Privacy Policy
Privacy Policy for pikk.company Website
Effective Date: August 01, 2025
This Privacy Policy ("Policy") governs the processing of personal data by Mystic Quantum Pvt Ltd., doing business as pikk.company ("we," "us," or "our"), in connection with your use of the website located at https://www.pikk.co.in (the "Website"). This Policy is drafted in alignment with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India, and draws inspiration from global standards such as the General Data Protection Regulation ("GDPR") where applicable, while embodying the same spirit of user empowerment, data minimalism, transparency, and non-intrusiveness as our pikkc app privacy promise. We collect only what is strictly necessary, prioritize device-side or user-controlled processing, avoid tracking or profiling, and ensure users retain full control over their data. No data is sold, and sharing is limited to essential, consented purposes.
We break down this Policy by each identified touch point on the Website, based on its current structure (homepage, enquiry forms, product pages like pikkstop, blog if applicable, app links, contact methods, and site-wide elements like cookies/analytics). For each touch point, we detail: (i) data collected; (ii) purposes and legal basis; (iii) retention; (iv) sharing; and (v) user rights/controls. This granular approach promotes transparency and accountability.
If the Website evolves (e.g., new pages added), this Policy will be updated accordingly, without altering its core ethos. We do not engage in automated decision-making or profiling that produces legal effects.
1. Homepage (General Browsing and Navigation)
-
Data Collected: Automatically logged non-personal data such as IP address (anonymized), browser type, device information, referral sources, and pages viewed. No personal identifiers unless you interact further. If cookies are used (essential only), they facilitate basic functionality (e.g., session management); no tracking cookies for advertising.
-
Purposes and Legal Basis: To enable Website functionality, diagnose technical issues, and improve user experience (e.g., load balancing). Legal basis: Legitimate interests (Section 7, DPDP Act) for essential operations; consent for any non-essential cookies via banner.
-
Retention: Logs retained for up to 30 days for security/debugging; deleted thereafter unless required for legal compliance.
-
Sharing: Limited to hosting providers (e.g., anonymized analytics via tools like Microsoft Clarity for heatmaps, if implemented—subject to their limitations: session recordings may capture interactions without full opt-out, data retained indefinitely in aggregated form, shared with Microsoft affiliates for processing). No sharing with advertisers.
-
User Rights/Controls: Opt-out of non-essential analytics via browser settings or "Do Not Track" signals (honored). Access or delete logs by request; withdraw consent anytime without affecting lawfulness of prior processing.
2. Enquiry Forms (e.g., "Enquire Seriously" Page at /enquire-seriously)
-
Data Collected: Personal data submitted voluntarily, including name, email, phone number (e.g., WhatsApp), address (for welcome kits or site scouting), company details, job title/skillset, enquiry specifics (e.g., EV charging site preferences, drawings/notes), native currency, and payment info for refundable fees (processed via third-party gateways; no card details stored by us).
-
Purposes and Legal Basis: To process partnership/investment enquiries, schedule calls, send kits, and facilitate site scouting for pikkstops or datacenters. Legal basis: Consent (explicit via form submission, Section 6 DPDP Act); contractual necessity for fee processing/refunds.
-
Retention: Enquiry data held for 2 years post-interaction or until resolution/refund (e.g., 50% after 180 days if no sale); deleted upon request or inactivity.
-
Sharing: With payment processors (e.g., for fees—subject to their policies) or partners for collaborations (only with your explicit consent). If using Microsoft Clarity for form analytics, limitations include potential capture of sensitive interactions in recordings, shared with third parties for security, without granular opt-outs. No broader sharing.
-
User Rights/Controls: Withdraw consent mid-process (e.g., cancel enquiry); access, correct, or erase data; receive portable copy. Refunds as per terms reinforce user control.
3. Product Pages (e.g., Pikkstop Page at /pikkstop)
-
Data Collected: Similar to homepage browsing data; if enquiry CTAs present, same as enquiry forms (e.g., contact details for pikkstop deployments). No additional collection beyond navigation logs.
-
Purposes and Legal Basis: To display product info (e.g., EV chargers, data pods) and handle related enquiries. Legal basis: Legitimate interests for site operation; consent for any form submissions.
-
Retention: Browsing logs: 30 days; enquiry data: As per Section 2.
-
Sharing: Analytics tools (e.g., Google Analytics if integrated—limitations: collects device/IP data, combines for ads/profiling across services, retains in backups post-deletion, shares with affiliates/partners for measurement/legal reasons). Mitigated by anonymization and no ad tracking.
-
User Rights/Controls: Same as homepage; block cookies to limit logging. Request data export related to product views.
4. Blog (If Implemented, e.g., at /blog)
-
Data Collected: Browsing data as per homepage; if comments/subscriptions enabled, email/name for posts or newsletters. No mandatory login.
-
Purposes and Legal Basis: To provide insights on phygital innovations, EV kiosks, and micro-business tools; engage users via comments. Legal basis: Legitimate interests for content delivery; consent for subscriptions/comments.
-
Retention: Comments: Indefinitely if public; subscriptions: Until unsubscribe. Logs: 30 days.
-
Sharing: With content management tools (e.g., if using third-party commenting—limitations similar to Clarity: potential interaction capture). No sharing for marketing without opt-in.
-
User Rights/Controls: Unsubscribe from newsletters; request comment deletion. Opt-out of analytics.
5. App Links/Downloads (e.g., Links to pikkc App at https://www.pikkc.com)
-
Data Collected: Click logs (anonymized); if downloading via Website, referral data. App-specific data handled per pikkc policy (e.g., photos/media stored locally/user's Google Drive—no access by us).
-
Purposes and Legal Basis: To facilitate app access for photo organization/IoT features. Legal basis: Legitimate interests for referrals; consent implied by click.
-
Retention: Logs: 30 days. No app data collected via Website.
-
Sharing: With app stores (e.g., Google Play—limitations: collects usage stats, device IDs, links to ads, retains data for fraud prevention, shares with developers/partners). pikkC ethos applies: No tracking; users control Drive data.
-
User Rights/Controls: No Website data tied to app; refer to pikkc policy for app rights (e.g., delete via settings).
6. Contact Methods (e.g., Email, Phone, WhatsApp in Footers/Forms)
-
Data Collected: Provided details (e.g., email to ceo@pikk.co.in, phone +91-9066777455) for general queries.
-
Purposes and Legal Basis: To respond to support/partnership requests. Legal basis: Consent via submission.
-
Retention: 1 year post-resolution.
-
Sharing: Communication tools (e.g., WhatsApp—limitations: Meta collects metadata, messages encrypted but shared for legal/safety). No unsolicited sharing.
-
User Rights/Controls: Request erasure; opt-out of future contacts.
7. Site-Wide Elements (Cookies, Analytics, Integrations)
-
Data Collected: Cross-site: Cookies (essential only), analytics (e.g., Clarity/Google—device/interaction data).
-
Purposes and Legal Basis: Functionality/security. Legal basis: Legitimate interests; consent for analytics.
-
Retention: Cookies: Session-based; analytics: Up to 2 years (aggregated).
-
Sharing: As noted per tool (e.g., Clarity limitations: Recordings/profiling, no full opt-out; Google: Ad-linked data, indefinite retention in some cases).
-
User Rights/Controls: Consent banner; browser opt-outs; data access requests.