Last Updated: 01-Feb-2025
Privacy Policy
This Privacy Policy describes how Acriotech Pvt. Ltd. ("Acriotech", "we", "us", or "our") collects, uses, processes, and shares information about you when you use our websites, software products, and professional services. We are committed to protecting your personal data and being transparent about how we handle it.
1. Who We Are and How to Contact Us
Acriotech is the data controller for personal data collected through our marketing website and corporate operations. For data processed as part of our enterprise software services, Acriotech acts as a data processor on behalf of our clients (who are the data controllers).
Acriotech Pvt. Ltd.
14, Shiv Narayan Complex, Virani Circle, Kaliyabid,
Bhavnagar - 364002, Gujarat, India
Data Protection Officer (DPO): privacy@acriotech.com
2. Information We Collect
We collect information in several ways, and we are deliberate about what we collect and why:
2.1 Information You Provide Directly
- Contact and Account Information: Name, email address, phone number, job title, and company name when you fill out a contact form, sign up for a demo, or create an account.
- Communications: The content of emails, messages, or support tickets you send to us. We retain these to resolve issues and improve our service.
- Payment Information: Billing name, address, and payment card information. Note: we do not store full card numbers — this data is processed directly by our PCI-DSS Level 1 certified payment processor.
- Project Data: Any data you upload, share, or create within our software platforms as part of your engagement with Acriotech.
2.2 Information Collected Automatically
- Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, time of visit, and time spent on pages. This is standard web server log data retained for 90 days.
- Cookies and Tracking: We use strictly necessary cookies for site function, and analytics cookies (with your consent) to understand usage patterns. See our Cookie Policy for full details.
- Device Information: Device type, screen resolution, and hardware configuration to ensure our software renders correctly across devices.
2.3 Information from Third Parties
We may receive information about you from third-party sources such as CRM integrations, marketing partners, or public professional networks (e.g., LinkedIn) for the purpose of identifying potential enterprise clients. Any such data is handled with the same care as directly collected data.
3. How We Use Your Information
We use the information we collect based on specific lawful bases as required by applicable privacy laws (including GDPR):
To provide and manage our software engineering services, process payments, issue invoices, and fulfill all contractual obligations under a signed Statement of Work (SOW) or Master Services Agreement (MSA).
To improve our services, conduct security monitoring, prevent fraud, perform analytics, and communicate about products that may interest enterprise clients (always with an opt-out mechanism).
To comply with applicable laws and regulations, respond to lawful requests from government authorities, and maintain financial records as required under Indian tax law.
To send marketing communications, set non-essential cookies, or process data in ways not covered above. You may withdraw consent at any time without affecting the legality of prior processing.
4. Data Sharing and Disclosure
We do not sell your personal data. We share it only in the following limited circumstances:
- Service Providers (Sub-processors): We engage vetted third-party vendors to help deliver our services, including cloud hosting (AWS, GCP), communication tools, payment processors, and analytics platforms. All sub-processors are bound by Data Processing Agreements (DPAs) that meet or exceed GDPR requirements. A current list of our sub-processors is available upon request.
- Business Transfers: In the event of a merger, acquisition, or sale of substantially all assets, your data may be transferred to the acquirer. We will notify you before any such transfer occurs and before your data becomes subject to a different privacy policy.
- Legal Requirements: We may disclose personal data if required to do so by law or in response to a valid court order, subpoena, or government request. We will attempt to notify affected individuals unless prohibited by law.
- Protection of Rights: We may disclose data if we believe in good faith that it is necessary to protect the rights, property, or safety of Acriotech, our clients, or the public.
5. Your Rights as a Data Subject
Depending on your jurisdiction, you have the following rights regarding your personal data. To exercise any of these rights, contact our DPO at privacy@acriotech.com. We will respond within 30 days.
Request a copy of all personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data where there is no legitimate reason to continue processing.
Request that we restrict the processing of your data under certain conditions.
Receive your personal data in a structured, machine-readable format to transfer to another controller.
Object to processing based on legitimate interests, including direct marketing.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Account data is retained for the duration of the contractual relationship plus 7 years (to satisfy financial record-keeping requirements under the Indian Companies Act, 2013). Anonymized analytics data may be retained indefinitely. Upon termination of an enterprise agreement, all client project data is securely deleted or returned within 60 days unless a longer retention period is required by law.
7. International Data Transfers
Acriotech is headquartered in India. If you are located in the European Economic Area (EEA) or the United Kingdom, your data may be transferred to and processed in India or other countries that may not have data protection laws equivalent to those in your jurisdiction. When we transfer personal data internationally, we use appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, and our Data Processing Addendum (DPA) incorporates these clauses by reference.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email to registered account holders at least 30 days before they take effect. Continued use of our services after the effective date constitutes acceptance of the revised policy.