Introduction & Scope
Our commitment to data protection and compliance
Additya Exports ("we," "us," "our") operates the website www.addityaexports.com as a B2B jewelry manufacturer serving business clients globally. This Privacy Policy governs all personal and business data collected through our Site, emails, or orders, ensuring compliance with GDPR (EU/UK), CCPA/CPRA (California), UK Data Protection Act 2018, and other international data protection laws.
Data Collection
What information we collect from our business clients
Business Information
Full company name, registered address, tax identification numbers (EIN/VAT/GST), business license copies, and trade references. Banking/payment details for transaction processing.
Personal Data of Representatives
Names, job titles, corporate email addresses, phone numbers, and professional signatures of individuals acting on behalf of client businesses.
Automated/Technical Data
IP addresses, device identifiers, browser types, and operating systems. Website usage patterns (pages visited, session duration) via cookies and analytics tools like Google Analytics.
Transactional Data
Order histories, custom design specifications, invoices, shipping records, and communication logs.
Data Usage
How we process and utilize your information
Order Fulfillment
To process orders, manufacture jewelry, manage shipping, and issue invoices.
Client Communication
To respond to inquiries, provide quotes, and share production updates.
Site Improvement
To optimize website functionality and user experience based on analytics.
Legal Compliance
To meet tax, customs, and anti-fraud regulations across jurisdictions.
B2B Marketing
To send product catalogs or promotions to existing clients (opt-out always available).
Legal Basis
GDPR/UK compliance and processing justification
Contractual Necessity
Processing data to fulfill orders and payment obligations.
Legitimate Interests
Using client contact details for direct B2B marketing or fraud prevention.
Legal Obligations
Retaining invoice data for tax audits.
Explicit Consent
Required for non-essential cookies or promotional emails to new prospects.
Data Sharing
Third-party partnerships and international transfers
Third Parties
We share data only with payment gateways (e.g., Stripe) for transaction processing, logistics partners (e.g., DHL/FedEx) for shipping, and cloud hosting providers (e.g., AWS) with servers in Germany/US.
Cross-Border Transfers
Data transferred outside the EU/UK to India is safeguarded via GDPR Standard Contractual Clauses (SCCs). US transfers comply with CCPA requirements.
Security Measures
How we protect your data and respond to breaches
Technical Safeguards
AES-256 encryption for data at rest and in transit, firewalls, and regular penetration testing.
Organizational Protocols
Role-based access controls, mandatory employee training, and confidentiality agreements with all processors.
Breach Response
Notification to regulators within 72 hours (GDPR) and affected clients if high risk exists.
Your Rights
Control and access to your personal information
Access/Portability
Request a copy of your data in machine-readable format.
Correction
Update inaccurate business/personal details.
Erasure
Delete non-essential data (excludes legal/tax records).
Object/Restrict
Halt processing for marketing or legitimate interests.
Withdraw Consent
Opt out of emails or cookies anytime.
How to exercise your rights: Submit requests to addityaexports@gmail.com with business verification.
Data Retention
How long we keep your information
Active Clients
Data retained for 7 years after the last transaction for legal/tax purposes.
Inquiries/Prospects
3 years from last contact if no order is placed.
Website Logs
12 months for security monitoring.
Custom Designs
10 years to protect intellectual property rights.
Cookies & Tracking
Our use of cookies and analytics technologies
Essential Cookies
Required for login sessions and shopping cart functionality.
Analytical Cookies
Anonymized usage tracking via Google Analytics (opt-out via cookie banner).
Marketing Cookies
Used only with prior consent for retargeting ads.
Policy Updates
Policy changes will be notified via email 30 days in advance. Continued use of our services after updates constitutes acceptance of the revised terms.