1. Introduction
iTechSarathi Private Limited, operating under the brand name iTechSarathi, respects the privacy of its customers, users, website visitors and individuals whose personal data is processed through the iTechSarathi platform.
This Privacy Policy explains how iTechSarathi collects, receives, uses, stores, shares, protects, retains and deletes personal data when a person or organization:
- visits the iTechSarathi website;
- creates or uses an iTechSarathi account;
- uses our AI-powered ERP, CRM, automation, communication, analytics or AI-agent services;
- connects a WhatsApp Business Account, Google account or another supported integration;
- communicates with us through email, telephone, WhatsApp, forms or support channels; or
- interacts with a business that uses iTechSarathi to manage its operations or communications.
By using the services, you acknowledge that personal data may be processed as described in this Privacy Policy. Where consent is legally required, we will seek consent through an appropriate notice or affirmative action.
2. Company Information
- Legal Entity: iTechSarathi Private Limited
- Brand: iTechSarathi
- Registered Office: 501 & 502, RM Arcade, Takshashila School Road, Nirant Cross Road, Near Karnavati, Vastral, Ahmedabad, Gujarat – 382415, India
- Privacy and Support Email: admin@itechsarathi.in
- Support Phone: +91 72038 23823
- Grievance Officer: Suraj Tiwari
In this Privacy Policy, "iTechSarathi," "we," "us" and "our" refer to iTechSarathi Private Limited.
3. Scope
This Privacy Policy applies to personal data processed through:
- the iTechSarathi public website;
- iTechSarathi web and mobile applications;
- customer, employee, vendor and partner portals;
- ERP, CRM, HRMS and business-operation modules;
- WhatsApp Business Platform integrations;
- Google integrations;
- AI chatbots, AI voice agents and generative-AI features;
- APIs, webhooks and automation tools;
- technical support and professional services; and
- other services that link to this Privacy Policy.
A business customer using iTechSarathi may publish its own privacy notice. When you interact with such a business, you should also review that business’s notice because the business may independently determine how and why it uses your personal data.
4. Our Role in Processing Personal Data
4.1 When iTechSarathi acts as a Data Fiduciary or controller
iTechSarathi generally determines the purpose and manner of processing for information relating to:
- website visitors and product enquiries;
- account registration and business administrators;
- subscription, billing and contract management;
- direct customer-support communications;
- security, authentication and service-usage records;
- compliance, fraud prevention and legal claims;
- iTechSarathi’s own marketing communications; and
- recruitment or employment administration undertaken by iTechSarathi.
For these activities, iTechSarathi may act as the Data Fiduciary, controller or equivalent responsible organization.
4.2 When iTechSarathi acts as a Data Processor or service provider
Business customers may use iTechSarathi to process information about their customers, leads, employees, vendors, patients, service users, dealers, distributors and other contacts. In these situations, the business customer generally determines the purpose of processing and configures the relevant modules. iTechSarathi processes the information on the customer’s documented instructions and generally acts as a Data Processor, processor or service provider.
The business customer is responsible for:
- establishing an appropriate lawful basis;
- providing required notices;
- obtaining required consent or opt-in;
- ensuring the information is collected and used lawfully;
- configuring access rights appropriately;
- responding to the individuals with whom it has a relationship; and
- complying with sector-specific and local requirements.
Our obligations to business customers may also be governed by an agreement, order form or Data Processing Agreement.
5. iTechSarathi Services
Depending on the customer’s subscription and configuration, iTechSarathi may provide modules and capabilities including:
- Customer Relationship Management;
- lead, enquiry and opportunity management;
- sales, quotation and target management;
- order and dispatch management;
- procurement, purchase and vendor management;
- inventory, stock and warehouse management;
- manufacturing, production, machine and shop-floor management;
- product, variant and bill-of-material management;
- finance, invoicing, accounting, costing and profitability reporting;
- Human Resource Management System, attendance, leave and payroll;
- project, task and workflow management;
- helpdesk, complaint and grievance management;
- appointment and calendar scheduling;
- document and knowledge management;
- WhatsApp, email and supported communication tools;
- dashboards, analytics, forecasts and reports;
- AI-generated reply suggestions and summaries;
- AI chatbots and AI voice agents;
- document, image, audio and message analysis;
- task, lead and intent detection;
- knowledge-base responses and workflow recommendations; and
- other business-operation modules introduced from time to time.
