← Back to Zehbia's Wardrobe

KHADIM SOLUTIONS

Privacy Notice

Zehbia's Wardrobe — A Tailoring Platform

PRIVACY NOTICE / PRIVACY POLICY

Document Version: 1.0Effective Date: 1st Sep 2026Last Updated: 1st Sep 2026Applicable Jurisdiction: IndiaPlatform: Zehbia Website, Web Application, Mobile Application and related services- Home Tailoring Platform

1. INTRODUCTION

Welcome to Zehbia’s Wardrobe - A Tailoring Platform ("Zehbia", "we", "us", "our).

This Privacy Notice explains how Zehbia collects, receives, uses, stores, processes, shares, protects and deletes personal data relating to customers and other individuals who use or interact with our website, mobile application, services, customer portal, home-visit services, tailoring services and related communication channels.

Zehbia is committed to handling personal data responsibly, transparently and securely.

This Privacy Notice is intended to be read together with:

Zehbia Terms & Conditions;

Cancellation & Refund Policy;

Payment Terms;

Offers & Cashback Terms;

Delivery Policy;

Cookie Policy, where applicable; and

Grievance Redressal / Data Rights Procedure.

Where applicable, this Privacy Notice is intended to operate consistently with the Digital Personal Data Protection Act, 2023, and the applicable rules and regulations made thereunder. The DPDP Act establishes the framework for processing digital personal data in India.

2. WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA?

The entity responsible for determining the purpose and means of processing your personal data will be:

Legal Entity Name: KHADIM SOLUTIONSBrand: Zehbia / Zehbia’s Wardrobe - A Tailoring PlatformRegistered Address: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir-JK 190015Email: zehbia@zehbia.comCustomer Support: +91-889-974-9158Grievance Contact: grievance@zehbia.com Data Protection Contact: info@zehbia.com

For purposes of applicable Indian data protection law, the relevant entity may act as the Data Fiduciary for personal data processed through the Zehbia platform.

If Zehbia's business structure changes, this Privacy Notice may be updated to identify the applicable legal entity.

3. WHAT PERSONAL DATA DO WE COLLECT?

We collect only personal data that is reasonably necessary for providing, managing, securing and improving Zehbia's services.

Depending on how you use Zehbia, this may include the following.

3.1 Account and Identification Information

We may collect:

Full name

Mobile number

Email address

Profile photograph, if voluntarily provided

Date of birth or age, where required

Gender or preferred garment category, where voluntarily provided

Login/account identifiers

OTP verification information

Account status

4. CONTACT AND ADDRESS INFORMATION

When you create an address or request a home visit, pickup or delivery, we may collect:

House/flat number

Building name

Street/locality

Area

City

District

State

PIN code

Landmark

Address type, such as Home, Office or Other

Delivery instructions

Contact person/name, where applicable

Alternate contact number, where voluntarily provided

We use this information to facilitate home visits, pickup, delivery and other services requested by you.

5. MEASUREMENT INFORMATION

Zehbia is a tailoring platform and therefore may process garment measurement information.

Depending on the garment, this may include:

Chest

Waist

Hip

Shoulder

Sleeve length

Armhole

Neck

Kurta length

Trouser length

Inseam

Outseam

Thigh

Knee

Cuff

Other garment-specific measurements

Measurement preferences

Fit preferences

Stitching preferences

Alteration instructions

Measurement notes

Measurement history

Measurement version information

Important

Zehbia will not assume that every customer requires the same measurements.

Measurements may be stored according to:

Customer → Garment Type → Measurement Profile → Version → Date

This allows Zehbia to maintain appropriate measurement history while reducing the need to repeatedly collect the same information.

6. PHOTOGRAPHS AND REFERENCE IMAGES

Where the service requires or permits it, customers may voluntarily provide:

Garment reference photographs

Design reference images

Fabric photographs

Stitching/reference photographs

Images relating to an order

Profile photographs

Such images may be processed for purposes such as:

Understanding design requirements;

Communicating tailoring instructions;

Processing an order;

Quality control;

Alterations;

Resolving disputes;

Maintaining order records; and

Providing requested services.

Zehbia will not use customer photographs for public advertising or promotional purposes without an appropriate legal basis and, where required, separate permission/consent.

