1. Scope and Application
This Policy applies to information processed in connection with CityAuction-operated websites, webpages, dashboards, forms, alerts, marketing interfaces, investor-support workflows, institutional workflows, Customs-auction information services, “Next Chapter” enquiries, customer support, CRM records, call/WhatsApp/email interactions and any other channel through which CityAuction or Estabizz Fintech Private Limited receives information relating to an identified or identifiable individual.
Where a separate notice is displayed for a specific service, transaction, statutory requirement, professional engagement, institutional mandate, document upload, auction workflow or third-party integration, that notice may supplement this Policy and, to the extent of inconsistency, the more specific notice shall govern for that processing activity.
2. Definitions and Interpretative Framework
For purposes of this Policy, references to “CityAuction”, “we”, “us” or “our” mean Estabizz Fintech Private Limited acting through the CityAuction venture, unless a context-specific notice states otherwise. “User”, “you” or “your” includes visitors, registered users, buyers, investors, bidders, institutional representatives, promoters, developers, professionals, counterparties and other persons interacting with CityAuction.
Terms such as “personal data”, “processing”, “Data Principal”, “Data Fiduciary”, “Data Processor”, “consent” and related expressions shall, where applicable, have the meanings assigned to them under the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and other applicable data-protection, information-technology, cybersecurity or sectoral laws, to the extent such provisions are in force from time to time.
3. Categories of Information We May Process
Depending on how you interact with CityAuction, we may process some or all of the following categories:
| Category | Illustrative Data |
|---|---|
| Identity & Contact | Name, mobile number, email address, correspondence address, organisation, designation and contact preferences. |
| Account & Authentication | User ID, authentication metadata, account settings, login events and security logs. |
| Transaction / Opportunity Preferences | Asset classes, locations, budgets, investor mandates, auction categories, institutional requirements and alert preferences. |
| KYC / Eligibility Information | Documents or particulars voluntarily provided or required for a specific service, bidder-support workflow, transaction or third-party process. |
| Asset / Company / Project Information | Property details, sale notices, project details, corporate information, transaction context and supporting documents submitted by users or institutional counterparties. |
| Communications | Emails, support tickets, form submissions, meeting notes, call-related records, WhatsApp communications and complaint/grievance records. |
| Technical / Device Data | IP address, browser, operating system, device identifiers, access times, session information, referral source, security events and diagnostic logs. |
| Usage & Interaction Data | Pages viewed, searches, filters, saved opportunities, clicks, alert interactions, document-access events and navigation patterns. |
| Marketing / Attribution Data | Campaign source, medium, referral information, communication response and consent/opt-out status. |
| Payment / Billing Metadata | Invoice references, payment status, transaction identifiers and limited payment metadata; payment credentials may be processed directly by third-party payment providers. |
4. Sources From Which Information May Be Obtained
Information may be obtained:
- directly from you through forms, registration, calls, messages, uploads, meetings or service requests;
- from your employer, authorised representative, adviser, agent, institution or counterparty;
- from Banks, NBFCs, ARCs, Liquidators, Insolvency Professionals, government authorities, auction platforms, custodians or other institutional sources;
- from publicly available notices, registries, websites, legal publications, court/tribunal records, governmental databases or other lawful public sources;
- from service providers, analytics providers, CRM systems, hosting/security vendors, communication providers or other processors;
- through cookies, logs, device interactions and similar digital technologies.
5. Purposes for Which Information May Be Processed
We may process information where reasonably connected with one or more of the following purposes:
- operating, administering, securing, maintaining and improving CityAuction;
- creating and managing user accounts, preferences, alerts and saved searches;
- presenting, matching, categorising or communicating auction, asset, project, company, Customs or strategic opportunities;
- responding to enquiries and providing requested information or support;
- providing or coordinating Investor Desk, due diligence, inspection, valuation, legal-support, bidder-readiness, institutional, liquidation or transaction-support workflows;
- facilitating introductions to institutions, advisers, professionals, lenders, buyers, investors, developers or other counterparties where requested or relevant;
- fraud prevention, misuse detection, security monitoring, access control, audit logging and incident response;
- analytics, service development, product improvement, user-experience optimisation and internal research;
- billing, accounting, taxation, compliance, audit, dispute handling and record keeping;
- sending service communications, requested alerts and, where legally permitted, promotional communications;
- complying with law, court/tribunal directions, regulatory requirements, government requests or enforcement obligations;
- establishing, exercising, defending or preserving legal rights and claims.
