Privacy Policy of Gujarat Ambuja Exports Limited
- Last updated: 20 July 2026
- This Privacy Policy is issued by Gujarat Ambuja Exports Limited ("GAEL", "we", "us", "our") and explains how we collect, use, share, store and protect your personal data when you visit www.ambujagroup.com or interact with us through this website.
- This Policy is prepared in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it, read with the Information Technology Act, 2000. For the purposes of the DPDP Act, GAEL is the Data Fiduciary and you are the Data Principal.
- Please read this Policy carefully. If you do not agree with it, please do not submit personal data to us through this website.
1. Who we are
- Gujarat Ambuja Exports Limited
- "Ambuja Tower", Opp. Sindhu Bhavan, Sindhu Bhavan Road, Bodakdev, P.O. Thaltej, Ahmedabad – 380 054, Gujarat, India
- CIN: L15140GJ1991PLC016151
- Phone: +91-79-61556677 | Fax: +91-79-61556678
- General e-mail: info@ambujagroup.com
2. Definitions
- Personal Data means any data about an individual who is identifiable by or in relation to such data.
- Processing means any operation performed on personal data, including collection, recording, storage, use, sharing, disclosure or erasure.
- Data Principal means the individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian; where the individual is a person with disability, it includes the lawful guardian.
- Data Fiduciary means the person who determines the purpose and means of processing personal data — in this case, GAEL.
- Data Processor means a person who processes personal data on behalf of a Data Fiduciary.
- Child means an individual who has not completed eighteen (18) years of age.
3. What personal data we collect, and why
- We collect only the personal data that is necessary for the specified purpose for which you provide it. We collect the following categories:
3.1 Business / product enquiry forms
- Data: name, company name, designation, e-mail address, telephone / mobile number, fax number, postal address, website URL, country and the contents of your enquiry.
- Purpose: to respond to your enquiry, to send you the product, technical or commercial information you have asked for, and to maintain a record of our correspondence with you.
- Basis: your consent, given by ticking the consent box on the form (Section 6, DPDP Act).
3.2 Career / job application form
- Data: name, telephone number, e-mail address, preferred work location, job profile, any message you write, and the resume you upload — which may itself contain your date of birth, postal address, photograph, educational qualifications and employment history.
- Purpose: solely to assess your application, to contact you regarding current or future vacancies, and to comply with our recruitment record-keeping obligations.
- Basis: your consent, given by ticking the consent box on the career form (Section 6, DPDP Act).
- We do not sell applicant data, and we do not use it for marketing.
3.3 Investor e-mail registration
- Data: name, folio number / DP-Client ID, e-mail address and contact details.
- Purpose: to register your e-mail address for service of annual reports, notices and other shareholder communications.
- Basis: your consent, and our compliance with the Companies Act, 2013 and the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 — a legitimate use under Section 7 of the DPDP Act.
3.4 Technical and usage data (only with your consent)
- Data: IP address, approximate city / region / country derived from that IP address, device type, browser type and version, operating system, pages visited, time and date of visit, time spent on pages, referring URL, clicks on telephone, e-mail, WhatsApp and map links, and session recordings / heatmaps of your interaction with pages.
- Purpose: to measure website traffic, understand which content is useful and improve the performance and usability of the website.
- Basis: your consent, given through the cookie consent banner. None of these technologies run before you consent. See Section 5 below.
3.5 Statutory and corporate disclosures
- Certain personal data is published on this website because the law requires it — for example the names, ages and professional backgrounds of our Directors and Key Managerial Personnel, and the shareholder details contained in unclaimed / unpaid dividend and IEPF filings (name, folio number / DP-Client ID and amount).
- Basis: compliance with the Companies Act, 2013, the Investor Education and Protection Fund rules and the SEBI (LODR) Regulations, 2015. This is a legitimate use under Section 7 of the DPDP Act and, being a statutory disclosure obligation, is subject to the exemptions in Section 17 of the DPDP Act. Consent is not required for these publications and they cannot be withdrawn while the statutory obligation subsists.
4. What we do not do
- We do not sell your personal data to any third party.
- We do not use your personal data for automated decision-making or profiling that produces legal effects for you.
- We do not knowingly collect personal data of children, or of persons with disability who have a lawful guardian, without verifiable consent — see Section 9 below.
- We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
5. Cookies and tracking technologies
- A cookie is a small file placed on your device. We also use similar technologies such as scripts, tags and pixels. We group them into two categories:
5.1 Strictly necessary — always active
- Session cookies (PHP session) — keep your form submission and any error messages working across pages. Deleted when you close your browser.
