Last updated: August 12, 2026
This Privacy Policy explains how Arechs Group collects, receives, uses, processes, stores, discloses, protects and otherwise handles Personal Data through its websites, distributor and customer portals, applications and related digital services.
1. Introduction
This Privacy Policy explains how Arechs Group and its relevant group companies, affiliates and entities ("Company", "Arechs Group", "we", "us" or "our") collect, receive, use, process, store, disclose, protect and otherwise handle Personal Data through its websites, online platforms, distributor portals, customer portals, applications, digital services and related business interactions (collectively, the "Website" or "Services").
This Privacy Policy applies to individuals who access or use the Website, including customers, prospective customers, distributors, prospective distributors, suppliers, service providers, business representatives and other persons interacting with the Company ("User", "you" or "your").
The Company recognises the importance of protecting Personal Data and is committed to processing such data in a lawful, fair, transparent and secure manner.
This Privacy Policy is intended to be read together with the Company's Terms of Service (https://www.arechs.com/terms) and other applicable policies or contractual documents.
2. Applicability and scope
This Privacy Policy applies to Personal Data collected or processed by the Company through the Company's websites and web pages, distributor portals, customer portals, online ordering platforms, enquiry and contact forms, registration forms, email communications, customer and distributor communications, digital applications and services, cookies and similar technologies, and other lawful business interactions.
This Privacy Policy applies whether Personal Data is collected directly from the User or received from another person or organisation acting lawfully on the User's behalf.
Where a particular service or transaction is governed by a separate privacy notice or contractual provision, such specific provision shall apply to the extent of any inconsistency.
3. Definitions
"Applicable Law" means all applicable laws, rules, regulations, notifications, directions and governmental requirements relating to privacy, data protection, information security and electronic communications, including the Digital Personal Data Protection Act, 2023 and rules or regulations made thereunder, to the extent applicable.
"Company" means the relevant Arechs Group entity which collects or processes the relevant Personal Data.
"Data Fiduciary", "Data Processor", "Data Principal", "Personal Data" and other expressions used in this Privacy Policy shall, where applicable, have the meanings assigned to them under Applicable Law.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Processing" includes collecting, recording, organising, storing, adapting, retrieving, using, disclosing, transferring, erasing or otherwise dealing with Personal Data.
"Services" means the Website, portals, digital services, online ordering facilities and other services made available by the Company.
"User" means any individual accessing or interacting with the Website or Services.
4. Information we collect
Depending upon the nature of the User's interaction with the Company, the Company may collect the following categories of Personal Data: Identity Information — name, designation, organisation and other information voluntarily provided by the User; Contact Information — email address, telephone/mobile number, business address and correspondence details; Business Information — company name, designation, distributor details, customer details, business requirements and transaction-related information; Account Information — username, login credentials, account identifiers and authentication information; Transaction Information — orders, quotations, invoices, purchase history, delivery information, payment references and related commercial records; Communication Information — emails, enquiries, correspondence, feedback, support requests and other communications with the Company; Technical Information — IP address, browser type, operating system, device information, access times and technical logs; Website Usage Information — pages visited, links accessed, downloads, navigation patterns and interactions with the Website; Location Information — approximate location information derived from technical information where reasonably necessary for security, analytics or service functionality; and other information voluntarily provided by the User or lawfully obtained by the Company.
5. Information collected from other sources
The Company may receive Personal Data from third parties where such collection is lawful and reasonably necessary for its business purposes.
Such sources may include distributors, customers, authorised representatives, business partners, service providers, logistics providers, payment service providers, publicly available sources, group companies, and governmental or regulatory authorities.
Where required by Applicable Law, the Company shall take reasonable steps to ensure that Personal Data received from third parties has been lawfully collected and may be lawfully shared with the Company.
6. Purposes of processing Personal Data
The Company may process Personal Data for the following purposes: providing and administering the Website and Services; responding to enquiries and requests; registering and managing customer and distributor accounts; processing orders and quotations; facilitating delivery and logistics; issuing invoices and maintaining business records; processing or facilitating payments; providing customer and distributor support; communicating with Users; managing contractual and commercial relationships; conducting due diligence and credit assessment; preventing fraud, misuse and unauthorised access; maintaining cybersecurity and Website integrity; analysing Website performance and improving Services; sending marketing and promotional communications where permitted by law; complying with legal, regulatory and governmental requirements; enforcing contractual rights and obligations; resolving disputes and investigating complaints; protecting the Company's rights, property and interests; and any other lawful purpose for which the Personal Data has been collected or may otherwise lawfully be processed.
