Privacy Policy Version 1.0
Effective date: September 9, 2026
We collect and use information primarily to provide, secure and support the MyBizRoom service.
Business customers remain responsible for the personal data they enter into their workspace and for having the appropriate authority to process that information.
01. Who We Are
MYBIZROOM SOFTWARE (OPC) PRIVATE LIMITED is a business workspace SaaS designed for small and growing businesses to manage customers, products, orders, invoices, payments and related operational workflows.
This Privacy Policy explains how we collect, use, store, protect and otherwise process personal data when you use our website, create an account or use the MyBizRoom application.
References to MYBIZROOM SOFTWARE (OPC) PRIVATE LIMITED, "we", "us" and "our" mean the service operator responsible for providing and supporting the MyBizRoom website and application.
02. Scope of This Policy
This policy applies to personal data processed through the public website, account registration, authenticated workspace, customer-support communications and related service operations.
It applies to information relating to account holders, business contacts, customers whose information is entered into a workspace, and other individuals whose information is processed through the service.
03. Information We Collect
Depending on how you use the service, we may process account and identity information such as your full name, business email address, telephone number, login credentials and email-verification status.
We may process organization information such as business name, business contact information, website, address, tax or business identifiers where voluntarily provided, currency, timezone and workspace configuration.
We may process operational business information entered into the workspace, including customer names, telephone numbers, WhatsApp details, addresses, notes, products, prices, orders, invoices, payment references, payment status and conversation-related operational records.
We may also process technical and security information such as IP address, device or browser information, authentication events, security events, timestamps and application logs where reasonably necessary for security, reliability and support.
We do not ask users to provide unnecessary sensitive personal data through the service. Users should not intentionally enter sensitive or unlawful information into fields that are not designed for it.
04. Business and Customer Data
A business using the service may enter personal data relating to its own customers, suppliers, contacts or other individuals. That business determines why that information is collected and how it is used for its business operations.
For such workspace data, the business using the service may act as the party responsible for determining the purposes of processing, while we process the information to provide and secure the services requested by that business.
The business is responsible for ensuring that it has an appropriate legal basis, notice, permission or other authorization required for the information it enters into the workspace.
05. How We Use Personal Data
We use personal data to create and manage accounts, authenticate users, verify email addresses, operate workspaces and provide the features requested by customers.
We use information to process orders, invoices, payment references, subscriptions, support requests and other operational workflows initiated by the customer.
We use technical and security information to prevent unauthorized access, detect abuse, investigate security events, enforce access controls, troubleshoot failures and maintain service reliability.
We may use information to communicate service- related messages such as account verification, password recovery, subscription notifications, important service notices and support responses.
We may retain information where necessary to comply with applicable law, resolve disputes, enforce agreements, protect the service or preserve security evidence.
06. Processing and Legal Basis
We aim to process personal data only for specific and legitimate purposes connected with providing, securing and supporting the service.
Depending on the context, processing may be based on the user's request for the service, performance of contractual or pre-contractual activities, compliance with applicable legal obligations, legitimate operational and security purposes, or consent where consent is the appropriate basis.
Where processing relies on consent, applicable withdrawal mechanisms will be provided where required. Withdrawal of consent does not necessarily affect processing that is permitted on another lawful basis or information that must be retained for legal or security purposes.
07. Service Providers and Data Sharing
We may use carefully selected service providers to operate parts of the platform. Depending on the service, these providers may process information on our behalf or provide infrastructure or payment services necessary to operate the product.
Our current Phase 1 service-provider categories include cloud/hosting infrastructure, transactional email delivery and payment processing.
We do not sell customer personal data as a business model.
We may disclose information where reasonably necessary to comply with law, lawful governmental requests, court or regulatory orders, investigate security incidents, protect rights or safety, or enforce our agreements.
08. Transactional Email
We use Resend for transactional email delivery, including account verification, welcome messages, password recovery and other service-related communications.
Information required to deliver an email may be transmitted to and processed by the email provider. Provider retention and processing may involve infrastructure outside India, subject to the provider's applicable terms, privacy documentation and contractual safeguards.
We do not use transactional email to sell or transfer customer data to unrelated advertisers.
09. Payments and Razorpay
We use Razorpay and related payment infrastructure for subscription and payment processing where applicable.
Payment-card details entered into a hosted or payment-provider checkout are processed by the relevant payment provider and payment ecosystem. We do not intentionally store full card numbers or card security codes in the MyBizRoom application.
Our application may retain limited payment and reconciliation information such as payment-provider identifiers, transaction status, amount, currency, timestamps and other information needed to operate billing and reconcile transactions.
