applicable and in force;
  5. applicable rules, regulations, notifications, directions and governmental orders issued under the foregoing legislation; and
  6. any other applicable law governing privacy, confidentiality, cybersecurity or protection of personal information.

The DPDP Act and DPDP Rules contain a phased commencement mechanism. Accordingly, where a provision of the DPDP Act or DPDP Rules has not yet commenced, the Company shall comply with the legal framework applicable at the relevant time and shall progressively implement the requirements of the DPDP framework as and when they become operative.

 

DEFINITION

Personal Data

Means any data about an individual who is identifiable by or in relation to such data, to the extent recognised as personal data under applicable law.

 “Data Principal”

Means the individual to whom the personal data relates.

“Processing”

Includes an operation or set of operations performed on digital personal data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, sharing, transmission, restriction, erasure or destruction, as applicable under law.

“Consent”

Means any freely given, specific, informed and unambiguous indication of the Data Principal’s wishes by which the Data Principal signifies agreement to the processing of personal data for the specified purpose, wherever consent is the applicable legal basis.

 

PRINCIPLE OF DATA MINIMISATION

The Company shall endeavour to collect only such Personal Data as is:

(a) reasonably necessary for the specified purpose;
(b) relevant to the relevant business interaction; and
(c) permitted under applicable law.

The Company shall not intentionally collect excessive Personal Data through ordinary Website forms.

 

NOTICE AND TRANSPARENCY

The Company shall endeavour to provide appropriate notice to the Data Principal regarding:

  1. the Personal Data proposed to be collected;
  2. the purpose or purposes for which the Personal Data will be processed;
  3. the goods, services or functions enabled by such processing;
  4. the means through which the Data Principal may exercise applicable rights;
  5. the mechanism for withdrawal of consent, where applicable;
  6. the mechanism for raising grievances; and
  7. other information required under applicable law.

Upon commencement of the relevant provisions of the DPDP Rules, the Company shall ensure that notices are provided in the form and manner prescribed by the Rules.

The DPDP Rules, 2025 specifically contemplate a standalone and understandable notice containing an itemised description of Personal Data and the specified purpose or purposes of processing.

 

LAWFUL PROCESSING

The Company shall process Personal Data only for a lawful purpose.

Depending upon the circumstances, processing may be undertaken:

(a) with the consent of the Data Principal;
(b) pursuant to a lawful request or business interaction;
(c) for specified lawful uses recognised under applicable law;
(d) for compliance with a legal obligation;
(e) for prevention, detection or investigation of unlawful activity;
(f) for protection of the Company’s legal rights; or
(g) on any other lawful basis recognised under applicable law.

Nothing in this Policy shall be interpreted as permitting processing that is prohibited under applicable law.

 

CONSENT

Where consent is required, the Company shall seek consent in accordance with applicable law.

Consent shall, where applicable:

  • be freely given;
  • be specific;
  • be informed;
  • be unambiguous;
  • relate to a specified purpose;
  • be capable of being withdrawn; and
  • be obtained through an appropriate affirmative action.

The Company shall not make withdrawal of consent unnecessarily difficult in comparison with the process through which consent was given.

Where consent is withdrawn, the Company shall cease processing based on that consent, subject to any continued processing permitted or required by law.

Withdrawal shall not affect the legality of processing undertaken prior to withdrawal.

 

DISCLOSURE REQUIRED BY LAW

The Company may disclose Personal Data where such disclosure is:

  • required by law;
  • required pursuant to a court order;
  • required by a governmental or regulatory authority;
  • necessary for prevention, detection or investigation of an offence;
  • necessary to protect the Company’s legal rights;
  • necessary to protect the safety or security of persons or systems; or
  • otherwise permitted by applicable law.

 

PERSONAL DATA BREACH

A “Personal Data Breach” shall be understood in accordance with applicable law.

In the event of a Personal Data Breach, the Company shall take appropriate measures, which may include:

  • identifying and containing the breach;
  • assessing the nature and extent of the breach;
  • mitigating potential harm;
  • investigating the cause;
  • restoring affected systems;
  • implementing remedial measures;
  • maintaining appropriate records; and
  • notifying affected Data Principals and/or competent authorities where required by applicable law.

The Company shall comply with the applicable breach notification requirements and prescribed timelines under the DPDP Act and DPDP Rules once the relevant provisions become operative.

 

WHATSAPP AND THIRD-PARTY COMMUNICATION SERVICES

Where the Website provides a link to WhatsApp or another third-party platform, the use of such platform shall also be governed by the privacy policy and terms of the relevant platform.

The Company shall not be responsible for the independent processing of Personal Data by such third-party platforms.

Users should review the applicable privacy terms of those platforms before using them.

 

INTERNATIONAL DATA TRANSFERS

Personal Data may be processed or stored outside India where necessary for the operation of the Website or engagement of service providers.

The Company shall comply with applicable restrictions concerning transfer of Personal Data outside India.

In particular, where Section 16 of the DPDP Act becomes applicable, the Company shall comply with any restrictions notified by the Central Government concerning transfer of Personal Data to specified countries or territories.

Nothing in this Policy shall override any law providing a higher degree of protection or imposing additional restrictions.

 

GOVERNMENT AND LAW-ENFORCEMENT REQUESTS

The Company may cooperate with competent governmental, regulatory, law-enforcement, judicial or other authorised authorities where legally required.

Where permitted by law, the Company may disclose information necessary to:

  • comply with lawful orders;
  • investigate offences;
  • prevent fraud;
  • protect national security;
  • protect the rights and property of the Company;
  • protect Users or third parties; or
  • comply with regulatory obligations.

 

CONFIDENTIAL BUSINESS INFORMATION

Users are requested not to submit confidential technical information, trade secrets, proprietary formulations, confidential commercial information or other sensitive business information through publicly accessible Website forms unless specifically requested or otherwise protected by an applicable confidentiality agreement.

The submission of information through a Website form does not automatically create a contractual confidentiality obligation.

 

THIRD-PARTY WEBSITES

The Website may contain links to third-party websites.

Such websites operate independently from the Company and may have their own privacy policies and terms.

The Company does not assume responsibility for the privacy practices, security or content of third-party websites.

 

GOVERNING LAW

This Policy shall be governed by and construed in accordance with the laws of India.

Nothing in this Policy shall limit, exclude or contractually waive any mandatory statutory right available to a Data Principal under applicable data protection law.

 

JURISDICTION

Subject to mandatory provisions of applicable law, disputes concerning this Policy or the processing of Personal Data by the Company shall be subject to the jurisdiction of the competent courts having jurisdiction over the Company’s registered office.

Nothing contained herein shall prevent a Data Principal from approaching any statutory authority, regulatory body, tribunal or other forum having jurisdiction under applicable law.

 

SEVERABILITY

If any provision of this Policy is determined to be invalid, unlawful or unenforceable, such provision shall, to the extent legally permissible, be severed or modified without affecting the validity of the remaining provisions.

 

NO WAIVER

Failure by the Company to exercise any right or remedy under this Policy shall not constitute a waiver of such right or remedy.