
This Privacy Policy (“Policy”) was updated on 1st March 2026 (“Effective Date”).
This Privacy Policy (“Policy”) is issued by HYPE APPAREL VENTURES (OPC) PRIVATE LIMITED (“The Designer Hype” or “Company”), a company incorporated under the laws of India and having its registered office at A-13, Wazipur Industrial Area, North West Delhi- 110052, which owns and operates the website www.thedesignerhype.com and its relevant mobile application (“The Designer Hype ” or “Company”).
The Designer Hype is an e-commerce platform that curates and showcases exclusive, community-driven, and culturally relevant products in the domains of fashion, sneakers, lifestyle collectibles, and designer-led collaborations. It enables users to explore, purchase, and engage with curated collections, while also inviting resellers and creators to contribute, showcase, and collaborate with the brand.
This Policy governs the collection, use, storage, processing, and disclosure of personal data of all individuals interacting with the Platform, including but not limited to customers, users, collaborators, and resellers. The Policy reflects The Designer Hype’s commitment to upholding the rights of individuals and its obligation to adopt responsible, transparent, and secure data practices.
This Policy is formulated in accordance with the provisions of the Digital Personal Data Protection Act, 2023 (“DPDPA”), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and such other rules, regulations, and guidelines as may be applicable. It is also guided by internationally recognised privacy principles, including purpose limitation, data minimisation and data security.
The Policy reflects the Company’s enduring commitment to ensure that all personal data is processed fairly, lawfully, and in a manner that respects the privacy rights of individuals and upholds the principles of integrity, confidentiality, and accountability.
WHEREAS
NOW THEREFORE, HYPE APPAREL VENTURES (OPC) PRIVATE LIMITED hereby adopts this Privacy Policy to provide a clear, lawful, and user-centric framework for the collection, processing, storage, use, disclosure, and protection of personal data, thereby reinforcing its commitment to data privacy and regulatory compliance. By accessing, browsing, using the Platform, via website or its application, submitting any personal data voluntarily, or otherwise engaging with the services of The Designer Hype, each user is deemed to have read, understood, and agreed to be bound by this Privacy Policy, and to adhere to the rights and obligations set out herein.
1.1. Definitions: In this Policy (including the recitals above hereto), except where the context otherwise requires, the following words and expressions shall bear the meaning assigned to them below:
shall be subject to obligations of confidentiality, data security, and regulatory compliance as prescribed under applicable law.
1.2. Interpretation
(i) Users who access, browse, or interact with any part of the website, irrespective of account creation whose session-based or cookie-related data is collected during their interaction with the Platform;
(ii) Registered customers who make purchases or create user profiles on the Platform;
(iii) Resellers, vendors, or business partners who submit information for the purposes of onboarding, verification, collaboration, or fulfilment;
(iv) Designers, artists, creative collaborators, and contributors who engage with the Platform through product design, promotion, or creative representation;
(v) Personal Data collected through both online and offline channels, including but not limited to customer interactions, surveys, feedback forms, product inquiries, email communications, social media interactions, and payment gateways;
(vi) Third parties acting on behalf of the Company (such as logistics providers, payment processors, marketing affiliates, or cloud service providers), to the extent that they process Personal Data under the Company’s instructions and authority;
(vii) Personal Data processed in India, as well as data collected from Users outside India but processed or stored in India, subject to applicable local and cross-border data transfer laws.
(i) Aggregated or anonymised information that does not, directly or indirectly, identify an individual;
(i) Data submitted directly to courier partners, affiliate service providers, or external applications used in conjunction with the Platform but governed by their own privacy practices;
(ii) Third-party websites, platforms, or applications which may be linked from the Company’s Platform but are not owned or operated by the Company. Users are encouraged to review the privacy policies of such third-party services independently;
(iii) Data that is collected or processed for purely personal, household, or journalistic purposes by individuals and is exempted under the provisions of the Digital Personal Data Protection Act, 2023.
Company and any Data Principal (such as employees, vendors, or consultants), the provisions offering higher privacy protection shall prevail, unless otherwise required by applicable law.
