+91 9822697543 contact@answerit.in Nagpur, Maharashtra, India
Mon - Fri: 9:00 AM - 6:00 PM

PRIVACY POLICY

answerIT OPC Private Limited (Website: answerit.in)

Company Legal EntityanswerIT OPC Private Limited
Applicable Websiteanswerit.in
Governing LawsDigital Personal Data Protection Act, 2023 (DPDP Act) & IT Act, 2000
Effective DateAugust 27, 2026
Policy Version1.0 (DPDP Act 2023 Aligned)
Grievance Contactlegal@answerit.in / contact@answerit.in
STATUTORY COMPLIANCE STATEMENTThis Privacy Policy is formulated in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It applies to all users, clients, and visitors accessing answerit.in and associated platforms.

1. INTRODUCTION & SCOPE

This Privacy Policy outlines how answerIT OPC Private Limited ('answerIT', 'Company', 'We', 'Us', or 'Our') collects, processes, stores, protects, and discloses Personal Data obtained through our website answerit.in and our digital platforms, products, and software services (including our SaaS products such as Kramiq).

By accessing answerit.in, registering an account, subscribing to our services, or interacting with our digital interfaces, you ('Data Principal', 'User', or 'You') acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with any terms, please discontinue platform usage immediately.

2. DEFINITIONS & KEY CONCEPTS

To ensure clarity under Indian privacy legislation, terms used herein shall carry specific statutory meanings:

Data Principal: The natural person to whom the Personal Data relates. Under the DPDP Act 2023, this includes individuals visiting answerit.in or utilizing our services.

Data Fiduciary: The entity (answerIT OPC Private Limited) which alone or jointly determines the purpose and means of processing personal data.

Data Processor: Any entity, person, or service provider processing personal data on behalf of a Data Fiduciary under a lawful contract.

Personal Data: Any data about an individual who is identifiable by or in relation to such data.

Processing: Any automated or manual operation performed on personal data, including collection, recording, organization, structuring, storage, alteration, retrieval, use, disclosure, dissemination, alignment, or erasure.

Consent: Free, specific, informed, unconditional, and unambiguous indication of the Data Principal's agreement through clear affirmative action.

3. OUR DUAL ROLES (DATA FIDUCIARY VS. DATA PROCESSOR)

Depending on how you interact with answerIT, our legal classification under the DPDP Act 2023 varies:

Data Fiduciary Role (Direct Users & Visitors): When you visit answerit.in, request demos, submit inquiry forms, create business accounts, or communicate directly with us, answerIT acts as a Data Fiduciary.

Data Processor Role (B2B SaaS Clients): When subscribing healthcare providers, clinics, or businesses deploy our SaaS platforms (such as Kramiq) to manage patient appointments or client records, the subscribing business acts as the Data Fiduciary, while answerIT operates strictly as a Data Processor under documented instructions.

4. INFORMATION WE COLLECT

We limit our collection of personal data strictly to what is necessary for fulfilling specified, lawful purposes.

4.1 Information Provided Directly by You

Identity Data: Full name, business title, designation, and professional organization.

Contact Information: Email address, mobile number, postal address, and city.

Account Credentials: Account usernames, encrypted passwords, authentication tokens, and security challenge responses.

Financial Metadata: Billing contact, company GSTIN, tax registration numbers, and payment transaction IDs. (We do not store complete credit card or debit card numbers).

Communication & Support Data: Inquiry messages, customer support chats, feedback forms, and email correspondence.

4.2 Information Collected Automatically

Technical Data: IP address, browser type and version, time zone setting, operating system, device hardware details, and network carrier info.

Usage Data: Page interaction info, clickstreams, session duration, URL referrers, feature usage statistics, and system error logs.

Messaging Metadata: Mobile numbers, timestamp headers, and delivery status logs required for automated transaction confirmations via WhatsApp, SMS, or Email.

4.3 Information We DO NOT Collect

Unless explicitly enabled under a specialized B2B contract, answerIT does not collect biometric data, genetic data, sensitive medical history, or unneeded government identifiers on answerit.in.

5. PURPOSES & LEGAL GROUNDS FOR PROCESSING

Under Sections 4, 5, 6, and 7 of the DPDP Act 2023, personal data is processed solely under lawful grounds:

5.1 Specified Lawful Purposes

Service Delivery & Provisioning: To provide, operate, and maintain answerit.in and our SaaS platforms.

Account & Billing Management: To process subscriptions, send invoices, verify credentials, and manage user accounts.

Communication & Notifications: To transmit appointment confirmations, schedule updates, security OTPs, and alerts via WhatsApp/SMS/Email.

Customer Support: To respond to inquiries, provide technical support, and resolve service issues.

Security & Platform Integrity: To detect, prevent, and mitigate security threats, fraud, unauthorized access, and cyber attacks.

Legal & Regulatory Compliance: To meet statutory obligations under Indian tax laws, IT regulations, court orders, and law enforcement directives.

5.2 Notice & Consent Framework (DPDP Sec 5 & 6)

Every request for personal data on answerit.in is accompanied by an itemized, clear notice stating the purpose of processing. Consent provided by Data Principals is voluntary, explicit, and tracked. You retain the absolute right to withdraw consent at any time.

