How Traiq Tech collects, uses, stores, and protects your personal data across our enterprise ERP platform.
Traiq Tech Private Limited ("Traiq Tech," "we," "us," or "our") is committed to protecting the privacy and security of personal information belonging to our customers, users, and business partners. This Privacy Policy describes how we collect, use, disclose, store, and safeguard personal data when you access or use the Traiq Tech enterprise ERP platform, associated services, mobile applications, APIs, and our corporate websites (collectively, the "Services").
This Policy applies to all individuals who interact with our Services, including enterprise customers, their authorized end-users, business contacts, and visitors to our public-facing websites. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please refrain from using our Services and contact us at privacy@traiq-tech.com to discuss your options.
Traiq Tech acts as a data processor with respect to personal data you provide through the platform on behalf of your organization, and as a data controller with respect to personal data we collect independently (such as account registration data, usage analytics, and marketing interactions). We maintain separate Data Processing Agreements (DPAs) with enterprise customers subject to GDPR, India's DPDPA, and comparable frameworks in other jurisdictions.
We review and update this Policy at least annually, and whenever material changes occur. The 'Last Updated' date at the top of every legal page reflects the most recent revision. Continued use of our Services after changes are published constitutes acceptance of the revised Policy unless otherwise required by law.
We collect personal data through multiple channels, including direct submission by users, automated technical collection, and data provided by your organization under our enterprise agreements. The categories of personal data we collect include: (a) Account and Identity Data — name, business email address, job title, employer, profile photograph, and authentication credentials; (b) Contact and Communication Data — phone numbers, postal addresses, and any information you provide in support tickets, chat sessions, or correspondence with our team.
We also collect Transaction and Subscription Data — billing contact information, payment method details (processed exclusively through PCI-DSS compliant third-party processors; we do not store raw card data), invoice history, and subscription tier details. For enterprise deployments, we collect Organization Data — company name, registered address, industry vertical, size, and organizational hierarchy required to configure role-based access.
Through your use of the platform, we automatically collect Usage and Technical Data — IP addresses, browser type and version, operating system, device identifiers, session duration, page views, feature interactions, error logs, and performance telemetry. This data is used to operate, secure, and improve the Services and is subject to aggregation and anonymization for analytics purposes.
Where our platform is configured to handle operational business data (such as inventory records, patient information in healthcare deployments, or student records in education), that data is customer content processed solely on your behalf under our DPA and governed by your own privacy obligations. Traiq Tech does not use customer content to train AI models or for any purpose other than delivering the contracted Services.
We do not sell personal data
Traiq Tech does not sell, rent, or trade personal data to third parties for commercial purposes. We share data only as described in this Policy and in accordance with our enterprise agreements.
We process personal data for the following purposes, each of which rests on a lawful basis under applicable data protection law: (a) Contract Performance — to provision, operate, and maintain the Services you or your organization have purchased, including user authentication, platform configuration, and customer support; (b) Legitimate Business Interests — to analyze usage patterns, troubleshoot technical issues, improve product features, conduct security monitoring, and prevent fraud; (c) Legal Compliance — to comply with applicable laws, regulations, court orders, or governmental requests in the jurisdictions where we operate.
We use Usage and Technical Data to generate aggregated, de-identified analytics that inform product decisions and infrastructure capacity planning. These analytics are never linked back to individual users or organizations once anonymized. We may also use account and contact data to send administrative communications (account alerts, security notifications, policy updates) and, subject to your marketing preferences, commercial communications about new features, case studies, and industry insights relevant to your deployment.
For customers utilizing AI Copilot features, interaction data within those features is processed to return real-time responses and is retained only as long as necessary for session continuity and debugging. We do not use this data to build behavioral profiles or to improve general AI models. Enterprise customers may configure data retention settings for AI interactions within their administrative console.
We do not make automated decisions that produce legal or similarly significant effects on individuals solely through algorithmic processing without human review. Our AI-assisted reporting and recommendation features are always subject to review by authorized enterprise users before any consequential action is taken.
Traiq Tech stores personal data on cloud infrastructure operated by Amazon Web Services (AWS) and, for certain regional deployments, Microsoft Azure. Primary data centers for Indian customers are located in the AWS ap-south-1 (Mumbai) region. European customers' data is stored in the AWS eu-west-1 (Dublin) region by default, with options for eu-central-1 (Frankfurt) upon request. Singapore-based and APAC customers are served from the ap-southeast-1 (Singapore) region.
