PRIVACY POLICY

PRIVACY POLICY

A. Introduction and Our Commitment:-

Petrolube Trade Private Limited (hereinafter referred to as "Petrolube Trade", "Company", "we", "us", or "our") operates a strictly Business-to-Business (B2B) digital marketplace platform (website, mobile applications, dashboards, and APIs) that facilitates trade in petroleum products, lubricants, bitumen, base oils, and related commodities between verified corporate buyers and sellers. We are fully committed to protecting the privacy and security of all information we process and to complying with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and all other applicable laws in India and international jurisdictions where our Users operate. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Legal Compliance:

We are committed to complying with all applicable data protection and privacy laws, including but not limited to the Digital Personal Data Protection Act, 2023 (DPDP Act), and any other relevant Indian or international regulations that may govern the collection and processing of personal, financial, and business data. This Policy reflects our intent to fully honour Users' statutory rights and to maintain lawful data processing practices.

2. Transparency of Data Practices:

This Policy clearly describes: a.The categories of information collected from Users, whether personal, business-related, or transactional. b.The purposes for which such information is collected, processed, and retained. c.The manner and scope of data storage, usage, sharing, and disclosure. d.The legal basis and obligations under which information is processed.

By providing this clarity, we aim to prevent any misunderstandings, disputes, or interpretations regarding the handling of their information.

3. User Rights and Control:

This Policy outlines Users' rights concerning their personal and business information, including the right to access, correct, delete, restrict processing, and object to the use of their data, in accordance with applicable laws. It also explains the mechanisms by which Users can exercise such rights.

4. Data Security and Risk Mitigation:

We commit to adopting reasonable administrative, technical, and physical safeguards to protect all collected data from unauthorized access, disclosure, alteration, or destruction. This includes sensitive business transaction details, financial information, and personal identifiers. By explicitly defining these measures, this Policy reduces potential legal liability and establishes clear standards for protection.

5. Operational Transparency:

Petrolube Trade operates as a B2B marketplace connecting Buyers and Sellers of petroleum products. All interactions, transactions, and communications via the platform are subject to this Policy. By outlining our data practices in detail, Users are fully informed of their rights, responsibilities, and obligations when using our platform, ensuring operational clarity and trust between all parties.

B. Scope & Applicability: -

This Privacy Policy governs the collection, processing, storage, usage, disclosure, and protection of information provided by or collected from all Users who access, interact with, or transact through the Petrolube Trade B2B marketplace platform. This includes information collected via our website, mobile applications, dashboards, APIs, or any other communication channels operated by the Company.

1. Applicability:

This Policy specifically applies to the following categories of Users:

1.Buyers: Entities or representatives of companies procuring petroleum products via the platform.

2.Sellers: Entities, manufacturers, distributors, or suppliers listing petroleum or petroleum-related products for sale on the platform.

3.Logistics Partners / Agents: Logistics Partners / Agents: Independent third-party service providers engaged directly by Buyers or Sellers for transportation, delivery, or storage of petroleum products. Petrolube Trade does not itself provide logistics, transportation, delivery, warehousing, or handling services. Any logistics activity is arranged solely between the concerned Buyer, Seller, and the third-party logistics provider, without the Company's involvement, responsibility, or control.

4.Visitors: Any individual or entity accessing the platform, website, dashboard, or related communications, to the extent such access involves information collection or interaction with the platform.

2. B2B Transactions Only:

This Privacy Policy applies exclusively to business-to-business (B2B) commercial transactions carried out through the Petrolube Trade platform. The platform is designed, structured, and operated solely for use by legally registered business entities and their authorized representatives engaged in the procurement or supply of petroleum and petroleum-related products. This Policy does not apply to individual consumers, end-users, or any transactions undertaken for personal, household, or non-commercial purposes. Since the Platform is intended solely for commercial B2B use by registered business entities. Use by individuals for personal purposes is prohibited and is not covered by this Policy. Any individual attempting to use the platform for non-commercial or personal activity does so entirely at their own risk, without creating any obligations, liabilities, or duties for the Company.

