
1. Data Controller Identification & Core Commitment
Helmetsan (“we,” “our,” or “the Platform”), operated by Ash Digital Services / Ashish Digital Services, is an independent computational motorcycle helmet intelligence and safety research platform. We are deeply committed to safeguarding the digital privacy, personal data rights, and confidentiality of riders, researchers, and visitors worldwide.
This Global Privacy Policy establishes how we collect, store, process, transfer, and protect your personal information when you access https://helmetsan.com/, our mobile applications, APIs, newsletters, and interactive tools.
Designated Data Controller: Ash Digital Services / Ashish Digital Services
Principal Grievance / Data Protection Officer: Ashish Dungdung
Physical Headquarters: Rourkela, Sundargarh District, Odisha 769004, India
Direct Privacy Inquiries: [email protected]
2. Categories of Personal Data We Collect
Depending on your interaction with Helmetsan, we collect personal data across two primary streams:
A. Information You Voluntarily Provide Directly to Us
- Direct Inquiries & Feedback: Your name, email address, topic subject, and message content when submitting contact requests, reporting specification discrepancies, or contacting our technical review team.
- Community Reviews & Comments: Any public feedback, helmet sizing experiences, motorcycle gear reviews, or username monikers you post publicly on our articles or product sheets.
- Newsletter Subscription Data: Your email address and preferred helmet category interests (e.g., Adventure, Track/Racing, Modular/Touring) if you subscribe to our technical research dispatches.
B. Information Automatically Collected via Platform Telemetry
- Network & Device Telemetry: Anonymized/truncated Internet Protocol (IP) addresses, browser brand and version, operating system architecture, screen resolution, and hardware device category (mobile, tablet, desktop).
- Regional Geolocation: Country-level and regional geolocation derived from edge network headers (Cloudflare CF-IPCountry) used exclusively to display locally compliant safety standards (ECE 22.06 vs DOT) and localized currency pricing.
- Interaction Telemetry: Pages visited, dwell duration, referral URLs, internal search queries, outbound retailer clicks, and interactive comparison matrix operations.
- Cookie & Local Storage State: Essential security tokens, language preferences (`pll_language`), and cookie consent preferences (`faz_consent_*`).
3. Lawful Bases for Processing Under GDPR & International Law
Under Article 6 of the General Data Protection Regulation (GDPR) and international equivalents, we only process your personal data where a defined lawful basis exists:
| Processing Purpose | Data Categories | Lawful Legal Basis |
|---|---|---|
| Delivering catalog, comparison engine, and search features | Device telemetry, anonymous session cookies | Legitimate Interests (Art. 6(1)(f)): Operating and maintaining platform performance. |
| Regional safety certification warnings & localized pricing | Edge geolocation headers (Country/Region) | Legitimate Interests (Art. 6(1)(f)): Ensuring riders are warned of local certification legality. |
| Responding to contact inquiries and technical support | Name, email address, correspondence history | Contractual Necessity / Consent (Art. 6(1)(b)/(a)): Fulfilling user-initiated communication. |
| Dispatching editorial newsletters & safety bulletins | Email address, preference tags | Explicit Consent (Art. 6(1)(a)): Revocable at any time via one-click unsubscribe links. |
| Edge firewall defense, bot detection, and rate limiting | Anonymized IP hashes, request headers | Legal Obligation & Security (Art. 6(1)(c)/(f)): Protecting infrastructure against cyber attacks. |
| Analytical performance and behavioral metrics (GA4) | Pseudonymized analytical cookies | Consent (Art. 6(1)(a)): Deployed strictly upon affirmative cookie consent. |
4. Authorized Third-Party Sub-Processors & Data Sharing
We do not sell, rent, monetize, or trade your personal information. We share minimal necessary data strictly with verified sub-processors under robust Data Processing Agreements (DPAs):
- Cloudflare Inc. (USA): Provides edge reverse-proxy caching, SSL/TLS termination, DDoS mitigation, and web application firewall (WAF) services.
- Hetzner Online GmbH (Germany / EU): High-performance private cloud server infrastructure where our primary application server and PostgreSQL/MySQL databases reside.
- Google LLC (USA / Ireland): Google Analytics 4 (with IP anonymization) and Google AdSense (display advertising, subject to user consent preferences).
- Affiliate Partner Networks: Impact.com, Amazon Associates, CJ Affiliate, and ShareASale. When you click an affiliate merchant button, an anonymous referral tracking identifier is transmitted to confirm transaction attribution. No personal identifiers (name, email, payment details) are ever shared with affiliate networks.
