In accordance with the Digital Personal Data Protection Act, 2023
For the purposes of this Policy, the following terms shall have the meanings assigned to them below:
| Detail | Information |
|---|---|
| Legal Name | Vouchagram India Pvt. Ltd. |
| Trade Name / Brand | GyFTR (www.gyftr.com) |
| Registered Address | 3rd Floor, B-11, Block B, Qutub Institutional Area, New Delhi – 110016, India |
| Website(s) | www.gyftr.com and all associated mobile applications and digital platforms |
| Grievance Officer | Mr. Jasdeep Sokhi |
| Grievance Email | jasdeep.s@gyftr.com |
| Jurisdiction | India |
This Policy applies to all personal data collected, stored, processed, or shared by Vouchagram India Pvt. Ltd. in the course of its business operations. It governs personal data collected through:
For data collected offline or through third parties, users will receive a Notice and consent will be obtained through the channel appropriate to that interaction.
Depending on how you use our services, we may collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity & Contact Data | Full name, email address, mobile number, postal address, date of birth |
| Account & Login Data | Username, password (hashed), authentication tokens, account preferences |
| Transactional Data | Gift voucher purchases, redemption history, payment instrument details (tokenized where applicable), transaction IDs |
| Financial & Sensitive Data | Bank account details and credit/debit card information (collected to process transactions; governed by SPDI Rules 2011 and applicable RBI regulations) |
| Device & Technical Data | IP address, device identifiers, operating system, browser type, app version, usage logs |
| Location Data | Approximate location, where required for service delivery or fraud detection (with your consent where required) |
| Marketing & Preference Data | Communication preferences, opt-in / opt-out records, survey responses |
| Cookies & Tracking Data | Session cookies, persistent cookies, analytics identifiers, pixel tags (see Section 5 below) |
We do not collect personal data beyond what is necessary for the stated purposes. You may choose not to provide certain data, but this may affect your ability to use some of our services.
We use the following categories of cookies on our platforms:
You may manage your cookie preferences at any time through your browser settings or our cookie preference centre. Withdrawing consent for non-essential cookies will not affect your access to core services.
In accordance with Section 5 of the DPDP Act, we will provide you with a clear, plain-language Notice at or before the time we seek your Consent to process your personal data. The Notice will:
Where we had previously collected your personal data before the commencement of the DPDP Act, we will provide you with such a Notice and seek fresh consent as required by applicable law and the transition provisions under the DPDP Rules.
We process your personal data on the basis of your Consent or on the basis of Certain Legitimate Uses as set out in Section 7 of the DPDP Act.
Consent is obtained through an explicit affirmative action, such as:
Consent so obtained shall be: (a) freely given; (b) specific to the stated purpose; (c) informed; (d) unconditional; and (e) unambiguous, in accordance with Section 6(1) of the DPDP Act.
You have the right to withdraw your Consent at any time by adjusting your preferences in your account settings or by writing to our Grievance Officer. Withdrawal of Consent shall not affect the lawfulness of processing carried out prior to such withdrawal, nor shall it restrict our ability to process your data where such processing is otherwise permitted under applicable law.
We process your personal data only for specified, clear, and lawful purposes under the DPDP Act. The table below sets out each purpose and the applicable legal ground:
| Purpose of Processing | Lawful Basis under DPDP Act 2023 |
|---|---|
| Service delivery: providing gift vouchers, gift cards, loyalty programmes, and payment services | Consent — Section 6, DPDP Act |
| Processing payments, fraud detection, and regulatory compliance (e.g., AML/KYC obligations) | Certain Legitimate Use — Section 7(b): Compliance with any law, judgment, or decree of a court or tribunal in force in India |
| Account-related communications (transactional alerts, service notifications) | Consent — Section 6, DPDP Act |
| Marketing and promotional communications (offers, campaigns, newsletters) | Consent — Section 6, DPDP Act (explicit opt-in; you may opt out at any time) |
| Service improvement, product analytics, and user experience research | Consent — Section 6, DPDP Act |
| Responding to legal process, court orders, or regulatory requests | Certain Legitimate Use — Section 7(b): Compliance with legal obligation / judicial order |
| Security monitoring, misuse prevention, and incident response | Certain Legitimate Use — Section 7(b): Compliance with legal obligation; and/or Section 7(h): Purposes in public interest as notified by the State |
| Client satisfaction surveys and feedback collection | Consent — Section 6, DPDP Act |
| Processing data of employees, contractors, and job applicants | Certain Legitimate Use — Section 7(d): Obligations and rights of the Data Fiduciary or the Data Principal under any law relating to employment |
We will retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy our contractual obligations, comply with applicable legal requirements, resolve disputes, and enforce our agreements.
Our retention periods are determined by the nature of the data and the purpose of processing. In general:
Once personal data is no longer required, it will be securely deleted, destroyed, or anonymised so that it can no longer be associated with you. If you request erasure of your personal data, we will comply within the period prescribed under the DPDP Rules (or within thirty (30) days where no such period has been prescribed), subject to any legal obligations requiring us to retain the data.
We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate contractual safeguards:
All Data Processors are required to process personal data only on our documented instructions, and are bound by contractual obligations consistent with the requirements of the DPDP Act.
