Privacy Notice

Privacy Notice

Last updated: 22 August 2026

ASMA is committed to handling personal data responsibly and is aligning its practices with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 in accordance with the Government of India’s notified commencement timeline.

1. Who we are

ASMA is a partnership firm operating the website asma.net.in. GSTIN: 29ABMFA4610P1ZZ. Customer care: customercare@asma.net.in | +91 80500 77460.

2. Personal data we may collect

Depending on how you use our website and services, we may collect your name, email address, telephone number, billing or delivery address, account details, order and transaction information, payment confirmation or payment reference information provided by payment processors, appointment preferences, messages and support enquiries, job-application information and resumes, device/browser information, IP address, cookie and similar technology data, and records of privacy or marketing choices and consent.

3. Why we use personal data

We use personal data to process and deliver orders; provide customer support; manage accounts, appointments and enquiries; process recruitment applications; prevent fraud and protect our website; comply with tax, accounting and other legal obligations; improve essential website functionality; and, where required, send marketing or use optional analytics, advertising or personalisation technologies only on an appropriate legal basis or with consent.

4. Consent and choice

Where consent is required, it should be specific to the stated purpose and not bundled with unrelated purposes. Optional marketing, analytics, advertising and personalisation choices should remain optional. You may withdraw consent at any time without affecting processing already lawfully carried out before withdrawal. Where available, cookie and tracking preferences can be changed through Your Privacy Choices.

5. Cookies and similar technologies

Essential cookies may be used to operate the storefront, cart, checkout, security and account functions. Non-essential analytics, advertising or personalisation technologies should not be activated before any consent required by applicable law has been obtained. Browser controls alone are not intended to replace an applicable consent mechanism.

6. Who may receive personal data

We may disclose data only as necessary to Shopify and storefront infrastructure providers, payment processors, delivery and logistics partners, communications and customer-support providers, IT and security providers, professional advisers, analytics or advertising providers where appropriately permitted, and public authorities where disclosure is required by law. We do not sell personal data as a business practice.

7. Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, tax, accounting, fraud-prevention, dispute-resolution or record-keeping requirements. Marketing data is retained until consent is withdrawn or the purpose ends, subject to maintaining a minimal suppression record where necessary. Recruitment data is retained only for the recruitment process or longer where a separate lawful basis applies. Consent, rights-request and security records may be retained as necessary to demonstrate compliance and resolve disputes.

8. Your rights

Subject to applicable law, you may request access to information about your personal data, correction or updating of inaccurate or incomplete data, erasure where applicable, withdrawal of consent, and grievance redressal. Rights that become applicable under the DPDP Act and Rules will be provided in accordance with the Government’s notified commencement dates. You can submit a request through our Data Rights Request page.

9. Children

Where legally required, persons under 18 should use our services with the involvement and verifiable consent of a parent or lawful guardian. We do not intend to use children’s personal data for tracking or behavioural monitoring, targeted advertising, or processing likely to cause a detrimental effect to a child.

10. International processing

Shopify and some service providers may process information outside India. Such processing and transfers are subject to applicable Indian law, including any restrictions notified by the Government of India, and appropriate contractual and security safeguards.

11. Security

We use reasonable technical and organisational safeguards appropriate to the nature of the data and the risks involved. No internet service can guarantee absolute security. Please do not send passwords, full payment-card details or other unnecessary sensitive information through general enquiry forms.

12. Grievance Officer and privacy contact

Mr. Adarsh Gupta
Email: adarshgupta1234@gmail.com
Phone: +91 98861 32044
Address: No. 54, SVP Arcade, Ground Floor, next to Passport Office Lane, Sudhamanagar, Bengaluru 560027, Karnataka, India.

You may also use our Grievance Redressal Policy and Data Rights Request page.

13. Changes to this notice

We may update this Notice when our practices, technology or applicable law changes. The current version and update date will be published on this page.


Legal review required: This Notice forms part of ASMA’s proactive DPDP compliance programme. Its legal wording, retention schedule, children’s-data position, international-processing language and grievance procedure should be reviewed by qualified Indian privacy counsel as additional DPDP provisions and Rules become effective.