1 · What we collect
To accept an order from you, we need three categories of data:
- Identity — your name, role, and Aadhaar attestation (received via DigiLocker XML — we never see the Aadhaar number in cleartext).
- Entity — your organisation's legal name, GSTIN, Udyam or LLPIN/CIN, PAN, and signed letterhead authorisation.
- Transactional — your shipping address, contact phone/email, order history, payment records (handled by Razorpay; we don't store card or UPI VPAs).
2 · Why we collect it
Three lawful purposes:
- Verify that the buyer is a legitimate organisation entitled to procure restricted-SKU items under the IT Act 2000, Wireless Telegraphy Act 1933, DGCA Drone Rules 2021 and DPDPA 2023.
- Issue a compliant GST invoice, register UIN for any >250 g drones we ship, and maintain audit-grade order records for 8 years per GST Act §35.
- Provide post-sale support, RMA handling, and warranty claims.
3 · How long we keep it
- KYC artefacts (DigiLocker XML, GSTN match record, signed letterhead, PAN) — retained 8 years from order completion per GST Act audit window.
- Order + invoice records — same 8-year window.
- WhatsApp / email correspondence — 90 days post order completion, then deleted.
- Form submissions that don't become orders — 90 days, then deleted.
4 · Who we share it with
We share data only where the law requires or the order requires:
- Razorpay — payment processing (PCI-DSS compliant, KYC fields are not shared).
- DigiLocker — Aadhaar attestation flow only.
- GSTN — GSTIN lookup only.
- DGCA / WPC / sectoral regulators — for UIN registration on drones above 250 g, as required.
- Logistics partners (Bluedart, FedEx, India Post for select PSU pin codes) — shipping address only.
We do not sell, license, or rent personal data. Period.
5 · Your rights under DPDPA 2023
You have the right to:
- Confirmation that we are processing your data + a summary of what we hold.
- Correction of inaccurate data + completion of incomplete records.
- Erasure once the legal-retention window (above) has expired.
- Grievance escalation to our Data Protection Officer, then to the DPDPA Board.
- Nominate a representative to exercise these rights on your behalf.
6 · How to exercise your rights
Email sales@trikaldarshi-labs.in with the subject "DPDPA request". We respond within 7 calendar days. Our DPO is Sunny Kashyap (founder) — no separate hat for this in our 18-person team.
7 · Cookies + analytics
We run Cloudflare Web Analytics — cookieless, no personal-data export. We don't use Google Analytics, Facebook Pixel, or third-party trackers. The only cookies we set are session cookies for your account state and a td-theme preference cookie that remembers your theme choice locally — that one never leaves your browser.
Last updated · 2026-05-05 · this notice will move with the law.