DPDP Act India LAMBLILY — Your Data Rights

LAMBLILY is a Data Fiduciary under the DPDP Act India — the Digital Personal Data Protection Act 2023 — India’s primary legislation governing personal data of Indian citizens and residents. This DPDP Act India LAMBLILY notice explains the data processed, your rights as a Data Principal, how consent is managed, who the LAMBLILY Grievance Officer is, and how to exercise your data rights as a customer, B2B buyer, or website visitor whose personal data LAMBLILY processes from its Chennai facility.

DPDP Act India LAMBLILY data principal rights consent Chennai Tamil Nadu 2026

DPDP Act India LAMBLILY — About the Legislation

The Digital Personal Data Protection Act 2023 — the DPDP Act India — received Presidential assent in August 2023 and came into force through phased implementation managed by MeitY in 2024. The legislation establishes a framework for processing personal data in India based on purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability. It creates two primary categories of regulated entity: Data Fiduciaries, which determine the purpose and means of processing personal data, and Data Processors, which process personal data on behalf of a Data Fiduciary. LAMBLILY is a Data Fiduciary under the the Act for all personal data collected from Indian residents through lamblily.com, WhatsApp support channels, the B2B trade desk, and the school and institutional programme operations across Chennai, Tamil Nadu, and the 42 Indian cities served by the LAMBLILY D2C delivery network. The legislation grants Indian residents — called Data Principals — a set of legally enforceable rights over their personal data, including the right to access, correction, erasure, and the right to nominate a nominee for their data rights in the event of death or incapacity. This the legislation LAMBLILY notice explains how LAMBLILY processes personal data, what rights Data Principals have, and how those rights can be exercised through the LAMBLILY Grievance Officer in Chennai, Tamil Nadu, India.

As a Data Fiduciary under the DPDP Act India, LAMBLILY is responsible for determining the purpose and means of processing personal data and ensuring that all processing is carried out in compliance with the obligations imposed by the legislation and its implementing rules. The this data protection legislation places primary accountability for compliance on the Data Fiduciary — not on the Data Processor or on the technology service providers used to deliver the LAMBLILY website, payment processing, logistics, and customer support operations. This means LAMBLILY bears direct responsibility for the lawfulness, fairness, and transparency of all personal data processing carried out for Indian residents through the LAMBLILY D2C and B2B operations from the Chennai facility. The the Act obligations that LAMBLILY fulfils as a Data Fiduciary include: providing clear notice to Data Principals about what personal data is collected and for what purpose; obtaining consent for processing personal data for purposes not covered by the legitimate use grounds specified in the legislation; implementing appropriate security safeguards to protect personal data from unauthorised access, loss, or disclosure; honouring Data Principal rights requests within the timeframes specified in the the legislation; and responding to grievances from Data Principals about the processing of their personal data through the designated Grievance Officer.

DPDP Act India LAMBLILY — Data We Process

LAMBLILY processes the following categories of personal data from Indian residents under the DPDP Act India. Customer personal data for D2C orders: name, email address, phone number, delivery address, order items and values, payment method type (card numbers and full payment details are processed directly by Razorpay and not stored by LAMBLILY), and order history including dispatch dates, delivery confirmations, and return or exchange records. B2B buyer personal data: business contact name, business email, business phone, business address, business registration details where provided for export documentation, purchase order history, and correspondence records from RFQ through production and dispatch. School and institutional programme data: school name, procurement contact name and email, logo artwork files provided for DTF print or embroidery, order history, and delivery records. Website user data: IP address, browser type, device type, operating system, pages visited, session duration, and other technical and usage data collected automatically through lamblily.com analytics tools and cookies as described in the LAMBLILY cookie policy at lamblily.com/legal/cookies/. The the Act LAMBLILY notice applies to all of these personal data categories. LAMBLILY does not collect sensitive personal data as defined in the legislation — including health data, financial data beyond payment method type, biometric data, caste, religious belief, or political opinion — in the ordinary course of its operations across India and in 12 international export markets served from the Chennai manufacturing facility.

