Skip to main content

Belding

Privacy Policy

BELDING INDIA LIMITED

Formerly known as Synthiko Foils Limited

WEBSITE PRIVACY POLICY

Governing the Collection, Use, and Protection of Personal Data

Version: 1.0

Effective Date: June 2026

 

 

Belding India Limited  |  Registered Office: 9th Floor, VB Capitol, Range Hills Road, Pune – 411007 Maharashtra, India  |  CIN: L63119PN1984PLC248366

 

IMPORTANT NOTICE: This Privacy Policy is a legally binding document. Please read it carefully before using the Belding India Limited website. By accessing or continuing to use this website, you confirm that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of this website immediately.

 

1.  Preliminary

 

1.1  About This Policy

This Website Privacy Policy (“Policy”) is published by Belding India Limited (“Belding”, “Company”, “we”, “us”, or “our”), a company incorporated under the Companies Act, 1956 and continuing under the Companies Act, 2013, having its registered office in the State of Maharashtra within the jurisdiction of the Registrar of Companies, Pune, India.

This Policy sets out the manner in which Belding collects, receives, possesses, stores, deals with, handles, uses, processes, discloses, and otherwise manages personal data of individuals who visit our website (“Website”), communicate with us, engage with our digital platforms, or interact with us in any capacity in relation to our business activities.

This Policy is published in compliance with, and is intended to give effect to the requirements of, the following applicable laws and regulations:

  • The Information Technology Act, 2000 (as amended) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
  • The Digital Personal Data Protection Act, 2023 (“DPDPA”) and the rules made thereunder, to the extent in force and applicable;
  • Any other applicable Indian law, regulation, or regulatory guidance relating to data protection and privacy as may be amended or enacted from time to time.

 

1.2  Scope of This Policy

This Policy applies to:

  • All individuals who access or browse the Website, whether or not they register or submit any information;
  • Individuals who submit enquiry forms, contact requests, job applications, or any other data through the Website;
  • Business contacts, clients, vendors, consultants, investors, and other stakeholders whose personal data is collected in connection with the Company’s business activities or through the Website;
  • Any individual whose personal data is otherwise processed by the Company in connection with the Website or the Company’s digital presence.

 

This Policy does not apply to:

  • Personal data processed by Belding in the context of employment or HR processes (which is governed by internal HR policies);
  • Personal data processed by third-party websites, applications, or platforms linked to from the Website, which are governed by those parties’ respective privacy policies;
  • Business-to-business data or information relating to legal persons (other than to the extent it constitutes personal data of individuals).

 

1.3  Data Controller Identity

For the purposes of applicable data protection legislation, Belding India Limited is the Data Fiduciary (as defined under the DPDPA) or data controller with respect to personal data collected through the Website. Details of the Company are as follows:

 

Company Name:  Belding India Limited (formerly Synthiko Foils Limited)

CIN:  L63119PN1984PLC248366

Registered Office:  [Registered Office Address], Maharashtra, India

Nature:  Indian Non-Government Company Limited by Shares

Governing Statute:  Companies Act, 2013

Principal Sectors:  Engineering, EPC, Data Centres, Renewable Energy, Battery Energy Storage Systems (BESS), Electronics, Automation, Manufacturing, and Defence

 

2.  Definitions

In this Policy, unless the context otherwise requires, the following expressions shall have the meanings assigned to them below:

 

“Applicable Law”  means all applicable Indian statutes, regulations, rules, notifications, guidelines, circulars, and orders as may be in force from time to time, including but not limited to the IT Act, the SPDI Rules, and the DPDPA.

“Belding Group”  means Belding India Limited and all entities that are subsidiaries, associates, or affiliates of Belding India Limited, including DC&T Global Private Limited, DC&T Defence Limited, BESS Limited, and Metafin Technology Private Limited, and any other entity that may be added to the Group from time to time.

“Cookies”  means small text files that are stored on a User’s device by a website, which may be used to retain information across sessions or track usage behaviour.

“Data Principal”  means the individual to whom personal data relates, as defined under the DPDPA; equivalent to a ‘data subject’ under other data protection regimes.

