PRIVACY POLICY, DATA PROTECTION POLICY & CHILD SAFETY POLICY

ENCRISS DEVICES PRIVATE LIMITED

Effective Date: Aug 7, 2026

This Policy should be read together with the applicable Terms & Conditions, quotation, purchase order acknowledgement, supply agreement, Statement of Work, website terms, and other contractual documents issued or accepted by Encriss Devices Private Limited, as applicable.

1. INTRODUCTION

Encriss Devices Private Limited (“Encriss”, “Company”, “we”, “our”, or “us”) is engaged in the sourcing, procurement, import, distribution, marketing, sale, supply, and support of semiconductors, electronic components, electromechanical parts, industrial electronics, automation hardware, IoT devices, sensors, modules, assemblies, accessories, and other technology products and related business services. We may also provide technical coordination, product identification assistance, sourcing support, integration assistance, prototyping support, and other ancillary services where specifically agreed.

We are committed to protecting personal data, business information, commercially sensitive information, and other information entrusted to us by customers, prospective customers, suppliers, vendors, manufacturers, channel partners, logistics providers, service providers, website visitors, job applicants, employees, consultants, and other persons who interact with us.

This Privacy Policy, Data Protection Policy & Child Safety Policy (“Policy”) explains how Encriss may collect, receive, record, use, process, store, organise, structure, analyse, verify, secure, disclose, transfer, retain, archive, delete, and otherwise handle information in connection with our websites, enquiries, quotations, purchase orders, sales orders, procurement activities, supplier relationships, imports, logistics, invoicing, payment processing, customer service, technical support, business communications, marketing, recruitment, premises access, and other business operations (“Services”).

This Policy is intended to reflect our privacy and data protection practices and shall be interpreted in accordance with applicable law, including the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and applicable rules thereunder, and other privacy, cybersecurity, consumer, corporate, tax, customs, import/export, employment, and sector-specific requirements, in each case to the extent applicable and in force from time to time (“Applicable Law”).

Where Encriss determines the purpose and means of processing personal data, Encriss may act as a data fiduciary or equivalent determining entity under Applicable Law. Where Encriss processes personal data solely on documented instructions of an enterprise customer or another entity, Encriss may act as a processor, service provider, or similar operational party, depending on the relevant arrangement.

2. APPLICABILITY

This Policy applies to information processed by Encriss in connection with its business and Services, including information relating to:

  • customers, prospective customers, distributors, dealers, system integrators, OEMs, contract manufacturers, repair organisations, industrial customers, government or institutional buyers, and their representatives;
  • suppliers, manufacturers, authorised distributors, brokers, sourcing partners, freight forwarders, customs agents, couriers, logistics providers, inspection agencies, testing laboratories, and other vendors;
  • website visitors and persons who submit enquiries, request quotations, download information, subscribe to updates, submit contact forms, or communicate with Encriss through email, telephone, messaging applications, social media, or other channels;
  • employees, consultants, contractors, interns, job applicants, and representatives interacting with Encriss in a business or employment context;
  • persons visiting Encriss offices, warehouses, partner facilities, exhibitions, trade fairs, customer locations, or other business premises where information may be collected for access, security, meeting, or operational purposes;
  • authorised users of any customer, supplier, inventory, CRM, procurement, order-management, support, analytics, or business systems operated or used by Encriss; and
  • any other individual whose personal data is lawfully received or processed by Encriss in connection with the Services or its legitimate business operations.

This Policy does not necessarily apply to third-party websites, platforms, services, marketplaces, payment processors, logistics providers, social-media services, or other external systems that maintain their own privacy policies. Where a third party independently determines how it processes personal data, its own privacy policy and terms shall apply to that processing.

Where a specific contract, data processing agreement, confidentiality agreement, employment policy, supplier agreement, or legally mandated notice contains privacy terms that are more specific to a particular relationship, those specific terms may supplement this Policy. In case of inconsistency, the applicable mandatory law and the specifically agreed written terms shall prevail to the extent of the inconsistency.

3. INFORMATION WE COLLECT

3.1. Business and Contact Information

Encriss may collect identification and business contact information such as name, designation, employer or organisation name, business address, email address, telephone number, mobile number, department, job title, business role, signature, visiting card details, professional profile information, and other information provided for business communication or relationship management.

3.2. Customer Enquiry, Quotation, and Order Information

When a person or organisation requests a quotation, places an order, sends a bill of materials (“BOM”), asks for component sourcing, or seeks technical or commercial assistance, Encriss may collect information including part numbers, manufacturer names, technical specifications, quantities, target pricing, delivery requirements, destination, intended application, alternate-part requirements, packaging preferences, quality or traceability requirements, inspection requirements, project references, drawings, datasheets, notes, correspondence, and other information required to understand and fulfil the request.