DPDP Act India LAMBLILY data categories D2C B2B school processing Chennai

DPDP Act India LAMBLILY — Your Rights as a Data Principal

The DPDP Act India grants Data Principals the following legally enforceable rights in relation to personal data processed by Data Fiduciaries including LAMBLILY. Right to access information: you have the right to obtain from LAMBLILY a summary of the personal data held about you and a summary of the processing activities carried out with that data under the the legislation. LAMBLILY will respond to a verified access request within 30 calendar days of receipt. Right to correction and erasure: you have the right to correct inaccurate or incomplete personal data held by LAMBLILY, and to request the erasure of personal data that is no longer needed for the purpose for which it was collected where no legal obligation requires continued retention under the this data protection legislation. Right to nominate: the legislation grants you the right to nominate another individual to exercise your data rights in the event of your death or incapacity. LAMBLILY will accept nominated individuals as representatives upon presentation of satisfactory evidence of the nomination and relevant supporting documentation. Right to grievance: you have the right to raise a grievance with the LAMBLILY Grievance Officer if you believe that LAMBLILY has not complied with the the Act in relation to your personal data. The Grievance Officer will respond to all grievances within 30 calendar days of receipt. Unresolved grievances may be escalated to the Data Protection Board of India when it becomes operational under the the legislation legislation.

DPDP Act India LAMBLILY — Consent and Legitimate Uses

The DPDP Act India requires Data Fiduciaries to process personal data only on the basis of legally recognised grounds. LAMBLILY processes personal data on the following grounds under the legislation. Consent: LAMBLILY relies on consent for marketing communications including promotional emails, WhatsApp broadcast messages, and retargeting advertising. Consent is obtained at account creation or order placement through a clear opt-in mechanism and recorded with a timestamp. Data Principals can withdraw consent for marketing communications at any time through the unsubscribe link in each communication or by contacting the LAMBLILY data protection team directly. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal date under the the Act framework. Legitimate uses: the the legislation permits processing for certain legitimate uses without separately obtained consent, including processing necessary for the performance of a contract such as order fulfilment, delivery, returns processing, and B2B trade desk operations; processing required to comply with a legal obligation such as retaining GST transaction records for 7 years as required by Indian tax law; and processing for other legitimate interests explicitly permitted by the legislation and its implementing rules. LAMBLILY applies the purpose limitation principle under the this data protection legislation by using personal data only for the specific purpose for which it was collected, and will seek fresh consent before using personal data for a new purpose not covered by the original consent or legitimate use ground.

DPDP Act India LAMBLILY — Grievance Officer and Contact

The DPDP Act India requires every Data Fiduciary to designate a Grievance Officer responsible for receiving and addressing Data Principal grievances about the Data Fiduciary’s compliance. The LAMBLILY Grievance Officer under the DPDP Act India is Leo Daniel Raja, co-founder of LAMBLILY, based in Chennai, Tamil Nadu, India. The Grievance Officer can be contacted through the LAMBLILY contact page at lamblily.com/contact/ with “DPDP Grievance” in the subject line, Monday to Saturday 9 AM to 6 PM IST. All grievances will be acknowledged within 72 hours and addressed with a substantive response within 30 calendar days as required by the DPDP Act India. Where the resolution requires additional time, the Grievance Officer will notify the Data Principal of the extended timeline before the initial 30-day response period expires. Data Principals not satisfied with the LAMBLILY Grievance Officer’s resolution have the right to escalate to the Data Protection Board of India. To exercise any right as a Data Principal under the DPDP Act India, submit a verified request via lamblily.com/contact/ with “DPDP Data Rights Request” in the subject line. Include your full name, email address associated with your LAMBLILY account, the specific right you wish to exercise under the DPDP Act India, details of the specific personal data concerned, and sufficient identity verification information. LAMBLILY will acknowledge your request within 72 hours and provide a substantive response within 30 calendar days. Learn about the DPDP Act India at MeitY.

DPDP Act India LAMBLILY grievance officer Leo Daniel Raja Chennai data rights

Data Security and Record Retention at LAMBLILY

LAMBLILY implements appropriate technical and organisational security measures to protect personal data processed in connection with its D2C and B2B operations from unauthorised access, accidental loss, destruction, or disclosure. These security measures include HTTPS encryption on all lamblily.com pages to protect data in transit between the user’s browser and the server, access controls limiting personal data access to team members who require it for their specific operational role within the Chennai facility, contractual restrictions on third-party service providers requiring them to maintain appropriate security standards, and documented incident response procedures for managing any personal data breach that may occur despite these protective measures. In the event of a personal data breach that poses a risk to the rights and freedoms of individuals whose data is affected, LAMBLILY will notify the affected individuals without undue delay and will report the breach to the relevant supervisory authority where required by applicable data protection law in the relevant jurisdiction. Individuals who become aware of potential security incidents involving their personal data processed by LAMBLILY should report them immediately via lamblily.com/contact/ with “Security Concern” in the subject line for urgent attention from the data protection team during business hours Monday to Saturday.