7. BOOKING INFORMATION

When you book a service, we may collect:

Booking ID

Customer ID

Service type

Pickup/stitching requirement

Preferred date

Preferred time slot

Address

Field Officer assignment

Booking status

Notes/instructions

Pickup status

Visit status

Cancellation information

Rescheduling information

8. ORDER INFORMATION

When you place an order, we may collect and process:

Order ID

Customer ID

Garment type

Quantity

Fabric information

Measurement profile

Stitching specifications

Design preferences

Alteration instructions

Assigned tailor

Warehouse information

Quality-control information

Delivery information

Order status

Order history

Cancellation information

Refund information

Customer communications relating to the order

9. PAYMENT INFORMATION

When you make a payment through Zehbia, we may process:

Payment reference number

Transaction ID

Order ID

Amount

Currency

Payment status

Payment date/time

Payment method

Refund information

Payment gateway response

Invoice information

We do not intend to store complete payment-card credentials such as:

Full card number;

CVV;

Card PIN; or

Internet banking password.

Where payment services are provided by a third-party payment gateway, payment information may be processed directly by that provider in accordance with its own privacy policy and applicable requirements.

Zehbia may retain transaction references necessary for accounting, reconciliation, customer support, fraud prevention, legal compliance and dispute resolution.

10. OTP AND AUTHENTICATION INFORMATION

Zehbia may use mobile OTP authentication.

We may process:

Mobile number;

OTP verification status;

OTP request timestamp;

OTP expiry;

Authentication attempts;

Device/session information;

Security/rate-limiting information.

OTP values should be used only for authentication and should not be retained longer than necessary.

For security purposes, Zehbia may maintain limited authentication logs, such as timestamps, request counts and verification status.

11. DEVICE AND TECHNICAL INFORMATION

When you access Zehbia's website or application, we may automatically collect certain technical information, including:

IP address;

Browser type;

Operating system;

Device type;

Application version;

Session information;

Login timestamps;

Device/security identifiers where technically required;

Error logs;

Crash information;

Approximate network information;

Security and fraud-prevention information.

This information may be used to maintain the security, reliability and performance of the platform.

12. LOCATION INFORMATION

Zehbia may process location-related information where it is necessary for a service you request.

For example, location-related information may be used for:

Home visit scheduling;

Pickup;

Delivery;

Field Officer assignment;

Service availability;

Route/service coordination.

Zehbia will request device-level location permission where such permission is required by the operating system.

Important

Zehbia should not collect continuous background location information unless such functionality is specifically required, clearly disclosed and legally justified.

For normal customer bookings, Zehbia should prefer address information provided directly by the customer rather than continuous GPS tracking.

13. HOW WE USE YOUR PERSONAL DATA

We may process personal data for the following purposes.

13.1 Account Management

To:

Create your account;

Verify your mobile number;

Authenticate you;

Maintain your profile;

Manage login sessions;

Secure your account.

13.2 Providing Tailoring Services

To:

Take and maintain measurements;

Manage measurement profiles;

Process tailoring requests;

Manage fabric pickup;

Assign field officers;

Assign warehouse staff;

Assign tailors;

Perform quality checks;

Manage alterations;

Arrange delivery.

13.3 Booking Management

To:

Create bookings;

Schedule appointments;

Confirm appointments;

Assign personnel;

Reschedule bookings;

Send booking notifications.

13.4 Order Management

To:

Create orders;

Track orders;

Maintain order history;

Process tailoring instructions;

Manage production;

Manage quality control;

Manage delivery;

Resolve order issues.

13.5 Payments

To:

Process payments;

Verify transactions;

Generate invoices;

Process refunds;

Reconcile transactions;

Detect suspicious transactions;

Maintain financial records.

13.6 Customer Support

To:

Respond to queries;

Resolve complaints;

Investigate order issues;

Handle refund requests;

Handle measurement/fitting issues;

Maintain support records.

13.7 Notifications

To send:

OTPs;

Booking confirmations;

Order status updates;

Pickup notifications;

Delivery notifications;

Payment confirmations;

Important service notices;

Account/security alerts.

14. OFFERS, CASHBACK AND MARKETING

Where permitted and appropriately disclosed, Zehbia may use certain personal data to provide:

Offers;

Discounts;

Cashback;

Loyalty benefits;

Promotional communications;

Product/service recommendations.

