Data Protection & GDPR/DPDP Compliance Policy
Review our policies and learn more about how we handle your information and provide our services.
Last updated: October 2025
At WizzyWeb Private Limited (“we,” “our,” “us”), we take the privacy and protection of your personal data seriously. This policy explains how we comply with the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act (DPDP), 2023 of India, and how we ensure your data is handled responsibly and securely.
1. Purpose of This Policy
This document outlines our practices for collecting, processing, storing, and protecting personal data in compliance with GDPR (EU Regulation 2016/679) and India’s DPDP Act. It applies to all users, clients, and partners who interact with our Services.
2. Data We Collect
We collect and process the following categories of data:
- Identity Information: Name, company, designation.
- Contact Information: Email, phone number, address.
- Usage Data: Website activity, device information, IP address.
- Billing & Transaction Data: Payment method, invoice details (if applicable).
3. Lawful Basis for Processing (GDPR Article 6)
We process personal data under one or more of the following lawful bases:
- Consent: When you voluntarily provide data or subscribe to our newsletters.
- Contractual Necessity: To deliver our products or services as agreed.
- Legitimate Interest: To improve services, enhance security, or prevent fraud.
- Legal Obligation: To comply with applicable laws or respond to lawful requests.
4. User Rights (GDPR Articles 12–23 / DPDP Sections 11–18)
Depending on your jurisdiction, you have the right to:
- Access and request a copy of your personal data.
- Rectify inaccuracies or update information.
- Withdraw consent at any time.
- Request deletion (Right to be Forgotten).
- Restrict or object to processing.
- Request data portability (for EU residents).
- Nominate another individual to exercise your rights under the DPDP Act, 2023 on your behalf in the event of your death or incapacity (Section 14).
To exercise any of these rights, please email support@wizzyweb.com with the subject “Data Rights Request.”
5. Data Retention
We retain personal data only as long as necessary for business, legal, or compliance purposes. When no longer required, data is securely deleted or anonymized.
6. International Data Transfers
Your personal data may be stored or processed in India or other jurisdictions. Under India’s DPDP Act, 2023, cross-border transfer of personal data is permitted except to countries or territories restricted by the Central Government of India by notification. Where we transfer data to the European Economic Area or process data of EU residents, we additionally rely on GDPR-recognised safeguards such as adequacy decisions or Standard Contractual Clauses.
7. Data Security Measures
We employ advanced technical and organizational security measures, including:
- Encrypted data storage and transmission (SSL/TLS)
- Regular vulnerability assessments
- Limited employee access based on role
- Secure data centers and backups
8. Data Breach Notification
In the event of a data breach, we will:
- Notify affected individuals and authorities within the time limits required by law.
- Take immediate steps to mitigate any potential damage.
9. Data Processor and Sub-Processor Relationships
We may use trusted third-party providers (e.g., hosting, analytics, payment gateways). Each is vetted to ensure compliance with GDPR and DPDP Act requirements, with Data Processing Agreements (DPAs) in place.
10. Children’s Data
Our Services are not intended for individuals under the age of 18 (“children”), as defined under the Digital Personal Data Protection Act, 2023. We do not knowingly collect personal data from children without verifiable consent from a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that we have collected a child’s personal data without such consent, we will delete it promptly. If you believe a child has provided us with personal data, please contact us using the details in the Grievance Redressal section below.
11. Data Protection Officer (DPO)
For compliance inquiries, you may contact our Data Protection Officer:
Data Protection Officer
WizzyWeb Private Limited
Email: privacy@wizzyweb.com
Registered Office: Gurugram, India
12. Grievance Redressal
If you have any complaints or concerns regarding how your personal data is processed, you may contact our Grievance Officer:
Grievance Officer
WizzyWeb Private Limited
Email: grievance@wizzyweb.com
We will acknowledge and address your grievance within a reasonable timeframe. If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023.
13. Updates to This Policy
We may update this Data Protection & Compliance Policy periodically. Updates will be posted on this page with a revised date. Continued use of our Services constitutes your acceptance of any such changes.
14. Contact Us
If you have questions, concerns, or complaints regarding our data protection practices, please contact:
WizzyWeb Private Limited
Email: support@wizzyweb.com
Website: https://wizzyweb.com
Registered Office: Gurugram, India
Related policies: Privacy Policy · Terms & Conditions · Cookies Policy · Cancellation & Refund Policy · Shipping & Delivery Policy · Disclaimer
Questions About Our Legal Policies?
If you have any questions about our legal policies or need clarification on any terms, please do not hesitate to contact us.