Privacy policy

Privacy Policy for Bluconnect AI India Pvt Ltd - Customizable B2B ERP with AI Agents

Updated 24 Oct 2025

Privacy vault icon

Bluconnect AI India Pvt Ltd ("we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our customizable Enterprise Resource Planning (ERP) software with AI Agents (the "Service").

Introduction and Our Privacy Commitment

Our Privacy Commitment: We never sell your personal data to third parties for advertising or marketing purposes. Our business model is based on providing value through our software services, not on monetizing your data. This Privacy Policy applies to:

  • Our website and web applications
  • Our ERP software platform
  • AI agents and automated systems
  • Mobile applications
  • Customer support services
  • All related services and integrations

Data Controller and Contact Information

Bluconnect AI India Pvt Ltd acts as the Data Controller for personal data processed through our services.

Contact Information:

  • Company: Bluconnect AI India Pvt Ltd
  • Address: FIRST-FR, FL-A, 2, RAM SETT ROAD BEADON STREET, Kolkata, West Bengal, India - 700006
  • Email: security@bluconn.ai
  • Data Protection Officer: Sanjay Singh

We process your personal data under the following legal bases:

For Business Customers (B2B Context)

  • Contract Performance: To provide ERP services, AI agent functionality, and customer support
  • Legitimate Interest: For service improvement, security, fraud prevention, and business analytics
  • Legal Obligation: To comply with accounting, tax, and regulatory requirements
  • Consent: Where explicitly required for specific processing activities

For Individual Data Subjects

  • Consent: For marketing communications and optional features
  • Contract: For service delivery and account management
  • Legal Obligation: For compliance with applicable laws

Information We Collect

Business Information

  • Company name, business registration details
  • Business contact information (addresses, phone numbers)
  • Industry classification and business type

User Account Information

  • Names and job titles of authorized users
  • Business email addresses
  • User credentials and authentication data
  • Role and permission settings
  • User preferences and settings

ERP System Data

  • Inventory and supply chain data
  • Employee records (as entered by clients)
  • Project and operational data
  • Custom fields and configurations

AI Agent Processing Data

  • Data inputs provided to AI agents
  • User interactions with AI features
  • Performance metrics and analytics

Technical and Usage Data

  • IP addresses
  • Log files and system activities
  • Feature usage patterns
  • Performance metrics

Communication Data

  • Support ticket communications
  • Chat logs and correspondence
  • Meeting recordings (with consent)
  • Feedback and survey responses

How We Use Your Information

Service Provision

  • Delivering ERP functionality and AI agent services
  • Processing business transactions and workflows
  • Providing customer support and technical assistance
  • Managing user accounts and access controls
  • Customizing the platform to your business needs

AI and Machine Learning

  • Providing automated recommendations and insights
  • Generating business intelligence and analytics

*Important: AI processing is conducted with privacy-preserving techniques, including data minimization, anonymization where possible, and purpose limitation.

Service Enhancement

  • Improving platform performance and reliability
  • Developing new features and capabilities
  • Conducting security assessments and monitoring
  • Analyzing usage patterns for optimization
  • Personalizing user experience

Legal and Compliance

  • Meeting regulatory and legal obligations
  • Preventing fraud and security threats
  • Enforcing our terms of service
  • Responding to legal requests and investigations
  • Maintaining business records as required by law

Data Sharing and Transfers

We Do Not Sell Your Data

We never sell, rent, or trade your personal data to third parties for marketing or advertising purposes.

Limited Data Sharing

We may share your data only in the following circumstances:

  • Service Providers: With trusted third-party processors who assist in delivering our services, under strict data processing agreements.
  • Business Transfers: In connection with mergers, acquisitions, or asset sales, with appropriate data protection safeguards.
  • Legal Requirements: When required by law, court order, or to protect our rights and safety.
  • With Your Consent: When you explicitly authorize specific data sharing.

