Your Data Rights
Last updated: 2026-07-03
India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) gives you — as a Data Principal — a set of rights over personal data that POSEngine processes about you. This page explains what those rights are and, most importantly, exactly how to exercise them. We aim to acknowledge every request within 24 hours and complete it within 7 business days unless the request is unusually complex.
Before you file a request, please read our Privacy Policy and (if you are a business customer) our Data Processing Agreement. They describe which data we hold as Data Fiduciary(data about you directly — account, billing, support) versus as Data Processor (data your business enters into POSEngine about its customers). Requests about your customers’ data must go to the merchant whose store collected it — we cannot action them without their instruction.
1. Right to access — §11
You can request a summary of the personal data POSEngine holds about you as a Data Fiduciary, the processing activities we perform with it, and the identities of any Data Processors and third parties with whom we have shared it.
How to file: email grievance@posengine.in from the email address associated with your POSEngine account with subject Access request — <your email>.
2. Right to correction, completion, updating and erasure — §12
You may correct any data that is inaccurate or misleading, complete any incomplete data, update stale data, and request erasure of data we no longer need for the purpose for which it was collected (subject to legal-retention exceptions such as tax invoices under GST law, which we must retain for 8 years).
Most self-service edits (name, phone, contact preferences) can be done directly in the Admin Dashboard under Settings → Account. For anything that cannot be self-served — bulk erasure, correction of billing records — email grievance@posengine.in.
3. Right to grievance redressal — §13
If you are unhappy with how we have handled your personal data, you can escalate to our Grievance Officer:
Grievance Officer
GrowThozhil Solutions Partnership Firm
Namakkal, Tamil Nadu 637408, India
Email: grievance@posengine.in
We will acknowledge your grievance within 24 hours and provide a substantive response within the statutory 30-day window. If you are not satisfied with our response, you may escalate to the Data Protection Board of India under §27.
4. Right to nominate — §14
You may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity. Send a signed nomination letter (physical or digitally-signed PDF) to the grievance mailbox above.
5. Right to withdraw consent — §6(5)
Where our processing depends on your consent (marketing emails, product analytics, cookie categories beyond “strictly necessary”), you may withdraw that consent at any time. Withdrawal does not affect processing that already happened before the withdrawal, and does not affect processing we do for legitimate uses (e.g., billing, fraud prevention, legal compliance) that do not require consent.
Two ways to withdraw:
- In-product: sign in to the Admin Dashboard and open Settings → Privacy → Withdraw consent. This posts to
/auth/withdraw-consent, writes an audit record, and emails our grievance mailbox to trigger the erasure workflow. - By email: message grievance@posengine.in from your account email with subject
Withdraw consent. We reply with a confirmation within 24 hours and complete the workflow within 7 business days.
6. What happens after we receive your request
- We acknowledge receipt within 24 hours.
- We verify your identity — usually by asking you to reply from the account email on file, or (for access/erasure) via a one-time code sent to your registered phone.
- We complete the request within 7 business days (30 days at the outer bound if the request is unusually complex, per §11(3)).
- For erasure requests, we send a final confirmation once the data has been deleted and we have notified any Data Processors involved (per the sub-processor list in our DPA §5).
7. Exceptions we must apply
The DPDP Act permits a Data Fiduciary to retain personal data despite an erasure request where:
- Retention is required by another law — e.g., GST invoices (Rule 56, 8 years), Income Tax records (6 years), Companies Act 2013 statutory registers.
- Data is needed to enforce a legal claim or defend against one.
- Data is needed for pending / ongoing litigation or regulatory inquiry.
In these cases we will tell you which data was retained and under which legal basis, and delete it once the retention obligation expires.
8. If your data was involved in a personal-data breach
Under §8(6) of the DPDP Act we notify the Data Protection Board of India and any affected Data Principal without undue delay if we identify a personal-data breach. Our internal 72-hour response playbook (Runbook 15 in our operations manual) lays out the containment, notification, and remediation sequence.
9. Questions
If any of the above is unclear — including whether we hold your data as Fiduciary or as Processor for a merchant — email grievance@posengine.in and we’ll clarify before you file the formal request.
Related documents: Privacy Policy · Data Processing Agreement · Terms of Service · Refund Policy