Legal ยท Tiaano Smart

Privacy Policy

Effective Date: 1 January 2025  ยท  Last Updated: 14 May 2026  ยท  Version: 2.1

This Privacy Policy (the "Policy") explains how Ti Anode Fab Pvt. Ltd. and its associated entities (collectively "Tiaano Smart", "we", "us", or "our") collect, use, store, disclose and protect personal data when you visit our websites, use our mobile applications, or interact with us through Google Play Store, Apple App Store, Facebook, WhatsApp or any other platform we operate on.

This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000 and the rules framed thereunder, and the data-handling requirements of Google Play, the Apple App Store, Meta Platforms (Facebook and WhatsApp) and the EU General Data Protection Regulation (GDPR) where applicable.

Table of Contents
  1. Who We Are
  2. Scope & Applicability
  3. Personal Data We Collect
  4. How We Collect Data
  5. Purposes & Legal Basis
  6. Aadhaar & DigiLocker
  7. Sharing & Disclosure
  8. Data Retention
  9. Security Measures
  10. Your Rights
  11. Children's Privacy
  12. Cookies & Tracking
  13. International Transfers
  14. Google Play Store
  15. Apple App Store
  16. Facebook Platform
  17. WhatsApp Business
  18. Updates to this Policy
  19. Contact & Grievance Officer

1.Who We Are

Tiaano Smart is the Centralized Control Unit (CCU) of the Tiaano group of companies, which has been engaged in inert-metal fabrication and allied industries since 1992. The Policy covers, but is not limited to, the following entities and brands:

  • Ti Anode Fab Pvt. Ltd. โ€” manufacturer of electrochemical equipment in titanium, tantalum, niobium, zirconium, nickel, duplex steel and precious-metal coatings
  • Aquafil โ€” Dimensionally Stable Anodes and water-technology products
  • Fibtec Enterprises โ€” composite (FRP / GRP) tanks, vessels and process piping
  • ScaleX โ€” electrolytic water-conditioning systems
  • Tiaano Vidyashrm โ€” CBSE-affiliated school in Pushpagiri, Kanchipuram
  • Tiaano Foundation โ€” CSR umbrella
  • Nayagi โ€” traditional snacks and ready-to-cook foods

Registered office: {COMPANY.address.line1}, {COMPANY.address.line2}, Tamil Nadu, India. For all data-protection enquiries, please refer to Section 19 (Contact).

2.Scope & Applicability

This Policy applies to all personal data we process when you:

  • Visit tiaanosmart.in or any of the Tiaano family of websites (anode, aquafil, fibtec, scalex, vidyashrm, foundation, nayagi);
  • Submit a career application via our careers portal (including documents fetched from DigiLocker);
  • Download, install or use any of our mobile applications listed on the Google Play Store or Apple App Store;
  • Interact with our pages, posts, ads, Messenger or Instagram presence on Facebook (Meta Platforms);
  • Contact us via WhatsApp using our WhatsApp Business number;
  • Place an order, subscribe to a newsletter, or correspond with us by email or phone.

3.Personal Data We Collect

The categories of personal data we collect depend on how you interact with us:

CategoryExamplesWhere collected
Identity data Full name, date of birth, gender, father's / spouse's name, photograph Careers form, DigiLocker
Government IDs Aadhaar (masked), PAN, scanned KYC documents Careers form, DigiLocker, KYC verification
Contact data Email, mobile number, residential and permanent address Careers form, contact / enquiry forms, WhatsApp Business
Professional data Education history, employment history, skills, certifications, rรฉsumรฉ Careers form
Demographic data Religion, community / caste, marital status, languages known Careers form (collected for statutory and equal-opportunity reporting only)
Technical data IP address, browser type, device identifiers, operating system, referring URL, time-stamps Automatic via server logs and analytics
Usage data Pages visited, time spent, clicks, search queries, downloads Cookies and similar tracking technologies
Communications data Content of emails, chat messages, WhatsApp conversations, support tickets Email, WhatsApp Business, contact forms
Transaction data Order details, payment status (we do not store card numbers) Online store, school fees, customer billing

4.How We Collect Data

  • Directly from you โ€” when you fill in a form, upload a document, send us an email or WhatsApp message, place an order, or sign in to one of our applications.
  • Automatically โ€” through cookies, server logs, error-tracking, and analytics on our websites and mobile apps.
  • From third parties โ€” for example, your Aadhaar e-KYC details are fetched from UIDAI's DigiLocker via Surepass; your rรฉsumรฉ may be sourced from a job-board where you applied; your contact details may be shared with us by a referrer.