“DPDPA”  means the Digital Personal Data Protection Act, 2023, enacted by the Parliament of India, and the rules, notifications, and regulations made thereunder, to the extent in force.

“Grievance Officer”  means the officer designated by Belding to address grievances relating to the processing of personal data, as specified in Section 14 of this Policy.

“IT Act”  means the Information Technology Act, 2000 (Act No. 21 of 2000), as amended from time to time.

“Personal Data”  means any data about an individual who is identifiable by or in relation to such data, including Sensitive Personal Data.

“Processing”  means any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.

“Sensitive Personal Data”  means personal data that reveals passwords, financial information such as bank accounts and credit/debit card details, physical, physiological, and mental health condition, sexual orientation, medical records and history, biometric information, and any other data notified as sensitive under Applicable Law.

“SPDI Rules”  means the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, notified under the IT Act.

“Third Party”  means any person, entity, or organisation other than Belding and the User.

“User”  means any individual who accesses, browses, or interacts with the Website or who provides Personal Data to the Company through any channel.

“Website”  means the official website of Belding India Limited and any sub-domains, micro-sites, or associated digital properties operated by the Company.

 

3.  The Belding Group and Its Business Activities

An understanding of the Company’s business context is relevant to understanding the nature and purposes of Personal Data processing under this Policy. Belding India Limited operates as a holding and operating company across a diversified group of entities engaged in engineering, industrial manufacturing, energy infrastructure, data centre construction, and technology.

 

3.1  Belding India Limited (Parent Entity)

Belding India Limited (formerly Synthiko Foils Limited) is the parent entity of the Group. Its objects include:

  • Design, research and development, engineering, manufacturing, fabrication, assembly, and procurement of mechanical, electrical, electronic, and industrial equipment, components, systems, enclosures, and cabinets.
  • EPC activities for data centres and related infrastructure, power generation and transmission systems, renewable energy projects, battery energy storage systems, energy management systems, and integrated energy solutions.
  • Manufacture, assembly, and supply of energy storage solutions, batteries, battery packs, automation products, semiconductors, digital chips, and data centre infrastructure components.

 

3.2  DC&T Global Private Limited (Subsidiary)

DC&T Global Private Limited is engaged in:

  • Engineering, procurement, and construction of data centres and related infrastructure, including server storage, cooling, cybersecurity, and power distribution systems.
  • Establishing and operating renewable energy power generation plants and transmission systems.
  • Manufacture and trade of digital chips, semiconductors (including Outsourced Semiconductor Assembly and Test), and electronic products.
  • Development and deployment of Battery Energy Storage Systems (BESS) and energy management platforms.

 

3.3  DC&T Defence Limited (Subsidiary)

DC&T Defence Limited operates in:

  • Research, development, engineering, manufacturing, and supply of products, systems, and solutions in the fields of energy, power, renewable energy, data centres, communication, data storage, cloud and digital infrastructure, and energy storage.
  • End-to-end infrastructure and system integration solutions, including EPC, BOT/BOOT, managed services, and lifecycle support for defence, government, public sector, industrial, and commercial customers.

 

3.4  BESS Limited (Subsidiary)

BESS Limited is focused on:

  • Developing, designing, engineering, manufacturing, integrating, installing, operating, and maintaining Battery Energy Storage Systems (BESS), renewable energy systems, and hybrid energy solutions, including solar photovoltaic (PV) systems.
  • Developing and deploying energy management systems (EMS) and related software for real-time monitoring, energy optimisation, peak load management, and renewable energy time-shifting.
  • EPC services and operations and maintenance (O&M) services for integrated energy installations, targeting industrial estates, commercial facilities, data centres, and smart cities.

 

3.5  Metafin Technology Private Limited (Subsidiary)

Metafin Technology Private Limited is engaged in:

  • Design, research and development, manufacture, fabrication, and assembly of mechanical, electronic, and electrical industrial goods, equipment, components, enclosures, and cabinets.
  • Delivering customised solutions for telecom, IT data centres, food and beverage, oil and gas, power, pharmaceutical, automotive, and agricultural sectors.
  • Design and manufacture of special purpose machinery, original equipment, robotic automation, industrial automation, and process automation including PLC, VFD panels, and LT power panels.

