Privacy Policy for News Subscription Service

This Privacy Policy (“Policy”) is published in accordance with the provisions of Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, read with Section 43A of the Information Technology Act, 2000, and shall be deemed to be a legally binding document between Winngoo India Private Limited (hereinafter referred to as “Company”, “We”, “Us”, or “Our”) and the user of the News Subscription Service (hereinafter referred to as “Subscriber”, “User”, or “You”).

WHEREAS, the Company is engaged in the operation and management of a digital platform providing news subscription services by way of electronic mail communication, notifications, and periodic updates (collectively referred to as “News Subscription Service” or “Service”);

AND WHEREAS, the Company recognizes the importance of maintaining the confidentiality, integrity, and security of personal information of its Subscribers, and accordingly adopts this Privacy Policy to govern the manner in which such information is collected, processed, stored, used, disclosed, transferred, and protected;

AND WHEREAS, this Privacy Policy has been framed to ensure compliance with the applicable laws of India, including but not limited to the Information Technology Act, 2000 and allied Rules, as well as the principles of lawful processing, fairness, transparency, accountability, and purpose limitation;

NOW, THEREFORE, in consideration of the mutual obligations between the Company and the Subscriber, this Privacy Policy sets out the rights and obligations of both parties in relation to the handling of information under the News Subscription Service.

 

1. DEFINITIONS

For the purposes of this Policy, unless the context otherwise requires:

1.1. “Personal Information” means any information that relates to an individual, which, either directly or indirectly, in combination with other information available or likely to be available with the Company, is capable of identifying such individual, including but not limited to name, contact number, email address, gender, date of birth, and communication preferences.

1.2. “Sensitive Personal Data or Information” (hereinafter referred to as “SPDI”) shall include such categories of data as are defined under Rule 3 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including passwords, financial information, health conditions, biometric data, or any other information so designated under law.

1.3. “Processing” means any operation or set of operations that is performed on Personal Information, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.

1.4. “Subscriber” means any natural person who has voluntarily provided information to the Company for the purpose of receiving news, notifications, or updates through the Service.

1.5. “Consent” means any freely given, specific, informed, and unambiguous indication of the Subscriber’s agreement to the processing of their Personal Information by way of a statement or affirmative action.

 

2. APPLICABILITY

2.1. This Privacy Policy applies exclusively to all Subscribers of the Winngoo News Subscription Service and governs all interactions arising from the voluntary subscription to receive news, alerts, and updates disseminated by the Company via email or other electronic channels.

2.2. By subscribing to the Service, the Subscriber acknowledges that they have read, understood, and agreed to the terms of this Policy and consent to the collection and use of their information in accordance herewith.

2.3. This Policy does not apply to third-party platforms or external websites that may be linked to the Company’s website or communications, nor does it apply to any information collected by such third parties.

 

3. COLLECTION OF INFORMATION

3.1. The Company collects Personal Information from Subscribers through online forms, digital interfaces, voluntary email submission, or other electronic means provided on the Company’s website or authorized communication channels.

3.2. The categories of information that may be collected include, but are not limited to:

(a) Full name and contact details;

(b) Email address used for subscription purposes;

(c) Communication preferences and topics of interest;

(d) System identifiers such as IP address, browser type, and device metadata, for the purpose of ensuring secure delivery;

(e) Transactional metadata related to subscription activity.

3.3. The Subscriber acknowledges that certain information is mandatory for the functioning of the Service, and failure to provide such information may result in partial or complete non-provision of the Service.

3.4. The Company does not knowingly collect information from minors under the age of eighteen (18) years. By subscribing, the Subscriber affirms that they have attained the age of majority as per the laws of India.

 

4. USE OF INFORMATION

4.1. The Personal Information so collected by the Company shall be used solely for legitimate and lawful purposes connected with the provision, management, enhancement, and maintenance of the News Subscription Service and ancillary operations thereof.

4.2. Without prejudice to the generality of the foregoing, the Company may process the Subscriber’s information for the following specific purposes:

(a) To manage and administer subscription enrolments, confirmations, renewals, and terminations;

(b) To send periodic news updates, notifications, and information relevant to the Subscriber’s expressed preferences;

(c) To authenticate user identity and ensure the secure transmission of communication;

(d) To maintain accurate records of Subscriber consent, preferences, and correspondence;

(e) To carry out internal assessments, performance analysis, and system testing to enhance user experience;

(f) To comply with legal obligations, regulatory audits, or statutory requests by competent authorities.

4.3. The Company shall not use or disclose Personal Information for purposes beyond those specified herein, unless the Subscriber has explicitly consented to such additional use, or such disclosure is mandated under applicable law or judicial order.

