1. Scope and Application:

    1. This Privacy Policy describes how Ahikoza (“Ahikoza”, “we”, “us” or “our”) collects, uses, shares, stores and otherwise processes personal data when you access or use our website www.ahikoza.com (the “Site”), purchase our products or otherwise interact with us. It applies to all processing of digital personal data in connection with the offering of our goods or services to individuals in India, in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”). This Privacy Policy constitutes a notice under the Digital Personal Data Protection Act, 2023 and is made available to you at or before the time of collection of your personal data.
    2. For purposes of this Privacy Policy, “personal data” means any data about an individual who is identifiable by or in relation to such data, including where collected in non-digital form and subsequently digitised.
  1. Data Fiduciary and Contact Details:

    1. For the purposes of the DPDP Act, Ahikoza acts as a Data Fiduciary in respect of personal data that it determines the purposes and means of processing for, including in relation to this Site and our direct-to-consumer operations. If you have any questions about this Privacy Policy or our privacy practices, you may contact us at:
      Email: bespoke@ahikoza.com

    2. Grievance Officer: In accordance with the DPDP Act, we have appointed the following Grievance Officer as the primary point of contact for grievances relating to our processing of your personal data and for exercise of rights under the DPDP Act: 
      Name: Namrata Karad
      Designation: Grievance Officer
      Email: Namrata.dudaney@ahikoza.com
      You may submit any grievance, request or complaint in relation to your personal data or this Privacy Policy to the Grievance Officer using the above contact details. We will respond within the time period prescribed under applicable law.
  1. Categories of Personal Data We Collect:

    • Information You Provide Directly:
        1. Account and Order Information: name, salutation or title, billing address, shipping address, contact number, email address, order details, purchase history, preferences, and any additional details you choose to provide when placing an order or creating an account.
        2. Payment Information: limited payment card or other payment instrument details as processed via our payment service providers (card type, masked card number, payment status, transaction identifiers). Full card details are collected and processed directly by our payment gateway partners and not retained by us beyond what is strictly necessary for reconciliation and record-keeping in accordance with applicable law.
        3. Customer Support Information: information you provide when you contact us, including name, email address, phone number, order details, queries, communications content and related correspondence.
        4. Marketing and Communication Preferences: your subscription status to our newsletters, promotional emails, SMS or other communications, and your preferences regarding these communications.

    • Information Collected Automatically (Device and Usage Data):

When you access or use the Site, we automatically collect certain information from your device and about your use of the Site, including through cookies and similar technologies.

        1. Device Information: IP address, browser type and version, operating system and platform, device identifiers, language settings, time zone.
        2. Usage Information: pages viewed, products viewed or added to cart, search terms, referring and exit pages, timestamps, clickstream and interaction data, and information about how you navigate and interact with the Site.
        3. Cookie and Tracking Data: identifiers associated with cookies, pixels, tags, beacons and similar technologies that may be set on your browser or device (see Section 9 below).
    1. Information from Third Parties:

We may receive personal data about you from the following categories of third parties:

        1. Payment Service Providers (e.g., card networks, payment gateways, wallets), who provide us with limited payment confirmation and risk / fraud indicators.
        2. Logistics and Delivery Partners, who provide delivery status and related information.
        3. Marketing and Advertising Partners, including social media platforms and ad networks, who may provide aggregated or inferred information about your interests or interactions with our ads, subject to their own privacy policies and your settings with them.
        4. Analytics Providers, such as Google Analytics, who help us understand Site usage patterns at an aggregated level.
  • Children’s Data:

Our products and Site are not intended for use by individuals under the age of 18 years. We do not knowingly collect or process personal data of children (as defined under the DPDP Act) without verifiable consent of their parent or lawful guardian, nor do we undertake tracking, behavioural monitoring or targeted advertising directed at children. 

If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact our Grievance Officer. Upon becoming aware, we will take steps to delete such data, subject to our legal obligations.

 

  1. Purposes and Lawful Basis of Processing:

We process personal data primarily on the basis of your consent. In certain limited circumstances, we may process personal data without consent where such processing is permitted under applicable law, including where you have voluntarily provided personal data for a specified and lawful purpose and such processing is reasonably expected in connection with that purpose.  