 

The breadth of the Belding Group’s activities means that Personal Data collected through the Website may be used in connection with business enquiries, project development, partnerships, or recruitment across any of these business verticals.

 

4.  Personal Data We Collect

The categories of Personal Data that we collect and process through the Website or in connection with our business activities include the following:

 

4.1  Data Provided Directly by Users

When you interact with the Website or contact us, you may provide us with the following categories of Personal Data:

 

(a)  Contact and Identification Data

  • Full name, salutation, and designation
  • Work email address and personal email address (where provided)
  • Telephone and mobile number
  • Postal address, city, state, country, and PIN code
  • Name and nature of employer organisation

 

(b)  Business and Enquiry Data

  • Nature of business enquiry or project requirement
  • Industry sector and type of organisation
  • Details of proposed collaboration, contract, or partnership
  • Technical specifications or project parameters submitted through enquiry forms
  • Commercial preferences and budget parameters (where disclosed)

 

(c)  Recruitment and Career Data

  • Curriculum vitae, resume, and cover letter
  • Educational qualifications and professional certifications
  • Employment history and professional experience
  • Skills, competencies, and professional achievements
  • References and referee contact details
  • Notice period and compensation expectations
  • Proof of identity and address documents (where required for verification)

 

(d)  Communication and Correspondence Data

  • Content of emails, messages, and other communications sent to or received from the Company
  • Records of calls and meetings where notes or records are maintained
  • Feedback, complaints, or grievances submitted through the Website

 

(e)  Event and Stakeholder Data

  • Registration details for webinars, conferences, or events hosted or co-hosted by the Company
  • Investor and shareholder identification and contact details (as required under company law)
  • Media and press contact details

 

4.2  Data Collected Automatically

When you visit the Website, certain technical data is automatically collected by our systems or by third-party tools integrated into the Website:

 

(a)  Device and Network Data

  • Internet Protocol (IP) address and approximate geographic location derived therefrom
  • Device type (desktop, mobile, tablet), device model, and device identifier
  • Operating system and version
  • Browser type, version, and language settings

 

(b)  Usage and Interaction Data

  • Pages visited on the Website and sequence of navigation
  • Duration of visit and time spent on each page
  • Referring URL (the page from which you arrived at the Website)
  • Links clicked and content interacted with
  • Search queries entered on the Website (if applicable)
  • Session start and end times and access timestamps

 

(c)  Cookie and Tracking Data

  • Session identifiers and persistent cookie data
  • Analytics data collected through tools such as Google Analytics or equivalent platforms
  • Preferences and settings data stored in browser cookies

Please refer to Section 10 of this Policy for a detailed explanation of our use of cookies and tracking technologies.

 

4.3  Data Received from Third Parties

In certain circumstances, we may receive Personal Data about individuals from sources other than directly from the individual concerned:

  • Business directories, public databases, company registrations, and professional networking platforms (such as LinkedIn) in connection with business development, client onboarding, or due diligence activities.
  • Background verification and reference-checking service providers engaged in connection with recruitment processes.
  • Government and regulatory databases (including MCA21, GSTIN databases, and similar) for KYC/KYB compliance purposes.
  • Partners, clients, or vendors who provide contact details of individuals within their organisations for the purposes of a specific project or engagement.
  • Publicly available sources, including news archives, regulatory filings, and government records, to the extent relevant to business activities.

 

We will only collect and process Personal Data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.

