GARUDAYA policy
Data Protection Policy
Administrative and technical controls for protecting GARUDAYA account, KYC, marketplace and operational data.
Applies to:
Users, partners, employees, auditors and enterprise reviewers.
Last updated:
08 August 2026
Entity:
GARUDAYA PRIVATE LIMITED / GARUDAYA AGRO INDUSTRIES
Private company and approval disclaimer
GARUDAYA PRIVATE LIMITED is a private company, not a government department, statutory authority, regulator, embassy, customs office, bank or insurer. A GARUDAYA review, checklist, referral or document submission does not itself grant a licence, certificate, permit, export clearance, tax registration or government approval. Any approval must be issued by the competent authority or contracting organization named in the applicable process. Users remain responsible for truthful information, fees, renewals and lawful compliance.
Protection principles
- Collect only information needed for defined agriculture, commerce, service, KYC, support and compliance purposes.
- Use role-based access, RLS, signed private documents and server-side secret isolation.
- Maintain audit logs for sensitive admin actions where technically enabled.
- Limit access to staff and service providers with a legitimate business need.
Sensitive data
Aadhaar, PAN, bank details, KYC documents, payment events and admin security data require stronger controls including masking, hashing/encryption where implemented, private storage and reviewer authorization.
Incident response
Suspected data incidents should be reported to admin@garudaya.in. GARUDAYA should maintain internal incident classification, containment, notification and remediation procedures. Transaction-specific prices, statutory charges, taxes, eligibility, service levels and timelines are disclosed in the applicable checkout, quotation, order, invoice or signed agreement. Where mandatory law gives a user stronger rights, that law prevails.
Independent providers and regulatory verification
GARUDAYA may apply to regulated, government or private providers for payment processing, email/SMS delivery, DigiLocker or API Setu access, PAN/Aadhaar checks, bank-account validation, logistics and other integrations. Displaying an integration workflow or accepting an application does not mean that a provider, regulator or government body has endorsed GARUDAYA. A feature is treated as live only after the relevant provider approves the account, production credentials are securely configured, and GARUDAYA completes acceptance testing. Until then, the website labels the result as pending, manual review or unavailable and does not represent it as verified.
Official contact and notices
Questions about data protection policy should be sent from the registered account email wherever possible. GARUDAYA may request order IDs, application IDs, invoice numbers, KYC references or proof of authority before sharing account-specific information. Official notices may be sent to legal@garudaya.in; operational support may be sent to support@garudaya.in. Registered office: C/O Sabita Jena Nuagam, Dasamundali, Sheragada, Aska, Ganjam – 761106, Odisha, India.
| Desk | |
|---|---|
| Grievance and legal notices | legal@garudaya.in |
| Customer support | support@garudaya.in |
| Payments and accounts | accounts@garudaya.in |
| KYC and privacy | kyc@garudaya.in |
| Export | export@garudaya.in |