Privacy Policy

Effective Date: 11 July 2026 | Last Updated: 11 July 2026

1. Introduction

iTechSarathi Private Limited, operating under the brand name iTechSarathi, respects the privacy of its customers, users, website visitors and individuals whose personal data is processed through the iTechSarathi platform.

This Privacy Policy explains how iTechSarathi collects, receives, uses, stores, shares, protects, retains and deletes personal data when a person or organization:

  • visits the iTechSarathi website;
  • creates or uses an iTechSarathi account;
  • uses our AI-powered ERP, CRM, automation, communication, analytics or AI-agent services;
  • connects a WhatsApp Business Account, Google account or another supported integration;
  • communicates with us through email, telephone, WhatsApp, forms or support channels; or
  • interacts with a business that uses iTechSarathi to manage its operations or communications.

By using the services, you acknowledge that personal data may be processed as described in this Privacy Policy. Where consent is legally required, we will seek consent through an appropriate notice or affirmative action.

2. Company Information

  • Legal Entity: iTechSarathi Private Limited
  • Brand: iTechSarathi
  • Registered Office: 501 & 502, RM Arcade, Takshashila School Road, Nirant Cross Road, Near Karnavati, Vastral, Ahmedabad, Gujarat – 382415, India
  • Privacy and Support Email: admin@itechsarathi.in
  • Support Phone: +91 72038 23823
  • Grievance Officer: Suraj Tiwari

In this Privacy Policy, "iTechSarathi," "we," "us" and "our" refer to iTechSarathi Private Limited.

3. Scope

This Privacy Policy applies to personal data processed through:

  • the iTechSarathi public website;
  • iTechSarathi web and mobile applications;
  • customer, employee, vendor and partner portals;
  • ERP, CRM, HRMS and business-operation modules;
  • WhatsApp Business Platform integrations;
  • Google integrations;
  • AI chatbots, AI voice agents and generative-AI features;
  • APIs, webhooks and automation tools;
  • technical support and professional services; and
  • other services that link to this Privacy Policy.

A business customer using iTechSarathi may publish its own privacy notice. When you interact with such a business, you should also review that business’s notice because the business may independently determine how and why it uses your personal data.

4. Our Role in Processing Personal Data

4.1 When iTechSarathi acts as a Data Fiduciary or controller

iTechSarathi generally determines the purpose and manner of processing for information relating to:

  • website visitors and product enquiries;
  • account registration and business administrators;
  • subscription, billing and contract management;
  • direct customer-support communications;
  • security, authentication and service-usage records;
  • compliance, fraud prevention and legal claims;
  • iTechSarathi’s own marketing communications; and
  • recruitment or employment administration undertaken by iTechSarathi.

For these activities, iTechSarathi may act as the Data Fiduciary, controller or equivalent responsible organization.

4.2 When iTechSarathi acts as a Data Processor or service provider

Business customers may use iTechSarathi to process information about their customers, leads, employees, vendors, patients, service users, dealers, distributors and other contacts. In these situations, the business customer generally determines the purpose of processing and configures the relevant modules. iTechSarathi processes the information on the customer’s documented instructions and generally acts as a Data Processor, processor or service provider.

The business customer is responsible for:

  • establishing an appropriate lawful basis;
  • providing required notices;
  • obtaining required consent or opt-in;
  • ensuring the information is collected and used lawfully;
  • configuring access rights appropriately;
  • responding to the individuals with whom it has a relationship; and
  • complying with sector-specific and local requirements.

Our obligations to business customers may also be governed by an agreement, order form or Data Processing Agreement.

5. iTechSarathi Services

Depending on the customer’s subscription and configuration, iTechSarathi may provide modules and capabilities including:

  • Customer Relationship Management;
  • lead, enquiry and opportunity management;
  • sales, quotation and target management;
  • order and dispatch management;
  • procurement, purchase and vendor management;
  • inventory, stock and warehouse management;
  • manufacturing, production, machine and shop-floor management;
  • product, variant and bill-of-material management;
  • finance, invoicing, accounting, costing and profitability reporting;
  • Human Resource Management System, attendance, leave and payroll;
  • project, task and workflow management;
  • helpdesk, complaint and grievance management;
  • appointment and calendar scheduling;
  • document and knowledge management;
  • WhatsApp, email and supported communication tools;
  • dashboards, analytics, forecasts and reports;
  • AI-generated reply suggestions and summaries;
  • AI chatbots and AI voice agents;
  • document, image, audio and message analysis;
  • task, lead and intent detection;
  • knowledge-base responses and workflow recommendations; and
  • other business-operation modules introduced from time to time.

