PRIVACY POLICY

Four Step Infra

Compliant with the Digital Personal Data Protection Act, 2023 (India)

Effective Date: 04 May 2026 | Version: 2.1

Entity Name: Four Step Infra

Registered Address: Waghodia, Vadodara, Gujarat – 391760, India

Website: www.floralwhite-worm-742126.hostingersite.com

RERA Status: Registered with Gujarat RERA Authority

Privacy Contact: privacy@floralwhite-worm-742126.hostingersite.com | +91 99999 99999

1. INTRODUCTION

Four Step Infra (“Company,” “we,” “our,” or “us”) is a real estate development entity incorporated and operating in India, with its principal place of business in Vadodara, Gujarat. We are committed to protecting the privacy and personal data of every individual who interacts with us — whether as a website visitor, prospective investor, customer, broker, channel partner, employee, or other stakeholder.

This Privacy Policy (“Policy”) explains how we collect, store, use, share, disclose, transfer, and protect personal information in accordance with applicable Indian laws, including:

  • The Digital Personal Data Protection Act, 2023 (“DPDP Act”)
  • The Information Technology Act, 2000 and Rules made thereunder
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”)
  • The Real Estate (Regulation and Development) Act, 2016 (“RERA”)
  • The Foreign Exchange Management Act, 1999 (“FEMA”) for NRI transactions
  • The Reserve Bank of India (RBI) regulations for cross-border investments
  • All other applicable Indian privacy and data protection laws

By accessing our Services, submitting an enquiry, providing personal information, or otherwise engaging with us, you confirm that you have read, understood, and consented to the practices described in this Policy. If you do not agree, please refrain from using our Services.

2. DEFINITIONS

For the purposes of this Policy, the following terms shall have the meanings assigned below:

TermMeaning
Personal DataAny data about an individual who is identifiable by, or in relation to, such data — as defined under the DPDP Act, 2023.
Sensitive Personal DataIncludes financial information (bank account details, PAN), passwords, biometric data, health information, and other categories specified under SPDI Rules.
Data PrincipalThe individual to whom personal data relates — i.e., you, the user.
Data FiduciaryThe entity which, alone or jointly with others, determines the purpose and means of processing personal data — i.e., Four Step Infra.
Data ProcessorAny third party engaged by us to process personal data on our behalf, such as cloud hosting providers, CRM platforms, or payment gateways.
ProcessingAny operation performed on personal data, including collection, storage, retrieval, use, disclosure, alteration, transfer, or erasure.
ServicesOur website, mobile app, sales offices, properties, marketing communications, and any related products or services offered by Four Step Infra.

3. INFORMATION WE COLLECT

We collect personal data in three primary ways:

3.1 Information You Provide Directly

When you interact with us through enquiry forms, site visits, phone calls, WhatsApp messages, emails, or in-person meetings, you may provide:

  • Identity Information: Full name, age, gender, date of birth, nationality, marital status, photographs
  • Contact Details: Phone number, alternate phone, email address, residential address, city, state, country, PIN code
  • Government Identification: PAN, Aadhaar number, voter ID, driving licence, passport (collected only when required for property transactions, KYC, or loan processing)
  • Financial Information: Investment budget, source of funds declaration, bank account details, income proof, ITR documents, salary slips, bank statements (collected only with express consent for purchase or loan applications)
  • Family & Profession Details: Occupation, employer, designation, annual income range, family member details (when relevant for joint ownership or co-applicants)
  • Property Preferences: Unit type, size preference, payment plan choice, possession timeline, investment goals
  • Communication Records: Phone call recordings (with disclosure), WhatsApp chat history, email correspondence, in-person meeting notes, video call recordings (with consent)

3.2 NRI-Specific Information

For Non-Resident Indian (NRI), Person of Indian Origin (PIO), and Overseas Citizen of India (OCI) investors, we collect additional information as required under FEMA and RBI regulations:

  • Passport details and visa status
  • OCI/PIO card information
  • Foreign residential address and country of residence
  • NRE/NRO/FCNR account details (for repatriable transactions)
  • Foreign tax identification number (where applicable)
  • Power of Attorney details if applicable

3.3 Information Collected Automatically

When you visit our website or interact with our digital platforms, we automatically collect:

  • Device & Browser Data: IP address, device type, operating system, browser type and version, screen resolution, device identifiers
  • Usage Information: Pages viewed, time spent, click patterns, search queries within our site, scroll depth, button clicks, form interactions
  • Location Data: Approximate geographic location based on IP address (we do not collect precise GPS data without explicit permission)
  • Referral Sources: Referring URLs, marketing campaign IDs (UTM parameters), social media platforms that brought you to us
  • Cookies & Tracking Technologies: As detailed in Section 7 below

3.4 Information from Third Parties

We may receive personal data about you from authorised third parties, including:

