Privacy Policy
Privacy Policy and Personal Data Processing Notice
Meridian Market Resources
Contents
- Introduction
- Applicability
- Data Fiduciary
- Definitions
- Personal Data We Collect
- How Personal Data is Collected
- Purposes of Processing Personal Data
- Consent
- Disclosure of Personal Data
- Third-Party Service Providers
- Cookies and Similar Technologies
- Cross-Border Processing of Personal Data
- Information Security
- Data Retention
- Rights of Data Principals
- Children's Personal Data
- Third-Party Websites
- International Users
- Grievance Redressal
- Limitation of Liability
- Changes to this Privacy Policy
- Severability
- Governing Law and Jurisdiction
- Contact Us
1. Introduction
Meridian Market Resources ("MMR", the "Company", "we", "our" or "us") recognises the importance of protecting the privacy of individuals whose Personal Data is processed by the Company in the course of its business operations.
This Privacy Policy and Personal Data Processing Notice ("Privacy Policy") describes how the Company collects, uses, stores, shares, retains and otherwise processes Personal Data through its website, business communications and related commercial activities.
This Privacy Policy constitutes the notice provided by the Company regarding the processing of Personal Data in accordance with the Digital Personal Data Protection Act, 2023, the rules framed thereunder and other applicable laws relating to privacy and data protection ("Applicable Data Protection Laws").
The Company is committed to processing Personal Data lawfully, fairly, transparently and only for legitimate business purposes.
Where Applicable Data Protection Laws require consent prior to processing Personal Data, the Company shall obtain such consent through appropriate means.
This Privacy Policy is intended to provide information regarding the Company's processing of Personal Data and shall not be construed as creating any contractual rights or obligations except where expressly required under Applicable Law.
2. Applicability
This Privacy Policy applies to all Personal Data processed by the Company in its capacity as a Data Fiduciary, whether collected through:
- the Company's website;
- online enquiry forms;
- requests for quotations;
- business communications;
- email correspondence;
- telephone communications;
- WhatsApp communications;
- meetings and business interactions;
- recruitment enquiries; or
- any other lawful interaction between the Company and an individual.
This Privacy Policy applies only to Personal Data processed by the Company and does not apply to websites, applications or services operated by independent third parties.
3. Data Fiduciary
For the purposes of Applicable Data Protection Laws, the Data Fiduciary is:
Meridian Market Resources
Registered Office: #5, 6th Main, BDA Industrial Suburb, Near SRS, Peenya, Bengaluru – 560058, Karnataka, India.
Website: www.meridianmarketresources.com
Email: enquiry@meridianmarketresources.com
Telephone: +91 99000 26915
4. Definitions
For the purposes of this Privacy Policy, unless the context otherwise requires:
- "Applicable Data Protection Laws" means the Digital Personal Data Protection Act, 2023, the rules framed thereunder and any other applicable laws governing the processing of Personal Data.
- "Company" means Meridian Market Resources.
- "Consent" means any free, specific, informed, unconditional and unambiguous indication whereby an individual signifies agreement to the processing of Personal Data for a specified purpose.
- "Data Fiduciary" shall have the meaning assigned under Applicable Data Protection Laws.
- "Data Principal" shall have the meaning assigned under Applicable Data Protection Laws.
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
- "Processing" includes the collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, sharing, transmission, restriction, erasure or destruction of Personal Data.
- "Services" means the products, services, consultations, quotations, commercial engagements and other business activities undertaken by the Company.
- "Website" means the Company's official website together with all webpages operating under its authorised domain.
5. Personal Data We Collect
The Company endeavours to collect only such Personal Data as is reasonably necessary for the purposes described in this Privacy Policy. Depending upon the nature of the interaction, the Company may collect the following categories of Personal Data.
5.1 Identity Information
Including:
- Full name;
- Employer or organisation;
- Job title or designation;
- Industry or business sector.
5.2 Contact Information
Including:
- Email address;
- Mobile or telephone number;
- WhatsApp number;
- Business correspondence address, where voluntarily provided.
5.3 Business Information
Where relevant to a commercial engagement, the Company may process information relating to:
- enquiries;
- quotation requests;
- product specifications;
- project requirements;
- technical discussions;
- procurement requirements;
- purchase enquiries;
- commercial negotiations;
- contractual communications; and
- other information voluntarily submitted in connection with the Company's Services.
5.4 Technical Information
When an individual accesses the Website, the Company or its authorised service providers may automatically collect certain technical information, including:
- Internet Protocol (IP) address;
- browser type and version;
- operating system;
- device information;
- referring website;
- pages visited;
- duration of website visit;
- approximate geographical location derived from IP address;
- diagnostic information relating to website performance.