 

5.  Purposes and Legal Basis for Processing

We process Personal Data only for lawful, specified, and legitimate purposes. The following table sets out the principal purposes for which we process Personal Data and the legal basis for such processing:

 

5.1  Business Development and Client Services

We process Personal Data for the following purposes in connection with our business operations:

  • To respond to and follow up on enquiries about the Company’s services and capabilities, including in the areas of EPC contracting, data centre infrastructure, renewable energy, BESS, engineering, and manufacturing solutions.
  • To evaluate and pursue potential business relationships, collaborations, joint ventures, licensing arrangements, or technology partnerships.
  • To prepare, negotiate, and execute proposals, term sheets, quotations, and commercial agreements.
  • To manage ongoing client relationships and deliver contractual services, including project management and technical support.
  • To carry out due diligence on prospective clients, vendors, and business partners as part of the Company’s onboarding and risk management processes.

 

5.2  Legal and Regulatory Compliance

We process Personal Data to comply with our legal obligations under Applicable Law:

  • Companies Act, 2013: maintenance of statutory registers, records of shareholders, directors, and officers; compliance with MCA filings and disclosure requirements.
  • Income Tax Act, 1961 and GST legislation: maintenance of tax records and supporting documentation.
  • Foreign Exchange Management Act (FEMA), 1999 and RBI regulations: compliance with foreign investment regulations and cross-border payment rules.
  • Prevention of Money Laundering Act (PMLA), 2002: Know Your Customer (KYC) and Know Your Business (KYB) obligations.
  • Sebi Regulations (as applicable): investor relations and disclosure obligations if and when applicable.
  • Labour laws and employee protection legislation: compliance with applicable employment statutes.
  • Any court order, regulatory direction, or lawful demand from a competent authority.

 

5.3  Recruitment and Human Resources

We process recruitment-related Personal Data for the following purposes:

  • To receive, evaluate, and respond to job applications submitted through the Website or by other means.
  • To conduct competency assessment, skills evaluation, and candidate screening.
  • To carry out background verification, reference checks, and qualification verification (with the candidate’s consent where required).
  • To schedule and manage interviews and assessments.
  • To communicate offers of employment and manage pre-joining formalities.
  • To maintain talent pipeline records for future vacancies (where the candidate has consented to such retention).

 

5.4  Corporate Communications and Marketing

We process Personal Data for the following communication and marketing purposes, subject to applicable consent requirements:

  • To provide stakeholder communications, project updates, and corporate news to clients, investors, media, and other stakeholders.
  • To invite relevant contacts to industry events, conferences, exhibitions, or product demonstrations.
  • To send periodic newsletters, company announcements, and capability updates (subject to your right to opt out).
  • To manage media and investor relations, including responding to press inquiries.

 

5.5  Website Administration and Security

We process technical and usage data for the following operational purposes:

  • To operate, maintain, and improve the Website and its features and functionality.
  • To monitor Website performance, identify technical errors, and conduct diagnostic analyses.
  • To detect, prevent, and respond to security threats, cyberattacks, fraud, and unauthorised access.
  • To conduct website analytics and understand user behaviour for the purpose of improving user experience.
  • To administer our IT systems and ensure business continuity.

 

6.  Disclosure and Sharing of Personal Data

Belding India Limited does not sell, rent, or trade Personal Data to any Third Party for commercial or marketing purposes. Personal Data is shared only in the circumstances described in this Section.

 

6.1  Within the Belding Group

We may share Personal Data with other entities within the Belding Group, including DC&T Global Private Limited, DC&T Defence Limited, BESS Limited, and Metafin Technology Private Limited, where such sharing is necessary for:

  • Managing integrated Group-level business relationships, contracts, or projects;
  • Consolidated reporting, governance, and risk management;
  • Group-level HR and recruitment functions;
  • IT systems and infrastructure services shared across the Group.

All intra-Group sharing is governed by internal data handling policies that impose equivalent levels of protection to those set out in this Policy.

 

6.2  Third-Party Service Providers

We engage third-party service providers and data processors who process Personal Data on our behalf and under our instructions. These include:

  • Information technology and cloud infrastructure providers (hosting, storage, email, collaboration tools);
  • Cybersecurity and data protection service providers;
  • Professional advisors including legal counsel, auditors, tax advisors, and financial consultants;
  • Background verification and screening agencies engaged in connection with recruitment;
  • Website analytics providers (including providers of tools such as Google Analytics or equivalent);
  • Event management, marketing communications, and printing service providers;
  • Payment processors (where applicable).

