1Who we are
Easarc Technologies Private Limited (“Easarc”, “we”, “us”) is a private limited company incorporated on 4 July 2026 under the Companies Act, 2013, bearing CIN U62011GJ2026PTC180081, with its registered office at 20 Pramukh Park, Soc Mota Varachha, Mota Varachha, Chorasi, Surat – 394101, Gujarat, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Easarc is a Data Fiduciary in respect of personal data we collect about visitors to this website and about the individual users of our products. Where we process personal data on behalf of a customer — for example the buyer contact details inside that customer’s Easarc Flow workspace — we act as a Data Processor under that customer’s instructions, and the data processing addendum governs that relationship.
2Personal data we collect
We collect the following categories of personal data.
- Contact and account data. Name, work email address, phone number, company name, designation and preferred language. Collected when you submit an enquiry, start a trial, or are added as a user by your organisation.
- Usage data. Pages viewed, features used, actions taken in the product, timestamps, and the workspace and role under which they occurred. Used to operate the service, to support you and to work out what to build next.
- Technical data. IP address, browser and device type, operating system, and referring URL. Retained in server and application logs.
- Billing data. Billing name, address, GSTIN and PAN, invoice history and payment status. We do not store card numbers, UPI handles or bank credentials; payments are handled by our payment gateway, which is a separate Data Fiduciary for that data.
- Customer content. The operational data you put into our products — orders, buyers, quantities, rates, inspection footage, support conversations. This may contain personal data about your own staff and buyers. We process it as a Processor, not for our own purposes.
- Recruitment data. If you apply for a role, the CV and correspondence you send us.
3Why we process it, and on what basis
Under the DPDP Act we process personal data either with your consent or for a legitimate use permitted by the Act. In practice:
- To provide the service you asked for. Creating your account, running your workspace, generating your invoices, and giving you support. Processed for the specified purpose for which you voluntarily provided the data.
- With your consent. Marketing email, and any non-essential analytics. Consent is requested clearly, and you can withdraw it at any time with the same ease as you gave it.
- To comply with law. Retention of invoices and tax records under the GST and income tax legislation, and responses to lawful requests from a competent authority.
- To keep the service safe. Detecting abuse, debugging failures and maintaining the audit log.
We do not sell personal data, and we do not share it with third parties for their own advertising.
4Cookies and analytics
This website sets a single first-party cookie to remember your theme preference. It carries no identifier and is not used for tracking. The product sets a first-party session cookie that is strictly necessary to keep you logged in.
We use privacy-preserving, self-hosted analytics that record page views without setting a cookie or building a cross-site profile. We do not embed advertising pixels or third-party trackers on this site.
5Where your data lives
All production data is stored and processed in the AWS ap-south-1 (Mumbai) region, inside India. Backups remain in the same region.
A small number of our operational tools — email, our helpdesk and our error tracker — are operated by providers outside India, and limited personal data (typically your name, email address and support correspondence) reaches them. We transfer such data only to countries not restricted by the Central Government under section 16 of the DPDP Act, and under contractual protections. Customer content in Flow, Vision and Desk is not transferred out of India.
6Who we share it with
- Infrastructure. Amazon Web Services India Private Limited, for hosting in the Mumbai region.
- Payments. Our payment gateway, for collecting and reconciling payments and issuing GST invoices.
- Communications. Our transactional email provider and, where you have opted into WhatsApp updates, the WhatsApp Business API provider.
- Professional advisers. Our chartered accountants and legal advisers, bound by professional confidentiality.
- Authorities. Where we are legally required to disclose, and only to the extent required. We will tell you unless we are prohibited from doing so.
- A successor. If the company is acquired or merges, personal data may transfer as part of that transaction, subject to this policy.
7How long we keep it
- Account and contact data — for as long as your account is active, and 90 days after closure.
- Customer content — for as long as your subscription runs, then 90 days, during which you can export it in full. After that it is deleted from live systems, and from backups within a further 35 days.
- Inspection clips — per your plan retention setting: 30 days on Vision Starter, 90 days on Growth, negotiated on Enterprise.
- Invoices and tax records — eight years, as required under Indian tax law. This is a legal obligation and survives a deletion request.
- Server logs — 90 days. Audit logs — as long as the account, plus one year.
- Recruitment data — twelve months from your last contact with us, unless you ask us to delete it sooner.
8Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Obtain a summary of the personal data we process about you and the processing activities we undertake.
- Obtain the identities of other Data Fiduciaries and Processors with whom we have shared it, and a description of what was shared.
- Have inaccurate or incomplete personal data corrected, completed or updated.
- Have your personal data erased, unless retention is required for a legal purpose.
- Nominate another individual to exercise these rights on your behalf if you die or become incapable of doing so.
- Withdraw a consent you previously gave, at any time.
- Have a grievance addressed by us before approaching the Data Protection Board of India.
Write to support@easarctech.com to exercise any of these. We respond within 30 days. If you are a user inside a customer’s workspace, we may need to route your request through that customer, since they determine what happens to that data — we will tell you if so.
9Children
Our products are business software and are not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child’s data has reached us, write to us and we will delete it.
10Security
We take reasonable security safeguards to prevent a personal data breach, including encryption in transit (TLS 1.2 or better) and at rest (AES-256, with keys in AWS KMS), role-based access control, least-privilege access for our own staff, an append-only audit log, and regular patching of our infrastructure.
If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal without delay, in the form and manner required by the DPDP Act and the rules under it.
11Grievance officer
In accordance with the DPDP Act and the Information Technology (Intermediary Guidelines) Rules, our Grievance Officer can be reached at:
Grievance Officer
Easarc Technologies Private Limited
20 Pramukh Park, Soc Mota Varachha, Mota Varachha, Chorasi, Surat – 394101, Gujarat, India
support@easarctech.com
We acknowledge a grievance within 24 hours and resolve it within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.
12Changes to this policy
We will update this page when our practices change, and revise the “last updated” date at the top. If a change materially affects how we use your personal data, we will tell you by email before it takes effect.