Such information is generally processed in an aggregated or de-identified manner wherever reasonably practicable.
5.5 Recruitment Information
Where an individual voluntarily submits an employment application, curriculum vitae or similar documentation, the Company may process Personal Data reasonably necessary for recruitment and employment-related purposes.
5.6 The Company requests that individuals do not submit confidential, proprietary or commercially sensitive information unless specifically requested or required for a legitimate business purpose.
6. How Personal Data is Collected
The Company may collect Personal Data:
- directly from the Data Principal;
- through enquiries submitted via the Website;
- through requests for quotations;
- during business correspondence;
- through email communications;
- during telephone or virtual meetings;
- through recruitment processes;
- through cookies and similar technologies;
- through publicly available business information voluntarily shared by the Data Principal; and
- through other lawful means consistent with Applicable Data Protection Laws.
The Company endeavours to ensure that Personal Data collected is relevant, accurate and limited to what is reasonably necessary for the identified purpose of processing.
7. Purposes of Processing Personal Data
The Company processes Personal Data only for lawful purposes connected with its business activities and only to the extent reasonably necessary for such purposes. Subject to Applicable Data Protection Laws, the Company may process Personal Data for one or more of the following purposes:
7.1 Responding to Enquiries
To receive, evaluate and respond to requests for information, product enquiries, requests for quotations, technical queries and other communications initiated by a Data Principal.
7.2 Provision of Services
To negotiate, administer and perform contractual or pre-contractual obligations, including preparing quotations, supplying products or services, communicating regarding orders and managing customer relationships.
7.3 Customer Relationship Management
To maintain records of commercial interactions, respond to follow-up communications, administer customer accounts and provide support in relation to the Company's products or services.
7.4 Website Administration
To operate, maintain, secure and improve the Website, diagnose technical issues, monitor performance and prevent unauthorised access or misuse.
7.5 Analytics and Business Improvement
To understand how visitors interact with the Website, analyse trends, improve user experience and evaluate the effectiveness of the Company's digital platforms. Where reasonably practicable, such information shall be processed in an aggregated or de-identified manner.
7.6 Recruitment
To assess employment applications, communicate with applicants, conduct recruitment processes and maintain records relating to recruitment.
7.7 Compliance with Legal Obligations
To comply with Applicable Law, judicial directions, governmental requests, regulatory obligations and lawful requests from competent authorities.
7.8 Protection of Legitimate Business Interests
To establish, exercise or defend legal rights, prevent fraud, investigate security incidents, protect the Company's assets and safeguard its information systems.
The Company shall not process Personal Data for purposes materially inconsistent with those specified in this Privacy Policy except where permitted under Applicable Data Protection Laws or with the consent of the Data Principal, where required.
8. Consent
Where Applicable Data Protection Laws require consent for processing Personal Data, the Company shall obtain such consent through appropriate means prior to processing.
A Data Principal may withdraw consent at any time by contacting the Company using the details provided in this Privacy Policy.
Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to such withdrawal.
Where processing is necessary for the provision of products or services requested by the Data Principal, withdrawal of consent may limit or prevent the Company's ability to provide such products or services.
9. Disclosure of Personal Data
The Company does not sell or rent Personal Data to third parties for their independent marketing purposes.
The Company may disclose Personal Data only where reasonably necessary for the purposes described in this Privacy Policy or where otherwise permitted or required under Applicable Law. Personal Data may be disclosed to:
9.1 Service Providers
Third-party service providers engaged to support the Company's business operations, including providers of:
- website hosting;
- cloud infrastructure;
- email services;
- cybersecurity services;
- information technology support;
- analytics services;
- document management;
- customer communication platforms; and
- other business support services.
Such service providers shall process Personal Data only on behalf of the Company and in accordance with applicable contractual obligations.
9.2 Professional Advisors
The Company's legal advisers, auditors, accountants, consultants, insurers and other professional advisers where reasonably necessary.
9.3 Financial Institutions and Payment Service Providers
Banks, payment service providers and financial institutions where disclosure is reasonably necessary for the performance of contractual obligations or financial transactions.
9.4 Regulatory and Government Authorities
Courts, tribunals, regulatory authorities, governmental agencies, law enforcement authorities or other competent bodies where disclosure is required or permitted under Applicable Law.
9.5 Corporate Transactions
In connection with any merger, acquisition, restructuring, business transfer, investment, financing or sale of assets, provided that appropriate confidentiality obligations continue to apply.
