Privacy policy

Last updated: May 18, 2026

At NOVCEL, we approach skincare with formulation discipline and transparency, and we bring that same clarity to how we handle your personal information. This Privacy Policy explains what data we collect when you visit novcel.com, how we use it, who we share it with, and what choices you have.

NOVCEL is a brand owned and operated by Rofzen Private Limited, a company incorporated under the laws of India (CIN: U21002MP2025PTC078617), with its registered office at 3A, Kothi Road, Civil Line, Dewas Bada Bazar, Dewas, Madhya Pradesh – 455001, India.

When you use our website, make a purchase, or get in touch with us, you are sharing information with Rofzen Private Limited on behalf of NOVCEL. This policy governs all such interactions.

We recommend reading this in full. But if you have a specific question, you can jump to the section that covers it.

What Information We Collect

We only collect what we genuinely need. The type of information we gather depends on how you interact with us.

1.1 Information You Give Us Directly

This includes anything you actively fill in or share with us, such as:

        Your name, email address, phone number, and delivery address when you place an order or create an account

        Payment details: processed securely through our payment partners; we do not store card numbers on our servers

        Messages or queries you send to our customer support team

        Feedback, reviews, or responses to any surveys you choose to participate in

1.2 Information We Collect Automatically

When you browse novcel.com, our systems automatically gather certain technical data. This is standard practice for most websites and helps us understand how people use the site. It may include:

        Your IP address, browser type, operating system, and device information

        Pages you visit, links you click, and how long you spend on each section

        Referral sources: meaning how you arrived at our website

        Session data and timestamps

Much of this data is aggregated and non-identifiable. We use it to improve the website experience, not to track you individually.

1.3 Cookies and Similar Technologies

We use cookies, small text files stored on your device, to keep the site functioning properly and to understand traffic patterns. You can find full details in our Cookie Policy. Briefly:

        Essential cookies keep your session active and your cart intact.

        Analytics cookies (like Google Analytics) help us measure how the site performs.

        Marketing cookies may be used to show relevant content based on your browsing, only with your consent.

You can manage or withdraw cookie consent at any time through our cookie settings link in the footer.

How We Use Your Information

We use the information we collect for specific and lawful purposes to provide our products and services, improve your experience, and comply with our legal obligations. We do not sell your personal data or use it for unrelated purposes without an appropriate legal basis.

We use your information to:

  • Process and fulfil your orders, including coordinating with courier partners for delivery.

  • Send you order confirmations, shipping updates, and customer support responses.

  • Create, manage, and maintain your account and keep your information accurate.

  • Improve our website, products, and customer experience by analysing how our services are used.

  • Send promotional communications only where you have provided your consent or where otherwise permitted by applicable law. You may opt out at any time.

  • Comply with applicable legal and regulatory obligations, including tax, accounting, and consumer protection requirements.

  • Detect, investigate, and prevent fraud, security incidents, and unauthorised access to our website or services.

If we need to use your personal information for a purpose that is materially different from those described above, we will inform you and, where required by applicable law, obtain your consent before doing so.


Why We Are Permitted to Process Your Data

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable regulations, we rely on the following legal grounds to process your personal data:

        Contract performance: When you place an order, we need your information to deliver it.

        Consent: For marketing communications and non-essential cookies, we only act with your explicit, freely given consent.

        Legal obligation: Certain data is retained to meet statutory requirements under Indian law.

      Certain legitimate uses permitted by law: We may process limited personal data where permitted under applicable law, including to detect and prevent fraud, protect the security of our website and services, investigate misuse, and comply with legal or regulatory requirements.

You have the right to withdraw consent at any time. Doing so will not affect any processing that already took place on the basis of that consent.

Who We Share Your Information With

We do not sell your personal data. 

There are, however, situations where we share your information with trusted third parties to help run our business. These include:

        Logistics and courier partners, to fulfil and track your orders

        Payment gateway providers, who process transactions on our behalf under strict security standards

        Technology and analytics service providers, who help us run and improve the website

        Email and communication platforms, used to send transactional and marketing messages

All third-party partners we work with are bound by confidentiality obligations and are only permitted to use your data for the specific tasks we assign to them. We do not authorise them to use your information for their own marketing or unrelated purposes.

We may also disclose information when required to do so by law, for instance, in response to a valid court order, regulatory request, or government directive. In such cases, we will disclose only the minimum necessary and, where legally permitted, notify you.