3.3. Supplier and Procurement Information

Encriss may collect supplier, manufacturer, distributor, sourcing, and procurement information including business identity, registration details, contact persons, quotations, product availability, source information, certifications, quality records, bank information, tax details, shipping details, manufacturer or distributor references, lead times, transaction history, performance history, and communications necessary to evaluate, onboard, purchase from, pay, monitor, or otherwise manage suppliers and service providers.

3.4. Transaction, Billing, Tax, and Payment Information

We may collect information relating to quotations, purchase orders, order acknowledgements, invoices, debit or credit notes, payment status, bank references, transaction identifiers, tax registrations, GST information, TDS information, PAN or other identifiers where legally required, shipping charges, duties, import costs, freight costs, credit terms, outstanding amounts, and related accounting or commercial records. Encriss generally does not seek to store complete payment-card credentials where payment is handled by a third-party payment processor.

3.5. Logistics, Delivery, and Import/Export Information

For order fulfilment and logistics, we may process consignee names, delivery addresses, contact numbers, shipping instructions, airway bill or tracking information, freight-forwarding details, customs and import/export records, country of origin information, package information, invoice data, KYC information required by carriers or authorities, and other information reasonably necessary for shipment, customs clearance, delivery, return, insurance, or claims handling.

3.6. Technical, Device, and Website Information

When you access our website or electronic systems, we may automatically receive technical information such as IP address, browser type, operating system, device type, approximate network location, referral source, pages visited, date and time of access, session information, cookies, identifiers, server logs, error logs, security logs, and other technical metadata. Such information may be used for functionality, security, analytics, fraud detection, performance monitoring, troubleshooting, and website improvement.

3.7. Communications and Support Information

We may retain business communications exchanged through email, telephone notes, contact forms, messaging applications, collaboration tools, support channels, social media, meetings, video calls, trade exhibitions, or other channels. This may include the substance of enquiries, support requests, complaints, RMA/return discussions, warranty communications, technical clarifications, approvals, meeting notes, and other correspondence.

3.8. Marketing and Preference Information

Where permitted, Encriss may maintain information about business interests, product categories, communication preferences, event participation, marketing consent, subscription preferences, response history, and interactions with promotional or informational communications. Marketing preferences may be changed through available unsubscribe mechanisms or by contacting Encriss.

3.9. Recruitment and Workforce Information

If you apply for employment, consulting, internship, or contractual work, Encriss may collect your resume, employment history, education, professional qualifications, contact information, interview notes, expected compensation, identification documents where required, references, background information lawfully obtained, and other information necessary for recruitment, onboarding, employment administration, security, statutory compliance, or workforce management.

3.10. Premises and Security Information

Where applicable, Encriss may collect visitor logs, access details, meeting details, identification information, vehicle information, CCTV footage, security records, and other limited information for physical security, access management, incident investigation, and protection of persons, products, records, and property.

3.11. Information Received from Third Parties

Encriss may receive information from customers, suppliers, manufacturers, distributors, channel partners, logistics providers, payment providers, credit-information sources, business directories, public registries, trade platforms, exhibition organisers, referral sources, professional networks, government authorities, and other lawful sources. We may combine such information with information already held by Encriss where reasonably necessary for business operations, verification, risk management, legal compliance, or relationship management.

3.12. Sensitive or Unnecessary Personal Data

Encriss does not intentionally request sensitive personal information that is unrelated to the relevant business purpose. Customers, suppliers, visitors, and other persons should avoid providing Aadhaar details, health information, biometric information, financial account credentials, passwords, personal documents, or other sensitive information unless specifically required for a lawful and clearly identified purpose. If such information is received inadvertently, Encriss may delete, restrict, or otherwise handle it in accordance with Applicable Law and operational requirements.

4. CUSTOMER, SUPPLIER, AND BUSINESS DATA

4.1. Ownership and Control of Business Data

Customers, suppliers, and other business partners retain their respective rights in information, documents, specifications, drawings, BOMs, product requirements, commercial records, technical documents, and other materials that they provide to Encriss (“Business Data”), subject to Encriss’s rights and obligations under applicable contracts, this Policy, and Applicable Law.

4.2. Processing of Business Data

Encriss may access, use, process, store, analyse, organise, transmit, reproduce, secure, archive, or otherwise handle Business Data to the extent reasonably necessary to evaluate enquiries, obtain supplier quotations, identify parts, source products, verify availability, prepare commercial offers, process orders, coordinate procurement, arrange imports, manage logistics, fulfil deliveries, provide support, administer warranties or returns, maintain transaction records, prevent fraud, secure operations, comply with law, and protect legitimate business interests.