7. Legal basis for processing
The Company shall process Personal Data only in accordance with Applicable Law.
Depending upon the circumstances, processing may be undertaken on the basis of valid consent; for the performance of a contract or steps requested prior to entering into a contract; for compliance with a legal or regulatory obligation; for legitimate and lawful business purposes, where recognised by Applicable Law; for responding to a request made by the User; or on any other lawful basis available under Applicable Law.
Where consent is relied upon, the Company shall seek consent in an appropriate manner and shall not treat consent as having been provided merely because a User has accessed the Website, except where such consent is lawfully implied or otherwise permitted.
8. Consent
Where processing is based upon consent, the Company shall seek consent in a manner that is free, specific, informed, unconditional (where required by law), and capable of being withdrawn in accordance with Applicable Law.
A User may withdraw consent by using the mechanism made available by the Company or by contacting the Company at legal@rmc.in.
Withdrawal of consent shall not affect the lawfulness of processing undertaken before such withdrawal.
Where withdrawal of consent prevents the Company from providing a particular service, the Company may inform the User of the resulting consequences.
9. Voluntary provision of Personal Data
Unless expressly stated otherwise, providing Personal Data to the Company is voluntary.
However, certain Personal Data may be necessary to create an account, process an order, provide requested Services, respond to an enquiry, fulfil contractual obligations, or comply with applicable legal requirements.
Where required information is not provided, the Company may be unable to provide the relevant service or complete the relevant transaction.
10. Principles governing processing
The Company seeks to apply the following principles when processing Personal Data: Lawfulness and Transparency — Personal Data shall be processed in accordance with Applicable Law and appropriate transparency requirements; Purpose Limitation — Personal Data shall be processed for specified and legitimate purposes; Data Minimisation — the Company shall seek to collect information reasonably necessary for the relevant purpose; Accuracy — reasonable measures shall be taken to maintain accurate and up-to-date Personal Data where necessary; Security — appropriate technical and organisational safeguards shall be implemented; Retention Limitation — Personal Data shall not be retained longer than reasonably necessary or permitted by law; and Accountability — the Company shall maintain appropriate processes and controls for responsible handling of Personal Data.
The Company may retain information where necessary for compliance with legal obligations, establishment or defence of legal claims, dispute resolution, audit, regulatory requirements, legitimate business records or other lawful purposes.
11. Cookies and similar technologies
The Website may use cookies, web beacons, pixels, software development kits (SDKs), local storage objects and other similar technologies ("Cookies") to improve user experience, enhance Website functionality, analyse Website traffic, maintain security and facilitate business operations. Cookies enable the Company to recognise returning Users, maintain login sessions, remember user preferences and understand how the Website is being used.
The Company may use the following categories of Cookies: Strictly Necessary Cookies, Functional Cookies, Performance Cookies, Analytics Cookies, Security Cookies, Preference Cookies, Session Cookies, Persistent Cookies, Authentication Cookies, and Marketing Cookies (where applicable).
Where required by applicable law, Users will be requested to provide consent before non-essential Cookies are placed on their devices. Users may withdraw such consent at any time through their browser settings or the cookie management tool provided on the Website.
Users may disable Cookies through browser settings. However, disabling Cookies may result in certain portions of the Website, including distributor login, customer accounts and online ordering functionality, not operating correctly.
12. Distributor portal
The Website may provide secure access to authorised distributors.
Information processed through the Distributor Portal may include distributor registration details, authorised representatives, user credentials, purchase history, quotations, pricing information, product catalogues, inventory availability, order status, invoices, payment history, credit information, and communication records.
The Company may use such information for distributor administration, order processing, customer support, commercial communications, credit management, business analytics, fraud prevention, and contractual compliance.
The Company reserves the right to suspend distributor accounts where fraudulent activity, misuse or unauthorised access is suspected.
13. Customer accounts
Where customer registration functionality is introduced, Users may create customer accounts.
Customer accounts may store identity information, contact details, delivery addresses, purchase history, order preferences, invoices, payment references, communications, and technical support requests.
