Skip to main content

Privacy policy

What personal data we collect, why we hold it, who else sees it, how long we keep it, and what you can ask us to do with it.

Awaiting legal review

This document describes how this business actually operates and is drafted against Indian law as it applies to a business-to-business reseller. It is not legal advice, and it has not yet been reviewed by the company's own adviser.

The retention periods in How long we keep it follow the statutory minimums under the Companies Act, 2013 and the CGST Act, 2017. The Digital Personal Data Protection Act, 2023 is in force but its rules are still being notified; this document is drafted to meet it, and should be revisited once those rules are final.

To remove this notice once the document has been approved, open the page in the admin panel and delete this block.

Who is responsible for your data

The company operating this website is the Data Fiduciary for the personal data described here — meaning it decides why and how that data is processed. Its registered name, registered office and contact details are on the about page, and the grievance officer for data protection matters is named at the foot of this page.

This policy covers this website, the account area, and the enquiry, quotation and order records created through them. It does not cover a publisher's own service — once a licence is provisioned into your Microsoft, Adobe, Autodesk or Zoho tenant, what happens to data in that tenant is governed by that publisher's terms and your own administrator's configuration.

What we collect, and when

When you submit an enquiry or request a quotation. Your name, business email address, telephone number, the organisation you represent, and what you told us you need. Where you ask for a formal quotation or an invoice, also your billing address and GSTIN.

When you create an account. The above, plus a password, which is stored only as a bcrypt hash and is never readable by us or recoverable in plain text.

When you place an order. The purchase order reference, the delivery contact, and the licence assignments made against the order. Where we provision into your tenant, the administrator email address needed to do it.

When you contact support. The content of the ticket and the correspondence on it.

Automatically, on every request. Your IP address, the page requested, the time, and the browser's user-agent string, recorded in server logs. Where a request fails or a security control is triggered, the same information is recorded in an audit log with the account it relates to.

What we deliberately do not collect

  • Card numbers, CVVs, net banking credentials and UPI PINs. This website processes no payments and has no payment integration; there is no field anywhere in it that accepts a payment credential.
  • Advertising or cross-site tracking data. There are no advertising pixels, no social plug-ins, no session recording and no third-party analytics on this site.
  • Sensitive personal data as defined by the SPDI Rules, 2011 — health, biometric, sexual orientation, political or religious affiliation. We have no reason to ask for it and no field that accepts it.
  • Your password in any readable form. Authentication compares a hash; a support agent cannot see, retrieve or tell you your password.

Why we process it

Under the Digital Personal Data Protection Act, 2023 we process personal data either with your consent or for a legitimate use permitted by the Act. In practice:

  • To answer your enquiry and prepare a quotation. You gave us the data for this purpose; that is the consent.
  • To perform a contract — provisioning licences, issuing invoices, providing support, managing renewals.
  • To meet a legal obligation — tax invoicing and the retention of books of account.
  • To keep the service secure — rate limiting, audit logging, and investigating misuse.
  • To tell you about a renewal that is approaching, which is a service message about something you already own rather than marketing.

We do not sell personal data, and we do not use it to build advertising profiles. We do not send marketing email to an address that only ever reached us through a support ticket.

Who else sees it

Publishers and distributors, where provisioning a licence requires it. To create a Microsoft, Adobe, Autodesk or Zoho subscription in your name we must pass the administrator's name, email address and the organisation's details to that publisher or to the distributor through whom the programme runs. Provisioning cannot happen without this, and it happens only for orders you have placed.

Our hosting and email providers, who process data on our instructions in order to run the site and deliver mail.

Professional advisers, auditors and authorities, where we are required to disclose — a lawful demand, a tax audit, or the defence of a legal claim.

That is the complete list. We do not share personal data with anyone else, and we do not transfer it as an asset except as part of a transfer of the business as a whole, in which case you would be told.

Transfers outside India. Some publishers operate their provisioning and support systems outside India. Where a licence you have ordered is provisioned through such a system, the data needed to provision it is processed there. We do not transfer personal data outside India for any other purpose.

How long we keep it

  • Enquiries that did not lead to an order3 years from last contact
  • Quotations, orders, invoices and licence records8 years — Companies Act, 2013
  • GST records72 months from the annual return — CGST Act, 2017
  • Account and profile dataFor the life of the account, then 12 months
  • Support tickets3 years from closure
  • Server request logs90 days
  • Security and audit logs12 months

The commercial retention periods are statutory minimums and we cannot shorten them on request — an invoice cannot be deleted from the books because its recipient asked. Everything outside those periods can be, and is.

Your rights

Under the Digital Personal Data Protection Act, 2023 you may:

  • ask what we hold about you, and why, and who it has been shared with;
  • have it corrected where it is wrong, incomplete or out of date — you can do most of this yourself in the account area;
  • have it erased, where we are not required to keep it for one of the reasons above;
  • nominate someone to exercise these rights on your behalf if you die or become incapacitated;
  • withdraw consent where processing rests on consent — though withdrawing it may mean we can no longer provide the service it supported;
  • complain to us, through the grievance officer below, and afterwards to the Data Protection Board of India if you are not satisfied.

To exercise any of these, write to the grievance officer named below. We will respond within thirty days. We may need to verify who you are before acting, which is a protection for you rather than an obstacle.

How it is protected

  • All traffic is served over TLS. Session cookies are marked HttpOnly, Secure and SameSite, so they cannot be read by scripts or sent from another site.
  • Passwords are stored as bcrypt hashes with a per-password salt.
  • Every state-changing request carries a CSRF token that is checked against the request's origin.
  • Staff access is role-based and least-privilege: sales staff cannot reach content administration, and content administrators cannot reach another organisation's commercial records without an audit entry.
  • Administrative actions are written to an audit log with the actor and the source address.
  • Credentials, tokens and payment fields are redacted from application logs before they are written.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as required by the Act, describing what happened, what data was involved, and what to do about it.

Cookies

This site sets two cookies, both strictly necessary, and no others. There is no analytics, advertising or tracking cookie anywhere on it. The cookie policy names each one and says what it does.

Children

This is a business service and is not directed at children. We do not knowingly collect the personal data of anyone under 18. If you believe a child's data has reached us, tell the grievance officer and it will be deleted.

Changes to this policy

We will update this policy when what we do changes, or when the law does. Where a change materially affects how we handle data you have already given us, we will tell account holders by email rather than only publishing it. The date of the last change is shown in the page footer.

Grievance redressal

If something has gone wrong and the team handling your account has not put it right, this is who to escalate to. We acknowledge a grievance within 48 hours of receiving it and aim to resolve it within one month, as required of an online seller under the Consumer Protection (E-Commerce) Rules 2020.

Details requiring configuration before launch. An online seller in India must publish a named grievance officer and their contact details. That appointment has not been configured for this deployment. Nothing here substitutes invented company information — unset values are simply omitted.

Postal address
407, 4th Floor, Pearl Business Park, Netaji Subhash Place, Pitampura, New Delhi, Delhi 110034, India

Please include your quotation or order reference, the name of your organisation, and what outcome you are looking for. A grievance raised without a reference takes longer to trace.

A question about this document

If anything here is unclear, or conflicts with a quotation or agreement you already hold, tell us before you act on it. Where a signed agreement and this page disagree, the agreement governs.