1. Overview
Rethela Technology Private Limited ("AdMesh", "we", "our", "us") operates the AdMesh platform — a verified physical retail advertising network. We act as a Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 (DPDP Act).
This policy applies to all individuals who interact with our platform, including brand partners, store owners (Carriers), visitors to our website, and users of our dashboard applications.
By using our services, you acknowledge that you have read, understood, and consented to the practices described in this policy. If you do not agree, please discontinue use of our services.
2. Data We Collect
We collect personal data only to the extent necessary to deliver our services. Under the DPDP Act, we practise data minimisation — collecting only what is required for a specific, stated purpose.
2.1 Account & Identity Data
- Full name
- Email address
- Company name and designation
- Phone number
- GST / MSME registration number (Carrier accounts)
2.2 Campaign & Business Data
- Campaign briefs, target geographies, and creative assets uploaded to the platform
- Billing and invoicing information
- Campaign performance data and analytics
2.3 Location & Operational Data
- GPS coordinates of registered store nodes (Carrier accounts)
- Photographic proof-of-display images captured by ground agents
- Timestamp and device metadata associated with proof uploads
2.4 Technical & Usage Data
- IP address, browser type, device identifiers
- Pages visited, session duration, clickstream data
- Error logs and diagnostic data for service improvement
2.5 Communication Data
- Emails or messages sent to our support team
- Form submissions (pilot requests, carrier registrations)
- Survey responses or feedback provided voluntarily
3. How We Use Your Data
We use collected data strictly for the purposes disclosed at the time of collection. We do not use your personal data for purposes beyond those explicitly stated, consistent with the purpose limitation principle of the DPDP Act.
4. Legal Basis for Processing (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, we process your personal data on the following lawful bases:
Consent
You have given free, specific, informed, and unambiguous consent for processing. Consent is obtained at the point of account creation or service enrolment. You may withdraw consent at any time by contacting us at legal@admesh.co.in.
Contract Performance
Processing is necessary to deliver our services to you — including campaign deployment, Carrier node activation, and payment processing.
Legal Obligation
We may process data to comply with applicable Indian laws, regulations, or court orders, including GST filing, KYC requirements, and responding to lawful government requests.
Legitimate Interests
We process certain technical and usage data to maintain platform security, detect fraud, and improve service quality — where this does not override your fundamental rights.
5. Your Rights as a Data Principal
Under the DPDP Act, 2023, you (the Data Principal) have the following rights, which we are legally obligated to honour:
Right to Access
Request a summary of personal data we hold about you and how it is being processed.
Right to Correction
Request correction of inaccurate, incomplete, or outdated personal data.
Right to Erasure
Request deletion of your personal data, subject to legal retention obligations.
Right to Grievance Redressal
File a complaint with our Grievance Officer and receive a response within 48 hours.
Right to Withdraw Consent
Withdraw previously given consent for any processing activity at any time.
Right to Nominate
Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email us at legal@admesh.co.in. We will respond within 30 days, as required by the DPDP Act.
6. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share data only in the following limited circumstances:
Cross-border transfers: Where data is transferred outside India, we ensure appropriate safeguards are in place as per Section 16 of the DPDP Act and applicable rules notified by the Central Government.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. In general:
Upon expiry of the retention period, data is securely deleted or anonymised in accordance with our data lifecycle management procedures.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
In the event of a personal data breach, we will notify affected Data Principals and the Data Protection Board of India as required under the DPDP Act.
10. Children's Privacy
Our services are not directed to children under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at legal@admesh.co.in and we will promptly delete such data as required under Section 9 of the DPDP Act.
11. Grievance Redressal
As required by the DPDP Act, we have designated a Grievance Officer to address any complaints or concerns regarding your personal data.
Organisation: Rethela Technology Private Limited
Platform: AdMesh
Email: legal@admesh.co.in
General Enquiries: hello@admesh.co.in
Response Time: We will acknowledge complaints within 48 hours and resolve within 30 days.
If your complaint is not resolved to your satisfaction, you may approach the Data Protection Board of India as constituted under the DPDP Act, 2023.
12. Policy Updates
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to your registered address) and post a prominent notice on our platform at least 14 days before the changes take effect.
Continued use of our services after the effective date of the revised policy constitutes your acceptance of the updated terms.
Questions about your data or this policy?