(i) Data voluntarily submitted by users during registration, checkout, communication, or onboarding;
(ii) Data automatically collected from the user’s browser, device, or activity on the Platform; (iii) Data obtained from third-party integrations or external platforms used to support the Designer Hype’s functionality;
(iv) Data inferred or derived through behavioural patterns, interaction history, and system analytics.
| Mode | Description | Examples | Typical Use Cases |
Voluntarily Provided | Information directly submitted bythe user through forms, registrations,submissions, or communication. | Account creation,checkout, newslettersign-up, reseller
onboarding, contactforms, event RSVPs. | Creating user accounts, submitting business details, subscribing to communication. |
| Automatically Collected | Data captured by systems, browsers,or devices during user interactionwith the Platform. | Cookies, deviceidentifiers, IPaddress, sessionanalytics,
clickstream, cartabandonment patterns. |
Website interaction tracking, improvingperformance, fraud detection, analytics. |
Social login data
Information obtained through
Collected from
(e.g., Google, Meta), payment gateway
Login via third-party providers, processing
Third Parties
external service providers, tools, or integrations.
status, influencer links, courier tracking data.
Wishlist trends, repeat purchase
payments, affiliate and referral tracking.
Behavioural targeting,
Derived or
Data analytically generated based on
analysis, likelihood
personalisation, product
Inferred Data
existing data and behaviour patterns.
of churn or engagement, profile preference tags.
recommendations,
feature improvements.
| CATEGORY | DESCRIPTION | SOURCE |
| Identity Data | Full name, username, gender, date of birth, profile photo (if provided), user ID | User during account registration or checkout |
| Contact Data | Email address, mobile number, billing address, shipping address | checkout forms, account registration |
| Payment and Financial Data | Credit/debit card number (masked), UPIID, bank account details (limited), billingtransaction ID, payment timestamps | Payment gateway, order processing |
| Order and Transaction Data | Purchase history, order ID, cart items, delivery tracking number, mode of payment | Platform backend, logistics partners |
Device & Technical Data Usage Data Marketing & Communication Data Account Credentials Social Media Data | IP address, browser type, device type, operating system, screen resolution, timezone, device identifiers Browsing behaviour, clickstream, pages visited, time spent, items added to cart or wishlist Newsletter opt-in, promotional preferences, communication logs, feedback or responses Hashed passwords, OTP verification records, login timestamps Public profile name, email ID, or linked account data when logged in via social platforms | Automatically via website or app Analytics tools, cookies User entries, CRM tools Registration & login systems Facebook, Google login integrations |
| CATEGORY | DESCRIPTION | SOURCE |
| Customer Support Data | Chat transcripts, service tickets, complaint records, call recordings (if applicable) | Helpdesk tools, email/chat support |
| Location Data (if any) | Approximate geolocation or delivery location via IP or GPS (when permitted by the user) | Device/browser during use |
| Referral or Affiliate Data | Referral codes, influencer coupon usage, and affiliate tracking URLs | Marketing platforms |
| User-Generated Content | Product reviews, comments, feedback, testimonials, and uploaded media (images/videos) | Platform, user interaction |
| PURPOSE OF PROCESSING | CATEGORY OF PERSONAL DATA INVOLVED | LEGAL BASIS UNDER DPDPA |
| To process, fulfil and deliver orders | Identity Data, Contact Data, Payment Data, Transaction Data, Location Data | Performance of contract; Consent |
| To provide account registration and login functionality | Identity Data, Account Credentials, Contact Data | Consent; Legitimate use |
To communicate order updates and service-related information
Contact Data, Order Data, Transaction Data
Legitimate use; Performance of contract
To personalise user experience and Usage Data, Device Data, Consent (via
| recommend products | Purchase History | cookies); Legitimate use |
| To conduct marketing campaigns and send promotional content | Contact Data, Marketing Preferences, Purchase History | Explicit Consent |
| To conduct customer satisfaction surveys, reviews, and feedback | Contact Data, Usage Data, Review Content | Consent |
| To provide customer service and resolve complaints | Contact Data, Order Data, Support Data | Legitimate use; Performance of contract |
To detect and prevent fraud, abuse or policy violations To comply with applicable legal, regulatory and tax requirements | Identity Data, Device Data, Transaction Data Identity Data, Transaction Data, Payment Data | Legitimate use; Legal obligation Legal obligation |
To maintain records for audit, dispute resolution, internal record keeping and risk management | Identity Data, Transaction Data, Payment Data, Contact Data | Legal obligation; Legitimate interest |
To improve website performance, analytics, internal reporting, products and services To process influencer codes, affiliate marketing programs, promotional emails, special offers | Usage Data, Device Data, Aggregated Non-Personal Data Referral Data, Identity Data, Transaction Data | Consent (via cookie consent); Legitimate use Consent; Performance of contract |
To publish and moderate user-generated content such as reviews or testimonials | User-Generated Content, Identity Data (where public), Feedback Data | Consent |
(i) Consent of the Data Principal: Where the Company collects Personal Data directly from a User or Data Principal, it shall do so after obtaining the individual’s free, specific, informed, unconditional, and unambiguous consent through clear affirmative action.