6. Processing Basis, Consent and Other Lawful Uses
Personal data may be processed on the basis of consent, for certain legitimate uses recognised under applicable law, for compliance with legal obligations, for performing requested services or taking steps at your request, or under another lawful ground available to CityAuction.
Where processing is based on consent, consent may be obtained through digital interfaces, forms, checkboxes, communications or other legally permissible mechanisms. Where required, you may withdraw consent using the method stated at the relevant collection point or by contacting us; withdrawal shall not affect processing already lawfully undertaken before such withdrawal and may affect our ability to provide a service that necessarily requires the relevant data.
9. Third-Party Information and Information Submitted About Other Persons
If you provide information relating to another individual, you represent that you are lawfully authorised to provide such information and that any required notice, consent or other legal prerequisite has been satisfied. CityAuction may rely on that representation unless circumstances reasonably indicate otherwise.
CityAuction is not responsible for the accuracy, completeness or lawful provenance of information supplied by users, institutions, counterparties or public sources, except to the extent applicable law imposes a non-excludable obligation on CityAuction.
10. Retention and Deletion
Information may be retained for as long as reasonably necessary for the relevant purpose, account administration, transaction history, legal compliance, taxation, audit, fraud prevention, security, dispute resolution, enforcement of agreements, defence of claims, business continuity or other lawful requirements.
Retention periods may vary by category and context. Where deletion or erasure is legally required, data may be deleted, anonymised, de-identified, restricted or rendered inaccessible in accordance with applicable technical and legal requirements. Residual copies may persist temporarily in backup, disaster-recovery or security systems until overwritten or retired under normal system cycles.
11. Information Security and Security Limitations
CityAuction may implement administrative, contractual, organisational and technical safeguards considered reasonable and appropriate having regard to the nature of the data, processing, systems and risks involved, including access controls, authentication, logging, vendor controls, backups and other safeguards.
No absolute-security representation: No internet transmission, electronic storage environment, software system, cloud infrastructure, third-party service or security control can be represented as completely secure or error-free. To the maximum extent permitted by law, CityAuction does not warrant that unauthorised access, interception, malware, infrastructure failure, credential compromise, third-party compromise or other security incidents can never occur.
Where a personal-data breach triggers legally applicable notification or remedial obligations, CityAuction will act in accordance with the law then in force and the scope of its role in relation to the affected processing.
12. Hosting, Remote Access and Cross-Border Processing
CityAuction and its service providers may use systems, personnel, infrastructure or cloud services located in India or other jurisdictions. Personal data may therefore be accessed, processed, backed up or stored outside the user’s location, subject to restrictions, transfer conditions or prohibitions applicable under law from time to time.
13. Data Principal / User Rights
Subject to applicable law and to the extent the relevant statutory provisions are in force, eligible individuals may have rights relating to access to information about processing, correction, completion, updating, erasure, withdrawal of consent, grievance redressal, nomination or other rights prescribed by law.
A request may be subject to verification of identity, authority, legal exceptions, record-retention obligations and technical feasibility. CityAuction may request information reasonably necessary to authenticate and process a request and may decline or limit requests where permitted by law.
14. Children and Persons Requiring Lawful Guardian Action
CityAuction is principally intended for adults, businesses, investors, professionals and institutional users. We do not intentionally design auction-investment, institutional or transaction-support services for children. Where applicable law requires verifiable parental or guardian consent or imposes restrictions concerning processing relating to children or persons represented by lawful guardians, CityAuction will apply such requirements to the extent legally applicable.
