Privacy policy
Privacy Policy for Bluconnect AI India Pvt Ltd - Customizable B2B ERP with AI Agents
Updated 24 Oct 2025

Table of contents
Introduction and Our Privacy Commitment
Data Controller and Contact Information
Legal Basis for Processing
Information We Collect
How We Use Your Information
Data Sharing and Transfers
Data Security and Protection
Data Retention
Your Privacy Rights
Cookies and Tracking Technologies
Privacy by Design
Compliance Framework
Data Breach Notification
Updates to This Policy
Dispute Resolution
Additional Information
Contact Information
Table of contents
Introduction and Our Privacy Commitment
Data Controller and Contact Information
Legal Basis for Processing
Information We Collect
How We Use Your Information
Data Sharing and Transfers
Data Security and Protection
Data Retention
Your Privacy Rights
Cookies and Tracking Technologies
Privacy by Design
Compliance Framework
Data Breach Notification
Updates to This Policy
Dispute Resolution
Additional Information
Contact Information
Bluconnect AI India Pvt Ltd ("we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our customizable Enterprise Resource Planning (ERP) software with AI Agents (the "Service").
Introduction and Our Privacy Commitment
Our Privacy Commitment: We never sell your personal data to third parties for advertising or marketing purposes. Our business model is based on providing value through our software services, not on monetizing your data. This Privacy Policy applies to:
- Our website and web applications
- Our ERP software platform
- AI agents and automated systems
- Mobile applications
- Customer support services
- All related services and integrations
Data Controller and Contact Information
Bluconnect AI India Pvt Ltd acts as the Data Controller for personal data processed through our services.
Contact Information:
- Company: Bluconnect AI India Pvt Ltd
- Address: FIRST-FR, FL-A, 2, RAM SETT ROAD BEADON STREET, Kolkata, West Bengal, India - 700006
- Email: security@bluconn.ai
- Data Protection Officer: Sanjay Singh
Legal Basis for Processing
We process your personal data under the following legal bases:
For Business Customers (B2B Context)
- Contract Performance: To provide ERP services, AI agent functionality, and customer support
- Legitimate Interest: For service improvement, security, fraud prevention, and business analytics
- Legal Obligation: To comply with accounting, tax, and regulatory requirements
- Consent: Where explicitly required for specific processing activities
For Individual Data Subjects
- Consent: For marketing communications and optional features
- Contract: For service delivery and account management
- Legal Obligation: For compliance with applicable laws
Information We Collect
Business Information
- Company name, business registration details
- Business contact information (addresses, phone numbers)
- Industry classification and business type
User Account Information
- Names and job titles of authorized users
- Business email addresses
- User credentials and authentication data
- Role and permission settings
- User preferences and settings
ERP System Data
- Inventory and supply chain data
- Employee records (as entered by clients)
- Project and operational data
- Custom fields and configurations
AI Agent Processing Data
- Data inputs provided to AI agents
- User interactions with AI features
- Performance metrics and analytics
Technical and Usage Data
- IP addresses
- Log files and system activities
- Feature usage patterns
- Performance metrics
Communication Data
- Support ticket communications
- Chat logs and correspondence
- Meeting recordings (with consent)
- Feedback and survey responses
How We Use Your Information
Service Provision
- Delivering ERP functionality and AI agent services
- Processing business transactions and workflows
- Providing customer support and technical assistance
- Managing user accounts and access controls
- Customizing the platform to your business needs
AI and Machine Learning
- Providing automated recommendations and insights
- Generating business intelligence and analytics
*Important: AI processing is conducted with privacy-preserving techniques, including data minimization, anonymization where possible, and purpose limitation.
Service Enhancement
- Improving platform performance and reliability
- Developing new features and capabilities
- Conducting security assessments and monitoring
- Analyzing usage patterns for optimization
- Personalizing user experience
Legal and Compliance
- Meeting regulatory and legal obligations
- Preventing fraud and security threats
- Enforcing our terms of service
- Responding to legal requests and investigations
- Maintaining business records as required by law
Data Sharing and Transfers
We Do Not Sell Your Data
We never sell, rent, or trade your personal data to third parties for marketing or advertising purposes.