4.4. The Company may anonymize or aggregate Personal Information to create statistical or analytical data for internal business intelligence, provided such data cannot reasonably be used to identify an individual Subscriber.

 

5. LAWFUL BASIS OF PROCESSING

5.1. The Company shall ensure that all Processing activities are conducted on one or more of the following lawful bases:

(a) The Subscriber has given explicit consent for one or more specified purposes;

(b) Processing is necessary for the performance of the Service or contractual obligations between the Company and the Subscriber;

(c) Processing is required for compliance with legal obligations imposed upon the Company;

(d) Processing is necessary for legitimate interests pursued by the Company, provided that such interests are not overridden by the fundamental rights and freedoms of the Subscriber.

5.2. The Company undertakes to maintain detailed records of processing activities, consent obtained, and the lawful basis relied upon in accordance with applicable compliance requirements.

 

6. DISCLOSURE OF INFORMATION

6.1. The Company shall not sell, rent, lease, or otherwise commercially exploit any Personal Information of the Subscriber.

6.2. Personal Information may, however, be disclosed under the following limited circumstances:

(a) To employees, officers, or authorized agents of the Company who require such access for operational or administrative purposes;

(b) To professional advisers, consultants, or auditors who are bound by confidentiality obligations;

(c) To governmental, statutory, or reg

6.3. All disclosures shall be recorded, and the Company shall ensure that any third party receiving information provides the same level of protection and security as prescribed under Indian law.

 

7. DATA STORAGE AND RETENTION

7.1. The Company shall retain Personal Information for such duration as is necessary to fulfill the purpose for which it was collected, or as required under applicable legal, regulatory, or contractual obligations.

7.2. Upon cessation of the purpose or upon withdrawal of consent, whichever is earlier, the Company shall either delete or anonymize the Personal Information, unless retention is required under law.

7.3. The Company maintains secure digital databases within infrastructure located in India. No data shall be transferred outside the territorial jurisdiction of India unless it meets the requirements of Section 43A of the IT Act, 2000 and any allied rules or government notification relating to cross-border data transfer.

7.4. The Company reserves the right to retain anonymized or non-personally identifiable information for research, analytics, or archival purposes in perpetuity.

 

8. DATA SECURITY AND PROTECTION

8.1. The Company has implemented reasonable security practices and procedures commensurate with the nature of the information collected and the risks associated therewith.

8.2. Such measures include, but are not limited to, encryption of communications, secure server architecture, access control mechanisms, regular vulnerability assessments, and monitoring for unauthorized access or intrusion attempts.

8.3. The Company shall not be liable for any unauthorized interception, access, or breach that occurs due to factors beyond its reasonable control, including but not limited to acts of hacking, system compromise, or transmission errors on the part of the Subscriber.

8.4. The Subscriber acknowledges and accepts that while the Company employs industry-standard measures to safeguard Personal Information, no system can guarantee absolute security.

8.5. Employees and authorized personnel handling Personal Information are trained and bound by confidentiality obligations and disciplinary action for any unauthorized disclosure.

 

9. RIGHTS OF THE SUBSCRIBER

9.1. Every Subscriber shall have the following rights in relation to their Personal Information:

(a) The right to obtain confirmation regarding whether the Company holds or processes their Personal Information;

(b) The right to access and request copies of such information;

(c) The right to correct or update inaccurate or incomplete information;

(d) The right to withdraw consent previously granted, subject to contractual and legal obligations;

(e) The right to request erasure or blocking of information that is no longer required;

(f) The right to object to processing carried out for direct marketing or non-essential purposes.

9.2. Any such request may be made by submitting a written communication to the Company’s designated Data Protection Officer (“DPO”), whose contact details shall be published on the official website of the Company.

9.3. The Company shall respond to such requests within a reasonable period, subject to verification of the Subscriber’s identity and applicable limitations under law.

 

10. CONSENT AND WITHDRAWAL

10.1. By subscribing to the Service and voluntarily providing information, the Subscriber consents to the collection and processing of their Personal Information in accordance with this Policy.

10.2. Consent may be withdrawn at any time by following the opt-out mechanism provided in each communication or by contacting the DPO directly.

10.3. The withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal. However, upon withdrawal, the Company reserves the right to discontinue the provision of the Service to the Subscriber.

10.4. Where consent is withdrawn, the Company shall delete or anonymize all Personal Information except such data as is required to be retained under law.

 

11. THIRD-PARTY LINKS AND SERVICES

11.1. The Service may contain links to third-party websites or external content operated by independent entities.

11.2. The Company assumes no responsibility for the privacy practices, security, or content of such third-party platforms. The Subscriber is encouraged to review the privacy statements of such platforms prior to interaction or disclosure of information.

