1. Who We Are
ProdGem is operated by RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED (CIN: U62091KA2025PTC210162), registered at #36, WeWork Prestige Central, Infantry Road, Mahatma Gandhi Road, Bengaluru, Karnataka 560001, India. GST: 29AAPCR1639E1Z3.
As a data fiduciary under the India Digital Personal Data Protection Act 2023, and as a data controller under GDPR for users in the European Economic Area, we are responsible for protecting your personal data.
2. Information We Collect
We collect the following personal data when you use our marketplace:
- Account information: Email address, name (optional), password (stored as a bcrypt hash — never recoverable)
- Payment information: Billing country, state, GSTIN (for Indian B2B customers). We do not store card numbers — Razorpay handles payment tokenization directly within its hosted interface.
- Order information: Products purchased, order amounts, payment reference IDs, timestamps
- Download logs: IP address, user agent, download timestamps (for security and dispute resolution)
- Technical data: IP address, browser type, device information (collected automatically via server logs)
- Cookie preferences: Your consent choices (essential / analytics / marketing), stored for 3 years
- Communications: Newsletter subscription email, contact form messages
3. How We Use Your Data
- To process your purchases and deliver digital products
- To generate GST-compliant invoices (India)
- To send order confirmation emails, license keys, and download links
- To prevent fraud and resolve download disputes
- To send marketing emails (only with your explicit consent)
- To respond to contact form submissions and support requests
- To maintain security audit logs and detect abuse
4. Legal Basis for Processing (GDPR Article 6)
For users in the European Economic Area, we process personal data under the following lawful bases:
- Contract performance (Art. 6(1)(b)): Processing your order, delivering products, and providing customer support.
- Legal obligation (Art. 6(1)(c)): Retaining order records for 8 years to comply with Indian tax law (GST Act).
- Legitimate interests (Art. 6(1)(f)): Fraud prevention, security monitoring, audit logging, and improving our services.
- Consent (Art. 6(1)(a)): Sending marketing emails and analytics cookies. You may withdraw consent at any time.
For Indian users, we process data on the basis of consent and legitimate use as defined under the DPDP Act 2023.
5. Your Rights (DPDP Act 2023, GDPR)
We comply with the Digital Personal Data Protection Act, 2023 (India) and GDPR (EU). You have the following rights:
- Right to Access / Data Portability: Export all your personal data in machine-readable format from Account Settings → Privacy → Export My Data.
- Right to Erasure: Delete your account and all personal data from Account Settings → Privacy → Delete Account. Order records are anonymised but retained for tax compliance (GST Act, 8 years).
- Right to Rectification: Update your profile information at any time from Account Settings.
- Right to Withdraw Consent: Unsubscribe from the newsletter via the “Unsubscribe” link in any newsletter email, or withdraw cookie consent via the “Cookie Preferences” link in the site footer. Takes effect immediately for future processing.
- Right to Restrict Processing: Deactivate your account to pause processing without deletion.
- Data Minimisation: We collect only what is necessary for the stated purpose.
- Data Residency: Data is processed and stored in India (Google Cloud Platform, Mumbai region).
To exercise any right, email our Grievance Officer at [email protected]. We will respond within 30 days.
6. Sub-processors and Third-Party Services
We share personal data with the following service providers, each of whom processes data on our behalf under a Data Processing Agreement:
- Razorpay (IN): Payment processing, including international cards — PCI DSS Level 1. Card data is tokenized within Razorpay's hosted Checkout widget; no PAN reaches our servers.
- Cloudflare (US/global): CDN, DDoS protection, and file delivery via R2 object storage — SOC 2 + ISO 27001.
- Resend (US): Transactional email delivery (order confirmations, license keys, password resets, newsletter) — SOC 2.
- Sentry (US): Error monitoring and diagnostics. Personal data (email, IP) is scrubbed before transmission via our
beforeSend filter — SOC 2. - Twilio (US): SMS one-time codes for optional multi-factor authentication — SOC 2 + ISO 27001.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
7. Cross-Border Data Transfers
Personal data originating in India may be transferred to our sub-processors in the United States (Cloudflare, Resend, Sentry, Twilio). All such transfers are governed by:
- DPDP Rules (Nov 2025): Transfers only to countries not blocked by the Indian government. Sub-processors have executed or are in the process of executing Data Processing Agreements.
- GDPR: Where applicable, Standard Contractual Clauses (SCCs) govern transfers outside the EEA.
Payment-specific data (card numbers, CVVs) never leaves the payment provider's infrastructure.
8. Data Retention
- Account / PII: Deleted immediately and irreversibly when you request account deletion — there is no recovery window, so make sure before you confirm
- Order records: 8 years (Indian GST Act + tax compliance)
- Session tokens: 7 days (refresh) / 15 minutes (access); revoked on logout
- Audit logs: 2 years
- Cookie consent records: 3 years
- Error / diagnostic logs: 30 days
Automated deletion cron jobs run nightly to enforce these schedules.
9. Cookies
We use the following categories of cookies. You can manage your preferences at any time via the “Cookie Preferences” link in the site footer, or from the cookie banner shown on your first visit:
- Essential: Authentication session cookie (
refresh_token, httpOnly, secure). Required for login and cannot be disabled. - Analytics: Used only with your consent to understand traffic patterns. No PII is shared with analytics providers.
- Marketing: Used only with your consent for conversion tracking (LinkedIn, Facebook). You may withdraw consent at any time.
We honour the Global Privacy Control (GPC) browser signal — if your browser sends a GPC signal, analytics and marketing cookies are automatically suppressed without requiring banner interaction.
10. Children's Data
ProdGem is not directed at children under 13 (globally) or under 18 without verifiable parental consent (India DPDP Act Rule 10). We do not knowingly collect personal data from children. If we discover that a child has provided personal data, we will delete it within 72 hours.
11. Do Not Sell My Personal Information (CCPA / CPRA)
We do not sell personal information to third parties, as defined under the California Consumer Privacy Act (CCPA) and its amendment (CPRA). No user-level identifiers are shared with ad networks.
California residents have the right to: know what personal information we collect and how we use it; request deletion; opt out of sale (not applicable — we do not sell data); and non-discrimination for exercising these rights. To exercise CCPA rights, email [email protected].
12. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33) and notify the Data Protection Board and affected data principals per DPDP Rules. Affected individuals will be notified without undue delay where the breach poses a high risk to their rights.
13. Security
We implement technical and organisational measures to protect your personal data, including:
- Passwords hashed with bcrypt (cost factor 12) — never stored in plain text
- All data in transit encrypted via TLS; HTTPS enforced with HSTS and strict Content Security Policy
- Authentication tokens stored in httpOnly, Secure, SameSite=Strict cookies
- Tamper-evident audit log with HMAC-SHA256 integrity hashes
- Payment card data never touches our servers (PCI SAQ-A posture)
- Download files delivered as AES-256 password-protected ZIPs via signed URLs
For a full security overview, see our Security & Trust page.
14. Grievance Officer (DPDP Act)
For any privacy concerns, data protection requests, or to exercise your rights under GDPR, DPDP, or CCPA, contact our Grievance Officer:
Santhosh Suryavanshi
Email: [email protected]
Phone: +91 91106 18988
Address: #36, WeWork Prestige Central, Infantry Road, Mahatma Gandhi Road, Bengaluru, Karnataka 560001, India
We will acknowledge your request within 3 business days and respond within 30 days.
15. Policy Changes
We may update this policy to reflect changes in our practices or applicable law. Material changes will be notified by email (for registered users) and by updating the “Last updated” date above. Continued use of the platform after the effective date constitutes acceptance.