DIGITAL PERSONAL DATA PROTECTION POLICY
[Formulated under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025]
Policy adopted and approved in the Board Meeting dated 07/04/2026
1. Introduction and Purpose
This Digital Personal Data Protection Policy (“Policy”) is formulated with reference to the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), as applicable to the Organisation from time to time.
Logix Built Solutions Limited (“Organisation”, “We”, “Us”, or “Our”) owns and operates “TradeOne CRM”, an integrated enterprise SaaS business management system accessible via web portal (https://tradeonecrm.com/) and mobile application (“TradeOne - AI CRM App”). The platform delivers end-to-end solutions for sales CRM, lead pipeline management, field workforce automation, attendance tracking, tour planning, inventory management, order processing, delivery management, and enterprise operations for manufacturers, distributors, traders, and service enterprises.
We are committed to collecting, storing, processing, and transferring digital personal data lawfully, fairly, transparently, and securely. This Policy establishes the governance framework and overarching privacy and data protection requirements governing personal data handled across TradeOne CRM. Detailed technical and operational standards may be maintained separately through applicable internal policies, procedures, and security standards. This Policy is intended to:
- Establish an internal compliance framework under the DPDP Act, DPDP Rules, and other applicable privacy and data protection requirements across all TradeOne CRM SaaS operations, as applicable from time to time.
- Delineate, protect, and give effect to the statutory rights of Data Principals (including authorised representatives, administrators, employees, field sales executives, and other individuals whose personal data is processed through TradeOne CRM, as applicable).
- Clearly define the dual capacities in which the Organisation operates - as a Data Fiduciary for direct platform subscriptions, website inquiries, and account billing, and as a Data Processor for client-controlled enterprise CRM records.
- Embed privacy-by-design, data minimisation, and role-based security across mobile telemetry, field force tracking, and cloud data architecture.
- Foster an institutional culture of data privacy, accountability, and regulatory compliance across all Personnel.
2. Scope and Applicability
2.1 Scope of Application
This Policy applies to:
- All processing of digital personal data carried out by or on behalf of the Organisation within the territory of India in connection with TradeOne CRM, including personal data collected in digital form or collected in non-digital form and subsequently digitised.
- Processing of digital personal data outside India, where such processing is in connection with offering TradeOne CRM SaaS services to enterprises and Data Principals within the territory of India.
- All directors, officers, employees, contractors, consultants, and other persons acting under the Organisation’s authority who are authorised to process personal data on behalf of the Organisation (“Personnel”), as applicable.
- Personal data collected across web portals, mobile application interfaces, enterprise onboarding forms, client communications, customer care channels, or offline documentation subsequently digitised.
- Third-party service providers, Data Processors, cloud infrastructure providers, telemetry gateways, and communication service providers engaged by the Organisation shall, as applicable to their role and processing activities, be subject to appropriate contractual, confidentiality, security, and data protection requirements.
2.2 Statutory Exclusions
This Policy does not apply to:
- Personal data processed by an individual for any purely personal or domestic purpose.
- Personal data that is made or caused to be made publicly available by the Data Principal to whom such personal data relates, or by any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.
3. Definitions
Unless the context otherwise requires, terms used in this Policy shall carry the meaning assigned to them under the DPDP Act and the rules framed thereunder:
- “Act” or “DPDP Act”: Means the Digital Personal Data Protection Act, 2023, as amended from time to time.
- “Consent”: Means any freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes, signified through clear affirmative action, agreeing to the processing of personal data for a specified purpose.
- “Consent Manager”: Means a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.
- “Data Fiduciary”: Means any person who, alone or in conjunction with other persons, determines the purpose and means of processing personal data. For processing activities where the Organisation determines the purpose and means of processing (such as platform user registration, billing, website inquiries, and product subscriptions), the Organisation shall act as the Data Fiduciary. Where the Organisation processes personal data solely on behalf of an enterprise client and in accordance with its documented instructions (such as field staff logs, customer CRM records, lead databases, and delivery receipts), the client acts as the Data Fiduciary and the Organisation shall act as a Data Processor to the extent applicable under the DPDP Act and DPDP Rules.
- “Data Principal”: Means the individual to whom the personal data relates (including enterprise administrators, field sales executives, delivery agents, customer business contacts, and authorized portal users).
- “Data Processor”: Means any person who processes personal data on behalf of a Data Fiduciary.
- “Personal Data”: Means any data about an individual who is identifiable by or in relation to such data.
- “Personal Data Breach”: Means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises its confidentiality, integrity, or availability.
