LEGAL
Privacy Policy

Last Updated: June 2026

1

Introduction & Scope

This Privacy Policy describes how Mellite Global Private Limited ("Mellite", "we", "our", or "us") collects, uses, stores, and protects your personal data when you use our platform, website, mobile applications, and related services (collectively, the "Services").

This policy applies to all users of our Services, including developers, buyers, contractors, vendors, site engineers, and other stakeholders within the real estate personalization ecosystem. By using our Services, you consent to the data practices described in this policy.

If you do not agree with this policy, please discontinue use of our Services. For the purposes of applicable data protection laws, Mellite Global Private Limited is the data controller for personal data processed through our platform.

2

Information We Collect

We collect information you provide directly to us when you create or modify your account, request services, contact support, or otherwise communicate with us. The types of personal information we collect include:

Account Information

Name, email address, phone number, job title, company name, and profile details.

Contact Information

Postal address, billing address, and communication preferences.

Payment Information

Payment method details, billing records, transaction history, and invoice data.

Project Data

Apartment configurations, material selections, buyer preferences, UIDs, pricing configurations, and customization data.

Communication Data

Support tickets, feedback, survey responses, and any other information you provide when contacting us.

3

Information Collected Automatically

When you use our Services, we automatically collect certain information about your device and usage patterns:

Log Information

Browser type and version, access times, pages viewed, referring URLs, IP address, and error logs.

Device Information

Device type, operating system version, unique device identifiers, and mobile network information.

Usage Data

Features used, selections made, interaction patterns, time spent on pages, and navigation paths.

Location Information

General location derived from IP address for service optimization and compliance with regional regulations.

4

How We Use Your Information

We use the information we collect to provide, maintain, and improve our Services. Specifically, we use your data for:

Service Delivery

Provide, maintain, and improve our platform features and user experience.

Transaction Processing

Process material selections, generate invoices, facilitate payments, and manage upgrade orders.

Project Management

Enable developers to manage buyer personalizations, track construction milestones, and coordinate with vendors.

Communications

Send technical notices, security alerts, support messages, product updates, and marketing communications.

Analytics & Improvement

Aggregate usage patterns to improve platform performance, UX, and feature development.

Compliance

Meet legal obligations including RERA compliance, tax reporting, and regulatory requirements.

Security

Detect, prevent, and address fraud, abuse, and security incidents.

5

Legal Basis for Processing

We process your personal data under one or more of the following legal bases, depending on the context:

Consent

Where you have given explicit consent for specific processing activities, such as marketing communications.

Contract Performance

Processing necessary to fulfill our contractual obligations to you, including providing the Services you have requested.

Legal Obligation

Processing required to comply with legal obligations, such as tax reporting, RERA compliance, and regulatory requirements.

Legitimate Interests

Processing necessary for our legitimate interests, such as improving our Services, preventing fraud, and ensuring network security, provided these interests do not override your fundamental rights.

6

Information Sharing

We may share your information in the following circumstances. We never sell your personal information to third parties.

Service Providers

With trusted third-party vendors who perform services on our behalf - including cloud hosting, payment processing, email delivery, analytics, and customer support.

Project Stakeholders

With developers, contractors, and vendors as part of your project ecosystem on a need-to-know basis, to facilitate project execution and delivery.

Affiliates & Subsidiaries

With our affiliates and subsidiaries for the purpose of providing and improving our Services.

Legal Compliance

When required by law, court order, or governmental regulation, or to protect the rights, property, or safety of Mellite, our users, or others.

We never sell your personal information to third parties. All third-party service providers are contractually obligated to protect your data and use it only for the purposes we specify.

7

Data Retention

We retain your information for as long as your account is active or as needed to provide services. We have established the following retention periods based on data type and legal requirements:

Account Data

Retained for the duration of your account activity plus 7 years after account closure, as required by Indian tax and corporate law.

Project Data

Retained for the project lifecycle plus 10 years to satisfy RERA requirements and support warranty claims.

Financial Records

Retained for 7 years from the date of transaction, as mandated by Indian tax regulations.

Communication Records

Support tickets and communications retained for 3 years from resolution for quality assurance purposes.

Analytics & Usage Data

Aggregated and anonymized data may be retained indefinitely for product improvement; personal identifiers are removed after 24 months.

After the applicable retention period, data is securely deleted using industry-standard methods. You may request early deletion where legally permissible.

8

Backup & Disaster Recovery

To ensure business continuity and data integrity, we maintain encrypted backups of all platform data:

Backup Retention

Backups are retained for 90 days beyond the standard retention period to support disaster recovery. Backup data is subject to the same security controls as production data.

