Privacy policy
As per the Indian Digital Personal Data Protection Act 2023 (DPDP Act) and the Information Technology Act 2000 with the IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011.
Data fiduciary (controller)
The data fiduciary is the operational team of Adenofrin India with address at Office No. 1207, 12th Floor, One BKC, G-Block, Mumbai — 400051, Maharashtra, India. To exercise your rights, kindly write to support@adenofrin.net or call +91 22 4082 1437 during the business hours indicated in the Contact section.
Types of data collected
- Identification data: name and surname provided through the order form.
- Contact data: mobile number provided through the order form.
- Delivery data: postal address communicated during the phone confirmation call.
- Technical data: IP address, browser user-agent, site access logs (for security purposes).
- Technical cookies: session identifiers necessary for site functioning.
Purposes and lawful basis
- Contract execution: processing the order, organising delivery and managing Cash on Delivery payment (DPDP Act, lawful purpose related to contract).
- Compliance with legal obligations: tax registration, lot traceability for food safety vigilance (DPDP Act, legal obligation).
- Legitimate use: information security, fraud prevention, service improvement (DPDP Act, legitimate use).
- Direct marketing: ONLY upon explicit consent of the data principal (DPDP Act, consent), always revocable.
Data retention
Order-related data is retained for the time necessary to execute the contract and subsequently for tax obligations (8 years from the date of the order, as per the Indian Income-tax Act). Marketing data is retained until consent is withdrawn. Technical logs are retained for a maximum of 12 months.
Rights of the data principal
You have the right to access your data, correct it, erase it, restrict processing, object to processing on legitimate use basis and obtain data portability (DPDP Act, sections 11-15). You also have the right to lodge a complaint with the Data Protection Board of India (when constituted). To exercise your rights, kindly write to support@adenofrin.net.
DPDP Act 2023 — Indian implementation specifics
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), received Presidential assent on 11 August 2023 and is in the process of phased commencement through notifications in the Official Gazette. Until the Data Protection Board of India is fully constituted under Section 18, complaints relating to sensitive personal data continue to be governed by Rule 8 of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, framed under Section 43A of the Information Technology Act, 2000. Sensitive Personal Data or Information (SPDI) under these Rules includes passwords, financial information, physical and mental health condition, biometric data, and any details revealing medical records. We do not collect SPDI through the order form. The phone number you provide is treated as Personal Data under the DPDP Act and is processed solely for the lawful purpose of order fulfilment under Section 7(a) (specified purpose for which consent was given).
Consent manager and withdrawal of consent
In accordance with Section 6(4) of the DPDP Act, you have the right to withdraw your consent at any time, and the consequences of such withdrawal shall be borne by you (e.g. inability to complete a pending Cash on Delivery shipment). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. To exercise withdrawal, write to support@adenofrin.net with the subject line "DPDP — Consent withdrawal" and quote the mobile number used at the time of consent. When the Data Protection Board notifies the Consent Manager framework under Section 6(7) we shall integrate a registered Consent Manager to facilitate granular consent management.
Cross-border data transfers
Personal data of Indian data principals is hosted on servers located within Indian territory or in countries notified by the Central Government under Section 16 of the DPDP Act. We do not transfer personal data to jurisdictions that have not been notified as permitted, and we do not transfer SPDI under the 2011 IT Rules without your explicit consent as required by Rule 7. Courier partners (Blue Dart Express, Delhivery, DTDC, Ekart, India Post) process delivery data exclusively within India under their respective privacy policies and data processing agreements with us.
Children's data and special categories
In line with Section 9 of the DPDP Act, we do not knowingly process personal data of individuals under 18 years of age. The product Adenofrin is intended for adult men over 40 and the order form requires confirmation of adulthood during the phone confirmation call. We do not undertake behavioural monitoring or targeted advertising directed at children, which is prohibited under Section 9(3).
Security safeguards (Section 8(5) DPDP Act)
Reasonable security safeguards have been implemented to prevent personal data breach: TLS 1.3 encryption for transit, AES-256 encryption at rest for database backups, role-based access controls with multi-factor authentication for staff, and annual security audits aligned with the IS/ISO/IEC 27001 international standard recognised under Rule 8 of the 2011 IT Rules. In the event of a personal data breach, we shall notify the Data Protection Board and affected data principals without undue delay as mandated by Section 8(6) DPDP Act.