Only the information needed for the modules activated and used by a customer is intended to be processed.

6. Personal Data We May Collect

6.1 Account and business-contact information

We may collect:

  • name;
  • business or organization name;
  • designation, department and professional role;
  • business email address;
  • mobile or telephone number;
  • business address;
  • user ID, profile information and preferences;
  • authentication information;
  • assigned role and permissions;
  • subscription and account details; and
  • communications with our sales, onboarding or support teams.

6.2 CRM, sales and customer information

When entered, imported or received under a customer’s instructions, we may process:

  • customer, prospect and lead names;
  • contact details;
  • communication history;
  • enquiries, requirements and preferences;
  • quotations, orders and invoices;
  • payment and transaction references;
  • purchase history and follow-up activities;
  • complaints, requests and support tickets; and
  • other records maintained in CRM or sales modules.

6.3 ERP and operational information

Depending on the modules used, we may process:

  • product, service and product-variant information;
  • stock, warehouse and inventory records;
  • purchase orders and vendor information;
  • sales orders, dispatches and delivery information;
  • manufacturing, production and quality records;
  • machine, routing and shop-floor information;
  • job and employee assignments;
  • bill-of-material and material-consumption information;
  • finance, tax, invoice, accounting and profitability records;
  • project, task, approval and workflow records; and
  • reports and operational analytics.

6.4 Employee and HRMS information

Where a customer enables HRMS or workforce-management modules, we may process:

  • employee name and contact details;
  • employee ID, role, department and reporting structure;
  • attendance, shift and leave records;
  • payroll and compensation information;
  • bank or payment information where configured;
  • performance, task and employment records;
  • employment-related documents;
  • emergency-contact information; and
  • other workforce information entered by the employer.

The employer or business customer is responsible for providing legally required notices and obtaining any required authorization.

6.5 WhatsApp Business Platform information

When a customer connects a WhatsApp Business Account, we may process:

  • Meta Business Portfolio ID;
  • WhatsApp Business Account ID;
  • WhatsApp Phone Number ID;
  • business display name and profile information;
  • display and contact phone numbers;
  • customer profile names;
  • message content and message metadata;
  • images, documents, audio, video and other media;
  • message templates, categories, languages and approval status;
  • message timestamps and conversation information;
  • sent, delivered, read and failed statuses;
  • customer replies and interactive selections;
  • webhook events;
  • opt-in and opt-out records maintained through the platform;
  • phone-number and account-quality information; and
  • other information made available through authorized WhatsApp Business Platform APIs.

This information may be used to provide shared-inbox, CRM, chatbot, automation, campaign, support and reporting functionality.

6.6 Google integration information

Where a customer authorizes a Google integration, we may process information within the permission scope granted by the customer, such as:

  • Google account identifiers;
  • OAuth authorization and token references;
  • calendar events, availability and appointment information;
  • email or document information where the applicable integration is enabled;
  • integration configuration and status; and
  • technical metadata needed to operate the integration.

We do not seek access beyond the permissions required for the feature selected by the customer.

6.7 Voice, telephone and audio information

Where AI voice agents or telephony features are enabled, we may process:

  • caller and recipient phone numbers;
  • call date, time, duration and routing information;
  • call recordings where enabled and lawfully permitted;
  • transcripts and voice commands;
  • agent responses and call outcomes;
  • appointment and follow-up information; and
  • technical call-quality information.

The business customer is responsible for giving any legally required recording, transcription or AI-processing notice.

6.8 Documents, images and uploaded files

Users may upload or transmit invoices, purchase orders, contracts, resumes, identity or employment documents, product images, spreadsheets, presentations, reports, audio, video and other files required for a selected business process. Such content may contain personal, confidential or sensitive information. Customers must ensure that they are authorized to upload and process it.

6.9 AI inputs and outputs

When AI-powered functions are used, we may process:

  • prompts, instructions and user queries;
  • messages and conversation context;
  • documents, images, audio and extracted text;
  • customer-configured knowledge-base information;
  • relevant ERP or CRM context supplied to the feature;
  • AI-generated replies, summaries, classifications and recommendations;
  • detected tasks, leads and intentions;
  • user feedback about outputs; and
  • technical metadata needed to provide, protect and troubleshoot the feature.