Marketing communications may be sent through channels such as:

SMS;

Email;

Push notifications;

WhatsApp or similar communication channels, where applicable.

You may have the ability to opt out of promotional communications.

Service vs Marketing Messages

Even if you opt out of promotional communications, Zehbia may continue sending essential service communications, such as:

OTPs;

Security alerts;

Booking confirmations;

Order updates;

Payment confirmations;

Delivery notifications;

Account-related notices.

15. NOTICE BOARD AND AD CENTRE

Zehbia may operate:

Notice Board;

Ad Centre;

Promotional banners;

Offers;

Campaigns;

Partner promotions.

Some advertisements may be displayed based on general audience categories or service context.

Unless separately disclosed and legally permitted, Zehbia should not provide identifiable customer personal data to advertisers merely for their own independent marketing purposes.

16. LEGAL BASES / PURPOSES FOR PROCESSING

Zehbia may process personal data where permitted under applicable law, including where:

you provide consent for a specified purpose;

processing is necessary to provide a service requested by you;

processing is necessary for a permitted legitimate purpose under applicable law;

processing is required to comply with a legal obligation;

processing is necessary for security, fraud prevention or protection of rights;

processing is necessary to respond to a lawful request or legal process; or

another lawful basis permitted under applicable Indian law applies.

Where consent is relied upon, Zehbia will seek to make the request understandable and appropriately specific.

17. CONSENT

Where Zehbia relies on consent, consent will be obtained through an appropriate mechanism.

For example, the registration process may contain:

☐ I have read and understood the Privacy Notice and agree to the processing of my personal data as described in it.

Where separate consent is required for an optional purpose, Zehbia should use a separate consent mechanism rather than bundling unrelated purposes into a single mandatory acceptance.

Example

Marketing consent should not be disguised as a condition for creating an account where marketing is not necessary for providing the requested service.

18. WITHDRAWAL OF CONSENT

Where processing is based on consent, you may withdraw your consent through the mechanisms made available by Zehbia.

Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.

Withdrawal may also affect Zehbia's ability to provide certain services where the relevant data is necessary for that service.

For example, if information necessary to complete a requested tailoring service is deleted or its processing is restricted, Zehbia may be unable to complete that service.

19. DATA MINIMISATION

Zehbia follows the principle that personal data should be collected only to the extent reasonably necessary for the relevant purpose.

Accordingly:

Zehbia should not collect unnecessary personal information;

Measurement fields should be garment-specific;

Optional information should be clearly identified;

Location access should not be unnecessarily continuous;

Payment credentials should not be unnecessarily stored;

Personal data should not be retained indefinitely.

20. DATA SHARING

Zehbia may share personal data with selected third parties where necessary for providing services, operating the platform, maintaining security, complying with law or performing other disclosed purposes.

These may include:

20.1 Field Officers

Relevant information may be shared with an assigned Field Officer, such as:

Customer name;

Contact number;

Appointment information;

Service address;

Booking details;

Relevant measurement information;

Pickup/delivery instructions.

Field Officers should only receive information necessary for performing their assigned responsibilities.

21. TAILORS AND PRODUCTION STAFF

Relevant information may be made available to assigned tailoring/production personnel, including:

Order ID;

Garment type;

Measurements;

Stitching instructions;

Fabric/design information;

Alteration requirements;

Relevant reference images.

Personnel should not have unrestricted access to unrelated customer information.

22. WAREHOUSE AND QUALITY-CONTROL STAFF

Where required for operations, relevant order information may be shared with:

Warehouse personnel;

Quality-control personnel;

Dispatch personnel.

Access should be restricted according to operational responsibility.

23. DELIVERY PARTNERS

Where third-party delivery services are used, relevant information may be shared, such as:

Customer name;

Delivery address;

Contact number;

Order/delivery reference;

Delivery instructions.

Only information reasonably necessary for delivery should be shared.

24. SERVICE PROVIDERS

Zehbia may use third-party technology/service providers for:

Cloud hosting;

Database infrastructure;

SMS/OTP;

Email;

Push notifications;

Payment processing;

Analytics;

Error monitoring;

Customer support;

Backup;

Security;

CDN;

Website/application infrastructure.

Such providers should receive only the information reasonably necessary for the services they provide and should be contractually or otherwise appropriately governed where required.

