Blog

Privacy Policy

Last Updated: July 20, 2026
Compliant with: Digital Personal Data Protection Act, 2023 (DPDP Act) as amended 2026

DPDP Act 2023/26 Compliant Data Principal Rights Consent Management Grievance Redressal

1. Scope and Application

This Privacy Policy describes how TEZAS ENTERPRISES ("we", "us", "our") collects, uses, processes, stores, and protects your personal data when you visit our website, use our services, or interact with us. This policy applies to all users of our website, services, and products (collectively, "Services").

This policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and subsequent amendments through 2026. We process your personal data in accordance with the principles of lawful, fair, and transparent processing as mandated by Section 4 of the DPDP Act.

3. Categories of Personal Data We Collect (DPDP Act, Section 4 & 5)

We collect the following categories of personal data, only when necessary for specified purposes:

3.1 Data You Provide Directly

  • Identity Data: Full name, email address, phone number, date of birth, gender
  • Contact Data: Email address, phone number, alternate phone number, shipping/billing address
  • Financial Data: GST number, PAN card, Aadhaar number (encrypted), bank account details, annual income, monthly electricity bill — credit/debit card information is processed entirely by Razorpay (our payment gateway) and never stored by us
  • Property Data: Property address, property type (residential/commercial/industrial), electricity bill details, roof type, roof area, roof direction, current electricity consumption in units
  • Identity Documents: Government-issued ID proofs uploaded for verification (Aadhaar, PAN) — stored encrypted via AES-256
  • Professional Data: Occupation, company name, years of experience, expected salary (collected during career applications)
  • Communication Data: Messages sent via our contact form, email correspondence, support ticket messages, blog comments
  • Career Data: Name, email, phone, resume/CV, cover letter when applying for positions
  • Nominee Data: Name, email, phone, relationship of your nominated person under DPDP Act Section 14
  • Location Data: Precise geolocation (latitude/longitude) of installation sites for project planning
  • 3.2 Data Collected Automatically

    • Usage Data: Pages visited, time spent on pages, referring URLs, browser type and version, operating system, device type
    • Technical Data: IP address, cookies and similar tracking technologies, session identifiers
    • Location Data: Approximate location derived from IP address

    3.3 Data from Third Parties

    • Payment Processors: Razorpay provides us with transaction status and masked payment details — we never receive full card numbers
    • reCAPTCHA: Google reCAPTCHA v3 is used on our contact and registration forms for spam prevention (subject to Google's privacy policy)
    • Analytics: Google Analytics provides aggregated usage statistics
    • Installation Partners: With your explicit consent, we share necessary data with our installation partners for service delivery

    3.4 Special Categories of Personal Data

    We do not collect sensitive personal data (health information, biometric data, genetic data, caste, religious beliefs, political opinions, or sexual orientation). Aadhaar and PAN data are collected only for government solar subsidy applications and tax compliance, and are stored with encryption at rest (AES-256) as required under Section 7 of the DPDP Act.

    4. Purpose and Lawful Basis of Processing (DPDP Act, Section 4 & 5)

    We process your personal data only for the following specified purposes:

    Purpose Data Categories Used Lawful Basis
    Service delivery & solar installation Identity, Contact, Property Consent / Contract performance
    Quotation & billing Identity, Contact, Financial Consent / Contract performance
    Customer support & communication Identity, Contact, Communication Consent / Legal obligation
    Solar subsidy processing Identity, Financial (Aadhaar/PAN) Consent / Legal obligation
    Fraud prevention & security Technical, Usage, Identity Legitimate interest / Legal obligation
    Website analytics Usage, Technical Consent
    Legal compliance & audit Identity, Financial, Communication Legal obligation

    5. Consent Management (DPDP Act, Section 5 & 6)

    Your consent is the basis for our processing activities. We implement a granular consent management system:

    5.1 Obtaining Consent

    • We present a clear cookie consent banner on your first visit with options to Accept All, Reject All, or Customize preferences
    • Consent is obtained through an unambiguous affirmative action — silent browsing or inaction does not constitute consent under the DPDP Act
    • Consent notices are in English and presented in clear, plain language

    5.2 Consent Categories

    We classify cookies into the following categories:

    1. Necessary (Strictly Required): Essential for website functionality — session management, CSRF protection, security. These cannot be disabled.
    2. Functional: Enable preferences such as dark mode and region settings.
    3. Analytics: Track aggregated usage patterns via Google Analytics to improve our Services.
    4. Marketing: Reserved for future use — no marketing cookies are currently deployed.
    5. Social Media: Reserved for future use — no social media tracking scripts are currently deployed.

    5.3 Consent Records

    Every consent action is timestamped and logged in our privacy consent database, recording: the consent category, your choice (accepted/rejected), the consent version, IP address, and session identifier. Records are retained for 365 days.

