Last updated: 1 April 2025. This Privacy Policy explains how LandEMI Real Estate Pvt. Ltd. (“LandEMI”, “we”, “our”, “us”) collects, uses, discloses, and safeguards personal data when you use our website, mobile application, and related services (collectively, the “Platform”). By accessing the Platform you accept this Policy.
1. Scope & Applicability
- This Policy applies to all visitors, registered users, buyers, referral partners, and any other person who interacts with the Platform.
- It governs personal data collected online (website, app) and offline (branch visits, phone calls, paper forms).
- LandEMI is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Body Corporate under the IT (Amendment) Act, 2008 and SPDI Rules, 2011.
- If you are a minor (below 18 years), you may use the Platform only with verifiable parental/guardian consent.
- This Policy does not apply to third-party websites linked from our Platform — review their privacy policies independently.
2. Information We Collect
- Identity data: Full legal name, date of birth, gender, nationality, Aadhaar number (masked), PAN card number, Passport/Voter ID/Driving Licence details.
- Contact data: Mobile number, email address, permanent/correspondence address, PIN code, city, state.
- Financial data: Bank account number, IFSC code, UPI ID, credit/debit card details (stored as a tokenised reference only — no raw card data is stored on our servers), income/salary details shared for EMI eligibility.
- Transaction data: EMI payment history, amounts, dates, gateway references, receipts, due-date records, outstanding balance.
- KYC data: Scanned copies of government-issued identity and address proof documents uploaded during onboarding.
- Property preference data: Plot shortlists, watchlists, search queries, filters applied, plots viewed, EMI plans compared.
- Communication data: Support ticket content, chat transcripts, emails, call recordings (where disclosed), feedback and survey responses.
- Device & technical data: IP address, browser type and version, operating system, device identifiers, time zone, screen resolution, referring URLs.
- Usage data: Pages visited, links clicked, session duration, feature interactions, error logs.
- Location data: City/state derived from IP (approximate) or GPS (if you grant permission in the mobile app).
- Referral data: Referral codes used, referred-user IDs, referral bonus calculations.
- Photograph/biometric: Profile photograph uploaded voluntarily; we do not process facial recognition or fingerprint data.
- Publicly available data: Information lawfully obtained from public records (e.g., RERA portal, MCA filings) to verify property or developer details.
3. How We Collect Information
- Directly from you when you register, fill a form, buy a plot, or contact support.
- Automatically through cookies, web beacons, log files, and SDKs embedded in the Platform.
- From third parties such as credit bureaus (CIBIL, Experian), payment gateways (Razorpay, PayU), KYC service providers, and government databases (DigiLocker, UIDAI).
- From our referral partners who share basic contact details of prospects with your consent.
- From analytics providers (Google Analytics, Mixpanel) under their respective privacy standards.
4. Cookies & Tracking
- We use strictly necessary cookies to keep you logged in and maintain session security — these cannot be disabled without breaking core functionality.
- Functional cookies store your preferences such as dark/light mode, saved filters, and language settings.
- Analytics cookies (Google Analytics) help us understand how visitors use the Platform. Data is anonymised before transmission.
- Marketing cookies from Meta (Facebook Pixel) and Google Ads are placed only with your explicit consent via our cookie-consent banner.
- You may manage or withdraw cookie consent at any time via the “Cookie Preferences” link in the footer. Withdrawing consent will not affect the lawfulness of prior processing.
- We honour browser-level “Do Not Track” signals for analytics tracking.
5. Legal Basis & Purpose of Processing
- Contract performance: Processing your plot booking, EMI schedules, and payment receipts is necessary to fulfil your agreement with us.
- Legal obligation: KYC, AML checks, TDS deduction (Section 194-IA), and RERA compliance require us to collect and retain certain data.
- Legitimate interest: Fraud prevention, platform security, improving our products, and direct marketing to existing customers.
- Consent: Promotional emails/SMS, push notifications, marketing cookies, and sharing data with affiliates require and rely on your explicit consent.
- We send transactional communications (payment receipts, EMI reminders, OTPs, account alerts) without seeking marketing consent as these are essential to the service.
6. How We Use Your Information
- To create and manage your account and verify your identity.
- To process plot bookings, generate EMI schedules, and collect payments.
- To send OTPs, EMI due-date reminders, payment receipts, and account alerts.
- To perform KYC and Anti-Money Laundering (AML) checks as required by law.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To personalise your experience — showing plots in your preferred city and price range.
- To calculate and credit referral bonuses and track the 5-level referral chain.
- To improve our platform through A/B testing, usage analysis, and user-experience research.
- To comply with tax obligations including TDS deduction and issuance of Form 26QB.
- To respond to your support queries, complaints, and legal notices.
- To send you promotional communications about new plots, offers, and platform features (only with consent).
- To fulfil regulatory reporting obligations to RERA authorities, income-tax authorities, and financial intelligence units.
7. Data Sharing & Disclosure
- We never sell your personal data to any third party for commercial gain.
- Payment processors (Razorpay, PayU, CCAvenue) receive payment data only to the extent required to process your transaction.
- KYC/identity verification providers receive document copies to verify your identity as mandated by law.