All data at rest is encrypted using AES-256. Data in transit between clients and our Services is protected using TLS 1.2 or higher. Encryption keys are managed through AWS Key Management Service (KMS) with hardware security module (HSM) backing. Separate encryption keys are maintained per-tenant to ensure logical isolation of customer data.
We operate redundant storage with continuous replication across at least two geographically separate availability zones within each primary region. Automated backups are taken daily, retained for 30 days, and stored in separate availability zones with independent encryption key hierarchies. Enterprise customers on Premium and Enterprise plans receive point-in-time recovery capabilities with configurable retention periods of up to 7 years.
For enterprise customers with specific data residency requirements (such as government sector deployments), we offer data sovereignty configurations that contractually and technically restrict data processing to nominated geographic zones. Speak to your account manager or contact dpa@traiq-tech.com for details on sovereign cloud configurations.
Traiq Tech implements a comprehensive, defense-in-depth security program designed to protect the confidentiality, integrity, and availability of personal data. Our security controls are aligned with internationally recognized frameworks, including ISO 27001 principles, NIST Cybersecurity Framework guidelines, and SOC 2-style operational controls. We commission independent third-party security assessments on a regular cadence and make executive summaries available to enterprise customers under NDA upon request.
Technical controls include: end-to-end encryption for data in transit and at rest; multi-factor authentication (MFA) enforcement for all internal employee access; network segmentation with private VPCs and strict outbound filtering; intrusion detection and prevention systems (IDS/IPS) with 24/7 monitoring; web application firewalls (WAF); and vulnerability scanning with a formal patch management SLA. Our infrastructure benefits from AWS's underlying physical security certifications.
We maintain a formal Security Incident Response Plan with designated response teams, escalation paths, and defined recovery time objectives (RTOs). In the event of a security incident affecting personal data, we will notify affected enterprise customers within 72 hours of confirmed discovery (or sooner where legally required), and will provide regular updates throughout investigation and remediation.
All Traiq Tech employees undergo background verification at hire, sign confidentiality agreements, and complete mandatory annual security and privacy training. Access to production systems is granted on a principle of least-privilege basis, reviewed quarterly, and revoked immediately upon departure. Privileged access to customer data is logged, monitored, and subject to four-eyes approval for sensitive operations.
Aligned with enterprise security standards
Our security controls are designed in alignment with ISO 27001, SOC 2 Type II-style operational practices, and NIST CSF. Security review reports are available to enterprise customers under NDA.
To deliver our Services, Traiq Tech engages a carefully vetted set of sub-processors — third-party companies that process personal data on our behalf under written data processing agreements. These sub-processors are authorized to process data only for specific purposes compatible with our service delivery and are prohibited from using data for their own commercial purposes.
Our primary sub-processors include: Amazon Web Services (cloud infrastructure and storage); Microsoft Azure (select regional deployments); Stripe (payment processing — PCI-DSS Level 1 certified); SendGrid / Twilio (transactional email and SMS communications); Datadog (infrastructure monitoring and log aggregation — with customer data fields masked); Intercom (customer support and in-app messaging — enterprise plan customers can opt for a self-hosted support integration); and Plausible Analytics (privacy-preserving product analytics).
We maintain an up-to-date sub-processor list at traiq-tech.com/dpa#subprocessors and notify enterprise customers with at least 30 days' advance notice before adding or materially changing sub-processors. Enterprise customers may object to sub-processor changes per the terms of their DPA. Where customers use third-party integrations built on Traiq Tech's public API (such as ERP connectors for SAP, Oracle, or Salesforce), data flows are governed by both our terms and the relevant third-party's privacy practices.
Our websites may contain links to third-party sites. Traiq Tech is not responsible for the privacy practices of those sites and recommends reviewing their privacy policies independently. We do not embed third-party advertising scripts on our platform or sell advertising inventory.
Depending on your jurisdiction and the nature of your relationship with Traiq Tech, you may have various rights regarding your personal data. These rights may include: the right to access the personal data we hold about you; the right to correct inaccurate or incomplete data; the right to request deletion of your data (subject to our legal obligations and legitimate interests); and the right to data portability in a structured, machine-readable format.
Enterprise end-users should note that many of these rights are best exercised through the organization that has deployed Traiq Tech, since the organization controls the data within their Traiq Tech environment. For platform-level personal data (account records, authentication data), you may submit requests directly to privacy@traiq-tech.com. We will respond within 30 days and may ask for identity verification before processing requests.