25. CURRENT / PLANNED ZEHBIA TECHNOLOGY PROVIDERS

The actual provider list must be finalized before production launch.

The implementation may include providers such as:

Important: This table must be updated with the actual providers before publication.

26. DATA PROCESSORS

Where a third party processes personal data on Zehbia's behalf, Zehbia will seek to establish appropriate contractual, technical and organisational safeguards.

Third-party processors should not be permitted to use Zehbia customer data for unrelated purposes unless separately authorised and legally permitted.

27. INTERNATIONAL DATA TRANSFERS

Some technology providers used by Zehbia may process or store information outside India.

Where personal data is transferred outside India, Zehbia will implement such transfer in accordance with applicable Indian law, including any restrictions, requirements or conditions applicable to transfers to jurisdictions outside India.

Zehbia may update this Privacy Notice when material changes occur in its international data-processing arrangements.

28. DATA SECURITY

Zehbia will implement reasonable technical and organisational security measures appropriate to the nature of personal data and the risks associated with its processing.

These measures may include:

Encryption in transit;

Encryption at rest where appropriate;

Secure password/token handling;

JWT and refresh-token controls;

Role-Based Access Control;

Least-privilege access;

Database access controls;

API authentication;

API authorisation;

Rate limiting;

OTP attempt limits;

Session management;

Audit logs;

Security monitoring;

Backups;

Vulnerability management;

Secure software development practices;

Access reviews;

Employee confidentiality obligations.

The final technical controls should be documented internally in Zehbia's security architecture and information-security procedures.

29. ACCESS CONTROL

Zehbia's internal systems should follow the principle of least privilege.

For example:

Customer

→ Own profile→ Own measurements→ Own bookings→ Own orders→ Own payments

Field Officer

→ Assigned bookings/customers only

Tailor

→ Assigned production jobs only

Warehouse

→ Relevant assigned warehouse orders only

Quality Control

→ Relevant QC orders only

Finance

→ Relevant payment/order information

Administrator

→ Access according to assigned administrative permissions.

Access should not automatically mean unrestricted access to all customer data.

30. DATA BREACH AND SECURITY INCIDENTS

If Zehbia becomes aware of a personal data breach, Zehbia will assess and respond to the incident in accordance with applicable law.

Depending on the nature and severity of the incident, Zehbia may:

investigate the incident;

contain the incident;

secure affected systems;

assess affected personal data;

document the incident;

notify relevant authorities where legally required;

notify affected individuals where legally required;

take remedial measures; and

implement measures to prevent recurrence.

The DPDP Rules include specific requirements relating to personal-data breach notifications and security safeguards.

31. DATA RETENTION

Zehbia will not retain personal data indefinitely merely because it has been collected.

Personal data should be retained only for as long as reasonably necessary for:

Providing requested services;

Maintaining order history;

Customer support;

Accounting;

Tax requirements;

Legal claims;

Fraud prevention;

Security;

Compliance with applicable law;

Resolving disputes.

Different categories of information may therefore have different retention periods.

32. PROPOSED RETENTION FRAMEWORK

The following is the recommended starting framework and should be confirmed by Zehbia's legal/accounting team:

Do not publish these periods until the actual business and legal retention schedule has been approved.

33. ACCOUNT DELETION

Customers may request deletion of their Zehbia account through:

In-app account deletion;

Website account deletion;

Customer support;

Other mechanism provided by Zehbia.

Where an account-deletion feature is provided, Zehbia should clearly explain what will happen when the account is deleted.

Certain information may need to be retained where required or permitted by law, including:

Financial records;

Tax records;

Transaction records;

Fraud/security records;

Legal claims;

Regulatory records;

Information required to establish, exercise or defend legal rights.

Where information cannot immediately be deleted because of such requirements, access and further processing should be restricted to the relevant purpose.

34. DELETION OF MEASUREMENT DATA

Because measurements are a core Zehbia service feature, customers may request deletion of measurement profiles where applicable.

If measurement information is deleted:

Future tailoring may require fresh measurements;

Existing orders may still require certain historical information where necessary;

Legally required records may not be immediately deleted.