      • Provision of Products and Services:
        • Processing and fulfilling your orders, including payment processing, order confirmation, shipping, delivery, returns and refunds.
        • Creating and managing your account, where applicable.
        • Providing customer support and responding to your queries, requests and complaints.
      • Site Operation, Security and Fraud Prevention:
        • Operating, maintaining and securing the Site, including troubleshooting, data analysis, system testing, and security monitoring.
        • Detecting, preventing and responding to fraud, misuse, abusive or unlawful activities (including chargebacks, payment fraud, or suspicious transactions).
        • Creating temporary deny-lists of IP addresses, devices or payment instruments where repeated suspicious or failed transactions are detected, for limited periods, to protect our business and customers.
      • Marketing, Promotions and Personalisation:
        • Sending you marketing communications (such as newsletters, offers, campaigns) about our products and services, consistent with your communication preferences.
        • Providing you with recommendations, tailored content and personalised offers based on your interactions with the Site, purchase history and preferences, where permitted.
        • Conducting surveys, giveaways or promotional events.
      • Analytics and Service Improvement:
        • Measuring and analysing Site traffic, usage patterns and performance.
        • Understanding customer behaviour and preferences to improve our products, services, user experience and business strategies.
      • Legal and Regulatory Compliance:
        • Complying with obligations under applicable laws, including tax, accounting and record-keeping requirements.
        • Responding to lawful requests or directions from governmental or regulatory authorities, courts or tribunals.
        • Enforcing or defending legal rights, claims and interests, including in connection with disputes, litigation or regulatory proceedings.

We collect and process only such personal data as is necessary for the purposes described in this Privacy Policy and do not retain or process personal data beyond what is reasonably required for such purposes.

  1. Consent and Withdrawal:

      • Where our processing of your personal data is based on your consent, such consent will be free, specific, informed, unconditional and unambiguous, signified by a clear affirmative action (such as ticking a box, clicking “I agree”, or proceeding after being presented with a clear notice). Consent will be limited to personal data necessary for the specified purpose.
      • We will present consent requests in clear and plain language and provide our contact details or those of our authorised representative for any queries relating to your rights.
      • You have the right to withdraw your consent at any time, with the ease of doing so being comparable to the ease with which consent was given. Withdrawal of consent will not affect the legality of processing based on consent prior to such withdrawal.
      • If you withdraw consent, we will cease (and cause our Data Processors to cease) processing your personal data within a reasonable time, unless further processing without consent is required or authorised by applicable law (for example, for tax, accounting or dispute-related purposes).
      • You may withdraw consent to:
          • Marketing communications by using the “unsubscribe” link in our emails or by contacting us using the details in Section 2.
          • Cookies or similar technologies by adjusting your browser settings or, where provided, through our cookie consent tools (see Section 9 below).
  1. Disclosures and Sharing of Personal Data:

We do not sell your personal data. We may share your personal data only as described below and only for lawful purposes, subject to appropriate contractual and security safeguards. As a Data Fiduciary, we remain responsible for compliance with applicable law for processing carried out on our behalf by Data Processors.

      • Service Providers and Data Processors:

We may share personal data with the following structured categories of service providers, who act as Data Processors on our behalf and under valid contracts:

            1. IT and Hosting Providers – providers of cloud hosting, infrastructure, software and IT support services required to operate the Site and our business.
            2. Payment Service Providers – payment gateways and processors that handle payment transactions, fraud checks and related services.
            3. Logistics and Delivery Partners – courier and logistics companies that deliver your orders and manage returns.
            4. Customer Support Platforms – tools and platforms that enable us to receive, manage and respond to customer queries.
            5. Marketing, Advertising and Analytics Partners – including email delivery services, advertising networks, social media platforms and analytics tools such as Google Analytics, used for campaigns, measurement and optimisation

These service providers are permitted to process personal data only in accordance with our documented instructions and are obligated to implement appropriate technical and organisational measures to protect personal data.

      • Group Entities and Business Partners:

We may share personal data with our current or future group entities (such as subsidiaries, affiliates or holding entities) for intra-group operations, consistent with this Privacy Policy and applicable law. We may also share limited information with business partners in connection with co-branded campaigns, collaborations or marketplace activities, where necessary and subject to appropriate safeguards.

      • Legal, Compliance and Enforcement:

We may disclose personal data where required or permitted under applicable law, including:

            1. to governmental or regulatory authorities, law enforcement agencies, courts or tribunals in response to lawful orders, directions or proceedings;
            2. where necessary to enforce our terms and conditions, protect our operations, rights, privacy, safety or property, or that of our customers or the public;
            3. for enforcement or defence of legal rights or claims, including in connection with disputes, investigations, detection or prosecution of offences or contraventions of law.

      • Business Transfers:

In the event of any merger, acquisition, restructuring, sale of assets or similar business transaction involving Ahikoza, personal data may be transferred to the relevant counterparty or successor entity as part of such transaction, subject to continued protection consistent with this Privacy Policy and applicable law, including without obtaining fresh consent where such transfer is permitted under applicable law.

