Invasystems Pvt Ltd

Privacy Policy

FieldDNA Platform  |  Effective Date: [DATE]  |  Last Updated: [DATE]
Your privacy is important to us. This Privacy Policy explains how Invasystems Pvt Ltd collects, uses, and protects information in connection with FieldDNA — our enterprise field sales automation platform. Please read it carefully.

1. Who We Are

Invasystems Pvt Ltd ("Invasystems", "we", "us", or "our") is a private limited company incorporated in India. We develop and operate FieldDNA, an enterprise SaaS platform designed to automate and optimise field sales operations for FMCG, pharmaceutical, and consumer goods companies.

For the purposes of applicable data protection law, Invasystems Pvt Ltd acts as the data controller in relation to information we collect directly from visitors to our website and from users of the FieldDNA platform. Where we process data on behalf of our enterprise customers (subscribers), we act as a data processor under the customer's instructions (see our Data Processing Agreement for details).

Registered address: [REGISTERED ADDRESS], Pune, Maharashtra, India — [PIN CODE]
CIN: [CORPORATE IDENTIFICATION NUMBER]

2. Scope of This Policy

This Privacy Policy applies to:

This Policy does not apply to data our enterprise customers upload or process using FieldDNA (e.g., their own customer records or outlet databases). That data is governed by the relevant customer's privacy policy and our Data Processing Agreement.

3. Information We Collect

3.1 Information You Provide to Us

CategoryExamplesWhen Collected
Account & identity informationFull name, work email address, job title, company name, phone numberAccount registration, demo requests, contact forms
Authentication credentialsUsername, hashed password, MFA tokensAccount creation and login
Profile dataRole, reporting hierarchy, assigned territory/beatSet up by administrator or during onboarding
CommunicationsEmails, support tickets, in-app messages, feedbackWhenever you contact us
Payment & billingBilling address, GST/tax identification, invoice records (card details handled by our payment processor)Subscription purchase and renewal

3.2 Information Collected Automatically

CategoryExamplesPurpose
Device & technical dataIP address, browser type and version, OS, device identifier, screen resolutionSecurity, compatibility, fraud prevention
Usage & activity dataPages visited, features accessed, clicks, session duration, module activity logs, reports generatedPlatform improvement, support, analytics
Location dataGPS coordinates and location history (field sales representatives using the mobile app, with in-app permission)Route optimisation, attendance and beat plan verification, compliance reporting
Log dataAccess logs, error logs, API call records, timestampsSecurity monitoring, debugging, SLA tracking
Cookies & trackingSession cookies, analytics cookies, preference cookiesAuthentication, analytics, personalisation — see our Cookie Policy

3.3 Information From Third Parties

We may receive information about you from:

4. How We Use Your Information

We use the information we collect for the following purposes:

PurposeTypes of Data Used
Providing, operating, and maintaining the FieldDNA platformAccount data, usage data, location data, credentials
Processing and managing subscriptions and billingBilling data, account data, communications
Customer support and responding to enquiriesCommunications, account data, usage logs
Platform personalisation and AI-powered recommendations (Smart Route Optimisation, Upsell & Cross-Sell)Usage data, location data, order history
Security, fraud detection, and access controlDevice data, log data, credentials
Analytics and product improvementUsage data, device data (aggregated or pseudonymised where possible)
Sending transactional communications (account alerts, password resets, billing notifications)Account data, communications
Sending marketing communications (product updates, newsletters, event invitations)Account data, communications — with consent or legitimate interest, with opt-out available
Compliance with legal obligations and enforcement of our TermsAll applicable categories
Route adherence monitoring and field activity reporting on behalf of enterprise customersLocation data, attendance data (processed as a data processor per the customer's instructions)

5. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under GDPR / UK GDPR:

For processing of location data, which may constitute sensitive processing in certain jurisdictions, we rely on your explicit consent (obtained via the mobile app permission prompt) and, where applicable, the contractual necessity of providing route optimisation services.

6. How We Share Your Information

We do not sell your personal data. We share it only as follows:

6.1 Within Our Organisation

Access to personal data is limited to employees and contractors who need it to perform their job functions, and is governed by internal access controls and confidentiality obligations.

6.2 With Enterprise Customers (Your Employer)

If you access FieldDNA as an end user through your employer's subscription, your employer has access to data relating to your platform use, attendance, location, and performance reports in their role as the data controller. Please refer to your employer's privacy policy for information on how they process this data.