35. CUSTOMER RIGHTS

Subject to applicable law and any conditions or exceptions provided by law, individuals may have rights relating to their personal data, including rights to:

Obtain information about processing;

Access information;

Request correction;

Request erasure/deletion;

Withdraw consent where consent is the basis;

Obtain information regarding grievance mechanisms;

Nominate another individual to exercise rights in specified circumstances.

The DPDP Act expressly establishes rights for Data Principals, including access to information, correction/erasure, grievance redressal and nomination, subject to the Act's provisions.

36. CORRECTION OF PERSONAL DATA

If information associated with your Zehbia account is inaccurate, incomplete or outdated, you may request correction through available account-management features or by contacting Zehbia.

For example, you may request correction of:

Name;

Mobile number;

Email;

Address;

Measurement;

Stitching preference;

Other account information.

37. GRIEVANCE REDRESSAL

If you have a privacy or personal-data concern, you may contact:

Grievance Officer / Privacy ContactName: Suhail FarooqDesignation: Manager OperationsEmail: zehbia@zehbia.com Phone: +91-889-974-9158Address: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir JK-190015

Zehbia will establish an appropriate grievance mechanism and process complaints in accordance with applicable law.

38. NOMINATION

Where applicable under the DPDP framework, Zehbia will provide a mechanism through which a Data Principal may nominate another individual to exercise specified rights in the event of death or incapacity, subject to applicable legal requirements.

The exact procedure will be published when the corresponding statutory requirements become applicable to Zehbia.

39. CHILDREN'S PERSONAL DATA

Zehbia's services are intended primarily for individuals capable of independently using the services in accordance with applicable law.

Where Zehbia processes personal data relating to children, Zehbia will implement the safeguards required under applicable law.

Zehbia will not knowingly use children's personal data for:

Behavioural monitoring;

Targeted advertising; or

Other prohibited purposes,

where such processing is prohibited by applicable law.

Where parental/guardian consent or other requirements apply, Zehbia will implement appropriate mechanisms.

40. CUSTOMER-PROVIDED INFORMATION ABOUT OTHER PEOPLE

Customers should not provide Zehbia with another person's personal data unless they have the authority or lawful basis to provide it.

For example, if a customer creates an order for:

A spouse;

Parent;

Child;

Relative;

Employee;

Another customer,

the customer should ensure that they are authorised to provide the information.

41. CUSTOMER CONTENT

Where customers upload:

Images;

Designs;

Reviews;

Feedback;

Instructions;

Other content,

Zehbia may process that content to provide the requested services.

Customers should not upload:

Unnecessary personal information of others;

Government IDs unless specifically requested through an authorised Zehbia process;

Financial credentials;

Passwords;

OTPs;

Sensitive information unrelated to the tailoring service.

42. COOKIES AND SIMILAR TECHNOLOGIES

Zehbia may use cookies and similar technologies to:

Maintain login sessions;

Remember preferences;

Improve website functionality;

Measure performance;

Detect fraud/security issues;

Understand usage patterns;

Provide relevant functionality.

Where required, Zehbia will provide appropriate cookie controls and information.

A separate Cookie Policy may be published where the website uses non-essential cookies or similar technologies.

43. ANALYTICS

Zehbia may use analytics technologies to understand:

Website usage;

Application performance;

Feature usage;

Error rates;

User journeys;

Technical performance.

Analytics should be configured to minimise unnecessary collection of personal data.

Where third-party analytics services are used, their applicable privacy terms should also be reviewed.

44. PERSONALISATION

Zehbia may use information such as:

Garment preferences;

Previous orders;

Measurements;

Service history;

Offers previously used,

to improve the customer's experience.

Personalisation will be subject to applicable legal requirements and the purposes communicated to the customer.

45. AUTOMATED DECISION-MAKING

Zehbia may use automated systems for limited operational purposes such as:

Fraud detection;

Security monitoring;

Appointment allocation;

Notification delivery;

Operational prioritisation.

Zehbia will not use automated processing to make decisions producing legally significant or similarly significant effects on individuals unless such processing is lawful and appropriately disclosed.

46. THIRD-PARTY WEBSITES AND SERVICES

Zehbia may contain links to third-party websites or services.

Examples may include:

Payment gateways;

Social media;

Maps;

Delivery tracking;

Partner websites.

Zehbia is not responsible for the privacy practices of independent third parties.

Customers should review the applicable privacy notices of those services before providing information.

