Privacy Policy

PRIVACY POLICY Setonex Last Updated: 22 September 2026 1. Introduction This Privacy Policy explains how Shreeintech ("Company", "we", "us") collects, uses, stores, shares, and protects personal data through the Shreeintech CRM platform and the Setonex family of applications, including the Setonex web application, the Setonex Android application, and the Setonex Attendance Android application (collectively, the "Services"). This Policy is issued in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 read with the Digital Personal Data Protection Rules, 2025 ("DPDP Act"), as they come into force in phases. By creating an account, logging in, or otherwise using the Services, you agree to the collection and use of information as described in this Policy. 2. Who This Policy Applies To - Account Users -- individuals who log into the CRM, Setonex, or Setonex Attendance app on behalf of a client business ("Client"). - Data Principals of our Clients -- leads, customers, contacts, and employees whose personal data our Clients upload, generate, or process through the Services. In respect of Account Users, the Company acts as a Data Fiduciary under the DPDP Act. In respect of a Client's own leads, contacts, and employee data processed on that Client's instructions, the Company acts as a Data Processor, and the Client is the Data Fiduciary responsible for obtaining lawful consent from their own leads/employees before uploading such data. Clients are independently responsible for their own DPDP compliance for data they input into the Services. 3. Personal Data We Collect - Account & identity data: Name, email, mobile number, password (hashed), company name, role -- via signup, login, admin-created users. - Business & lead data: Lead names, phone numbers, company details, enquiry details, source (e.g. IndiaMart) -- via CRM data entry, IndiaMart Push API integration. - Communication data: WhatsApp message content, delivery/read status, message templates, campaign contact lists -- via WhatsApp Automation module. - Call metadata: Call event, caller phone number, call timestamp -- via Setonex Android app, strictly to trigger the auto-WhatsApp-after-call feature. - Location data: GPS coordinates at check-in/check-out, device timestamp -- via Setonex Attendance Android app. - Payment data: Order amount, payment ID, payment method, billing period -- we do not collect or store your card, UPI, or bank details -- via checkout / subscription billing (Razorpay). - Usage & device data: IP address, browser/device type, log timestamps, app version -- collected automatically. - Cookies: Session identifiers, authentication tokens -- web application only. 4. Purpose of Processing We process personal data only to: (1) create and manage accounts and authenticate logins; (2) provide core CRM functionality; (3) operate WhatsApp Automation, including the call-triggered auto-message feature, on behalf of the Client to their own contacts; (4) record employee attendance via GPS on the Client's instructions; (5) process subscription payments and issue invoices; (6) detect and prevent fraud or misuse; (7) comply with applicable law; (8) improve the Services via aggregated, anonymized analytics. We do not use personal data for behavioral advertising and do not sell personal data to third parties. 5. Legal Basis for Processing We process personal data on the basis of consent (given at signup/first login, and by Clients on behalf of their own data principals where required) and certain specified uses recognized under the DPDP Act, such as data voluntarily provided for a specified purpose and employment-related processing of a Client's own employees. 6. How We Share Personal Data - Razorpay Software Pvt. Ltd. -- payment processing -- order amount, billing contact, never full card/bank credentials. - IndiaMART InterMESH Ltd. -- inbound lead sync (where enabled) -- lead enquiry data pushed by IndiaMart. - Cloud hosting infrastructure providers -- storing and running the Services -- all categories above, encrypted in transit and at rest where supported. - Google (Gemini API), where AI features are used -- processing specific AI feature requests -- only data relevant to that request. - Law enforcement / regulators -- legal compliance -- only pursuant to a valid legal request. We do not permit any third party to use personal data obtained through the Services for their own independent marketing purposes. International transfer: Our hosting infrastructure may process and store data on servers located outside India. Cross-border transfer is permitted under the DPDP Act by default, except to countries specifically restricted by the Central Government. 7. Data Retention We retain personal data only as long as necessary for the purposes in Section 4, or as required by law. Upon termination of a Client's subscription, account and business data is retained for 90 days to allow for reactivation or export, after which it is permanently deleted or anonymized, unless a longer retention period is required by law. 8. Your Rights as a Data Principal Subject to the DPDP Act, you may: access a summary of your personal data; request correction or erasure; raise a grievance; withdraw consent at any time (this may limit your use of the Services); and nominate someone to exercise these rights on your behalf in the event of death or incapacity. Contact us using the details in Section 11 to exercise any of these. 9. Children's Data The Services are intended for business use by adults (18+). We do not knowingly collect children's personal data, and will delete any inadvertently collected data promptly upon discovery. 10. Data Security We use reasonable security safeguards, including encryption in transit (HTTPS/TLS), encryption of stored payment-gateway credentials at rest, role-based access controls, and secure password hashing. In the event of a personal data breach, we will notify the Data Protection Board of India and affected data principals per the timelines prescribed under the DPDP Rules. 11. Grievance & Contact For any question, complaint, or request regarding this Policy or your personal data, please reach us through the support/contact channel published on our website. If unsatisfied with our response, you may approach the Data Protection Board of India under the DPDP Act. 12. Changes to This Policy We may update this Policy from time to time. Material changes will require your explicit re-acceptance before continued use. Minor or clarificatory changes will be notified without requiring re-acceptance.