Privacy Policy
Overview
Ambduz ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website at ambduz.com and our Real Estate Customer Relationship Management (CRM) software-as-a-service platform (collectively, the "Services").
By accessing or using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our Services immediately.
Scope: This policy applies to all users of the Ambduz platform — including real estate agents, brokers, agencies, property developers, and their end clients whose data is entered into the CRM. It covers our website, web application, mobile applications, and APIs.
Who We Are
Ambduz is a Micro Enterprise registered under the Government of India's MSME framework, providing SaaS-based Real Estate CRM solutions to businesses across India and internationally.
| Detail | Information |
|---|---|
| Legal Name | Ambduz |
| Udyam Registration | UDYAM-MH-26-1039546 |
| Type | Micro Enterprise (MSME) |
| Registered Address | A-10, Twin Palm CHS, Thergaon, Dange Chowk, Haveli, Pune – 411033, Maharashtra, India |
| Website | https://ambduz.com |
| [email protected] | |
| Phone | +91 96375 11110 |
| Incorporated | 28 June 2023 |
For the purposes of applicable data protection laws, Ambduz acts as a Data Controller for data collected directly through our website and marketing activities, and as a Data Processor for personal data that our business clients (Data Controllers) upload or input into the CRM platform.
Information We Collect
3.1 Information You Provide Directly
| Category | Data Points | Purpose |
|---|---|---|
| Account Registration | Full name, email address, phone number, business name, password (hashed) | Create and manage your account |
| CRM Contact Records | Name, email, phone of property leads/clients entered by you | Core CRM functionality |
| Profile Information | Business details, role, RERA number (if applicable) | Personalisation and compliance |
| Support Communications | Messages, emails, attachments you send us | Customer support and service improvement |
| Billing & Payment | Plan selection, billing address (payment card details handled by Razorpay — not stored by Ambduz) | Subscription management |
3.2 Information Collected Automatically
- Usage Data: Pages visited, features used, session duration, click events, and error logs within the platform.
- Device Information: Browser type and version, operating system, device model, screen resolution.
- Log Data: IP address, access timestamps, referring URLs, and HTTP request headers.
- Cookies & Tracking Technologies: Session cookies, preference cookies, and analytics tags (see Section 11).
3.3 Information We Do NOT Collect
We do not collect: government ID numbers (Aadhaar, PAN) unless explicitly required, biometric data, sensitive financial data (card numbers, bank account details — these are handled exclusively by Razorpay), or location/GPS data unless you explicitly enable location-based features.
Communication Consent (TRAI / NDNC Notice):
We collect personal details like your name, email address, and phone number. By sharing your information with Ambduz — whether through our website, contact form, CRM platform, or any other channel — you authorize Ambduz to contact you via SMS, RCS, WhatsApp, Email, and other communication channels for the purposes of service delivery, support, marketing, and updates. This consent overrides any NDNC/DND registration as per TRAI regulations.
How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Details |
|---|---|
| Service Delivery | Operate, maintain, and improve the Ambduz Real Estate CRM platform and all its features. |
| Account Management | Create accounts, authenticate users, and manage subscriptions. |
| Customer Support | Respond to inquiries, resolve disputes, and provide technical assistance. |
| Billing | Process subscription payments via our payment partners (Razorpay). |
| Communications | Send service updates, security alerts, invoices, and product announcements. You may opt out of marketing emails at any time. |
| Analytics & Improvement | Understand how users interact with the platform to improve features and performance. |
| Legal Compliance | Comply with applicable laws, respond to legal requests, and enforce our agreements. |
| Security | Detect, investigate, and prevent fraudulent transactions, abuse, and security incidents. |
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
Legal Basis for Processing
Under India's Digital Personal Data Protection (DPDP) Act, 2023 and the EU General Data Protection Regulation (GDPR), we process your data on the following lawful bases:
- Consent: Where you have given clear consent (e.g., marketing emails, optional cookies).
- Contract Performance: Where processing is necessary to perform the SaaS subscription contract with you.
- Legitimate Interests: For analytics, security, and fraud prevention — balanced against your rights.
- Legal Obligation: Where we are required to process data by applicable Indian or international law.
For users in the European Economic Area (EEA) or United Kingdom, you have enhanced rights under the GDPR as described in Section 10.
Sharing & Disclosure
We do not sell your personal data. We may share your information only in the following limited circumstances:
- Service Providers: Trusted third-party vendors who assist us in operating our platform (cloud hosting, email delivery, payment processing, analytics). These vendors are contractually bound to protect your data and use it only for the services they provide to us.
- Business Clients (CRM Users): If you are an end-client whose data has been entered into the Ambduz CRM by a real estate business, that business is the Data Controller for your information.