47. BUSINESS TRANSFERS

If Zehbia undergoes:

Merger;

Acquisition;

Restructuring;

Sale of assets;

Business transfer;

personal data may be transferred as part of the transaction, subject to applicable law and appropriate safeguards.

Customers will be informed where legally required.

48. GOVERNMENT AND LEGAL DISCLOSURES

Zehbia may disclose personal data where reasonably necessary to:

Comply with applicable law;

Respond to lawful government requests;

Comply with court orders;

Protect customers;

Prevent fraud;

Investigate security incidents;

Protect Zehbia's legal rights;

Establish, exercise or defend legal claims.

Zehbia will seek to limit such disclosure to what is reasonably necessary or legally required.

49. DATA ACCURACY

Customers are responsible for ensuring that information provided to Zehbia is accurate and updated.

This is particularly important for:

Measurements;

Address;

Contact number;

Delivery details;

Stitching instructions.

Incorrect information may result in:

Incorrect fitting;

Failed delivery;

Delayed service;

Additional alteration requirements.

50. MEASUREMENT ACCURACY DISCLAIMER

Tailoring measurements can change due to:

Body posture;

Measurement technique;

Garment style;

Fabric characteristics;

Fit preference;

Measurement conditions.

Zehbia will take reasonable operational measures to maintain measurement records but cannot guarantee that a stored measurement will remain accurate indefinitely.

Customers may request a fresh measurement where appropriate.

51. SECURITY OF CUSTOMER ACCOUNT

Customers are responsible for maintaining reasonable security over:

Their mobile device;

SIM/mobile number;

Email account;

Authentication sessions;

Account access.

Customers should never share:

OTPs;

Passwords;

Authentication codes;

Recovery information.

Zehbia staff should not request a customer's OTP for ordinary customer-support purposes.

52. FRAUD AND SECURITY MONITORING

Zehbia may process technical and account information to detect:

Fake accounts;

Repeated OTP abuse;

Payment fraud;

Account takeover;

Automated attacks;

Suspicious transactions;

Abuse of offers/cashback;

Platform attacks.

This may include maintaining security logs and blocking suspicious activity.

53. MARKETING PREFERENCES

Customers may manage promotional communication preferences through available:

Account settings;

Unsubscribe mechanisms;

Notification settings;

Customer support.

Where legally required, marketing communications will provide an appropriate opt-out mechanism.

54. PRIVACY OF EMPLOYEES AND OPERATIONAL USERS

Zehbia may also process personal data relating to:

Field Officers;

Tailors;

Warehouse staff;

Quality-control personnel;

Delivery personnel;

Administrators;

Other authorised users.

Such processing may be governed by separate internal employee/worker privacy notices and policies.

55. INTERNAL ACCESS TO CUSTOMER DATA

Zehbia personnel may access customer data only where reasonably required for their job responsibilities.

Examples:

Customer Support: customer/account/order information required to resolve an issue.

Field Officer: assigned booking and relevant customer information.

Tailor: assigned order, measurements and stitching instructions.

Warehouse: relevant order and production information.

Finance: payment and transaction information.

Administrator: information necessary for authorised administrative functions.

All privileged access should be logged where appropriate.

56. AUDIT LOGS

Zehbia may maintain audit records concerning activities such as:

Login;

Logout;

Account changes;

Measurement changes;

Order changes;

Payment changes;

Administrative actions;

Permission changes;

Data-access events;

Security events.

Audit records may be retained for security, accountability, fraud prevention and legal purposes.

57. PRIVACY BY DESIGN

Zehbia intends to incorporate privacy and security considerations into the design and development of its platform.

This includes:

Data minimisation;

Role-based access;

Purpose-based processing;

Secure authentication;

Secure APIs;

Access logging;

Controlled data sharing;

Retention controls;

Account deletion;

User rights mechanisms.

58. DATA PROTECTION IMPACT ASSESSMENT

Where required by applicable law or where Zehbia determines that processing presents significant privacy risks, Zehbia may conduct appropriate privacy/security assessments, including a Data Protection Impact Assessment or equivalent internal assessment.

59. SIGNIFICANT DATA FIDUCIARY

If Zehbia is notified or otherwise becomes subject to obligations applicable to a Significant Data Fiduciary, Zehbia will implement the additional requirements applicable to it.