How We Store and Protect Your Data

Your data is stored on secure servers. We use appropriate technical and organisational measures to protect it from unauthorised access, loss, or misuse. These include encrypted data transmission, access controls, and regular security reviews.

No system is completely immune to risk, and we cannot guarantee absolute security over the internet. But we take our responsibility seriously and act promptly if we identify a breach that could affect your rights.

If a data breach is likely to result in a risk to your rights, we will notify the relevant authority and, where required, inform you, in accordance with applicable law.

How Long We Keep Your Information

We do not hold on to your data longer than necessary. The retention period depends on the purpose for which the data was collected:

        Order and transaction data is retained for as long as required by Indian tax and accounting laws, typically seven years.

        Account information is kept while your account remains active. If you delete your account, we will remove your personal data within a reasonable period, except where retention is required by law.

        Marketing preferences and communication records are retained until you opt out, after which they are removed from active lists.

        Support communications may be retained for up to three years to help resolve future queries or disputes.

Your Rights Under the DPDP Act, 2023

India's Digital Personal Data Protection Act gives you meaningful control over your personal data. As a NOVCEL customer, you have the right to:

        Access: Request a summary of the personal data we hold about you.

        Correction: Ask us to correct inaccurate or incomplete information.

        Erasure: Request deletion of your personal data, subject to legal retention requirements.

        Withdraw consent: Opt out of marketing communications or withdraw cookie consent at any time.

        Nominate: Designate a nominee who can exercise these rights on your behalf in case of death or incapacity, as permitted under applicable law.

To exercise any of these rights, write to us at support@novcel.com. We will acknowledge your request within 48 hours and endeavour to resolve it within 30 days. For complex requests, we may take up to 90 days, but we will keep you informed.

If you believe we have not handled your request appropriately, you may escalate the matter to our Grievance Officer (see Section 10) or to the Data Protection Board of India, once it becomes operational.

Links to External Websites

Our website may include links to third-party websites, partner brands, payment processors, or informational resources. Once you leave novcel.com, this Privacy Policy no longer applies.

We are not responsible for the privacy practices of external websites and encourage you to review their policies before sharing any personal information.

Children's Privacy

NOVCEL's website and products are intended for individuals who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18.

Under the DPDP Act, anyone under 18 is considered a child, and processing their data requires verifiable parental consent. Our website does not target minors, and we do not engage in profiling or targeted advertising directed at them.

If you believe a minor has shared personal data with us without appropriate consent, please contact us at support@novcel.com and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time, for example, when we introduce new features, when law changes, or when we refine our data practices. When we do, we will post the revised version on this page with an updated effective date.

If any change is material meaning it significantly affects how we handle your data, we will notify you more prominently, either by email or through a notice on the website.

We encourage you to revisit this page periodically. Continued use of the website after changes are published constitutes acceptance of the revised policy.

Definitions and Interpretation

Core Terminology

Professional Definition & Corporate Interpretation

Anonymisation

The irreversible technique of stripping personal identifiers from corporate data assets, ensuring individuals can no longer be identified. This framework preserves data utility for strategic analysis and reporting while absolute safeguarding privacy integrity.

Behavioural Advertising

The strategic practice of observing and documenting consumers' digital navigation, search history, and interactions across platforms to deploy highly targeted marketing campaigns, tailored recommendations, and personalized commercial messaging.

Binding Corporate Rules (BCRs)

A globally recognized framework of rigorous internal data protection policies implemented by multinational enterprises. BCRs authorize the cross-border transfer of proprietary personal data to affiliated operations located within jurisdictions lacking equivalent statutory protections.

Biometric Data

High-security personal datasets derived from advanced technological evaluation of an individual's unique physical, physiological, or behavioral attributes. Standard enterprise use cases include facial recognition patterns, fingerprint telemetry, and iris scanning configurations.

Consent

A voluntary, explicit, informed, and unambiguous expression of intent executed through a written statement or definitive affirmative action. This serves as the verifiable legal mandate by which a data principal explicitly authorizes the processing of their information for clear, predetermined objectives.

Cookies

Microscopic textual data elements deployed by web servers onto a user’s local computing device. These files track, catalog, and preserve user browsing paths, preferences, and operational histories to maintain seamless session continuity and enhance digital experiences.

Data Fiduciary / Data Controller

The corporate entity, public institution, non-profit organization, or designated individual that autonomously or collaboratively determines the underlying business purposes, governance methodologies, and processing parameters for all collected personal records.

