Effective Date: Immediate upon posting or account creation.
1. Introduction, Scope & Corporate Structure
This Privacy Policy (“Policy”) governs the collection, processing, storage, disclosure, and protection of personal data by EquipRoute, a proprietary Software-as-a-Service (SaaS) platform owned, operated, and maintained by Systenics Solutions LLP (“Company”, “we”, “our”, “us”).
This Policy is formulated to comply strictly with applicable Indian data protection and information technology laws, including the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
EquipRoute provides a comprehensive business process and warehouse management SaaS platform tailored exclusively for business enterprise operations (“Enterprise Clients”, “you”, “your”).
2. User Eligibility & Business-Only Restrictions
- Business Enterprise Use Only: The platform is strictly intended for legitimate business and commercial operations. It is not designed or intended for individual consumer or personal household use.
- Age Restriction: Individuals under eighteen (18) years of age are expressly prohibited from registering an account, accessing, or using the EquipRoute platform.
- No Tracking of Minors: We do not knowingly collect, process, or track personal data of minors. EquipRoute does not engage in behavioral tracking, profiling, or targeted advertising directed at children.
3. Consent Framework & Roles under the DPDP Act, 2023
A. Direct User Consent
We collect and process personal data belonging to account administrators or primary account holders only after receiving clear, affirmative, and unambiguous consent. Consent is obtained via an un-ticked check box presented during registration. By checking the box and creating an account, you actively consent to the processing of your data in accordance with this Policy.
B. Enterprise Client as Data Fiduciary; EquipRoute as Data Processor
For employee data, end-user account credentials, or operational files entered into EquipRoute by Enterprise Clients:
- The Enterprise Client acts as the Data Fiduciary under the DPDP Act, 2023, determining the purpose and means of data processing.
- Systenics Solutions LLP / EquipRoute acts strictly as a Data Processor, processing personal data solely on behalf of, and pursuant to the documented instructions of, the Enterprise Client.
- Client Warranty: The Enterprise Client warrants, represents, and covenants that it has provided all statutory notices and obtained all necessary explicit consents from its employees, staff, contractors, and end-users before uploading or processing their personal data on the EquipRoute platform.
C. Right to Withdraw Consent
You retain the right to withdraw your consent at any time by written notice to our Designated Grievance Officer. Withdrawal of consent may result in the immediate restriction or termination of your access to the SaaS platform. Statutory data retention obligations (such as tax and accounting compliance) shall survive consent withdrawal as permitted under applicable law.
When navigating or utilizing our platform, we automatically aggregate non-personal metrics, including:
- Device hardware identifiers, browser types, operating systems, and IP addresses.
- Page navigation history, clickstream data, session durations, and feature utilization metrics.
- Aggregated telemetry data used exclusively to optimize system performance, evaluate promotional effectiveness, and maintain infrastructure stability.
During registration, onboarding, billing, or technical support interactions, we collect:
- Full name, corporate job title, business name, and business email address.
- Registered office address, billing address, and tax registration identifiers (e.g., GSTIN, PAN).
- Support ticket logs and communication history.
Required data fields are clearly demarcated during registration; optional fields may be omitted at your discretion.
5. Technical & Reasonable Security Practices (RSPP)
In compliance with Section 43A of the IT Act, 2000 and Section 8(5) of the DPDP Act, 2023, Systenics Solutions LLP implements industry-standard Technical and Organizational Measures (TOMs) to safeguard personal data, including:
- Encryption: Data in transit is encrypted using TLS 1.3 / SSL 256-bit encryption; stored databases and file repositories are encrypted at rest using AES-256 standards.
- Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) govern administrative access.
- Vulnerability & Incident Management: Continuous infrastructure monitoring, periodic vulnerability assessments, automated patch management, and secure off-site backups.
While we enforce rigorous security safeguards, no electronic transmission or cloud storage environment can be guaranteed 100% immune from security threats.
6. Data Retention, Account Deletion & Purging Policy
We strictly adhere to purpose-limitation lifecycles for all client data:
- Active Subscriptions: Client data and personal files are securely maintained during the active subscription lifecycle.
- Lapse / Non-Renewal Grace Period: If a platform subscription lapses or is terminated, a mandatory ninety (90) day grace period commences. During this window, data remains read-only for account recovery or subscription reactivation.
- Permanent Data Purging: Upon the expiration of the 90-day grace period, all databases, files, and personal data associated with the account will be permanently deleted and securely purged from our servers, backup systems, and third-party hosting infrastructure.
- Statutory Exceptions: Personal data required to be retained under statutory Indian laws (e.g., GST records, income tax filings, corporate audit compliance) shall be archived for the minimum period mandated by law and purged thereafter.
7. Third-Party Sharing, Sub-processors & Statutory Disclosures
We do not sell, rent, lease, or trade personal data to third parties. Data transfers occur strictly under the following operational or statutory conditions:
- Authorized Service Providers / Sub-processors: We may share data with vetted third-party infrastructure providers (e.g., cloud hosting facilities, transactional email engines, SMS gateways) operating under strict data processing agreements and confidentiality obligations.
- Statutory & Legal Obligations: We may disclose personal data to courts, law enforcement agencies, statutory regulatory bodies, or the Data Protection Board of India (DPBI) when compelled by a valid legal subpoena, judicial order, or statutory rule under Indian law.
- Corporate Restructuring: In the event of a merger, acquisition, corporate reorganization, asset sale, or joint venture involving Systenics Solutions LLP, client data may be securely transferred to the acquiring or successor legal entity under equivalent privacy protections.