This may include enhanced governance, assessments, audits and other measures prescribed by applicable law.

60. CHANGES TO THIS PRIVACY NOTICE

Zehbia may update this Privacy Notice from time to time.

Changes may be made because of:

New services;

New technology;

Changes to processing;

New service providers;

Legal/regulatory changes;

Security requirements;

Business changes.

The updated version will include a revised "Last Updated" date.

Where a change materially affects how personal data is processed, Zehbia will provide appropriate notice or obtain consent where legally required.

61. VERSION HISTORY

62. CONTACT US

For privacy-related questions, requests or complaints:

Zehbia Privacy Contact

Legal Entity: KHADIM SOLUTIONSBrand: Zehbia’s Wardrobe - A Tailoring PlatformAddress: 1324 Khadim Villa Mehjoor Nagar Natipora Srinagar Kashmir JK-190015Email: zehbia@zehbia.com Grievance Email: grievance@zehbia.com Customer Support: +91-889-974-9158Website: www.zehbia.com | www.zehbia.in

63. DATA RIGHTS REQUEST PROCEDURE

A customer may submit a privacy request through the mechanism provided by Zehbia.

The request may include:

Full name;

Registered mobile number/email;

Nature of request;

Relevant account/order reference, where applicable;

Supporting information reasonably required to verify the requester.

Zehbia may perform reasonable verification before acting on a request in order to protect the customer's account and personal data from unauthorised requests.

64. REQUEST TYPES

Available request categories may include:

A. Access / Information Request

Request information regarding processing of your personal data.

B. Correction Request

Request correction of inaccurate or incomplete personal data.

C. Erasure Request

Request deletion of personal data where applicable.

D. Consent Withdrawal

Withdraw consent where processing is based on consent.

E. Grievance

Raise a complaint regarding processing or privacy.

F. Nomination

Exercise nomination rights where applicable under law.

65. IDENTITY VERIFICATION

Zehbia may need to verify the identity of a person making a data request.

Verification may include:

OTP verification;

Registered email verification;

Account authentication;

Other reasonable verification mechanisms.

Zehbia should not request unnecessary identity documents merely to process an ordinary privacy request.

66. WHEN ZEHBIA MAY RETAIN INFORMATION

Even following an account deletion request, Zehbia may retain certain information where necessary for:

Compliance with law;

Tax/accounting requirements;

Fraud prevention;

Cybersecurity;

Dispute resolution;

Legal claims;

Regulatory requirements;

Establishing, exercising or defending legal rights.

Retained information should not be used for unrelated purposes merely because it remains in a backup or archive.

67. BACKUPS

Deleted information may remain temporarily within secure backups where immediate deletion from backup systems is technically impractical.

Zehbia should ensure that such information:

Is protected;

Is not restored except where necessary;

Is not used for ordinary business processing;

Is deleted or overwritten according to the applicable backup lifecycle.

68. EMPLOYEE CONFIDENTIALITY

Employees, contractors and authorised service personnel who have access to customer data should be subject to appropriate confidentiality obligations.

Access should be revoked when personnel:

Leave Zehbia;

Change roles;

No longer require access.

69. NO SALE OF CUSTOMER PERSONAL DATA

Zehbia does not intend to sell customer personal data as a commercial product.

Zehbia will not disclose customer personal data to third parties for independent commercial purposes except where:

The customer has been appropriately informed and the processing is lawful;

The disclosure is necessary for a requested service;

It is required or permitted by law; or

Another lawful basis applies.

70. PRIVACY POLICY DOES NOT OVERRIDE LAW

Nothing in this Privacy Notice is intended to:

Restrict any mandatory legal requirement;

Exclude any statutory right;

Limit consumer protection rights;

Prevent lawful government action;

Remove rights that cannot legally be waived.

If any provision conflicts with applicable mandatory law, the applicable law will prevail to the extent of the conflict.

71. GOVERNING LAW

This Privacy Notice shall be governed by the laws applicable in India.

Any disputes concerning privacy or personal-data processing shall be handled through the applicable grievance and legal mechanisms available under Indian law.

Nothing in this clause is intended to exclude statutory rights or remedies available to an individual.