Only the information needed for the modules activated and used by a customer is intended to be processed.
6. Personal Data We May Collect
6.1 Account and business-contact information
We may collect:
- name;
- business or organization name;
- designation, department and professional role;
- business email address;
- mobile or telephone number;
- business address;
- user ID, profile information and preferences;
- authentication information;
- assigned role and permissions;
- subscription and account details; and
- communications with our sales, onboarding or support teams.
6.2 CRM, sales and customer information
When entered, imported or received under a customer’s instructions, we may process:
- customer, prospect and lead names;
- contact details;
- communication history;
- enquiries, requirements and preferences;
- quotations, orders and invoices;
- payment and transaction references;
- purchase history and follow-up activities;
- complaints, requests and support tickets; and
- other records maintained in CRM or sales modules.
6.3 ERP and operational information
Depending on the modules used, we may process:
- product, service and product-variant information;
- stock, warehouse and inventory records;
- purchase orders and vendor information;
- sales orders, dispatches and delivery information;
- manufacturing, production and quality records;
- machine, routing and shop-floor information;
- job and employee assignments;
- bill-of-material and material-consumption information;
- finance, tax, invoice, accounting and profitability records;
- project, task, approval and workflow records; and
- reports and operational analytics.
6.4 Employee and HRMS information
Where a customer enables HRMS or workforce-management modules, we may process:
- employee name and contact details;
- employee ID, role, department and reporting structure;
- attendance, shift and leave records;
- payroll and compensation information;
- bank or payment information where configured;
- performance, task and employment records;
- employment-related documents;
- emergency-contact information; and
- other workforce information entered by the employer.
The employer or business customer is responsible for providing legally required notices and obtaining any required authorization.
6.5 WhatsApp Business Platform information
When a customer connects a WhatsApp Business Account, we may process:
- Meta Business Portfolio ID;
- WhatsApp Business Account ID;
- WhatsApp Phone Number ID;
- business display name and profile information;
- display and contact phone numbers;
- customer profile names;
- message content and message metadata;
- images, documents, audio, video and other media;
- message templates, categories, languages and approval status;
- message timestamps and conversation information;
- sent, delivered, read and failed statuses;
- customer replies and interactive selections;
- webhook events;
- opt-in and opt-out records maintained through the platform;
- phone-number and account-quality information; and
- other information made available through authorized WhatsApp Business Platform APIs.
This information may be used to provide shared-inbox, CRM, chatbot, automation, campaign, support and reporting functionality.
6.6 Google integration information
Where a customer authorizes a Google integration, we may process information within the permission scope granted by the customer, such as:
- Google account identifiers;
- OAuth authorization and token references;
- calendar events, availability and appointment information;
- email or document information where the applicable integration is enabled;
- integration configuration and status; and
- technical metadata needed to operate the integration.
We do not seek access beyond the permissions required for the feature selected by the customer.
6.7 Voice, telephone and audio information
Where AI voice agents or telephony features are enabled, we may process:
- caller and recipient phone numbers;
- call date, time, duration and routing information;
- call recordings where enabled and lawfully permitted;
- transcripts and voice commands;
- agent responses and call outcomes;
- appointment and follow-up information; and
- technical call-quality information.
The business customer is responsible for giving any legally required recording, transcription or AI-processing notice.
6.8 Documents, images and uploaded files
Users may upload or transmit invoices, purchase orders, contracts, resumes, identity or employment documents, product images, spreadsheets, presentations, reports, audio, video and other files required for a selected business process. Such content may contain personal, confidential or sensitive information. Customers must ensure that they are authorized to upload and process it.