6.10 Technical, usage and security information

We may automatically collect:

  • IP address;
  • browser, device and operating-system information;
  • session and login timestamps;
  • pages, modules and features used;
  • account and audit events;
  • API and integration activity;
  • error, performance and diagnostic information;
  • security events and alerts;
  • approximate location derived from IP address; and
  • cookies or similar identifiers.

6.11 Information from third parties

We may receive information from customer-authorized or operational providers, including Meta and WhatsApp, Google, Amazon Web Services and other integrations selected by a customer. Their independent processing is governed by their own terms and privacy notices.

7. How We Use Personal Data

We may process personal data to:

  • create, authenticate and administer accounts;
  • provide subscribed ERP, CRM, HRMS, communication, automation and AI services;
  • operate customer-configured workflows and integrations;
  • manage customers, leads, employees, vendors, products, orders and business records;
  • process operational, accounting and reporting information;
  • send and receive authorized communications;
  • manage WhatsApp templates and webhook events;
  • display messages in shared inboxes;
  • operate AI chatbots, voice agents and assisted-response features;
  • generate summaries, classifications, recommendations and reports;
  • schedule appointments and follow-ups;
  • provide customer service, training and technical support;
  • process subscriptions, invoices and payment status;
  • maintain audit trails and business records;
  • secure accounts and detect fraud, spam, misuse and unauthorized access;
  • monitor availability, reliability and performance;
  • troubleshoot errors and improve usability;
  • communicate account, billing, product and security updates;
  • comply with legal and contractual obligations;
  • respond to lawful requests; and
  • establish, exercise or defend legal rights.

Where practical, we may use aggregated or de-identified information for analytics, capacity planning and service improvement.

9. WhatsApp Communications

Business customers using iTechSarathi for WhatsApp communications are responsible for:

  • obtaining appropriate recipient opt-in or another lawful basis;
  • providing required notices;
  • maintaining evidence of consent where applicable;
  • using approved templates where required;
  • observing applicable messaging and customer-service-window requirements;
  • respecting opt-out requests;
  • avoiding misleading, unlawful or unsolicited communications; and
  • complying with Meta, WhatsApp and applicable legal requirements.

A recipient may request that messages stop by using the opt-out method included in the communication, contacting the sending business or contacting iTechSarathi at admin@itechsarathi.in.

Where supported and configured, iTechSarathi may maintain suppression or opt-out records to reduce the risk of further unwanted communications.

Disconnecting a WhatsApp integration prevents the integration from receiving new information after the disconnection becomes effective. Previously processed information remains subject to the applicable retention configuration, customer instructions and legal requirements.

10. Artificial Intelligence and Automated Processing

10.1 AI features

AI-powered capabilities may include reply suggestions, conversation summaries, document and image extraction, lead and task detection, customer-intent classification, business analytics, chatbots, voice agents, appointment assistance and workflow recommendations.

10.2 Human review

AI outputs may be inaccurate, incomplete, outdated or unsuitable for the intended purpose. Users must apply appropriate human review before relying on an output for:

  • medical or healthcare decisions;
  • legal or regulatory decisions;
  • financial, lending or credit decisions;
  • employment actions;
  • safety-critical activities; or
  • any decision that materially affects an individual.

Unless expressly agreed and lawfully configured, iTechSarathi’s AI capabilities are designed to assist rather than replace human judgment.

10.3 AI model training

iTechSarathi does not use private Customer Data to train general-purpose models made available to unrelated third parties unless the customer has received clear notice, provided separate authorization and the processing is permitted by applicable law and contract.

Where an external enterprise or API-based AI service is used, iTechSarathi seeks to use available contractual and technical settings intended to prevent Customer Data from being used for unrelated general model training. The exact processing conditions depend on the enabled service and provider terms.

10.4 Automated decisions

iTechSarathi does not independently make legally binding decisions about individuals solely through AI unless the customer has expressly configured the process and appropriate legal, contractual and human-review safeguards are in place.

11. Sharing and Disclosure

We may disclose personal data to the following categories of recipients.

11.1 Business customers and authorized users

Information processed through a customer account may be available to that customer and the users it authorizes. The customer is responsible for configuring permissions appropriately.