  • Marketing Lead Platforms: Facebook Lead Ads, Google Ads, MagicBricks, 99acres, Housing.com, NoBroker
  • Bank & Financial Partners: HDFC Bank, SBI, ICICI, Axis Bank, Bank of Baroda, Kotak Mahindra, LIC Housing Finance, PNB Housing Finance (only with your explicit consent for loan processing)
  • Channel Partners & Brokers: Authorised real estate brokers and consultants in our partner network
  • Background Verification Agencies: When required for high-value transactions or compliance with anti-money laundering (AML) requirements
  • Public Sources: Publicly available business directories, professional networks (only for business-to-business outreach)

4. PURPOSE & LEGAL BASIS FOR PROCESSING

We process your personal data only for specified, explicit, and legitimate purposes. Our legal basis for processing under the DPDP Act, 2023 includes:

PurposeDescription & Legal Basis
Service DeliveryProcess enquiries, schedule site visits, allocate units, draft and execute Sale Agreements, manage construction milestones. (Basis: Contract performance + Consent)
CommunicationSend transactional updates, payment receipts, possession notices, RERA-mandated communications, project completion notifications. (Basis: Legitimate interest + Legal obligation)
MarketingSend promotional content about new projects, offers, market insights via email, WhatsApp, SMS — only with your explicit opt-in consent. (Basis: Consent)
KYC & ComplianceVerify identity for property transactions, comply with PMLA, FEMA, RBI, RERA, and Income Tax requirements. (Basis: Legal obligation)
Loan ProcessingShare financial documents with partner banks for home loan applications. (Basis: Consent)
Fraud PreventionDetect and prevent fraudulent transactions, identity theft, and unauthorized access. (Basis: Legitimate interest + Legal obligation)
AnalyticsAnalyse website usage, optimise marketing campaigns, improve user experience. Data is anonymised and aggregated where possible. (Basis: Legitimate interest)
Legal DefenceEstablish, exercise, or defend legal claims; respond to court orders, regulatory inquiries, or government requests. (Basis: Legal obligation)

We will not use your personal data for purposes beyond those stated above without obtaining fresh consent, except where required or permitted by law.

5. CONSENT MANAGEMENT

Under the DPDP Act, 2023, your consent is the primary basis for most processing activities. We are committed to obtaining and managing consent in a transparent and lawful manner:

5.1 How We Obtain Consent

  • Free, specific, informed, unconditional, and unambiguous — never bundled with unrelated services
  • Provided through clear affirmative action — checkbox, signature, or recorded verbal consent
  • Available in English and Indian regional languages (currently Hindi and Gujarati upon request)
  • With clear notice explaining what data is collected and why

5.2 Withdrawing Consent

You have the right to withdraw your consent at any time. To do so:

  • Email us at privacy@floralwhite-worm-742126.hostingersite.com with subject line “Withdraw Consent”
  • Use the unsubscribe link in any marketing email
  • Reply STOP to any marketing SMS or WhatsApp message
  • Call our privacy helpline at +91 99999 99999

Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Note that some processing is required to fulfill our contractual or legal obligations and cannot be opted out of (e.g., RERA-mandated communications, payment receipts).

5.3 Consent for Sensitive Personal Data

Sensitive personal data (such as financial information, biometric data, or health data) is processed only with your express written consent and only when strictly necessary for the specified purpose.

6. DISCLOSURE & SHARING OF YOUR DATA

We do NOT sell your personal data. However, we may share your information in the following limited circumstances:

6.1 Authorised Recipients

  • Banking & Financial Partners: When you apply for home loans, your KYC and financial documents are shared with HDFC, SBI, ICICI, Axis, and other partner banks you choose.
  • Legal & Compliance Service Providers: Lawyers, chartered accountants, RERA filing agents, document registrars who help us register sale deeds and meet regulatory requirements.
  • Service Providers (Data Processors): Cloud hosting (AWS Mumbai region, Google Cloud India), CRM platforms (Zoho, LeadSquared), email service providers, SMS gateways, payment processors — all bound by data processing agreements with strict confidentiality clauses.
  • Marketing & Analytics Tools: Google Analytics, Meta Pixel, Microsoft Clarity, LinkedIn Insight Tag — primarily anonymized aggregate data.
  • Property Management Team: Once you become a unit owner, your contact information is shared with our internal property management team for tenant placement, rent disbursement, and maintenance coordination.
  • Insurance Providers: For property insurance, title insurance, or related coverages purchased through our affiliations.
  • Government Authorities: When mandated by Indian law, court orders, RERA authorities, Income Tax Department, Enforcement Directorate, or other competent legal authority.
  • Business Transfers: In the unlikely event of a merger, acquisition, restructuring, or sale of business assets, your data may be transferred to the acquiring entity — subject to equivalent privacy protections.