3. Exclusions:

This Privacy Policy does not apply to any interactions, accesses, or transactions undertaken by individuals for personal, non-commercial, or household purposes. Any data processing arising from activities unrelated to the commercial procurement or supply of petroleum or petroleum-related products falls outside the scope of this Policy. Petrolube Trade operates strictly as a B2B marketplace, and consequently, the Company does not assume any responsibility or liability for compliance with consumer-specific laws or regulations applicable to personal or individual use. Any person accessing or attempting to use the platform for personal purposes does so entirely at their own risk, and the Company shall not be held accountable for any resulting obligations, claims, or consequences.

C. Types of Information We Collect: -

Petrolube Trade adheres to the principle of data minimization, meaning we collect only the information strictly necessary to facilitate safe, lawful, and efficient B2B transactions in petroleum products. We do not collect excessive, irrelevant, or sensitive personal information beyond what is required for operational, legal, or regulatory purposes.

1. Business Information:

For all Users engaging in B2B transactions on the platform, we collect the following business-related information:

1.Company Name: The registered legal name of the entity using the platform.

2.Registered Business Address: The official address of the business, as required for legal documentation, invoicing, and regulatory compliance.

3.GST Number: Goods and Services Tax Identification Number, necessary for taxation, invoicing, and legal verification in India.

4.PAN / CIN: Permanent Account Number or Corporate Identification Number for regulatory compliance, audit, and business verification.

5.Licensing Documents: Any licenses, permits, or certifications required to legally trade, store, or transport petroleum products, including approvals under relevant petroleum regulations.

6.Official Email Address: Corporate email for communication, notifications, verification, and record-keeping purposes.

7.Authorized Signatory Details: Name, designation, and contact information of individuals legally authorized to act on behalf of the business for transactions, agreements, or regulatory compliance.

2. Identification Information (for Verification)

To maintain the integrity, security, and lawful operation of the Petrolube Trade B2B marketplace, we collect certain identification and verification information from Users, specifically to prevent fraud, fake orders, shell companies, and violations of petroleum safety or regulatory norms.

The information collected may include:

1.Name of Authorized Representative: The full name of the individual legally empowered to act on behalf of the business entity for transactions and contractual obligations.

2.Identity Proof: Government-issued identification documents such as Aadhaar, Passport, Voter ID or Driving License of the authorized representative(s), strictly for the limited purpose of KYC/Verification to confirm identity and legal authority. The Platform shall not store copies of sensitive government ID documents longer than necessary for the one-time verification process required by its third-party verification agencies, unless a longer retention period is explicitly required by applicable law (e.g., anti-money laundering regulations).

3.Business Verification Documents: Documents demonstrating the legitimacy of the business, including incorporation certificates, GST registration, licenses, or other regulatory approvals necessary for petroleum trade.

4.Contact Number: Mobile or landline number of the authorized representative for verification, urgent communication, and transaction confirmation.

5.Email Address: Official email address for communication, verification, transaction notifications, and records.

3. Transaction Information:

To ensure smooth, secure, and legally accountable operations on the Petrolube Trade B2B marketplace, we collect information relating to all commercial transactions and interactions conducted through the platform. This includes, but is not limited to:

1.Orders Placed: Detailed records of all orders submitted by Buyers, including product specifications, quantity, pricing, and order timestamps.

2.Bids Submitted: Information on bids placed by Sellers or Buyers during platform-facilitated negotiations or auctions.

3.Commission Details: Records of any platform fees, commissions, or service charges applicable to a particular transaction.

4.Payment / Advance Transaction Records: Documentation of financial transactions made through or in connection with the platform, including payment methods, amounts, dates, and transaction confirmations.

5.Delivery Instructions: Shipping, logistics, or delivery-related instructions provided by Buyers or Sellers for order fulfillment.

6.Negotiation History: Any negotiation communications conducted via the platform, including counter-offers, clarifications, and agreements, where applicable.

4. System and Technical Data:

To protect the security, integrity, and proper functioning of the Petrolube Trade B2B marketplace, the platform collects certain technical and system-related information from Users during their interactions with the platform. This information includes, but is not limited to:

1.IP Address: The Internet Protocol address from which a User accesses the platform, used to identify network origins, detect unusual activity, and prevent unauthorized access.