4.3. Sharing of BOMs, Specifications, and Sourcing Requirements

The nature of component sourcing may require Encriss to share relevant portions of a customer’s BOM, part numbers, manufacturer references, quantity requirements, specifications, drawings, or delivery requirements with manufacturers, authorised distributors, suppliers, brokers, testing providers, logistics providers, or other sourcing partners for the purpose of obtaining availability, pricing, technical confirmation, quality information, lead times, or fulfilment support. Encriss shall seek to limit such disclosure to information reasonably necessary for the sourcing or transaction purpose.

4.4. Confidential and Commercially Sensitive Information

Where Business Data is confidential or commercially sensitive, its use and disclosure may also be governed by applicable confidentiality terms, non-disclosure agreements, quotations, purchase orders, supply agreements, or other contractual arrangements. Nothing in this Policy is intended to reduce any express confidentiality obligation accepted by Encriss in writing.

4.5. Customer and Supplier Personal Data

Where Business Data contains personal data of employees, representatives, agents, customers, suppliers, end users, or other individuals, the organisation providing such data is responsible for ensuring that it has an appropriate lawful basis, authority, notice, or consent for providing that data to Encriss, except to the extent Applicable Law assigns responsibility differently.

5. PURPOSE OF PROCESSING

Encriss may process information for one or more of the following purposes, as applicable to the relationship and subject to Applicable Law:

  • responding to enquiries, requests for quotation (“RFQs”), requests for information, and other business communications;
  • identifying, sourcing, verifying, evaluating, quoting, procuring, importing, stocking, selling, supplying, delivering, returning, replacing, or supporting products;
  • reviewing BOMs, technical specifications, drawings, manufacturer references, alternates, lifecycle information, availability, packaging, and commercial requirements;
  • managing customer, supplier, distributor, manufacturer, partner, and service-provider relationships;
  • creating and administering quotations, purchase orders, order acknowledgements, invoices, shipping documents, credit/debit notes, tax records, returns, warranty claims, and commercial records;
  • conducting supplier onboarding, vendor due diligence, sourcing checks, commercial checks, product verification, quality coordination, traceability checks, and risk management;
  • processing payments, collections, accounting, tax compliance, reconciliation, credit management, and recovery of outstanding dues;
  • arranging freight, courier, warehousing, customs clearance, import/export documentation, delivery, insurance, claims, and related logistics;
  • providing customer service, technical coordination, complaint handling, RMA/return support, warranty coordination, and post-sale assistance;
  • operating, maintaining, securing, analysing, and improving websites, CRM systems, ERP systems, procurement systems, inventory systems, email, communication tools, and other internal business technology;
  • detecting, preventing, investigating, and responding to fraud, misuse, security threats, payment risk, suspicious transactions, counterfeit concerns, policy violations, or unlawful activity;
  • maintaining backups, audit trails, transaction history, security logs, compliance records, business continuity records, and evidence of commercial communications;
  • sending service communications, transactional updates, order updates, product information, business announcements, invitations, newsletters, or marketing communications where permitted;
  • performing business analytics, forecasting, product-demand analysis, customer relationship management, procurement planning, operational improvement, and internal reporting;
  • recruiting, onboarding, managing, and administering employees, consultants, contractors, and applicants;
  • complying with tax, customs, import/export, corporate, accounting, regulatory, judicial, law-enforcement, cybersecurity, and other legal requirements;
  • establishing, exercising, defending, or enforcing contractual or legal rights, including debt recovery, dispute resolution, and investigation of claims; and
  • carrying out any other purpose that is disclosed at the time of collection, is reasonably connected with the original purpose, is consented to, or is otherwise permitted by Applicable Law.

5.1. Consent and Other Lawful Uses

Where Applicable Law requires consent, Encriss may seek consent through written, electronic, digital, contractual, or other legally recognised means. Consent may be withdrawn using the mechanism made available by Encriss or by contacting us, subject to processing that is required or permitted to continue under Applicable Law, contractual necessity, legal obligations, dispute requirements, or other lawful grounds.

5.2. Business Communications

Encriss may send communications necessary to administer an enquiry, quotation, order, payment, shipment, return, warranty, support request, supplier relationship, legal requirement, or other ongoing business relationship. Such transactional or operational communications may continue even if a person has opted out of promotional communications, where necessary for the relevant transaction or lawful purpose.

