PRIVACY POLICY

Effective Date: October 15, 2023 | Last Updated: October 15, 2023

1. DEFINITIONS AND INTERPRETATION

Key Definitions

Personal Data: Any information relating to an identified or identifiable natural person.

Processing: Any operation performed on Personal Data, whether or not by automated means.

Data Subject: An individual who is the subject of Personal Data.

Controller: The entity that determines the purposes and means of processing Personal Data.

Processor: An entity that processes Personal Data on behalf of the Controller.

1.1 Scope and Application

This Privacy Policy applies to all Personal Data processed by Cheap o Deal through our website (www.cheapodeal.co.in), mobile applications, and related services (collectively, "Services").

1.2 Compliance Framework

We comply with applicable data protection laws, including but not limited to:

  • The Information Technology Act, 2000 and its corresponding rules
  • General Data Protection Regulation (GDPR) for EU data subjects
  • California Consumer Privacy Act (CCPA) for California residents
  • Other applicable data protection regulations

2. INFORMATION COLLECTION AND CATEGORIZATION

2.1 Personal Data We Collect

We collect several categories of Personal Data, which include:

Data Category Examples Collection Method
Identity Data Full name, username, government ID Registration forms, verification processes
Contact Data Email address, phone number, physical address Contact forms, account registration
Financial Data Payment card details, billing information Payment processing, invoice generation
Technical Data IP address, browser type, device information Automated collection, cookies
Usage Data Website interaction, service usage patterns Analytics tools, server logs
Marketing Data Communication preferences, marketing responses Consent forms, preference centers

2.2 Special Categories of Data

We do not intentionally collect Special Categories of Personal Data (such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data). If we inadvertently collect such data, we will delete it immediately.

4. USE OF PERSONAL INFORMATION

4.1 Purposes of Processing

We use your Personal Data for the following business purposes:

Purpose Data Categories Used Legal Basis
Service provision and account management Identity, Contact, Technical Contract, Legitimate Interests
Payment processing and billing Identity, Contact, Financial Contract, Legal Obligation
Customer support and communication Identity, Contact, Technical Contract, Legitimate Interests
Marketing and promotional communications Contact, Marketing, Usage Consent, Legitimate Interests
Security and fraud prevention Technical, Identity, Usage Legitimate Interests, Legal Obligation
Legal compliance and regulatory requirements All categories as required Legal Obligation

4.2 Marketing Communications

We will only send you marketing communications if you have explicitly consented or where we have a legitimate interest. You can opt-out at any time using the unsubscribe link in our emails or by contacting us directly.

5. DATA SHARING AND DISCLOSURE

5.1 Categories of Recipients

We may share your Personal Data with the following categories of recipients:

5.1.1 Service Providers

Third-party vendors who provide services on our behalf, including:

  • Payment processors (Stripe, PayPal)
  • Cloud hosting providers (AWS, Google Cloud)
  • Customer support platforms
  • Marketing and analytics services
  • IT maintenance and security services

5.1.2 Professional Advisors

Legal, accounting, and other professional advisors bound by confidentiality obligations.

5.1.3 Legal and Regulatory Authorities

When required by law, court order, or governmental regulations.

5.2 Business Transfers

In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business, your Personal Data may be transferred to the acquiring entity.

6. INTERNATIONAL DATA TRANSFERS

6.1 Transfer Mechanisms

Your Personal Data may be transferred to, and processed in, countries other than your country of residence. We ensure such transfers are compliant with applicable data protection laws through:

  • Adequacy decisions by relevant authorities
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)
  • Other approved transfer mechanisms

6.2 Safeguards

We implement appropriate safeguards to ensure that your Personal Data remains protected according to the standards of this Privacy Policy when transferred internationally.

7. DATA SECURITY MEASURES

7.1 Technical and Organizational Measures

We implement appropriate technical and organizational security measures to protect your Personal Data, including:

Security Area Measures Implemented
Access Control Role-based access, multi-factor authentication, principle of least privilege
Data Encryption SSL/TLS encryption, database encryption, file-level encryption
Network Security Firewalls, intrusion detection systems, DDoS protection
Physical Security Secure data centers, access logs, environmental controls
Procedural Security Security policies, employee training, incident response plans

7.2 Security Incident Response

We have established procedures to handle any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8. DATA RETENTION PERIODS

8.1 Retention Criteria

We retain Personal Data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

8.2 Specific Retention Periods

Data Category Retention Period Basis for Retention
Customer account data 7 years after account closure Legal obligation, contract enforcement
Financial and transaction records 7 years from transaction date Tax and accounting laws
Marketing data 3 years from last interaction Legitimate interests, consent period
Technical and usage data 2 years from collection Analytics, security purposes
Support communications 5 years from resolution Quality assurance, legal protection

9. YOUR LEGAL RIGHTS

9.1 Rights Overview

Under applicable data protection laws, you have rights regarding your Personal Data, including:

Right Description
Right to Access Obtain confirmation and copy of your Personal Data
Right to Rectification Correct inaccurate or incomplete Personal Data
Right to Erasure Request deletion of your Personal Data
Right to Restriction Limit processing of your Personal Data
Right to Data Portability Receive your data in a structured, machine-readable format
Right to Object Object to processing based on legitimate interests
Right to Withdraw Consent Withdraw consent at any time where processing is based on consent

9.2 Exercising Your Rights

To exercise any of these rights, please contact us using the details in Section 14. We will respond to your request within 30 days and may need to verify your identity before processing your request.

9.3 Right to Lodge Complaint

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your Personal Data violates applicable data protection laws.

14. CONTACT INFORMATION AND DATA PROTECTION OFFICER

Data Protection Officer

For all data protection inquiries, including exercising your rights or reporting concerns, please contact our Data Protection Officer:

Email: dpo@cheapodeal.co.in

Phone: +91 98880 77739

Address: 69 Guru Har Rai Nagar, Ludhiana, Punjab 141008, India

Response Time: We endeavor to respond to all legitimate requests within 30 days. Occasionally, it may take longer if your request is particularly complex or you have made multiple requests.

15. GOVERNING LAW AND JURISDICTION

This Privacy Policy is governed by and construed in accordance with the laws of India. Any disputes relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Ludhiana, Punjab.