Cybersecurity & Compliance

Enterprise Data Privacy & Protection Policy

How AURO EXIM safeguards corporate identity, trade telemetry, customs manifest data, and proforma RFQ transactions in full compliance with global privacy regulations.

Effective Date: January 1, 2026Version: 3.1-ENTERPRISEGDPR & India DPDP Act 2023 Compliant

1. Overview & Data Controller

This Enterprise Privacy Policy ("Policy") outlines how AURO EXIM Private Limited ("AURO EXIM", "we", or "our") collects, processes, encrypts, and protects business data, personal credentials, and trade telemetry when you utilize our export portal, mobile applications, RFQ generators, or B2B supply chain tools.

AURO EXIM adheres strictly to international data governance frameworks including the EU General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act 2023 (India DPDP), and California Consumer Privacy Act (CCPA).

ISO/IEC 27001 Security Standard: Our cloud infrastructure, trade databases, and API integrations with seaport terminals employ AES-256 bit encryption at rest and TLS 1.3 in transit.

2. Information We Collect

In conducting global B2B agricultural commodity trade, we collect specific categories of business and technical information:

Corporate & Trade Credentials

Company name, Tax ID / IEC (Import Export Code), GSTIN, business email, contact phone, seaport of destination, and proforma RFQ specifications.

Logistics & IoT Telemetry

Cold-chain reefer container GPS coordinates, temperature (-20°C to +4°C) loggers, Bill of Lading manifest filings, and automated shipment tracking metadata.

3. How We Use Trade Data

We collect and process your information exclusively for legitimate commercial, legal, and operational purposes:

  • Automated Quotation & RFQ: Generating FOB/CIF proforma estimates, freight rates, and packaging options tailored to your destination port.
  • Customs & Port Manifest Declarations: Filing export shipping bills with Indian Customs (ICEGATE), APEDA, and ocean freight carriers.
  • Quality COA & Lab Validation: Transmitting product specifications to accredited third-party testing laboratories (SGS, Geo-Chem).
  • Financial Settlement: Processing Letters of Credit (L/C) and banking documentation with issuing and advising banks.

4. Third-Party Data Sharing & Seaports

AURO EXIM never sells, rents, or monetizes corporate or personal data. We share necessary shipment parameters strictly with authorized trade ecosystem partners:

Seaport Authorities & Freight Forwarders
Port of Nhava Sheva (JNPT), Mundra Port, Maersk Line, MSC, and destination port customs clearance desks.
Government Inspection Bodies & Certification Councils
APEDA, FSSAI, Spices Board of India, USDA, and ISO auditor authorities for export certification.

5. Data Security & Retention

We maintain stringent technical, physical, and organizational safeguards to protect trade records against unauthorized access, loss, or alteration.

Trade records, export manifests, and tax invoices are retained for 7 years in accordance with Indian Customs & Reserve Bank of India (RBI) statutory mandates, after which data is securely purged.

6. Your Rights & Data Protection Desk

Under applicable data protection laws (GDPR & DPDP), international buyers and portal users possess full rights regarding their data:

Right to Access
Request copies of stored corporate records.
Right to Erasure
Request deletion of non-statutory records.
Right to Portability
Export data in structured JSON/CSV format.
Chief Data Protection Officer (DPO)
privacy@auroexim.com
Email DPO Desk