- “Platform”: Means the TradeOne CRM web portal (https://tradeonecrm.com/), mobile applications (“TradeOne - AI CRM App”), and associated cloud services operated by the Organisation.
- “Processing”: Means a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, retrieval, use, alignment, combination, transmission, restriction, erasure, or destruction.
- “Significant Data Fiduciary” or “SDF”:Means any Data Fiduciary, or class of Data Fiduciaries, notified as such by the Central Government under Section 10 of the DPDP Act, having regard to such factors as may be applicable under the DPDP Act, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
4. Categories of Data Principals and Personal Data Processed
TradeOne CRM processes personal data across specific operational categories, governed strictly by the principles of purpose limitation and data minimisation:
4.1 Enterprise Client Administrators & Registered Users
Identity & Business Contact Data: Full name, corporate email address, mobile number, job title, department, enterprise name, registered business address, and account authentication information necessary to establish and secure access to the Platform. Authentication secrets such as passwords, where used, shall be protected using appropriate security mechanisms and shall not be stored in plaintext.
Subscription & Financial Administration: Corporate billing address, GSTIN, payment status, transaction and reference identifiers, and financial reconciliation data. Sensitive payment authentication credentials (such as credit/debit card details, net banking passwords, or UPI PIN) are processed directly by authorized third-party payment gateways and are not stored by the Organisation.
4.2 Field Sales Executives & Mobile App Users
Field Automation & Telemetry Data: Precise or approximate GPS geo-location coordinates, geo-tagged check-in and check-out timestamps, tour routes, distance travelled, and attendance logs collected through the mobile application when the relevant field-force or attendance functionality is enabled or used, for workforce management, attendance verification, and tour planning.
Operational Media & Attachments: Photographs captured via device camera or uploaded from storage representing proof of delivery, customer site visit evidence, business cards, and documentation attached to sales orders or client interactions when the relevant functionality is used.
4.3 Customer Contacts, Leads & Enterprise CRM Data (Processed on Client Instructions)
CRM & Transactional Records: Names, professional contact numbers, business designations, inquiry notes, quotations, purchase/sales orders, inventory entries, dispatch records, and customer feedback entered into the platform by enterprise users under their administrative control.
4.4 All Platform Users
Technical & Usage Telemetry: IP address, device model, operating system version, app version, unique device identifiers, crash logs, and session activity collected automatically for platform security, maintenance, and performance optimization.
5. Grounds for Processing Personal Data
The Organisation shall process personal data only in accordance with the DPDP Act and for a lawful purpose, based on the Data Principal’s consent or for certain legitimate uses recognised under the DPDP Act, as applicable.
5.1 Consent Framework
Where consent is the applicable legal basis, it shall be free, specific, informed, unconditional, and unambiguous, obtained through clear opt-in affirmative action. Pre-ticked checkboxes or bundled consent mechanisms are strictly prohibited.
A clear, standalone notice in plain English (with the option to access the 22 languages specified in the Eighth Schedule to the Constitution of India) shall accompany or precede the request for consent provide the Data Principal with the information required under the DPDP Act and DPDP Rules, including an itemised description of the personal data to be processed, specified purposes, and the manner of exercising rights and grievances.
Data Principals may withdraw consent at any time with the ease of doing so being comparable to the ease with which consent was given. Upon receipt of a valid withdrawal request, the Organisation shall cease processing based on that consent within a reasonable time and, where applicable, cause its Data Processors to do the same, unless continued processing without consent is required or authorized under applicable law.
5.2 Certain Legitimate Uses (Section 7)
The Organisation may process personal data without separate consent for certain legitimate uses recognised under Section 7 of the DPDP Act, as applicable to the Organisation and the relevant processing activity, including:
- Processing for the specified purpose for which personal data was voluntarily provided by the Data Principal without objection.
- Processing for compliance with any applicable law, judgment, decree, or order issued under any law in India, or compliance with any judgment/order relating to civil/contractual claims under law outside India.
- mployment-related purposes and purposes of safeguarding the enterprise from loss or liability, including prevention of corporate espionage, protection of trade secrets or intellectual property, and providing services or benefits sought by employees, to the extent permitted under Section 7 of the DPDP Act.
- Responding to medical emergencies, public health threats, disasters, or breakdown of public order under Section 7.
- Any other legitimate use expressly recognised under Section 7 of the DPDP Act, where applicable.
