support@airawat.org # Privacy Policy
* Airawat Research Foundation * * Product: Airwat ERP App *
Last Updated: 14/07/26
1. Introduction
Airawat Research Foundation we provides Airawat ERP App Application, an enterprise resource planning solution designed to help businesses manage operations, finance, human resources, inventory, procurement, and related functions.
This Privacy Policy explains how we collect, use, store, disclose, and protect information when you or your organization Customer use the Application, whether through our web platform, desktop client, mobile app, or APIs.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
2. Scope and Roles
In most cases: - The Customer the organization that has licensed the Application acts as the Data Controller for the personal data of its employees, vendors, and customers entered into the system. - * Airawat Research Foundation * acts as the Data Processor, processing data on the Customer's behalf and instructions, in accordance with our Data Processing Agreement (DPA), where applicable.
This Policy describes our practices as both the platform provider and, where relevant, as a processor.
3. Information We Collect
3.1 Account and Registration Data
- Name, work email address, phone number, job title
- Company name, business address, tax/registration IDs
- Login credentials (encrypted)
3.2 Business Data Entered Into the ERP
Depending on the modules used, this may include: - HR & Payroll: employee names, contact details, salary, bank details, attendance, leave records, performance data - Finance & Accounting: invoices, ledgers, tax records, bank/payment details - Sales & CRM: customer names, contact information, order history - Procurement & Inventory: vendor details, purchase orders, stock records - Project Management: task assignments, timesheets, internal communications
3.3 Technical & Usage Data
- IP address, browser type, device identifiers, operating system
- Log data (login times, pages/modules accessed, actions taken)
- Cookies and similar tracking technologies (see Section 9)
3.4 Support & Communication Data
- Information provided when contacting customer support, including chat logs, emails, and call records
4. How We Use Information
We use collected information to: 1. Provide, operate, and maintain the ERP Service 2. Process transactions and generate reports (financial, HR, inventory, etc.) 3. Authenticate users and manage access control/permissions 4. Provide customer support and respond to inquiries 5. Monitor system performance, detect fraud, and ensure security 6. Send service-related notifications (updates, maintenance, security alerts) 7. Improve the Application through analytics (in aggregated/anonymized form where possible) 8. Comply with legal, regulatory, and contractual obligations 9. With consent, send marketing communications (opt-out available)
5. Legal Basis for Processing (GDPR/Applicable Law)
Where applicable data protection law requires a legal basis, we rely on: - Contractual necessity – to perform our service agreement with the Customer - Legitimate interests – e.g., system security, fraud prevention, service improvement - Legal obligation – e.g., tax, labor, or financial record-keeping laws - Consent – where required, e.g., for marketing communications
6. Data Sharing and Disclosure
We do not sell personal data. We may share information with:
| Recipient | Purpose |
|---|---|
| Cloud hosting/infrastructure providers | Hosting, storage, backups |
| Payment processors | Billing and subscription management |
| Analytics providers | Usage analytics (aggregated/anonymized where possible) |
| Professional advisors | Legal, audit, or compliance support |
| Government/regulatory authorities | When legally required (e.g., court order, tax audit) |
| Successors in a merger/acquisition | Business transfers, subject to this Policy |
All third-party processors are bound by confidentiality and data protection obligations via written agreements.
7. Data Storage and Security
- Data is stored on servers located in India.
- We use industry-standard security measures, including encryption in transit (TLS) and at rest, role-based access control (RBAC), multi-factor authentication (MFA), regular security audits, and activity logging.
- Despite these measures, no system is 100% secure. We encourage strong password practices and prompt reporting of suspected security incidents.
8. Data Retention
- We retain data for as long as the Customer's account is active or as needed to provide the Service.
- Upon termination of a subscription, data will be retained for 90 days to allow export, after which it will be securely deleted or anonymized, unless longer retention is required by law (e.g., statutory financial/tax record requirements).
9. Cookies and Tracking Technologies
We use cookies and similar technologies for: - Session management and authentication - Remembering user preferences - Analytics and performance monitoring
You can control cookies through your browser settings; disabling certain cookies may affect Application functionality.
10. Your Rights
Depending on your jurisdiction India's DPDP Act, you may have the right to: - Access the personal data we/the Customer hold about you - Correct inaccurate or incomplete data - Request deletion - Restrict or object to certain processing - Data portability - Withdraw consent (where processing is consent-based) - Lodge a complaint with a supervisory authority
Note: If you are an employee, vendor, or customer of one of our Customer organizations, requests should generally be directed to that organization first, as they control the data. Contact us at [privacy@company.com] and we will assist or forward your request accordingly.
11. International Data Transfers
If data is transferred across borders, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent legal mechanisms, as required by applicable law.
12. Children's Privacy
The Service is intended for business use by adults (employees, contractors, and business partners of our Customers) and is not directed at individuals under 18. We do not knowingly collect data from children.
13. Third-Party Integrations
The Application may integrate with third-party services (e.g., payment gateways, accounting tools, communication platforms) at the Customer's configuration. Data shared with such integrations is governed by the respective third party's privacy policy, and Customers are responsible for reviewing those terms before enabling integrations.
14. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-app notice at least [X days] before taking effect. The "Last Updated" date reflects the most recent revision.
15. Contact Us
For questions, concerns, or data subject requests regarding this Privacy Policy:
* Airawat Research Foundation * Email: support@airawat.org
Address: Technopark Phase-I building Indian Institute of Technology Kalyanpur, Kanpur, 208016 UP, India
Disclaimer: This document is a general template and does not constitute legal advice. Please have it reviewed by a qualified attorney to ensure compliance with applicable laws in your jurisdiction (e.g., GDPR, CCPA, India's DPDP Act, or other regional regulations) before publishing or using it in production.