Users shall be responsible for maintaining the confidentiality of their login credentials. The Company shall not be liable for unauthorised access resulting from the User's failure to adequately protect passwords or authentication credentials.
14. Online orders and payment information
Where online ordering is introduced, the Website may facilitate quotation requests, purchase orders, order confirmations, invoice generation, shipment tracking, returns, and customer support.
Payment transactions may be processed through authorised third-party payment service providers. The Company shall not store complete payment card information unless expressly required by law and processed in accordance with applicable payment security standards.
Users acknowledge that payment processing may be subject to the privacy policies and terms of the relevant payment gateway. The Company shall not be responsible for the privacy practices of independent payment processors.
15. Marketing communications
The Company may send newsletters, product updates, technical bulletins, promotional offers, seminar invitations, exhibition announcements, regulatory updates, and business communications.
Where required by applicable law, such communications shall be sent only after obtaining appropriate consent.
Users may unsubscribe from marketing communications at any time through the unsubscribe link, account settings, written request, or email to legal@rmc.in.
Withdrawal of consent shall not affect communications necessary for contractual performance, legal compliance or account administration.
16. Analytics
The Company may use analytics tools to understand Website usage, visitor behaviour, page performance, download activity, navigation patterns, device information, geographic trends, and referral sources.
Analytics information may be aggregated and anonymised. Such information assists the Company in improving Website performance, security, products and services.
Where third-party analytics providers are engaged, they shall be contractually required to process information only for authorised purposes and in accordance with applicable law.
17. Third-party service providers
The Company may engage third-party service providers for Website hosting, cloud infrastructure, email communications, customer relationship management, analytics, cybersecurity, payment processing, logistics integration, customer support, document management, and marketing automation.
Such service providers shall have access only to information necessary for performing their services and shall be contractually obligated to maintain confidentiality and implement appropriate security measures.
The Company shall exercise reasonable diligence in selecting service providers but shall not be liable for independent acts or omissions of such providers beyond the extent required by applicable law.
18. Third-party websites
The Website may contain links to websites operated by third parties. The Company has no control over the privacy practices of such websites.
Users are encouraged to review the privacy policies of third-party websites before providing personal information. The inclusion of a third-party link does not constitute endorsement or approval by the Company.
19. Social media
The Website may include links to social media platforms or enable interaction with official Company pages on such platforms.
Where Users voluntarily interact with the Company's social media pages, the collection and processing of personal data shall also be governed by the privacy policies of the relevant social media platform. The Company shall not be responsible for the privacy practices of such platforms.
20. Cross-border transfer of Personal Data
The Company forms part of an international business group and may engage with customers, distributors and service providers located in multiple jurisdictions.
Accordingly, personal data may be transferred to, stored in or accessed from jurisdictions outside India where such transfer is necessary for contractual performance, required for customer support, necessary for order fulfilment, required for IT infrastructure, necessary for cloud hosting, required by law, or otherwise permitted under applicable law.
The Company shall take reasonable steps to ensure that any recipient of personal data outside India provides a level of protection substantially comparable to that required under applicable law and that such transfers are undertaken in accordance with the Digital Personal Data Protection Act, 2023 and other applicable legal requirements.
21. Data security
The Company shall implement reasonable and appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, disclosure, alteration, loss, misuse, destruction or other unlawful processing.
Depending upon the nature and volume of Personal Data processed, such measures may include access controls and role-based permissions; authentication and authorisation mechanisms; encryption or other appropriate protection measures; secure storage and transmission of Personal Data; system monitoring and security logging; vulnerability assessment and security testing; malware and intrusion protection; backup and disaster-recovery measures; secure software-development and deployment practices; employee and contractor confidentiality obligations; security awareness and training; vendor and Data Processor security controls; and periodic review and improvement of security safeguards.
Where applicable, the Company shall implement the security measures prescribed under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), as and when the relevant provisions become applicable.
The notified DPDP Rules specifically contemplate measures such as encryption, masking or tokenisation, access controls, logging and monitoring, backups, contractual security provisions with Data Processors, and appropriate technical and organisational measures.
Access to Personal Data shall be limited to personnel, contractors and service providers who require such access for legitimate business purposes. The Company may maintain access logs and other records for security monitoring, investigation, audit and compliance purposes.
Users are responsible for maintaining the confidentiality of their account credentials, and shall use reasonably secure passwords, not share authentication credentials, not permit unauthorised persons to access their accounts, promptly notify the Company of suspected unauthorised access, and cooperate reasonably with security investigations.
