Effective date: 23 Jul 2026 | Last updated: 26 Aug 2026 | Version 1.0
This Privacy Policy is drafted for Munafa ERP, a multi-tenant B2B distribution/trade ERP operated by Loyaltics Tech Pvt. Ltd., primarily under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 along with the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011.
This Privacy Policy applies to all users of Munafa ERP ("Platform"), including tenant organizations ("Client", "you", the business subscribing to Munafa ERP) and the individual users Client authorizes to access the Platform under its account (owners, staff, field sales personnel, accountants, distributors/dealers where given portal access). It is published by Loyaltics Tech Pvt. Ltd. ("Loyaltics", "we", "us", "our"), CIN [U58201MP2024PTC073280], registered office at TOPAZ 36, Silver Spring- II, Indore -452020.
Munafa ERP is a business-to-business product. It is not directed at consumers or children, and is not intended for use by individuals below 18 years of age acting in a personal capacity.
| Term | Meaning |
|---|---|
| Data Principal | The individual to whom the personal data relates (e.g., a Client's employee, field agent, or a dealer/distributor with portal access). |
| Data Fiduciary | The entity that determines the purpose and means of processing personal data. For data Client's own customers/dealers submit into the Platform, Client is the Data Fiduciary; Loyaltics processes that data on Client's behalf (see Data Processing Addendum). |
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Business Data | Non-personal transactional, inventory, pricing, scheme, and ledger data belonging to Client's business. |
| Processing | Any operation performed on personal data — collection, storage, use, sharing, disclosure, erasure, etc. |
3.1 Account & identity data
Name, business email, phone number, designation, employee/user ID
Business/organization details: firm name, GSTIN, PAN, billing address, bank details for settlement where applicable
Login credentials (passwords are stored hashed, never in plaintext)
3.2 Business & transactional data (Client's data, processed on Client's behalf)
Sales, purchase, inventory, ledger, journal entries, and chart of accounts
GST invoicing data: HSN codes, e-invoice/e-way bill references, tax details
Scheme, commission, and loyalty program data, including channel-partner hierarchies
Dealer/distributor/customer master data entered by Client (names, contact numbers, addresses, credit terms)
3.3 Field & device data (where field-force features are used)
Approximate or precise geolocation of field sales personnel during working hours, for attendance, beat-plan, and order-capture features (collected only with the user's device permission)
Device identifiers, OS version, app version, IP address
3.4 Usage & support data
Log data, feature usage analytics, error/crash reports
Support tickets, call recordings (if any), chat transcripts with our support team
We do not knowingly collect sensitive categories such as health data, biometric data, or financial account credentials beyond what is strictly necessary for invoicing/settlement.
Directly from Client during onboarding, KYC, and subscription setup
Directly from Data Principals when they use the Platform (login, data entry, mobile app usage)
Automatically through the Platform (logs, device data, location where permitted)
From integrated third-party systems Client connects (Tally, payment gateways, GST Suvidha Providers)
We process personal data to: (a) provide, operate, and maintain the Platform under the contract with Client; (b) authenticate users and secure accounts; (c) generate statutory documents (GST invoices, e-way bills) required by law; (d) provide customer support; (e) monitor and improve Platform performance and security; (f) comply with legal obligations, including tax, accounting, and regulatory recordkeeping; (g) communicate service updates, billing notices, and (with consent) product updates.
Under the DPDP Act, our processing basis is: (i) the Data Principal's consent, obtained via Client at the point of onboarding/account creation, and (ii) legitimate uses recognized under Section 4 of the DPDP Act, including performance of a contract, compliance with law, and employer-employee processing for field staff attendance/location tracking. Client, as Data Fiduciary for its own customers/dealers, is responsible for obtaining valid consent from those individuals before entering their data into the Platform.
Data is primarily stored and processed within India. Where any sub-processor stores or processes data outside India, we ensure such transfer complies with the DPDP Act, including any country restrictions notified by the Central Government from time to time. [Confirm and list any non-India processing locations here, or state "we do not transfer personal data outside India."]
Account and transactional data: retained for the duration of the subscription plus 8 years after termination, to align with GST and Companies Act recordkeeping norms, or as required by applicable tax/accounting law.
Field location data: retained for 1 month and used only for attendance/route reporting purposes, after which it is aggregated or deleted.
Support tickets and logs: retained for 1 month for security and audit purposes.
On termination of a Client's subscription, Client's business data is retained for 1 month to permit data export, after which it is permanently deleted or anonymized, except where retention is legally mandated.
We implement reasonable security practices under Section 43A of the IT Act and the SPDI Rules, 2011, including: encryption of data in transit (TLS 1.2+) and at rest; role-based access control and tenant data isolation in the multi-tenant architecture; password hashing; audit logging; periodic vulnerability assessment; and documented incident response procedures. No system is completely secure; we cannot guarantee absolute security but commit to promptly investigating and addressing any known vulnerability.
Under the DPDP Act, Data Principals have the right to:
Access a summary of their personal data being processed and the processing activities
Correction and completion of inaccurate or incomplete personal data
Erasure of personal data once the purpose is no longer being served, subject to legal retention requirements
Grievance redressal through our Grievance Officer (Section 11 below)
Nominate another individual to exercise these rights on their behalf in the event of death or incapacity
Withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
For data where Client is the Data Fiduciary (e.g., a dealer's data entered by Client), such requests should first be directed to Client; we will assist Client in fulfilling them as required under our Data Processing Addendum.
In accordance with the DPDP Act and IT Rules, 2011, the Grievance Officer for Loyaltics Tech Pvt. Ltd. is:
| Name | HANIT VAIRAGI |
|---|---|
| Designation | CTO |
| info@bzloyalty.com | |
| Phone | 8920889501 |
| Address | Topaz-36, Silver Spring II, Indore |
| Response time | Acknowledgement within 48 hours; resolution within 30 days as mandated under the DPDP Act |
Munafa ERP is a business tool and is not intended for use by or collection of data relating to children (individuals under 18). We do not knowingly collect children's personal data. If we become aware that we have inadvertently done so, we will delete it promptly.
If Munafa ERP is accessed via web browser or PWA, we use strictly necessary cookies/local storage for session authentication, and may use functional cookies to remember user preferences. We do not use third-party advertising cookies. [If you add analytics cookies (e.g., Google Analytics), disclose them here and provide an opt-out mechanism.]
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals/Clients as required under the DPDP Act, without undue delay, describing the nature of the breach, likely consequences, and remedial measures taken. Client will be notified within [e.g., 72 hours] of us becoming aware of a breach affecting Client's data.
We may update this Privacy Policy from time to time. Material changes will be notified to Client via email or in-app notice at least [X days] before taking effect. Continued use of the Platform after the effective date constitutes acceptance.
This Policy is governed by the laws of India. Courts at Indore, Madhya Pradesh shall have exclusive jurisdiction, subject to the dispute resolution clause in the Terms of Service.
For privacy-related questions not covered by the Grievance Officer process above:
Loyaltics Tech Pvt. Ltd.
TOPAZ 36, Silver Spring- II, Indore -452020
Email: info@bzloyalty.com