2.Device Type: Information regarding the hardware or device used to access the platform, including operating system, device model, and device identifiers, to ensure compatibility and secure access.

3.Browser Information: Details of the web browser, version, and settings, used to optimize the platform experience, identify potential vulnerabilities, and monitor secure session activity.

4.Cookies and Session Data: Cookies or similar tracking technologies used solely for session management, authentication, security, and operational purposes, including maintaining logged-in status and preventing unauthorized access.

D. How We Use Your Information: -

Petrolube Trade collects and processes User information strictly for legitimate business purposes essential to operating a secure, lawful, and efficient B2B petroleum marketplace. The collected information is used for the following purposes:

1.Account Verification & Onboarding: To confirm the identity and legitimacy of Users before enabling access to the platform.

2.KYC and Compliance Verification: To comply with statutory requirements, including regulatory, licensing, taxation, and anti-money laundering obligations.

3.Facilitating Product Listings: To allow Sellers to list petroleum products accurately and enable Buyers to access verified product information.

4.Enabling Bidding, Negotiation & Purchase: To support commercial interactions between Buyers and Sellers, including offers, counter-offers, and finalizing transactions.

5.Securing the 5% Advance from Buyers: To ensure legitimate transaction processing and safeguard prepayment against misuse or fraud.

6.Commission Settlement with Sellers (0.5% / 0.25%): To calculate, process, and document commissions payable to the platform transparently and accurately.

7.Fraud Prevention: To detect, prevent, and mitigate fraudulent activities, unauthorized transactions, and fake accounts.

8.Legal and Regulatory Compliance: To meet obligations under Indian law, including DPDP Act, petroleum trade regulations, GST, corporate law, and other applicable statutes.

9.Ensuring Transparent and Auditable Trade: To maintain records, audit trails, and transaction history for dispute resolution, accountability, and operational transparency.

E. Sharing of Information: -

Petrolube Trade does not sell, rent, or otherwise commercialize User data. Information is shared only when strictly necessary to facilitate legitimate B2B operations, regulatory compliance, or legal obligations.

1. Buyer-Seller Information Exchange:

Buyer information is shared with the relevant Seller only after explicit buyer confirmation or consent for the specific transaction. Similarly, Seller information is shared with the relevant Buyer only when required for order processing, negotiation, or delivery, and after necessary consent.

2. Third-Party Service Providers

To enable secure, efficient, and legally compliant operation of the Petrolube Trade B2B marketplace, the Company may share certain User information with trusted third-party service providers strictly for purposes necessary to support platform functionality and transaction execution. Such service providers may include, but are not limited to:

1.Payment Gateways: To process payments, advances, commissions, and refunds securely.

2.Logistics Partners: To facilitate shipment, delivery, and tracking of petroleum products.

3.Verification Agencies: To conduct KYC, identity verification, and business legitimacy checks in compliance with applicable regulations.

4.Cloud Storage and IT Service Providers: To store and manage data securely, support platform operations, and ensure system reliability.

3. Regulatory or Legal Authorities

Petrolube Trade may share User information only when legally required to comply with applicable laws, regulations, or governmental directives. Such disclosures are strictly limited to what is necessary to fulfill statutory obligations and may include, but are not limited to:

1.Digital Personal Data Protection Act (DPDP Act): To comply with lawful requests from regulatory authorities regarding personal or business data.

2.Petroleum & Explosives Safety Organisation (PESO) Compliance: To meet safety, licensing, or trade-related inspections and requirements under petroleum regulations.

3.Goods and Services Tax (GST) Authorities: To provide information necessary for tax reporting, verification, or audit purposes.

4.Court Orders or Government Directives: To respond to judicial orders, government investigations, or lawful subpoenas.

F. Data Storage & Retention: -

Petrolube Trade is committed to securely storing and retaining User information in a manner that protects data integrity, confidentiality, and compliance with applicable laws.

1. Data Storage

1.All information collected through the platform is stored on secure servers with restricted access, protected by administrative, technical, and physical safeguards.