8. Rights of the Data Principal & DPBI Complaints
Under the DPDP Act, 2023, Data Principals possess specific statutory rights regarding their personal data, exercisable by submitting a written request to our Grievance Officer:
- Right to Access & Summary: Obtain a summary of personal data held by us and processing activities performed.
- Right to Correction & Updating: Request immediate correction, completion, or updating of inaccurate or outdated files.
- Right to Erasure: Request premature erasure of personal data, subject to statutory retention limits.
- Right to Grievance Redressal: Submit grievances regarding data processing directly to our Grievance Officer.
- Right to Complain to DPBI: In accordance with Section 13 of the DPDP Act, 2023, if you are unsatisfied with the response or resolution provided by our Grievance Officer, you have the statutory right to register a formal complaint with the Data Protection Board of India (DPBI).
9. Disclaimer of Warranties, Limitation of Liability & Terms of Service
A. Disclaimer of Warranties
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE EQUIPROUTE PLATFORM IS PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. SYSTENICS SOLUTIONS LLP EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE PLATFORM WILL BE UNINTERRUPTED, TIMELY, SECURE, ERROR-FREE, OR FREE OF BUGS OR SERVICE OUTAGES.
B. Exclusion of Indirect, Special, and Consequential Damages
IN NO EVENT SHALL SYSTENICS SOLUTIONS LLP, EQUIPROUTE, ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, OR AFFILIATES BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF SAVINGS, LOSS OF DATA, BUSINESS INTERRUPTION, REPUTATIONAL DAMAGE, OR WAREHOUSE OPERATIONAL DISRUPTIONS, ARISING OUT OF OR IN CONNECTION WITH THE USE OR INABILITY TO USE THE PLATFORM, REGARDLESS OF THE LEGAL THEORY (CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
C. Maximum Aggregate Liability Cap
NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED IN THIS PRIVACY POLICY OR ELSEWHERE, THE TOTAL AGGREGATE LIABILITY OF SYSTENICS SOLUTIONS LLP AND EQUIPROUTE FOR ALL CLAIMS, LOSSES, DAMAGES, DEMANDS, OR CAUSES OF ACTION ARISING OUT OF OR RELATING TO THIS POLICY OR THE PLATFORM SHALL BE STRICTLY LIMITED TO THE ACTUAL AMOUNT PAID BY YOU TO SYSTENICS SOLUTIONS LLP FOR ACCESS TO THE EQUIPROUTE PLATFORM IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE INCIDENT GIVING RISE TO LIABILITY, OR INR 10,000 (WHICHEVER IS LESS).
D. Governance by Master Terms of Service
Proprietary software rights, intellectual property ownership, reverse engineering prohibitions, license transfer restrictions, and detailed commercial SLA terms are governed by the EquipRoute Master Terms and Conditions, which is incorporated herein by reference.
10. Client Indemnification
You agree to defend, indemnify, and hold harmless Systenics Solutions LLP, EquipRoute, its directors, officers, employees, and agents from and against any and all third-party claims, lawsuits, liabilities, damages, penalties, losses, costs, and expenses (including reasonable legal fees) arising out of or related to:
- Your breach of this Privacy Policy or applicable data privacy laws;
- Any personal data, files, or records uploaded or processed on the platform without requisite authority or statutory employee consent;
- Your failure to comply with statutory tax, GSTIN, or regulatory rules; or
- Misuse of platform credentials by your employees, staff, or representatives.
11. Governing Law, Exclusive Jurisdiction & Mandatory Arbitration
- Governing Law: This Privacy Policy shall be governed by and construed in accordance with the substantive laws of the Republic of India.
- Exclusive Jurisdiction: Subject to arbitration below, any legal action, suit, or proceeding arising out of or relating to this Privacy Policy or EquipRoute shall be subject to the exclusive jurisdiction of the competent Courts located in Mumbai, Maharashtra, India.
- Mandatory Arbitration: Any dispute, controversy, or claim arising out of or relating to this Policy or the breach thereof shall be settled by binding arbitration in accordance with the Arbitration and Conciliation Act, 1996 (as amended). The arbitration tribunal shall consist of a sole arbitrator appointed mutually by Systenics Solutions LLP and the client. The seat and venue of arbitration shall be Mumbai, India, and the language of proceedings shall be English.
12. Grievance Redressal & Designated Grievance Officer
In compliance with Section 10 of the Information Technology Rules, 2011 and Section 12 of the DPDP Act, 2023, the contact details of the Designated Grievance Officer for EquipRoute / Systenics Solutions LLP are published below:
- Title: Designated Grievance & Data Protection Officer
- Company: Systenics Solutions LLP (EquipRoute Division)
- Physical Address: The Affaires, Unit #F-1, 1st Floor, Plot #9, Sector - 17, Opp. Bhumiraj Costarica, Sanpada, Navi Mumbai - 400705, Maharashtra, India
- Grievance Email: info@equiproute.com
Communication & Redressal Timelines
- Acknowledgement: All formal privacy grievances and data protection queries will be acknowledged within 48 business hours of receipt.
- Resolution Window: Valid grievances will be formally investigated and resolved within fifteen (15) to thirty (30) calendar days, as mandated under applicable statutory guidelines.
- Technical Support: Routine customer support queries receive best-effort responses within two (2) Indian business days, following the operating holiday calendar of India.
13. Policy Updates & Notifications
Systenics Solutions LLP reserves the right to modify or update this Privacy Policy at any time to reflect legal, regulatory, or operational changes. The updated version will be posted on our platform with a revised “Last Updated” timestamp. Material changes will be communicated via email or platform notification prior to taking effect. Continued use of the EquipRoute platform following such posting constitutes acceptance of the revised Privacy Policy.
For general privacy inquiries or data rights requests, please contact our privacy team at info@equiproute.com.