Examples:
(ii) The User may withdraw consent at any time through the settings panel, opt-out links, or by contacting the Grievance Officer. Such withdrawal shall not affect any prior lawful processing.
(iii) Performance of a Contract: The Company may process Personal Data where such processing is necessary to fulfil its obligations under a contract with the Data Principal or to take steps at their request before entering into a contract.
Examples:
(iv) Compliance with Legal Obligations: The Company may process Personal Data where it is legally required to do so under applicable laws, court orders, or regulations, including requirements imposed by government or law enforcement agencies.
Examples:
or applicable consumer laws.
(v) Legitimate Use (as permitted under Section 7 of the DPDPA, 2023): The Company may process Personal Data without consent for certain “legitimate uses” as explicitly provided under the DPDPA, including but not limited to:
LEGITIMATE USE CATEGORY | EXAMPLE |
Voluntary Data Provided by User | User submits details for placing an order or contacting customer support |
| Provision of Benefit or Service | Delivering a purchased product or issuing an invoice |
| Legal Proceedings or Dispute Resolution | Defending legal claims, enforcing contractual rights |
| Public Interest or PublicOrder | Co-operating with investigations, law enforcement or public safety officials |
| Employment or InternalAdministration | Processing employee/vendor data for internal compliance or record-keeping |
(vi) The Company ensures that any reliance on legitimate use does not override the fundamental rights and expectations of the Data Principal and is consistent with the purpose limitation and necessity principles.
(vii) Public Interest or Public Health (If Applicable): In exceptional circumstances such as pandemics or emergencies, the Company may process Personal Data in the interest of public health, subject to applicable statutory permissions or directions from government authorities.
(viii) Where Personal Data is collected indirectly or through third-party service providers, the Company ensures that such third parties have obtained appropriate legal basis (including consent) for sharing such data with the Company. A list of categories of third parties (including their names, where applicable) with whom Personal Data may be shared is set out below. These third parties are contractually obligated to maintain the confidentiality and security of the data and to process such data strictly in accordance with applicable law and instructions issued by the Company.