All third-party processors are engaged under written contracts that require them to process Personal Data only in accordance with our instructions and to implement appropriate technical and organisational security measures. We conduct reasonable due diligence on our processors and do not engage processors who cannot provide adequate data protection guarantees.

 

6.3  Business Transactions and Corporate Restructuring

In connection with any merger, acquisition, demerger, sale of a business or assets, amalgamation, restructuring, fundraising, or similar corporate transaction involving Belding or any entity within the Belding Group, Personal Data may be disclosed to prospective acquirers, investors, or their advisors as part of due diligence processes. Any such disclosure will be made subject to appropriate confidentiality obligations, and where practicable, data will be anonymised or aggregated prior to disclosure.

 

6.4  Legal and Regulatory Authorities

We may disclose Personal Data to:

  • Courts, tribunals, regulatory bodies, or law enforcement agencies in response to a lawful court order, summons, legal process, or regulatory direction;
  • The Ministry of Corporate Affairs (MCA), Securities and Exchange Board of India (SEBI), Reserve Bank of India (RBI), Income Tax Department, Enforcement Directorate, or any other competent authority as required under Applicable Law;
  • Any authority exercising supervisory, audit, or investigative powers to the extent required by Applicable Law.

Where lawfully permissible, we will attempt to notify you of such a disclosure requirement before complying, unless prohibited by Applicable Law or court order.

 

6.5  Protection of Rights and Prevention of Harm

We may disclose Personal Data where we believe in good faith that such disclosure is reasonably necessary to:

  • Protect and enforce the legal rights and remedies of the Company, its directors, employees, clients, or other Users;
  • Investigate, prevent, or take action against alleged fraud, unauthorised access, illegal activity, or serious misconduct;
  • Protect the safety or security of any person;
  • Defend the Company against any legal claim or proceeding.

 

7.  Cross-Border Transfers of Personal Data

Belding is an Indian company and processes most Personal Data within India. However, given the Group’s operations, use of cloud-based technology platforms, and engagement with international clients, partners, and service providers, Personal Data may be transferred to, stored in, or accessed from jurisdictions outside the territory of India.

 

Transfers of Personal Data outside India are carried out in compliance with:

  • The requirements of the DPDPA and the rules made thereunder, to the extent in force, including any restrictions on cross-border data transfers to notified countries;
  • The SPDI Rules, where applicable;
  • Any contractual safeguards required to ensure that the recipient provides a level of data protection equivalent to that applicable in India.

 

Where we engage cloud service providers or other processors whose infrastructure is located outside India, we ensure appropriate contractual protections are in place, including standard contractual clauses or equivalent mechanisms, as may be required under Applicable Law.

 

8.  Data Retention

We retain Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by Applicable Law. Our retention periods are determined with reference to the following considerations:

 

  • The purpose for which the Personal Data was collected and whether that purpose has been fulfilled or remains relevant;
  • Legal and regulatory retention obligations under Applicable Law (for example, the Companies Act, 2013 requires certain records to be maintained for a minimum of 8 years; the Income Tax Act, 1961 requires financial records to be maintained for the relevant assessment period; the PMLA requires KYC records to be maintained for 5 years following the end of a business relationship);
  • The nature and sensitivity of the Personal Data and the potential risk of harm from unauthorised use or disclosure;
  • The applicable limitation periods for legal claims and the need to retain evidence in connection with potential disputes;
  • Guidance from the Data Protection Board of India (once constituted) or other competent authorities on retention practices.