5.Purposes & Legal Basis for Processing

We process personal data only for specific, lawful purposes that are necessary for the operation of our business, and only where we have a valid legal basis under the DPDP Act and applicable laws:

  • To evaluate your job application, conduct background verification and on-board you (basis: legitimate interest and consent);
  • To deliver products and services you have requested, and to manage your customer or student account (basis: contract);
  • To communicate with you regarding enquiries, orders, school admissions or service updates (basis: legitimate interest);
  • To comply with statutory obligations including KYC, tax, labour, education-board and CSR regulations (basis: legal obligation);
  • To improve our websites and applications, prevent fraud and ensure information security (basis: legitimate interest);
  • To send you marketing communications, but only with your explicit opt-in consent โ€” you may withdraw consent at any time (basis: consent).

6.Aadhaar & DigiLocker

UIDAI compliance: We never store the raw Aadhaar number, OTP, or biometric data. The Aadhaar number is captured only for the purpose of verifying identity via the UIDAI-authorised DigiLocker e-KYC flow, and is stored only in masked form (XXXX XXXX 1234) along with the verified XML payload returned by DigiLocker.

What happens during DigiLocker authentication

  • You enter your 12-digit Aadhaar number on our careers form;
  • You authenticate yourself on UIDAI's DigiLocker servers using the OTP sent to your Aadhaar-linked mobile, or using your existing DigiLocker credentials;
  • UIDAI returns a digitally-signed XML containing only the e-KYC fields you consented to share (name, date of birth, gender, address, photo);
  • We store this payload, encrypted at rest, only for the purpose of completing your job application and statutory employment records.

Tiaano Smart is not a Requesting Entity under the Aadhaar Act and does not perform Aadhaar authentication directly with UIDAI. All Aadhaar interactions are routed through Surepass Technologies Pvt. Ltd., a licensed sub-AUA / KUA, whose own privacy practices are available at surepass.io/privacy-policy.

7.Sharing & Disclosure

We do not sell personal data. We disclose personal data only in the following circumstances and only to the minimum extent necessary:

  • Within the Tiaano family โ€” between the entities listed in Section 1 for legitimate business purposes (e.g. routing your enquiry to the right division);
  • Service providers โ€” payment processors, cloud hosting (Microsoft Azure, AWS), SMS gateway (PPV Technology / mydreamstechnology), email service (Zoho), DigiLocker partner (Surepass), background-verification agencies, and similar processors who act on our instructions under signed Data-Processing Agreements;
  • Statutory authorities โ€” when required to comply with applicable law, court orders, or regulatory requests (income tax, EPFO, ESI, MCA, CBSE, GST, RBI, etc.);
  • Professional advisors โ€” auditors, lawyers and insurers, bound by professional confidentiality;
  • In connection with a business transaction โ€” to a successor entity in the event of merger, acquisition, restructuring or sale of assets;
  • With your explicit consent โ€” in any other case not covered above.

8.Data Retention

We retain personal data only as long as necessary:

  • Unsuccessful job applications: 12 months from the date of application, then anonymised or deleted;
  • Employee records: for the duration of employment plus 8 years thereafter (to satisfy income-tax, EPFO, ESI and labour-law requirements);
  • Customer order records: 8 years (GST and Companies Act requirements);
  • Marketing-consent records: until you withdraw consent, plus 1 year for audit purposes;
  • Web server & application logs: 90 days, then aggregated;
  • WhatsApp / messaging logs: 24 months from the last interaction.

9.Security Measures

We have implemented reasonable security practices and procedures aligned with ISO/IEC 27001 principles, including:

  • TLS 1.2+ encryption for all data in transit;
  • AES-256 encryption for data at rest in our databases;
  • Role-based access control with least-privilege principles;
  • Multi-factor authentication for all administrative access;
  • Regular vulnerability assessments and penetration testing;
  • Quarterly security awareness training for staff;
  • Documented incident-response and data-breach notification procedures.

In the unlikely event of a data breach affecting your personal data, we will notify the Data Protection Board of India and you within 72 hours of becoming aware, in accordance with the DPDP Act.

10.Your Rights

Under the DPDP Act and applicable data-protection laws, you have the following rights:

  • Right to access the personal data we hold about you;
  • Right to correction and erasure of inaccurate or unnecessary data;
  • Right to grievance redressal by writing to our Data Protection Officer (see Section 19);
  • Right to nominate another individual to exercise your rights in the event of your death or incapacity;
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • Right to data portability โ€” receive a copy of your data in a structured, commonly-used format;
  • Right to lodge a complaint with the Data Protection Board of India if you believe your rights have been violated.

To exercise any of these rights, please email privacy@tiaanosmart.in. We will respond within 30 days.

11.Children's Privacy

Our public-facing services are intended for users aged 18 and above. Where we do process the personal data of children (for example, at Tiaano Vidyashrm school), we do so only with verifiable parental consent, and we never use such data for targeted advertising, behavioural profiling, or any purpose that could cause harm to the child, in line with Section 9 of the DPDP Act and COPPA (United States) where applicable.

12.Cookies & Tracking Technologies

Our websites use cookies and similar technologies for the following purposes:

  • Strictly necessary โ€” session management, security, load balancing;
  • Functional โ€” remembering your preferences (e.g. dismissed banners);
  • Analytics โ€” aggregated usage statistics (no individual tracking);
  • Marketing โ€” only with your explicit consent.