Data Processing

The comprehensive lifecycle of operations executed upon personal data assets, comprising collection, digital archiving, systematic aggregation, alteration, cross-border transmission, cloud dissemination, security masking, and secure terminal destruction.

Data Protection Board / The Board

The designated sovereign regulatory authority established under the statutory mandate of the Digital Personal Data Protection Act, 2023 (DPDPA), responsible for enforcing compliance frameworks, arbitrating grievances, and penalizing operational non-compliance.

Data Retention

The internal corporate governance governance policies and schedules determining the explicit operational duration and structural frameworks required for archiving, storing, and systematically purging historical personal data assets.

Data Principal / Data Subject

The identifiable natural person—whether currently living or deceased—whose personal, professional, or digital information forms the subject matter of corporate data processing activities.

Direct Marketing

A focused commercial outreach strategy involving the deployment of physical or targeted collateral directly to consumers to pitch specific products, institutional services, or brand initiatives.

Encryption

The advanced cryptographic transmuting of plaintext information into unreadable ciphertext. This secure protocol prevents unauthorized system access, ensuring data can only be decoded by entities possessing the corresponding cryptographic decryption key.

Financial Data

Any highly sensitive alphanumeric identifier or descriptive dataset mapping an individual's transactional accounts, credit card provisions, or payment architecture. This encompasses credit history vectors, remuneration structures, and broader institutional banking relationships.

Genetic Data

Highly specialized personal information concerning an individual's inherited or acquired biological characteristics. This data provides unambiguous insights into physiological traits or health metrics, derived from the laboratory analysis of biological samples.

Health Data

Sensitive personal information detailing the physical or mental health status of an individual, including medical histories, clinical diagnoses, and health status indicators managed across healthcare or institutional networks.

Identifiable Natural Person

An individual who can be distinguished or recognized, directly or indirectly, through distinct data points such as national identity numbers, operational tracking markers, location analytics, or unique social factors.

International Organisation

An institutional entity and its auxiliary bodies governed by public international law, or established via multilateral treat agreements executed between sovereign states.

IP Address

A distinct numerical label allocated to digital hardware connected to a local network or the wider Internet, enabling seamless machine identification and packet routing across global networks.

Online Behavioural Advertising

Advanced digital marketing models that comprehensively evaluate consumer search intent, demographic variables, geographic tracking, and user profile preferences to deliver targeted commercial advertisements.

Personal Data

Any itemized or contextual information that allows for the immediate or indirect identification of an individual. This includes names, biometric indexes, online identifiers, and data gathered across offline promotional events, digital properties, or partner networks.

Personal Data Breach

Any security failure, operational lapse, or unauthorized intrusion that leads to the accidental, unlawful, or compromised destruction, alteration, unauthorized disclosure, or exposure of processed personal data.

Privacy and Data Protection

The cohesive ecosystem of statutory regulations, banking mandates, and electronic communications laws governing corporate transparency, consumer privacy, confidentiality, and data handling metrics.

Personal Data Protection Act / DPDPA

The Digital Personal Data Protection Act, 2023 (India), which serves as the supreme national regulatory framework governing the commercial collection, processing, and preservation of digital personal records.

Processor

The independent vendor or legal entity appointed under a formal service agreement to manage, transform, and execute computational operations on personal data strictly on behalf of the primary Data Controller.

Profiling

Automated or systemic analysis of personal datasets to assess, forecast, and categorize an individual’s workspace performance, financial health, lifestyle preferences, behavior patterns, or physical tracking metrics.

Pseudonymization

A critical risk-mitigation data masking practice where personal fields are decoupled from explicit identifiers, ensuring the data cannot point to a specific individual without utilizing separate, highly secure cryptographic reference parameters.

Recipient

Any external party, legal entity, public institution, or organizational body to whom corporate personal records are formally disclosed or structurally transferred.

Restriction of Processing

The intentional administrative isolation or marking of archived personal data within storage infrastructures to limit its computational utilization or access profile moving forward.

Special Categories of Personal Data

A hyper-sensitive subset of information demanding elevated corporate security protocols. This category comprises racial data, philosophical or religious beliefs, political alignments, financial and credit parameters, genetic mapping, sexual orientation, or criminal legal histories.

Supervisory Authority

The statutory, independent regulatory apparatus or administrative department tasked with enforcing data protection mandates, audit guidelines, and corporate compliance across jurisdictions.

Third-Party

Any legal entity, processing agency, public office, or individual operating outside the direct operational loop of the data subject, primary controller, or designated data processor.