 

The following indicative retention periods apply to key categories of Personal Data:

 

Category of Data

Indicative Period

Legal / Operational Basis

Business enquiry and contact data

3 years from last interaction

Legitimate business interest; potential contract claims

Contract and agreement data

8 years from expiry of contract

Companies Act, 2013; limitation period for commercial disputes

Financial and transactional records

8 years from relevant financial year

Income Tax Act; GST legislation; Companies Act

KYC and AML records

5 years post-relationship

Prevention of Money Laundering Act, 2002 (PMLA)

Recruitment data (unsuccessful candidates)

1 year from rejection

Talent pipeline management (with consent); legal claims

Recruitment data (successful candidates)

Duration of employment + 8 years

Labour laws; Companies Act; limitation periods

Website usage and analytics data

Up to 26 months

Standard analytics retention; improvement of services

Cookie data

Session cookies: end of session; Persistent: as stated in cookie table (Section 10)

Functionality; analytics; user preference

Investor and shareholder data

Indefinitely or as required by MCA

Companies Act, 2013; SEBI regulations (as applicable)

Legal correspondence and dispute records

10 years from final resolution

Limitation Act, 1963; evidence retention

 

Upon expiry of applicable retention periods, Personal Data will be securely deleted, destroyed, or anonymised using industry-standard methods. Where deletion is not immediately technically feasible (for example, in backup systems), the data will be isolated from further active processing until permanent deletion can be carried out.

 

9.  Data Security

Belding implements a comprehensive framework of technical, administrative, and organisational measures to protect Personal Data against unauthorised access, acquisition, use, disclosure, alteration, loss, or destruction. Our security framework is informed by applicable Indian laws (including the SPDI Rules) and recognised international information security standards.

 

9.1  Technical Measures

  • Encryption of Personal Data in transit using industry-standard protocols (TLS/SSL);
  • Encryption of Sensitive Personal Data at rest using appropriate encryption standards;
  • Firewalls, intrusion detection and prevention systems, and network monitoring;
  • Multi-factor authentication for access to systems and applications containing Personal Data;
  • Regular vulnerability assessments, penetration testing, and security audits;
  • Secure coding practices and application security reviews for digital platforms;
  • Data backup and disaster recovery systems to ensure availability and resilience.

 

9.2  Administrative and Organisational Measures

  • A formal Information Security Policy and associated procedures governing the handling of Personal Data;
  • Role-based access controls ensuring that Personal Data is accessible only to authorised personnel with a legitimate need-to-know;
  • Regular employee training and awareness programmes on data protection, information security, and phishing prevention;
  • Confidentiality obligations imposed on all employees and contractors with access to Personal Data;
  • Data processor agreements with all third-party service providers who process Personal Data on our behalf;
  • A Data Breach Incident Response Plan, including procedures for detection, containment, assessment, notification, and remediation of security incidents;
  • Periodic review and update of security measures in response to evolving threats.

 

9.3  Limitation of Liability

While Belding employs commercially reasonable and legally compliant security measures, no information system or method of electronic transmission can be guaranteed to be completely secure. Users are advised that the transmission of Personal Data over the internet is at the User’s own risk. In the event of a security breach, we will comply with our notification obligations under Applicable Law, including to the Data Protection Board of India (once constituted) and, where required, to affected Data Principals.

 

10.  Cookies and Tracking Technologies

10.1  What Are Cookies

Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit a website. They are widely used to enable websites to function correctly, to remember user preferences, and to provide information to website operators about how their sites are used. In addition to cookies, we may use other tracking technologies such as web beacons, pixel tags, and local storage objects.

 

10.2  Categories of Cookies We Use

 

(a)  Strictly Necessary Cookies

These cookies are essential to enable the Website to function and to provide services requested by Users. They cannot be disabled. They include cookies that support navigation, session management, and security. No personally identifiable information is stored in strictly necessary cookies.

 

(b)  Functional Cookies

These cookies allow the Website to remember choices made by Users (such as language preferences) and to provide enhanced, personalised features. They may be set by us or by third-party providers whose services are integrated into the Website.

 

(c)  Performance and Analytics Cookies

These cookies collect information about how Users interact with the Website, including which pages are visited most frequently, whether error messages are received, and how users navigate through the site. The data collected is aggregated and anonymised and is used to improve the performance and content of the Website. We may use tools such as Google Analytics or equivalent platforms for this purpose. You may opt out of analytics tracking by following the instructions provided by the relevant tool provider.

