Legal Information
Our commitments to you regarding privacy, service terms, cookies, refunds, and your data rights under the DPDP Act 2023.
legal@clapcle.com
Privacy Policy
Last updated: 1 June 2025
1. Who We Are and Scope of This Policy
Clapcle Infotech Private Limited ("Clapcle", "we", "us", or "our") is a company incorporated under the Companies Act 2013, with its registered office in Surat, Gujarat, India. We develop and operate cloud-based business management software including ERP, CRM, HRMS, and Bug Tracker products (collectively, the "Platform").
This Privacy Policy applies to all personal data processed by Clapcle in connection with your use of the Platform, our website at clapcle.com, and any related services. It is issued in compliance with the Digital Personal Data Protection Act 2023 ("DPDP Act") and the Information Technology Act 2000 ("IT Act").
2. Information We Collect
Account Data
- Full name, email address, mobile number, and designation
- Organisation name, GST Identification Number (GSTIN), PAN, and business address
- Account credentials (passwords stored as bcrypt hashes — never in plaintext)
- Billing and payment details processed via Razorpay (we do not store card numbers)
Business Data
- Financial records, invoices, ledger entries, and GST return data you upload or generate
- Employee records including payroll, attendance, leave, and PF/ESI details
- Sales pipeline, CRM contacts, and customer interaction logs
- Bug reports, project data, and sprint histories entered into the Bug Tracker
Technical Data
- IP address, browser type and version, operating system, and device identifiers
- Session tokens, authentication logs, and API access records
- Error logs and crash reports generated automatically
Usage Data
- Feature interactions, page views, search queries, and navigation paths within the Platform
- Support tickets, chat transcripts, and feedback submissions
- Product usage frequency and module adoption metrics (aggregated)
3. How We Use Your Information
We use the information collected for the following purposes:
- To provision, operate, and maintain the Platform under your subscription agreement
- To process subscription payments and issue GST-compliant tax invoices
- To send transactional and operational communications such as invoice receipts, account alerts, and compliance reminders
- To respond to support requests, investigate bugs, and resolve disputes
- To conduct security monitoring, fraud prevention, and access control audits
- To improve Platform features based on aggregated, anonymised usage patterns
- To send marketing communications and product updates where you have explicitly opted in
- To comply with applicable Indian laws including the DPDP Act 2023, IT Act 2000, GST Act 2017, Income Tax Act 1961, Companies Act 2013, and Factories Act / labour laws as applicable
4. Legal Basis for Processing (DPDP Act 2023)
Under the Digital Personal Data Protection Act 2023, we process personal data on the following legal grounds:
Consent
Where you have provided free, specific, informed, and unambiguous consent — for example, when subscribing to marketing communications or enabling optional analytics features.
Contractual Necessity
Processing necessary to deliver the Platform services under our subscription agreement, including account management, billing, and feature delivery.
Legal Obligation
Where processing is required by Indian law, including statutory record-keeping under the GST Act, Income Tax Act, Companies Act, Employees' Provident Funds Act, and the ESI Act.
Legitimate Interests
For fraud prevention, information security, abuse detection, and improving service reliability — provided such interests are not overridden by your data protection rights.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to any third party. We disclose data only in the following circumstances:
- Amazon Web Services India Pvt. Ltd. (AWS) — cloud hosting and infrastructure in the ap-south-1 (Mumbai) region under a data processing agreement
- Razorpay Software Pvt. Ltd. — payment processing for subscription billing; they are PCI-DSS compliant
- Communication service providers (e.g., email and SMS gateways) for transactional notifications, operating under contractual confidentiality obligations
- Government authorities, courts, or regulatory bodies where disclosure is required by law, court order, or pursuant to a lawful request by a competent authority
- Successor entities in the event of a merger, acquisition, or restructuring, subject to equivalent privacy protections
All sub-processors are bound by data processing agreements requiring at minimum the protections afforded under the DPDP Act 2023.
6. Data Storage and Security
All customer data is stored exclusively within India on Amazon Web Services infrastructure in the ap-south-1 (Mumbai) region. No personal data is transferred outside the territory of India without explicit consent or as permitted under applicable law.
Technical Safeguards
- Encryption in transit: TLS 1.3 for all client-server and inter-service communication
- Encryption at rest: AES-256 for all database volumes, backups, and object storage
- Role-based access controls (RBAC) with least-privilege principles for all internal staff
- Multi-factor authentication required for all administrative access to production systems
- Continuous vulnerability scanning and annual third-party penetration testing
- Automated anomaly detection and intrusion prevention systems
In the event of a personal data breach that poses a risk to your rights and interests, we will notify you and the Data Protection Board of India within 72 hours of becoming aware of the breach, as required under the DPDP Act 2023.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to statutory minimum retention periods prescribed under Indian law:
- Account and subscription data: duration of the active subscription plus 7 years post-termination
- GST invoices and tax records: 7 years from the end of the relevant financial year (GST Act 2017, Rule 56)
- Payroll and statutory filings (PF, ESI, TDS): 8 years from the end of the relevant assessment year (Income Tax Act 1961)
- Company financial records: 8 years as required under the Companies Act 2013
- Audit logs and system access records: 5 years or as required by SEBI/RBI/sector regulations
- Marketing consent records: until consent is withdrawn, plus 3 years for audit purposes
Personal data not subject to any statutory retention obligation will be deleted within 30 days of your account termination or upon a verified erasure request, whichever is earlier.
8. Your Rights Under the DPDP Act 2023
As a Data Principal under the Digital Personal Data Protection Act 2023, you have the following rights with respect to your personal data held by Clapcle:
- Right to Access: Obtain a summary of personal data we hold about you and the purposes for which it is being processed
- Right to Correction and Updation: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of personal data that is no longer necessary for the purposes for which it was collected, subject to statutory retention obligations
- Right to Nominate: Nominate another individual to exercise your data rights in the event of your death or incapacity
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing, without affecting the lawfulness of prior processing
- Right to Grievance Redressal: Lodge a complaint with our Grievance Officer (see Section 11) and escalate to the Data Protection Board of India if unsatisfied with our resolution
To exercise any of these rights, contact our Data Privacy Officer at privacy@clapcle.com. We will acknowledge your request within 72 hours and provide a substantive response within 30 days.
9. Cookies and Tracking Technologies
We use cookies and similar technologies on clapcle.com and the Platform. Please refer to our Cookie Policy (accessible from the sidebar) for a full breakdown of the technologies we use, their purpose, and how to manage your preferences.
We do not use cross-site tracking cookies or sell behavioural advertising data. Analytics data is collected first-party and processed in aggregate.
10. Children's Data
The Platform is designed exclusively for business use and is not intended for persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that personal data of a person under 18 has been collected without appropriate consent, we will delete it promptly. If you believe we hold such data, contact privacy@clapcle.com immediately.
11. Grievance Officer and Contact
In accordance with Rule 5(9) of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 and Section 13 of the DPDP Act 2023, we have appointed a Grievance Officer:
- Role: Data Privacy Officer
- Email: privacy@clapcle.com
- Address: Clapcle Infotech Private Limited, Shop-C-401, Amora Arcade, Utran, Chorasi, Surat – 394105, Gujarat, India
- Response time: We will acknowledge complaints within 72 hours and resolve them within 30 days
This Privacy Policy is governed by the laws of the Republic of India. Disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Surat, Gujarat.