You also have the right to withdraw consent for marketing communications at any time using the unsubscribe link in any email or by updating your notification preferences in your account settings. Withdrawal of marketing consent does not affect processing based on other lawful bases (such as contract performance or legal obligation).
We do not discriminate against individuals who exercise their privacy rights. Exercising your rights will not affect the quality or availability of Services you are entitled to receive under your enterprise agreement.
Submit a request online
You can exercise any of these rights through our data-request form at traiq-tech.com/privacy/data-request. We acknowledge requests within 5 business days and aim to respond substantively within 30 days, after verifying your identity.
For individuals in the European Economic Area (EEA), United Kingdom, and Switzerland, the General Data Protection Regulation (GDPR) and applicable national implementing legislation provide specific rights. These include: (Art. 15) the right to access; (Art. 16) the right to rectification; (Art. 17) the right to erasure ('right to be forgotten'); (Art. 18) the right to restriction of processing; (Art. 20) the right to data portability; and (Art. 21) the right to object to processing based on legitimate interests.
For international data transfers from the EEA to countries not recognized by the European Commission as providing adequate protection (including India, where Traiq Tech is headquartered), we rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism. Enterprise customers requiring additional transfer impact assessments (TIAs) for GDPR compliance may request these from dpa@traiq-tech.com.
Traiq Tech has appointed a Data Protection Representative for the EEA. EEA-based individuals may exercise their GDPR rights by contacting privacy@traiq-tech.com with the subject line 'GDPR Rights Request.' You also have the right to lodge a complaint with your local supervisory authority (e.g., the Irish Data Protection Commission for Traiq Tech's EU operations; the UK ICO for UK-based individuals) if you believe your rights have been infringed.
Our legal bases for processing personal data under GDPR are: (a) contract performance (Art. 6(1)(b)) for delivering the Services; (b) legitimate interests (Art. 6(1)(f)) for security monitoring, analytics, and fraud prevention; (c) legal obligation (Art. 6(1)(c)) for compliance purposes; and (d) consent (Art. 6(1)(a)) for marketing communications and optional analytics cookies. We do not rely on consent as a basis for processing that is required for service delivery.
GDPR transfer mechanism
International transfers of EEA personal data to Traiq Tech in India are covered by EU Standard Contractual Clauses (SCCs). Enterprise customers can request a copy of our SCCs and Transfer Impact Assessment from dpa@traiq-tech.com.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods depend on the category of data and the applicable legal and regulatory requirements in each jurisdiction.
Account and identity data is retained for the duration of the enterprise contract plus a post-termination period of 90 days during which customers may export their data. After this period, active account data is deleted or anonymized. Billing and transaction records are retained for 7 years to comply with financial record-keeping requirements under Indian and applicable international tax law. Security audit logs are retained for 12 months in hot storage and an additional 24 months in archived cold storage.
For enterprise deployments subject to sector-specific regulations (e.g., HIPAA-aligned healthcare deployments, FERPA-aligned education deployments), retention periods are configured to match the applicable regulatory minimum. Enterprise customers may configure custom retention policies within their administrative console, subject to minimum retention floors required by law.
Upon contract termination, we will delete or return all customer content (as defined in the Master Subscription Agreement) within 90 days unless a longer retention period is required by law. Backups containing customer content are rotated and purged within 90 days of the primary deletion. Customers may request a written confirmation of deletion.
If you have any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us at: Email: privacy@traiq-tech.com | Mailing Address: Data Privacy Officer, Traiq Tech Private Limited, Rajapalayam, Tamilnadu, India. You can also submit a data-subject request through our online form at traiq-tech.com/privacy/data-request.
Enterprise customers with active DPAs may also contact their dedicated Customer Success Manager or reach the DPA team directly at dpa@traiq-tech.com. For security-related disclosures, please use our responsible disclosure program at security@traiq-tech.com.
We aim to acknowledge all privacy inquiries within 5 business days and to provide a substantive response within 30 days. For complex requests or those requiring coordination with enterprise data controllers, we will inform you of any expected extension within the initial 30-day period.
Traiq Tech is built from the ground up for enterprise security and compliance requirements. Our controls are designed to help your organization meet GDPR, DPDPA, and sector-specific regulatory obligations.
Have questions about our security posture? Our team responds within one business day.