5.3 Certain Legitimate Uses (DPDP Sec 7)

In limited circumstances, processing may occur without explicit consent where authorized by law, such as complying with court orders, medical emergency responses, or responding to lawful government inquiries.

6. DATA PROTECTION & TECHNICAL SAFEGUARDS

In compliance with Section 8(5) of the DPDP Act 2023 and the IT (Reasonable Security Practices) Rules 2011, answerIT implements robust organizational and technical safeguards:

Encryption in Transit: All data transmitted to and from answerit.in is encrypted using TLS 1.3/HTTPS protocols.

Encryption at Rest: Sensitive databases, authentication secrets, and backups are encrypted using standard AES-256 encryption.

Access Control: Strict role-based access control (RBAC), multi-factor authentication (MFA), and least-privilege administrative access.

Infrastructure Protection: Routine vulnerability scans, automated firewall protection, intrusion detection systems, and encrypted off-site backups.

Data Sovereignty & Localization: Our primary hosting infrastructure is located within Tier-III/IV data centers in Mumbai, Maharashtra, India, ensuring domestic data residency.

6.1 Personal Data Breach Management (DPDP Sec 8(6))

In the event of a personal data breach affecting data maintained by answerIT, we maintain a mandatory response workflow to contain the incident, investigate the root cause, and notify the Data Protection Board of India (DPBI) and affected Data Principals in accordance with statutory timelines.

7. DATA RETENTION & ERASURE PROTOCOLS

Under Section 8(7) of the DPDP Act 2023, answerIT shall erase personal data upon:

Consent Withdrawal: The Data Principal withdrawing consent for data processing; or

Purpose Fulfillment: The specified purpose for which data was collected no longer being served.

Retained data is purged or anonymized within standard technical backup cycles, except where retention is strictly required to comply with Indian statutory limitation periods, accounting standards, or legal disputes.

8. RIGHTS OF THE DATA PRINCIPAL

The DPDP Act 2023 grants Data Principals comprehensive rights regarding their personal data, which answerIT strictly honors:

Right to Access Information (DPDP Sec 11): Right to obtain a summary of personal data being processed, processing activities, and identities of third parties with whom data has been shared.

Right to Correction & Completion (DPDP Sec 12): Right to request correction of inaccurate or misleading data, completion of incomplete data, and updating of profile details.

Right to Erasure (DPDP Sec 12): Right to request erasure of personal data that is no longer necessary for the specified purpose, subject to legal retention overrides.

Right to Grievance Redressal (DPDP Sec 13): Right to readily available grievance redressal provided by answerIT regarding any act or omission concerning data processing obligations.

Right to Nominate (DPDP Sec 14): Right to nominate another individual who shall exercise data rights in the event of death or incapacity of the Data Principal.

9. DUTIES & OBLIGATIONS OF DATA PRINCIPALS

Under Section 15 of the DPDP Act 2023, Data Principals interacting with answerit.in must observe the following statutory duties:

Legal Compliance: Comply with all applicable provisions of Indian law while exercising data protection rights.

Authenticity: Ensure that false or impersonated identities are not submitted when providing personal data.

Truthful Claims: Refrain from registering false, frivolous, or malicious complaints or grievances.

Accurate Information: Furnish verifiably authentic details when requesting data corrections or updates.

10. THIRD-PARTY DISCLOSURES & TRANSFERS

answerIT does not sell, rent, or trade personal data to third-party marketers. Third-party disclosures occur exclusively under strict contractual obligations:

Trusted Service Processors: Disclosures to infrastructure hosts, payment gateways, and communications API providers (e.g. WhatsApp/SMS gateways) strictly for platform execution.

Statutory Disclosures: Sharing personal data when mandated by Indian law enforcement agencies, statutory authorities, or court orders.

Cross-Border Data Transfers: Cross-border transfers of personal data shall adhere strictly to Central Government notifications and restrictions under Section 16 of the DPDP Act 2023.

11. PROTECTION OF CHILDREN'S DATA

In accordance with Section 9 of the DPDP Act 2023, answerit.in does not intentionally target or collect personal data from minors (individuals under 18 years of age) without verifiable parental or lawful guardian consent. We do not engage in targeted advertising, behavioral tracking, or profiling directed at children.

12. GRIEVANCE REDRESSAL OFFICER & CONTACT DETAILS

To exercise your statutory rights or submit data protection grievances, please contact our designated Grievance Redressal Officer:

Grievance Redressal Officer: Legal & Compliance Department

Company Name: answerIT OPC Private Limited

Registered Address: 58B, Ramna Maroti Nagar, Shriprabhu Nagar, Nagpur – 440024, Maharashtra, India

Grievance Email: legal@answerit.in

General Support Email: contact@answerit.in

Contact Phone: +91 9822697543

Official Website: https://answerit.in

Response SLA: Acknowledgment within 24–48 hours; full resolution within 30 days.

13. UPDATES TO THIS PRIVACY POLICY

We review and update this Privacy Policy periodically to reflect changes in our operational practices, technology, and statutory rules issued under the DPDP Act 2023. Material changes will be published on answerit.in with an updated revision date.

14. GOVERNING LAW & JURISDICTION

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Nagpur, Maharashtra, India.