  1. Cross-Border Transfer of Personal Data:

        • We may transfer or allow access to your personal data to recipients located outside India, including for the purposes of engaging global service providers, facilitating international transactions, supporting operational scalability, or where our or our service providers’ infrastructure is located outside India.
        • Such transfers will be undertaken in accordance with the DPDP Act and any notifications issued by the Central Government restricting transfer of personal data to specified countries or territories, if and when applicable.
        • Where we transfer personal data internationally, we take reasonable steps to ensure that the recipient provides a level of protection that is comparable to that required under the DPDP Act, including through contractual safeguards and security measures.
  1. Data Retention:

    • We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required to comply with legal, regulatory, accounting or reporting obligations, and then erase or anonymise it, unless retention is otherwise required by law. In particular:
        • Order and Transaction Data (including invoices, payment confirmations and related communications) is retained for periods necessary to meet tax, accounting and legal requirements and to handle any disputes or claims arising from the transaction, in line with applicable limitation periods.
        • Customer Support Data is retained for as long as necessary to address your query or complaint and for a reasonable period thereafter to maintain records of our interactions and to improve our services.
        • Marketing Data is retained for as long as you remain subscribed to our marketing communications or until you withdraw consent or opt out, after which it will be erased or pseudonymised, except to the extent needed to maintain a record of your opt-out.
        • Technical and Analytics Data (including cookies and logs) is retained for periods that are appropriate for security, analysis and improvement purposes, generally no longer than is necessary to achieve such purposes, subject to any overriding legal obligations.
    • Under the DPDP Act, we are required to erase your personal data upon withdrawal of consent or as soon as it is reasonable to assume that the specified purpose is no longer being served and retention is not necessary for compliance with any law in force. We will also cause our Data Processors to erase personal data that we have shared with them, subject to such legal obligations.
    • We periodically review the personal data we hold and apply retention schedules and erasure processes consistent with these principles. Data that has been irreversibly anonymised such that no individual can be identified is not considered personal data and may be retained and used by us for analytics, research, and business purposes.
  1. Cookies and Similar Technologies:

We use cookies and similar technologies (such as pixels, tags and beacons) on the Site to improve your browsing experience, remember your preferences, understand Site usage and deliver relevant advertising.

      • Types of Cookies We Use:
        • Strictly Necessary Cookies: Essential to enable basic Site functionality, such as page navigation, secure login, and shopping cart features. The Site cannot function properly without these cookies.
        • Functional Cookies: Enable the Site to remember choices you make (such as region or language) and provide enhanced, more personalised features.
        • Performance and Analytics Cookies: Collect information about how visitors use the Site (for example, pages visited, time spent on pages, error messages) to help us improve performance and user experience.
        • Advertising and Targeting Cookies: Used by us and our advertising partners to deliver ads that are more relevant to your interests and to measure the effectiveness of advertising campaigns.
      • Third-Party Cookies and Tools: We use third-party tools, including:
        • Google Analytics – to help us understand how visitors use the Site. For details on how Google processes your data, please see Google’s privacy policy at https://policies.google.com/privacy?hl=en.
        • Advertising Platforms – such as Facebook and Google Ads, which may set cookies to deliver targeted advertisements based on your interactions with our Site and other sites on the internet, based on your settings with them.
      • Managing Cookies and Tracking:

        You can manage or disable cookies through your browser settings. Most browsers allow you to refuse cookies, accept cookies only from trusted sites, or only accept cookies from the sites you are currently visiting. Please note that disabling or blocking some cookies may affect the functionality of the Site and your ability to use certain features.

        Blocking cookies may not completely prevent information from being shared with third parties such as advertising partners. To exercise your rights or opt out of certain uses of your information by these parties, you should also review and adjust your settings directly with such partners (for example, Facebook Ads preferences or Google Ads settings).
      • Do Not Track:
        At present, there is no consistent industry standard for how to respond to “Do Not Track” (DNT) signals. Accordingly, we do not alter our data collection and usage practices when we detect a DNT signal from your browser.

Non-essential cookies (including analytics and advertising cookies) are deployed only after obtaining your consent through our cookie consent mechanism, where required under applicable law.

  1. Your Rights under the DPDP Act:

As a Data Principal under the DPDP Act, you have certain rights regarding your personal data, subject to applicable conditions and exemptions.