11.2 Service providers and subprocessors

We may use service providers for cloud hosting, databases, storage, security, authentication, WhatsApp connectivity, Google integrations, AI processing, monitoring, backup and related technical services. These providers may process information only to the extent necessary for the applicable service and subject to relevant terms and safeguards.

Our current significant subprocessors are listed at: https://itechsarathi.in/subprocessors

11.3 Meta and WhatsApp

Information may be exchanged with Meta and WhatsApp to complete Embedded Signup, connect WhatsApp Business Accounts, register and manage phone numbers, send and receive messages, manage templates, process media and receive webhook events and delivery statuses.

11.4 Google

Information may be exchanged with Google when a customer uses Google-authorized integrations or enabled AI functionality. The information shared depends on the feature, permission scope and customer configuration.

11.5 Legal and regulatory disclosures

We may disclose information where reasonably necessary to comply with applicable law, respond to a valid legal process, investigate fraud or security incidents, enforce agreements, protect rights or safety, or establish, exercise or defend legal claims.

11.6 Corporate transactions

Information may be transferred in connection with a merger, acquisition, investment, restructuring, financing or sale of business assets, subject to appropriate confidentiality and legal safeguards.

11.7 No sale of personal data

iTechSarathi does not sell or rent personal data for monetary consideration.

12. International Processing

Meta, Google, AWS or other customer-authorized services may process information in India or other countries depending on the selected service, cloud region, account configuration and provider infrastructure.

Where personal data is processed outside India, iTechSarathi takes reasonable steps intended to:

  • use reputable providers;
  • apply appropriate contractual protections;
  • restrict access to authorized purposes;
  • limit information to what is reasonably necessary;
  • use available encryption and access controls; and
  • comply with applicable cross-border restrictions.

13. Data Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, customer instruction, contract, security requirement or legal obligation.

Information categoryGeneral retention approach
Account and administrator informationRetained while the account or business relationship remains active and for a limited period afterward for administration, security, disputes and compliance
Customer ERP, CRM and HRMS contentRetained according to the customer’s configuration, contract, order form or Data Processing Agreement
WhatsApp messages and mediaRetained according to customer settings, service configuration and contractual requirements
Voice recordings and transcriptsRetained only where enabled and according to the customer’s configuration or contract
AI prompts and outputsRetained according to the service configuration, security requirements and applicable provider settings
Billing and transaction recordsRetained for the period required by accounting, taxation and other applicable legal requirements
Support communicationsRetained for issue resolution, service improvement, audit and dispute purposes
Security, access and audit logsRetained for periods reasonably necessary for security, fraud prevention, compliance and investigation
Deleted-account backupsRemoved or overwritten through the ordinary protected backup-retention cycle

When information is no longer required, it may be deleted, anonymized, aggregated, returned to the customer or securely isolated until deletion from backups.

14. Information Security

iTechSarathi maintains administrative, technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure or destruction.

Depending on the nature of the service and the current technical implementation, safeguards may include:

  • encryption in transit;
  • encryption or equivalent protection at rest where appropriate;
  • role-based access controls;
  • multi-factor authentication for privileged access;
  • secure credential and token management;
  • tenant and environment separation;
  • logging and monitoring;
  • network and infrastructure controls;
  • backup and recovery procedures;
  • vulnerability and patch management;
  • employee confidentiality and access restrictions;
  • vendor-security requirements; and
  • incident-response procedures.

No internet-based service or storage system can guarantee absolute security. Customers are responsible for protecting passwords, devices, user access, API credentials and integration permissions.

15. Personal Data Breaches and Security Incidents

If iTechSarathi becomes aware of a suspected personal data breach, we may investigate, contain and remediate the incident, preserve relevant evidence, assess potential harm, notify affected business customers and assist with legally required notifications.

Where required by applicable law or contract, notifications may describe:

  • the nature of the incident;
  • the categories of information affected;
  • known or likely consequences;
  • mitigation measures taken;
  • recommended protective steps; and
  • contact information for further assistance.

Where iTechSarathi acts as a Data Processor, it will notify the responsible customer without undue delay after confirming a relevant incident, subject to the applicable agreement.