6. Enterprise SaaS Architecture & Field Automation Safeguards
TradeOne CRM implements specialized policy and technical guardrails for enterprise field operations:
- Configurable GPS Tracking: Mobile location tracking and geo-fencing features are configured for field-force/drivers, attendance, delivery, and tour-related functionality and operate in accordance with the applicable enterprise configuration and usage settings. Enterprise administrators are responsible for configuring tracking parameters in accordance with applicable internal policies and law.
- Device Hardware Permissions: Camera and file access are used for user-initiated attachments and related Platform functionality and are not intentionally accessed by the application in the background for such purposes.
- Dual-Capacity Processing Governance: Where TradeOne CRM acts as a Data Processor for enterprise clients, the client retains full authority as the Data Fiduciary over end-customer and field worker data. The Organisation shall process such data strictly under documented instructions, executed DPAs, and applicable statutory standards.
- Age Restriction & Commercial Scope: TradeOne CRM is an enterprise business solution intended for use by individuals who have completed eighteen years of age and is not intended for registration or use as a direct Platform user by children. Where the Organisation acts as a Data Processor for an enterprise client, the Organisation may process personal data contained in the client's records, including data relating to individuals below eighteen years of age, in accordance with the client's documented instructions, applicable contractual terms, and applicable law.
7. Obligations of the Organisation
7.1 Purpose Limitation and Data Minimisation
Personal data collected across web portals, CRM pipelines, and mobile applications is strictly restricted to what is reasonably necessary for platform functionality and contractual delivery.
7.2 Data Accuracy, Completeness and Consistency
The Organisation implements reasonable controls, including authentication and verification mechanisms, and provides appropriate tools to enable authorised enterprise users to correct and update personal data within their authorised access. Where the Organisation acts as a Data Processor, the enterprise client remains responsible for the accuracy and maintenance of client-controlled CRM records, subject to the applicable agreement and law.
7.3 Storage Limitation, Erasure & Client Instructions
Personal data shall not be retained beyond the period necessary for the specified purpose, or beyond any applicable retention period prescribed under the DPDP Act, DPDP Rules, or other applicable law, unless further retention is required or permitted by law.
For client-controlled CRM data processed as a Data Processor, data retention, backup cycles, and final erasure or export upon contract termination shall be governed by the applicable Master SaaS Agreement, DPA, the client’s documented instructions, and applicable law.
Where processing is based on consent, upon withdrawal of consent, the Organisation shall cease processing based on that consent within a reasonable time and, where applicable, cause its Data Processors to do the same, and shall erase the relevant personal data when retention is no longer required or permitted under applicable law, subject to applicable security, backup, and dispute-resolution requirements.
7.4 Reasonable Technical and Organisational Security Safeguards
The Organisation implements reasonable technical and organisational measures appropriate to the nature and risks of the processing, including, as applicable:
- Encryption of personal data in transit using TLS 1.3/HTTPS and industry-standard encryption at rest.
- Role-based access controls, appropriate authentication, and segregation of administrative privileges, as applicable to the relevant systems and users.
- Appropriate logging and monitoring mechanisms for security, operational, and incident-management purposes.
- Security monitoring, threat detection, and other risk-based security measures appropriate to the relevant systems and processing activities.
- Appropriate backup, recovery, and business-continuity measures proportionate to the nature and risks of the relevant systems and processing activities.
7.5 Personal Data Breach Management
On becoming aware of a personal data breach, the Organisation shall notify the Data Protection Board of India and affected Data Principals, as applicable, without undue delay and in the form, manner, and within the timelines prescribed under the DPDP Act and DPDP Rules.
Where the Organisation acts as a Data Processor, it shall notify the relevant enterprise Data Fiduciary without undue delay upon becoming aware of a personal data incident, in accordance with the applicable DPA, Master SaaS Agreement, and applicable law, to enable the Data Fiduciary to meet its regulatory obligations.
The Organisation maintains a documented incident response process and designates appropriate personnel or an incident response team, as appropriate to the nature and severity of the incident, to contain, investigate, remediate, and document personal data breaches. Records of material breaches shall be maintained in accordance with law.
7.6 Grievance Redressal Mechanism
The Organisation maintains an effective and readily accessible grievance redressal mechanism through its Grievance Officer and shall address grievances within the timeline prescribed under applicable law.
7.7 Data Processor & Subprocessor Oversight
Relevant cloud infrastructure providers, database hosts, communication gateway vendors, and other service providers that process personal data on behalf of the Organisation shall, where applicable, be subject to appropriate written contractual arrangements, including Data Processing Agreements, requiring confidentiality, appropriate security safeguards, and compliance with applicable data protection requirements.