| CATEGORY | PURPOSE OF PROCESSING | THIRD PARTY NAME(S) | TYPE OF DATA SHARED |
Payment Processors Shipping &Logistics Partners | To facilitate securepayments To deliver orders and providetracking | Razorpay, Paytm,Cashfree, PhonePe,Stripe Nimbuspost,
Delhivery,
Shiprocket, Bluedart, Ekart | Name, contact,transaction ID, masked card/bankinfo Name, contact,address, orderdetails |
Email & SMS Communication
To send order updates, alerts, and promotional
messages
Mailchimp,
Sendinblue,
Gupshup, Twilio
Email, phone number,
communication logs
Web Hosting & Website operation, Hostinger, AWS, Device metadata, IP
| CATEGORY | PURPOSE OF PROCESSING | THIRD PARTY NAME(S) | TYPE OF DATA SHARED |
| Infrastructure | backups, andperformance | Cloudflare, DigitalOcean | address, access logs |
| Marketing andRetargeting Tools | Online advertising,analytics, andpromotional campaigns | Meta (Facebook),Google Ads,
Instagram, Hotjar,CleverTap | IP address, browsing
behavior, cookies |
| Customer SupportTools | Customer querymanagement andticketing | Freshdesk, Zoho Desk, Intercom | Name, contact, chatlogs, order info |
Analytics &Tracking Providers Affiliate/Influencer Platforms | Monitor websiteusage and improveservices Track referral codes,commissions | Google Analytics,Facebook Pixel,
Microsoft Clarity Impact.com,
Refersion, custominfluencer codes | IP, session data, page visits, clicks Referral ID, couponusage, transaction
data |
CA firms, Legal
Internal
Consultants & Auditors
Government or Legal Authorities
Legal, tax, or compliance
purposes
Legal compliance, law enforcement
counsel,
Compliance
auditors (on retainer)
Income Tax Dept., Police, Consumer Forums
Financial, order, and sometimes user data
Any legally mandated personal data, upon request
(ix) The Company maintains detailed internal records of the legal basis applicable to each processing activity, and such records are reviewed periodically to ensure compliance.
(x) In cases where the legal basis for processing changes (e.g., from contract to consent), the Company shall notify the Data Principal and, where required, obtain fresh consent before proceeding.
(i) Account registration;
(ii) Checkout and payment stages;
(iii) Subscription to newsletters or marketing communications;
(iv) Participation in contests, surveys, or referral programs;
(v) Accepting cookies and similar tracking technologies on the website.
(i) The purpose of data collection;
(ii) The categories of data collected;
(iii) Whether the data will be shared with third parties;
(iv) A link to this Privacy Policy;
(v) Contact details of the Grievance Officer.
(i) Users have the right to refuse consent for optional features (such as marketing communications) without affecting their access to essential services (such as ordering products).
(ii) Any conditional consent that ties unrelated services or benefits to the provision of Personal Data is not enforced by the Company, unless reasonably necessary for the functioning of such services.
(i) The Data Principal may withdraw consent at any time, without any adverse consequences, by:
(i) The Company shall cease processing the concerned Personal Data within a reasonable time, unless required to retain it under law;
(ii) Certain services may become unavailable to the User where such services are dependent on the withdrawn data.
(i) The Company does not knowingly collect Personal Data from individuals below the age of 18 years without verifiable parental or guardian consent as required under Section 9 of the DPDPA, 2023.
(ii) If the Company becomes aware that Personal Data of a minor has been collected without lawful parental consent, such data shall be promptly deleted.
(i) The Company uses cookies and similar technologies for enhancing User experience, analytics, and targeted advertising.
(ii) Consent for cookies is obtained through a cookie banner that allows Users to:
(iii) The Company honors the User’s tracking preferences and provides information on how to modify or withdraw cookie preferences in its Cookie Policy.
(i) Users may modify their consent preferences at any time by visiting their My Account > Privacy Settings section or by contacting customer care.
(ii) The Company periodically prompts Users to review and confirm their consent preferences to ensure continued alignment with their expectations and legal requirements.
(i) It is necessary for delivering a service explicitly intended for child users; and
(ii) Verifiable parental or guardian consent has been obtained through acceptable means, such as a digitally signed declaration or validated OTP-based consent process.
(i) Promptly delete such Personal Data from its systems; and
(ii) Notify the parent or guardian, if identifiable, of such deletion.
(i) Accept all cookies;
(ii) Reject non-essential cookies;
(iii) Manage preferences granularly by category.
the specified purposes. A summary of categories of Third Parties with whom data may be shared, and the purpose of sharing, is set out in Section 5(a)(viii) above.
