Legal
Privacy Policy
How we handle your personal information — written in plain language, compliant with India's Digital Personal Data Protection Act, 2023 and the EU General Data Protection Regulation.
In short
- We collect only what we need to fulfil your order, respond to your quote request, or log you in.
- We do not sell, rent, or trade your personal data. Ever.
- Payments are processed by Razorpay — we never see or store your card details.
- You can access, correct, or delete your data anytime by emailing info@paperconcepts.in.
1. Who we are
Paper Concepts ("we", "our", "us") is a packaging manufacturer based in Mumbai, India. We operate this website at paperconcepts.in and act as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Data Controller under the EU General Data Protection Regulation ("GDPR") for any personal data we collect through this site.
Registered address:
Paper Concepts
Shop No. 2/3, Londhe House
D'Lima Street, Dockyard Road
Mumbai — 400010, India
Contact: info@paperconcepts.in
2. Information we collect
We collect only the personal data needed for the specific purpose you engage with us. Depending on how you use our site, this may include:
2.1 Information you give us directly
| When | What we collect |
|---|---|
| You request a quote | Name, company, email, phone, product type, quantity, and any message you include |
| You contact us | Name, email, subject line, and message content |
| You request a callback | Name, phone number, brief note |
| You place an order | Billing name, address, email, phone, GSTIN (if provided), order items, payment method |
| You create an account | Email address, password (hashed — we never see it in plain text), display name |
| You log in via OTP | Email address, one-time code (deleted immediately after use or expiry) |
2.2 Information collected automatically
| What | Purpose |
|---|---|
| IP address | Anti-spam rate limiting on public forms; security logs |
| Browser type and version, device type | Ensuring the site displays correctly; debugging |
| Pages viewed, timestamp of visits | Basic server logs (retained ~30 days for security only) |
| Cookies (see Section 8) | Login sessions, cart contents, security tokens |
2.3 What we do NOT collect
We do not use third-party analytics, tracking pixels, advertising cookies, or fingerprinting. We do not collect biometric data, location data, or "sensitive personal data" as defined under the DPDP Act (unless you voluntarily include it in a quote message). We do not knowingly collect data from children under 18 — please see Section 11.
3. Why we collect it (legal basis)
Under the DPDP Act, we process your data based on your consent or "legitimate uses" recognised by law. Under the GDPR, the equivalent legal bases are set out below.
| Purpose | Legal basis (DPDP) | Legal basis (GDPR) |
|---|---|---|
| Fulfilling an order or quote | Consent + legitimate use for performance of a contract | Art. 6(1)(b) — contract performance |
| Sending order confirmations, shipping updates | Legitimate use — post-purchase communication | Art. 6(1)(b) — contract |
| Marketing emails (only if you opted in) | Consent | Art. 6(1)(a) — consent |
| Login authentication (OTP + password) | Consent | Art. 6(1)(b) — contract |
| Fraud prevention, rate limiting | Legitimate use — security | Art. 6(1)(f) — legitimate interest |
| Legal compliance (tax records, invoices) | Legitimate use — legal obligation | Art. 6(1)(c) — legal obligation |
4. Who we share your data with
We share personal data only with the service providers ("Data Processors") we need to run the business. Each is contractually or by policy required to use your data only for the purposes we specify.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Razorpay Software Pvt Ltd | Payment processing | Name, email, phone, order amount | India |
| Hostinger International Ltd | Website hosting, email delivery | All site data (stored on Hostinger servers) | India (Mumbai region) |
| Google LLC (Google Fonts) | Font file delivery | IP address (via CSS/font request) | Global CDN |
| Automattic Inc. (Gravatar, optional) | Comment avatar images | Hashed email address | USA |
| Shipping / courier partners | Order delivery | Name, delivery address, phone, order ID | India |
We do not sell, rent, or trade your personal data to any third party for their independent marketing use.
We may disclose personal data if required by law, court order, or a legitimate request from a government authority in India, or to protect our rights, property, or safety.
5. International data transfers
Some of our service providers (notably Google Fonts and Gravatar) may process data outside your country. Where personal data is transferred outside the European Economic Area (for EU users) or India (for Indian users), we rely on:
- Adequacy decisions where applicable
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The service provider's own privacy commitments and certifications (e.g., Google's Data Processing Addendum)
Under the DPDP Act, the Central Government of India may notify countries to which personal data may not be transferred. We monitor such notifications and update our providers accordingly.