Limited Data Sharing
We may share your data only in the following circumstances:
- Service Providers: With trusted third-party processors who assist in delivering our services, under strict data processing agreements.
- Business Transfers: In connection with mergers, acquisitions, or asset sales, with appropriate data protection safeguards.
- Legal Requirements: When required by law, court order, or to protect our rights and safety.
- With Your Consent: When you explicitly authorize specific data sharing.
International Data Transfers
If we transfer data internationally, we ensure adequate protection through:
- EU Standard Contractual Clauses
- Adequacy decisions by relevant authorities
- Other approved transfer mechanisms
- Additional safeguards as required
Data Security and Protection
Technical Safeguards
- Regular security assessments and penetration testing
- Secure development practices and code reviews
Organizational Measures
- Staff training on data protection and security
- Strict access controls on a need-to-know basis
- Regular security audits and compliance assessments
- Incident response and breach notification procedures
Infrastructure Security
- 24/7 monitoring and threat detection
- Regular security updates and patch management
- Disaster recovery and business continuity plans
- Isolated customer environments and data segregation
Data Retention
Retention Principles
We retain personal data only as long as necessary for:
- Fulfilling the purposes for which it was collected
- Complying with legal and regulatory obligations
- Resolving disputes and enforcing agreements
- Billing Records: 7 years for tax and accounting compliance
Data Deletion
- Automated deletion processes for expired data
- Secure deletion using industry-standard methods
- Regular audit trails of deletion activities
- Customer-initiated deletion options in the platform
Your Privacy Rights
Exercising Your Rights
To exercise your privacy rights:
- Email: Send requests to security@bluconn.ai
- Support: Contact our support team through the platform
Cookies and Tracking Technologies
Types of Cookies We Use
- Essential Cookies: Required for platform functionality
- Performance Cookies: To analyze and improve service performance
- Functional Cookies: To remember your preferences and settings
- Security Cookies: For authentication and fraud prevention
Third-Party Services
We may use third-party services for:
- Analytics and performance monitoring
- Customer support tools
- Security and fraud prevention
- Integration with external business systems
Privacy by Design
We implement privacy by design principles:
- Proactive: Privacy protections built into system design
- Privacy as the Default: Highest privacy settings as standard
- Full Functionality: Privacy without sacrificing business functionality
- End-to-End Security: Comprehensive protection throughout data lifecycle
- Visibility and Transparency: Clear information about data practices
- Respect for User Privacy: User-centric privacy controls
Compliance Framework
Standards and Certifications
We maintain compliance with:
- ISO 27001: Information Security Management System
- SOC 2 Type II: Security, availability, and confidentiality
- GDPR: EU data protection requirements
- Industry Standards: Relevant sector-specific requirements
Regular Assessments
- Annual third-party security audits
- Quarterly privacy impact assessments
- Continuous monitoring and compliance reviews
- Regular staff training and certification updates
Data Breach Notification
Our Response
In case of a data breach, we will:
- Contain and investigate the incident immediately
- Assess the risk to individuals and businesses
- Notify relevant authorities within 72 hours (where required)
- Inform affected customers without undue delay
- Provide clear information about the incident and remediation steps
Customer Responsibilities
Business customers should:
- Implement appropriate internal security measures
- Report suspected security incidents promptly
- Notify their own stakeholders as required by law
- Cooperate with incident investigation and response
Updates to This Policy
Policy Changes
We may update this Privacy Policy to reflect:
- Changes in our services or business practices
- Updates to applicable laws and regulations
- Improvements in privacy protection measures
- Feedback from customers and stakeholders
Dispute Resolution
Contact Us First
If you have concerns about our privacy practices, please contact our Data Protection Officer first at security@bluconn.ai
Additional Information
Business Transfers
In the case of business restructuring, merger, or acquisition, personal data may be transferred as part of business assets, subject to equivalent privacy protections.
Contact Information
For privacy-related questions or concerns:
Office:
- Email: security@bluconn.ai
- Address: FIRST-FR, FL-A, 2, RAM SETT ROAD BEADON STREET, Kolkata, West Bengal, India - 700006
General Support:
- Email: support@bluconn.ai
This Privacy Policy is effective as of 24 October 2025 and applies to all users of our services. Please review this policy regularly for any updates.