BACK TO HOME

Privacy Policy & Data Governance Charter

I MANDATE & PHILOSOPHY

At PantherX, we recognize that data is the lifeblood of modern commerce and its protection is a fundamental human right. This Data Governance Charter (the "Charter") is not merely a legal requirement but a solemn pledge to our users. We employ "Privacy by Design" principles, ensuring that every line of code written and every server configured prioritizes the sanctity of your business intelligence.

This document provides an exhaustive disclosure of how PantherX Technology Solutions ("we", "us", "our") handles the Personal Data and Business Intelligence of its registered users. By engaging with our services, you enter into a covenant of trust, governed by the terms explicitly detailed herein.

II TAXONOMY OF DATA COLLECTION

2.1 Core Identity Intelligence

We collect high-fidelity identity data to ensure the integrity of our logistics network. This includes your legal birth name, secondary contact vectors (alternative emails and numbers), and precise geographical coordinates of your registered business headquarters.

2.2 Regulatory & Statutory Assets (KYC)

In adherence to the Digital Personal Data Protection (DPDP) Act and Anti-Money Laundering (AML) directives, we require:

  • Government Issued IDs: High-resolution scans of Aadhaar, PAN, and Voter ID for biometric-linked verification.
  • Taxation Credentials: GSTIN certificates and associated filing history to validate commercial legitimacy.
  • Financial DNA: Cancelled cheques, IFSC codes, and bank statement snippets for automated payout reconciliation.
2.3 Behavioral & Telemetric Metadata

Our sophisticated tracking engines monitor your digital footprint within the PantherX ecosystem. This includes heatmaps of dashboard usage, API latency logs, session duration, and device-specific telemetry (IMEI numbers, MAC addresses, and CPU architecture logs) to prevent unauthorized account cloning.

III THE ALGORITHMIC ENGINE: WHY WE PROCESS DATA

Data processing at PantherX is strictly limited to "Authorized Purposes" which include:

  • Dynamic Routing: Utilizing your address data to calculate the most efficient transit paths through our 20+ carrier partners.
  • Predictive Analytics: Analyzing your shipping volumes to offer customized "Enterprise Tier" pricing and credit limits.
  • Security Orchestration: Using IP geolocation to block "Man-in-the-Middle" attacks and unauthorized login attempts from high-risk jurisdictions.
  • Legal Compliance: Generating e-Way bills and automated tax invoices that comply with local and international revenue laws.

FORTRESS-GRADE SECURITY ARCHITECTURE

PantherX utilizes Military-Grade AES-256 bit encryption at rest and TLS 1.3 encryption in transit. Our database is sharded across multiple geo-redundant locations to ensure 99.99% data availability. However, the User acknowledges that the "Human Element" is the weakest link in security; PantherX shall not be held liable for breaches caused by the User's password hygiene or social engineering attacks.

IV THIRD-PARTY ECOSYSTEM & DATA FLOW

We do not "sell" data in the traditional sense. However, to execute your logistics requirements, data must flow to:

  • Carrier Aggregators: Your shipment data is tokenized and transmitted to partners like FedEx, BlueDart, and Delhivery for physical execution.
  • Identity Gateways: KYC documents are processed through government-approved E-Sign and Digilocker APIs for real-time authentication.
  • Cloud Sovereignty: All data is stored on servers located within the sovereign borders of India to comply with local data residency laws.

V DATA LIFECYCLE & OBLIVION RIGHTS

5.1 Retention Mandates

By law, financial and KYC records must be preserved for a period of 84 months (7 years). This data remains in an encrypted "Read-Only" state even if the User terminates their account, to satisfy potential audits by the Enforcement Directorate or Income Tax authorities.

5.2 The Right to be Forgotten

Users may request the "De-indexing" of their non-essential data. Upon such a request, we will purge marketing profiles and behavioral logs within 30 days, provided there are no outstanding financial liabilities or active legal disputes.

VI CROSS-BORDER DATA TRANSFERS

For international shipments (Exports), your data may be transmitted to foreign customs authorities and international carriers. You acknowledge that data protection laws in destination countries may differ from those in India, and you explicitly waive any claims against PantherX regarding data handling by foreign statutory bodies.

VII GRIEVANCE REDRESSAL & DPO

In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, we have appointed a Chief Data Protection Officer (DPO). Any grievances regarding data misuse or privacy breaches must be formally lodged via our encrypted grievance portal.

VIII REVISIONS & JURIDICAL UPDATES

The digital legal landscape is constantly evolving. PantherX reserves the right to modify this Charter at any time. Significant changes will be broadcasted via the User Dashboard. Your continued use of the platform after such notifications constitutes an "Affirmative Action" of acceptance of the new terms.

IX COOKIE ARCHITECTURE & TRACKING PIXELS

PantherX uses cookies, web beacons, and tracking pixels to enhance user experience. These are categorized into:

  • Essential Cookies: Necessary for session persistence and security.
  • Analytical Pixels: Provided by Google Analytics and Meta to understand user navigation patterns.
  • Functional Cookies: To remember your dashboard preferences and saved addresses.

By using the platform, you consent to the placement of these cookies on your device. You may disable them in browser settings, but certain features of the PantherX dashboard may become non-functional.

X CHILDREN'S PRIVACY (COPPA COMPLIANCE)

PantherX is a B2B platform and does not knowingly collect data from individuals under the age of 18. If we discover that a minor has provided us with personal data, we will immediately purge the record and terminate the associated account.

XI DATA BREACH NOTIFICATION PROTOCOL

In the highly unlikely event of a data breach, PantherX will notify the relevant statutory authorities (CERT-In) within 72 hours. Users will be informed via dashboard alerts or email regarding the nature of the breach and steps taken to mitigate risk. PantherX's liability in such events is limited to the restoration of service and does not extend to financial compensation.

XII CROSS-DEVICE TRACKING & FINGERPRINTING

To prevent account sharing and unauthorized access, we use "Device Fingerprinting" technology. This collects metadata about your hardware, operating system, and browser to create a unique identifier. This ensures that only you can access your account from authorized devices.

XIII COOPERATION WITH LAW ENFORCEMENT

PantherX will proactively cooperate with all government agencies, including but not limited to the Narcotics Control Bureau (NCB), Enforcement Directorate (ED), and the Police, by providing user data, IP logs, and shipment history without requiring a prior court order in cases of suspected criminal activity.

XIV BIOMETRIC METADATA DISCLOSURE

When you upload KYC documents, our AI engines may extract facial biometrics and digital signatures for cross-verification against government databases. By uploading these documents, you provide "Informed Consent" for the processing of such biometric-linked metadata.

DATA SANCTITY IS OUR PRIORITY.

PantherX Data Protection Office • New Delhi, India

Document ID: PX-PRIV-2025-REv4.0