Geographic Redundancy

Backups are stored in geographically separate data centers to protect against regional outages.

Restoration Process

In the event of data loss, we will restore from backups and notify affected users of any restoration activities that may impact their data.

9

Data Security

We implement comprehensive security measures to protect your personal and project data:

Encryption

Data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 encryption.

Access Control

Role-based access controls with least-privilege principles. Multi-factor authentication is available and recommended for all users.

Audit Logging

All access to sensitive data is logged, monitored, and retained for security review and compliance purposes.

Infrastructure Security

Our infrastructure is hosted on SOC 2 compliant cloud platforms with regular security audits and penetration testing.

Employee Training

All employees undergo data protection and security training. Access to personal data is restricted to authorized personnel only.

10

Data Breach Notification

In the unlikely event of a data breach that compromises your personal information, we are committed to notifying affected users and relevant authorities in accordance with applicable law:

Notification Timeline

We aim to notify affected users within 72 hours of becoming aware of a breach that poses a risk to your rights and freedoms.

What We Will Communicate

The nature of the breach, types of data affected, steps we have taken, and recommended actions you can take to protect yourself.

Regulatory Reporting

We will report breaches to the relevant data protection authorities as required by applicable law, including the Indian Computer Emergency Response Team (CERT-In).

11

Cookies

We use cookies and similar technologies to enhance your experience, analyze usage, and support our marketing efforts. You can control cookie preferences through your browser settings or our cookie consent manager.

Essential Cookies

Required for platform functionality - session management, security tokens, and authentication.

Functional Cookies

Remember your preferences, settings, and choices to provide a personalized experience.

Analytics Cookies

Help us understand platform usage patterns to improve features and performance.

Marketing Cookies

Used to deliver relevant content and measure the effectiveness of our marketing campaigns.

12

Third-Party Services & Links

Our Services may contain links to third-party websites, services, or applications that are not operated by us. We are not responsible for the privacy practices of these third parties:

Payment Processors

We use trusted payment processors to handle transactions. Their privacy policies govern the collection and use of your payment information.

Analytics Providers

We use analytics services to understand how our Services are used. These services may collect information about your use of our platform.

Cloud Infrastructure

Our Services are hosted on third-party cloud platforms. These providers have their own security and privacy controls.

External Links

Our Services may link to external websites. We are not responsible for the content or privacy practices of these sites.

13

International Data Transfers

Mellite is based in India and operates globally. Your personal data may be transferred to, stored in, and processed in countries other than your country of residence, including for our GCC market expansion:

Transfer Mechanisms

All international transfers are conducted with appropriate safeguards, including standard contractual clauses and adequacy decisions where applicable.

Cross-Border Project Data

Project data may be transferred between India and other jurisdictions where our developer clients or vendor partners operate, subject to contractual protections.

Your Rights

You have the right to be informed about international transfers and to request details about the safeguards we have in place.

14

Automatic Decision-Making & Profiling

Our platform uses automated systems to provide certain features and insights:

Margin Calculations

Our platform automatically calculates upgrade margins, pricing, and financial projections based on project data. These calculations are deterministic and based on configurable rules.

Vendor Matching

We may use automated systems to match projects with suitable vendors based on location, capability, and availability.

Your Control

You maintain full control over all automated decisions. You can review, adjust, or override any automated recommendations at any time.

15

AI & Machine Learning

Our platform incorporates artificial intelligence and machine learning technologies to enhance platform capabilities:

Material Intelligence Engine

We use ML models to analyze material catalogs, predict pricing trends, and recommend optimal material selections based on project context and historical data.

Predictive Demand Forecasting

We analyze aggregated project data to predict material demand patterns, helping developers plan procurement and vendors manage inventory.

Data Used for ML

ML models are trained on aggregated, anonymized data. Personal identifiers are removed or pseudonymized before being used for model training.

Human Oversight

All AI-generated recommendations are reviewed by human operators. No automated system makes binding decisions without human approval.

16

Do Not Track Signals

Some browsers support a "Do Not Track" (DNT) signal that indicates a user does not want their online activity tracked. Our platform currently does not respond to DNT signals. Instead, we provide granular cookie controls through our consent manager, allowing you to opt out of non-essential cookies.

We believe this approach provides you with greater transparency and control over your data than a binary DNT signal.

17

WhatsApp, SMS & Communication Channels

Mellite uses WhatsApp Business API and SMS to facilitate project communications, nudge automation, and stakeholder notifications. By providing your phone number, you consent to receive communications through these channels:

Project Notifications

Construction milestone updates, delivery confirmations, and site audit notifications sent to relevant stakeholders.

Nudge Automation

Automated reminders for pending actions, document submissions, and approval workflows relevant to your role in the project.