11.3. Any interaction with such third-party links shall be at the sole risk and discretion of the Subscriber.

 

12. COOKIES, TRACKING, AND ANALYTICS

12.1. The Company may use cookies, tracking pixels, or similar technologies to improve the functionality, user experience, and security of the Service.

12.2. Cookies are small text files placed on the Subscriber’s device to assist in storing preferences, authenticating sessions, and analysing traffic patterns.

12.3. The Subscriber may disable cookies through browser settings; however, certain features of the Service may not function optimally thereafter.

12.4. Any analytical data collected through cookies shall be used solely for internal purposes and shall not be shared externally in identifiable form.

 

13. DATA BREACH MANAGEMENT AND INCIDENT REPORTING

13.1. The Company recognizes that despite best efforts and reasonable security practices, incidents of data breaches may occur due to unforeseen technical or human failures. In such an event, the Company shall act promptly to contain, assess, and mitigate the impact of the breach.

13.2. Upon detection of a data breach or suspected compromise involving Personal Information, the Company shall:

(a) Immediately restrict unauthorized access to prevent further loss or misuse of data;
(b) Conduct a detailed internal investigation to ascertain the cause, scope, and impact of the breach;
(c) Record all relevant facts, findings, and remedial measures taken in an incident register;
(d) Where legally required, notify the affected Subscribers and relevant authorities, including the Indian Computer Emergency Response Team (CERT-In), within the time frame stipulated under law;
(e) Implement corrective and preventive action plans to prevent recurrence.

13.3. The Company shall maintain an internal Data Breach Response Protocol consistent with the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, as amended from time to time.

13.4. No compensation, liability, or damages shall be payable by the Company for breaches arising out of external factors beyond its control, including acts of hacking, malware intrusion, or force majeure events.

 

14. LEGAL DISCLOSURE

14.1. The Company may be required to disclose Personal Information to governmental or regulatory authorities, law enforcement agencies, or courts pursuant to lawful requests or directions.

14.2. The Company shall ensure that such disclosure is made only to the extent necessary and in compliance with applicable procedures prescribed under Indian law.

14.3. The Subscriber hereby expressly consents that the Company shall not be held liable for any such disclosure made in good faith and in compliance with statutory obligations.

 

15. TRANSFER OF INFORMATION

15.1. All Personal Information collected shall be processed and stored within the territorial limits of India.

15.2. In exceptional circumstances where cross-border transfer is necessary for service facilitation, technical processing, or backup storage, the Company shall ensure that:

(a) The transfer is made only to jurisdictions that ensure an equivalent or higher degree of data protection;
(b) The receiving entity provides binding contractual assurances of maintaining confidentiality and security;
(c) The Subscriber’s consent has been obtained prior to such transfer, except where mandated under law.

15.3. The Company retains the discretion to use secure, India-based cloud or hybrid infrastructure solutions for redundancy and disaster recovery.

 

16. LIMITATION OF LIABILITY

16.1. To the fullest extent permitted under applicable law, the Company, its directors, officers, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to the collection, storage, use, or disclosure of Personal Information under this Policy.

16.2. The total aggregate liability of the Company for any direct loss or damage under this Policy shall not exceed the sum of ₹1,000 (Rupees One Thousand Only) per Subscriber, irrespective of the number of claims or occurrences.

16.3. The Company shall not be responsible for any delay, error, or failure in transmission, communication, or data processing due to factors beyond its reasonable control.

17. INDEMNITY

17.1. The Subscriber agrees to indemnify, defend, and hold harmless the Company, its affiliates, and their respective officers, employees, and representatives from any claims, losses, damages, liabilities, or costs (including reasonable legal fees) arising from:

(a) Any breach of this Policy by the Subscriber;
(b) Misuse, unauthorized disclosure, or fraudulent use of the Service;
(c) Violation of applicable laws or third-party rights in connection with the Subscriber’s actions;
(d) Any act or omission resulting in harm or loss to another Subscriber or to the Company.

17.2. The obligations contained in this clause shall survive termination of the subscription or cessation of the Service.

18. COMPLIANCE WITH LAW

18.1. The Company undertakes to comply with all applicable data protection, cybersecurity, and information technology laws of India, including but not limited to:

(a) The Information Technology Act, 2000;
(b) The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
(c) The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
(d) Any future data protection legislation enacted by the Government of India.

18.2. The Company may, at its discretion, voluntarily align certain practices with international standards such as the General Data Protection Regulation (GDPR) of the European Union for enhanced user trust and transparency, without prejudice to its obligations under Indian law.