(i) Payment gateways and processors – to facilitate secure payment transactions; (ii) Shipping and logistics providers – to deliver products to customers;
(iii) Cloud hosting and IT infrastructure providers – to securely store and manage Platform data;
(iv) Marketing, analytics, and advertising tools – to run campaigns and personalise content;
(v) Customer support and CRM tools – to resolve service requests and complaints; (vi) Auditors, legal counsel, tax advisors – for regulatory, dispute, or audit purposes; (vii) Government authorities or law enforcement – when required under applicable laws or court orders.
(viii) Affiliate marketing and referral partners – to track referrals, influencer codes, and campaign performance.
(ix) Retargeting and personalised advertising platforms – to deliver interest-based advertisements across websites and social media.
(x) Analytics and performance monitoring tools – to understand usage patterns, improve features, and track system performance (e.g., Google Analytics).
(xi) Communication and messaging platforms – to manage transactional emails, SMS, voice calls, and customer notifications (including via third-party APIs).
(xii) User authentication and access management providers – to verify identity and manage secure account login and session activity.
(xiii) Product testing and development service providers – to conduct usability testing, feature deployment, and technical troubleshooting.
(xiv) Affiliates and group entities – to ensure coordinated service delivery and shared business operations under common control.
(xv) Business partners – to jointly offer or promote co-branded products, services, events, or incentives.
(xvi) M&A or corporate transaction parties – in connection with mergers, acquisitions, investments, restructuring, or sale of business assets.
(i) As of the effective date of this Policy, the Company stores and processes all Personal Data on servers located within India. However, certain third-party tools and service providers may process data on infrastructure located outside India, subject to appropriate legal safeguards.
(ii) Any transfer of Personal Data outside India (if required in the future) shall be conducted in accordance with Section 16 of the Digital Personal Data Protection Act, 2023, and any rules or government-issued notifications relating to cross-border transfers.
(iii) The Company shall ensure that any such transfers are made:
(iv) No Sale of Personal Data: The Company does not sell, rent, trade, or otherwise monetize Personal Data of its users or customers to any third party for direct commercial gain.
(v) Aggregated and Anonymised Data: The Company may share anonymised or aggregated data (which does not identify an individual directly or indirectly) with business partners, advertisers, or research agencies for the purpose of market analysis, trend detection, or improving services. Such data is outside the scope of “Personal Data” as defined under applicable law.
(vi) Due Diligence and Oversight: The Company undertakes vendor due diligence and executes appropriate data processing agreements or confidentiality undertakings with all Third Parties who receive or process Personal Data, ensuring that:
disclosed, or reused in an insecure manner;
iii. Users are advised to log out from shared or public systems and update
passwords periodically
iii. Submits or uploads objectionable, abusive, harmful, fraudulent, or misleading content, including fabricated user reviews or impersonated identities.
iii. Use any automated tools or scripts (e.g., bots, scrapers, crawlers) without prior written consent from the Company.
iii. Receipt of fraudulent communications impersonating the Platform.
iii. Reposting or syndicating it via the Designer Hype’s social media or partner platforms.
iii. Remove any UGC without prior notice at its sole discretion.
iii. Through channels approved by the user, such as email, SMS, WhatsApp, or push notifications.
iii. Writing directly to the Company at the contact email provided in this Policy.
(i) Fulfil the purpose for which it was collected;
(ii) Comply with legal or regulatory obligations;
(iii) Resolve disputes, enforce contracts, or defend legal claims;
(iv) Maintain records for auditing, taxation, or business continuity purposes.
