Privacy Policy
Last updated: 5 November 2025
1. Introduction
At Dass Water Solutions Pvt. Ltd. (“Company,” “we,” “our,” or “us”), we value your trust and are committed to protecting your personal and business information with the highest standards of privacy and transparency. This Privacy Policy describes how we collect, store, process, and use personal data of individuals (“you,” “your,” or “data subject”) who interact with our website, products, or services - including installation, maintenance, and rental of Reverse Osmosis (RO) plants.
This Policy has been drafted in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act). It reflects our commitment to maintaining lawful, fair, and transparent processing of personal information. The principles guiding this Policy are necessity, data minimization, accuracy, purpose limitation, accountability, and consent-based collection.
This Privacy Policy applies to all personal data collected through our website (www.rolan.in), customer communication channels, physical service agreements, and on-site interactions. By using our website or engaging our services, you agree to the terms of this Policy. If you do not agree, please refrain from using our digital or physical services.
2. Legal Framework & Applicability
This Privacy Policy operates under the legal jurisdiction of the Republic of India and is governed by applicable laws relating to data protection, electronic governance, and cyber security. Specifically, this Policy adheres to:
- The Information Technology Act, 2000 (as amended) - governing electronic records and digital communication.
- The Information Technology (Reasonable Security Practices and Procedures) Rules, 2011 - prescribing standards for collection, storage, and handling of sensitive personal data.
- The Digital Personal Data Protection Act, 2023 (DPDP Act) - India’s principal data privacy law that mandates data processing with consent, purpose limitation, and transparency.
This Policy applies to all individuals residing in India who provide personal data to Dass Water Solutions Pvt. Ltd., whether as customers, employees, vendors, service users, or website visitors. It also covers data collected from companies or institutions to the extent that such data includes personal identifiers.
The Company acts as a “Data Fiduciary” under the DPDP Act, meaning we determine the purpose and means of processing personal data. All third parties, contractors, and service providers who handle data on our behalf act as “Data Processors” and are contractually bound to comply with this Policy and applicable Indian law.
3. Information We Collect
We collect personal and non-personal information necessary for business operations, customer support, compliance, and service delivery. This includes data collected directly from users, automatically via digital technologies, and from authorized third parties.
3.1 Personal Information
“Personal Information” refers to any data that identifies an individual directly or indirectly. Examples include:
- Full name, email address, phone number, and postal address provided via inquiry or service forms.
- Company details such as name, GST number, business location, and contact persons when signing service contracts.
- Government-issued identifiers (e.g., PAN, Aadhaar, GSTIN) when legally required for invoicing or compliance.
- Bank or payment information, limited to processing authorized transactions.
3.2 Non-Personal & Technical Information
Non-personal data refers to anonymized information used for analytics, including:
- Browser type, device details, operating system, and IP address.
- Pages visited, time spent on site, and referral URLs collected via analytics tools.
- Cookies and session identifiers that enhance website functionality and security.
3.3 Sensitive Personal Data
We do not intentionally collect sensitive personal data such as health information, biometric identifiers, sexual orientation, or political beliefs. If such data is ever collected for compliance or operational necessity, it will be with explicit written consent and secured using encryption and restricted access.
4. Purpose of Information Use
We use personal and business data only for legitimate, consent-based purposes, consistent with the principles of necessity and proportionality under Indian law. The purposes include:
- Fulfilling installation, rental, and maintenance service requests.
- Processing quotations, invoices, and payments in compliance with tax regulations.
- Providing customer support, technical assistance, and warranty services.
- Maintaining internal records, audits, and performance reports.
- Sending service updates, notifications, and legally required communications.
- Conducting water quality audits, operational testing, and statutory certifications.
The Company does not engage in unauthorized profiling, targeted advertising, or resale of personal data. Every instance of data use is documented internally and periodically reviewed for compliance.
5. Data Storage, Retention & Deletion
Dass Water Solutions Pvt. Ltd. maintains robust data management systems to ensure accuracy, integrity, and security of stored data. Personal data is stored on secure servers located within India, ensuring compliance with data localization requirements where applicable.
Retention periods vary depending on the nature of data:
- Customer records - retained for up to 8 years for tax and contractual compliance.
- Billing & financial data - retained for statutory audit requirements as per Indian tax law.
- Marketing data - retained only until withdrawal of consent.
- Technical logs - retained for 12 months for analytics and service optimization.
Upon expiry of the retention period or fulfillment of purpose, data is securely deleted using industry-approved erasure protocols. Users may request deletion of their data under Section 8 (“Rights of Individuals”). However, certain data may be retained if required by law or for dispute resolution.
6. Disclosure & Third-Party Sharing
We do not sell or rent your personal data. Data may be shared only under the following legitimate circumstances:
- With logistics partners, operators, or engineers for service delivery.
- With financial institutions for payment processing and invoice settlements.
- With authorized auditors or legal consultants for regulatory compliance.
- With government agencies when legally required under statutory provisions.
Every third-party partner handling data is contractually obligated to maintain confidentiality, implement strong security measures, and process data strictly within the agreed purpose. Any cross-border data sharing will comply with the DPDP Act and relevant government guidelines.
7. Security Measures & Breach Management
We adopt reasonable security practices consistent with Rule 8 of the IT (Reasonable Security Practices and Procedures) Rules, 2011. These include technical, operational, and organizational safeguards such as firewalls, encryption, multi-factor authentication, and access control policies. Regular vulnerability assessments and internal audits are conducted to ensure continued protection.
In the unlikely event of a data breach, we will follow a structured incident response plan: immediate containment, internal reporting, forensic investigation, and notification to affected individuals and relevant authorities as required under the DPDP Act. Corrective measures will be implemented promptly to prevent recurrence.
8. Rights of Individuals
Under the Digital Personal Data Protection Act, 2023, you have specific rights regarding your personal data. These include:
- Right to Access: Obtain confirmation and a summary of personal data processed.
- Right to Correction: Request rectification of inaccurate or outdated information.
- Right to Erasure: Seek deletion of personal data when no longer required.
- Right to Withdraw Consent: Withdraw consent for data processing at any time.
- Right to Grievance Redressal: Lodge complaints through the contact information provided below.
To exercise any of these rights, send a written request to contact@rolan.in. We will verify your identity before responding. Requests are processed within 30 working days unless extended under lawful exceptions.
9. Updates & Amendments
This Privacy Policy may be updated periodically to reflect legal, operational, or technological changes. Updated versions will be posted on our website with a revised “Last Updated” date. Substantial changes affecting user rights will be communicated via email or prominent website notice.
Continued use of our services following any update constitutes your acceptance of the revised Policy.
10. Contact & Grievance Redressal
Dass Water Solutions Pvt. Ltd.
1st Floor, Dass Furniture Mall, Bajarangwadi, Pune Nagar Road, Shikrapur, Pune – 412208
Phone: +91 7507245993
Email: contact@rolan.in
For any concerns regarding privacy, data handling, or this Policy, please write to our designated Grievance Officer at contact@rolan.in. The officer will acknowledge your complaint within 7 working days and resolve it within 30 working days in accordance with Section 13 of the DPDP Act, 2023.
If you remain unsatisfied with our response, you may escalate the matter to the Data Protection Board of India as constituted under the DPDP Act.
Questions about these Privacy Policy?
We’re happy to clarify any clause or prepare a project-specific addendum.