2.Access to data is limited to authorized personnel and third-party service providers who are contractually bound to maintain confidentiality and comply with data protection obligations.

3.Measures include encryption, secure authentication protocols, and regular audits to prevent unauthorized access, loss, or misuse.

2. Data Retention

1.User information is retained only as long as necessary to fulfill the purposes outlined in this Policy, including business operations, regulatory compliance, and transaction facilitation.

2.Petroleum transactions require retention of certain business, financial, and compliance documents for a minimum period of five (5) years, in accordance with statutory requirements, audit obligations, and potential dispute resolution needs.

3.Once data is no longer required for legitimate business or legal purposes, it is securely deleted or anonymized to prevent misuse

G. Security Measures: -

Petrolube Trade is committed to maintaining the highest standards of security to protect User information and ensure the integrity of all B2B transactions on the platform. We implement comprehensive administrative, technical, and physical safeguards, including but not limited to:

1.End-to-End Encrypted Data Transmission: All data exchanged between Users and the platform is encrypted using industry-standard protocols to prevent unauthorized interception or access.

2.Password Hashing and Secure Authentication: User passwords are stored in a hashed and salted format, and secure authentication protocols are enforced to prevent unauthorized account access.

3.Multi-Factor Authentication (MFA): Additional verification methods are implemented to enhance account security and prevent unauthorized logins.

4.Role-Based Access Control (RBAC): Access to sensitive information is restricted based on roles, ensuring that only authorized personnel can view or process specific data.

5.Server Firewalls & Intrusion Detection Systems: Robust firewalls and monitoring systems are deployed to detect and prevent cyber-attacks or unauthorized system access.

6.Periodic Vulnerability Assessments & Security Audits: Regular testing, monitoring, and auditing are conducted to identify and remediate potential security risks proactively.

H. User Rights:-

In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the principles of transparency and accountability, Users of the Petrolube Trade B2B marketplace are entitled to exercise the following rights with respect to their personal and business information:

1.Access: Users may request to view the information that the Company has collected and processed about them. This allows Users to verify accuracy and understand how their data is being used.

2.Correction: Users may request correction or updating of any inaccurate, incomplete, or outdated information. The Company will take reasonable steps to effect such corrections promptly.

3.Deletion / Erasure: Users may request deletion of information, where legally permissible and operationally feasible, provided such deletion does not conflict with statutory retention requirements, contractual obligations, or audit needs.

4.Withdrawal of Consent: Where processing is based on consent, Users may withdraw their consent at any time. Important: Withdrawal of consent may limit or restrict access to certain platform features, including the ability to place orders, receive deliveries, or participate in bidding.

We will respond to any valid request within 30 days (or shorter period prescribed by law). For complex requests we may extend by a further 30 days with notice.

I. Cookies & Tracking Technology: -

Petrolube Trade uses cookies and similar tracking technologies strictly for operational and security purposes. This includes:

Security: Detecting unauthorized access attempts and securing User sessions.

Session Management: Maintaining logged-in status, session continuity, and authentication during active use.

Platform Performance: Monitoring system functionality, page load performance, and technical errors to improve operational reliability.

Restrictions:

Cookies are not used for advertising, marketing, behavioral profiling, or any commercial exploitation of User data.

Users may manage browser settings to control cookies, although some functionality may be limited if cookies are disabled.

J. Email, SMS, and Communication Policy: -

Petrolube Trade may contact Users only for essential platform and transaction-related purposes, including:

1.Verification: Account creation, identity verification, and KYC procedures.

2.Transaction Updates: Order confirmations, delivery instructions, payment receipts, and commission settlements.

3.Bidding Notifications: Alerts regarding bids, negotiations, and counter-offers.

4.Policy Updates: Notices regarding changes to platform rules, privacy policy, or terms of service.

5.Security Alerts: Notifications about potential unauthorized access, account breaches, or platform vulnerabilities.

Limitations:

Users cannot opt out of essential communications, as these are required for secure and lawful operation of the B2B marketplace.

Promotional communications are sent only if the User has explicitly consented.