6. TECHNOLOGY, AUTOMATION, ANALYTICS, AND AI-ASSISTED OPERATIONS

Encriss may use software tools, automation systems, analytics tools, enterprise applications, document-processing tools, CRM/ERP systems, product databases, search tools, cybersecurity systems, and, where appropriate, Artificial Intelligence (“AI”) or Large Language Model (“LLM”) tools to support business operations. Such tools may assist with activities such as classification of enquiries, extraction of part numbers, translation, drafting, document review, analytics, fraud detection, customer support, product research, or internal productivity.

Encriss does not represent that AI-assisted outputs are infallible. Where AI or automated tools are used in connection with technical, commercial, compliance, sourcing, or operational matters, outputs may require human review and verification before reliance. Encriss may modify, replace, restrict, or discontinue particular technology tools as operational requirements change.

Encriss will seek to apply reasonable controls when using external AI or automation providers, including limiting data disclosure where practicable, using available enterprise or privacy configurations, and avoiding unnecessary submission of confidential or sensitive information. However, information processed through third-party technology may be subject to the technical and contractual terms of those providers.

Unless specifically disclosed and permitted, Encriss does not intend to use customer confidential BOMs, private commercial information, or supplier confidential information to train a publicly available AI model for independent purposes unrelated to providing or improving Encriss’s own business operations. Where any materially different AI use is proposed, Encriss may provide an additional notice or obtain consent where required by Applicable Law.

7. COOKIES AND TRACKING TECHNOLOGIES

7.1. Use of Cookies

Encriss websites and online services may use cookies, pixels, local-storage technologies, session identifiers, analytics tools, log files, security technologies, and similar mechanisms. These technologies may be used to remember preferences, maintain sessions, understand website use, measure performance, protect against abuse, identify errors, improve navigation, and support marketing or analytics where permitted.

7.2. Categories of Cookies

Depending on the website configuration, cookies may include strictly necessary cookies, functional cookies, analytics/performance cookies, security cookies, and advertising or marketing cookies. Not all categories will necessarily be used at all times.

7.3. Cookie Choices

Users may be able to control cookies through browser settings, device settings, cookie banners, consent tools, or other preference mechanisms. Blocking certain cookies may affect website functionality, saved preferences, analytics, login sessions, or other features.

7.4. Third-Party Analytics and Links

Where Encriss uses third-party analytics, embedded content, social media links, maps, videos, marketing tools, or similar services, those third parties may collect information in accordance with their own privacy policies. Encriss does not control the independent processing practices of third parties.

8. THIRD-PARTY SERVICES

Encriss may use or engage third-party service providers to operate and support its business. Depending on the activity, these may include:

  • cloud hosting, email, file-storage, collaboration, database, backup, cybersecurity, and IT service providers;
  • CRM, ERP, inventory, accounting, procurement, customer-support, analytics, productivity, automation, and AI software providers;
  • banks, payment service providers, payment gateways, collection partners, accountants, auditors, insurers, and financial service providers;
  • manufacturers, authorised distributors, component suppliers, sourcing partners, inspection agencies, testing laboratories, and technical service providers;
  • couriers, transporters, freight forwarders, customs brokers, warehouses, logistics companies, shipping lines, airlines, insurers, and delivery partners;
  • marketing agencies, website providers, analytics providers, event organisers, trade-fair organisers, communication providers, and social-media platforms;
  • legal advisors, consultants, professional advisors, recovery agents, compliance providers, auditors, and other specialist service providers; and
  • government departments, customs authorities, tax authorities, regulators, courts, law-enforcement agencies, and other authorities where legally required or reasonably necessary.

Third-party providers may process information in India or other jurisdictions. Encriss may enter into contracts, confidentiality obligations, data-processing terms, security arrangements, or other controls with such providers where appropriate to the nature of the processing, the information involved, and Applicable Law.

Encriss is not responsible for the independent privacy practices of third parties where those parties determine their own purposes and means of processing. Users should review relevant third-party privacy notices where appropriate.

9. DATA SHARING

9.1. Sharing for Business Operations

Encriss may share information with authorised employees, directors, group personnel, consultants, contractors, suppliers, manufacturers, distributors, sourcing partners, service providers, logistics providers, banks, payment providers, professional advisors, and other recipients where reasonably necessary for the purposes described in this Policy.

9.2. Sharing for Product Sourcing and Fulfilment

To source or fulfil a product request, Encriss may disclose part numbers, quantities, required manufacturer, specifications, delivery location, packaging or quality requirements, and limited business contact information to potential or confirmed suppliers. Where possible and appropriate, Encriss may avoid disclosing unnecessary customer identity or commercially sensitive information during preliminary sourcing.

9.3. Corporate Transactions

If Encriss is involved in a merger, acquisition, investment, financing, restructuring, sale of business or assets, joint venture, transfer, insolvency process, or similar corporate transaction, information may be disclosed to prospective or actual investors, acquirers, financiers, advisors, or transaction counterparties subject to appropriate confidentiality and legal safeguards.