5. International Data Transfers & Cross-Border Safeguards
Helmetsan operates internationally with primary hosting infrastructure in the European Union (Germany) and operational management in the Republic of India. When personal data is transferred across international boundaries, we ensure adequate protections are enforced:
- Standard Contractual Clauses (SCCs): We utilize the European Commission’s approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) to govern transfers between EU entities and third-country sub-processors.
- Technical Transfer Protections: All cross-border data in transit is encrypted using modern TLS 1.3 cryptography, and all analytical storage is pseudonymized at rest using AES-256 encryption.
6. Data Retention Schedules & Security Measures
We retain personal information only for the minimum duration strictly necessary to fulfill the purposes outlined in this policy:
- General Server Logs: Rotated and permanently purged after thirty (30) days.
- Contact & Support Correspondence: Retained for twelve (12) months following ticket resolution to ensure support continuity, after which messages are securely purged.
- Newsletter Data: Retained until the subscriber exercises an unsubscribe request, after which the email address is permanently removed from active broadcast lists.
- Analytical Data: Google Analytics 4 user-level data retention is capped at 14 months, after which aggregated metrics only are retained.
7. Your Statutory Data Subject Rights
Regardless of your geographical location, Helmetsan affords you comprehensive, enforceable statutory rights over your personal data:
- Right of Access (Article 15 GDPR): You have the right to request a formal copy of all personal data we hold concerning you.
- Right to Rectification (Article 16 GDPR): You may request the prompt correction of inaccurate, obsolete, or incomplete personal data.
- Right to Erasure / “Right to be Forgotten” (Article 17 GDPR): You may request the permanent deletion of your personal records where processing is no longer necessary or consent has been withdrawn.
- Right to Restriction of Processing (Article 18 GDPR): You may request that we temporarily suspend active processing of your data while an audit or legal contestation is pending.
- Right to Data Portability (Article 20 GDPR): You may request an export of your provided personal information in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to Object (Article 21 GDPR): You have the absolute right to object at any time to the processing of your data for direct marketing or based on legitimate interests.
- Right to Withdraw Consent: Where processing is predicated upon consent, you may withdraw your consent at any moment with immediate prospective effect.
To exercise any data subject right, email our Data Protection Desk at [email protected]. We will verify your identity and fulfill your statutory request without fee within thirty (30) calendar days.
8. United States State Privacy Rights (California CCPA/CPRA, Virginia, Colorado)
This section provides mandatory disclosures for residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA), as well as residents of Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA):
- Notice at Collection: In the preceding 12 months, we have collected identifiers (IP address, email for contact forms), internet activity (page interactions), and approximate geolocation (country/state level).
- We Do Not Sell Personal Information: Helmetsan has not “sold” personal consumer information for monetary consideration in the preceding 12 months.
- Sharing for Cross-Context Behavioral Advertising: We permit third-party advertising partners (Google AdSense) to place cookies on your browser for cross-context behavioral ads if you permit analytical and advertising cookies. California residents may opt out by enabling the Global Privacy Control (GPC) or submitting a request below.
- Non-Discrimination: We will never deny services, alter pricing, or degrade service quality because you exercised your statutory privacy rights.
- Authorized Agents: California consumers may designate an authorized agent to submit requests on their behalf, subject to verified written authorization.
9. Indian Digital Personal Data Protection (DPDP) Act 2023 Compliance
For individuals residing within the Republic of India, personal data is collected and processed in strict compliance with the Digital Personal Data Protection Act, 2023. Helmetsan operates as a Data Fiduciary. You possess the right to access a summary of your digital personal data, the right to correction and erasure, the right of grievance redressal, and the right to nominate an individual to exercise your rights in the event of incapacity.
Any unresolved grievances may be submitted directly to our Grievance Officer ([email protected]), with statutory recourse to the Data Protection Board of India.
10. Children’s Online Privacy Protection (Under 16)
Helmetsan is an adult-oriented motorcycling platform and does not knowingly solicit, collect, or process personal data from children under the age of sixteen (16). If we discover that personal information has been collected from a child under 16 without verified parental consent, we will delete that data immediately. Parents or guardians who believe we may have inadvertently collected such data should contact [email protected].
11. Policy Modifications & Official Privacy Inquiries
We reserve the right to periodically update this Privacy Policy to reflect changing technical capabilities, new platform features, or evolving global regulations. The revised document will be published with an updated “Version” and “Effective Date” header.
Official Privacy Desk: [email protected]
Data Protection Officer: Ashish Dungdung
Physical Address: Ash Digital Services / Helmetsan Legal, Rourkela, Sundargarh District, Odisha 769004, India