9.6 Protection of Rights
Where reasonably necessary to:
- establish, exercise or defend legal claims;
- prevent fraud;
- investigate unlawful activities;
- protect the safety of individuals;
- enforce contractual rights; or
- protect the legitimate interests of the Company.
9.7 Compliance with Contractual Obligations
The Company may disclose Personal Data to customers, suppliers, logistics partners or other business counterparties where such disclosure is reasonably necessary for the performance of contractual obligations or legitimate commercial transactions.
10. Third-Party Service Providers
The Company may engage independent third-party service providers to assist in the operation of its business. Such service providers may include providers of:
- website hosting;
- cloud storage;
- website analytics;
- email communications;
- information technology support;
- cybersecurity services; and
- other operational support services.
The Company endeavours to engage service providers that maintain appropriate administrative, technical and organisational safeguards for the protection of Personal Data.
The Company is not responsible for the independent privacy practices of third parties except to the extent required under Applicable Law.
11. Cookies and Similar Technologies
The Website may use cookies and similar technologies to facilitate its operation, improve user experience and analyse Website usage. Cookies may include:
- Essential Cookies, which are necessary for the operation and security of the Website;
- Analytics Cookies, which assist the Company in understanding Website usage and improving performance; and
- Functional Cookies, which enable certain Website features and remember user preferences.
Most internet browsers permit users to control, disable or delete cookies through browser settings. Disabling cookies may affect certain Website functionalities.
12. Cross-Border Processing of Personal Data
Certain service providers engaged by the Company may process or store Personal Data outside India.
Where Personal Data is transferred outside India, the Company shall endeavour to ensure that such transfer is undertaken in accordance with Applicable Data Protection Laws and subject to appropriate contractual, organisational or technical safeguards, where applicable.
Nothing contained in this Privacy Policy shall be construed as creating any obligation on the Company to transfer Personal Data outside India.
13. Information Security
The Company implements appropriate administrative, technical and organisational safeguards designed to protect Personal Data against unauthorised access, disclosure, alteration, misuse, loss or destruction. Such safeguards may include, where appropriate:
- encryption of data in transit;
- access control mechanisms;
- authentication procedures;
- password protection;
- firewall and network security measures;
- system monitoring;
- restricted access based on business requirements; and
- periodic review of information security practices.
While the Company endeavours to maintain appropriate safeguards, no method of electronic transmission, storage or internet communication can be guaranteed to be completely secure.
Accordingly, except to the extent required by Applicable Law, the Company does not warrant uninterrupted or error-free security of its systems or Website.
The Company periodically reviews and updates its information security measures having regard to the nature of Personal Data processed, technological developments and reasonably foreseeable risks.
14. Data Retention
The Company retains Personal Data only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy or to comply with Applicable Law. Retention periods may vary depending upon:
- contractual obligations;
- statutory requirements;
- accounting requirements;
- taxation requirements;
- litigation;
- regulatory investigations;
- insurance claims;
- enforcement of legal rights; and
- legitimate business requirements.
Upon expiry of the applicable retention period, the Company shall take reasonable steps to securely delete, anonymise or otherwise dispose of Personal Data unless continued retention is required under Applicable Law.
15. Rights of Data Principals
Subject to Applicable Data Protection Laws, a Data Principal may exercise such rights as are available under law, including the right to:
- request a summary of Personal Data processed by the Company;
- request correction, completion or updating of inaccurate Personal Data;
- request erasure of Personal Data where applicable;
- withdraw consent, where processing is based upon consent;
- seek grievance redressal; and
- nominate another individual to exercise rights where permitted by Applicable Law.
The Company may decline or limit any request where permitted under Applicable Law or where necessary to protect the rights of other individuals or the legitimate interests of the Company.
The Company may require reasonable verification of identity prior to acting upon any request.
16. Children's Personal Data
The Website and the Company's Services are intended for business and commercial purposes and are not directed towards children.
The Company does not knowingly solicit or collect Personal Data from children in circumstances where parental consent or other legal requirements apply under Applicable Data Protection Laws.
Where the Company becomes aware that Personal Data has been collected contrary to Applicable Law, it shall take appropriate steps to delete such Personal Data in accordance with Applicable Law.
17. Third-Party Websites
The Website may contain links to third-party websites or services for the convenience of users.
The Company neither controls nor assumes responsibility for the privacy practices, security or content of such third-party websites.
Access to third-party websites shall be governed by the terms and privacy policies of the respective operators, and users are encouraged to review such policies before submitting Personal Data.
