Privacy Policy
Last Updated: July 20, 2026
Compliant with: Digital Personal Data Protection Act, 2023 (DPDP Act) as amended 2026
1. Scope and Application
This Privacy Policy describes how TEZAS ENTERPRISES ("we", "us", "our") collects, uses, processes, stores, and protects your personal data when you visit our website, use our services, or interact with us. This policy applies to all users of our website, services, and products (collectively, "Services").
This policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and subsequent amendments through 2026. We process your personal data in accordance with the principles of lawful, fair, and transparent processing as mandated by Section 4 of the DPDP Act.
3. Categories of Personal Data We Collect (DPDP Act, Section 4 & 5)
We collect the following categories of personal data, only when necessary for specified purposes:
3.1 Data You Provide Directly
- Identity Data: Full name, email address, phone number, date of birth, gender
- Contact Data: Email address, phone number, alternate phone number, shipping/billing address
- Financial Data: GST number, PAN card, Aadhaar number (encrypted), bank account details, annual income, monthly electricity bill — credit/debit card information is processed entirely by Razorpay (our payment gateway) and never stored by us
- Property Data: Property address, property type (residential/commercial/industrial), electricity bill details, roof type, roof area, roof direction, current electricity consumption in units
- Identity Documents: Government-issued ID proofs uploaded for verification (Aadhaar, PAN) — stored encrypted via AES-256
- Professional Data: Occupation, company name, years of experience, expected salary (collected during career applications)
- Communication Data: Messages sent via our contact form, email correspondence, support ticket messages, blog comments
- Career Data: Name, email, phone, resume/CV, cover letter when applying for positions
- Nominee Data: Name, email, phone, relationship of your nominated person under DPDP Act Section 14
- Location Data: Precise geolocation (latitude/longitude) of installation sites for project planning
- Usage Data: Pages visited, time spent on pages, referring URLs, browser type and version, operating system, device type
- Technical Data: IP address, cookies and similar tracking technologies, session identifiers
- Location Data: Approximate location derived from IP address
- Payment Processors: Razorpay provides us with transaction status and masked payment details — we never receive full card numbers
- reCAPTCHA: Google reCAPTCHA v3 is used on our contact and registration forms for spam prevention (subject to Google's privacy policy)
- Analytics: Google Analytics provides aggregated usage statistics
- Installation Partners: With your explicit consent, we share necessary data with our installation partners for service delivery
- We present a clear cookie consent banner on your first visit with options to Accept All, Reject All, or Customize preferences
- Consent is obtained through an unambiguous affirmative action — silent browsing or inaction does not constitute consent under the DPDP Act
- Consent notices are in English and presented in clear, plain language
- Necessary (Strictly Required): Essential for website functionality — session management, CSRF protection, security. These cannot be disabled.
- Functional: Enable preferences such as dark mode and region settings.
- Analytics: Track aggregated usage patterns via Google Analytics to improve our Services.
- Marketing: Reserved for future use — no marketing cookies are currently deployed.
- Social Media: Reserved for future use — no social media tracking scripts are currently deployed.
- Cookie preferences: Manage and withdraw consent through our cookie preferences available on every page
- Email: Contact our DPO at privacy@tezassolar.com
- Account Settings: Logged-in users can manage privacy preferences from their privacy dashboard
- Log in to your privacy dashboard and navigate to the "Nominee" section
- Provide the nominee's full name, email address, phone number, and relationship to you
- The nominee will receive a verification link — they must confirm acceptance
- Until acceptance, the nomination remains pending and may be withdrawn or modified at any time
- Upon your death or certified incapacity, your nominated person may exercise your data rights by providing supporting evidence (death certificate, medical certificate, or legal guardianship order)
- If no nominee has been appointed, your legal heir may exercise these rights by submitting legal documentation proving their authority
- Online: Through the privacy dashboard
- Email: To our DPO at privacy@tezassolar.com with subject "Data Principal Nominee Request"
- Anonymised — names replaced with "Deleted User #ID", emails anonymised
- Permanently deleted — identifiable data not required for legal retention
- Archived — data required under legal obligations, with restricted access
- Our services are not targeted at children under 18 years of age
- We do not knowingly collect personal data of children without verifiable parental consent
- If we discover a child's data collected without appropriate consent, we will immediately delete such data
- We do not engage in behavioural monitoring or targeted advertising directed at children
- Any guardian who believes their child's data has been collected should contact our DPO immediately
- Encryption in transit: TLS 1.3 for all web traffic (HTTPS)
- Encryption at rest: AES-256 for sensitive data fields (Aadhaar, PAN)
- Access controls: Role-based access control — only authorised personnel can access personal data