Retention periods for personal data processed by LAMBLILY in its operations: D2C customer order data is retained for 7 years from the date of the transaction to comply with Indian GST record-keeping requirements applicable to all registered businesses under the Goods and Services Tax Act; B2B commercial data is retained for 7 years from the date of the last transaction or the termination of the commercial relationship; customer account data is retained until account closure plus 2 years to allow for any post-closure enquiries or claims that may arise; marketing consent records are retained for 3 years from the date of consent to enable LAMBLILY to demonstrate compliance with consent requirements if challenged; website analytics data is retained in aggregated and anonymised form for up to 3 years for product and website improvement purposes without this constituting personal data retention once the anonymisation process is complete and no individual data subject can be re-identified from the aggregated data set. Personal data is deleted or anonymised when the applicable retention period expires unless a further legal obligation under Indian tax law, customs regulations, export control requirements, or other applicable regulatory framework requires continued retention for a longer period under the applicable compliance requirements of LAMBLILY’s domestic and international operations.

DPDP Act India LAMBLILY FAQ

What is the DPDP Act India LAMBLILY follows?

The DPDP Act India — Digital Personal Data Protection Act 2023 — is India’s primary data protection legislation that came into force in 2024. LAMBLILY operates as a Data Fiduciary under the DPDP Act India, processing personal data from D2C customers, B2B buyers, school contacts, and website users with a documented legal basis for each processing purpose and a designated Grievance Officer — Leo Daniel Raja — for all data rights requests and complaints from Indian residents whose personal data LAMBLILY processes in its operations across India and 12 international export markets.

What rights do I have under DPDP Act India?

Under the DPDP Act India, Data Principals whose personal data is processed by LAMBLILY have the following rights: the right to access a summary of personal data held and processing activities; the right to correct inaccurate or incomplete personal data; the right to erasure of personal data no longer required for its collected purpose where no legal retention obligation applies under the DPDP Act India legislation; the right to nominate another individual to exercise these rights in the event of death or incapacity; and the right to raise a grievance with the LAMBLILY Grievance Officer and escalate to the Data Protection Board of India if not satisfied with the resolution provided by LAMBLILY.

Who is LAMBLILY DPDP Act India grievance officer?

The LAMBLILY Grievance Officer for purposes of the DPDP Act India is Leo Daniel Raja, co-founder of LAMBLILY, based in Chennai, Tamil Nadu, India. Contact the Grievance Officer via lamblily.com/contact/ with “DPDP Grievance” in the subject line, Monday to Saturday 9 AM to 6 PM IST. All grievances are acknowledged within 72 hours and addressed within 30 calendar days of receipt as required by the DPDP Act India. Unresolved grievances may be escalated to the Data Protection Board of India established by MeitY under the DPDP Act India framework.

How do I withdraw consent under DPDP Act India?

Under the DPDP Act India, LAMBLILY relies on consent only for marketing communications — order fulfilment and B2B trade desk operations are carried out under the legitimate use ground. To withdraw marketing consent, click the unsubscribe link in any LAMBLILY marketing email or WhatsApp message, or contact the data protection team via lamblily.com/contact/ with “Consent Withdrawal” in the subject line. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal date under the DPDP Act India. Transaction records are retained for 7 years for GST compliance regardless of consent withdrawal under the DPDP Act India framework.

How does DPDP Act India apply to LAMBLILY orders?

For D2C and B2B orders, LAMBLILY processes personal data under the DPDP Act India legitimate use ground of contract performance — processing name, contact details, delivery address, and order data is necessary to fulfil the purchase contract. Transaction records are retained for 7 years under Indian GST compliance requirements, as legal obligation is a valid ground for continued retention under the DPDP Act India. Marketing communications require separate consent under the legislation. All order processing under the DPDP Act India follows the purpose limitation principle — data is used only for the purpose communicated at the time of collection from the Data Principal.

LAMBLILY (DPDP Act India Data Fiduciary, Chennai, Tamil Nadu, India) is co-founded by Leo Daniel Raja (Grievance Officer under the DPDP Act India) and Juliet Preena. Contact for all DPDP Act India data rights requests: lamblily.com/contact/. Effective: 1 August 2024. Last updated: 1 January 2026.