Legal

Privacy Policy

How we collect, use, and protect your personal data at Bizmitra.

Bizmitra.io is committed to safeguarding your privacy. Contact us at mkr2005@gmail.com if you have any questions or concerns regarding the use of your Personal Data, and we will gladly assist you.

By using this site or our services, you consent to the processing of your Personal Data as described in this Privacy Policy.

Definitions Used in This Policy

Personal Data means any information that relates to an identified or identifiable living individual. Processing means any operation performed on Personal Data, such as collection, storage, use, or disclosure. Data Subject refers to the individual whose Personal Data is being processed.

Data Protection Principles We Follow

We promise to follow these data protection principles:

  • Processing is lawful, fair, and transparent.
  • Processing is limited to the purpose for which the data was collected.
  • Processing is done with minimal data.
  • Processing is limited with a defined time period.
  • We strive to ensure data accuracy, integrity, and confidentiality.

Data Storage and Hosting

Primary Infra
Akamai Cloud
Mumbai, India · Dedicated servers
Backup Infra
Hetzner
Germany · ISO-certified data centers

Both providers comply with international security standards. We use dedicated (non-shared) servers to ensure data isolation and high availability. Data is not transferred to any other location except as required for backups and service continuity.

What Rights You Have Regarding Your Personal Data

  • Access: Request a copy of the data we hold about you.
  • Rectification: Ask us to correct inaccurate personal data.
  • Erasure: Request deletion of your personal data where no legitimate grounds exist for continued processing.
  • Objection: Object to processing based on legitimate interests.
  • Portability: Receive your data in a structured, machine-readable format.

To exercise any of these rights, contact us at mkr2005@gmail.com.

What Personal Data We Collect

  • Registration Info: Name, email address, and mobile number — used solely for account creation, authentication, and automated personalized emails.
  • Location Data: Employees can share their location for check-in purposes. Used only to validate attendance, not for any other tracking.
  • Profile Photos: Selfies uploaded by employees to personalize their profiles — visible only within the app for identification.
  • Uploaded Files: Excel documents and images uploaded by ERP users — used only for the intended functionality within the app.
  • Device ID: Collected to enable secure PIN-based login functionality.

How We Use Your Personal Data

  • To create and manage your account.
  • To authenticate your login credentials.
  • To validate check-ins using location data for attendance purposes.
  • To allow you to upload and manage files as part of ERP functionalities.
  • To send automated emails for personalized communication.

Who Else Has Access to Your Personal Data

We do not share your Personal Data with any third parties. All data is used solely within the app for the purposes outlined above.

How We Secure Your Data

TLS 1.2+ Encryption SSH Key Access Only Daily Backups Fail2Ban & IP Banning
  • All traffic is encrypted using TLS 1.2+ (HTTPS).
  • Data is stored on secure, access-controlled servers with network firewalls and intrusion prevention systems.
  • Each company's data is logically isolated via unique company_id scoping at the application level.
  • Access to production systems is restricted to authorized personnel using SSH keys only; passwords are never used.
  • Regular security updates, monitoring, and logging are in place to detect and prevent unauthorized access.
  • Automated daily backups are maintained for disaster recovery.

Despite our best efforts, we cannot guarantee absolute security. In the event of a data breach, we will notify you and the appropriate authorities promptly.

Cookies and Other Technologies

  • Enhance your experience on our website.
  • Analyze website performance and usage through tools like Google Analytics.

You can manage or disable cookies through your browser settings. Note that disabling cookies may affect certain functionalities of the website.

Contact Information

If you have any questions or concerns regarding this Privacy Policy, contact us at: mkr2005@gmail.com

Legal Basis for Processing (GDPR)

  • Contractual necessity: To provide you with the ERP services you sign up for.
  • Legitimate interests: To improve and secure our platform.
  • Consent: For optional features such as cookies or location check-ins.

Changes to This Privacy Policy

We reserve the right to make changes to this Privacy Policy. Any updates will be posted on this page. Last updated: 01/10/2025.

Bizmitra Assistant