6.9 AI inputs and outputs
When AI-powered functions are used, we may process:
- prompts, instructions and user queries;
- messages and conversation context;
- documents, images, audio and extracted text;
- customer-configured knowledge-base information;
- relevant ERP or CRM context supplied to the feature;
- AI-generated replies, summaries, classifications and recommendations;
- detected tasks, leads and intentions;
- user feedback about outputs; and
- technical metadata needed to provide, protect and troubleshoot the feature.
6.10 Technical, usage and security information
We may automatically collect:
- IP address;
- browser, device and operating-system information;
- session and login timestamps;
- pages, modules and features used;
- account and audit events;
- API and integration activity;
- error, performance and diagnostic information;
- security events and alerts;
- approximate location derived from IP address; and
- cookies or similar identifiers.
6.11 Information from third parties
We may receive information from customer-authorized or operational providers, including Meta and WhatsApp, Google, Amazon Web Services and other integrations selected by a customer. Their independent processing is governed by their own terms and privacy notices.
7. How We Use Personal Data
We may process personal data to:
- create, authenticate and administer accounts;
- provide subscribed ERP, CRM, HRMS, communication, automation and AI services;
- operate customer-configured workflows and integrations;
- manage customers, leads, employees, vendors, products, orders and business records;
- process operational, accounting and reporting information;
- send and receive authorized communications;
- manage WhatsApp templates and webhook events;
- display messages in shared inboxes;
- operate AI chatbots, voice agents and assisted-response features;
- generate summaries, classifications, recommendations and reports;
- schedule appointments and follow-ups;
- provide customer service, training and technical support;
- process subscriptions, invoices and payment status;
- maintain audit trails and business records;
- secure accounts and detect fraud, spam, misuse and unauthorized access;
- monitor availability, reliability and performance;
- troubleshoot errors and improve usability;
- communicate account, billing, product and security updates;
- comply with legal and contractual obligations;
- respond to lawful requests; and
- establish, exercise or defend legal rights.
Where practical, we may use aggregated or de-identified information for analytics, capacity planning and service improvement.
8. Consent and Lawful Processing
We process personal data:
- with valid consent;
- for the specified purpose for which information was voluntarily provided;
- for legitimate uses or other grounds permitted under applicable law;
- to provide a requested or authorized service;
- where processing is required or authorized by law;
- to protect systems, users and legal rights; or
- on the documented instructions of a business customer responsible for establishing the appropriate lawful basis.
Where consent is relied upon, it may be withdrawn through an available account control or by contacting us. Withdrawal does not affect processing lawfully completed before withdrawal. Certain features may no longer be available where the information is necessary to provide them. We may continue to retain or process information where permitted or required by law.
9. WhatsApp Communications
Business customers using iTechSarathi for WhatsApp communications are responsible for:
- obtaining appropriate recipient opt-in or another lawful basis;
- providing required notices;
- maintaining evidence of consent where applicable;
- using approved templates where required;
- observing applicable messaging and customer-service-window requirements;
- respecting opt-out requests;
- avoiding misleading, unlawful or unsolicited communications; and
- complying with Meta, WhatsApp and applicable legal requirements.
A recipient may request that messages stop by using the opt-out method included in the communication, contacting the sending business or contacting iTechSarathi at admin@itechsarathi.in.
Where supported and configured, iTechSarathi may maintain suppression or opt-out records to reduce the risk of further unwanted communications.
Disconnecting a WhatsApp integration prevents the integration from receiving new information after the disconnection becomes effective. Previously processed information remains subject to the applicable retention configuration, customer instructions and legal requirements.
10. Artificial Intelligence and Automated Processing
10.1 AI features
AI-powered capabilities may include reply suggestions, conversation summaries, document and image extraction, lead and task detection, customer-intent classification, business analytics, chatbots, voice agents, appointment assistance and workflow recommendations.
