1. INTRODUCTION & THE “TRUST” PREAMBLE
At Yutiqaa Lifestyle Private Limited (“Yutiqaa”), we recognize that our Patrons value their privacy as much as the exquisite craft they acquire. This Policy outlines our commitment to “Data Dignity.” We act as the Data Fiduciary under the Indian Digital Personal Data Protection (DPDP) Act, 2023, and as the Data Controller under the European Union GDPR. This Policy governs all interactions across our Website, the Yutiqaa Consumer App (Android/iOS etc.), Social Media/Commerce channels (Instagram/WhatsApp/Twitter/X etc.), and Exclusive Concierge Services.
2. DEFINITIONS & INTERPRETATIONS
- Personal Data: Any information that relates to an identified or identifiable natural person.
- Sensitive Personal Data: Financial identifiers, biometric data (where applicable), specific purchase preferences requiring enhanced protection, and health/preference data.
- Processing: Any operation performed on data, including collection, storage, usage, and deletion.
- Consent: A free, specific, and informed indication of the Patron’s wishes.
3. DATA COLLECTION: (What we collect and Why)
Purpose: We collect this data primarily to provide the Service, ensure secure delivery, and meet statutory KYC/AML obligations for high-value transactions.
We collect data across the following distinct categories:
- Identity Data: Full name, username, title, gender, and date of birth (to verify age eligibility).
- Contact Data: Billing address, precise shipping address (including GPS coordinates for global courier accuracy), email address, and telephone numbers.
- Financial Data: Primary Account Number (PAN) replacements (tokens), and bank details for high-value refund processing.
- Transaction Data: History of luxury purchases, handloom preferences, and Sutra Circle membership status.
- Technical Data: IP address, device identifiers from the Yutiqaa App, and browser telemetry.
- Usage Data: Granular logs of how you interact with our craft stories and product galleries.
4. METHODS OF DATA COLLECTION
- Direct Interaction: Data provided via account creation, DM orders, or concierge calls.
- Automated Technologies: Technical data captured via cookies, server logs, and web beacons.
- Third-Party Sources: Logistics status from couriers and fraud-risk signals from payment gateways.
5. HOW WE USE YOUR INFORMATION (The Purpose)
- Order Fulfillment: Processing payments, arranging international shipping, and issuing dispatch/delivery confirmations.
- Communication: Managing Exclusive concierge interactions, transactional alerts (WhatsApp/SMS), newsletters, and addressing customer support queries.
- Analytics & Performance: Utilizing data to improve website/app UI/UX and tailoring personalized luxury craft recommendations.
- Security & Fraud Prevention: Protecting against “Chargeback Fraud,” verifying high-value transactions, and preventing unauthorized access.
6. LEGAL BASIS FOR PROCESSING (The “Why”)
We process data based on:
- Contractual Necessity (to ship your order): Fulfillment of the “Contract of Sale” defined in the T&C.
- Legitimate Interest (brand protection): Internal brand protection, fraud detection, and enhancing the luxury user experience.
- Consent (marketing opt-ins): Explicit opt-ins for marketing communications and cultural newsletters.
- Legal Obligation (tax and AML compliance): Mandatory data retention for KYC/AML compliance and tax reporting.
7. INTERNATIONAL DATA TRANSFERS
- Explicit Disclosure: Your information may be transferred to and maintained on servers located in India. For Patrons in the EU, UK, or other jurisdictions with strict data export laws, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
8. MARKETING & THE OPT-OUT RIGHT
- Patrons may withdraw consent for marketing communications at any time via the “Preference Center” in the Yutiqaa App or the “Unsubscribe” link in emails. Such withdrawal will not affect the lawfulness of any processing based on consent before its withdrawal. Upon receipt of a withdrawal request, Yutiqaa shall cease processing the specific personal data within a reasonable timeframe, unless such processing is required by law for transactional or tax purposes.
- Transactional communications or alerts regarding active orders cannot be silenced.
