Privacy Policy
Website: https://nolta.in Effective date: 17 Aug 2026 Last updated: 17 Aug 2026
Version: 1.0
1. Introduction
This Privacy Policy explains how Kottaram Trading Company (trading as Nolta), a company incorporated under the Companies Act, 2013, having its office at Kottaram Tower, Payyapilly Road, Near MG Road, Kacheripady, Kochi, Ernakulam, Kerala 682035, India (“Nolta“, “we“, “us“, “our“) collects, uses, shares, stores and protects your personal data when you visit https://nolta.in (the “Website“), submit an enquiry to us, or otherwise interact with us in connection with our cookware, glassware, crockery, opalware and homeware products.
We are the Data Fiduciary in respect of the personal data described in this Policy, and you are the Data Principal. This Policy is published in accordance with:
- the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules“);
- the Digital Personal Data Protection Act, 2023 (“DPDP Act“) and the Digital Personal Data Protection Rules, 2025, as and to the extent they are brought into force in a phased manner; and
- other applicable Indian laws.
By using the Website or submitting information to us, you acknowledge that you have read and understood this Policy. Where the law requires your consent, we will ask for it separately and you may withdraw it at any time as described in Section 12.
2. Scope
This Policy applies to the Website and to enquiries, warranty requests and after-sales service communications received by us through the Website, email, telephone or our official social media pages.
This Policy does not apply to:
- websites, marketplaces or retail stores operated by third parties, including authorised dealers, distributors and online marketplaces that sell Nolta products — those parties have their own privacy policies; or
- third-party platforms (such as Facebook, Instagram, Google or WhatsApp) whose own terms and privacy policies govern your use of them.
3. Personal data we collect
3.1 Information you give us directly
| Data | Where it comes from | Why we need it |
|---|---|---|
| Name | Enquiry form, email, phone, social messages | To identify and respond to you |
| Email address | Enquiry form, email | To reply to your enquiry |
| Phone number (if you provide it) | Email, phone, WhatsApp | To respond and, for warranty matters, to arrange service |
| Message or enquiry content | Enquiry form, email | To understand and act on your request |
| “How did you hear about us” selection | Enquiry form | To understand how customers find us |
| Product, purchase and warranty details (model, date and place of purchase, invoice or proof of purchase, service address) | Warranty and after-sales requests | To verify and process warranty and service claims |
| Dealership or business enquiry details (firm name, place of business, GSTIN, contact person) | Business enquiries | To evaluate and respond to distribution enquiries |
Please do not send us payment card numbers, bank account details, passwords, government identifiers or health information through the Website or by email. We do not ask for such information and do not require it to answer an enquiry.
3.2 Information collected automatically
When you visit the Website, our servers and analytics tools may automatically record:
- your IP address and approximate location derived from it (typically city or region level);
- your browser type and user-agent string, operating system, device type and screen or viewport size;
- the pages you view, the date and time of your visit, time spent on pages, and the referring URL or search terms that brought you to us;
- interactions such as clicks, scroll depth and form submissions; and
- error and security logs, including records of failed login attempts and suspected malicious activity.
3.3 Information from third parties
If you interact with our pages or advertisements on third-party platforms, those platforms may provide us with aggregated or pseudonymised reports (for example, campaign reach and engagement statistics). We may also receive your details from an authorised dealer or service partner where you have asked them to escalate a matter to us.
3.4 Data we do not collect
We do not knowingly collect biometric data, financial account data, or the categories of “sensitive personal data or information” under the SPDI Rules through the Website. We do not use the Website to profile individuals for automated decision-making that produces legal effects.
4. Children’s data
The Website is intended for adults and is not directed at children. We do not knowingly collect the personal data of any person below eighteen (18) years of age without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, please write to our Grievance Officer (Section 13) and we will delete it.
5. Purposes for which we use your personal data
We use personal data only for the purposes for which it was provided, or for compatible purposes permitted by law:
- Responding to you — answering enquiries, product questions, complaints and feedback.
- Warranty and after-sales service — verifying eligibility, arranging inspection, repair or replacement, and maintaining service records.
