Privacy Policy
Last Updated: [DATE TBA]
Esters & Solvents LLP (“Esters & Solvents”, “we”, “us”, or “our”) is committed to safeguarding the privacy of individuals whose personal data we collect and process in connection with our chemical manufacturing and related business operations. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with applicable privacy and data protection laws.
- Scope
This Privacy Policy applies to:
- Our vendors, suppliers, distributors, agents, contractors, and business partners
- Visitors to our facilities or business contacts via phone, email, or in person
- Any individual whose personal data is collected during the course of business operations
This Policy does not apply to data collected through a commercial website, mobile app, or e-commerce platform, as we do not currently provide these services to consumers.
- Applicable Laws
This Privacy Policy is designed to comply with:
- India: Information Technology Act, 2000 & Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules)
- European Union/EEA: General Data Protection Regulation (EU) 2016/679 (GDPR)
- United Kingdom: UK General Data Protection Regulation (UK GDPR)
- United States – California: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Other jurisdictions: Local data protection laws where applicable
- What Personal Information We Collect
We may collect the following categories of personal data:
- Identification and Contact Data: Full name, business address, email ID, phone number, company name, designation
- Government/Compliance Data: PAN, GSTIN, license numbers, KYC documents, or identity verification data (only where required by law or contracts)
- Communication Records: Emails, phone call notes, meeting notes, letters, and related documents
- Device and Access Data (if applicable): IP address, browser data, and metadata from emails and digital communications
We do not intentionally collect any sensitive personal data (as defined under SPDI Rules or GDPR) unless legally required, and we ensure lawful processing where applicable.
- Lawful Basis for Processing
We collect and process personal information under the following legal bases:
- Performance of a contract – e.g., supplier agreements, service contracts
- Compliance with legal obligations – e.g., tax, environmental, safety, or government reporting requirements
- Legitimate interests – for internal administrative and business operations
- Consent – where required (e.g., newsletter or marketing communications)
- Vital interests or legal defence – e.g., safety or legal claims
- How We Use Personal Information
Your data may be used for:
- Business communication and relationship management
- Contract execution (procurement, delivery, quality checks)
- Compliance with applicable laws, audits, and safety regulations
- Internal record-keeping and dispute resolution
- Protection of our facilities, personnel, and intellectual property
- Security incident detection and fraud prevention
We do not use your personal data for automated profiling or behavioural advertising.
- Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
| Category | Purpose |
| Third-party service providers (e.g., IT, cloud hosting, security, logistics) | To operate, manage, or secure our business |
| Regulatory bodies or government authorities | Legal compliance and inspections |
| Auditors, legal advisors, consultants | Business or legal reviews |
| Affiliates, parent, or successor entities | Business continuity, M&A transactions |
We do not sell or share your personal data for advertising or cross-context behavioural targeting.
- Data Transfers (International)
Your personal information may be transferred to and stored in jurisdictions outside your home country, including the United States, the EU, and others. In such cases:
- For EU/EEA/UK residents, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK Addendum to SCCs
- Adequacy decisions by the European Commission or UK government
- Data Security
We have implemented appropriate technical and organizational measures, consistent with ISO/IEC 27001, to:
- Prevent unauthorized access, disclosure, or alteration of personal data
- Protect data in transit and at rest
- Limit access to only authorized personnel
- Maintain data integrity through regular audits and controls
While we take all reasonable precautions, no data transmission or storage is 100% secure.
- Data Retention
We retain your personal information only for as long as is necessary for the purposes stated in this policy or as required by:
- Contractual obligations
- Legal or regulatory requirements
- Tax, audit, or dispute resolution processes
After the retention period, personal data is securely deleted or anonymized.
- Your Rights
Subject to local laws, you may have the following rights:
| Right | Explanation |
| Access | Request details of personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of personal data (subject to legal obligations) |
| Restriction | Ask us to restrict processing under certain conditions |
| Object | Object to processing for direct marketing or legitimate interest |
| Portability | Request a copy of data in a machine-readable format |
| Withdraw consent | Where processing is based on your consent |
| Lodge a complaint | With your local data protection authority |
To exercise your rights, contact us using the information in Section 12.
- Children’s Privacy
We do not knowingly collect or process data from individuals under the age of 18. If we learn that we have inadvertently collected data from a minor, we will delete it promptly.
- Contact Us
If you have any questions, concerns, or wish to exercise your data protection rights, please contact:
Esters & Solvents LLP
Email: info@esters-solvents.com
If you are not satisfied with our response, you may contact the relevant Data Protection Authority in your jurisdiction.