Personal data shall not be transferred outside the territory of India except to countries or territories notified by the Central Government of India under Section 16 of the DPDP Act. Any such transfer will be made subject to the conditions and safeguards prescribed under the DPDP Act and the DPDP Rules, as amended from time to time.
Until the Central Government publishes the list of notified countries, we will process your personal data primarily within India. In the event any cross-border transfer becomes necessary, we will ensure compliance with the prevailing requirements under the DPDP Act before effecting such transfer.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. Our security framework includes:
| Security Measure | Description |
|---|---|
| Access Control | Access to personal data is granted only to authorized personnel on a strict need-to-know basis; all access is logged and monitored. |
| Data Encryption | Sensitive personal data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256), in compliance with SPDI Rules 2011. |
| Network Security | Firewalls, intrusion detection systems, and secure network architecture are deployed to prevent unauthorized access. |
| Regular Audits | We conduct regular internal and independent security audits and vulnerability assessments. Annual third-party audits are carried out as required under SPDI Rules 2011 (Rule 8(4)). |
| Incident Management | Documented protocols for detecting, reporting, and managing data security incidents, including breach response procedures. |
| Employee Training | Regular data protection and information security training for all personnel with access to personal data. |
| Third-Party Compliance | All Data Processors are contractually required to maintain security standards equivalent to our own. |
| ISO/IEC 27001:2022 | We adhere to the ISO 27001 Information Security Management System (ISMS) framework as an internationally recognized standard. |
| Business Continuity | Tested business continuity and disaster recovery plans to ensure availability of critical systems and data. |
Notwithstanding the foregoing, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we will promptly notify the relevant authorities in the event of a breach as required by law.
In the event of a personal data breach, the Company shall, without undue delay, notify the Data Protection Board of India, in the manner and within the timelines prescribed under Section 25 of the DPDP Act and the DPDP Rules.
Notification to affected Data Principals shall be carried out as directed by the Data Protection Board of India following its assessment of the breach. We will cooperate fully with the Board in any investigation and take all reasonable steps to mitigate the impact of any breach on affected individuals.
As a Data Principal under the DPDP Act, you have the following rights:
To exercise any of the rights above, please contact our Grievance Officer at:
Grievance Officer, Vouchagram India Pvt. Ltd., 3rd Floor, B-11, Block B, Qutub Institutional Area, New Delhi – 110016
We will acknowledge your request promptly and respond within the timelines prescribed under the DPDP Rules. If you are not satisfied with our response, you may register a complaint with the Data Protection Board of India.
We do not knowingly collect or process personal data of children (individuals below the age of 18 years) without obtaining verifiable consent from their parent or lawful guardian, in compliance with Section 9 of the DPDP Act.
When you access or use our services, we will ask you to confirm your age. If you are below 18 years of age, we will seek verifiable consent from your parent or lawful guardian before processing your personal data. Verifiable consent will be obtained through one or more of the following mechanisms:
In accordance with Section 9(3) of the DPDP Act, we shall not:
If we become aware that we have inadvertently collected personal data from a child without the required verifiable parental consent, we will promptly delete such data and may restrict access to our services pending compliance.
Where the Company uses automated processing, including profiling, in a manner that produces decisions with a legal or similarly significant effect on you (for example, fraud scoring or creditworthiness assessments), we will:
In accordance with Section 15 of the DPDP Act, as a Data Principal, you undertake the following duties when interacting with our platforms and services:
Non-compliance with the above duties may constitute a contravention under the DPDP Act and may attract penalties as prescribed therein.
In the event the Company is designated as a Significant Data Fiduciary (“SDF”) by the Central Government under Section 10 of the DPDP Act, the Company shall comply with all additional obligations prescribed thereunder, which may include:
This Section will be updated promptly upon any such designation.
This Policy is governed by and shall be construed in accordance with the laws of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the rules and regulations made thereunder.
The Company may, to the extent relevant to its international operations or contractual obligations, also align its data protection practices with applicable international standards such as the General Data Protection Regulation (GDPR) of the European Union. Nothing in this Policy shall be construed as an express representation of compliance with any foreign law unless otherwise stated in writing by the Company.
This Policy shall be updated to reflect any future amendments to the DPDP Act, rules made thereunder, or other applicable legislation.
Any dispute, controversy, or claim arising out of or relating to this Policy or any breach thereof shall be subject to the exclusive jurisdiction of the competent courts at New Delhi, India.
We may update this Policy periodically to reflect changes in our data processing practices, applicable law, or regulatory guidance. We will notify you of any material changes through:
The “Last Updated” date at the top of this Policy will be revised accordingly. Continued use of our services after the effective date of any revised Policy will constitute your acceptance of the changes, to the extent permitted by law.
If you have any questions, concerns, or complaints regarding this Policy or our data processing practices, please contact our Grievance Officer:
| Contact | Details |
|---|---|
| Grievance Officer | Mr. Jasdeep Sokhi |
| jasdeep.s@gyftr.com | |
| Postal Address | Vouchagram India Pvt. Ltd., 3rd Floor, B-11, Block B, Qutub Institutional Area, New Delhi – 110016, India |
| Response Time | We will acknowledge your complaint within 3 working days and endeavor to resolve it within the timelines prescribed under the DPDP Rules. |
If your complaint is not resolved to your satisfaction by our Grievance Officer, you have the right to register a complaint with the Data Protection Board of India (DPBI) at the link / address notified by the Board from time to time.