22. Personal Data breaches
In the event of an actual or reasonably suspected Personal Data breach, the Company shall take appropriate measures to identify and contain the incident, assess its nature and scope, mitigate potential harm, secure affected systems, investigate the circumstances, implement corrective measures, maintain appropriate records, and make legally required notifications.
Where required under applicable law, the Company shall notify affected Data Principals of a Personal Data breach; such notification may include information concerning the nature and extent of the breach, the likely consequences, measures taken or proposed to mitigate the impact, steps the Data Principal may take to protect themselves, and appropriate contact information for further assistance.
The DPDP Rules prescribe specific breach-notification requirements, including notification to affected Data Principals without delay and notification to the Data Protection Board in accordance with the prescribed requirements.
Where a breach occurs at a Data Processor or other service provider handling Personal Data on behalf of the Company, the Company may require the service provider to promptly notify the Company, cooperate with the investigation and take appropriate remedial action.
23. Data retention and deletion
The Company shall retain Personal Data only for as long as reasonably necessary for the purpose for which it was collected, performance of a contract, provision of products or services, customer or distributor account administration, compliance with legal, regulatory, tax, accounting or reporting obligations, establishment, exercise or defence of legal claims, fraud prevention and security, legitimate business record-keeping, or any other lawful purpose permitted under applicable law.
When Personal Data is no longer required for the purpose for which it was collected, and there is no legal, regulatory, contractual or legitimate requirement to retain it, the Company shall take reasonable steps to delete, anonymise or otherwise render such Personal Data no longer attributable to an identifiable individual — whether through permanent deletion, secure destruction, anonymisation, aggregation, or another legally permissible method.
Deletion requests shall not require the Company to delete information where retention is necessary or permitted under applicable law, including information required for taxation, accounting, regulatory compliance, contractual records, dispute resolution, fraud prevention, cybersecurity, legal proceedings, or enforcement of contractual rights. The Company may retain such information for the applicable retention period and restrict its use to the purpose for which retention is required.
Security logs, audit records and technical information may be retained for appropriate periods for cybersecurity, investigation, fraud prevention, system integrity and legal compliance.
The DPDP Rules prescribe specific retention requirements for certain logs and Personal Data in specified circumstances, including a minimum one-year period for certain security and processing records, subject to applicable law.
24. Rights of Data Principals
Subject to applicable law and the commencement of the relevant provisions of the DPDP Act, a Data Principal may have the following rights in relation to their Personal Data.
Right to access information. A Data Principal may request information concerning the Personal Data processed by the Company, including information regarding processing activities to the extent required by applicable law.
Right to correction and updating. A Data Principal may request correction, completion or updating of inaccurate, incomplete or misleading Personal Data maintained by the Company. The Company may require reasonable information necessary to verify the request and protect against fraudulent or unauthorised requests.
Right to erasure. A Data Principal may request deletion of Personal Data where permitted by applicable law. The Company may decline or defer deletion where retention is legally required or otherwise permitted.
Right to withdraw consent. Where processing is based on consent, a Data Principal may withdraw consent at any time; withdrawal shall not affect the lawfulness of processing carried out before it, and where processing is necessary for a contract, legal obligation, security, fraud prevention or another lawful basis, withdrawal may not result in cessation of such processing. The Company shall provide a mechanism for withdrawal of consent that is as easy to use as the mechanism through which consent was provided, where required under applicable law, as expressly addressed under the DPDP Rules.
Right to grievance redressal. A Data Principal may raise a grievance concerning the Company's processing of Personal Data, and the Company shall provide an appropriate mechanism for submitting and resolving such grievances in accordance with applicable law.
Right to nominate. Where applicable under the DPDP Act, a Data Principal may nominate another individual to exercise their rights in accordance with the prescribed legal framework.
25. How to exercise Data Principal rights
Requests relating to Personal Data may be submitted through the contact mechanism specified in this Privacy Policy.
A request should, where reasonably possible, include the name of the requester, contact details, the nature of the request, sufficient information to identify the relevant account or relationship, and any other information reasonably necessary to process the request.
The Company may request reasonable verification information before acting on a request. This is intended to protect Data Principals against unauthorised disclosure, alteration or deletion of Personal Data.
