Brownfield Multipack Private Limited (“Brownfield Multipack”, “Company”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal information. We collect and use personal information responsibly when you visit our website www.brownfieldindia.com, contact us, submit an enquiry, request a quotation, or engage with us for business purposes.
This Privacy Policy explains how we collect, use, store, protect, and manage your personal information. It applies to information shared through our Website, email, telephone, enquiry forms, business communications, and other interactions with Brownfield Multipack. We are committed to maintaining the confidentiality and security of your information in accordance with applicable privacy and data protection laws.
1. APPLICABLE LAWS
This Privacy Policy is framed with reference to, and Brownfield Multipack undertakes to process personal data in accordance with, the following (as applicable to the relevant data and data subject):
- The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules framed/to be framed thereunder, being the primary data protection law of India.
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent still applicable/relevant.
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, insofar as they require a Grievance Officer for the Website.
- The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020, to the extent applicable to online transactions.
- For Users, customers, or data subjects located in the European Economic Area or the United Kingdom in connection with our export business, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and/or the UK GDPR and Data Protection Act, 2018, to the extent applicable.
- For Users/customers in other jurisdictions in which we conduct export business, applicable local data protection/privacy laws, to the extent they apply to our processing of that individual’s personal data.
- Foreign Exchange Management Act, 1999 and Customs Act, 1962, insofar as they mandate retention and disclosure of certain trade/KYC-related information to Indian regulatory and banking authorities in connection with export transactions.
2. KEY DEFINITIONS
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data (as defined under the DPDP Act), and, where relevant to our export operations, “personal data” as defined under the GDPR.
- “Sensitive Personal Data or Information” (under the SPDI Rules) includes information such as financial information (bank/credit card details), and, in the limited circumstances where collected (e.g., for certain export/KYC documentation), passport or government-identifier details.
- “Data Principal” means the individual to whom the Personal Data relates (referred to as “Data Subject” under GDPR).
- “Data Fiduciary” means Brownfield Multipack, being the entity that determines the purpose and means of processing Personal Data (referred to as “Data Controller” under GDPR).
- “Data Processor” means any third party that processes Personal Data on behalf of and under the instructions of Brownfield Multipack (e.g., our IT/hosting vendor, courier/freight partner, or payment gateway).
- “Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transfer, and erasure.
3. PERSONAL DATA WE COLLECT
3.1 Information You Provide Directly
- Identity and contact information: name, designation, company name, business address, e-mail address, telephone/mobile number, submitted through website enquiry/”Contact Us”/”Request a Quote” forms, e-mail, telephone, or in-person at trade fairs/exhibitions.
- Business/transactional information: purchase orders, billing and shipping addresses, GSTIN (for domestic Buyers), Import-Export Code and bank/LC details of overseas Buyers (for export documentation and payment realisation), tax identification numbers, and correspondence relating to quotations, Orders, and after-sales support.
- Export/KYC-related information: where required for export documentation, customs clearance, or bank compliance (e.g., Letter of Credit processing, Certificate of Origin, or due diligence under sanctions/anti-money-laundering requirements), we may collect authorised signatory details, company registration/incorporation documents, and, in limited circumstances, identification document details of authorised representatives.
- Recruitment information: if you apply for a position with us, we collect your resume/CV, educational and employment history, and contact details.
- Communications: records of e-mail, telephone, or written correspondence between you and the Company, including customer support and quality-claim correspondence.
3.2 Information Collected Automatically (Website)
- Technical data: IP address, browser type and version, device type, operating system, referring URL, pages visited, time and date of visit, and time spent on pages, collected through server logs and analytics tools.
- Cookies and similar tracking technologies: as described in Clause 6 below.
3.3 Information from Third Parties
- Information received from dealers, distributors, freight forwarders, customs brokers, banks (in connection with LC/collection processing), credit-reporting/trade-reference agencies (for credit assessment of prospective Buyers), and publicly available business directories/trade databases.
