AO Plus Solutions Pvt Ltd
Privacy Policy
How we collect, use, and protect information across aoplus.in and our ERPNext, hosting, and automation services.
1. Introduction
AO Plus Solutions Pvt Ltd ("AO+", "we", "us", "our") provides ERPNext implementation, private cloud hosting, n8n workflow automation, DevOps/Kubernetes, and related IT consulting services to businesses in India and internationally. This Privacy Policy explains what personal data we collect through our website (aoplus.in), our client portal ("Biz Portal"), and in the course of delivering our services, why we collect it, how we use and protect it, and the choices and rights available to you.
This policy is drafted with reference to India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where relevant to our international clients, principles consistent with the EU/UK General Data Protection Regulation (GDPR). By using our website or engaging our services, you agree to the practices described here.
2. Who we are
| Legal entity | AO Plus Solutions Pvt Ltd |
|---|---|
| CIN | U72900MH2019PTC330456 |
| Registered office | Mumbai, Maharashtra, India |
| GSTIN | 27AASCA6842P2ZQ |
| PAN | AASCA6842P |
| Website | https://aoplus.in |
| Phone | +91 98333 75149 |
| [[email protected]] |
For the purposes of the DPDP Act, AO+ acts as a Data Fiduciary for personal data collected through our website and our own business operations, and as a Data Processor for personal data our clients store or process using ERPNext, n8n, or other systems we implement or host on their behalf. Where we process client data as a processor, the client remains the Data Fiduciary and our processing is governed by our services agreement with them, not this policy.
3. Scope of this policy
This policy covers:
- Visitors to aoplus.in, including anyone who fills out a contact form, books an assessment call, or subscribes to our newsletter.
- Prospective and existing clients, vendors, and partners we correspond with.
- Users of our client-facing portal (Biz Portal) built on Frappe.
It does not cover the personal data our clients themselves collect and process within their own ERPNext, n8n, or other instances that we host or support — that data is governed by each client's own privacy policy and their instructions to us as a processor.
4. Information we collect
4.1 Information you give us directly
- Contact and enquiry data: name, company name, email, phone number, and message content submitted via our contact form or "Book Assessment" flow.
- Scheduling data: when you book a call via Calendly, we (and Calendly, as an independent data controller for that tool) receive your name, email, and selected time slot.
- Newsletter data: email address, if you subscribe to MSME/technology updates.
- Client onboarding data: business details, billing/GST information, and technical requirements shared during scoping, contracting, or implementation.
- Support data: information you provide when raising a support ticket or corresponding with our team.
4.2 Information collected automatically
- Usage and device data: IP address, browser type, device type, pages visited, referring URL, and timestamps, collected via server logs and cookies. See our Cookie Policy for details.
- Infrastructure logs: where we provide hosting or DevOps services, our monitoring tools on Hetzner infrastructure may log access and performance data necessary to operate and secure the service.
4.3 Information we do not intentionally collect
We do not knowingly collect sensitive personal data (such as health records, biometric data, or financial account credentials) through our website. Any such data processed within client ERPNext/n8n instances is governed by our data processing agreement with that client.
5. How we use information
- To respond to enquiries and schedule assessment calls.
- To scope, deliver, and support ERPNext implementation, private cloud hosting, n8n automation, and DevOps services.
- To send service-related communications (invoices, maintenance notices, security alerts).
- To send marketing communications such as our MSME/open-source newsletter, where you have opted in — you may unsubscribe at any time.
- To improve our website, services, and internal security posture.
- To comply with tax, accounting, and other legal obligations under Indian law.
- To detect, prevent, and investigate fraud, abuse, or security incidents.
We do not sell personal data to third parties.
6. Our legal basis for processing
Under the DPDP Act, we process personal data on the basis of your consent (for example, when you submit a contact form or subscribe to our newsletter) or for certain legitimate uses recognised under the Act, such as responding to a request you have voluntarily initiated, or compliance with law.
For clients in jurisdictions covered by the GDPR or similar laws, we rely on contractual necessity (to deliver services under a signed agreement), consent, and our legitimate interests in operating and securing our business, balanced against your rights.
9. International data transfers
Because we use Hetzner infrastructure, some data (including data for our own website and for clients who choose Hetzner-hosted deployments) may be stored on servers located outside India, primarily in the European Union. Where we transfer personal data internationally, we take reasonable steps to ensure it continues to receive an appropriate standard of protection, including relying on our hosting provider's own security and compliance certifications. Clients who require data to remain within India can request an India-region or India-only hosting configuration as part of their services agreement.
10. Data retention
- Enquiry/contact form data: retained for up to 24 months from last contact, or until you ask us to delete it, whichever is earlier.
- Client account and billing data: retained for the duration of the engagement and thereafter as required by Indian tax and corporate law (typically 7–8 years for financial records).
- Newsletter subscriptions: retained until you unsubscribe.
- Infrastructure/security logs: retained for a limited operational window (typically 30–90 days) unless needed longer for an active security investigation.
11. Security measures
We apply industry-standard technical and organisational measures appropriate to a company running production infrastructure, including access controls and role-based permissions, encrypted connections (HTTPS/TLS) for data in transit, hardened server baselines on our hosting infrastructure, regular patching of our open-source stack (ERPNext, n8n, and underlying OS/container images), and restricted, logged administrative access to production systems. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to promptly identify and remediate vulnerabilities.
12. Your rights
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Erase personal data we no longer need or that you have withdrawn consent for.
- Withdraw consent at any time for processing based on consent (such as our newsletter), without affecting processing carried out before withdrawal.
- Nominate another individual to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.
- Grievance redressal, as described in Section 14 below.
To exercise any of these rights, contact us using the details in Section 16. We may need to verify your identity before acting on a request.
13. Children's privacy
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us so we can delete it.
14. Grievance officer
In accordance with the DPDP Act and applicable Indian IT rules, we have designated a Grievance Officer to address complaints regarding the processing of your personal data.
| Name | [Grievance Officer name] |
|---|---|
| [[email protected]] | |
| Address | AO Plus Solutions Pvt Ltd, Mumbai, Maharashtra, India |
| Response time | We aim to acknowledge grievances within 48 hours and resolve them within 30 days. |
If you are not satisfied with our response, you may approach the Data Protection Board of India or other competent authority as applicable.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. We will post the revised policy on this page with an updated "Last updated" date, and for material changes we will make reasonable efforts to notify active clients directly.
16. Contact us
Questions about this policy or how we handle your data:
- Email: [[email protected]]
- Phone: +91 98333 75149
- Post: AO Plus Solutions Pvt Ltd, Mumbai, Maharashtra, India