Transactional Messages

Order confirmations, payment receipts, invoice notifications, and service-related alerts.

Opt-Out

You can opt out of non-transactional communications at any time by replying STOP to any message or contacting support. Transactional messages essential to your account cannot be disabled.

Message Retention

WhatsApp and SMS communications are retained as part of project records for the same period as other communication data.

18

Mobile App & Device Permissions

The Mellite mobile application (used by site engineers and field teams) may request certain device permissions to deliver core functionality:

Camera

Used for QR code scanning at construction sites, capturing progress photos, and documenting site conditions. Images may be uploaded to your project records.

Location

Used to verify site visits, tag audit checklists with location data, and provide location-aware vendor recommendations. Location data is collected only during active app sessions.

Storage

Used to save project documents, photos, and offline data for field use in areas with limited connectivity.

Notifications

Used to deliver real-time task assignments, approval requests, and site alerts relevant to your role.

Your Control

All permissions are optional and can be managed through your device settings. Denying a permission may limit certain app features but will not prevent access to the web platform.

19

Indian Data Protection Laws & Compliance

Mellite operates in compliance with Indian data protection legislation and is committed to upholding the highest standards of data protection:

Digital Personal Data Protection (DPDP) Act, 2023

We process personal data in accordance with the DPDP Act, ensuring lawful basis for processing, data minimization, and purpose limitation.

Information Technology Act, 2000

We comply with the IT Act and associated rules, including reasonable security practices and procedures for handling sensitive personal data.

SPDI Rules

Sensitive personal data including financial information, payment details, and project financials are handled with enhanced security measures and explicit consent where required.

Data Localization

Primary data storage is located in India to comply with applicable data localization requirements. Cross-border transfers follow applicable legal frameworks.

RERA Compliance

Project data is retained and managed in accordance with Real Estate Regulatory Authority requirements specific to each state.

20

API & Third-Party Developer Access

Mellite provides API access for authorized third-party developers and integration partners to extend platform functionality:

API Data Scope

API access is scoped to specific data categories and project contexts as defined in the integration agreement. Developers can only access data relevant to their integration function.

Authentication & Authorization

All API access requires OAuth 2.0 authentication with scoped permissions. Access tokens are short-lived and can be revoked at any time.

Data Handling Obligations

Third-party developers are contractually obligated to process API data solely for the agreed purpose, implement appropriate security measures, and delete data upon termination of the integration.

Audit & Monitoring

API usage is logged and monitored. Suspicious activity triggers automatic rate limiting and potential access revocation.

21

Children's Privacy

Our Services are designed for business use by real estate developers, contractors, and related professionals. We do not knowingly collect personal information from children under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected].

If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.

22

Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data. We are committed to helping you exercise these rights:

Right to Access

Request a copy of the personal data we hold about you.

Right to Correction

Request correction of inaccurate or incomplete personal data.

Right to Deletion

Request deletion of your personal data, subject to legal retention requirements.

Right to Data Portability

Request transfer of your data to another service provider in a structured, commonly used format.

Right to Object

Object to processing of your personal data for direct marketing or legitimate interest purposes.

Right to Restrict Processing

Request limitation of processing under certain circumstances.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days or as required by applicable law. For data subject access requests, we may require verification of your identity before disclosing data.

23

Account & Data Deletion

In compliance with Google Play and App Store guidelines, you have the right to request the deletion of your account and associated personal data at any time.

In-App Deletion

You can delete your account directly within the Mellite mobile app by navigating to Profile > Settings > Delete Account.

Email Request

Alternatively, you can request account and data deletion by emailing us at [email protected] from your registered email address.

Data Retention Post-Deletion

Upon receiving a deletion request, we will delete your personal data within 30 days, except for data we are legally required to retain (such as financial records for tax purposes or RERA compliance project data).

24

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify you of material changes by:

In-App Notification

Displaying a prominent notice in the platform for 30 days after the update.

Email Notification

Sending an email to the address associated with your account for significant policy changes.

Updated Policy

Posting the updated policy on this page with a revised "Last Updated" date.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

25

Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a concern, please contact our Data Protection Officer / Privacy Desk:

Phone / WhatsApp

+91 95055 51760

Postal Address

Mellite Global Private Limited, Level 4, Prestige Tech Park, Outer Ring Road, Bengaluru, Karnataka, India - 560037

Response Time

We aim to respond to all privacy-related inquiries within 5 business days.

Grievance Redressal

If you are unsatisfied with our response, you may escalate to our Grievance Desk at [email protected]. If the issue remains unresolved, you may file a complaint with the Data Protection Board of India or your local data protection authority.

Your data is protected.