Data Privacy Policy

Aligned to the Digital Personal Data Protection Act, 2023 (DPDPA) · Touchstone Enterprises Private Limited ("OffiNeeds"). This Policy explains how OffiNeeds (operated by Touchstone Enterprises Private Limited) collects, uses, shares, retains and protects personal data, and the rights available to you as a Data Principal under the Digital Personal Data Protection Act, 2023 and its Rules.

1. Scope & our role

This Policy applies to personal data we process through our websites, brand stores, corporate-gifting platforms (KitUp, Rewards, GiftKart, BrandStore, Corporate Gifts), applications, and business operations.

(a) As a Data Fiduciary

  • Where we determine the purpose and means of processing (e.g. our own customers, website visitors, account holders, vendors, employees).

(b) As a Data Processor

  • Where we process personal data on behalf of and under instruction from a client Data Fiduciary, for example corporate-gifting recipient lists provided by a corporate client to fulfil and deliver gifts. In such cases the client is the Data Fiduciary; we process only per a written Data Processing Agreement.
Privacy Illustration

2. Key terms

Data Principal The individual to whom the personal data relates (for a child, the parent/lawful guardian).
Personal Data Any data about an individual who is identifiable by or in relation to such data.
Data Fiduciary The person/entity that determines the purpose and means of processing personal data.
Data Processor A person/entity that processes personal data on behalf of a Data Fiduciary.
Processing Any operation on personal data — collection, storage, use, sharing, erasure, etc.

3. Personal data we collect

Identity & contact Name, email, phone, billing/delivery address, organisation, designation.
Gifting / recipient data Recipient name, delivery address, phone/email, gift preference, occasion, message (often provided by a corporate client).
Transaction data Orders, invoices, payment references (we do not store card numbers; payments are handled by PCI-DSS payment gateways).
Account & usage Login credentials (hashed), preferences, support tickets, and technical/usage logs, cookies.

We practise data minimisation — we collect only what is necessary for the stated purpose.

4. Purposes & lawful basis

We process personal data on the basis of your consent, or for legitimate uses permitted under the DPDPA (e.g. a purpose for which you voluntarily provided data, or to fulfil a legal obligation). Purposes include:

  • Creating and managing accounts; processing and delivering orders and corporate gifts;
  • Customer support, communication and service notifications;
  • Payments, invoicing, tax and statutory compliance;
  • Security, fraud prevention and platform integrity;
  • Service improvement and internal analytics (no automated decision-making with legal effect; no AI processing of customer data in the gifting platforms).

5. Notice & consent

Where we rely on consent, we present a clear notice at or before collection describing the personal data, the purpose, and how to exercise your rights. Consent is requested through a clear affirmative action (e.g. ticking an unticked box) and is free, specific, informed, unconditional and unambiguous, limited to the data necessary for the stated purpose.

Withdrawing consent: you may withdraw consent at any time — as easily as it was given — by contacting privacy@offineeds.com or using the controls in your account. Withdrawal does not affect processing already carried out, and we will stop further processing and erase data unless retention is legally required.

The notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.

6. When we act as a Data Processor (client gifting data)

When a corporate client (the Data Fiduciary) provides recipient personal data for gifting, we process it strictly to fulfil that engagement, under a written Data Processing Agreement. We do not use it for our own purposes, do not further share it except with delivery/logistics sub-processors necessary for fulfilment, and erase or return it on completion or on the client's instruction. The client is responsible for issuing notice and obtaining consent from the Data Principals.

7. Sharing & disclosure

We do not sell personal data. We may share it only with:

  • Sub-processors / service providers: logistics & courier partners, payment gateways, cloud hosting, email/SMS providers — bound by confidentiality and processing terms.
  • Legal: where required by law, regulation, or a lawful authority request.

8. Data retention & erasure

We retain personal data for a period of 1 year from the date of collection or last interaction, or for as long as necessary for the purpose for which it was collected, whichever is applicable, unless a longer period is required by law (e.g. tax/accounting records). Corporate-gifting recipient data processed on a client's behalf is retained until fulfilment plus a window of up to 1 year for delivery queries/returns, after which it is erased or returned. On expiry of the 1-year retention period, or once the purpose is served and no legal retention applies, we erase the data.

9. Security safeguards

We implement reasonable technical and organisational measures, including TLS 1.3 encryption in transit and encryption at rest, role-based access control (least privilege) with MFA, edge protection (WAF/DDoS), centralised security monitoring (SIEM / file-integrity monitoring), patching and vulnerability management, and an ISO/IEC 27001:2022-certified ISMS.

10. Children's data

Our services are intended for adults and businesses. We do not knowingly process the personal data of children (under 18) without verifiable parental/guardian consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

11. Your rights as a Data Principal

  • Access — a summary of the personal data we process and our processing activities;
  • Correction, completion & updating of inaccurate or incomplete data;
  • Erasure of personal data no longer necessary for the purpose;
  • Grievance redressal — a readily available means to raise concerns;
  • Nomination — to nominate another individual to exercise your rights in the event of death or incapacity;
  • Withdraw consent at any time.

To exercise any right, contact our Grievance Officer (below). We respond within the period prescribed under the DPDPA Rules.

12. Grievance redressal

If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India as provided under the DPDPA.

13. Breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDPA and our Incident Response procedure (ISMS-IR / CERT-In timelines).

14. Changes to this Policy

We may update this Policy from time to time. The current version and its effective date are published on our website.

Your data, your control. We prioritise your privacy in every interaction.

×

Unlock customised, hassle-free gifting solutions tailored just for you!

75+

DEDICATED PARTNERS

21+

YEARS OF EXPERIENCE

2K+

LOGISTIC PARTNERS

2K+

HAPPY CUSTOMERS

Trusted by Industry Leaders

Decades of trusted performance seen in the iconic brands we serve chosen by industry leaders for our reliability, our dedication, and the results we consistently deliver.