Privacy Policy

How we collect, use, and safeguard personal information across the Jovaris CRM web portal and mobile apps.

Effective 7 June 2026

01 · Introduction

Jovaris Tech ("Jovaris Tech", "we", "us", or "our") operates Jovaris CRM, an internal customer-relationship-management application provided as a web portal at www.jovariscrm.com and as companion Android and iOS apps (collectively, the "Services"), for use by our authorised employees, agents, and administrators. This Privacy Policy explains what personal information we collect, how we use it, the choices you have, and the safeguards we apply.

We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. By using the Services you confirm that you have read and understood this Policy.

02 · Information We Collect

We collect the following categories of information:

Information you provide

  • Account & profile details — name, email address, phone number, employee ID, role, photo, designation, department, and branch.
  • Work records you enter — lead and customer information you create or are assigned on behalf of the company.
  • Uploaded files — documents and images you attach to lead or customer records.
  • Communications — support requests, feedback, and other messages you send us.

Information collected automatically

  • Attendance location — your device's GPS coordinates captured only at the moment you check in or check out for attendance. We do not track your location in the background.
  • Device & network data — device model, operating-system version, IP address, and connection type.
  • Diagnostic data — limited crash and error logs used to keep the apps stable.

Information from third parties

  • Employment / agency records — your status and reporting hierarchy, where your organisation provisions your account.

We do not use third-party advertising networks, social media trackers, or cross-site analytics tools, and we do not collect a device advertising identifier.

03 · How We Use Your Information

We process personal data for the following purposes:

  • To authenticate you and provide access to the Services.
  • To record attendance and verify your check-in / check-out location.
  • To manage the leads and customer records assigned to you.
  • To enable coordination between agents, employees, and administrators.
  • To debug errors, prevent fraud, and protect the platform.
  • To comply with applicable legal, regulatory, and audit requirements.

Under the DPDP Act, our lawful basis is your consent (provided during registration), the performance of your employment or agency relationship with us, compliance with our legal obligations under labour and tax law, and our legitimate interest in operating, securing, and improving the Services.

04 · How We Share Information

We share data only as described below. We do not sell your personal data.

  • Service providers — application hosting (Vercel), database (Supabase / PostgreSQL), file storage (Cloudflare R2), and email delivery — each bound by contractual confidentiality and data-processing obligations.
  • Internal personnel — administrators, IT, HR, and compliance staff on a strict need-to-know basis.
  • Legal & safety — to comply with applicable law, court orders, or lawful requests, and to enforce our terms or protect rights, property, or safety.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with notice to affected users.

05 · Data Retention

We retain personal data only as long as needed for the purposes set out in this Policy or as required by law. Typical retention periods:

  • Account & profile data: while your account is active.
  • Attendance & check-in location records: retained for the period required under applicable labour and tax law (generally at least three years).
  • Lead & customer records: retained per company record-keeping requirements; anonymised when linked to a deleted account.
  • Diagnostic / crash logs: up to 90 days.

When retention is no longer necessary we securely delete or irreversibly anonymise the data.

06 · Security

We apply technical and organisational measures, including:

  • TLS 1.2+ encryption in transit and AES-256 encryption at rest.
  • Role-based access control following the principle of least privilege.
  • Idle-session timeout that signs you out after a period of inactivity.
  • Automated backups and data-processing agreements with all sub-processors.

No system is perfectly secure. If we become aware of a personal-data breach likely to cause harm, we will notify affected users and the Data Protection Board of India as required under the DPDP Act.

07 · Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request erasure, subject to legal retention obligations.
  • Withdraw consent at any time.
  • Receive a copy of your data in a machine-readable format (Settings → Download my data).
  • Nominate another person to exercise your rights in the event of death or incapacity.
  • Lodge a grievance with our Grievance Officer (Section 12) or with the Data Protection Board of India.

To exercise any right, email info@jovariscrm.com. We respond within 30 days and may verify your identity before fulfilling sensitive requests.

08 · Account Deletion

You may request deletion of your account at any time by:

On deletion we immediately anonymise your personal identifiers (name, email, phone, and photo) and, within 30 days, permanently remove associated uploaded files and irreversibly hash any residual identifier. Work records such as leads and customers may be retained in anonymised form where required for legal, audit, or business-continuity purposes.

09 · Children

The Services are intended for authorised adult employees and agents and are not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child's data has been provided to us, contact our Grievance Officer and we will delete it promptly.

10 · International Transfers

Our primary infrastructure is operated in India. Some service providers may process data in other jurisdictions. When data is transferred outside India we ensure the recipient applies safeguards consistent with the DPDP Act and that contractual protections (Standard Contractual Clauses or equivalent) are in place.

11 · Changes to This Policy

We may update this Policy from time to time. Material changes will be notified through the Services and, where appropriate, by email. The "Effective" date at the top of this page indicates when the latest version took effect.

12 · Contact & Grievance Officer

For privacy questions or to file a grievance under the DPDP Act, contact our Grievance Officer:

Email: info@jovariscrm.com
Web: www.jovariscrm.com/support

We respond to all grievances within 30 days of receipt.