Privacy Policy

  • Effective date: 23 Jul 2026 | Last updated: 26 Aug 2026 | Version 1.0

    This Privacy Policy is drafted for Munafa ERP, a multi-tenant B2B distribution/trade ERP operated by Loyaltics Tech Pvt. Ltd., primarily under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 along with the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011.

1. Who This Policy Covers
  • This Privacy Policy applies to all users of Munafa ERP ("Platform"), including tenant organizations ("Client", "you", the business subscribing to Munafa ERP) and the individual users Client authorizes to access the Platform under its account (owners, staff, field sales personnel, accountants, distributors/dealers where given portal access). It is published by Loyaltics Tech Pvt. Ltd. ("Loyaltics", "we", "us", "our"), CIN [U58201MP2024PTC073280], registered office at TOPAZ 36, Silver Spring- II, Indore -452020.

    Munafa ERP is a business-to-business product. It is not directed at consumers or children, and is not intended for use by individuals below 18 years of age acting in a personal capacity.

2. Definitions
TermMeaning
Data Principal The individual to whom the personal data relates (e.g., a Client's employee, field agent, or a dealer/distributor with portal access).
Data Fiduciary The entity that determines the purpose and means of processing personal data. For data Client's own customers/dealers submit into the Platform, Client is the Data Fiduciary; Loyaltics processes that data on Client's behalf (see Data Processing Addendum).
Personal Data Any data about an individual who is identifiable by or in relation to such data.
Business Data Non-personal transactional, inventory, pricing, scheme, and ledger data belonging to Client's business.
Processing Any operation performed on personal data — collection, storage, use, sharing, disclosure, erasure, etc.
3. Data We Collect
  • 3.1 Account & identity data

    Name, business email, phone number, designation, employee/user ID

    Business/organization details: firm name, GSTIN, PAN, billing address, bank details for settlement where applicable

    Login credentials (passwords are stored hashed, never in plaintext)

  • 3.2 Business & transactional data (Client's data, processed on Client's behalf)

    Sales, purchase, inventory, ledger, journal entries, and chart of accounts

    GST invoicing data: HSN codes, e-invoice/e-way bill references, tax details

    Scheme, commission, and loyalty program data, including channel-partner hierarchies

    Dealer/distributor/customer master data entered by Client (names, contact numbers, addresses, credit terms)

  • 3.3 Field & device data (where field-force features are used)

    Approximate or precise geolocation of field sales personnel during working hours, for attendance, beat-plan, and order-capture features (collected only with the user's device permission)

    Device identifiers, OS version, app version, IP address

  • 3.4 Usage & support data

    Log data, feature usage analytics, error/crash reports

    Support tickets, call recordings (if any), chat transcripts with our support team

  • We do not knowingly collect sensitive categories such as health data, biometric data, or financial account credentials beyond what is strictly necessary for invoicing/settlement.

4. How We Collect It
  • Directly from Client during onboarding, KYC, and subscription setup

  • Directly from Data Principals when they use the Platform (login, data entry, mobile app usage)

  • Automatically through the Platform (logs, device data, location where permitted)

  • From integrated third-party systems Client connects (Tally, payment gateways, GST Suvidha Providers)

5. Purpose & Legal Basis for Processing
  • We process personal data to: (a) provide, operate, and maintain the Platform under the contract with Client; (b) authenticate users and secure accounts; (c) generate statutory documents (GST invoices, e-way bills) required by law; (d) provide customer support; (e) monitor and improve Platform performance and security; (f) comply with legal obligations, including tax, accounting, and regulatory recordkeeping; (g) communicate service updates, billing notices, and (with consent) product updates.

    Under the DPDP Act, our processing basis is: (i) the Data Principal's consent, obtained via Client at the point of onboarding/account creation, and (ii) legitimate uses recognized under Section 4 of the DPDP Act, including performance of a contract, compliance with law, and employer-employee processing for field staff attendance/location tracking. Client, as Data Fiduciary for its own customers/dealers, is responsible for obtaining valid consent from those individuals before entering their data into the Platform.