We do not knowingly collect special categories of Personal Data (such as health data, religious belief, or biometric data) through the Website, and request that such information not be submitted to us unless specifically and lawfully required in a defined business context (e.g., statutory employee health records maintained separately under applicable labour law, which are outside the scope of this Website-focused Policy).
4. PURPOSE OF PROCESSING
We process Personal Data for the following purposes:
- To respond to enquiries, provide quotations, and process purchase Orders across our Agriculture, Packaging, and Infrastructure divisions.
- To perform our contractual obligations, including manufacturing, invoicing, arranging domestic transportation or export shipment, customs clearance coordination, and after-sales/warranty support.
- To process payments, Letters of Credit, and export remittances, and to comply with banking, RBI/FEMA, and customs requirements associated with Export Transactions.
- To verify creditworthiness and conduct due diligence (including sanctions-screening) prior to onboarding a new domestic or export Buyer, dealer, or distributor.
- To communicate updates regarding Orders, dispatches, shipment tracking, and product/technical information relevant to a Buyer’s Order.
- To send marketing communications regarding new products, catalogues, or trade fair participation, where you have consented to receive such communications (or where permitted as an existing business relationship under Applicable Law), and to allow you to opt out at any time.
- To maintain, secure, and improve the Website, including analysing usage trends and preventing fraud/unauthorised access.
- To comply with legal and regulatory obligations, including under the CGST/IGST Act, 2017, FEMA, 1999, the Customs Act, 1962, the Companies Act, 2013, and requests from courts, law-enforcement, or regulatory authorities.
- To recruit personnel, where you submit a job application.
- To establish, exercise, or defend legal claims.
5. LEGAL BASIS FOR PROCESSING
Under the DPDP Act, we process Personal Data primarily on the basis of your consent (for example, when you submit an enquiry form or subscribe to marketing communications) and, where applicable, for “certain legitimate uses” recognised under the DPDP Act, including performance of a contract to which you are a party, compliance with a legal obligation, and voluntary sharing of Personal Data by you for a specified purpose. Where the GDPR applies to our processing of a data subject’s Personal Data (e.g., an EU-based export Buyer), we rely on one or more of the following legal bases: (a) performance of a contract with you; (b) compliance with a legal obligation to which we are subject; (c) our legitimate interests (such as fraud prevention, credit assessment, and direct marketing to existing business contacts), provided such interests are not overridden by your rights; and/or (d) your consent, which you may withdraw at any time.
6. COOKIES AND TRACKING TECHNOLOGIES
- The Website uses cookies and similar technologies (such as web beacons and local storage) to enable core website functionality, remember preferences, analyse traffic (e.g., via analytics tools), and, where applicable, support marketing/retargeting.
- Categories of cookies used may include: (a) Strictly Necessary Cookies, required for the Website to function; (b) Performance/Analytics Cookies, which help us understand how visitors use the Website; and (c) Functionality Cookies, which remember your preferences.
- You can control or disable cookies through your browser settings; however, disabling certain cookies may affect the functionality of the Website. Where required by Applicable Law, we will present a cookie consent banner allowing you to accept or manage cookie preferences before non-essential cookies are set.
7. SHARING AND DISCLOSURE OF PERSONAL DATA
We do not sell Personal Data. We may share Personal Data with the following categories of recipients, strictly for the purposes described in Clause 4:
- Logistics and export partners: transporters, freight forwarders, shipping lines/airlines, customs house agents, and customs authorities (Indian and destination-country), to the extent necessary to arrange delivery/export of Products.
- Financial institutions: banks and financial institutions involved in processing payments, Letters of Credit, bank guarantees, or export remittances, and, where legally required, credit-reporting agencies.
- Professional advisors and service providers: IT/website hosting providers, cloud storage providers, analytics providers, auditors, and legal/compliance advisors, each bound by confidentiality and data-processing obligations consistent with this Policy.
- Group companies/affiliates: for internal administrative purposes, subject to this Policy or an equivalent standard of protection.
- Government and regulatory authorities: including GST authorities, DGFT, RBI, customs authorities, courts, and law-enforcement agencies, where disclosure is required or permitted under Applicable Law, or to protect the rights, property, or safety of the Company or others.