- Legal Requirements: Where required by court order, government request, or applicable law (including the IT Act, 2000 and DPDP Act, 2023).
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, subject to equivalent privacy protections.
- With Your Consent: In any other circumstances, only with your explicit consent.
Third-Party Services
Ambduz integrates with and relies on the following categories of third-party services. Each has its own privacy policy:
| Service Type | Provider(s) | Purpose |
|---|---|---|
| Payment Processing | Razorpay | Subscription billing; payment card data is processed and stored exclusively by Razorpay — Ambduz never sees or stores full card details. |
| Cloud Hosting | [Your hosting provider, e.g., AWS / Google Cloud] | Secure infrastructure for the Ambduz platform. |
| Email Delivery | [e.g., SendGrid / Mailgun] | Transactional emails, invoices, notifications. |
| Analytics | [e.g., Google Analytics] | Aggregate platform usage analytics. |
| Meta Platforms | Meta (Facebook/Instagram) | Business page management and advertising, subject to Meta's Data Policy. |
| Google Services | Google LLC | Google Workspace, Maps API (if enabled). Subject to Google's Privacy Policy. |
⚠ We are not responsible for the privacy practices of third-party services. We encourage you to review their respective privacy policies.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law:
| Data Type | Retention Period |
|---|---|
| Account and Profile Data | Duration of active subscription + 90 days after account closure |
| CRM Contact Records | As long as the subscribing business maintains an active account |
| Billing Records | 7 years (as required by Indian tax and accounting laws) |
| Support Communications | 2 years from the date of resolution |
| Usage/Analytics Logs | 12 months (aggregated/anonymised thereafter) |
| Security/Audit Logs | 90 days |
Upon account deletion, we will delete or anonymise your personal data within 30 days, except where retention is required by law.
Data Security
We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit using TLS/HTTPS
- Encrypted storage for sensitive data fields
- Hashed and salted passwords (we never store plain-text passwords)
- Role-based access controls within the platform
- Regular security assessments and vulnerability scanning
- Strict internal data access policies on a need-to-know basis
In the event of a data breach that affects your personal data, we will notify you and the relevant authorities (as required under the DPDP Act, 2023) within the legally mandated timeframe.
Your Rights
Under the DPDP Act, 2023 (India) and applicable international law, you have the following rights regarding your personal data:
| Right | What It Means |
|---|---|
| Right to Access | Request a copy of the personal data we hold about you. |
| Right to Correction | Request correction of inaccurate or incomplete data. |
| Right to Erasure | Request deletion of your personal data (subject to legal retention obligations). |
| Right to Withdraw Consent | Withdraw previously given consent at any time, without affecting prior processing. |
| Right to Grievance Redressal | Raise a complaint with our Grievance Officer (see Section 15). |
| Right to Data Portability | Request your data in a structured, machine-readable format. |
| Right to Object | Object to processing based on legitimate interests or for direct marketing. |
| Right to Nominate | Nominate another individual to exercise your rights in case of death or incapacity (DPDP Act, 2023). |
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
Cookies & Tracking Technologies
We use cookies and similar technologies to operate and improve our Services. Types of cookies we use:
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Authentication, security, session management. Required for the platform to function. | No (essential) |
| Functional | Remember your preferences (language, layout, dashboard settings). | Yes |
| Analytics | Understand how users navigate the platform to improve features. | Yes |
| Marketing | Serve relevant advertisements on third-party platforms (only on public website). | Yes |
You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may impact the functionality of our Services.
Children's Privacy
Our Services are intended solely for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at [email protected] and we will take steps to delete such information promptly.
International Data Transfers
Ambduz is headquartered in India. Your information may be stored and processed in India or in other countries where our cloud service providers operate. When we transfer personal data outside India, we ensure adequate safeguards are in place consistent with the DPDP Act, 2023, including:
- Transfers only to countries notified by the Indian government as providing adequate data protection, or
- Standard contractual clauses or equivalent data transfer agreements with recipients.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send a notification to your registered email address
- Display a prominent notice within the platform
We encourage you to review this policy periodically. Continued use of our Services after any changes constitutes your acceptance of the updated policy.
Contact & Grievance Officer
As required under the DPDP Act, 2023 and IT Act, 2000, we have designated a Grievance Officer for addressing privacy concerns:
Grievance Officer / Data Protection Contact
Ambduz
A-10, Twin Palm CHS, Thergaon, Dange Chowk,
Haveli, Pune – 411033, Maharashtra, India
Email: [email protected]
Phone: +91 96375 11110
We will acknowledge your complaint within 48 hours and endeavour to resolve it within 30 days