5. PURPOSES OF PROCESSING
5.1 Overarching Principle
5.1.1 Glatro processes personal data strictly for lawful, specified, and legitimate purposes, as permitted under applicable Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023.
5.1.2 The purposes described in this Section are illustrative and non-exhaustive, and Glatro reserves the right to process personal data for additional purposes where such processing is:
(a) reasonably connected to the original purpose of collection;
(b) necessary for platform operations, safety, or compliance; or
(c) otherwise permitted or required under law.
5.1.3 Users expressly acknowledge that processing of personal data is integral to the functioning of the Platform, and restriction of such processing may result in partial or complete denial of services.
5.2 Account Creation, Authentication & Management
5.2.1 Personal data is processed to:
(a) create and maintain User accounts;
(b) authenticate Users during login and access;
(c) verify identity and prevent impersonation;
(d) manage account preferences, settings, and permissions.
5.2.2 Glatro may use multi-factor authentication, OTP verification, and risk-based access controls as part of its security framework.
5.2.3 Failure to provide accurate data may result in suspension or termination of access without liability.
5.3 Order Fulfilment & Platform Operations
5.3.1 Personal data is processed to:
(a) enable placement, confirmation, modification, and cancellation of orders;
(b) coordinate with Vendors and Delivery Partners;
(c) manage inventory availability signals;
(d) ensure timely fulfilment and delivery tracking.
5.3.2 Glatro may retain order-related data for extended periods to ensure auditability, dispute resolution, and legal defence.
5.4 Payments, Settlements & Financial Reconciliation
5.4.1 Personal data and payment metadata are processed to:
(a) facilitate payment transactions through authorised gateways;
(b) reconcile payments, refunds, and settlements;
(c) detect and prevent payment fraud, chargebacks, or abuse;
(d) comply with accounting, tax, and audit requirements.
5.4.2 Glatro disclaims liability for failures attributable to third-party payment systems.
5.5 Vendor & Delivery Partner Verification
5.5.1 Enhanced personal data may be processed for:
(a) onboarding and KYC verification;
(b) risk profiling and eligibility assessment;
(c) compliance with anti-fraud and financial regulations;
(d) payout processing and recovery actions.
5.5.2 Glatro reserves the right to re-verify such data periodically or upon suspicion of risk.
5.6 Fraud Prevention, Abuse Detection & Security
5.6.1 Personal data may be processed to:
(a) detect fraudulent transactions or activities;
(b) prevent misuse of promotions, refunds, or platform features;
(c) enforce platform rules and contractual obligations;
(d) protect the integrity and security of the Platform.
5.6.2 Glatro may deploy automated tools, monitoring systems, and internal investigations for these purposes.
5.6.3 Users acknowledge that such processing may result in account restrictions or enforcement actions.
5.7 Customer Support, Communications & Grievance Handling
5.7.1 Personal data is processed to:
(a) respond to queries, complaints, and support requests;
(b) investigate grievances and disputes;
(c) communicate service-related updates and notices;
(d) improve customer experience and service quality.
5.7.2 Communications may be recorded, stored, and reviewed for quality assurance, training, and legal defence.
5.8 Legal Compliance, Audits & Enforcement
5.8.1 Personal data may be processed to:
(a) comply with statutory obligations;
(b) respond to court orders, regulatory notices, or law enforcement requests;
(c) conduct internal or external audits;
(d) enforce contractual rights and pursue legal remedies.
5.8.2 Such processing may continue even after account deletion, where required or permitted by law.
5.9 Analytics, Research & Platform Improvement
5.9.1 Personal data, including aggregated or anonymised data, may be processed for:
(a) analytics and reporting;
(b) performance measurement;
(c) service optimisation;
(d) internal research and development.
5.9.2 Insights derived from such processing are proprietary to Glatro.
5.10 Business Continuity & Risk Management
5.10.1 (a) ensure business continuity;
5.10.1 (b) manage operational risks;
5.10.1 (c) conduct internal investigations;
5.10.1 (d) protect Glatro’s legal, financial, and reputational interests.