6.2 What We Will NEVER Do

  • Sell your personal data to any third party for monetary or other valuable consideration
  • Share your data with unrelated marketers or advertisers
  • Use sensitive personal data for advertising purposes
  • Share data with parties not contractually bound by confidentiality
  • Disclose data without legal basis or court order, even on government request

7. COOKIES & TRACKING TECHNOLOGIES

Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyse site performance. Below is a summary of what we use:

Cookie CategoryPurposeOpt-Out Available?
EssentialRequired for the website to function — page navigation, form submissions, security features, session management.No (required for service)
AnalyticsHelp us understand visitor behaviour through Google Analytics 4, Microsoft Clarity. Data is anonymised.Yes
MarketingUsed by Meta Pixel, Google Ads, LinkedIn Insight Tag to show relevant advertisements on other platforms.Yes
FunctionalRemember language preferences, form data, login state to improve user experience.Yes

You can manage cookies through:

  • The cookie consent banner on your first visit
  • Your browser settings (“Clear cookies” / “Block cookies”)
  • Browser extensions like Privacy Badger or Ghostery
  • Do Not Track (DNT) signals (we honour DNT requests)

Note: Disabling certain cookies may impact website functionality (e.g., contact forms, language preferences may not save).

8. DATA SECURITY MEASURES

We implement industry-standard organisational, technical, and physical security measures to protect your personal data:

8.1 Technical Safeguards

  • SSL/TLS encryption for all data transmission (HTTPS protocol)
  • AES-256 encryption for sensitive data at rest
  • Secure cloud hosting with AWS (Mumbai region) and Google Cloud (Mumbai region) — both ISO 27001 certified
  • Multi-factor authentication (MFA) for employee access to sensitive systems
  • Regular security patches and software updates
  • Automated daily backups stored in geo-redundant locations within India
  • Web Application Firewall (WAF) and DDoS protection

8.2 Organisational Safeguards

  • Need-to-know access controls — only authorised personnel access specific data categories
  • Mandatory data protection training for all employees
  • Confidentiality agreements signed by every employee, contractor, and partner
  • Periodic internal and third-party security audits
  • Documented incident response and breach notification procedures
  • Vendor due diligence for all data processors

8.3 Physical Safeguards

  • Restricted access to office premises housing physical records
  • Secure document destruction (shredding) for hard-copy records past retention
  • CCTV surveillance and access logs for sensitive areas

8.4 Breach Notification

In the event of a personal data breach affecting your data, we will:

  • Notify affected Data Principals within 72 hours of becoming aware of the breach
  • Inform the Data Protection Board of India as required under the DPDP Act
  • Provide details of the nature of the breach, data affected, likely consequences, and measures taken
  • Recommend protective actions you should take (e.g., changing passwords, monitoring accounts)

9. DATA RETENTION

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy or to comply with legal, accounting, or reporting requirements:

Data CategoryRetention PeriodLegal Basis
Enquiry & Lead DataUp to 24 months from last interaction, then anonymisedLegitimate interest + Consent
Customer RecordsTerm of investment + 7 years post-transactionIncome Tax Act, 1961
Financial Documents8 years after transaction completionCompanies Act, 2013 + IT Act
KYC DocumentsMinimum 5 years post-relationshipPMLA, 2002
Marketing SubscriptionsUntil unsubscribed; deleted within 30 days thereafterConsent
Website AnalyticsAggregated data: indefinite. Individual identifiers: 26 monthsLegitimate interest
Call Recordings12 months from date of callLegitimate interest + Consent
Employee RecordsThroughout employment + 7 years thereafterLabour & Tax Laws

After the applicable retention period, your personal data is securely deleted, anonymised, or aggregated such that you can no longer be identified.

10. YOUR RIGHTS AS A DATA PRINCIPAL

Under the DPDP Act, 2023 and other applicable laws, you have the following rights regarding your personal data:

10.1 Right to Access

You may request a summary of personal data we hold about you and the processing activities undertaken with that data.

10.2 Right to Correction & Erasure

You may request correction of inaccurate or misleading data, completion of incomplete data, or erasure of data that is no longer necessary for the purpose it was collected.

10.3 Right to Withdraw Consent

As detailed in Section 5.2, you may withdraw your consent for processing at any time.

10.4 Right to Grievance Redressal

You may file a grievance with our designated Grievance Officer (see Section 14) or escalate to the Data Protection Board of India.

10.5 Right to Nominate

You may nominate another individual to exercise your rights in case of your death or incapacity, as permitted under the DPDP Act.

10.6 How to Exercise Your Rights

To exercise any of these rights:

  • Email privacy@floralwhite-worm-742126.hostingersite.com with the subject line indicating your request type
  • Include a copy of valid government-issued identification for verification
  • Provide specific details of your request

We will respond within 30 days of receiving a verified request. For complex requests, this period may be extended by an additional 30 days, with notice to you.