- Google reCAPTCHA (Google LLC / Google India Private Limited) — protects our forms from automated abuse and spam. It processes your IP address and device / browser characteristics. Governed by the Google Privacy Policy.
- Consent cookie (
gael_consent_v1) — stores your own cookie choice so that we do not ask you again on every page. Expires after 6 months. - These are necessary for the website to function and to keep it secure, and are treated as a legitimate use under Section 7 of the DPDP Act.
5.2 Analytics and performance — only with your consent
- Google Analytics 4 (Google LLC) — aggregate website traffic and usage statistics. IP anonymisation is enabled.
- Microsoft Clarity (Microsoft Corporation) — session recordings and heatmaps showing how visitors move through and interact with our pages.
- ipify and ipinfo.io — look up your IP address and derive an approximate city / region / country, which we attach to our own internal record of clicks on telephone, e-mail, WhatsApp and map links.
- These technologies are blocked until you give consent through the cookie banner. If you decline, they are never loaded.
5.3 Managing and withdrawing your cookie consent
- You may change or withdraw your cookie consent at any time, and it is as easy to withdraw as it was to give (Section 6(3), DPDP Act). Use the button below, or the "Cookie preferences" control shown at the bottom-left of every page.
- You can also block or delete cookies through your browser settings. If you block strictly necessary cookies, parts of this website may not work correctly.
6. Who we share your personal data with
- Our own personnel: the relevant sales, technical, human resources or secretarial team within GAEL, on a need-to-know basis.
- Data Processors acting on our instructions: our website hosting and e-mail service providers, and the analytics providers named in Section 5.2 above. We require every processor to process personal data only under a valid contract and only for the purposes we specify.
- Group companies, subsidiaries and joint-venture partners of GAEL, where necessary to answer your enquiry, and subject to this Policy.
- Registrar and Share Transfer Agent, depositories, stock exchanges, the Ministry of Corporate Affairs, SEBI and the Investor Education and Protection Fund Authority — for investor and shareholder data, as required by law.
- Courts, regulators and law-enforcement agencies — where disclosure is required by law or by an order of a court or authority.
- Professional advisers and acquirers — in connection with a merger, acquisition, restructuring or sale of assets, subject to confidentiality obligations.
7. Transfer of personal data outside India
- Some of the service providers named in Section 5.2 — in particular Google LLC and Microsoft Corporation — operate servers outside India. If you consent to analytics cookies, your usage data, IP address and device information may therefore be transferred to and stored on servers located outside India, including in the United States.
- Such transfers are made in accordance with Section 16 of the DPDP Act. We will not transfer personal data to any country or territory that the Central Government has notified as restricted, and we will comply with any such notification issued in future.
- If you do not wish your data to be transferred outside India, decline analytics cookies in the consent banner. This will not affect your ability to use the website or to contact us.
8. How long we keep your personal data
- In accordance with Section 8(7) of the DPDP Act, we erase personal data once the purpose for which it was collected is no longer being served, and once retention is no longer necessary for compliance with any law. Our retention periods are:
| Category of personal data | Retention period |
|---|---|
| Business / product enquiry data | 3 years from the date of last contact with you |
| Career applications and resumes | 12 months from submission (longer only if you are hired, in which case employee record rules apply) |
| Analytics, cookie and usage data | Up to 26 months from collection |
| Record of your consent | For as long as we hold the related personal data, plus 1 year, in order to evidence consent |
| Investor, shareholder and statutory records | 8 years, or such longer period as prescribed under the Companies Act, 2013 and the SEBI (LODR) Regulations, 2015 |
- If you withdraw your consent earlier, we will erase the relevant personal data, and instruct our processors to do the same, unless retention is required by law.
9. Children and persons with disability
- Under the DPDP Act, a child is any individual below eighteen (18) years of age. This website and its services are intended for business, professional and investor use and are not directed at children.
- We do not knowingly collect the personal data of a child without the verifiable consent of the parent or lawful guardian, as required by Section 9 of the DPDP Act. The same applies to a person with disability who has a lawful guardian.
- We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
- If you are a parent or guardian and believe a child has provided us with personal data, please contact our Grievance Officer (Section 13 below) and we will erase it promptly.
10. How we protect your personal data
- In accordance with Section 8(5) of the DPDP Act, we maintain reasonable technical and organisational security safeguards, including:
- Encryption in transit — the whole website is served over HTTPS/TLS.