10.2 Human review
AI outputs may be inaccurate, incomplete, outdated or unsuitable for the intended purpose. Users must apply appropriate human review before relying on an output for:
- medical or healthcare decisions;
- legal or regulatory decisions;
- financial, lending or credit decisions;
- employment actions;
- safety-critical activities; or
- any decision that materially affects an individual.
Unless expressly agreed and lawfully configured, iTechSarathi’s AI capabilities are designed to assist rather than replace human judgment.
10.3 AI model training
iTechSarathi does not use private Customer Data to train general-purpose models made available to unrelated third parties unless the customer has received clear notice, provided separate authorization and the processing is permitted by applicable law and contract.
Where an external enterprise or API-based AI service is used, iTechSarathi seeks to use available contractual and technical settings intended to prevent Customer Data from being used for unrelated general model training. The exact processing conditions depend on the enabled service and provider terms.
10.4 Automated decisions
iTechSarathi does not independently make legally binding decisions about individuals solely through AI unless the customer has expressly configured the process and appropriate legal, contractual and human-review safeguards are in place.
12. International Processing
Meta, Google, AWS or other customer-authorized services may process information in India or other countries depending on the selected service, cloud region, account configuration and provider infrastructure.
Where personal data is processed outside India, iTechSarathi takes reasonable steps intended to:
- use reputable providers;
- apply appropriate contractual protections;
- restrict access to authorized purposes;
- limit information to what is reasonably necessary;
- use available encryption and access controls; and
- comply with applicable cross-border restrictions.
13. Data Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, customer instruction, contract, security requirement or legal obligation.
| Information category | General retention approach |
|---|---|
| Account and administrator information | Retained while the account or business relationship remains active and for a limited period afterward for administration, security, disputes and compliance |
| Customer ERP, CRM and HRMS content | Retained according to the customer’s configuration, contract, order form or Data Processing Agreement |
| WhatsApp messages and media | Retained according to customer settings, service configuration and contractual requirements |
| Voice recordings and transcripts | Retained only where enabled and according to the customer’s configuration or contract |
| AI prompts and outputs | Retained according to the service configuration, security requirements and applicable provider settings |
| Billing and transaction records | Retained for the period required by accounting, taxation and other applicable legal requirements |
| Support communications | Retained for issue resolution, service improvement, audit and dispute purposes |
| Security, access and audit logs | Retained for periods reasonably necessary for security, fraud prevention, compliance and investigation |
| Deleted-account backups | Removed or overwritten through the ordinary protected backup-retention cycle |
When information is no longer required, it may be deleted, anonymized, aggregated, returned to the customer or securely isolated until deletion from backups.
14. Information Security
iTechSarathi maintains administrative, technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure or destruction.
Depending on the nature of the service and the current technical implementation, safeguards may include:
- encryption in transit;
- encryption or equivalent protection at rest where appropriate;
- role-based access controls;
- multi-factor authentication for privileged access;
- secure credential and token management;
- tenant and environment separation;
- logging and monitoring;
- network and infrastructure controls;
- backup and recovery procedures;
- vulnerability and patch management;
- employee confidentiality and access restrictions;
- vendor-security requirements; and
- incident-response procedures.
No internet-based service or storage system can guarantee absolute security. Customers are responsible for protecting passwords, devices, user access, API credentials and integration permissions.
15. Personal Data Breaches and Security Incidents
If iTechSarathi becomes aware of a suspected personal data breach, we may investigate, contain and remediate the incident, preserve relevant evidence, assess potential harm, notify affected business customers and assist with legally required notifications.
Where required by applicable law or contract, notifications may describe:
- the nature of the incident;
- the categories of information affected;
- known or likely consequences;
- mitigation measures taken;
- recommended protective steps; and
- contact information for further assistance.
Where iTechSarathi acts as a Data Processor, it will notify the responsible customer without undue delay after confirming a relevant incident, subject to the applicable agreement.
16. Your Privacy Rights
Subject to applicable law, identity verification and any valid limitation, an individual may request:
- information about relevant personal data and processing activities;
- correction of inaccurate or misleading data;
- completion of incomplete data;
- updating of outdated data;
- erasure of eligible data;
- withdrawal of consent;
- grievance redressal; and
- other rights available under applicable law.
