Privacy Policy

This Privacy policy(“Policy”) is subject to the terms of the Site Policy (User agreement) of Prophandy Technologies Pvt. Ltd. herein called Inspacco. This policy is effective from the date and time a user registers with Inspacco by filling up the Registration form and accepting the terms and conditions laid out in the Site Policy. We sincerely believe that you should always know what data we collect from you, the purposes for which such data is used, and that you should have the ability to make informed decisions about what you want to share with us. Therefore, we want to be transparent about: (i) how and why we collect, store and use your personal data in the various capacities in which you interact with us; and (ii) the rights that you have to determine the contours of this interaction.

To extend this personalized experience, Inspacco may track the IP address of a user’s computer and save certain information on your system in the form of cookies.

A user has the option of accepting or declining the cookies of this website by changing the settings of your browser. The personal information provided by the users to Inspacco will not be provided to third parties without the previous consent of the user concerned.
Information of a general nature may, however, be revealed to external parties. Every effort will be made to keep the information provided by users in a safe manner. The information that will be displayed on the website will be done so only after obtaining consent from the users. Any user browsing the site generally is not required to disclose their identity or provide any information about them. It is only at the time of registration that you will be required to furnish the details in the registration form.

A full user always has the option of not providing the information which is not mandatory. You are solely responsible for maintaining confidentiality of the User password and user identification and all activities and transmission performed by the User through their user identification and shall be solely responsible for carrying out any online or offline transaction involving credit cards, debit cards, or other forms of instruments or documents for making such transactions. Inspacco assumes no responsibility or liability for improper use of information relating to such usage of credit/debit cards used by the subscriber online/offline.

Inspacco fully complies with all applicable Indian laws. Inspacco shall always cooperate with law enforcement inquiries. Inspacco may disclose all or part of your personal details in response to a request from the law enforcement authorities or in a case of a bonafide requirement to prevent an imminent breach of the law. We are grateful to Freepik and Flaticon for their amazing free collection of images and icons.

Your Rights & Preferences as a Data Subject

Subject to the DPDPA and applicable law's limitations, the following rights are afforded to you as a data subject:

Right to Be Informed

You have a right to be informed about the manner in which any of your personal data is collected or used.

Right of Access

You have a right to access the personal data you have provided by requesting us to provide you with the same.

Right to Rectification

You have a right to request us to amend or update your personal data if it is inaccurate or incomplete.

Right to Erasure

You have a right to request us to delete your personal data.

Right to Restrict

You have a right to request us to temporarily or permanently stop processing all or some of your personal data.

Right to Object

You have an absolute right to object to us processing your personal data for the purposes of direct marketing.

Right to Data Portability

You have a right to request a copy of your personal data in electronic format for use with another service.

Right Against Automated Decisions

You have a right to not be subject to a decision based solely on automated decision-making, including profiling.

Grounds for Processing Your Data

Nature of Data Grounds
Visitor Data Consent · Performance of a Contract · Legitimate Interest
Account Registration Data Compliance with applicable laws · Legitimate Interest
Service Usage Data Performance of a Contract · Legitimate Interest
Data for Marketing Consent · Legitimate Interest

If you believe we have used your personal data in violation of these rights or have not responded to your objections, you may lodge a complaint with your local supervisory authority.

YOUR RIGHTS UNDER INFORMATION TECHNOLOGY (REASONABLE SECURITY PRACTICES AND PROCEDURES AND SENSITIVE PERSONAL DATA OR INFORMATION) RULES, 2011

Inspacco adheres to the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) to ensure your data is secure. Here's how Inspacco complies with the SPDI Rules:

Right Description
The right to be informed and give consent Before Inspacco collects any of your personal data, we will clearly explain what information we need, why we need it, and how we will use it. We will only collect your personal data with your explicit consent.
The right to access your data You have the right to request access to the personal information Inspacco holds about you. This includes the ability to review and verify its accuracy and completeness.
The right to correct mistakes If you find any errors or missing information in your data held by Inspacco, you have the right to request corrections. We will take reasonable steps to update your information promptly upon verification of your request.
The right to withdraw consent You can withdraw your consent for Inspacco to process your sensitive personal data at any time. Once you withdraw consent, we will stop using your data for the purpose originally agreed upon, unless there's a legal reason for continued processing (like a court order). To withdraw consent, please click here.

Please contact our Grievance Officer, whose details are presented in this page below, if you would like to exercise the rights listed above.