K. Third-Party Links Disclaimer: -

Users may come across links, references, or redirections to third-party websites, applications, or external service providers while using the Petrolube Trade platform. Petrolube Trade does not own, control, operate, supervise, monitor, or endorse any third-party websites, services, or their content, policies, or business practices.

Any interaction, communication, or transaction carried out on a third-party platform is entirely between the User and the third-party entity.

Petrolube Trade does not assume responsibility for:

The accuracy, legality, safety, or reliability of third-party content.

The manner in which third parties collect, process, store, or protect User data.

Any loss, damage, or harm resulting from visiting or using third-party platforms.

Users are strongly advised to carefully review and verify the privacy policies, terms of use, disclaimers, and operational practices of any third-party platform before proceeding with any engagement.

L. Children's Data: -

The Platform is strictly intended for Users who are 18 years of age or older and who are acting on behalf of legally registered business entities. The services offered by Petrolube Trade are exclusively for B2B commercial transactions, and not for individual or personal use.

Petrolube Trade does not knowingly collect, store, or process personal data of minors (persons below 18 years of age).

If the Company becomes aware that a minor has attempted to register or has inadvertently provided personal information, such data will be immediately deleted and access to the Platform will be denied.

Users are responsible for ensuring that only authorized adult representatives of their business entity access and use the Platform.

M. Updates to This Privacy Policy: -

Petrolube Trade reserves the right to modify, update, alter, or amend this Privacy Policy at any time in order to comply with evolving legal, regulatory, or operational requirements, or to enhance platform security and user data protection standards. Any material or significant changes that may affect User rights or obligations will be communicated through email notifications, platform alerts, or any other reasonable mode of communication adopted by the Company. Users are expected to periodically review the updated Policy, and continued access to or use of the Platform after the effective date of such revisions shall be deemed to constitute the User's acceptance of the updated Privacy Policy. If a User disagrees with any modification, the User must immediately discontinue use of the Platform and may request closure of their account in accordance with applicable rules and procedures.

N. Compliance with Petroleum Laws: -

Users represent and warrant that they possess all required licences, permits, and approvals from the Petroleum and Explosives Safety Organisation (PESO), State authorities, and any other regulatory body for the storage, transport, sale, or purchase of petroleum and petroleum products. Petrolube Trade does not verify or guarantee the validity of such licences and shall not be liable for any violation.

O. Hazardous Goods Disclaimer: -

Petroleum products are classified as hazardous/dangerous goods. The Platform only facilitates introduction between Buyers and Sellers. All responsibility for safe handling, transportation in approved tankers, compliance with ADR/IMDG rules (if international), and insurance rests solely with the Buyer, Seller, and their logistics providers.

P. Compliance Audit Right: -

The Platform Owner reserves the right, at any time during a User's active account status, to demand current copies of all requisite licenses, permits, and governmental approvals (including but not limited to PESO, GST, and environmental permits) necessary for the lawful purchase, sale, storage, or transport of petroleum products. Failure to provide satisfactory proof of valid and current compliance documentation within five (5) business days of written notice shall constitute a material breach of these Terms, leading to immediate suspension and/or termination of the User's account and ongoing Transactions.

Q. Automated Security and Compliance Monitoring: -

Users agree that the Platform may use transaction history, login data, IP addresses, and other System and Technical Data for automated analysis, profiling, and monitoring to detect and prevent activities that indicate fraud, money laundering, market manipulation, or non-compliance with statutory regulations. The Platform reserves the right to share the results of such analysis with relevant regulatory or law enforcement authorities as required by law.

R. Transfer of Personal Information Outside India: -

Unless stated otherwise, we store and process your Personal Information in India. There may, however, be occasions when we need to transfer your Personal Information outside India for our business requirements. In such instances, we will exercise the same level of care in handling the Personal Information outside India as we do in India, and shall take such actions only in compliance with the laws of India.

S. Contact Information: -

For any queries, complaints, or requests regarding this Privacy Policy or the handling of personal or business data, Users may contact: Compliance Officer: Mr. ………….. to exercise any of these rights. We will respond to your request within a reasonable time.

Last Updated: January 2025