You can control cookies through your browser settings. Disabling strictly-necessary cookies may break certain features of the site.

13.International Transfers

Some of our service providers (Microsoft, AWS, EmailJS, Zoho, Meta, Google) may process data on servers located outside India. Where this occurs, we ensure that an adequate level of protection is in place, either by selecting providers in jurisdictions whitelisted under the DPDP Act, or by signing Standard Contractual Clauses approved by the EU Commission for GDPR-equivalent protection.

14.Google Play Store Play Store

For Android applications published by Tiaano Smart on the Google Play Store, the Data Safety section declares the following:

Data TypeCollected?Shared?PurposeOptional?
Name, email, phoneYesNoAccount / app functionalityRequired
Photos & documentsYesNoProfile / KYCOptional
Device or other IDsYesNoAnalytics, fraud preventionRequired
App activityYesNoAnalytics, app performanceRequired
Crash logs & diagnosticsYesNoPerformance, stabilityRequired
Precise locationNoโ€”โ€”โ€”
Contacts, SMS, call historyNoโ€”โ€”โ€”
Financial info (e.g. card numbers)Noโ€”Handled by payment gateway onlyโ€”

Data is encrypted in transit using TLS 1.2 or higher. You may request the deletion of your account and associated data from within the app (Settings โ†’ Delete account) or by writing to privacy@tiaanosmart.in.

Our apps comply with the Google Play Developer Programme Policies, including the User Data Policy, Sensitive Permissions Policy and Families Policy.

15.Apple App Store App Store

For iOS / iPadOS applications, the Privacy Nutrition Label declared on the App Store reflects the following:

  • Data Linked to You: Contact Info (name, email, phone), User Content (rรฉsumรฉ, photo), Identifiers (User ID), Usage Data, Diagnostics;
  • Data Not Linked to You: aggregated analytics;
  • Data Used to Track You: none โ€” Tiaano Smart does not track users across apps or websites owned by other companies.

We do not use the App Tracking Transparency (ATT) framework because we do not engage in cross-app or cross-website tracking. Push notifications, if any, are opt-in. We honour Apple's App Store Review Guidelines, including Section 5.1 (Privacy).

16.Facebook Platform (Meta) Facebook

When you interact with our Facebook Page, Messenger, Instagram or any Tiaano Smart application that uses Facebook Login or the Graph API, the following applies:

  • We receive only the information you have authorised on the Facebook permission screen (typically: public profile, name, email).
  • We use this information solely to create your account on our service, pre-fill your contact details, or respond to your message.
  • We do not share Facebook-derived data with third parties beyond what is necessary to operate our service.
  • We comply with Facebook's Platform Terms and the Developer Policies.
  • You may revoke our access to your Facebook account at any time via Facebook Settings โ†’ Apps and Websites.
  • To request deletion of your Facebook-sourced data on our servers, please email privacy@tiaanosmart.in referencing your Facebook user ID.

17.WhatsApp Business

We use the official WhatsApp Business Platform (provided by Meta Platforms Ireland Limited) for customer support, order updates, admission communications, and OTP delivery. By messaging us on WhatsApp, you acknowledge:

  • Your messages are end-to-end encrypted between you and us;
  • Meta processes message metadata in accordance with its own WhatsApp Business Policy and WhatsApp Privacy Policy;
  • We send transactional and utility messages only after you have opted in (for example, by initiating a conversation, ticking a consent box, or by saving our number with a clear "I want to receive updates" indication);
  • We send marketing or promotional messages only after a separate, explicit opt-in;
  • You may opt out at any time by replying STOP to any message, or by writing to privacy@tiaanosmart.in;
  • We do not use WhatsApp for unsolicited bulk marketing.

Our use of WhatsApp Business complies with the WhatsApp Business Messaging Policy and the Commerce Policy. We do not share your WhatsApp number with third-party marketers.

18.Updates to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we do, we will revise the "Last Updated" date at the top of this page. For material changes, we will provide a more prominent notice (including, for certain services, an in-app notification or email).

19.Contact & Grievance Officer

If you have any questions about this Policy, wish to exercise your rights, or wish to file a complaint, please contact us at:

Data Protection Officer / Grievance Officer
Ti Anode Fab Pvt. Ltd. (Tiaano Smart)
Madambakkam, Chennai โ€“ 600126
Tamil Nadu, India

Email: privacy@tiaanosmart.in
Phone: +91 44 2278 1234
Web: tiaanosmart.in

Statutory escalation If you are not satisfied with our response within 30 days, you may approach the Data Protection Board of India established under the DPDP Act, 2023, for redressal.

ยฉ Ti Anode Fab Pvt. Ltd. โ€” All rights reserved.
This document is provided for legal-disclosure purposes and is reproduced verbatim across the Google Play Store, Apple App Store, Facebook for Developers, and WhatsApp Business Platform listings of Tiaano Smart.