7. Cross-Border Data Transfer
  • Data is primarily stored and processed within India. Where any sub-processor stores or processes data outside India, we ensure such transfer complies with the DPDP Act, including any country restrictions notified by the Central Government from time to time. [Confirm and list any non-India processing locations here, or state "we do not transfer personal data outside India."]

8. Data Retention
  • Account and transactional data: retained for the duration of the subscription plus 8 years after termination, to align with GST and Companies Act recordkeeping norms, or as required by applicable tax/accounting law.

  • Field location data: retained for 1 month and used only for attendance/route reporting purposes, after which it is aggregated or deleted.

  • Support tickets and logs: retained for 1 month for security and audit purposes.

  • On termination of a Client's subscription, Client's business data is retained for 1 month to permit data export, after which it is permanently deleted or anonymized, except where retention is legally mandated.

9. Security Measures
  • We implement reasonable security practices under Section 43A of the IT Act and the SPDI Rules, 2011, including: encryption of data in transit (TLS 1.2+) and at rest; role-based access control and tenant data isolation in the multi-tenant architecture; password hashing; audit logging; periodic vulnerability assessment; and documented incident response procedures. No system is completely secure; we cannot guarantee absolute security but commit to promptly investigating and addressing any known vulnerability.

10. Rights of Data Principals
  • Under the DPDP Act, Data Principals have the right to:

  • Access a summary of their personal data being processed and the processing activities

  • Correction and completion of inaccurate or incomplete personal data

  • Erasure of personal data once the purpose is no longer being served, subject to legal retention requirements

  • Grievance redressal through our Grievance Officer (Section 11 below)

  • Nominate another individual to exercise these rights on their behalf in the event of death or incapacity

  • Withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal

  • For data where Client is the Data Fiduciary (e.g., a dealer's data entered by Client), such requests should first be directed to Client; we will assist Client in fulfilling them as required under our Data Processing Addendum.

11. Grievance Officer
  • In accordance with the DPDP Act and IT Rules, 2011, the Grievance Officer for Loyaltics Tech Pvt. Ltd. is:

NameHANIT VAIRAGI
DesignationCTO
Emailinfo@bzloyalty.com
Phone8920889501
AddressTopaz-36, Silver Spring II, Indore
Response timeAcknowledgement within 48 hours; resolution within 30 days as mandated under the DPDP Act
12. Children's Data
  • Munafa ERP is a business tool and is not intended for use by or collection of data relating to children (individuals under 18). We do not knowingly collect children's personal data. If we become aware that we have inadvertently done so, we will delete it promptly.

13. Cookies & Tracking Technologies
  • If Munafa ERP is accessed via web browser or PWA, we use strictly necessary cookies/local storage for session authentication, and may use functional cookies to remember user preferences. We do not use third-party advertising cookies. [If you add analytics cookies (e.g., Google Analytics), disclose them here and provide an opt-out mechanism.]

14. Personal Data Breach Notification
  • In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals/Clients as required under the DPDP Act, without undue delay, describing the nature of the breach, likely consequences, and remedial measures taken. Client will be notified within [e.g., 72 hours] of us becoming aware of a breach affecting Client's data.

15. Changes to This Policy
  • We may update this Privacy Policy from time to time. Material changes will be notified to Client via email or in-app notice at least [X days] before taking effect. Continued use of the Platform after the effective date constitutes acceptance.

16. Governing Law & Jurisdiction
  • This Policy is governed by the laws of India. Courts at Indore, Madhya Pradesh shall have exclusive jurisdiction, subject to the dispute resolution clause in the Terms of Service.

17. Contact Us
  • For privacy-related questions not covered by the Grievance Officer process above:

    Loyaltics Tech Pvt. Ltd.

    TOPAZ 36, Silver Spring- II, Indore -452020

    Email: info@bzloyalty.com