- Access control — personal data is accessible only to authorised personnel on a need-to-know basis, using individual credentials.
- Input validation and anti-abuse measures — server-side validation of all form submissions and Google reCAPTCHA on public forms.
- File upload restrictions — resumes are restricted by file type and size before being accepted.
- Contractual safeguards — every Data Processor engaged by us is bound by a written contract restricting the purposes of processing and requiring equivalent security measures.
- Retention limits and deletion — data is erased in line with the schedule in Section 8 above.
- Periodic review — our safeguards, access rights and processor arrangements are reviewed periodically.
- No method of transmission over the internet or of electronic storage is completely secure. While we apply the safeguards above, we cannot guarantee absolute security.
11. Personal data breach
- In the event of a personal data breach, GAEL will, in accordance with Section 8(6) of the DPDP Act and the rules made under it, give intimation of the breach to the Data Protection Board of India and to each affected Data Principal, in the form and manner and within the timelines prescribed.
- Our intimation will describe the nature and extent of the breach, its likely consequences, the measures we have taken or propose to take to mitigate risk, and the contact details of our Grievance Officer.
- We maintain an internal incident response procedure covering detection, containment, assessment, notification and remediation of personal data breaches.
12. Your rights as a Data Principal
- Right to access information (Section 11) — to obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of all other Data Fiduciaries and Processors with whom it has been shared.
- Right to correction, completion, updating and erasure (Section 12) — to have inaccurate or misleading data corrected, incomplete data completed, out-of-date data updated, and data erased where it is no longer needed for the purpose it was collected for, unless retention is required by law.
- Right of grievance redressal (Section 13) — to a readily available means of raising a grievance with us about our processing or about our response to your requests. We will respond within the period prescribed under the DPDP Act.
- Right to nominate (Section 14) — to nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
- Right to withdraw consent (Section 6(3)) — to withdraw your consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
12.1 Your duties as a Data Principal (Section 15)
- Please comply with applicable law when exercising your rights, do not impersonate another person when providing personal data, do not suppress material information, do not register a false or frivolous grievance or complaint, and furnish only information that is verifiably authentic when seeking correction or erasure.
12.2 How to exercise your rights
- Write to our Grievance Officer at cs@ambujagroup.com with the subject line "DPDP Request", stating which right you wish to exercise and enough detail for us to identify your records.
- We may ask you for information reasonably necessary to verify your identity before acting on a request. We do not charge a fee for exercising your rights.
- For cookie and tracking consent specifically, you can act immediately yourself using the "Manage or withdraw cookie consent" button in Section 5.3 above.
13. Grievance Officer
- In accordance with Section 8(9) of the DPDP Act, the business contact details of the person able to answer questions from Data Principals about the processing of their personal data are:
- Mr. Kalpesh Bhupatbhai Dave
- Company Secretary & Compliance Officer — also designated as Grievance Officer for the purposes of the DPDP Act, 2023
- Gujarat Ambuja Exports Limited, "Ambuja Tower", Opp. Sindhu Bhavan, Sindhu Bhavan Road, Bodakdev, P.O. Thaltej, Ahmedabad – 380 054, Gujarat, India
- E-mail: cs@ambujagroup.com
- Phone: +91-79-61556677 | Fax: +91-79-61556678
- Further contact details are available at Investor Contacts.
14. Escalation to the Data Protection Board of India
- If you have raised a grievance with our Grievance Officer and are not satisfied with the response, or if we have not responded within the period prescribed under the DPDP Act, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and the rules made under it.
- Exhausting our internal grievance mechanism first is a precondition to approaching the Board.
15. Links to other websites
- This website contains links to third-party websites, including stock exchange, regulatory and depository websites. We do not control those sites and are not responsible for their content or their privacy practices. We encourage you to read the privacy policy of every website you visit.
16. Changes to this Privacy Policy
- We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities or in the law, including the rules notified under the DPDP Act.
- We will post the revised Policy on this page and update the "Last updated" date at the top. Where the change is significant, we will give prior notice by e-mail and/or a prominent notice on this website, and where the change requires it, we will ask for your consent afresh.
- Please review this Policy periodically. Changes take effect when they are posted on this page.
17. Contact us
- For questions about this Privacy Policy or about how we handle your personal data, contact our Grievance Officer at cs@ambujagroup.com.
- For all other queries, contact us at info@ambujagroup.com or +91-79-61556677.