01Who we are and what this covers
"We", "us" and "our" mean TCCT Pvt. Ltd., which operates the Netlio website and account area and is the data fiduciary for the personal data described in this policy under the Digital Personal Data Protection Act 2023.
This policy covers everything you do with us: browsing the Netlio website, opening and using an account, the enquiry, checkout and partner forms, and your calls, WhatsApp messages and emails with the support desk. It applies whether the unit you buy comes from our own stock or from a verified partner seller.
We sell refurbished enterprise IT hardware to businesses and IT professionals, so most of what we hold is business contact and invoicing data. We collect only what is needed to sell, deliver, invoice and support the hardware, and each use is explained below. Read this policy together with our Terms and Conditions and Refund Policy.
Complaints about personal data follow the grievance route in the last section and can be escalated to the Data Protection Board of India; our Terms and Conditions govern everything else.
02Information you give us
You give us personal data when you register, fill in your profile, place an order, save items, or contact the support desk. This is what each part of the site collects:
| Account | Your name, email address and mobile number, your notification preferences, and your password, which is stored only as a hash that cannot be reversed. |
|---|---|
| Business profile | Company name, GSTIN, PAN if you provide it for invoicing, and your billing and shipping addresses. You can save several addresses and edit them in the account area. |
| Orders | The items and serial numbers you buy, quotations, the delivery tier and address for each line, delivery contact details, invoices and credit notes, tracking updates, and any cancellation or return request with its return number. |
| Payments | Only what our payment partner returns to us: payment method, status, transaction reference and a masked card number or UPI handle. Full card numbers and CVVs never reach us. If you choose to save a payment method, we store only the card brand, masked number, holder name and expiry, or your UPI ID. |
| Support and service | Support tickets, contact-form enquiries and the enquiry number issued to each, warranty and AMC records tied to your serial numbers, and notes from your calls, WhatsApp messages and emails with the support desk. |
| Wishlist and cart | Products you add to your wishlist are saved to your account. While you are signed out, your cart is kept in your browser's local storage; when you sign in it is merged into your account cart, which is stored on our servers so it follows you across devices. |
| Seller and partner applications | The business and contact details you submit when applying to the partner programme and, for approved sellers, the listings and articles you publish under your name. |
03Information collected automatically
When you use the site our servers record ordinary request logs: your IP address, browser and device type (the user agent), the time of each request and the pages or endpoints requested. We use these logs to keep the site secure, detect abuse such as repeated sign-in or OTP attempts, and debug faults. They are not used to profile you or to target advertising.
We run no third-party analytics service and place no advertising pixels, tracking scripts or social-media plugins on the site. If that ever changes, we will update this policy first and, where consent is required, ask for it before anything is loaded.
05Why we use it and the legal basis
The Digital Personal Data Protection Act 2023 allows personal data to be processed either with your consent or for certain legitimate uses, such as data you give us for a purpose of your own or data we must keep to meet a legal obligation. Each purpose below names which applies. We do not use your data for anything not listed here without telling you first.
| Taking, fulfilling and delivering your order | Legitimate use — you gave it to us for this purpose. Without this data we cannot supply, ship or insure the unit. |
|---|---|
| Issuing tax invoices, credit notes and GST returns | Legitimate use — a legal obligation (GST and company records). Your business name, GSTIN and the serial numbers supplied appear on the invoice. |
| Account security, fraud prevention and one-time passwords | Legitimate use — you gave it to us to open and use your account, and keeping that account secure is part of the purpose. Where mobile verification is switched on, this includes sending and checking OTPs. |
| Service messages | Legitimate use — you gave it to us for this purpose. Order confirmations, dispatch and delivery updates, return status, ticket replies and warranty or AMC service updates are not marketing and continue while you have an active order, warranty or AMC. |
| Warranty, AMC and RMA support | Legitimate use — you gave it to us for this purpose, including the 1-year standard warranty and the 6 months of free AMC that comes with every order. |
| Marketing: deals, new stock and price drops | Your consent — withdraw any time. You can switch it off in the notification preferences in your account, and the change takes effect immediately. |
| Responding to lawful requests and legal claims | Legitimate use — a legal obligation or a lawful order, and establishing or defending a legal claim. |
We do not build advertising profiles from your data, and we do not combine it with data bought from third parties.
06One-time passwords and SMS
Where mobile verification is switched on, we confirm your number by sending a one-time password (OTP) by SMS through our SMS gateway, which receives your number and the message.
- We store only a hash of the code, which cannot be reversed; the code itself goes only to your handset.
- Codes expire after 5 minutes, resends and attempts are limited, and the record is deleted within 24 hours.
