InfynoSpark Brand Mark
INFYNOSPARK
INFYNOSPARK LEGAL & GOVERNANCE DIRECTIVE

Privacy Policy & Data Security Directive

Last Updated: September 24, 2026 Effective Date: January 1, 2026

InfynoSpark Systems Pvt. Ltd. ("InfynoSpark") is committed to total transparency, hardware-backed data security, and full compliance with India's DPDP Act 2023, DPDP Rules 2025, and global GDPR guidelines. Policy Version: 2026.1

Executive Summary & Key Commitments

DPDP Act 2023 & Rules 2025 Compliant: Itemized consent architecture, purpose specification, and 100% Indian Cloud Data Sovereignty.
Zero Raw Biometric Storage: Hardware minutiae hashing directly inside TPM 2.0 enclaves before cloud transmission.
Zero Data Monetization: We never sell, rent, or trade client, student, parent, or employee data to advertising networks.

01. Corporate Identity & Service Architecture

InfynoSpark Systems Pvt. Ltd. ("InfynoSpark", "we", "us") operates as an enterprise IT Services, Digital Transformation Consultancy, and provider of the flagship InfynoSecure SaaS ERP platform. Data protection, biometric hardware confidentiality, and international compliance are embedded directly into our software architecture.

02. Digital Personal Data Protection (DPDP) Act 2023 & Rules 2025

In accordance with India's DPDP Act 2023 and DPDP Rules 2025, InfynoSpark acts as a Data Fiduciary and Data Processor. We process personal data exclusively based on explicit, itemized consent for clear, specified business purposes. Data Principals retain rights to withdraw consent, request corrections, and demand permanent erasure at any time.

03. Hardware Minutiae & Zero Raw Biometric Storage

Our BioSecure edge terminals process fingerprint and facial minutiae directly inside hardware secure enclaves. Raw biometric imagery is converted into 256-bit cryptographic minutiae vectors via SHA-256 with TPM 2.0 salting. Only tokenized hashes are transmitted over TLS 1.3 encrypted streams to our cloud ERP servers. Reconstructing raw biological images from these tokenized vectors is mathematically impossible.

04. Categories of Data Collected

We collect and process the following data categories: • IT Consultancy & Inquiry Data: Name, work email, phone number, organization name, and service project scope submitted through contact forms. • InfynoSecure SaaS ERP Telemetry: Employee/student IDs, shift rosters, punch timestamps, and WhatsApp notification phone numbers. • Technical & Cookie Markers: IP address, user agent, session identifiers, rate-limiting tokens, and consent preference flags.

05. Specified Purpose of Processing

Personal data is processed strictly for: 1. Delivering subscribed InfynoSecure SaaS ERP features (attendance calculation, automated HRMS payroll, NABH/CBSE compliance reports). 2. Dispatching automated real-time WhatsApp parent entry alerts and system status updates. 3. Responding to IT software engineering consultancies and project RFP inquiries. 4. Maintaining platform cybersecurity, detecting brute-force attacks, and enforcing rate limiting.

06. Third-Party Service Providers

We share necessary data with audited third-party service providers bound by strict data processing agreements: • Cloud Infrastructure: Indian Data Centers (AWS Mumbai / GCP Bengaluru) for 100% Indian Cloud Data Sovereignty. • WhatsApp Business API: For automated parent attendance alert delivery. • Analytics & Performance: Google Analytics (anonymized IP enabled) loaded strictly after user consent.

07. Data Retention & Erasure Schedule

Data is retained strictly for specified operational durations: • Contact Inquiries: 12 months from last interaction. • SaaS ERP Subscription Data: Retained during active contract + 30 days post-termination before permanent cluster purging. • Audit & System Logs: 90 days.

08. Data Principal Rights (DPDP & GDPR)

Under DPDP Act 2023 and GDPR, you have the right to: 1. Right to Access & Portability: Obtain a summary of your personal data processed by InfynoSpark. 2. Right to Correction & Erasure: Request rectification of inaccurate records or permanent deletion. 3. Right to Withdraw Consent: Revoke consent for non-essential communications or WhatsApp alerts. 4. Grievance Redressal: File a complaint directly with our Data Protection Officer.

09. Grievance Officer & Contact Details

For privacy inquiries, audit requests, or formal DPDP complaints, contact our designated Data Protection & Grievance Officer: • Name: Mr. Rajesh K. Varma • Title: Data Protection Officer & Grievance Redressal Manager • Email: grievance@infynospark.cloud • Phone: +91 76667 62800 • Postal Address: InfynoSpark Innovation Labs, Tech Hub Park, Mumbai, Maharashtra, 400001, India • Mandatory Response SLA: Within 7 business days as mandated by DPDP Rules 2025.