- Authentication: Session management with strict timeouts, rate limiting on sensitive endpoints
- Logging & monitoring: All access to personal data is logged and periodically reviewed
- Data minimisation: We collect only data necessary for specified purposes
- Incident response: Documented breach response and notification procedures
- Security headers: HSTS, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy headers on all pages
- Internal discovery & containment: Immediate identification and containment of the breach
- Notification to Data Protection Board: We notify the Board within 72 hours of becoming aware of the breach, including:
- Nature and extent of the breach
- Categories of personal data affected
- Number of data principals affected
- Contact details of the DPO
- Mitigation measures taken
- Notification to affected data principals: Affected individuals are notified immediately after Board notification
- The Board is an independent quasi-judicial body tasked with adjudicating data protection disputes
- You may file a complaint through the Board's official website or designated platform
- The Board has the power to direct us to take specific actions, including correction, erasure, or compensation
- Any penalty or compensation imposed by the Board is binding, subject to appeal provisions
- A prominent notice on our website
- Email notification to registered users (if the change significantly affects your rights)
- Updating the "Last Updated" date at the top of this policy
- ✓ Appointed a qualified Data Protection Officer as required under Section 10
- ✓ Implemented granular consent management with withdrawal mechanism under Section 5 & 6
- ✓ Legitimate uses processing framework under Section 7
- ✓ Established a grievance redressal mechanism under Section 13 — respond within 30 days
- ✓ Data breach notification procedures under Section 14 — Board notified within 72 hours
- ✓ Children's data protection safeguards under Section 9
- ✓ Data principal rights framework — access, correction, erasure, portability, nomination under Sections 8-14
- ✓ Reasonable security practices — encryption, access controls, regular audits under Section 8
- ✓ Data retention and anonymisation policy
- ✓ Data collection logging and consent audit trail
3.2 Data Collected Automatically
3.3 Data from Third Parties
3.4 Special Categories of Personal Data
We do not collect sensitive personal data (health information, biometric data, genetic data, caste, religious beliefs, political opinions, or sexual orientation). Aadhaar and PAN data are collected only for government solar subsidy applications and tax compliance, and are stored with encryption at rest (AES-256) as required under Section 7 of the DPDP Act.
4. Purpose and Lawful Basis of Processing (DPDP Act, Section 4 & 5)
We process your personal data only for the following specified purposes:
| Purpose | Data Categories Used | Lawful Basis |
|---|---|---|
| Service delivery & solar installation | Identity, Contact, Property | Consent / Contract performance |
| Quotation & billing | Identity, Contact, Financial | Consent / Contract performance |
| Customer support & communication | Identity, Contact, Communication | Consent / Legal obligation |
| Solar subsidy processing | Identity, Financial (Aadhaar/PAN) | Consent / Legal obligation |
| Fraud prevention & security | Technical, Usage, Identity | Legitimate interest / Legal obligation |
| Website analytics | Usage, Technical | Consent |
| Legal compliance & audit | Identity, Financial, Communication | Legal obligation |
5. Consent Management (DPDP Act, Section 5 & 6)
Your consent is the basis for our processing activities. We implement a granular consent management system:
5.1 Obtaining Consent
5.2 Consent Categories
We classify cookies into the following categories:
5.3 Consent Records
Every consent action is timestamped and logged in our privacy consent database, recording: the consent category, your choice (accepted/rejected), the consent version, IP address, and session identifier. Records are retained for 365 days.
5.4 Withdrawal of Consent (DPDP Act, Section 6)
You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent:
6. Legitimate Uses (DPDP Act, Section 7)
In addition to processing based on your consent, the DPDP Act permits us to process your personal data without consent in certain circumstances recognised as legitimate uses under Section 7.
| Purpose | Legal Basis |
|---|---|
| Compliance with any law or regulation in force in India | Section 7(1) — Compliance with law |
| Performance of any function under any law or contract | Section 7(2) — Legal obligation |
| Employment purposes (hiring, payroll, benefits) | Section 7(4) — Employment purposes |
| Prevention, detection, or prosecution of fraud | Section 7(6) — Fraud prevention |
7. Your Data Principal Rights (DPDP Act, Section 8 - 13)
Under the DPDP Act, you have the following rights regarding your personal data. We respond to all legitimate requests within 30 days:
7.1 Right to Access (Section 8)
You have the right to obtain confirmation as to whether we are processing your personal data, and if so, access to such data along with information about the processing activities.
Exercise: Visit your privacy dashboard or email privacy@tezassolar.com
7.2 Right to Correction (Section 9)
You have the right to correct any inaccurate or incomplete personal data we hold about you.
Exercise: Update via your profile settings or contact our DPO
7.3 Right to Erasure (Section 10)
You have the right to request deletion of your personal data. We will comply unless retention is required by law. Data is anonymized rather than hard-deleted where legal retention applies.