19. COMMUNICATION OF CHANGES

19.1. The Company reserves the right to amend, modify, or update this Privacy Policy at any time in its sole discretion, subject to applicable law.

19.2. Any material changes to this Policy shall be communicated to Subscribers via electronic mail or by publishing the revised version on the official website of the Company.

19.3. Continued use of the Service after publication of such amendments shall constitute deemed acceptance by the Subscriber.

20. TERMINATION OF SUBSCRIPTION

20.1. The Subscriber may terminate their subscription to the Service at any time through the prescribed procedure.

20.2. Upon termination, the Company shall cease all further communications and delete or anonymize the Subscriber’s Personal Information, subject to retention obligations under law.

20.3. The Company reserves the right to suspend or terminate any subscription without notice in cases of suspected misuse, unlawful conduct, or breach of this Policy.

21. CONFIDENTIALITY OBLIGATIONS

21.1. The Company acknowledges that Personal Information shared by the Subscriber constitutes confidential data and undertakes to maintain the strictest degree of confidentiality in its handling.

21.2. Employees and authorized personnel shall execute appropriate non-disclosure undertakings as a precondition to their access to such data.

21.3. Confidential information shall not be disclosed, copied, reproduced, or disseminated except for legitimate business purposes or under compulsion of law.

22. FORCE MAJEURE

22.1. The Company shall not be liable for any failure to perform its obligations under this Policy if such failure arises out of or results from circumstances beyond its reasonable control, including but not limited to natural disasters, wars, civil disturbances, power failures, network outages, government actions, or pandemics.

22.2. Upon the occurrence of a Force Majeure event, the Company shall endeavour to resume normal operations as soon as practicable.

23. GOVERNING LAW AND JURISDICTION

23.1. This Privacy Policy shall be governed by and construed in accordance with the laws of India.

23.2. Subject to Clause 24 herein, the courts at Chennai, Tamil Nadu, shall have exclusive jurisdiction over any disputes arising out of or relating to this Policy.

24. DISPUTE RESOLUTION AND ARBITRATION

24.1. Any dispute, controversy, or claim arising from or in connection with this Privacy Policy shall be resolved amicably through consultation within thirty (30) days of the dispute being notified by either party.

24.2. In the event that such dispute remains unresolved, it shall be referred to arbitration in accordance with the provisions of the Arbitration and Conciliation Act, 1996.

24.3. The arbitration shall be conducted by a sole arbitrator appointed mutually by both parties. The seat and venue of arbitration shall be Chennai, India, and the proceedings shall be conducted in the English language.

24.4. The arbitral award shall be final and binding on both parties and may be enforced in any competent court of jurisdiction.

25. CONTACT AND GRIEVANCE REDRESSAL

25.1. In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Company has designated a Grievance Officer to address concerns related to the processing of information under this Policy.

25.2. The details of the Grievance Officer are as follows:
Name: Grievance Officer – Winngoo India Private Limited
Email: [insert email]
Address: No. 45, Adyar, Chennai, Tamil Nadu – 600020, India
Working Hours: Monday to Friday, 10:00 AM to 6:00 PM (IST)

25.3. The Grievance Officer shall acknowledge receipt of a complaint within seven (7) working days and endeavor to resolve the matter within thirty (30) days from such acknowledgment.

25.4. In case the Subscriber is dissatisfied with the resolution provided, they may escalate the issue to the relevant statutory authority having jurisdiction.

26. MISCELLANEOUS

26.1. If any provision of this Policy is held to be invalid, illegal, or unenforceable by a competent authority, such provision shall be severed, and the remainder of the Policy shall continue in full force and effect.

26.2. The headings contained herein are for convenience only and shall not affect the interpretation of this Policy.

26.3. No waiver of any right or remedy by the Company shall operate as a waiver of any other right or remedy.

26.4. This Policy constitutes the entire understanding between the Subscriber and the Company with respect to the subject matter hereof and supersedes all prior communications or representations.

IN WITNESS WHEREOF, this Privacy Policy has been duly adopted by Winngoo India Private Limited and published for the information of all Subscribers of its News Subscription Service, effective as of the date of publication.

Mobile Experience

Grab Your Coupon Bag
with Our Mobile App!

Discover businesses, exclusive offers, and valuable deals, all in one app designed to help you spend smarter.

  • Explore Nearby BusinessesDiscover businesses and services around you with ease.
  • Discover Exclusive DealsFind valuable offers and discounts from listed businesses.
  • Save On Every PurchaseEnjoy better value with deals that help you save more.