RETENTION OF PERSONAL INFORMATION

We will store any personal data we collect from you as long as it is necessary in order to facilitate your use of the Services and for ancillary legitimate and essential business purposes — these include, without limitation, for improving our Services, attending to technical issues, and dealing with disputes.

We may need to retain your personal data even if you seek deletion thereof, if it is needed to comply with our legal obligations, resolve disputes and enforce our agreements.

If you are a customer, please be advised that: (i) you will need to inform your Leads about how you store and deal with any data you collect from them using one of our Services, in compliance with applicable laws including the GDPR; and (ii) after you terminate your usage of a Service, we may, unless legally prohibited, delete all data provided or collected by you from our servers.

TOOLS USED BY OUR CUSTOMERS

If you are a Customer, you are empowered to use proprietary or other third party technologies and integrate with our App. If you do, you agree and acknowledge that it is your sole obligation to inform your stakeholders about any data you collect by using such technologies and the policies by which such collection is bound.

TRANSFER OF INFORMATION

In order for us to facilitate our operations, we may transfer and store the data we collect and process in accordance with this Policy, to our database server in a third-country for Disaster Recovery purpose. Your rights and protections will, under no circumstances, be diluted by this transfer.

Further, in the ordinary course of business, we may employ other companies and people to assist us in providing certain components of our Services in compliance with the provisions of this Policy. To do so, we may need to share your data with them.

Where applicable — if the entities to which these transfers are affected are not situated in countries deemed 'adequate' by the European Commission, we shall enter into appropriate Data Protection Addendums with the transferee parties that comprehensively protect your data. We shall also put in place industry-standard technical and organizational measures (including robust data handling policies) to ensure that such transfers are completed in accordance with applicable laws.

Some of the examples of where we may sub-contract processing activities to third parties include — data analysis, marketing assistance, processing credit card payments, and providing customer service.

COMPELLED DISCLOSURE

In addition to the purposes set out in the Policy, we may disclose any data we collected or processed from you if it is required:

  • Under applicable law or to respond to a legal process, such as a search warrant, court order, or subpoena;
  • To protect our safety, your safety or the safety of others or in the legitimate interest of any party in the context of national security, law enforcement, litigation, criminal investigation or to prevent death or imminent bodily harm;
  • If required in connection with legal proceedings brought against Inspacco, its officers, employees, affiliates, customers or vendors; or
  • To establish, exercise, protect, defend and enforce our legal rights.

SECURITY OF YOUR PERSONAL INFORMATION

We implement industry-standard technical and organizational measures by using a variety of security technologies and procedures to help protect your data from unauthorized access, use, loss, destruction or disclosure. When we collect particularly sensitive data it is encrypted using industry-standard cryptographic techniques including but not limited to SSL, TLS, RSA, and AES.

We adhere to the ISO/IEC 27001:2022 standard, an internationally recognized framework for Information Security Management Systems (ISMS). Our commitment to ISO 27001 ensures that we follow rigorous security practices and maintain high standards for information security.

In compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we adhere to the following reasonable security practices and procedures to protect your personal data:

Measure Description
Access Control We ensure that access to personal data is granted only to authorized personnel on a need-to-know basis and that such access is logged and monitored.
Data Encryption Sensitive personal data is encrypted both in transit and at rest using strong encryption methods such as AES-256.
Network Security We employ secure network architecture, including firewalls and intrusion detection systems, to prevent unauthorized access.
Regular Audits We conduct regular security audits and assessments to identify potential vulnerabilities and ensure compliance with our security policies.
Incident Management We have established protocols for managing and responding to security incidents, including data breaches, to mitigate any potential impact on your personal data.
Employee Training We conduct regular training programs for our employees to ensure they are aware of and comply with our security policies and procedures.
Third-Party Compliance We ensure that any third-party service providers who handle personal data on our behalf adhere to equivalent security standards and practices.
Physical and Environmental Security We have implemented robust physical security controls to protect our data centers and other facilities from unauthorized access, damage, and interference.
Business Continuity Management We have developed and tested business continuity plans to ensure the availability of critical information and systems in the event of a disruption.
Risk Assessment and Treatment We conduct regular risk assessments to identify potential security threats and vulnerabilities, and implement appropriate risk treatment plans to mitigate identified risks.
Audit and Compliance We conduct regular internal and external audits to ensure compliance with ISO 27001 standards and continuously improve our ISMS.

Contact Our Grievance Officer

Inspacco Grievance Officer

Velsignet Vista, S.No. 38/1/125+127, Pancard Club Road,
Behind Costa Blanca Society, Baner, Pune – 411045