    5.4 Withdrawal of Consent (DPDP Act, Section 6)

    You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent:

    • Cookie preferences: Manage and withdraw consent through our cookie preferences available on every page
    • Email: Contact our DPO at privacy@tezassolar.com
    • Account Settings: Logged-in users can manage privacy preferences from their privacy dashboard

    6. Legitimate Uses (DPDP Act, Section 7)

    In addition to processing based on your consent, the DPDP Act permits us to process your personal data without consent in certain circumstances recognised as legitimate uses under Section 7.

    Purpose Legal Basis
    Compliance with any law or regulation in force in India Section 7(1) — Compliance with law
    Performance of any function under any law or contract Section 7(2) — Legal obligation
    Employment purposes (hiring, payroll, benefits) Section 7(4) — Employment purposes
    Prevention, detection, or prosecution of fraud Section 7(6) — Fraud prevention

    7. Your Data Principal Rights (DPDP Act, Section 8 - 13)

    Under the DPDP Act, you have the following rights regarding your personal data. We respond to all legitimate requests within 30 days:

    7.1 Right to Access (Section 8)

    You have the right to obtain confirmation as to whether we are processing your personal data, and if so, access to such data along with information about the processing activities.

    Exercise: Visit your privacy dashboard or email privacy@tezassolar.com

    7.2 Right to Correction (Section 9)

    You have the right to correct any inaccurate or incomplete personal data we hold about you.

    Exercise: Update via your profile settings or contact our DPO

    7.3 Right to Erasure (Section 10)

    You have the right to request deletion of your personal data. We will comply unless retention is required by law. Data is anonymized rather than hard-deleted where legal retention applies.

    Exercise: Submit a deletion request from your privacy dashboard or email our DPO

    7.4 Right to Grievance Redressal (Section 13)

    If you are dissatisfied with our response to any data principal request, you have the right to file a grievance with our Grievance Officer. We will respond within 30 days as prescribed under Section 13.

    Exercise: Submit a grievance through our online form

    7.5 Right to Data Portability

    You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON) and to transmit that data to another data fiduciary.

    Exercise: Download your data from your privacy dashboard

    7.6 Right to Withdraw Consent (Section 6)

    As detailed in Section 5.4 above, you may withdraw consent at any time. Processing before withdrawal remains lawful.

    7.7 Right to Nominate (Section 14)

    You have the right to nominate a person who shall, in the event of your death or incapacity, exercise the rights under this Chapter on your behalf.

    How to Nominate

    • Log in to your privacy dashboard and navigate to the "Nominee" section
    • Provide the nominee's full name, email address, phone number, and relationship to you
    • The nominee will receive a verification link — they must confirm acceptance
    • Until acceptance, the nomination remains pending and may be withdrawn or modified at any time

    In the Event of Death or Incapacity

    • Upon your death or certified incapacity, your nominated person may exercise your data rights by providing supporting evidence (death certificate, medical certificate, or legal guardianship order)
    • If no nominee has been appointed, your legal heir may exercise these rights by submitting legal documentation proving their authority

    Where to Submit

    8. Data Retention and Deletion (DPDP Act, Section 5(2))

    Data Category Retention Period Rationale
    Account & profile data 365 days of inactivity Service delivery + legal compliance
    Transaction data 8 years Income Tax Act, 1961
    Support & communication 3 years Service improvement & legal defence
    Cookie/consent logs 365 days Consent audit trail
    Financial records 8 years Legal & tax compliance

    Once the retention period expires, personal data is:

    • Anonymised — names replaced with "Deleted User #ID", emails anonymised
    • Permanently deleted — identifiable data not required for legal retention
    • Archived — data required under legal obligations, with restricted access

    9. Data Sharing and Disclosure (DPDP Act, Section 4(2))

    We share your personal data only with the following categories of recipients:

    Recipient Purpose Data Shared
    Razorpay (payment gateway) Payment processing Order amount, transaction ID, customer name and email
    Solar panel manufacturers & distributors Order fulfillment Name, address, contact details, order specifications
    Installation partners Service delivery Name, address, property details, contact
    Google Analytics Website analytics Anonymised usage data, truncated IP address
    Legal & regulatory authorities Legal compliance As required by law

    We ensure all third-party data processors are contractually obligated to comply with DPDP Act requirements, implement adequate security measures, and process data only on our documented instructions. We do not sell your personal data to any third party.

    10. Cross-Border Data Transfers (DPDP Act, Section 16)

    We process and store all personal data within India on servers located in India. Where third-party services such as Google Analytics operate globally, data transfers are governed by standard contractual clauses ensuring equivalent levels of data protection. We do not transfer personal data to countries outside India except where necessary for service delivery and with appropriate safeguards in place.