These rights may be limited where processing or retention is necessary for legal compliance, security, fraud prevention, an ongoing transaction, contractual enforcement, legal claims or protection of another person’s rights.
Where information is controlled by an iTechSarathi business customer, the request should normally be submitted to that business. We may forward the request or assist the customer in responding.
17. Data Deletion Requests
Data-deletion instructions are available at:
https://itechsarathi.in/data-deletion
A request may also be emailed to:
- Email: admin@itechsarathi.in
- Subject: Privacy or Data Deletion Request
The requester should provide sufficient information to identify the relevant account, business and data and to verify identity or authority.
We may retain limited information about the request to demonstrate compliance, prevent fraud, maintain an opt-out record, resolve disputes or comply with legal obligations.
Deleting information from iTechSarathi does not automatically delete information independently held by Meta, WhatsApp, Google or another third party.
18. Account and Integration Disconnection
An authorized administrator may request disconnection through available account controls, the applicable third-party service or iTechSarathi support.
Following disconnection:
- new information will no longer be received after the disconnection becomes effective;
- related automations may stop functioning;
- previously processed information remains subject to applicable retention terms; and
- information held independently by the third-party provider remains governed by that provider.
19. Grievance Redressal
Privacy questions, complaints and grievances may be submitted to:
Grievance Officer: Suraj Tiwari
Company: iTechSarathi Private Limited
Email: admin@itechsarathi.in
Phone: +91 72038 23823
Address: 501 & 502, RM Arcade, Takshashila School Road, Nirant Cross Road, Near Karnavati, Vastral, Ahmedabad, Gujarat – 382415, India
We aim to acknowledge a privacy grievance within seven working days and resolve it within 30 calendar days. Where additional time is reasonably required, we will communicate the reason and expected completion period. We will comply with any shorter or maximum period required by applicable law.
20. Children’s Personal Data
iTechSarathi is a business software platform and is not intended for independent use by children under 18 years of age.
A business customer may use certain modules in a context involving children, such as healthcare, education or appointment management. In such cases, the business customer is responsible for determining whether the processing is appropriate, obtaining verifiable parental or guardian consent where required, providing notices, limiting access and complying with applicable child-protection requirements.
If you believe a child’s personal data has been processed improperly, contact admin@itechsarathi.in.
21. Health, Financial and Other High-Risk Information
Some customers may use iTechSarathi in sectors involving health, financial, employment, identity or other high-risk information. Customers are responsible for determining whether such data should be collected, limiting collection to what is necessary, obtaining required authorization, configuring suitable access controls and complying with sector-specific requirements.
AI-generated content must not be treated as a substitute for qualified medical, legal, financial, accounting or regulatory advice.
23. Marketing Communications
iTechSarathi may send business users information about products, features, events, service updates, training or related offerings in accordance with applicable preferences and legal requirements.
Recipients may opt out using an unsubscribe method, an available account setting or by contacting admin@itechsarathi.in. Opting out of marketing does not stop essential account, billing, security or service communications.
24. Third-Party Websites and Services
Our services may contain links to or integrations with third-party websites and products. iTechSarathi is not responsible for the independent privacy, security, availability, content or terms of third parties. Users should review the relevant provider’s policies before enabling an integration or submitting information.
25. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, AI functionality, processing practices, integrations, security controls, business operations or applicable law.
The updated version will be posted on this page with a revised “Last Updated” date. Where a change materially affects personal-data processing, we may provide additional notice or seek fresh consent where required.
26. Contact Us
For privacy questions, corrections, deletion requests, integration disconnection or grievances, contact:
iTechSarathi Private Limited501 & 502, RM Arcade
Takshashila School Road
Nirant Cross Road
Near Karnavati
Vastral, Ahmedabad
Gujarat – 382415, India
Email: admin@itechsarathi.in
Phone: +91 72038 23823
Grievance Officer: Suraj Tiwari