CATEGORY OF DATA | TYPICAL RETENTION PERIOD | LEGAL/OPERATIONAL BASIS |
Identity and Contact Data | 3 years from last activity ortransaction | Statutory limitation period for claims, customer support |
Order and Transaction Data | 8 years from date of transaction | Income Tax Act, accounting and audit requirements |
Payment and Financial Data (masked) Customer Support and Complaint Logs | Retained as per Payment Aggregator Guidelines (RBI) 3 years from last contact | Regulatory requirements and fraud detection Dispute resolution and quality assurance |
Marketing Preferences and Opt-in Data Analytics and Usage Data (pseudonymised) | Until withdrawal of consent or inactivity beyond 2 years 12–18 months from date of collection | Consent-based processing Internal performance and improvement analysis |
CATEGORY OF DATA | TYPICAL RETENTION PERIOD | LEGAL/OPERATIONAL BASIS |
Account Credentials | Until account is deleted or deactivated | Contractual necessity for user authentication |
Unused or Dormant Account Data | 2 years of inactivity (with 30-day prior notice before deletion) | Data minimisation and retention compliance |
Aggregated DataRetained indefinitelyOutside scope of “Personal Data”
Anonymised or
under DPDPA
Note: The above periods are subject to change in case of any legal proceedings, enforcement actions, or statutory hold directives.
(i) Permanently deleted from all systems (active and backup); or
(ii) Anonymised or de-identified in a way that prevents re-identification of the Data Principal.
The Company ensures that deletion is performed in a secure manner using industry-standard sanitization or erasure methods.
(i) A Data Principal may request deletion of their Personal Data where:
(ii) Such requests will be honored subject to legal and contractual retention obligations and shall be responded to within a reasonable period as prescribed under the DPDPA, 2023.
and storage practices to ensure compliance with evolving legal standards and operational needs. Any changes to retention durations will be notified through an update to this Policy.
(i) End-to-end encryption of sensitive data during transmission (SSL/TLS protocols); (ii) Hashing and salting of passwords;
(iii) Firewalls and intrusion detection systems for network monitoring;
(iv) Access control policies based on role and need-to-know;
(v) Secure APIs and encrypted payment gateways;
(vi) Multi-factor authentication (MFA) for administrative and system access;
(vii) Logging and monitoring of access to sensitive systems;
(viii) Regular vulnerability assessments and penetration testing (VAPT);
(ix) Frequent security patching and system updates.
(i) Nature and categories of Personal Data af ected;
(ii) Number of individuals impacted;
(iii) Date and time of the breach (estimated and confirmed);
(iv) Likely consequences or harm;
(v) Actions taken to mitigate risks and limit damage;
(vi) Contact information of the Grievance Of icer or point of contact;
(vii) Instructions for Users on how to protect themselves.
(i) Level 1 – Minor: No sensitive data involved, minimal or no risk;
(ii) Level 2 – Moderate: Involves contact or identity data, limited exposure; (iii) Level 3 – Critical: Involves sensitive personal data, financial data, or a large number of individuals, with potential for significant harm.
Only Level 2 and Level 3 breaches require mandatory external notification.
| RIGHT | DESCRIPTION | TIMELINE FORRESPONSE | HOW TO EXERCISE THIS RIGHT |
| Right to Access | To know whether theCompany processesyour Personal Dataand requests detailssuch as categories,purpose, recipients,and retention period. |
Within 15 working days
| Email a request tosupport@thedesignerhype.com. or useyour account dashboard (if available). |
| RIGHT | DESCRIPTION | TIMELINE FORRESPONSE | HOW TO EXERCISE THIS RIGHT |
| Right toCorrection | To request correction,updating, orcompletion ofinaccurate, outdated, or incompletePersonal Data. |
Within 10 working
days
| Submit a correction request with validsupporting documents tosupport@thedesignerhype.com. |
Right to Erasure Right toWithdraw Consent Right toGrievance Redressal Right toNominate | To request deletion ofPersonal Data that isno longer necessary,has been unlawfullyprocessed, or afterconsent withdrawal. To withdrawpreviously given
consent for specificdata processingactivities. To file a complaintregarding delay,denial, misuse, or
mishandling ofPersonal Data ornon-fulfilment ofrights. To nominate anotherindividual to exerciseyour rights under this
Policy in the event ofyour death orincapacity. |
Within 15 working
days
Immediate upon confirmation
Acknowledgement in
48 hrs, resolution in 7
working days
As per Company
records
| Send a deletion request via email tosupport@thedesignerhype.com. withidentity verification. Use opt-out links in emails or write to support@thedesignerhype.com. specifying the consent to withdraw. Email your grievance to the Grievance
Officer at
support@thedesignerhype.com. Send a signed nomination form or declaration via email tosupport@thedesignerhype.com. |
| Right to BeInformed | To receive clear,accessible informationon data collection,legal basis, purpose,rights, third-partydisclosures, andpolicy changes. |
Continuous right
| Review this Privacy Policy regularlyand subscribe to update notificationsvia email or the Platform. |
the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the IT Rules, 2011, the Company has appointed a Grievance Officer to ensure proper handling of grievances related to Personal Data.