- Credit bureaus may receive EMI repayment history if you opt into credit-reporting (disclosed separately at sign-up).
- Cloud infrastructure providers (AWS, DigitalOcean) host encrypted data in data centres located in India.
- Legal authorities: We disclose data when required by a court order, government authority, or law enforcement agency under applicable Indian law.
- Developers/landowners receive your basic contact details (name, phone) only after you confirm purchase intent, to facilitate registration paperwork.
- Professional advisors: Lawyers, auditors, and insurers bound by confidentiality obligations.
- Business transfer: In the event of a merger, acquisition, or asset sale, personal data may be transferred — you will be notified before any such transfer.
8. Data Retention
- Account data is retained for the duration of your account plus 7 years after closure, as required by Indian accounting and tax laws.
- KYC documents are retained for 5 years post-transaction under Prevention of Money Laundering Act (PMLA) rules.
- Payment records are retained for 8 years as required by the Income Tax Act, 1961.
- Support communications are retained for 3 years to handle potential disputes.
- Marketing consent logs are retained for 3 years after consent withdrawal to demonstrate compliance.
- Server access logs are retained for 180 days for security purposes, then automatically purged.
- Anonymised, aggregated analytics data may be retained indefinitely as it cannot identify individuals.
9. Data Security
- All data in transit is encrypted using TLS 1.2 / 1.3.
- Data at rest (databases, file storage) is encrypted using AES-256.
- Passwords are hashed using bcrypt with a per-user salt — plaintext passwords are never stored.
- Payment card data is never stored on our servers — we use PCI-DSS-compliant tokenisation provided by payment gateways.
- Access to production systems is restricted to authorised engineers via multi-factor authentication and SSH key pairs.
- We conduct annual third-party security audits and penetration tests.
- A dedicated Data Protection Officer (DPO) oversees our data security programme and can be reached at dpo@landemi.in.
- In the event of a data breach affecting your rights, we will notify you and the relevant authority within 72 hours of becoming aware, as required by DPDPA 2023.
10. Cross-Border Data Transfers
- We store and process all personal data of Indian residents on servers located within India.
- Analytics data processed by Google (Google Analytics) may transit through servers outside India under Google’s Standard Contractual Clauses.
- Any future cross-border transfer will comply with Section 16 of the DPDPA 2023 and Central Government notifications issued thereunder.
11. Your Rights as a Data Principal
- Right to access: Request a summary of personal data we hold about you at any time.
- Right to correction: Rectify inaccurate or incomplete personal data via your account settings or by emailing privacy@landemi.in.
- Right to erasure: Request deletion of your data; note that data required by law or for pending transactions cannot be erased immediately.
- Right to data portability: Receive your personal data in a machine-readable format (JSON/CSV) for transfer to another service.
- Right to withdraw consent: Withdraw marketing consent at any time — this does not affect prior processing.
- Right to nominate: Under DPDPA 2023, you may nominate another individual to exercise your data rights in the event of death or incapacity.
- Right to grievance redressal: Raise a complaint with our Grievance Officer (details below) within a reasonable time. We will resolve it within 30 days.
- Right to approach the Data Protection Board: If unsatisfied with our response, you may file a complaint with the Data Protection Board of India established under DPDPA 2023.
12. Children’s Privacy
- The Platform is not intended for persons below 18 years of age.
- We do not knowingly collect personal data from minors without verifiable parental consent.
- If we discover that a minor has registered without consent, we will delete the account and associated data promptly.
13. Third-Party Links & Integrations
- The Platform may contain links to third-party sites (e.g., RERA portal, DigiLocker, government stamp-duty calculators). We are not responsible for their privacy practices.
- Social login (Google OAuth) transmits only your name, email, and profile picture — we do not receive your passwords or private contacts.
14. Changes to This Policy
- We reserve the right to amend this Policy at any time. Material changes will be notified via email and a prominent banner on the Platform at least 15 days before the change takes effect.
- Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
- A version history of this Policy is maintained and available on request.
15. Grievance Officer & Contact
- Grievance Officer: Mr. Ravi Shankar, Chief Compliance Officer, LandEMI Real Estate Pvt. Ltd.
- Email: grievance@landemi.in | Phone: +91-40-XXXX-XXXX (Mon–Fri, 9 AM–6 PM IST)
- Postal address: 4th Floor, Tech Tower, HITEC City, Hyderabad – 500081, Telangana, India.
- Complaints related to personal data may be raised at privacy@landemi.in. We will acknowledge within 48 hours and resolve within 30 days.
- For Data Protection Officer enquiries: dpo@landemi.in.
16. Governing Law
- This Policy is governed by the laws of India including the Information Technology Act, 2000, SPDI Rules 2011, the DPDPA 2023, and applicable RBI and RERA regulations.
- Disputes arising from this Policy are subject to the exclusive jurisdiction of courts in Hyderabad, Telangana.
- This Policy is written in English. In the event of a conflict between the English version and any translation, the English version prevails.
- If any provision of this Policy is held to be invalid by a competent authority, the remaining provisions shall continue in full force and effect.
- Our cookie consent management platform (CMP) logs a timestamped record of every consent or refusal for audit purposes.
- We conduct privacy impact assessments (PIAs) before launching any new feature that involves significant personal data processing.