9.4. Legal, Regulatory, and Protective Disclosures

Information may be disclosed where Encriss reasonably believes disclosure is required or permitted to comply with Applicable Law, court orders, regulatory requests, customs or tax requirements, investigations, law-enforcement requests, cybersecurity incident response, fraud prevention, protection of rights or property, enforcement of contracts, recovery of dues, or protection of users, employees, customers, suppliers, or the public.

9.5. No Sale of Personal Data for Unrelated Consumer Profiling

Encriss does not intend to sell personal data as a standalone commodity to unrelated third parties for their independent consumer profiling or advertising purposes. This does not restrict legitimate sharing with service providers, business partners, corporate transaction counterparties, or authorities for the purposes described in this Policy.

10. DATA SECURITY

10.1. Security Measures

Encriss implements commercially reasonable technical, organisational, physical, operational, and administrative safeguards designed to protect information against unauthorised access, acquisition, disclosure, alteration, misuse, loss, destruction, or compromise. Security controls may vary depending on the nature, sensitivity, volume, location, and business importance of the information and the systems used to process it.

Measures may include, as appropriate:

  • role-based access controls, account permissions, authentication controls, and least-privilege practices;
  • password controls, multi-factor authentication where supported, device security, and endpoint protections;
  • encryption or secure protocols for transmission and, where appropriate, storage;
  • network protections, firewalls, anti-malware controls, monitoring, logging, and security alerts;
  • backup, recovery, business-continuity, and incident-response practices;
  • vendor and service-provider assessment appropriate to the service and data involved;
  • confidentiality obligations, employee awareness, access restrictions, and internal operational controls;
  • physical access restrictions and security measures at offices or other facilities, where applicable; and
  • periodic review, patching, configuration, monitoring, and improvement of security controls.

10.2. No Absolute Security Guarantee

No information system, internet transmission, cloud environment, email system, device, or storage mechanism can be guaranteed to be completely secure. Accordingly, while Encriss uses reasonable safeguards, we cannot warrant absolute security, uninterrupted availability, or immunity from all cyberattacks, unauthorised acts, third-party failures, human error, or events beyond reasonable control.

10.3. Security Incidents

Where Encriss becomes aware of a personal data breach or security incident affecting information under its control, Encriss may investigate, contain, mitigate, remediate, document, and notify affected persons or competent authorities as required by Applicable Law and the circumstances of the incident. Information regarding an incident may be shared with cybersecurity specialists, insurers, legal advisors, law-enforcement agencies, service providers, or regulators where reasonably necessary.

10.4. User Security Responsibilities

Persons interacting with Encriss should use reasonable care when sending confidential or sensitive information, verify recipient addresses before transmission, protect account credentials, use secure devices and networks, and promptly notify Encriss of suspected impersonation, phishing, credential compromise, fraudulent payment instructions, or unauthorised access relevant to an Encriss transaction.

11. DATA PROTECTION POLICY

11.1. Core Data Protection Principles

Encriss seeks to process personal data in a manner that is lawful, fair, transparent, proportionate, and reasonably connected with specified business purposes. Subject to Applicable Law, Encriss seeks to apply the following principles:

  • purpose limitation: process information for identified, lawful, and reasonably related purposes;
  • data minimisation: collect and use information reasonably necessary for the relevant purpose;
  • accuracy: take reasonable steps to maintain accurate and current information where accuracy is material to the purpose;
  • access control and confidentiality: limit access to persons who require the information for authorised purposes;
  • security: implement safeguards proportionate to the nature and risk of the processing;
  • retention limitation: avoid retaining personal data indefinitely where there is no continuing operational, contractual, legal, or legitimate requirement;
  • accountability: maintain appropriate policies, contracts, logs, processes, or records to support responsible processing; and
  • rights and grievance handling: provide mechanisms for applicable data rights and complaints as required by law.

11.2. Data Fiduciary Responsibilities

Where Encriss acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023, Encriss will seek to provide appropriate notice, use personal data for lawful purposes, implement reasonable security safeguards, address personal data breaches as required, facilitate applicable Data Principal rights, and maintain grievance-redressal mechanisms in accordance with Applicable Law.

11.3. Data Processors and Service Providers

Encriss may engage processors or service providers to process personal data on its behalf. Encriss may require such providers to process data for defined purposes, protect confidentiality, apply reasonable security measures, and comply with contractual and legal requirements appropriate to the service.

11.4. Data Accuracy

Customers, suppliers, applicants, and other persons are expected to provide accurate information and update Encriss where material information changes. Encriss may rely on information provided by the relevant person or organisation unless there is a reason to believe it is inaccurate or verification is required by law or business risk.