(i) Denial or delay in fulfilling your data rights;
(ii) Misuse, unauthorized access, or mishandling of your Personal Data;
(iii) Withdrawal of consent not being respected;
(iv) Violation of any terms of this Privacy Policy;
(v) Any breach of applicable data protection laws;
Email: support@thedesignerhype.com.
Address: A-13 Wazirpur industrial area -110052
Working Hours: Monday to Friday, 10:00 AM to 6:00 PM IST
| STAGE | ACTION | TIMELINE |
| Acknowledgement | The Grievance Officer will acknowledge receipt of your complaint. | Within 48 hours |
| Initial Review | Assess completeness and legitimacy of the grievance. | Within 2 working days |
Investigation and Resolution | Conduct internal inquiry, coordinate with relevant departments, resolve issues. | Within 7 working days |
Notification of Outcome | Communicate resolution decision or status update to the complainant. | Within 10 working days total |
e) If you are dissatisfied with the resolution provided by the Grievance Officer or if no response is received within the prescribed period, you have the right to escalate the matter to the Data Protection Board of India under Section 13(2) of the Digital Personal Data Protection Act, 2023.
FORCE MAJEURE
The Company shall not be held liable for any failure or delay in performing its obligations under this Privacy Policy, including the processing of rights requests or breach notifications, due to circumstances beyond its reasonable control. Such events may include natural disasters, war, civil unrest, pandemic, governmental actions, electricity or internet outages, cyberattacks, or other force majeure events. During such periods, the Company will take reasonable steps to mitigate the impact and restore normal operations as soon as practicable.
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts located in New Delhi, India, without regard to conflict of law principles.
(i) Prominent notices on the Platform;
(ii) Email communication to registered Users (where applicable); and
(iii) Updates to the “Last Updated” date at the top of this Policy.
Users are encouraged to periodically review this Policy to stay informed of how their Personal Data is protected.
Grievance Officer
Email: support@thedesignerhype.com.
Address: A-13 Wazirpur industrial area 110052
Working Hours: Monday to Friday, 10:00 AM to 6:00 PM IST
By continuing to access or use the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. Your continued use of the services constitutes your consent to the collection, processing, and disclosure of your Personal Data in accordance with this Policy.
This Privacy Policy shall remain in effect until it is updated, superseded, or revoked by the Company.
******
ANNEXURE A
DATA BREACH RESPONSE FRAMEWORK & TIMELINE
| STAGE | ACTION | TIMELINE |
| 1. Detection & Containment | Identify and verify the breach, isolate affected systems | Within 6 hours of detection |
| 2. Preliminary Risk Assessment | Assess scope, type of data affected, sensitivity, and potential impact | Within 12 hours of detection |
| 3. Internal Escalation | Notify Compliance Officer, Data Protection Officer, and senior management | Within 12 hours |
| 4. Reporting to Authorities | Notify CERT-In and/or the Data Protection Board of India, where applicable | Within 6 hours of confirming the breach (as per CERT-In guidelines) |
| 5. Notification to Individuals | Inform affected Data Principals of the nature of the breach, risk, and mitigation steps | Within 48 hours, where risk of harm is high |
| 6. Remedial Action | Contain breach, patch systems, reset credentials, and prevent recurrence | Immediate, completed within 72 hours |
| 7. Documentation & Audit Trail | Record breach details, investigation logs, and corrective measures taken | Within 7 days of incident |
| 8. Final Report & Policy Update | Root cause analysis and review of internal policies/training | Within 15 days of breach |