Keep codes to yourself
Our team will never ask you for an OTP, your password or your full card number by phone, WhatsApp or email. If anyone does, end the conversation and write to hello@netlio.store.
08Where it is stored and how long
Your data is held in the systems we operate for the Netlio platform and, for the specific purposes described under "Who we share it with", in the systems of the partners named there. A partner acting for us keeps it only for as long as its role requires.
We keep personal data only for as long as the purpose or the law requires:
| Orders, invoices, credit notes and warranty records | The statutory period for tax and warranty records, which for GST records is at least 6 years. Serial numbers stay attached because your warranty is mapped to the serial and printed on the invoice. |
|---|---|
| Account and business profile | Until you ask us to delete it. Deletion removes your profile, saved addresses, saved payment methods, cart, wishlist and preferences; invoice records are kept separately for the statutory period. |
| Support tickets and enquiries | The life of your account plus the statutory period, because tickets often document warranty and AMC claims. |
| OTP records | The code expires 5 minutes after it is sent and the hashed record is deleted within 24 hours. |
| Server logs | A short rolling period, after which they are overwritten, unless a specific log is needed to investigate a security incident. |
| Wishlist and cart | Guest cart: in your browser until you sign in, check out or clear storage. Account cart and wishlist: until you remove the items or delete your account. |
When a retention period ends we delete the data or anonymise it so that it can no longer identify you.
09Security
- All traffic between your browser and Netlio is encrypted in transit with TLS.
- Passwords and OTPs are stored only as hashes.
- Access to the admin and seller panels is role-based, so a customer, seller or admin account sees only what its role requires.
- Every unit we sell is wiped to NIST 800-88 before it is listed, so no previous owner's data ships on it. The certificate of erasure is attached to your order in the account area.
If a security incident affects your personal data, we will notify you and the relevant authority in the manner and within the time the law requires, and tell you what we are doing about it.
10Your rights and how to exercise them
You have the following rights over the personal data we hold about you:
- Access: a summary of the personal data we hold about you and how it is being used.
- Correction: fixing anything inaccurate or out of date. You can edit most profile, address and GSTIN details yourself in Profile Settings.
- Deletion: erasure of data we no longer need, except records we must keep for the statutory period, such as invoices and GST records.
- Withdraw consent: switch off marketing at any time. Service messages about active orders, warranty and AMC continue because they are part of the contract.
- Nominate: name a person who may exercise these rights on your behalf if you are unable to.
- Grievance: complain about how we have handled your data, as described under "Grievance officer and contact" below.
To exercise a right, write to hello@netlio.store from the email address on your account, or raise a ticket in My Support Tickets. We first verify that the request comes from the account holder, then answer within 30 days. There is no charge. If we cannot act on a request because of a legal duty to retain the data, we will tell you why.
11Children
The site is not directed at anyone under 18 and we do not knowingly collect personal data from children. If you believe a minor has created an account or placed an order, write to hello@netlio.store and we will remove the data.
12Business customers and data you give us about others
Most orders are placed on behalf of a company. When you give us details of other people, such as a delivery contact at the site, the engineer who will receive the rack, an accounts contact for invoices or a colleague who will use the AMC, you confirm that you are allowed to share them and that you have told those people how we use their data, for example by pointing them to this policy.
We use those details only to deliver, invoice and support the order and to perform the warranty and AMC, and we protect them under this policy in the same way as your own.
13Changes to this policy
We update this policy when our practices, our partners or the law change. The last-updated date at the top of the page identifies the current version. For changes that materially affect how we use your data, we will post a notice on the site and send account holders a service message before the change takes effect. Continuing to use Netlio after that date means the updated policy applies to you.
14Grievance officer and contact
If you have a question, a complaint or a request about your personal data, write to hello@netlio.store or raise a ticket in My Support Tickets; the desk routes every data protection matter to our designated grievance officer.
- Email hello@netlio.store from the address registered on your account.
- Call or WhatsApp +91 8368843215 during the support hours shown at the end of this page.
- If you are signed in, raise a ticket in My Support Tickets so the request is tied to your account from the start.
Grievances are acknowledged within 48 hours and resolved within 1 month, as the Consumer Protection (E-Commerce) Rules 2020 require. If you are not satisfied with the outcome, you may escalate the matter to the Data Protection Board of India under the Digital Personal Data Protection Act 2023.
Questions about this page?
Updated 19 September 2026TCCT Pvt. Ltd.GSTIN 09AABCN4521R1ZP
Plot No. 131, Kh No. 14/1, Gali No. 4C, Goyla Vihar, New Delhi - 110071
Or send the contact form and quote the enquiry number you receive on any follow-up. The desk is open Monday to Saturday, 9 AM to 8 PM IST, and replies within 1 working day.