11.5. Privacy by Design and Operational Controls

Where reasonably practicable, Encriss may incorporate privacy and security considerations into new business processes, systems, integrations, forms, supplier arrangements, and technology deployments, taking into account the nature, scale, sensitivity, and risk of the processing.

12. CUSTOMER, SUPPLIER, AND USER RESPONSIBILITIES

Customers, suppliers, vendors, partners, and other persons providing information to Encriss are responsible for ensuring that they are authorised to provide that information and that their collection, use, sharing, and instructions comply with Applicable Law and applicable contractual obligations.

Without limiting the above, such persons should:

  • avoid providing personal data that is unnecessary for the relevant commercial or operational purpose;
  • obtain required notices, authorisations, permissions, or consents before sharing personal data of employees, customers, end users, or other individuals with Encriss;
  • ensure that product requirements, technical documents, BOMs, drawings, and commercial information supplied to Encriss do not unlawfully infringe third-party rights or contractual confidentiality obligations;
  • ensure that email addresses, telephone numbers, delivery details, tax information, and payment instructions provided to Encriss are accurate and authorised;
  • promptly notify Encriss if information previously supplied becomes inaccurate, outdated, compromised, or subject to a deletion or restriction request that may affect Encriss processing;
  • protect credentials for any portal, shared system, or collaboration tool made available by Encriss;
  • not use Encriss websites, communication channels, systems, or services for unlawful, fraudulent, abusive, harmful, exploitative, or malicious purposes; and
  • comply with applicable export-control, sanctions, customs, procurement, anti-bribery, tax, cybersecurity, privacy, and other laws relevant to the transaction.

Where an enterprise customer instructs Encriss to process personal data on its behalf, that customer remains responsible for its independent obligations as data fiduciary/controller or equivalent determining entity, except to the extent Applicable Law or a written data-processing agreement expressly provides otherwise.

13. CROSS-BORDER PROCESSING

Encriss operates in a supply chain that may involve customers, suppliers, manufacturers, distributors, logistics providers, cloud providers, technology providers, and professional service providers located in India and other countries. Accordingly, information may be accessed, transmitted, stored, backed up, processed, or otherwise handled in jurisdictions outside the location where it was originally collected.

Cross-border processing may occur, for example, when Encriss communicates with overseas semiconductor or electronic-component suppliers, arranges international freight or customs clearance, uses globally hosted cloud or communication services, obtains quotations from international distributors, processes export or import documentation, or receives technical or commercial support from service providers located outside India.

Any cross-border transfer of digital personal data from India shall be subject to restrictions, conditions, or requirements prescribed or notified by the Government of India under Applicable Law. Encriss may implement contractual, organisational, technical, or other safeguards where appropriate to the nature of the transfer and the recipient.

Users acknowledge that privacy and data protection laws may differ between jurisdictions. Where a third-party recipient independently determines its own processing, that recipient may also be subject to the laws and privacy obligations of its jurisdiction.

14. DATA RETENTION

14.1. General Retention Approach

Encriss may retain personal data and Business Data for the period reasonably necessary to fulfil the purposes described in this Policy, perform contractual obligations, maintain commercial and transaction records, comply with legal requirements, support warranty or return obligations, resolve disputes, enforce rights, prevent fraud, maintain security, and satisfy audit, accounting, tax, customs, regulatory, or evidentiary requirements.

14.2. Factors Affecting Retention

Retention periods may differ depending on:

  • the nature and sensitivity of the information;
  • whether the information relates to an active customer, supplier, employee, applicant, visitor, or business relationship;
  • applicable limitation periods, tax, customs, corporate, accounting, import/export, employment, or regulatory requirements;
  • warranty, RMA, quality, traceability, product-liability, recall, or dispute considerations;
  • the need to maintain transaction history, sourcing records, supplier records, pricing records, or evidence of communications;
  • security, fraud-prevention, investigation, or litigation requirements;
  • backup cycles, archival processes, system limitations, and disaster-recovery practices; and
  • contractual commitments or consent, where applicable.

14.3. Deletion, Anonymisation, or Archival

At the end of an applicable retention period, Encriss may delete, destroy, anonymise, de-identify, archive, restrict, or otherwise remove information from active use, subject to technical feasibility, backup cycles, legal holds, contractual requirements, and Applicable Law. Data may remain temporarily in protected backups or archives until overwritten or deleted in accordance with standard retention processes.