There is no fee for exercising these rights, except where requests are manifestly unfounded, excessive, or repetitive — in which case we may charge a reasonable administrative fee or refuse to act on the request.

11. CHILDREN’S PRIVACY

Our Services are intended for individuals aged 18 years and above. In compliance with the DPDP Act, 2023:

  • We do not knowingly collect personal data from children (individuals below 18) without verifiable parental consent
  • We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children
  • If we learn that we have inadvertently collected data from a child without parental consent, we will delete such data within 7 days of verification

Parents or guardians who believe their child has provided personal information to us may contact privacy@floralwhite-worm-742126.hostingersite.com for immediate removal.

12. CROSS-BORDER DATA TRANSFERS

Most of our data processing occurs within India. However, in limited cases, your personal data may be transferred outside India for processing:

  • Cloud Services: Some service providers may store data in international data centres for redundancy
  • Email Services: Email correspondence may transit through international servers
  • Communication Tools: Video conferencing platforms may have international infrastructure

All cross-border transfers are conducted in accordance with the DPDP Act, 2023 and only to countries notified by the Central Government as offering adequate protection. Where we transfer data internationally, we ensure equivalent privacy protections through:

  • Standard Contractual Clauses (SCCs)
  • Data Processing Agreements (DPAs) with strict confidentiality obligations
  • Verification that recipient countries have adequate data protection laws

13. THIRD-PARTY LINKS & EXTERNAL PLATFORMS

Our website and communications may contain links to third-party websites, social media platforms, bank loan portals, property aggregators, and other external services. Examples include:

  • Social Media: Facebook, Instagram, LinkedIn, YouTube
  • Property Portals: MagicBricks, 99acres, Housing.com, NoBroker
  • Bank Portals: HDFC, SBI, ICICI, Axis Bank, Bank of Baroda
  • Payment Gateways: Razorpay, PayU, Paytm Business
  • Maps & Navigation: Google Maps, Apple Maps

This Privacy Policy does NOT apply to those external sites. Once you click an external link, our policies no longer govern your interaction. We encourage you to review the privacy policies of every external service before sharing personal information.

Four Step Infra is not responsible for the content, security, or privacy practices of third-party platforms.

14. GRIEVANCE OFFICER (As Required Under IT Act)

In compliance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, we have designated a Grievance Officer to address your privacy concerns:

  • Name / Designation: Privacy Grievance Officer
  • Email: privacy@floralwhite-worm-742126.hostingersite.com
  • Phone: +91 99999 99999 (Mon–Fri, 10 AM – 6 PM IST)
  • Postal Address: Four Step Infra, Office Address, Waghodia, Vadodara – 391760, Gujarat, India
  • Acknowledgement Time: Within 48 hours of receipt
  • Resolution Time: Within 30 days (extendable by 30 days for complex matters)

If you are unsatisfied with our response or believe your rights have been violated, you may escalate the matter to the Data Protection Board of India, established under the DPDP Act, 2023.

15. POLICY UPDATES

We may update this Privacy Policy from time to time to reflect:

  • Changes in our business practices or services
  • Updates to applicable Indian laws and regulations
  • Implementation of new technologies
  • Feedback from users and regulators

When we make material changes:

  • The “Last Updated” date at the top of this Policy will be revised
  • Registered users will be notified via email or WhatsApp at least 14 days before changes take effect
  • For significant changes affecting how we use your data, we will request fresh consent where required
  • Previous versions will be archived and available upon request

We encourage you to review this Policy periodically. Your continued use of our Services after changes are posted constitutes acceptance of the revised terms.

16. CONTACT US

If you have any questions, concerns, or feedback about this Privacy Policy or our data handling practices, please reach out using any of the following channels:

  • Privacy Email: privacy@floralwhite-worm-742126.hostingersite.com
  • General Email: hello@floralwhite-worm-742126.hostingersite.com
  • Phone: +91 99999 99999
  • WhatsApp: +91 99999 99999 (24/7 chatbot, business hours for human support)
  • Office Address: Four Step Infra, Office Address, Waghodia, Vadodara – 391760, Gujarat, India
  • Website: www.floralwhite-worm-742126.hostingersite.com

17. JURISDICTION & GOVERNING LAW

This Privacy Policy and any disputes arising from or related to it shall be governed by and construed in accordance with the laws of India, without regard to its conflict of laws principles. All disputes shall be subject to the exclusive jurisdiction of the competent courts in Vadodara, Gujarat, India.

ACKNOWLEDGEMENT

By using our Services, you confirm that:

  • You have read and understood this Privacy Policy in full
  • You consent to the collection, use, and disclosure of your personal data as described herein
  • You are at least 18 years of age, or have parental/guardian consent
  • The information you provide is accurate, complete, and up-to-date