6.3 With Sub-Processors and Service Providers

Service Provider CategoryPurposeData Shared
Cloud infrastructure (Microsoft Azure)Hosting, storage, computeAll platform data (encrypted at rest and in transit)
Payment processor ([e.g., Razorpay / Stripe])Subscription billingBilling address, transaction data (not card numbers)
Email delivery serviceTransactional and marketing emailsEmail address, name
Analytics providerProduct analyticsPseudonymised usage data
Customer support platformHelpdesk ticketingSupport communications, account data
Error monitoringBug tracking and debuggingLog data, device data (no PII by default)

All sub-processors are bound by data processing agreements and are required to maintain appropriate security measures.

6.4 Legal and Safety Disclosures

We may disclose information where required by law, court order, or government authority, or where necessary to protect the rights, property, or safety of Invasystems, our customers, or the public.

6.5 Business Transfers

In the event of a merger, acquisition, asset sale, or restructuring, personal data may be transferred to the acquiring entity, subject to the same privacy protections.

7. International Data Transfers

FieldDNA is hosted on Microsoft Azure infrastructure. Data may be stored and processed in Azure data centres located in India (primary) and, for certain sub-processors, in other regions including the European Economic Area or the United States.

Where we transfer personal data outside India or the EEA, we ensure appropriate safeguards are in place, such as:

8. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy, or as required by applicable law. Our standard retention practices are:

Data CategoryRetention Period
Active account dataDuration of the subscription, plus 90 days post-termination (to allow data export)
Location and attendance logsUp to 3 years (or as specified in the enterprise customer agreement)
Financial and billing records7 years (as required by Indian tax and accounting regulations)
Support communications3 years from last interaction
Marketing contact dataUntil opt-out or 3 years from last engagement, whichever is earlier
Security and access logs12 months
Anonymised analytics dataIndefinitely (as it cannot be linked back to individuals)

Upon expiry of the retention period, data is securely deleted or anonymised.

9. Security

We implement industry-standard technical and organisational measures to protect your data, including:

However, no method of transmission or storage is 100% secure. If you suspect unauthorised access to your account, please contact us immediately at security@invasystems.com.

10. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal data:

RightDescriptionApplicable Jurisdictions
AccessRequest a copy of the personal data we hold about youIndia (DPDPA), EEA/UK (GDPR)
CorrectionAsk us to correct inaccurate or incomplete dataIndia, EEA/UK, most jurisdictions
Erasure ("Right to be Forgotten")Request deletion of your data where no longer necessary or where consent is withdrawnEEA/UK, CCPA (right to delete), India (DPDPA)
RestrictionAsk us to restrict processing in certain circumstancesEEA/UK
PortabilityReceive your data in a structured, machine-readable formatEEA/UK
Object to processingObject to processing based on legitimate interests or for direct marketingEEA/UK
Opt out of sale / sharingWe do not sell data. You may opt out of data sharing for cross-context behavioural advertising.California (CCPA/CPRA)
Non-discriminationWe will not discriminate against you for exercising your rightsCalifornia (CCPA)

To exercise any of these rights, please submit a request to privacy@invasystems.com. We will respond within 30 days (or the period required by applicable law). We may need to verify your identity before fulfilling your request.

Note for enterprise users: If you access FieldDNA through your employer's subscription, some rights must be exercised through your employer as the data controller. We will redirect requests to the appropriate party where applicable.

Marketing communications: You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email or contacting us at the address below. Transactional communications (e.g., account alerts) are not subject to opt-out while your account is active.

11. Children's Privacy

FieldDNA is an enterprise business platform and is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

12. Third-Party Links

Our platform or website may contain links to third-party websites, integrations, or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party services you access through our platform.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:

Your continued use of FieldDNA after the effective date of any updated Policy constitutes your acceptance of the changes. If you disagree with a change, please stop using the platform and contact us.

14. Contact & Grievance Officer

Data Privacy & Grievance Contact

Grievance Officer (India — DPDPA/IT Act):
[Name of Grievance Officer]
Invasystems Pvt Ltd
[Address], Pune, Maharashtra — [PIN CODE], India
Email: privacy@invasystems.com
Phone: [+91 XX XXXX XXXX]
Response time: within 30 days of receipt of complaint

EU/UK Representative (if applicable):
[Representative name and contact — required under GDPR Art. 27 if you regularly process data of EU/UK data subjects]

If you are in the EEA or UK and believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In the EU, you can find your authority at edpb.europa.eu.