72. IMPORTANT PRIVACY COMMITMENT

Zehbia's privacy approach can be summarised as:

Collect what we need.Explain why we need it.Use it for the stated purpose.Give access only to those who need it.Protect it appropriately.Retain it only as long as justified.Delete it when no longer required, subject to law.

73. CUSTOMER-FACING SHORT PRIVACY NOTICE

For the registration screen, I recommend not displaying the entire Privacy Policy.

Instead, use a short notice such as:

Your Privacy Matters

Zehbia collects and uses your personal information, such as your name, mobile number, address, measurements, booking, order and payment-related information, to provide and manage our tailoring services.

We may share relevant information with authorised personnel and service providers where necessary to complete your requested services.

For more information about how we collect, use, protect, retain and delete your personal data, please read our Privacy Notice.

[Read Privacy Notice]

Then:

☐ I have read and understood the Privacy Notice.

For optional marketing:

☐ I would like to receive offers, discounts, cashback and promotional communications from Zehbia.

The second checkbox should be separate from acceptance of the Privacy Notice.

74. RECOMMENDED APP REGISTRATION SCREEN

For the Zehbia application, I recommend this structure:

Create Your Zehbia Account

Mobile Number

[ +91 _____________ ]

[ Send OTP ]

By continuing, you acknowledge that you have read

and understood the Zehbia Privacy Notice and agree

to the Terms & Conditions.

[ Privacy Notice ] [ Terms & Conditions ]

☐ Send me offers, discounts and cashback updates.

[ Continue ]

This is substantially better than:

"I agree to Terms, Privacy Policy, Marketing, Offers and everything else."

because Zehbia should keep service acceptance and optional marketing logically separate.

75. RECOMMENDED DATA ARCHITECTURE FOR ZEHBIA

This Privacy Policy should also influence the actual database design.

For example:

Customer

├── Profile

├── Addresses

├── Measurement Profiles

│ ├── Garment Type

│ ├── Version

│ ├── Measurements

│ └── Preferences

├── Bookings

├── Orders

│ ├── Tailor

│ ├── Warehouse

│ ├── QC

│ └── Delivery

├── Payments

├── Notifications

├── Offers / Cashback

└── Privacy / Consent Records

For the Privacy/Consent Records, I strongly recommend maintaining fields such as:

ConsentRecord

-------------------------

id

customerId

purpose

consentStatus

consentVersion

privacyNoticeVersion

timestamp

source

withdrawnAt

This will give Zehbia a much better audit trail than simply storing:

marketingConsent = true

76. RECOMMENDED PRIVACY MODULE IN ADMIN

The Zehbia Admin Panel should eventually contain:

Privacy & Compliance

Privacy requests

Access requests

Correction requests

Deletion requests

Consent records

Consent withdrawal

Marketing preferences

Data export requests

Grievances

Data breach incidents

Audit logs

Retention configuration

Processor/vendor register

Privacy policy versions

This should be part of the platform architecture rather than something added after launch.

77. IMPORTANT IMPLEMENTATION REQUIREMENTS BEFORE LAUNCH

The Privacy Policy alone is not sufficient for DPDP compliance.

Before Zehbia goes live, the development team should implement at minimum:

Authentication

OTP expiry

OTP attempt limits

OTP resend cooldown

Rate limiting

Secure refresh-token handling

Session revocation

Authorisation

RBAC

Permission-based access

Resource-level access

Customer can access only their own records

Field Officer can access only assigned records

Tailor can access only assigned jobs

Database

Encryption where appropriate

Restricted DB access

No plaintext passwords

No unnecessary OTP storage

Audit fields

Soft-delete/retention strategy where appropriate

API

Authentication middleware

Authorisation guards

Input validation

Rate limiting

Secure headers

Logging

Error handling without exposing personal data

Privacy

Account deletion

Data correction

Consent management

Marketing opt-out

Privacy-request workflow

Data retention rules

Privacy policy versioning

Operations

Employee confidentiality

Access reviews

Staff offboarding

Incident response

Vendor/processor management

Backup policy

78. REGULATORY BASIS

This document has been drafted with reference to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as officially published by the Government of India/MeitY. The notified Rules contain a phased commencement framework, so Zehbia should implement the policy and technical controls in a manner that is ready for the applicable provisions as they become operative.

MeitY's own explanatory material states that the Rules provide the implementation framework for the DPDP Act and emphasise clear, simple communication and contextual explanations.