Privacy Notice

Last Updated: 13 May 2026

This Privacy Notice is published in accordance with the provisions of the Digital Personal Data Protection (DPDP) Act, 2023, and the DPDP Rules, 2025. This document explains how Brandmagicz Agency ("Brandmagicz," "We," "Us," or "Our") acts as a Data Fiduciary to collect, use, process, store, and protect your digital personal data. We are committed to processing your data in a manner that is lawful, fair, transparent, and respectful of your privacy rights.

1. The Information We Collect

We practice strict data minimization. We only collect the personal data that is absolutely necessary for providing our products and services to you. The categories of digital personal data we collect include:

  • Identity Data: First name, last name, date of birth (for age verification).
  • Contact Data: Billing address, delivery address, email address, and mobile number.
  • Financial Data: Payment processing details (processed securely via our third-party payment gateways; we do not store full credit card numbers on our servers).
  • Technical and Usage Data: IP address, browser type, device identifiers, platform interaction metrics, and purchase history.

2. The Purpose and Legal Basis for Processing

We process your personal data based on your explicit, affirmative consent or under the legitimate uses prescribed by the DPDP Act. We utilize your data for the following specific purposes:

  • Order Fulfillment: To process transactions, manage logistics, and deliver the Ayurvedic and personal care products you have purchased.
  • Customer Support: To provide post-purchase assistance, handle returns, and resolve grievances.
  • Platform Optimization: To analyze user behavior to improve website functionality and product offerings.
  • Regulatory Compliance: To comply with tax laws (e.g., GST reporting) and consumer protection mandates.

3. Consent, Withdrawal, and Minor's Data

3.1. Affirmative Consent

Your data is processed only after you provide free, specific, informed, and unambiguous consent via an affirmative action (e.g., clicking an unticked "I Agree" box).

3.2. Withdrawal of Consent

You have the right to withdraw your consent at any time without facing any detrimental consequences regarding the use of the platform prior to withdrawal. You can withdraw consent by accessing the "Privacy Preferences" tab in your account dashboard or by contacting our Data Protection Officer. Upon withdrawal, we will cease processing your personal data, which may result in our inability to provide certain services.

3.3. Protection of Children's Data

Brandmagicz Agency does not knowingly collect or process personal data from individuals under the age of 18 without obtaining verifiable consent from a parent or lawful guardian. We strictly prohibit any tracking, behavioral monitoring, or targeted advertising directed at children.

4. Data Sharing and Third-Party Processors

We do not sell your personal data to data brokers. However, to fulfill our services, we share necessary data with trusted third-party Data Processors. We maintain strict Data Processing Agreements (DPAs) with these entities to ensure they uphold DPDP Act standards. We share data with:

  • Logistics and Fulfillment Partners: (e.g., courier services and quick-commerce platforms) for delivery execution.
  • Payment Gateways: For secure transaction processing.
  • Cloud Infrastructure Providers: For secure data hosting and server management.
  • Statutory Authorities: When required to comply with law enforcement requests, tax audits, or legal mandates.

5. Data Retention and Security Safeguards

5.1. Storage Limitation

We retain your personal data only for as long as is necessary to fulfill the specific purpose for which it was collected, or to comply with overriding legal, accounting, or reporting requirements. Once the purpose is exhausted, or upon a valid request for erasure, your data will be permanently deleted or anonymized.

5.2. Security Controls

Brandmagicz Agency implements robust technical and organizational measures, including role-based access control (RBAC), data encryption in transit and at rest, and regular security audits, to protect your data against unauthorized access, disclosure, or alteration. In the unlikely event of a personal data breach, we will notify both the Data Protection Board of India and the affected individuals in accordance with statutory timelines.

6. Your Rights as a Data Principal

Under the DPDP Act, 2023, you possess the following actionable rights regarding your personal data:

  • Right to Access: The right to obtain a summary of your personal data being processed and the identities of third-party processors it has been shared with.
  • Right to Correction and Erasure: The right to request the correction of inaccurate data, the updating of obsolete data, or the complete erasure of your personal data when it is no longer necessary for processing.
  • Right of Grievance Redressal: The right to have your privacy-related complaints addressed rapidly by our internal mechanisms.
  • Right to Nominate: The right to nominate an individual to exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, please submit a request via the "Data Principal Rights Form" in your account dashboard or email our Data Protection Officer.

7. Privacy Grievance Officer / Data Protection Officer (DPO)

Name

Hiriharan Palani

Designation

Data Protection Officer / Privacy Grievance Officer

Email Address

support@brandmagicz.com

Postal Address

129, 14th E Cross Rd, Gangadhar Nagar, 1st Phase, J. P. Nagar, Bengaluru, Karnataka 560078

Engineering Compliance Roadmap

True compliance is achieved when these policies dictate the architecture of the digital platform itself. Our engineering team is committed to the following structural integrations:

Consent Gateway

Implementation of distinct actions for T&C and Privacy Notice with explicit opt-in (no pre-ticked boxes).

Multilingual Infrastructure

Localization toggle for all 22 official languages to ensure linguistic transparency.

Privacy Control Center

Dedicated dashboard tab for users to view data, manage sharing, and trigger erasure workflows.

Legacy Remediation

Retrospective application of consent for historical datasets to ensure full statutory compliance.