9. DATA SHARING & THE “ZERO-SALE” PROMISE
- The Zero-Sale Promise: Yutiqaa explicitly guarantees that we do not, and will never, sell, rent, or trade your Personal Data to third-party data brokers or marketing aggregators for their own commercial use.
- Data is only shared with:
- Operational Service Providers: Authorized Logistics, Payment, and Cloud Hosting service providers, who are contractually bound to process data only for Yutiqaa’s specific purposes.
- Professional Advisors: Legal counsel, auditors, insurers, and banking partners.
- Regulatory & Statutory Authorities: Disclosure to Tax/Customs officials (GST compliance) and Law Enforcement where legally mandated.
10. FINANCIAL DATA SECURITY (PCI-DSS TOKENIZATION)
To protect our patrons during high-value transactions in line with RBI guidelines:
- No Raw Storage: Yutiqaa does not store raw Credit/Debit card numbers, CVV, or expiry dates or UPI PINs on its servers.
- Tokenization Protocol: We utilize PCI-DSS Compliant Tokenization. Your sensitive card data is replaced with a “surrogate value” (token) by our payment partners. This ensures that even in the unlikely event of a system breach, your actual financial identifiers remain unreadable and useless to unauthorized parties.
11. THE “FORTRESS” PROTOCOL: DATA SECURITY
- Encryption Standards: We employ SSL/TLS encryption for all data in transit.
- Access Control: Internal access is restricted to “Need-to-Know” employees only via Role-Based Access Control (RBAC).
- Breach Notification: In the event of a breach, we commit to notifying the relevant authorities and affected patrons within 72 hours.
12. DATA RETENTION (How Long We Keep It)
- Statutory Limits: Records are retained for as long as necessary to fulfill the purposes outlined (e.g., 7–10 years for Indian tax compliance).
- Account Lifespan: Profile data records are retained as long as the account remains active or the “Sutra Circle” membership is valid.
- Anonymization: Inactive accounts and non-essential data are periodically purged or anonymized & transitioned into an aggregated, non-identifiable state for craft trend analysis.
13. GLOBAL PATRON RIGHTS (Jurisdiction-Specific)
Depending on your location, you have the right to: Access your data, Correct inaccuracies, Erasure (Right to be Forgotten), and Portability.
- India (DPDP Act): Right to correction, right to nominate a representative, and right to grievance redressal.
- EU (GDPR): Right to erasure (Right to be Forgotten), data portability, and the right to restrict processing.
- USA (CCPA): Right to know, right to delete, and non-discrimination for exercising privacy rights.
14. CHILDREN’S PRIVACY
- Strict Prohibition: Yutiqaa does not knowingly collect data from individuals under the age of 18.
- Parental Erasure Protocol: If a minor’s data is inadvertently collected, it will be purged immediately upon notification.
15. COOKIES & TRACKING TECHNOLOGIES
- Technical Summary: We use cookies, web beacons, and pixels to enhance your experience. These technologies help us remember your preferences, understand how you navigate our craft stories, and ensure our security protocols are functioning. While some cookies are essential for the Yutiqaa App and Website to function, you have the right to opt-out of non-essential tracking via our dedicated Cookie Policy.
- External Links: Our platforms may include links to third-party websites, plug-ins, and applications (such as Instagram, Pinterest, or external payment gateways). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Yutiqaa does not control these third-party websites and is not responsible for their privacy statements. When you leave our platform, we encourage you to read the privacy policy of every website you visit, especially before providing any sensitive or financial information.
16. CHANGES TO THIS POLICY
- Version Control: The “Last Updated” date & “Version” at the top of this page indicate the current version.
- Notification Protocol: Patrons will be notified of material changes via a website banner or direct email alerts.
17. CONTACT & GRIEVANCE REDRESSAL
- Data Protection Officer (DPO): For privacy inquiries or to exercise your rights, contact our DPO: Rakesh Sahu (Head of Technology) at
- Nodal Officer Information: Hiran Dash (Co-Founder, Director) is our Nodal Officer for Indian Grievance Redressal.
Address: Flat 403, Sai Kesava Residency, Prashanth Nagar Colony, Kondapur, Hyderabad, Telangana, India, 500084