- Product and dealer information — sending you the information, catalogues, price lists or dealer references you asked for.
- Marketing communications — sending offers, launches and newsletters, only where you have opted in, and always with an unsubscribe option.
- Website operation and improvement — measuring traffic and performance, fixing errors, and improving content and navigation.
- Security and fraud prevention — protecting the Website against spam, misuse, unauthorised access and attacks, and detecting counterfeit or misuse of our trademarks.
- Legal and regulatory compliance — meeting obligations under tax, consumer protection, product safety and other applicable laws, and responding to lawful requests from authorities.
- Establishing and defending legal claims — where necessary to protect our rights.
Where we rely on your consent, our legal basis is Section 6 of the DPDP Act. Where we process data because you have voluntarily provided it for a specified purpose, or for employment, legal compliance, or the protection of interests recognised under Section 7 of the DPDP Act, we rely on those legitimate uses.
6. Cookies and similar technologies
The Website is built on WordPress and uses cookies and similar technologies. A cookie is a small text file placed on your device.
| Category | Examples and purpose | Typical duration |
|---|---|---|
| Strictly necessary | WordPress session and security cookies; a test cookie set on the login page to check whether your browser accepts cookies; cookies that keep the site functioning and secure | Session to 2 days |
| Preference | Remembering display choices; if you comment, optionally storing your name, email and website so you need not re-enter them | Up to 1 year |
| Administrative | For logged-in site administrators only: login state, screen options, and a cookie recording the post ID of a recently edited article | 1 day to 1 year (up to 2 weeks with “Remember Me”) |
| Analytics | [Google Analytics 4 / other — confirm and name the tools actually installed] to understand aggregate visitor numbers and behaviour | [Up to 14 months] |
| Marketing | [Meta Pixel / Google Ads — include only if actually installed] to measure campaign performance and show relevant advertisements | [Up to 13 months] |
Managing cookies. You can accept, reject or delete cookies through our cookie banner (where displayed) and through your browser settings. Blocking strictly necessary cookies may prevent parts of the Website from working. Withdrawing consent to analytics or marketing cookies does not affect processing already carried out lawfully.
7. Comments and content you submit
If commenting is enabled and you leave a comment on the Website, we collect the data shown in the comment form together with your IP address and browser user-agent string, which help us detect spam. Comments may be screened through an automated spam-detection service. An anonymised string (a hash) created from your email address may be shared with the Gravatar service to check whether you use it; the Gravatar privacy policy is available at https://automattic.com/privacy/. Once your comment is approved, your profile picture is visible to the public alongside your comment.
If you are able to upload images to the Website, please avoid uploading images containing embedded location data (EXIF GPS), because visitors can download such images and extract that data.
8. Embedded content and third-party services
Pages on the Website may include embedded content from other websites — for example, a Google Maps embed on our Contact page, web fonts, and links or feeds from Facebook and Instagram. Embedded content behaves as if you had visited that other website directly: the third party may collect data about you, set cookies, deploy additional tracking, and monitor your interaction with the embedded content, including where you are logged in to that service.
We also rely on service providers who process personal data on our behalf under contract, for example:
- website hosting and content delivery;
- email and enquiry-form handling;
- security, backup and anti-spam services;
- analytics and advertising measurement (where enabled); and
- logistics and authorised service partners, for warranty and delivery matters.
These providers are permitted to use your data only to provide services to us, and are required to keep it confidential and secure.
9. When we share personal data
We do not sell or rent your personal data. We disclose it only:
- to the service providers and service partners described in Section 8;
- to our authorised dealers, distributors or service centres, where this is necessary to answer your enquiry, deliver a product or complete a warranty or service request;
- to our group companies and affiliates, where necessary for the purposes in Section 5 and subject to equivalent protections;
- to professional advisers (legal, audit, insurance) under duties of confidentiality;
- to courts, regulators, law-enforcement or other authorities where disclosure is required or authorised by law, or to establish, exercise or defend legal claims; and
- to an acquirer or successor in the event of a merger, restructuring or transfer of business, subject to this Policy continuing to apply to the transferred data.