  • Right to Access Information about Your Personal Data:

You have the right to obtain from us, upon request and in the manner prescribed under applicable rules:

      1. a summary of your personal data being processed by us and the processing activities we undertake with respect to such data;
      2. the identities or categories of Data Fiduciaries and Data Processors with whom your personal data has been shared, along with a description of the data so shared, except where restricted by law;
      3. other prescribed information related to your personal data and its processing.
  • Right to Correction, Completion, Updating and Erasure:
    You have the right to request:
      1. correction of inaccurate or misleading personal data;
      2. completion of incomplete personal data;
      3. updating of your personal data; and
      4. erasure of your personal data, subject to our obligation to retain it where necessary for the specified purpose or to comply with applicable law
        .
  • Right of Grievance Redressal:

You have the right to have readily available means of grievance redressal in respect of any act or omission by us regarding our obligations in relation to your personal data or your rights under the DPDP Act. You must first exhaust our internal grievance redressal mechanism before approaching the Data Protection Board of India.

  • Right to Nominate:

You have the right to nominate, in the prescribed manner, any other individual who, in the event of your death or incapacity, may exercise your rights under the DPDP Act in relation to your personal data.

  • Duties of Data Principals:

While exercising your rights, you are required under the DPDP Act, among other things, not to impersonate another person, not to suppress material information when providing personal data for government identifiers, not to file false or frivolous grievances, and to furnish only verifiably authentic information when seeking correction or erasure.

  • How to Exercise Your Rights:

You may exercise the above rights by:

        1. contacting us or our Grievance Officer using the contact details in Section 2; or
        2. using any self-service tools we may make available on the Site from time to time.
  • We may need to reasonably verify your identity (or the identity of your nominee or authorised representative) before acting on your request. We will respond within the timelines prescribed under applicable law.
  • We reserve the right to decline or reasonably limit requests that are manifestly unfounded, excessive, repetitive, or not in accordance with applicable law.
  1. Security of Personal Data:

We implement appropriate technical and organisational measures, including encryption, access controls, secure storage systems, and periodic security reviews, to protect personal data in our possession or under our control. In the event of a personal data breach that is likely to result in significant harm, we will provide intimation to the Data Protection Board of India and to affected Data Principals in the form and manner prescribed by applicable rules.
While we implement reasonable safeguards, no method of transmission over the internet or method of electronic storage is completely secure, and we do not guarantee absolute security.

  1. Automated Processing and Profiling:

We do not engage in fully automated decision-making that has a legal or similarly significant effect on you. We may use automated tools (such as analytics and advertising technologies) to help us understand customer behaviour or to personalise content and offers, but such processing does not in itself produce legal effects or similarly significant decisions regarding you.

  1. Limitation of Liability:

    • Nothing in this Privacy Policy excludes or limits any rights you may have under applicable law, including under the Digital Personal Data Protection Act, 2023, or any liability that cannot be excluded or limited under such law.
    • To the fullest extent permitted by applicable law, Ahikoza shall not be liable for any indirect, incidental, consequential or punitive damages, including loss of profits, data, goodwill or business opportunities, arising out of or in connection with the processing of personal data.
    • Ahikoza shall not be responsible for any loss, damage or harm arising from:
      • unauthorised access, disclosure, alteration or destruction of personal data caused by factors beyond our reasonable control; or
      • any acts or omissions of users or third parties not under our control, including where such events occur despite our implementation of reasonable security safeguards in accordance with applicable law.
        .

This limitation of liability shall apply notwithstanding any failure of essential purpose of any limited remedy.

  1. Third-Party Links and Services:

The Site may contain links to third-party websites, plug-ins or services. When you click on such links or enable such connections, third parties may collect or share data about you. We do not control and are not responsible for the privacy practices of such third parties. We encourage you to read the privacy policies of every website and service you visit.

  1. Changes to this Privacy Policy:

We may update or modify this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations or for other operational, legal or regulatory reasons. When we do so, we will revise the “Effective Date” at the top of the Policy. Where required by applicable law, we will provide appropriate notice of material changes and, where necessary, seek your consent to such changes. Your continued use of the Site or our services after the effective date of an updated Privacy Policy constitutes your acceptance of the revised Policy.

  1. Additional Information for Users in the European Economic Area (EEA):

While our primary compliance framework is the DPDP Act, if you are located in the European Economic Area, we may, to the extent applicable, also rely on lawful bases for processing under the General Data Protection Regulation (GDPR), including consent, performance of a contract, compliance with legal obligations and legitimate interests. In such cases, your GDPR rights (such as access, rectification, erasure, restriction, portability and objection) may be exercised through the same contact channels set out in Section 2, and we will handle such requests in accordance with applicable EU data protection laws.

  1. Contact and Escalation:

If you have any questions, concerns or complaints regarding this Privacy Policy or our handling of your personal data, please contact:

      1. Email: bespoke@ahikoza.com
      2. Grievance Officer Email: Namrata.dudaney@ahikoza.com

If you are not satisfied with our response, and after you have exhausted our internal grievance redressal process, you may lodge a complaint with the Data Protection Board of India in accordance with the DPDP Act and applicable rules.