- Business transfer: in connection with a merger, acquisition, restructuring, or sale of business assets, subject to the acquiring entity agreeing to honour the commitments in this Policy.
8. CROSS-BORDER TRANSFER OF PERSONAL DATA
- As Brownfield Multipack conducts export business, Personal Data (primarily business contact and transactional data of overseas Buyers, and, where relevant, of our own personnel who interact with overseas counterparties) may be transferred to, stored, and processed in countries outside India, including the destination country of an Export Transaction, the jurisdiction of an overseas bank processing an LC, or the location of our IT/hosting service providers.
- Such cross-border transfers shall be made in compliance with the DPDP Act (including any list of restricted countries that may be notified by the Central Government from time to time) and, where the GDPR applies to the Personal Data of an EEA/UK-based data subject, only to countries recognised as providing an adequate level of protection, or subject to appropriate safeguards such as Standard Contractual Clauses, or another valid transfer mechanism recognised under the GDPR/UK GDPR.
- By providing your Personal Data to us in connection with an Export Transaction or an international business relationship, you acknowledge that your data may be processed outside your home country, including in India, for the purposes described in this Policy.
9. DATA RETENTION
- We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including for the purpose of satisfying any legal, accounting, tax, export-documentation, or reporting requirements.
- Transactional and export-documentation records (invoices, shipping bills, bank realisation certificates, LC documents) are generally retained for the period mandated under the CGST/IGST Act, 2017, the Customs Act, 1962, the Companies Act, 2013, and FEMA regulations (commonly a minimum of eight (8) years for GST/company records, subject to the specific statutory period applicable), or longer if required to establish, exercise, or defend legal claims.
- Website enquiry data and marketing-consent records are retained until you withdraw consent or request erasure, or for a reasonable period thereafter to maintain a record of the withdrawal, unless a longer period is required by Applicable Law.
- Job-application data is generally retained for a limited period after the recruitment process concludes, unless you consent to your data being retained for consideration in future openings.
10. DATA SECURITY
- We implement reasonable security practices and procedures, including administrative, technical, and physical safeguards, commensurate with the sensitivity of the Personal Data, in line with the SPDI Rules and, where applicable, internationally recognised standards, to protect Personal Data against unauthorised access, alteration, disclosure, or destruction.
- Such measures may include access controls, encryption of sensitive data in transit, firewalls, secure hosting environments, and confidentiality obligations imposed on employees and Data Processors who handle Personal Data.
- While we take reasonable steps to protect Personal Data, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Users are encouraged to take reasonable precautions when transmitting sensitive information over the internet.
11. YOUR RIGHTS
11.1 Rights under the DPDP Act (Data Principals in India)
- Right to access information about the Personal Data processed by us, including a summary of the Personal Data and the processing activities undertaken.
- Right to correction and updating of inaccurate or incomplete Personal Data.
- Right to erasure of Personal Data that is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations described in Clause 9.
- Right to grievance redressal, including the right to have any grievance regarding processing of your Personal Data addressed by our Grievance Officer/Data Protection contact (Clause 14) and, thereafter, to approach the Data Protection Board of India, once constituted.
- Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity, in accordance with the DPDP Act.
- Right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out prior to withdrawal.
11.2 Additional Rights for EEA/UK Data Subjects (GDPR)
- Right of access, rectification, and erasure (“right to be forgotten”).
- Right to restriction of processing and right to object to processing (including direct marketing).
- Right to data portability, where technically feasible.
- Right to withdraw consent at any time, and the right to lodge a complaint with your local supervisory authority.
To exercise any of the above rights, please contact us using the details in Clause 14. We may require you to verify your identity before acting on a request, and may charge a nominal fee where permitted by Applicable Law for manifestly unfounded or excessive requests. We will respond within the timeframe prescribed under the applicable law.