8. Sharing and Disclosure of Personal Data
Personal data processed through TradeOne CRM may be disclosed only to the extent necessary to the following categories:
- Cloud & Infrastructure Providers: Secure enterprise cloud servers and database hosting infrastructure engaged under binding DPAs.
- Communication & Telemetry Gateways: SMS gateways, WhatsApp Business APIs, email delivery platforms, and OTP verification services.
- Financial Intermediaries: Authorized payment service providers and banking partners for SaaS subscription settlements.
- Enterprise Clients (Role-Based Visibility): Field sales telemetry, visit logs, delivery proofs, and other client-controlled records may be made available to authorised personnel of the respective enterprise client in accordance with the client's role-based access configuration, documented instructions, and applicable law.
- Statutory Authorities: Judicial, regulatory, law enforcement, or government bodies where mandatory under applicable law.
9. Rights of Data Principals
Under the DPDP Act and DPDP Rules, Data Principals are entitled to:
- Right to Access Information: To obtain, in the manner prescribed under applicable law, a summary of Personal Data being processed, details of the processing activities undertaken, and the identities of other Data Fiduciaries and Data Processors with whom the Personal Data has been shared, together with a description of the Personal Data so shared, subject to applicable legal exceptions.
- Right to Correction, Completion, Updating and Erasure: To request correction of inaccurate or misleading personal data, completion of incomplete data, updating of data, and erasure where applicable under the DPDP Act and DPDP Rules, subject to applicable legal, contractual, and retention requirements.
- Right to Grievance Redressal: To access readily available grievance redressal mechanisms regarding any act or omission of the Organisation in relation to their personal data.
- Right to Nominate: To nominate another individual to exercise statutory rights on their behalf in the event of death or incapacity, in the prescribed manner.
- Right to Withdraw Consent: To withdraw consent at any time with comparable ease, without affecting the lawfulness of processing prior to withdrawal.
10. Duties of Data Principals
In accordance with Section 15 of the DPDP Act, Data Principals utilizing TradeOne CRM shall comply with all applicable laws, refrain from impersonating other persons, provide authentic verification records, and avoid submitting false or frivolous complaints.
11. Cross-Border Transfer of Personal Data
The Organisation may transfer Personal Data outside India, including to Data Processors, where permitted under applicable law. Any such transfer shall be subject to applicable requirements or restrictions prescribed by the Central Government and appropriate contractual, technical, and organisational safeguards. Such transfer shall not affect the rights of Data Principals under applicable law.
12. Significant Data Fiduciary Obligations
If the Organisation is notified as a Significant Data Fiduciary under Section 10 of the DPDP Act, it shall appoint an India-based Data Protection Officer responsible to the Board of Directors, engage an independent data auditor for periodic audits, and conduct Data Protection Impact Assessments (DPIA) as prescribed.
13. Grievance Officer / Authorised Privacy Contact Person
The designated Grievance Officer for TradeOne CRM is:
Name: Mr. Chirag Patel | Designation: Chief Technology Officer & Grievance Officer
Email: cp@logixbuilt.com / development.tradeonecrm@gmail.com
Contact Number: +91 97246 76277 / +91 70462 27768
Address: Sh. 314 - 322, Sahaj Icon, Near Prime Arcade, A M Road, Adajan, Surat - 395009, Gujarat, India
Support Contacts: +91 88669 89930 / +91 99090 22418
Website: https://tradeonecrm.com/
14. Training and Awareness
The Organisation conducts periodic training sessions for Personnel-specifically product engineering, technical support, and client onboarding teams-on data protection principles, RBAC access controls, and statutory duties under the DPDP Act.
15. Phased Implementation and Alignment
The Organisation aligns TradeOne CRM with the phased commencement schedule notified by the Central Government under the DPDP Act and DPDP Rules, maintaining continuous compliance as specific provisions come into force.
16. Policy Review, Governance and Updates
This Policy shall be reviewed at least annually, and additionally whenever necessitated by statutory amendments or platform enhancements. Amendments to this Policy shall be approved in accordance with the Organisation’s applicable corporate governance and delegation framework and communicated to relevant stakeholders, as appropriate.
17. Consequences of Non-Compliance and Statutory Penalties
Non-compliance with this Policy by Personnel may result in disciplinary action up to termination of employment or contract, subject to applicable law and contract terms, without prejudice to statutory or contractual consequences applicable to the Organisation or the concerned person.
The Data Protection Board of India may impose monetary penalties and take such other action as may be prescribed under the DPDP Act, DPDP Rules, and other applicable law, as amended from time to time, for breaches of statutory obligations.