Payment providers may process information under their own privacy notices and contractual terms.
10. Security Safeguards
We use reasonable technical and organizational safeguards appropriate to the nature of the information processed by the service.
These safeguards include authenticated access controls, tenant-level authorization, password hashing, protected authentication tokens, rate limiting, security headers, controlled API access and security logging.
We limit access to workspace information according to application roles and operational requirements.
No internet service can guarantee absolute security. Customers are responsible for protecting their account credentials and promptly reporting suspected unauthorized access or security incidents.
12. Data Retention
We retain personal data for as long as reasonably necessary to provide the service, operate the customer's workspace, maintain business records, satisfy applicable legal obligations, resolve disputes, prevent abuse and maintain security.
Different categories of information may therefore have different retention periods.
Authentication tokens and other temporary security credentials are retained only for the period reasonably required for their intended security function and are subject to expiry or revocation.
Application and security logs may be retained for security, operational and incident-response purposes and may be subject to applicable regulatory retention requirements.
Where a customer closes a workspace, eligible operational data may be deleted or anonymized after an appropriate recovery and processing period, subject to legal, accounting, security, dispute and other legitimate retention requirements.
Backups may continue to contain deleted information for a limited backup lifecycle before those copies are overwritten or securely disposed of.
13. Deletion and Legal Retention
We aim to delete or anonymize personal data when it is no longer required for the purpose for which it was processed, unless continued retention is required or permitted for legal, accounting, security, dispute-resolution or other legitimate purposes.
Deletion of a workspace does not necessarily result in immediate deletion of every record where retention is required by law, required for legitimate business records, needed to investigate security incidents, or preserved as part of a legal hold.
Information that is no longer required for active use may be removed from operational systems while remaining temporarily in encrypted backups until the applicable backup lifecycle expires.
14. Data Principal Rights and Privacy Requests
Where applicable under Indian data-protection law, individuals may have rights relating to access to information, correction, erasure, grievance redressal and other rights provided by applicable law.
A privacy request must contain enough information for us to reasonably verify the identity and authority of the requester. We may request additional information where necessary to prevent unauthorized disclosure.
Requests concerning customer data stored inside a business workspace may need to be coordinated with the business that controls or determines the purpose of that data.
We will process verified requests within the time and manner required by applicable law and our operational procedures, subject to lawful retention requirements and other applicable exceptions.
15. Privacy Grievances and Contact
Privacy questions, data requests and privacy grievances may be submitted through the Contact Us page available on the website.
We may request account or identity verification before providing information, changing records or processing a deletion request.
We will maintain an appropriate internal process for receiving, reviewing and responding to privacy requests and grievances.
16. Security Incidents and Data Breaches
We maintain security monitoring, access controls and incident-response procedures appropriate to the service.
If we identify a personal-data breach or other security incident requiring notification under applicable law or regulatory directions, we will take the required containment, investigation, preservation and notification steps.
Where notification to affected individuals, customers, regulators or authorities is legally required, we will provide the information and notifications required by the applicable framework.
17. International Processing
Some service providers used by the platform may process or store information outside India.
Where such processing occurs, we will use the applicable contractual, technical and organizational safeguards required or appropriate for the relevant processing.
Customers should review the provider-specific information described in this policy when deciding whether the service is appropriate for their business.
18. Children's Data
MYBIZROOM SOFTWARE (OPC) PRIVATE LIMITED is a business software service and is not intended to be used as a service directed at children.
Customers should not intentionally create accounts for children or enter children's personal data unless such processing is lawful and the customer has satisfied the requirements applicable to that processing.
19. Customer Responsibilities
Customers are responsible for the accuracy of information entered into their workspace and for determining whether they have the necessary authority and legal basis to collect and use personal data relating to their customers and contacts.
Customers must use appropriate internal access controls, protect credentials, avoid sharing accounts, and promptly remove or restrict access that is no longer required.
Customers must not use the service to store unlawful content, information they are prohibited from processing, or information that creates an unreasonable security or legal risk to the platform or other users.
20. Changes to This Policy
We may update this Privacy Policy when the service, processing activities, providers or applicable legal requirements change.
The version number and last-updated date shown on this page identify the published version.
Where a change materially affects how personal data is processed, we will take reasonable steps to provide an appropriate notice and, where required, obtain any required acknowledgement or consent.
21. Contact
For privacy questions, data requests or other concerns relating to this policy, please use the Contact Us page on the MyBizRoom website.
We may request sufficient information to verify the requester and identify the relevant account or workspace before responding to a privacy request.