26. Identity verification
The Company may take reasonable measures to verify the identity of a person making a request relating to Personal Data.
Verification may include confirmation through a registered email address, authentication through an account, confirmation through a registered mobile number, other reasonable authentication mechanisms, or additional documentation where reasonably necessary.
The Company shall seek to avoid collecting excessive information solely for the purpose of processing a rights request.
27. Grievance redressal
Users and Data Principals may submit complaints concerning collection or use of Personal Data, accuracy of Personal Data, account-related processing, withdrawal of consent, requests for correction or deletion, suspected misuse of Personal Data, security incidents, or other privacy-related concerns.
The Company shall designate an appropriate person responsible for addressing privacy-related queries and grievances, and the relevant contact details shall be displayed on the Website and/or in the applicable privacy notice. Where a Data Protection Officer ("DPO") is required to be appointed under applicable law, the Company shall publish the DPO's business contact information in the manner prescribed by law.
The DPDP Rules require a Data Fiduciary to prominently publish contact information for responding to questions concerning Personal Data processing and Data Principal rights, including DPO information where applicable.
The Company shall make reasonable efforts to review and resolve valid privacy grievances within the period prescribed by applicable law, and may request additional information from the complainant where required.
28. Children's Personal Data
The Website is primarily intended for business customers, distributors, professionals and other adult Users. The Company does not knowingly seek to collect Personal Data from children except where permitted and appropriately authorised under applicable law.
Where the Company processes Personal Data of a child, it shall implement the safeguards required under applicable law, including requirements relating to parental or lawful guardian consent where applicable. The DPDP Rules prescribe mechanisms concerning verifiable parental consent and require appropriate technical and organisational measures in relation to processing a child's Personal Data.
The Company shall not knowingly undertake processing of children's Personal Data in a manner prohibited by applicable law.
29. Compliance, audit and cooperation
The Company may maintain appropriate records, policies, procedures and controls relating to Personal Data processing.
The Company may periodically review its privacy practices, access controls, security measures, Data Processor arrangements, retention practices, consent mechanisms, rights-request procedures, and incident-response procedures.
Where required by applicable law, the Company shall cooperate with the competent regulatory authorities and comply with lawful directions, orders and statutory requirements. The Company may also conduct internal or external assessments of its privacy and information-security practices where considered appropriate.
30. Changes to this Privacy Policy
The Company may update this Privacy Policy from time to time to reflect changes to its products or services, changes to the Website or Distributor Portal, introduction of online ordering or other functionality, changes in data-processing practices, changes in applicable laws or regulations, regulatory guidance, changes to technology or security practices, or other legitimate business requirements.
The updated Privacy Policy shall be published on the Website with the revised "Last Updated" date. Where required by applicable law, the Company shall provide additional notice or obtain fresh consent before implementing material changes that require such action.
Continued use of the Website after an updated Privacy Policy becomes effective shall be subject to the revised Policy to the extent permitted by applicable law.
31. Contact information
For privacy-related questions, requests, complaints or the exercise of Data Principal rights, Users may contact the relevant Arechs Group entity at its registered office, World Trade Centre, Unit 49, 1st Floor, Arcade Building, Cuffe Parade, Colaba, Mumbai 400005, by email at legal@rmc.in, or by telephone at +91 22 6947 1000.
The Company's Data Protection Officer is Ranganatha Rao, who may be contacted at legal@rmc.in for privacy-related queries, requests and grievances.
32. Governing law
This Privacy Policy shall be governed by and interpreted in accordance with the laws of India, to the extent applicable. Nothing in this Privacy Policy shall limit any statutory rights available to a Data Principal under applicable law.
Where the Website is accessed or used outside India, additional privacy rights or obligations may apply depending upon the User's jurisdiction and the Company's activities in that jurisdiction.
33. Severability
If any provision of this Privacy Policy is determined to be invalid, unlawful or unenforceable, such provision shall be interpreted to the maximum extent permitted by law, and the remaining provisions shall continue in full force and effect.
34. Entire Privacy Policy
This Privacy Policy, together with any applicable notices, consent mechanisms, the Company's Terms of Service (https://www.arechs.com/terms), Distributor Portal terms and other privacy-related notices published by the Company, constitutes the Company's privacy framework for the Website and related digital services.
Where a specific privacy notice applies to a particular product, service, transaction or processing activity, that notice shall be read together with this Privacy Policy.