6. How long we keep your data
| Data type | Retention period | Why |
|---|---|---|
| OTP codes | 10 minutes | Auto-expiry after single use |
| Failed login counters | Up to 1 hour | Auto-expires with the lockout window |
| Rate-limit records | 60 seconds | Auto-expires |
| Quote submissions | 3 years | Sales follow-up + record-keeping |
| Contact form messages | 1 year | Reference and follow-up |
| Order records, invoices | 8 years | Required under the Companies Act, 2013 and GST Act |
| Account data | Until you delete your account | Enables login and order history |
| Server access logs | ~30 days | Security investigations only |
When the retention period ends, we securely delete or anonymise the data.
7. Your rights
Both the DPDP Act and the GDPR give you strong rights over your personal data. To exercise any of these, email info@paperconcepts.in. We respond within 30 days (often faster).
7.1 Rights under the DPDP Act, 2023 (Indian users)
- Right to information — a summary of the personal data we hold about you and the processing done to it
- Right to correction and erasure — request that we correct inaccurate data or delete data that is no longer needed
- Right to grievance redressal — file a complaint with our Grievance Officer (see Section 12)
- Right to nominate — nominate another individual who can exercise your rights in the event of your death or incapacity
- Right to withdraw consent — withdraw consent at any time; this will not affect the lawfulness of prior processing
7.2 Rights under the GDPR (EU users)
- Right of access (Art. 15) — a copy of your personal data
- Right to rectification (Art. 16) — correction of inaccurate data
- Right to erasure / "right to be forgotten" (Art. 17) — deletion, subject to legal retention rules
- Right to restrict processing (Art. 18) — pause processing while a dispute is resolved
- Right to data portability (Art. 20) — receive your data in a machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7.3) — where consent is the legal basis
- Right to lodge a complaint (Art. 77) — with your local Data Protection Authority
8. Cookies and similar technologies
We use a small number of cookies, all strictly necessary for the site to function. We do not use tracking cookies, advertising cookies, or third-party analytics.
| Cookie | Purpose | Lifetime |
|---|---|---|
| wordpress_logged_in_* | Keeps you signed in | Session or 14 days ("remember me") |
| wp-settings-* | Admin dashboard preferences | 1 year |
| woocommerce_cart_hash | Cart state | Session |
| woocommerce_items_in_cart | Cart badge count | Session |
| wp_woocommerce_session_* | Anonymous cart identification | 2 days |
You can block or delete cookies via your browser settings. If you do, some features (such as staying logged in or keeping your cart) may not work as expected.
9. How we protect your data
We take security seriously and use industry-standard measures:
- Encryption in transit — the entire site runs on HTTPS with HSTS enforced; passwords and payment details are never sent in plain text
- Hashed passwords — stored using WordPress's PHPass-style algorithm; we never see or store your password in plain text
- Brute-force protection — automated lockouts on both password and OTP login after repeated failures
- Payment security — payment data is handled entirely by Razorpay's PCI-DSS certified systems; we never receive card details
- Access control — only authorised staff can view order and customer data in our admin panel
- Rate limiting and honeypots on all public forms to prevent scraping and abuse
- Security headers — HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and a Content Security Policy
No system is 100% secure. In the unlikely event of a personal data breach that is likely to result in significant harm, we will notify affected users and the Data Protection Board of India (under the DPDP Act) or the relevant supervisory authority (under the GDPR) without undue delay, in accordance with law.
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. Automated rate-limiting and anti-spam checks are the only automated processes that touch your data, and they are strictly technical measures — they do not evaluate you as a person.
11. Children's data
Our services are intended for businesses and adults. Under the DPDP Act, we do not knowingly process personal data of individuals below the age of 18 without verifiable parental consent. Under the GDPR, we do not process personal data of individuals below the age of 16 in the EU without parental consent. If you believe a child has provided us data, please contact us at info@paperconcepts.in and we will delete it promptly.
12. Grievance Officer (DPDP Act) & Data Protection Contact (GDPR)
If you have a question, complaint, or want to exercise any of your rights, please contact our Grievance Officer:
Grievance Officer: Mufaddal Kagalwala
Email: info@paperconcepts.in
Postal: Paper Concepts, Shop No. 2/3, Londhe House, D'Lima Street, Dockyard Road, Mumbai — 400010, India
Response time: Within 30 days of receipt (per DPDP Act) or one month (per GDPR)
If we cannot resolve your complaint, you have the right to escalate:
- India (DPDP Act): to the Data Protection Board of India, once established under the Act
- EU (GDPR): to the supervisory authority of your Member State (a list is available at edpb.europa.eu/about-edpb/board/members)
13. Updates to this policy
We may update this policy as our practices or applicable laws evolve. When we do, we will change the "Last updated" date at the top of this page. For material changes (for example, new categories of data or new recipients), we will notify registered users by email at least 30 days before the change takes effect.
14. Questions?
Anything about your data, your rights, or this policy — write to us at info@paperconcepts.in. We answer every message.