14.4. Dormant Enquiries and Marketing Records

Encriss may retain records of past enquiries, quotations, customer or supplier interactions, and marketing preferences for reasonable business periods to maintain relationship history, respond to repeat requirements, honour opt-out preferences, analyse demand, prevent fraud, or support legitimate commercial operations, unless deletion is required by Applicable Law or a valid request is accepted.

15. DATA PRINCIPAL RIGHTS, ACCESS, CORRECTION, DELETION, AND GRIEVANCE REDRESSAL

15.1. Applicable Rights

Subject to Applicable Law and the circumstances of the processing, an individual may have rights relating to personal data processed by Encriss. Such rights may include the right to obtain information about personal data processing, request correction or updating of inaccurate personal data, request erasure where legally applicable, withdraw consent where processing is based on consent, submit a grievance, and exercise rights through a nominee where recognised by law.

15.2. Requests

Requests should contain sufficient information to enable Encriss to identify the requester, understand the request, locate the relevant records, and verify that the requester is entitled to exercise the requested right. Encriss may request reasonable identity or authority verification before disclosing, correcting, deleting, or otherwise acting on personal data.

15.3. Limitations and Exceptions

A request may be denied, limited, deferred, or only partially fulfilled where permitted by Applicable Law, including where information must be retained to comply with law, complete a transaction, maintain tax or customs records, establish or defend legal claims, investigate fraud or security incidents, protect another person’s rights, preserve confidential commercial information, comply with a legal hold, or where the request is otherwise not legally required to be fulfilled.

15.4. Business Records and Data Export

Requests for copies or export of business transaction data, invoices, order history, quotations, BOMs, sourcing records, or supplier records may also be governed by contractual obligations, confidentiality restrictions, third-party rights, technical feasibility, payment status, record-retention requirements, and Encriss’s standard operational procedures. This Policy does not create a general contractual right to obtain Encriss internal sourcing databases, supplier identities, proprietary pricing records, internal margins, confidential supplier terms, or unrelated business records.

15.5. Withdrawal of Consent

Where processing is based on consent, a person may withdraw consent using the method communicated by Encriss or by contacting the privacy/grievance contact specified below. Withdrawal shall not affect the lawfulness of processing completed before withdrawal and may not prevent processing that Encriss is independently required or permitted to continue under Applicable Law.

15.6. Grievance Redressal

A person who has a concern regarding Encriss’s processing of personal data may contact the grievance/privacy contact listed in Section 21. Encriss will seek to acknowledge, review, and respond to legitimate privacy grievances within the period required by Applicable Law. The requester may also have the right to approach the competent authority or Data Protection Board in accordance with Applicable Law after using applicable grievance mechanisms.

15.7. No Charge Except Where Permitted

Encriss generally does not charge a fee for valid statutory data-rights requests. However, where permitted by law, Encriss may refuse manifestly abusive or fraudulent requests or recover reasonable operational costs for non-statutory commercial data extraction, customised reports, archival retrieval, or other services outside the scope of legally mandated rights.

16. CHILD SAFETY POLICY

Encriss Devices Private Limited is primarily a business-to-business supplier of semiconductors, electronic components, industrial electronics, automation hardware, and related technology products. Our Services are intended for businesses, professionals, authorised representatives, and adults capable of entering into commercial arrangements. They are not designed or directed primarily to children.

For purposes of this Policy, “child” shall have the meaning assigned under Applicable Law. Under the Digital Personal Data Protection Act, 2023, a child generally means an individual who has not completed eighteen years of age, subject to any statutory exemptions, notifications, or changes applicable from time to time.

Encriss does not knowingly seek to collect personal data from children for independent marketing, profiling, commercial targeting, or account creation. If a child’s personal data must be processed for a lawful and legitimate purpose, Encriss may require verifiable consent of a parent or lawful guardian and may apply additional safeguards as required by Applicable Law.

Where Encriss becomes aware that personal data of a child has been collected without an appropriate lawful basis or required consent, Encriss may restrict, delete, anonymise, or otherwise remediate the information, subject to legal, security, evidentiary, and technical requirements.

17. PROHIBITED CONTENT OR ACTIVITIES INVOLVING CHILDREN

No person may use Encriss websites, communication channels, systems, business services, products, support channels, file-transfer mechanisms, or other facilities to transmit, request, store, create, promote, distribute, facilitate, or otherwise engage in unlawful, exploitative, abusive, harmful, sexual, violent, deceptive, or inappropriate activity involving a child.

Prohibited conduct includes, without limitation:

  • child sexual abuse material or any content that sexually exploits or depicts the sexual abuse of a child;
  • grooming, coercion, extortion, trafficking, solicitation, sexualisation, or exploitation of children;
  • instructions, communications, or arrangements intended to facilitate unlawful contact with or harm to a child;
  • use of Encriss systems or business communications to conceal, distribute, procure, or facilitate unlawful content involving minors;
  • impersonation, harassment, threats, blackmail, or other harmful conduct targeting children; and
  • any activity involving children that violates Applicable Law, court orders, platform rules, or lawful directions of competent authorities.

