This Privacy Policy describes how IA Webtech collects, uses, processes, stores, and protects personal and commercial data across our cloud SaaS business management platforms, custom software engineering engagements, and corporate digital services.
1. Purpose and Statutory Compliance
IA Webtech (Idea To Advance Web Technologies) (“Company”, “we”, “us”, “our”) is committed to maintaining the highest standards of data security, confidentiality, and regulatory compliance. This Privacy Policy is formulated in strict accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 (DPDPA) of India, and internationally recognized data protection principles (including the General Data Protection Regulation (GDPR) where applicable).
2. Scope: Data Controller vs. Data Processor
To ensure contractual and regulatory transparency, IA Webtech operates in two distinct legal capacities:
- IA Webtech as a Data Controller: We act as a Data Controller for personal data submitted directly to us for business accounts, billing and invoicing, customer support, commercial inquiries, and technical engagement administration.
- IA Webtech as a Data Processor: When commercial clients utilize our multi-tenant SaaS platforms (such as BolkarBIZ, IA BizSoft, eSchool, or Laundry Management ERP) to process organizational records (e.g., end-customer invoices, student records, inventory, tenant transactions, or staff data), the client remains the Data Controller. IA Webtech processes such operational data strictly on behalf of the client, in accordance with the governing Master Services Agreement (MSA) and client instructions.
3. Information We Collect
We collect and process only the information necessary to fulfill commercial contracts, deliver cloud software, maintain Service Level Agreements (SLAs), and process authorized transactions.
3.1 Information You Provide Directly
- Account & Commercial Contacts: Name, business email address, phone number, organization name, job title, and registered corporate address.
- Billing & Financial Information: Billing address, GSTIN / Corporate Tax Identification number, purchase order references, and payment settlement records.
- Custom Engineering & Project Data: Architectural specifications, requirements documents, database schemas, and configuration parameters shared under mutual non-disclosure agreements (NDAs) for custom development projects.
3.2 Technical Diagnostics & Telemetry
- Device & Connection Data: IP address, browser type and version, operating system, and secure session identifiers.
- Service Telemetry: Request latency, application error logs, and system performance metrics used solely for security monitoring, platform optimization, and SLA verification.
3.3 Information We Never Collect or Store
We do not collect, store, or hold sensitive payment card details (such as full 16-digit credit/debit card numbers, CVVs, PINs, or net-banking passwords) on our servers. All financial transactions are handled exclusively through PCI-DSS certified payment aggregators.
4. Payment Gateway Integration & Transaction Security
To provide secure, seamless payment processing for SaaS subscriptions, custom software retainers, and milestone billings:
- PCI-DSS Level 1 Certified Processors: All online payments are handled directly by certified, banking-grade payment gateways (including Stripe, Razorpay, CCAvenue, Cashfree, and authorized banking partners).
- End-to-End Encryption: Payment credentials are transmitted directly from your client browser to the payment processor using TLS 1.3 encryption. IA Webtech receives only tokenized payment identifiers, transaction reference IDs, settlement timestamps, and masked card identifiers (e.g., last 4 digits) for tax invoice generation.
- Multi-Factor Authentication: Transactions comply with Reserve Bank of India (RBI) directives, requiring Two-Factor Authentication (2FA) / 3D-Secure 2.0 verification (OTP or biometric authentication).
5. How We Use Your Data
We process personal and commercial data strictly under legitimate and lawful grounds, including contractual necessity and legal compliance:
- Service Provisioning: Setting up dedicated cloud database partitions, issuing software licenses, and configuring access credentials.
- Custom Development Execution: Architecting, coding, testing, and deploying custom software deliverables according to executed Statements of Work (SOW).
- Invoicing & Tax Compliance: Processing recurring subscriptions, milestone payments, and generating GST-compliant corporate invoices.
- SLA Monitoring & Support: Delivering system updates, diagnosing software defects, and fulfilling enterprise uptime commitments.
- Infrastructure Security: Protecting platforms against unauthorized intrusion, DDoS attacks, and fraudulent activity.
6. Data Architecture, Security & Custom Work SLAs
IA Webtech maintains defense-in-depth technical and organizational controls to protect client information:
- Encryption Standards: All data in transit is encrypted using TLS 1.3 / HTTPS. All database partitions, persistent storage volumes, and backups are encrypted at rest using AES-256.
- Multi-Tenant Data Isolation: SaaS applications enforce logical and structural tenant separation at the database and application tiers, preventing cross-tenant data access.
- Offline-First Architecture (BolkarBIZ): For offline-first deployments, operational data stored locally on client hardware is protected with device-level encryption and syncs to cloud storage only through secure, authenticated API handshakes.
- Confidentiality & NDAs: All proprietary source code, algorithms, and business logic developed during custom engineering engagements are treated as strictly confidential under binding mutual NDAs. Intellectual property rights are transferred upon full settlement of milestone fees.
- Service Level Agreements (SLAs): Production SaaS platforms operate under target 99.9% uptime commitments. Custom engineering engagements include defined defect remediation and severity-based incident response tiers (Severity 1 to 4) as specified in individual MSAs.
- Access Controls: Access to production databases and client code repositories is governed by the Principle of Least Privilege (PoLP), role-based access control (RBAC), multi-factor authentication (MFA), and immutable audit logs.
7. Third-Party Disclosures & Subprocessors
We never sell, rent, monetize, or trade your personal or business data to third-party data brokers or marketing agencies.
We share data only with authorized subprocessors necessary to deliver our services, under strict confidentiality and data processing agreements:
- Cloud Hosting Providers: Enterprise cloud infrastructure (AWS, Google Cloud, DigitalOcean) operating within compliant data center regions.
- Payment Gateways: Certified financial aggregators for billing settlement.
- Transactional Email & SMS: Secure enterprise notification gateways for transactional invoices, security alerts, and system notifications.
- Legal & Regulatory Authorities: Only when strictly mandated by applicable law, valid judicial subpoena, or regulatory directive under Indian jurisdiction.
8. Data Retention & Secure Disposal
- Active Subscriptions: Client operational data is retained for the duration of the active contractual term.
- Post-Termination Grace Period: Following subscription cancellation, database partitions are preserved for thirty (30) calendar days to enable data export or reactivation. After 30 days, tenant data is permanently purged from production systems.
- Statutory Retention: Invoices, tax records, and transactional logs are retained for seven (7) years in accordance with statutory requirements under Indian corporate and tax legislation.
9. Your Rights as a Data Subject
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable international frameworks, you have the right to:
- Access & Portability: Obtain confirmation of data processing and request a structured copy of your personal data.
- Correction & Updating: Request rectification of inaccurate, incomplete, or obsolete information.
- Erasure: Request the deletion of personal data no longer necessary for contractual or statutory purposes.
- Grievance Redressal: Submit inquiries or grievances directly to our designated Grievance Officer.
10. Grievance Officer & Corporate Contact Details
In compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer and corporate contact channels are provided below:
- Company Legal Entity: IA Webtech (Idea To Advance Web Technologies)
- Designated Grievance Officer: Legal & Compliance Officer
- Grievance & Privacy Email: privacy@iawebtech.com
- Corporate Legal Desk: legal@iawebtech.com
- Billing & Payment Desk: billing@iawebtech.com
- Telephone: +91 8307857276
- Registered Corporate Address:
J1001, Sidhartha NCR One, Sector 95,
Gurugram 122505, Haryana, India.
All privacy inquiries and grievances will be acknowledged within forty-eight (48) hours and resolved within thirty (30) business days.