International Data Transfers

If we transfer data internationally, we ensure adequate protection through:

  • EU Standard Contractual Clauses
  • Adequacy decisions by relevant authorities
  • Other approved transfer mechanisms
  • Additional safeguards as required

Data Security and Protection

Technical Safeguards

  • Regular security assessments and penetration testing
  • Secure development practices and code reviews

Organizational Measures

  • Staff training on data protection and security
  • Strict access controls on a need-to-know basis
  • Regular security audits and compliance assessments
  • Incident response and breach notification procedures

Infrastructure Security

  • 24/7 monitoring and threat detection
  • Regular security updates and patch management
  • Disaster recovery and business continuity plans
  • Isolated customer environments and data segregation

Data Retention

Retention Principles

We retain personal data only as long as necessary for:

  • Fulfilling the purposes for which it was collected
  • Complying with legal and regulatory obligations
  • Resolving disputes and enforcing agreements
  • Billing Records: 7 years for tax and accounting compliance

Data Deletion

  • Automated deletion processes for expired data
  • Secure deletion using industry-standard methods
  • Regular audit trails of deletion activities
  • Customer-initiated deletion options in the platform

Your Privacy Rights

Exercising Your Rights

To exercise your privacy rights:

  • Email: Send requests to security@bluconn.ai
  • Support: Contact our support team through the platform

Cookies and Tracking Technologies

Types of Cookies We Use

  • Essential Cookies: Required for platform functionality
  • Performance Cookies: To analyze and improve service performance
  • Functional Cookies: To remember your preferences and settings
  • Security Cookies: For authentication and fraud prevention

Third-Party Services

We may use third-party services for:

  • Analytics and performance monitoring
  • Customer support tools
  • Security and fraud prevention
  • Integration with external business systems

Privacy by Design

We implement privacy by design principles:

  • Proactive: Privacy protections built into system design
  • Privacy as the Default: Highest privacy settings as standard
  • Full Functionality: Privacy without sacrificing business functionality
  • End-to-End Security: Comprehensive protection throughout data lifecycle
  • Visibility and Transparency: Clear information about data practices
  • Respect for User Privacy: User-centric privacy controls

Compliance Framework

Standards and Certifications

We maintain compliance with:

  • ISO 27001: Information Security Management System
  • SOC 2 Type II: Security, availability, and confidentiality
  • GDPR: EU data protection requirements
  • Industry Standards: Relevant sector-specific requirements

Regular Assessments

  • Annual third-party security audits
  • Quarterly privacy impact assessments
  • Continuous monitoring and compliance reviews
  • Regular staff training and certification updates

Data Breach Notification

Our Response

In case of a data breach, we will:

  • Contain and investigate the incident immediately
  • Assess the risk to individuals and businesses
  • Notify relevant authorities within 72 hours (where required)
  • Inform affected customers without undue delay
  • Provide clear information about the incident and remediation steps

Customer Responsibilities

Business customers should:

  • Implement appropriate internal security measures
  • Report suspected security incidents promptly
  • Notify their own stakeholders as required by law
  • Cooperate with incident investigation and response

Updates to This Policy

Policy Changes

We may update this Privacy Policy to reflect:

  • Changes in our services or business practices
  • Updates to applicable laws and regulations
  • Improvements in privacy protection measures
  • Feedback from customers and stakeholders

Dispute Resolution

Contact Us First

If you have concerns about our privacy practices, please contact our Data Protection Officer first at security@bluconn.ai

Additional Information

Business Transfers

In the case of business restructuring, merger, or acquisition, personal data may be transferred as part of business assets, subject to equivalent privacy protections.

Contact Information

For privacy-related questions or concerns:

Office:

  • Email: security@bluconn.ai
  • Address: FIRST-FR, FL-A, 2, RAM SETT ROAD BEADON STREET, Kolkata, West Bengal, India - 700006

General Support:

This Privacy Policy is effective as of 24 October 2025 and applies to all users of our services. Please review this policy regularly for any updates.