15. Alerts, Service Messages and Marketing Communications
Users may receive communications relating to account activity, requested alerts, saved mandates, service enquiries, document requests, security matters, transaction workflows or similar operational purposes. Promotional communications may be sent where lawfully permitted and subject to applicable consent/opt-out requirements.
Unsubscribing from marketing does not necessarily prevent operational, legal, security or transaction-related communications that are necessary for an active service or relationship.
16. Public Records, Auction Notices and Institutional Information
CityAuction may collect, index, structure, summarise, link to or display information appearing in auction notices, public records, institutional publications, public websites or governmental/tribunal/court sources. Such information may contain names, addresses, borrower/guarantor references, property details or other information lawfully made public or supplied by an authorised institution.
The fact that information appears on CityAuction does not mean that CityAuction originated, independently verified, owns or controls the underlying source information. Requests concerning correction, removal or restriction of public/institution-supplied information will be assessed having regard to source authority, legal obligations, public-record status, platform role and applicable law.
17. Search, Matching, Analytics and Automated Tools
CityAuction may use software, algorithms, rules, analytics, search ranking, recommendation systems or AI-assisted tools to organise information, identify potential matches, classify opportunities, detect anomalies, prioritise leads, personalise alerts or support internal workflows.
Such outputs may be probabilistic, incomplete or dependent on source data. They do not constitute legal, investment, valuation, credit or professional advice and should not be treated as determinative of suitability, title, value, risk or transaction outcome.
18. Privacy-Specific Disclaimers and Limitation of Liability
To the maximum extent permitted by applicable law, and without limiting any non-excludable statutory duty, CityAuction shall not be responsible for loss, damage, liability, claim, cost or consequence arising solely from:
- information supplied by a user, institution, professional, public source or third-party system that is inaccurate, incomplete, outdated, unlawfully supplied or subsequently changed;
- a third party’s independent use, retention, disclosure, security practices or failure after data is lawfully transmitted to that third party for a requested or permitted purpose;
- user-side credential compromise, device compromise, phishing, impersonation, malware, insecure networks or failure to maintain account security;
- temporary system outages, infrastructure failures, force-majeure events, telecommunications failures, cloud/service-provider incidents or cyber events beyond CityAuction’s reasonable control;
- the user’s reliance on public-source, auction-source, algorithmic, matched or summarised information without reviewing the authoritative source or undertaking independent diligence;
- communications or transactions initiated outside CityAuction systems or with persons falsely representing an association with CityAuction.
Where liability cannot legally be excluded, any limitation shall operate only to the extent, form and amount permitted under applicable law. Nothing in this Policy limits liability for any matter for which limitation or exclusion is prohibited by law.
Policy allocation of risk: This Policy does not create a warranty that information will always remain confidential, available, accurate, recoverable or immune from lawful disclosure, cyber risk or third-party processing. It allocates responsibilities subject to mandatory law and must be read with the Terms & Conditions and other CityAuction legal policies.
19. Amendments to this Privacy Policy
We may amend this Policy to reflect legal, regulatory, operational, technical, product, security or business changes. The updated version may be published on this page with a revised effective date. Where applicable law requires additional notice or consent for a material change, such steps will be taken to the extent required.
20. Privacy Requests, Grievance Redressal and Contact
Privacy questions, consent-withdrawal requests, correction/erasure requests, complaints or grievances may be submitted using the contact details below. Requests will be handled subject to identity verification, legal requirements, applicable exemptions and the statutory framework in force at the relevant time.
Gyan Marg, PDPU Road, Raysan, Gandhinagar, Gujarat – India
Email: info@estabizz.com
Phone: +91 98256 69668
Any specifically designated grievance officer, privacy contact, Data Protection Officer or statutory contact required by applicable law may be separately identified on CityAuction once such designation becomes applicable or is formally made.