 

(d)  Marketing and Targeting Cookies

Where applicable, these cookies may be used to deliver advertisements and content that are relevant to User interests and to track the effectiveness of marketing campaigns. They may be set by us or by trusted advertising partners. We will seek your consent before deploying marketing cookies where required by Applicable Law.

 

10.3  Cookie Retention Periods

Session cookies are temporary and are deleted when you close your browser. Persistent cookies remain on your device for a defined period as set out in the cookie settings of the Website. The specific retention period for each cookie category is disclosed in our Cookie Notice, which is accessible through the cookie consent banner on the Website.

 

10.4  Managing Your Cookie Preferences

You may manage your cookie preferences at any time through:

  • The cookie consent management tool available on the Website;
  • Your browser settings, which typically allow you to view, block, and delete cookies (note that blocking certain cookies may affect the functionality of the Website);
  • Third-party opt-out mechanisms (e.g., Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout).

 

11.  Rights of Data Principals

Subject to the provisions of the DPDPA, the IT Act, and other Applicable Law, Data Principals (i.e., individuals whose Personal Data we process) have the following rights in relation to their Personal Data:

 

11.1  Right of Access and Confirmation

You have the right to obtain confirmation from us as to whether we are processing your Personal Data, and if so, to receive a summary of the Personal Data being processed and the processing activities being carried out in relation to your data. Where permissible, you may request a copy of the Personal Data we hold about you.

 

11.2  Right to Correction and Completeness

You have the right to request that we correct any inaccuracy in your Personal Data or complete any Personal Data that is incomplete. We will carry out corrections promptly where they are reasonably verifiable. Where we have shared the relevant data with Third Parties, we will notify them of the correction to the extent practicable.

 

11.3  Right to Erasure

You have the right to request the erasure of your Personal Data where:

  • The Personal Data is no longer necessary for the purposes for which it was collected;
  • You withdraw your consent (where consent was the basis for processing) and there is no other legal basis for processing;
  • The Personal Data has been unlawfully processed.

Please note that the right to erasure is not absolute. We may be required to retain certain Personal Data under Applicable Law (for example, statutory records under the Companies Act) or for the establishment, exercise, or defence of legal claims.

 

11.4  Right to Withdraw Consent

Where we process your Personal Data on the basis of your consent, you have the right to withdraw that consent at any time by contacting our Grievance Officer using the details in Section 14. Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal, nor will it affect the processing of Personal Data carried out under a legal basis other than consent.

 

11.5  Right to Grievance Redressal

You have the right to raise a grievance with our Grievance Officer regarding any act or omission by Belding in respect of its obligations under this Policy or Applicable Law. Grievances will be addressed within the timeframe specified in Section 14.

 

11.6  Right to Nominate

Under the DPDPA, you have the right to nominate another individual who shall, in the event of your death or incapacity, exercise your rights as a Data Principal on your behalf. Details on how to register a nominee may be obtained from our Grievance Officer.

 

11.7  How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to our Grievance Officer using the contact details provided in Section 14. Your request should:

  • Clearly identify the nature of your request and the right you wish to exercise;
  • Include sufficient information to enable us to verify your identity (we will not process requests where we cannot verify the identity of the requestor, in order to protect the rights of third parties);
  • Specify the Personal Data to which the request relates, to the extent known.

We will acknowledge receipt of your request within a reasonable time and will respond substantively within the timeframe required by Applicable Law. In complex cases, we may extend the response period, in which case we will notify you of the extension and the reason therefor.

 

We will not charge a fee for legitimate requests to exercise Data Principal rights. However, where requests are manifestly unfounded, repetitive, or excessive, we reserve the right to charge a reasonable fee or to decline to act on the request, in accordance with Applicable Law.

 

12.  Children’s Personal Data

The Website is not directed at, and is not intended for use by, children below the age of 18 years. Belding does not knowingly collect, process, or store Personal Data of minors without verifiable parental or guardian consent, as may be required under the DPDPA.

If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take immediate steps to delete such data from our records. If you believe that we may have collected Personal Data from a child, we request you to notify our Grievance Officer immediately using the contact details in Section 14.