12. MARKETING COMMUNICATIONS AND OPT-OUT
Where you have consented (or where permitted under Applicable Law based on an existing business relationship), we may send you product catalogues, updates on new offerings across our Agriculture, Packaging, and Infrastructure divisions, and invitations to trade fairs/exhibitions, by e-mail, WhatsApp Business, or telephone. You may opt out of marketing communications at any time by using the “unsubscribe” link in our e-mails, replying “STOP”, or contacting us using the details in Clause 14. Opting out of marketing communications does not affect transactional/Order-related communications, which are necessary for the performance of our contract with you.
13. CHILDREN’S PRIVACY
The Website and our business are directed at businesses, professionals, and adults (B2C/B2B/B2G procurement), and are not intended for use by, or directed at, children. We do not knowingly collect Personal Data from individuals below the age of eighteen (18) years. If we become aware that we have inadvertently collected Personal Data from a child without appropriate parental/guardian consent as required under the DPDP Act, we will take steps to delete such data promptly.
14. GRIEVANCE OFFICER / DATA PROTECTION CONTACT
In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, we have designated the following contact person to address privacy-related queries, complaints, and requests to exercise your rights:
Grievance Officer / Data Protection Contact: Brownfield Management
Designation: Admin
Brownfield Multipack
Address: The One 40, Sector B, Greater Brajeshwari, Indore, Madhya Pradesh 452016, India
E-mail: [brownfieldmultipack@gmail.com]
Phone: [+91 75668 77301 , +91 96858 85898 ]
Working Hours: [Monday–Saturday, 9:30 AM to 6:30 PM IST]
We will acknowledge complaints within forty-eight (48) hours and endeavour to resolve them within thirty (30) days, or such other period as may be prescribed under Applicable Law.
15. DATA BREACH NOTIFICATION
In the event of a Personal Data breach that is likely to result in harm to affected Data Principals, we shall notify the Data Protection Board of India and/or affected individuals, and, where the GDPR applies, the relevant supervisory authority and affected data subjects, within the timelines and in the manner prescribed under the DPDP Act and/or GDPR, as applicable, and shall take reasonable steps to mitigate the impact of such breach.
16. THIRD-PARTY WEBSITES AND LINKS
The Website may contain links to third-party websites, including payment gateways, logistics-tracking portals, and social media platforms. This Privacy Policy does not apply to, and we are not responsible for, the privacy practices of such third-party websites. We encourage you to review the privacy policy of any third-party website you visit.
17. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The revised Policy will be posted on the Website with an updated “Last Updated” date. Where required by Applicable Law, we will seek your fresh consent for any material change that affects the purpose or manner of processing your Personal Data. We encourage you to review this Policy periodically.
18. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy shall be subject to the dispute resolution mechanism (including arbitration and jurisdiction of courts) set out in our Terms and Conditions.
19. CONTACT US
[Brownfield Multipack]
Registered Office: The One 40, Sector B, Greater Brajeshwari, Indore, Madhya Pradesh 452016, India
GSTIN:23ARNPP4903D1ZY|
IEC: [An Importer-Exporter Code (IEC) certificate is a mandatory 10-digit identification number issued by the Directorate General of Foreign Trade (DGFT)]
Privacy/Data Protection Queries: brownfieldmultipack@gmail.com
General Enquiries: [brownfieldmultipack@gmail.com] | Phone: [+91 75668 77301 , +91 96858 85898 | Website: [www.brownfieldindia.com]
IMPORTANT NOTE: This document is a comprehensive template prepared for Brownfield Multipack’s Pan-India and export business, based on the Digital Personal Data Protection Act, 2023; Information Technology Act, 2000 and the SPDI Rules, 2011; IT (Intermediary Guidelines) Rules, 2021; Consumer Protection (E-Commerce) Rules, 2020; and, for export/international data subjects, the EU/UK GDPR. As the DPDP Act’s implementing Rules are still being finalised/notified by the Government of India and are subject to change, and as GDPR adequacy/transfer mechanisms are also periodically updated, all bracketed placeholders ([Insert …]) must be completed with Brownfield Multipack’s exact corporate details, and this Policy should be reviewed and formally vetted by a qualified data-protection/corporate lawyer prior to publication, and updated promptly once the DPDP Rules are finally notified, to ensure continued legal accuracy.










