Legal & Privacy
Privacy Policy
Your privacy matters to us. This Privacy Policy explains exactly what personal data Tophawks collects, why we collect it, how we use and protect it, and your rights over it. We do not sell your personal data — ever.
01Introduction
Overview
Tophawks Technologies Private Limited ("Tophawks," "we," "us," or "our") operates the website https://www.tophawks.com (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our Platform or use our services.
We are committed to protecting your privacy in accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, and, where applicable, the General Data Protection Regulation (GDPR) of the European Union.
Please read this policy carefully. If you disagree with its terms, please discontinue use of the Platform.
02Data Types
Data We Collect
We may collect the following categories of personal data:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Name, username, profile photo | Account creation & identification |
| Contact Data | Email address, phone number | Communication, support, notifications |
| Technical Data | IP address, browser type, device ID, OS | Security, analytics, performance |
| Usage Data | Pages visited, clicks, session duration | Platform improvement, personalization |
| Transaction Data | Purchase history, payment method type | Order fulfilment, billing (no full card data stored) |
| Communications Data | Messages sent via contact forms, support tickets | Customer support, legal compliance |
| Marketing Data | Preferences, survey responses, opt-in status | Targeted communications (with consent) |
| Location Data | Country, city (derived from IP) | Geo-relevant content, fraud prevention |
03Collection Methods
How We Collect Your Data
We collect data through the following means:
04Data Use
How We Use Your Data
We use personal data collected from you for the following purposes, each resting on a lawful basis:
| Purpose | Lawful Basis |
|---|---|
| Provide, operate, and maintain the Platform | Contract performance |
| Process transactions and send related notices | Contract performance |
| Manage your account and authenticate access | Contract performance |
| Respond to inquiries, provide customer support | Contract / Legitimate interest |
| Send administrative, security, or legal notices | Legal obligation |
| Send marketing communications (with opt-out) | Consent |
| Analyse usage patterns to improve services | Legitimate interest |
| Detect, prevent, and address fraud or security issues | Legitimate interest / Legal obligation |
| Comply with applicable laws and legal processes | Legal obligation |
| Enforce our Terms of Use and policies | Legitimate interest |
06Tracking
Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyse traffic, and serve relevant content. The cookies we use fall into these categories:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Authentication, security, session management | Session |
| Functional | Remembering preferences, language, region | 1 year |
| Analytics | Usage data (Google Analytics, Hotjar) | Up to 2 years |
| Marketing | Interest-based advertising, retargeting | Up to 1 year |
You can manage or disable non-essential cookies at any time via our Cookie Preferences Centre or through your browser settings. Disabling certain cookies may affect Platform functionality.
07Retention
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.
Upon expiration of the retention period, we securely delete or anonymise your personal data.
08Protection
Security of Your Data
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
09Rights
Your Privacy Rights
Subject to applicable law, you have the following rights regarding your personal data. Submit requests to privacy@tophawks.com. We will respond within 30 days.
10Minors
Children's Privacy
The Platform is not directed at individuals under the age of 18 years. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact us at privacy@tophawks.com and we will take steps to delete such data promptly.
In accordance with the DPDP Act, 2023, we obtain verifiable parental consent before processing data of children where we become aware of a user's minor status.
11Transfers
International Data Transfers
Tophawks is based in India. If you access the Platform from outside India, your data may be transferred to, stored, and processed in India or other countries where our service providers operate.
When transferring data internationally, we ensure appropriate safeguards are in place, including:
By using the Platform, you consent to the transfer of your data to India and other jurisdictions as described in this policy.
12External Links
Third-Party Links & Services
The Platform may contain links to third-party websites, plugins, or services. Clicking on these links may allow third parties to collect or share data about you. We do not control these third-party platforms and are not responsible for their privacy practices.
We encourage you to review the privacy policy of every website you visit. This Privacy Policy applies solely to data collected by Tophawks through the Platform.
13India — DPDP
Digital Personal Data Protection Act, 2023 (India)
As an Indian entity, Tophawks complies fully with the Digital Personal Data Protection Act, 2023 (DPDP Act). Under this Act, you have specific rights as a "Data Principal," and we act as the "Data Fiduciary."
To exercise your rights under the DPDP Act, contact our Data Protection Officer at dpo@tophawks.com.
14EU/UK — GDPR
GDPR Notice (EU & UK Users)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or the UK GDPR respectively.
Our lawful bases for processing are: Contract Performance (Art. 6(1)(b)), Legitimate Interests (Art. 6(1)(f)), Legal Obligation (Art. 6(1)(c)), and Consent (Art. 6(1)(a)) for marketing.
15Updates
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of the Platform after the effective date of any revised policy constitutes your acceptance of the changes. We encourage you to review this page periodically.
16Contact
Contact & Data Protection Officer
For privacy-related questions, concerns, or to exercise your rights, please contact us:
| Role | Contact |
|---|---|
| Privacy Team | privacy@tophawks.com |
| Data Protection Officer (DPO) | dpo@tophawks.com |
| Security Incidents | security@tophawks.com |
| GDPR Inquiries | gdpr@tophawks.com |
| Registered Address | Tophawks Technologies Private Limited, New Delhi, India |
| Website | www.tophawks.com |
Privacy request or concern?
We aim to respond within 30 days. For urgent matters, mark your subject line [PRIVACY URGENT].