18. International Users
The Company is incorporated and operates from India. This Privacy Policy has been prepared in accordance with Applicable Data Protection Laws of India.
Where the Company processes Personal Data of individuals located outside India, such processing shall be undertaken only to the extent permitted or required under Applicable Law.
Nothing contained in this Privacy Policy shall be construed as a representation that the Company is subject to the laws of any jurisdiction solely because its Website may be accessible from such jurisdiction.
Where cross-border processing is undertaken, the Company shall endeavour to implement appropriate safeguards consistent with Applicable Law.
19. Grievance Redressal
The Company is committed to addressing concerns relating to the processing of Personal Data in a fair and timely manner.
Any Data Principal who has a concern, complaint or request relating to the processing of Personal Data may contact the Company's Grievance Officer using the details provided below.
The Grievance Officer shall endeavour to acknowledge and address grievances within the timelines prescribed under Applicable Data Protection Laws.
Grievance Officer
Name: Mrs. Seema Menon
Designation: CEO
Email: enquiry@meridianmarketresources.com
Postal Address: Meridian Market Resources, #5, 6th Main, BDA Industrial Suburb, Near SRS, Peenya, Bengaluru – 560058, Karnataka, India.
The Company may request reasonable information necessary to verify the identity of the individual submitting a request before acting upon such request.
20. Limitation of Liability
The Company endeavours to process Personal Data in accordance with Applicable Data Protection Laws and to implement appropriate safeguards for its protection. However, except to the extent prohibited by Applicable Law:
- the Company does not warrant that the Website or any communication system will operate without interruption, delay or error;
- the Company does not guarantee that electronic communications or internet-based transmissions will be completely secure or free from unauthorised interception;
- the Company shall not be responsible for any loss, damage or unauthorised access arising from circumstances beyond its reasonable control, including cyber-attacks, internet failures, acts of governmental authorities, force majeure events or failures of third-party communication networks; and
- nothing contained in this Privacy Policy shall create any contractual obligation or liability beyond those imposed upon the Company under Applicable Law.
Nothing contained in this clause shall restrict any rights that a Data Principal may have under Applicable Data Protection Laws.
Nothing in this Privacy Policy limits or excludes any liability that cannot lawfully be excluded under Applicable Law.
21. Changes to this Privacy Policy
The Company reserves the right to amend, modify or update this Privacy Policy from time to time to reflect changes in Applicable Law, regulatory guidance, business operations, technological developments or the Company's information handling practices.
The revised version shall be published on the Website together with the updated "Effective Date".
Material changes to this Privacy Policy shall become effective from the revised Effective Date specified herein.
22. Severability
If any provision of this Privacy Policy is held by a court or competent authority to be invalid, illegal or unenforceable, such provision shall be deemed modified to the minimum extent necessary to make it enforceable or, if modification is not possible, severed from this Privacy Policy.
The remaining provisions shall continue in full force and effect.
23. Governing Law and Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of India.
Subject to the rights and remedies available under Applicable Data Protection Laws, any dispute arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts at Bengaluru, Karnataka.
24. Contact Us
If you have any questions regarding this Privacy Policy or the Company's privacy practices, you may contact:
Meridian Market Resources
Registered Office: #5, 6th Main, BDA Industrial Suburb, Near SRS, Peenya, Bengaluru – 560058, Karnataka, India.
Website: www.meridianmarketresources.com
General Email: enquiry@meridianmarketresources.com
Privacy Email: enquiry@meridianmarketresources.com
Telephone: +91 99000 26915
Annexure A
Categories of Personal Data Processed
| Category of Personal Data | Purpose of Processing | Typical Recipients | Indicative Retention |
|---|---|---|---|
| Identity Information | Responding to enquiries, customer relationship management, quotations | Internal personnel, authorised service providers | As long as necessary for the applicable purpose and thereafter as required by Applicable Law |
| Contact Information | Business communications, customer support, contractual communications | Internal personnel, email service providers | As required for business, contractual and legal purposes |
| Business Information | Quotations, procurement, project discussions, contractual performance | Internal personnel, professional advisers, service providers | Duration of the business relationship and applicable statutory limitation periods |
| Recruitment Information | Recruitment and employment-related evaluation | HR personnel, authorised recruitment support providers | Until completion of recruitment or longer where required by law or legitimate business needs |
| Technical Information | Website administration, security, analytics and performance improvement | Website hosting provider, analytics provider, IT support | As configured in the Company's systems or service provider settings, subject to operational and legal requirements |