If you request a password reset for an account on the Website, your IP address will be included in the reset email.
10. Cross-border transfers
Some of our service providers may store or process data on servers outside India. Where this happens, we transfer personal data only to countries or territories not restricted by the Central Government under Section 16 of the DPDP Act, and we require the recipient to apply protections at least equivalent to those described in this Policy.
11. Retention and erasure
We keep personal data only for as long as it is needed for the purpose for which it was collected, or for as long as required by law:
| Data | Retention |
|---|---|
| Enquiry and contact form submissions | [24] months from last contact, unless a longer period is needed to resolve a matter |
| Warranty and after-sales service records | Warranty period plus [3] years, to support claims and statutory obligations |
| Comments and their metadata (if commenting is enabled) | Retained while the comment remains published, so that follow-up comments can be recognised and approved automatically |
| Registered user profile data (if user registration is enabled) | Until the account is deleted at your request |
| Marketing consents and opt-outs | Retained as long as needed to honour your preference |
| Server, security and access logs | [12] months, or longer where required for security or legal purposes |
| Accounting, tax and statutory records | As required under applicable law (generally 8 years) |
If commenting or user registration is enabled, registered users can see, edit or delete their personal information at any time, except that a username cannot be changed. Website administrators can also see and edit that information. Where erasure is requested, we will delete or irreversibly anonymise the data unless we are obliged to retain it for administrative, legal, security or accounting purposes.
12. Your rights
Subject to applicable law, you have the right to:
- Access — obtain a summary of the personal data we hold about you and how it is processed, and the identities of parties with whom it has been shared;
- Correction and completion — have inaccurate or incomplete data corrected, completed or updated;
- Erasure — have your personal data deleted where it is no longer necessary for the purpose for which it was collected and we are not required to retain it;
- Withdraw consent — withdraw consent at any time, with effect for future processing;
- Opt out of marketing — unsubscribe from marketing messages using the link in any such message or by writing to us;
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity; and
- Grievance redressal — raise a complaint with us and, if unresolved, with the Data Protection Board of India.
How to exercise your rights. Write to our Grievance Officer (Section 13) from the email address or phone number you used to contact us, describing your request. We may ask for information reasonably necessary to verify your identity. We will respond within thirty (30) days, and in any event within the timelines prescribed by law. Complaints will be resolved within ninety (90) days of receipt. There is no charge for exercising your rights, although we may decline manifestly unfounded or repetitive requests.
13. Grievance Officer
For any question, request or complaint about this Policy or your personal data:
Email: customercare@kottaram.in Address: Kottaram Tower, Payyapilly Road, Near MG Road, Kacheripady, Kochi, Ernakulam, Kerala 682035, India Office hours: Monday to Friday, 8:00 a.m. to 5:00 p.m. IST
We will acknowledge your communication within [48] business hours.
14. Security
We maintain reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the SPDI Rules, proportionate to the nature of the data we hold. These include encryption of data in transit (HTTPS/TLS), role-based access controls and least-privilege administration for the Website, strong authentication for administrator accounts, regular updates and patching of the platform, plugins and themes, firewalling and anti-spam controls, periodic backups, and internal confidentiality obligations for personnel and vendors.
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security, and you share information with us at your own discretion. If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India in the manner and within the timelines prescribed by law.
15. Third-party links
The Website may link to third-party websites, dealer sites, marketplaces and social media pages. We do not control those sites and are not responsible for their content, security or privacy practices. Please review their policies before providing them with personal data.
16. Changes to this Policy
We may update this Policy to reflect changes in our practices, technology or the law. The revised version will be posted on this page with a new effective date and version number. Where changes are material, we will provide a prominent notice on the Website and, where required, seek your fresh consent. Please review this page periodically.
17. Contact
Kottaram Trading Company (trading as Nolta) Kottaram Tower, Payyapilly Road, Near MG Road, Kacheripady, Kochi, Ernakulam, Kerala 682035, India Email: customercare@kottaram.in Website: https://nolta.in
This Policy is available in English. Where it is translated, the English version prevails in the event of any inconsistency.