5.10.2 Such processing shall not give rise to enforceable rights in favour of Users.
5.11 Marketing, Promotions & Communications
5.11.1 Subject to applicable law and consent requirements, Glatro may process personal data to:
(a) inform Users of offers, promotions, or updates;
(b) personalise content or recommendations;
(c) conduct surveys or feedback initiatives.
5.11.2 Users may opt out of certain communications, however service-related communications shall continue.
5.12 Limitation of Purpose-Based Claims
5.12.1 Users expressly waive any claim against Glatro arising solely from lawful processing of personal data for the purposes outlined in this Section.
5.12.2 Glatro’s determination of the necessity or relevance of processing for a particular purpose shall be final, subject to mandatory statutory provisions.
6. AUTOMATED DECISION-MAKING, PROFILING & RISK ASSESSMENT
6.1 Use of Automated Systems
6.1.1 Glatro may deploy automated tools, algorithms, rule-based engines, and machine-assisted decision-making systems for the purpose of operating, securing, and optimising the Platform.
6.1.2 Such automated systems may be used across multiple functional areas, including but not limited to:
(a) fraud detection and prevention;
(b) risk scoring and behavioural analysis;
(c) abuse identification and enforcement actions;
(d) payment validation and anomaly detection;
(e) eligibility assessment for promotions, offers, or incentives;
(f) operational efficiency and platform integrity.
6.1.3 The deployment of such systems is undertaken in Glatro’s legitimate business interest and for the protection of Users, Vendors, Delivery Partners, and the Platform as a whole.
6.2 Profiling Activities
6.2.1 Glatro may create profiles of Users based on observed behaviour, transaction history, usage patterns, and other relevant data points.
6.2.2 Profiling may involve:
(a) categorisation of Users into risk or trust tiers;
(b) identification of anomalous or suspicious activity;
(c) analysis of usage frequency, refund behaviour, or transaction patterns;
(d) assessment of compliance with platform policies.
6.2.3 Profiling outcomes may be used to:
(a) restrict or enhance access to certain features;
(b) apply additional verification measures;
(c) trigger internal reviews or investigations;
(d) determine eligibility for promotional or commercial benefits.
6.3 Automated Enforcement Actions
6.3.1 Based on automated assessments, Glatro may take enforcement actions including, without limitation:
(a) temporary or permanent account suspension;
(b) limitation of services or features;
(c) withholding or adjustment of Wallet balances or payouts;
(d) cancellation of orders or transactions;
(e) blacklisting across devices, identifiers, or accounts.
6.3.2 Users expressly acknowledge and agree that such actions may be taken without prior notice, where permitted by law, in order to protect the Platform and its stakeholders.
6.4 Human Oversight & Discretion
6.4.1 While automated systems may assist in decision-making, Glatro reserves the right to:
(a) review automated outcomes manually;
(b) override, confirm, or modify such outcomes;
(c) rely on internal discretion and risk assessment.
6.4.2 Glatro is under no obligation to provide detailed explanations of automated logic, scoring methodologies, or internal thresholds, except where expressly required by law.
6.5 No Enforceable Rights Created
6.5.1 The use of automated decision-making or profiling does not create any enforceable rights in favour of Users, including any right to:
(a) demand disclosure of algorithms or logic;
(b) challenge risk scores or internal classifications;
(c) claim entitlement to promotions, offers, or continued access.
6.5.2 Any benefit, access, or privilege extended by Glatro may be withdrawn at its discretion.
6.6 Statutory Compliance & Limitations
6.6.1 To the extent applicable, Glatro’s use of automated decision-making shall comply with mandatory provisions of Indian law, including the Digital Personal Data Protection Act, 2023.
6.6.2 Nothing in this Policy shall be construed as restricting Glatro’s ability to:
(a) prevent fraud or unlawful activity;
(b) comply with legal obligations;
(c) protect its legal and commercial interests.
6.7 Waiver of Claims
6.7.1 Users expressly waive any claims, demands, or causes of action against Glatro arising solely from:
(a) lawful automated processing;
(b) profiling-based decisions;
(c) enforcement actions taken in good faith.
6.7.2 This waiver shall apply to the maximum extent permitted under applicable law.