Privacy Policy

Last Updated: November 4, 2025

At Döner & Gyros India, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data in compliance with the General Data Protection Regulation (GDPR), the Information Technology Act, 2000, and other applicable data protection laws.

GDPR Compliant
ISO 27001 Compliant
IT Act 2000

1. Data Controller Information

Data Controller: Döner & Gyros India Private Limited

Email: enquiries@donergyrosindia.com

Phone: +91 98198 87999

Data Protection Officer: enquiries@donergyrosindia.com

2. Information We Collect

2.1 Information You Provide Directly

  • Franchise Inquiries: Name, email, phone number, city, investment capacity, experience
  • Contact Form: Name, email, phone number, message
  • Newsletter: Email address (with explicit consent)

2.2 Information Collected Automatically

  • Analytics: We use Plausible Analytics (privacy-friendly, EU-hosted, no cookies, no personal data)
  • Technical Information: IP address (hashed for privacy), browser type, device type, operating system
  • Usage Data: Pages visited, time spent, referral source
  • Location Data: City-level geolocation only (no precise location tracking)

2.3 Cookies and Tracking

We use essential cookies for website functionality and analytics cookies with your consent. See our Cookie Policy for details.

3. How We Use Your Information

3.1 Franchise Management (Legal Basis: Contract/Legitimate Interest)

  • • Process and evaluate franchise applications
  • • Communicate about franchise opportunities
  • • Conduct background verification
  • • Provide franchise support and documentation

3.2 Customer Service (Legal Basis: Contract/Legitimate Interest)

  • • Respond to inquiries and feedback
  • • Provide customer support
  • • Resolve complaints and issues

3.3 Marketing Communications (Legal Basis: Consent)

  • • Send newsletters (only with explicit consent)
  • • Notify about new menu items and promotions
  • • Share company updates and news

3.4 Website Improvement (Legal Basis: Legitimate Interest)

  • • Analyze website traffic and user behavior
  • • Improve website performance and user experience
  • • Test new features and content

3.5 Security and Fraud Prevention (Legal Basis: Legal Obligation/Legitimate Interest)

  • • Detect and prevent fraudulent activities
  • • Monitor for security threats
  • • Maintain audit logs for compliance

4. Data Security Measures

We implement industry-standard security measures to protect your personal data:

  • Encryption at Rest: AES-256-GCM encryption for all personal data in database
  • Encryption in Transit: TLS 1.3 for all data transmission
  • Access Controls: Role-based access control (RBAC) for admin users
  • Password Security: bcrypt hashing with 12+ character requirement
  • IP Hashing: SHA-256 hashing for IP addresses (privacy-compliant tracking)
  • Audit Logging: Comprehensive logging of all data access and modifications
  • Rate Limiting: Protection against brute force attacks
  • Secure Backups: Encrypted database backups with secure storage
  • Security Headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options
  • Regular Updates: Timely security patches and dependency updates

5. Data Sharing and Third Parties

We share your data only with trusted third-party service providers who help us operate our business:

Supabase (Database Hosting)

Purpose: Secure database storage and hosting
Data Shared: All encrypted application data
Location: EU and US data centers
GDPR: Fully compliant with Data Processing Agreement (DPA)
Privacy Policy: supabase.com/privacy

Cloudinary (Media Hosting)

Purpose: Image and media optimization and delivery
Data Shared: No personal data (public media only)
Location: Global CDN (GDPR-compliant)
Privacy Policy: cloudinary.com/privacy

Plausible Analytics (Website Analytics)

Purpose: Privacy-friendly website analytics
Data Shared: Anonymized usage data (no personal information)
Location: EU-hosted
GDPR: Fully compliant (no cookies, no personal data)
Privacy Policy: plausible.io/privacy

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6. Data Retention Policy

We retain personal information only as long as necessary for the purposes outlined in this policy:

  • Franchise Applications: 2 years from submission date
  • Contact Form Submissions: 1 year from submission date
  • Audit Logs: 1 year for security and compliance purposes
  • Analytics Data: 2 years (anonymized)
  • Marketing Consent: Until consent is withdrawn

You may request earlier deletion of your data by contacting us at enquiries@donergyrosindia.com.

7. International Data Transfers

Your data may be transferred to and processed in countries outside India, including:

  • European Union: Supabase (EU data centers), Plausible Analytics (EU-hosted)
  • United States: Supabase (US data centers), Cloudinary

We ensure appropriate safeguards through:

  • • Standard Contractual Clauses (SCCs) approved by the European Commission
  • • Data Processing Agreements (DPAs) with all third-party processors
  • • Adequacy decisions where applicable

8. Your Privacy Rights

Under GDPR and Indian data protection laws, you have the following rights:

Right to Access

Request a copy of all personal data we hold about you. Email enquiries@donergyrosindia.com with subject "Data Access Request".

Right to Rectification

Correct inaccurate or incomplete personal data. Contact us at enquiries@donergyrosindia.com.

Right to Erasure

Request deletion of your personal data. Email enquiries@donergyrosindia.com. We will respond within 30 days.

Right to Data Portability

Receive your personal data in a machine-readable format (JSON) for transfer to another service.

Right to Object

Object to processing based on legitimate interests or for marketing purposes.

How to Exercise Your Rights: Email us at enquiries@donergyrosindia.com with your request. We will verify your identity and respond within 30 days.

9. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at enquiries@donergyrosindia.com.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:

  • • Update the "Last Updated" date at the top of this page
  • • Notify you via email (if you have provided an email address)
  • • Display a prominent notice on our website

Continued use of our services after changes indicates acceptance of the updated policy.

11. Contact Information

Related Policies

1
Privacy Policy | Döner & Gyros India | Döner & Gyros India