Gritticon Technologies · Legal
Privacy Policy
v1.0 · Effective 2026-08-22
What personal data Gritticon collects, the specific purpose of each item, and the rights and routes you have over it.
1. Two roles, stated plainly
This policy is published by Gritticon Technologies Private Limited ("Gritticon", "we") under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and is structured to meet the Digital Personal Data Protection Act, 2023 and its Rules as their obligations come into force.
Gritticon holds personal data in two different roles, and your rights route differently depending on which applies:
- Data Fiduciary — for visitors to gritticon.com, people who contact us, and the account holders of our customers (the school administrators and merchants who sign up). For this data, Gritticon decides the purpose and this policy governs directly.
- Data Processor — for the records our customers keep inside the products: a school’s student, parent, and staff records in Gritticon SMS and the Know Your Child app; a merchant’s customer and order records in Shop OS. We process this data only on the customer’s instructions under our contract with them. The school or merchant is the fiduciary for that data — requests about it go to them, and we assist them in answering.
2. What we collect, and the purpose of each item
We collect only what each purpose needs. Itemised:
- Name — to identify you in an enquiry or an account. Collected when you submit the contact form or an account is created.
- Email address — to respond to your enquiry, operate your account, send service and billing notices, and give notice of changes to legal documents. Collected with the contact form or at signup.
- Phone number (optional on the contact form) — to respond to your enquiry by call where you prefer that.
- School / organisation name (optional) — to prepare a relevant walkthrough and to administer the customer relationship.
- Your message — to understand and answer the enquiry you sent.
- Product interest (SMS or Shop OS) — to route your enquiry to the right team.
- Account and billing records (customers) — to provide the subscribed service, invoice correctly under GST, and meet statutory record-keeping duties.
- Technical logs (IP address, request metadata) — to secure the service, investigate incidents, and meet the CERT-In log-retention direction.
- Analytics events on gritticon.com (via Google Analytics) — to understand aggregate site usage. See section 6.
3. What we do not do
- We do not sell personal data.
- We do not share personal data with advertisers or with "partners" in the abstract. Disclosures happen only to the named categories in section 5, for the purposes named there.
- We do not use the data our customers hold in the products (student records, order records) for our own marketing.
- We do not direct behavioural advertising at children, and the Know Your Child app carries no advertising. Children’s data inside a school’s records is processed solely on the school’s instructions.
- We do not condition our services on consent to unrelated processing.
4. Consent, and withdrawing it
Where we rely on consent — the contact form, marketing emails — the consent moment is a standalone, itemised notice at the point of collection, with nothing pre-ticked and nothing bundled. You may withdraw consent at any time by writing to info@gritticon.com, and withdrawing is as easy as giving: one email. After withdrawal we stop the processing that rested on that consent; processing already done remains lawful, and data we must keep under law is kept for the statutory period only.
Account and billing data is processed to perform our contract with the customer and to meet legal obligations, and does not depend on marketing consent.
5. Where data goes
Personal data is hosted on managed cloud infrastructure in India (Mumbai region). We use a small set of sub-processors to run the business — cloud hosting, email delivery, and analytics — each under a written contract limited to the purpose named here. A current list of sub-processor categories is available on request at info@gritticon.com.
Where any sub-processor processes data outside India, we do so within the transfer rules of the DPDP framework and applicable sectoral requirements, and we say so in the sub-processor list. Payment data, where applicable, is handled within India in line with RBI directions; Gritticon does not store card numbers.
We disclose personal data to public authorities only where law requires it, and we verify the demand before answering it.
6. Cookies and analytics
gritticon.com uses Google Analytics (GA4) to measure aggregate site usage — pages visited, approximate region, device class. We use this to improve the site, not to build advertising profiles. Product applications (the school platform, the merchant app, storefronts) are not covered by this website measurement.
You can block analytics with browser settings or extensions without affecting the site’s function. Where law requires consent for this measurement, the site presents that choice before firing analytics.
7. Security practices
We follow reasonable security practices appropriate to the data we hold, aligned to recognised standards contemplated by the SPDI Rules: encryption of data in transit and at rest, role-based access control inside the products, per-tenant data isolation, scoped and expiring sessions, audit logging of sensitive operations, and separation of credentials from code. We claim only what we operate — we do not advertise certifications we do not hold.
8. Breach handling
We maintain an incident response process built to the clocks the law sets: reportable cyber incidents go to CERT-In within 6 hours of our noticing them, and when the DPDP breach provisions are in force, affected users receive intimation of what was exposed and what to do, with a report to the Data Protection Board within 72 hours. We will never promise you a slower timeline than the law demands of us.
9. Retention
- Contact-form enquiries — 24 months from our last exchange with you, then deleted.
- Account and billing records — the life of the customer relationship plus 8 years, the period Indian financial record-keeping law names.
- Technical and security logs — 180 days, stored in India, per the CERT-In Directions 2022.
- Customer Data processed for a school or merchant — retained per their instructions and our contract; on exit, exported and deleted per the Terms & Conditions (30-day export window, deletion from active systems within 60 days).
- Analytics — aggregate GA4 retention as configured, not exceeding 14 months.
10. Your rights
You may ask us to access, correct, or delete the personal data we hold about you as fiduciary, and to tell you what we hold. Write to info@gritticon.com. We answer within the grievance clocks on the Grievance Redressal page (acknowledgement within 24 hours, disposal within 15 days). When the DPDP Act’s rights provisions are in force you will additionally have the rights it names — access, correction, erasure, grievance redressal, and nomination — through the same route.
If your request concerns records held inside a school’s or merchant’s account, we will route you to that organisation, which controls that data, and assist them in answering you.
11. Changes to this policy
Material changes are notified by email and in-product at least 30 days before they take effect; a change that expands processing takes effect for you only on fresh consent. Every version carries a number and effective date, and prior versions remain reachable from the Legal versions page.
12. Contact and Grievance Officer
- Email: info@gritticon.com
- Phone: +91 98666 77408 (Monday–Friday, 9:00–18:00 IST)
- Grievance Officer: Pammi Maheswar Reddy, Director & Grievance Officer
- CIN: U58201TS2023PTC179420
- Postal address: 7-37, Datta Sai Devalayam, Peerzadiguda Road, Hyderabad, Medchal-Malkajgiri District, Telangana 500098, India
- Response clock: acknowledge within 24 hours, dispose within 15 days.
Prior versions of every legal document remain reachable from the Legal versions page. Questions or complaints: see Grievance Redressal.