Encriss may immediately restrict access, preserve relevant records, suspend communications, terminate a relationship, block a transaction, investigate, or take other protective action where it reasonably suspects prohibited activity involving children.

18. CHILD SAFETY REPORTING

Encriss reserves the right to investigate, review, restrict, preserve, suspend, terminate, report, or cooperate with competent law-enforcement agencies, regulatory authorities, cybersecurity authorities, child-protection authorities, service providers, or other legally authorised bodies in relation to suspected unlawful, abusive, exploitative, harmful, or unsafe activity involving children.

Where Encriss receives a credible child-safety complaint, it may preserve relevant logs, communications, account information, transaction records, device information, or other evidence to the extent reasonably necessary for investigation, legal compliance, reporting, protection of affected persons, or cooperation with authorities.

Nothing in this Policy requires Encriss to independently monitor all customer, supplier, website, or communication activity for child-safety violations where such monitoring is not required by Applicable Law. However, Encriss may use reasonable automated or manual controls to detect abuse, fraud, security incidents, or unlawful activity where appropriate.

19. COMPLIANCE AND LEGAL DISCLOSURES

19.1. Compliance with Law

Encriss may process, preserve, disclose, transfer, or restrict information where necessary to comply with Applicable Law, regulatory requirements, court orders, governmental requests, customs or tax requirements, audit obligations, investigation demands, law-enforcement requests, cybersecurity directions, or other legally valid processes.

19.2. Protection of Legal Rights

Encriss may process and disclose information to establish, exercise, protect, or defend legal and contractual rights, including enforcement of quotations, purchase orders, supply terms, confidentiality obligations, intellectual property rights, payment obligations, warranty terms, return obligations, fraud claims, insurance claims, or other legal interests.

19.3. Fraud, Counterfeit, and Supply-Chain Risk

Because semiconductor and electronic-component transactions may involve fraud, impersonation, payment diversion, counterfeit risk, unauthorised sourcing, sanctions risk, and supply-chain integrity concerns, Encriss may conduct reasonable verification, screening, logging, due diligence, and investigation. Information may be shared with banks, insurers, suppliers, manufacturers, testing organisations, logistics providers, professional advisors, or authorities where reasonably necessary to investigate or prevent such risks.

19.4. Mandatory Disclosure and Confidentiality

Where disclosure is legally required, Encriss may provide only the information reasonably necessary for the lawful request, subject to applicable confidentiality, privilege, statutory restrictions, and the authority of the requesting body. Where legally permitted and appropriate, Encriss may seek clarification, narrowing, protective treatment, or confidentiality for commercially sensitive information.

20. MODIFICATION OF POLICY

Encriss reserves the right to modify, revise, update, supplement, or replace this Policy from time to time to reflect changes in Applicable Law, regulatory guidance, business operations, technology, security practices, product offerings, suppliers, service providers, corporate structure, or data-processing activities.

The updated Policy may be made available through the applicable Encriss website, customer or supplier communication, electronic notice, or other reasonable means. Unless a different date is specified, the updated version shall become effective from the date stated in the revised Policy or upon publication, subject to any consent or advance-notice requirement under Applicable Law.

Where a change materially affects the purpose of processing personal data or otherwise requires fresh consent under Applicable Law, Encriss may provide additional notice or seek consent as required. Continued business interaction after a non-consent-based update may be subject to the revised Policy to the extent permitted by law.

21. CONTACT INFORMATION

Questions, privacy requests, complaints, grievances, child-safety concerns, or data-protection communications relating to this Policy may be addressed to:

CompanyEncriss Devices Private Limited
Authorized RepresentativeSumit Garg
Privacy / Grievance Emailsgarg@encriss.com
Websitehttps://www.encriss.in/
Contact / Correspondence Address1005, 1007, DLF Galleria Tower, DLF Phase IV, Gurgaon - 122009, India
Registered Office1005, 1007, DLF Galleria Tower, DLF Phase IV, Gurgaon - 122009, India

For privacy or grievance requests, the requester should provide sufficient information to identify the relevant relationship or record, but should avoid transmitting passwords, full financial credentials, or unrelated sensitive personal information. Encriss may verify identity or authority before acting on a request.

If Encriss appoints or designates a specific Data Protection Officer, Consent Manager interface, Grievance Officer, or other statutory contact in the future, updated contact information may be published on the applicable website or communicated through an updated version of this Policy.