16. Your Privacy Rights

Subject to applicable law, identity verification and any valid limitation, an individual may request:

  • information about relevant personal data and processing activities;
  • correction of inaccurate or misleading data;
  • completion of incomplete data;
  • updating of outdated data;
  • erasure of eligible data;
  • withdrawal of consent;
  • grievance redressal; and
  • other rights available under applicable law.

These rights may be limited where processing or retention is necessary for legal compliance, security, fraud prevention, an ongoing transaction, contractual enforcement, legal claims or protection of another person’s rights.

Where information is controlled by an iTechSarathi business customer, the request should normally be submitted to that business. We may forward the request or assist the customer in responding.

17. Data Deletion Requests

Data-deletion instructions are available at:
https://itechsarathi.in/data-deletion

A request may also be emailed to:

The requester should provide sufficient information to identify the relevant account, business and data and to verify identity or authority.

We may retain limited information about the request to demonstrate compliance, prevent fraud, maintain an opt-out record, resolve disputes or comply with legal obligations.

Deleting information from iTechSarathi does not automatically delete information independently held by Meta, WhatsApp, Google or another third party.

18. Account and Integration Disconnection

An authorized administrator may request disconnection through available account controls, the applicable third-party service or iTechSarathi support.

Following disconnection:

  • new information will no longer be received after the disconnection becomes effective;
  • related automations may stop functioning;
  • previously processed information remains subject to applicable retention terms; and
  • information held independently by the third-party provider remains governed by that provider.

19. Grievance Redressal

Privacy questions, complaints and grievances may be submitted to:

Grievance Officer: Suraj Tiwari

Company: iTechSarathi Private Limited

Email: admin@itechsarathi.in

Phone: +91 72038 23823

Address: 501 & 502, RM Arcade, Takshashila School Road, Nirant Cross Road, Near Karnavati, Vastral, Ahmedabad, Gujarat – 382415, India

We aim to acknowledge a privacy grievance within seven working days and resolve it within 30 calendar days. Where additional time is reasonably required, we will communicate the reason and expected completion period. We will comply with any shorter or maximum period required by applicable law.

20. Children’s Personal Data

iTechSarathi is a business software platform and is not intended for independent use by children under 18 years of age.

A business customer may use certain modules in a context involving children, such as healthcare, education or appointment management. In such cases, the business customer is responsible for determining whether the processing is appropriate, obtaining verifiable parental or guardian consent where required, providing notices, limiting access and complying with applicable child-protection requirements.

If you believe a child’s personal data has been processed improperly, contact admin@itechsarathi.in.

21. Health, Financial and Other High-Risk Information

Some customers may use iTechSarathi in sectors involving health, financial, employment, identity or other high-risk information. Customers are responsible for determining whether such data should be collected, limiting collection to what is necessary, obtaining required authorization, configuring suitable access controls and complying with sector-specific requirements.

AI-generated content must not be treated as a substitute for qualified medical, legal, financial, accounting or regulatory advice.

22. Cookies and Similar Technologies

Our website and applications may use cookies and similar technologies for authentication, session management, security, user preferences, performance monitoring, error detection and optional analytics.

Further information is available at: https://itechsarathi.in/cookie-policy

23. Marketing Communications

iTechSarathi may send business users information about products, features, events, service updates, training or related offerings in accordance with applicable preferences and legal requirements.

Recipients may opt out using an unsubscribe method, an available account setting or by contacting admin@itechsarathi.in. Opting out of marketing does not stop essential account, billing, security or service communications.

24. Third-Party Websites and Services

Our services may contain links to or integrations with third-party websites and products. iTechSarathi is not responsible for the independent privacy, security, availability, content or terms of third parties. Users should review the relevant provider’s policies before enabling an integration or submitting information.

25. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, AI functionality, processing practices, integrations, security controls, business operations or applicable law.

The updated version will be posted on this page with a revised “Last Updated” date. Where a change materially affects personal-data processing, we may provide additional notice or seek fresh consent where required.

26. Contact Us

For privacy questions, corrections, deletion requests, integration disconnection or grievances, contact:

iTechSarathi Private Limited
501 & 502, RM Arcade
Takshashila School Road
Nirant Cross Road
Near Karnavati
Vastral, Ahmedabad
Gujarat – 382415, India

Email: admin@itechsarathi.in
Phone: +91 72038 23823
Grievance Officer: Suraj Tiwari

© Copyright 2025 - iTechSarathi Pvt. Ltd.