    11. Children's Data Protection (DPDP Act, Section 9)

    • Our services are not targeted at children under 18 years of age
    • We do not knowingly collect personal data of children without verifiable parental consent
    • If we discover a child's data collected without appropriate consent, we will immediately delete such data
    • We do not engage in behavioural monitoring or targeted advertising directed at children
    • Any guardian who believes their child's data has been collected should contact our DPO immediately

    12. Data Security Measures (DPDP Act, Section 8)

    We implement reasonable security safeguards to protect your personal data:

    • Encryption in transit: TLS 1.3 for all web traffic (HTTPS)
    • Encryption at rest: AES-256 for sensitive data fields (Aadhaar, PAN)
    • Access controls: Role-based access control — only authorised personnel can access personal data
    • Authentication: Session management with strict timeouts, rate limiting on sensitive endpoints
    • Logging & monitoring: All access to personal data is logged and periodically reviewed
    • Data minimisation: We collect only data necessary for specified purposes
    • Incident response: Documented breach response and notification procedures
    • Security headers: HSTS, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy headers on all pages

    13. Data Breach Notification (DPDP Act, Section 14)

    In the event of a data breach that may cause harm to data principals, we follow these procedures:

    • Internal discovery & containment: Immediate identification and containment of the breach
    • Notification to Data Protection Board: We notify the Board within 72 hours of becoming aware of the breach, including:
      • Nature and extent of the breach
      • Categories of personal data affected
      • Number of data principals affected
      • Contact details of the DPO
      • Mitigation measures taken
    • Notification to affected data principals: Affected individuals are notified immediately after Board notification

    14. Cookies and Tracking Technologies

    We use cookies and similar technologies as described in our cookie preference centre. You can manage your preferences at any time.

    Cookie Purpose Duration Category
    tezassolar_session Session identifier — maintains user session for authentication, cart, and state Session Necessary
    XSRF-TOKEN CSRF protection Session Necessary
    cookie_consent Records your cookie consent choice (accepted/rejected/custom) 1 year Necessary
    privacy_anon_id Anonymous identifier linking consent preferences to your guest session 1 year Necessary
    privacy_reviewed Tracks that you have reviewed the privacy policy notice 1 year Necessary
    darkMode Stores your dark/light mode preference (localStorage) Persistent Functional
    _ga, _gid, _gat, _ga_* Google Analytics — distinguish users, throttle requests, and track campaign data 1 day – 2 years Analytics
    Razorpay session cookies Payment processing session (set by checkout.razorpay.com) Session Necessary

    Note: We do not currently deploy marketing cookies, social media tracking pixels, or third-party advertising cookies. Any future deployment will require your explicit consent.

    15. Contact Information — Data Protection Officer & Grievance Officer

    Under Section 10(1) of the DPDP Act, we have designated a Data Protection Officer (DPO) and Grievance Officer:

    Data Protection Officer

    Email: privacy@tezassolar.com
    TEZAS ENTERPRISES

    Grievance Officer (Section 13)

    For complaints regarding processing of your personal data:
    Submit a Grievance Online
    Or email: privacy@tezassolar.com
    We respond within 30 days as mandated under Section 13(2).

    16. Complaint to Data Protection Board of India

    If you are not satisfied with our response to your grievance within the prescribed period, you have the right to file a complaint with the Data Protection Board of India established under Section 18 of the DPDP Act.

    • The Board is an independent quasi-judicial body tasked with adjudicating data protection disputes
    • You may file a complaint through the Board's official website or designated platform
    • The Board has the power to direct us to take specific actions, including correction, erasure, or compensation
    • Any penalty or compensation imposed by the Board is binding, subject to appeal provisions

    We encourage you to first raise a grievance with us before approaching the Board.

    17. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. When we make material changes, we will notify you through:

    • A prominent notice on our website
    • Email notification to registered users (if the change significantly affects your rights)
    • Updating the "Last Updated" date at the top of this policy

    18. Governing Law and Jurisdiction

    This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (as amended 2025-2026) and the Information Technology Act, 2000.

    Any disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts at Jaipur, Rajasthan.

    DPDP Act 2023/26 Compliance Statement

    TEZAS ENTERPRISES is committed to full compliance with the Digital Personal Data Protection Act, 2023 as amended through 2026. We have implemented the following compliance measures:

    • ✓ Appointed a qualified Data Protection Officer as required under Section 10
    • ✓ Implemented granular consent management with withdrawal mechanism under Section 5 & 6
    • ✓ Legitimate uses processing framework under Section 7
    • ✓ Established a grievance redressal mechanism under Section 13 — respond within 30 days
    • ✓ Data breach notification procedures under Section 14 — Board notified within 72 hours
    • ✓ Children's data protection safeguards under Section 9
    • ✓ Data principal rights framework — access, correction, erasure, portability, nomination under Sections 8-14
    • ✓ Reasonable security practices — encryption, access controls, regular audits under Section 8
    • ✓ Data retention and anonymisation policy
    • ✓ Data collection logging and consent audit trail