Parents and legal guardians who discover that their child has provided Personal Data to the Company without their consent are encouraged to contact us so that we can take the necessary corrective action.

 

13.  Third-Party Websites and Linked Platforms

The Website may contain hyperlinks to third-party websites, social media platforms (including LinkedIn, Twitter/X, YouTube, and similar), industry portals, and other external digital resources. These links are provided solely for informational convenience and do not constitute an endorsement, recommendation, or approval by Belding of the linked website or the information contained therein.

Belding has no control over, and accepts no responsibility for, the content, privacy policies, data practices, or security measures of any third-party website or platform. Once you navigate away from the Website by following a third-party link, this Policy ceases to apply to your interactions on the linked website. We strongly encourage you to review the privacy policy and terms of use of any third-party website before submitting any Personal Data.

The presence of a hyperlink to a third-party website on the Website does not imply that we have reviewed or approved the privacy or security practices of such third parties.

 

14.  Grievance Officer and Contact Details

In accordance with the IT Act, the SPDI Rules, and the DPDPA, Belding has designated a Grievance Officer to address queries, concerns, and grievances relating to the processing of Personal Data under this Policy.

 

14.1  Contact Details of the Grievance Officer

Name:  Ms. Muskan Pinjani

Designation:  Company Secretary

Department:  Compliance

Organisation:  Belding India Limited

Registered Address:  9th floor, VB Capitol, Range Hills Road, Bhosale Nagar – 411007

Email:  compliance@beldingindia.in

Working Hours:  Monday to Friday, 10:00 AM to 6:00 PM IST (excluding public holidays)

 

14.2  Grievance Redressal Timeframe

Grievances relating to the processing of Personal Data or any alleged violation of this Policy will be acknowledged within 48 hours of receipt and addressed within 30 days of acknowledgement, or such shorter period as may be required under Applicable Law. We may request additional information from the complainant if necessary for the resolution of the grievance.

If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India (once established and operational under the DPDPA), whose jurisdiction, process, and contact details will be notified by the Government of India in due course.

 

15.  Amendments to This Policy

Belding reserves the right to amend, update, revise, or replace this Policy at any time to reflect changes in our data processing practices, the Company’s business activities, Applicable Law, or regulatory guidance. All amendments will be effective from the date of publication on the Website.

Where we make material changes to this Policy that significantly affect the rights of Data Principals or the manner in which we process Personal Data, we will take reasonable steps to notify affected individuals, which may include a prominent notice on the Website or direct communication where we hold contact details.

The “Last Reviewed” and “Version” information appearing on the cover page of this Policy will be updated each time an amendment is made. We encourage Users to review this Policy periodically to remain informed about how we protect Personal Data.

Your continued use of the Website following any amendment constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you should discontinue use of the Website.

 

16.  Governing Law and Jurisdiction

This Policy is governed by and shall be construed in accordance with the laws of the Republic of India. Any dispute, controversy, or claim arising out of or in connection with this Policy, including its validity, interpretation, breach, or enforcement, shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction at Pune, Maharashtra, India.

Nothing in this clause shall limit the rights of any Data Principal to submit a complaint to the Data Protection Board of India or any other competent regulatory authority under Applicable Law.

 

17.  Miscellaneous

17.1  Language

This Policy has been drafted in the English language. In the event of any conflict or inconsistency between this Policy and any translation thereof, the English language version shall prevail.

 

17.2  Severability

If any provision of this Policy is found by a court of competent jurisdiction to be invalid, illegal, or unenforceable, such provision shall be deemed severed from the Policy and the remaining provisions shall continue in full force and effect.

 

17.3  No Waiver

The failure of Belding to enforce any provision of this Policy shall not constitute a waiver of that provision or any other provision of this Policy.

 

BELDING INDIA LIMITED

Formerly known as Synthiko Foils Limited  |  Registered in Maharashtra, India  |  CIN: L63119PN1984PLC248366 | Website Privacy Policy  |  Version 1.0  |  June 2026