Exercise: Submit a deletion request from your privacy dashboard or email our DPO
7.4 Right to Grievance Redressal (Section 13)
If you are dissatisfied with our response to any data principal request, you have the right to file a grievance with our Grievance Officer. We will respond within 30 days as prescribed under Section 13.
Exercise: Submit a grievance through our online form
7.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON) and to transmit that data to another data fiduciary.
Exercise: Download your data from your privacy dashboard
7.6 Right to Withdraw Consent (Section 6)
As detailed in Section 5.4 above, you may withdraw consent at any time. Processing before withdrawal remains lawful.
7.7 Right to Nominate (Section 14)
You have the right to nominate a person who shall, in the event of your death or incapacity, exercise the rights under this Chapter on your behalf.
How to Nominate
In the Event of Death or Incapacity
Where to Submit
8. Data Retention and Deletion (DPDP Act, Section 5(2))
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account & profile data | 365 days of inactivity | Service delivery + legal compliance |
| Transaction data | 8 years | Income Tax Act, 1961 |
| Support & communication | 3 years | Service improvement & legal defence |
| Cookie/consent logs | 365 days | Consent audit trail |
| Financial records | 8 years | Legal & tax compliance |
Once the retention period expires, personal data is:
9. Data Sharing and Disclosure (DPDP Act, Section 4(2))
We share your personal data only with the following categories of recipients:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Razorpay (payment gateway) | Payment processing | Order amount, transaction ID, customer name and email |
| Solar panel manufacturers & distributors | Order fulfillment | Name, address, contact details, order specifications |
| Installation partners | Service delivery | Name, address, property details, contact |
| Google Analytics | Website analytics | Anonymised usage data, truncated IP address |
| Legal & regulatory authorities | Legal compliance | As required by law |
We ensure all third-party data processors are contractually obligated to comply with DPDP Act requirements, implement adequate security measures, and process data only on our documented instructions. We do not sell your personal data to any third party.
10. Cross-Border Data Transfers (DPDP Act, Section 16)
We process and store all personal data within India on servers located in India. Where third-party services such as Google Analytics operate globally, data transfers are governed by standard contractual clauses ensuring equivalent levels of data protection. We do not transfer personal data to countries outside India except where necessary for service delivery and with appropriate safeguards in place.
11. Children's Data Protection (DPDP Act, Section 9)
12. Data Security Measures (DPDP Act, Section 8)
We implement reasonable security safeguards to protect your personal data:
13. Data Breach Notification (DPDP Act, Section 14)
In the event of a data breach that may cause harm to data principals, we follow these procedures:
14. Cookies and Tracking Technologies
We use cookies and similar technologies as described in our cookie preference centre. You can manage your preferences at any time.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| tezassolar_session | Session identifier — maintains user session for authentication, cart, and state | Session | Necessary |
| XSRF-TOKEN | CSRF protection | Session | Necessary |
| cookie_consent | Records your cookie consent choice (accepted/rejected/custom) | 1 year | Necessary |
| privacy_anon_id | Anonymous identifier linking consent preferences to your guest session | 1 year | Necessary |
| privacy_reviewed | Tracks that you have reviewed the privacy policy notice | 1 year | Necessary |
| darkMode | Stores your dark/light mode preference (localStorage) | Persistent | Functional |
| _ga, _gid, _gat, _ga_* | Google Analytics — distinguish users, throttle requests, and track campaign data | 1 day – 2 years | Analytics |
| Razorpay session cookies | Payment processing session (set by checkout.razorpay.com) | Session | Necessary |
Note: We do not currently deploy marketing cookies, social media tracking pixels, or third-party advertising cookies. Any future deployment will require your explicit consent.
15. Contact Information — Data Protection Officer & Grievance Officer
Under Section 10(1) of the DPDP Act, we have designated a Data Protection Officer (DPO) and Grievance Officer:
Data Protection Officer
Email: privacy@tezassolar.com
TEZAS ENTERPRISES
Grievance Officer (Section 13)
For complaints regarding processing of your personal data:
Submit a Grievance Online
Or email: privacy@tezassolar.com
We respond within 30 days as mandated under Section 13(2).
16. Complaint to Data Protection Board of India
If you are not satisfied with our response to your grievance within the prescribed period, you have the right to file a complaint with the Data Protection Board of India established under Section 18 of the DPDP Act.
We encourage you to first raise a grievance with us before approaching the Board.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through:
18. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (as amended 2025-2026) and the Information Technology Act, 2000.
Any disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts at Jaipur, Rajasthan.
DPDP Act 2023/26 Compliance Statement
TEZAS ENTERPRISES is committed to full compliance with the Digital Personal Data Protection Act, 2023 as amended through 2026. We have implemented the following compliance measures: