1. Who we are
Ametecs India Private Limited ("Ametecs", "we", "us") is a company incorporated in India on 2 January 2019, with its registered office at Modern Profound Techpark, Ground Floor, HIVE Business Space, opposite Google, Whitefields, Kondapur, Hyderabad, Telangana 500084.
We build and operate business software platforms including SmartDCM, SmartPRS, SmartEPT, LeadGER, Smart31, TeloZar, SmartRMI, SmartABCD and Envinity.ai.
2. What this policy covers
This policy explains how we handle personal data in two distinct roles, because the difference matters and most policies blur it:
- As a data fiduciary — for this website, our sales conversations, our customers' account and billing records, and our own employees and applicants. We decide why and how that data is used.
- As a data processor — for the information inside our platforms that belongs to our customers: their customers, their employees, their call recordings, their attendance records. We process that data only on our customer's documented instructions. They decide what is collected and why; we do not use it for our own purposes, and we do not sell it.
Where you are an individual whose data sits inside a customer's Ametecs platform — for example an employee monitored through SmartEPT, or a customer contacted through SmartDCM — your relationship is with that organisation. Please direct requests to them first. We will assist them in responding.
3. Information we collect
When you visit this website. Our web server records standard technical information — IP address, browser type, pages requested, date and time — in access logs, for security and to keep the site working. We do not run advertising or cross-site tracking, and we do not build profiles of visitors.
When you contact us. Your name, organisation, email address, telephone number and whatever you choose to tell us about your requirements.
When you become a customer. Account and authorised-user details, billing and GST information, deployment and configuration records, and support correspondence.
Inside our platforms. Whatever our customer configures the platform to hold. Depending on the product this can include contact records, call recordings and transcripts, attendance and biometric-linked events, payroll and statutory data, application and activity data from company-owned workstations, and lead and campaign records.
4. How we use information
- To provide, support, secure and improve our platforms and services.
- To respond to enquiries, arrange demonstrations and prepare proposals.
- To invoice, collect payment and meet tax and accounting obligations.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To comply with law and to establish or defend legal claims.
We do not sell personal data. We do not share it for advertising. We do not use customer platform data to train models for other customers or for our own products.
5. Cookies
This website uses only what is strictly necessary to function. It does not set advertising, analytics or cross-site tracking cookies. A single local browser entry records that you have dismissed our cookie notice, so it is not shown again — that entry stays in your browser and is never sent to us.
Our customer-facing product applications use session cookies necessary for authentication. If we introduce analytics on this website in future, we will ask for your consent before any such cookie is set.
6. Sharing
We share personal data only with:
- Infrastructure and service providers — cloud hosting, telecommunications carriers, payment processors and similar, bound by contract to protect the data and use it only to deliver the service.
- Professional advisers — auditors, accountants and lawyers, under duties of confidentiality.
- Authorities — where required by law, valid legal process, or to protect rights and safety.
- An acquirer — if the business or a part of it is transferred, with notice to affected parties.
7. Where data is held
Our platforms are deployed in several ways, and this determines where data resides. Under SaaS, data is held on infrastructure we manage. Under a client-hosted or on-premise licence, the data resides on our customer's own infrastructure and we access it only when the customer asks us to, for support. We will tell you which model applies to your deployment, and we support customers who require data to remain in India.
8. If you are outside India
We sell and support internationally, and Envinity.ai is built for markets beyond India. Where we handle personal data of individuals in other jurisdictions, we apply the following in addition to Indian law.
Cross-border transfers. Personal data may be transferred to, stored in, or accessed from India, where our engineering and support teams are located. Where the law of your jurisdiction requires a transfer mechanism, we will put one in place before the transfer — for the EEA and the United Kingdom, the European Commission's Standard Contractual Clauses (and the UK Addendum) incorporated into our customer agreement, together with the technical and organisational measures described in section 9. A copy is available on request.
UK and EEA (GDPR). Where GDPR applies to our processing, our lawful bases are: performance of a contract (providing our platforms and services); legitimate interests (running, securing and improving our business, where not overridden by your rights); legal obligation (tax, accounting, statutory record-keeping); and consent, where we ask for it. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority. Where we act as a processor for a customer, exercise those rights with that customer as controller.
Other jurisdictions. Where the law of a customer's country imposes requirements on how we process data on their behalf — data residency, breach notification periods, sub-processor approval, audit rights — those are addressed in the customer agreement for that engagement rather than in this general policy. Ask us before you sign; we would rather agree the position up front than discover a mismatch later.
Data residency. Where a customer requires that data does not leave a particular country, the client-hosted and on-premise deployment models exist for exactly that reason. Tell us the requirement and we will tell you plainly whether we can meet it.
9. Security
We apply role-based access control, traceable actions, controlled data visibility, audit records and deployment options matched to customer risk requirements. Access to customer environments is limited to personnel who need it for support, and is logged.
We state our position plainly: we do not claim certifications, regulatory approvals or absolute protection unless they have been formally obtained and can be independently verified. No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority as required by law.
10. Retention
We keep account, billing and tax records for the periods Indian law requires. Enquiry correspondence is kept while a commercial relationship is reasonably in prospect. Data inside a customer platform is retained according to that customer's configuration and contract; on termination we return or delete it as the contract provides.
11. Your rights
Subject to the Digital Personal Data Protection Act, 2023 and other applicable law, you may ask us to confirm what personal data we hold about you, correct or complete it, erase it where it is no longer needed, or withdraw a consent you previously gave. You may also nominate another person to exercise these rights in the event of your death or incapacity.
To exercise a right, write to admin@ametecsindia.com. We may need to verify your identity. If the data sits inside a customer's platform, we will refer your request to that organisation and support them in answering it.
12. Grievances
If you are not satisfied with how we have handled your personal data or a request, contact our Grievance Officer at admin@ametecsindia.com or by post at the registered office above. We aim to acknowledge within 48 hours and resolve within 30 days. You may also complain to the Data Protection Board of India.
13. Children
Our platforms are business tools and are not directed at children. We do not knowingly collect personal data of children through this website. Where a customer's use of our platforms involves data of children, that customer is responsible for obtaining any consent the law requires.
14. Changes
We may update this policy. The date at the top shows when it last changed. Where a change materially affects how we handle your data, we will take reasonable steps to tell you.
15. Contact
Ametecs India Private Limited · Modern Profound Techpark, Ground Floor, HIVE Business Space, opposite Google, Whitefields, Kondapur, Hyderabad, Telangana 500084, India
admin@ametecsindia.com · +91 90000 98877