This Policy states what personal data Quinite Technologies Private Limited processes through OnwardCRM, why we process it, who receives it and how long we keep it.
Who we are
OnwardCRM is operated by Quinite Technologies Private Limited, CIN U62099GJ2023PTC139209 and GSTIN 24AAACQ8863E1ZD. In this Policy, “Onward”, “we”, “us” and “our” refer to that company.
Our registered office is at GF-001, Mauryansh Elanza, 132 Feet Ring Road, Satellite, Ahmedabad, Gujarat 380015, India.
A customer using OnwardCRM is the Data Controller for its Lead data. It decides why and how that data is processed. Onward is the Data Processor and processes the data only for the Platform, on the customer’s documented instructions, or where law requires us to act.
Data we collect
Organisation and team data
We process the Organisation’s name, address, GSTIN, plan, invoices and billing history. We also process each User’s name, email address, role, permissions, reporting line and login activity. The Platform records seat counts, call minutes, token use, available call credits and audit events.
Lead and prospect data
Customer Data may include a Lead’s name, phone number, email address, budget, BHK preference, location preference and purchase timeline. It may also include notes, tags, tasks, uploaded documents, site visits, deal history, pipeline stage and inventory interests. Leads may enter the Platform through website forms, manual entry or an enabled integration. We may retain source information to match fields and show how the Lead entered the Platform.
Calls, messages and AI data
When an Organisation uses these features, we process call audio, recordings, transcripts, phone numbers, messages, call and delivery status, duration, usage and transfer details. AI processing may produce classifications, sentiment, summaries, scores and suggested next steps.
Website and analytics data
Website forms may collect a person’s name, phone number, email address and property interest. We record page and listing views, time of access, browser and device information, referrer, interaction events and approximate location. Google Analytics 4 and Meta Pixel are described in section 10.
How we use data
- We create and administer CRM accounts, Users, roles and permissions.
- We capture Leads and operate pipelines, tasks, site visits, inventory records and reports.
- We place AI voice calls when an Organisation starts a campaign.
- We transcribe and analyse calls and support transfer to a human agent.
- We operate messaging, templates, broadcasts and automation.
- We measure seats, call minutes and tokens for billing.
- We secure the Platform, investigate misuse and keep audit records.
- We analyse use and measure marketing conversions.
- We keep records required for tax, accounting, disputes and legal compliance.
The Organisation must have a lawful basis for all Customer Data. Where consent is required, the Organisation must obtain it and honour its withdrawal. We do not sell personal data.
Meta integrations (Lead Ads & WhatsApp)
When an Organisation connects its Meta account, we process:
- Facebook access tokens to maintain the connection;
- Lead Ads data, including names, email addresses, phone numbers and custom form responses submitted through the Organisation’s lead forms;
- ad account and Page metadata needed to identify the lead forms and Pages to sync; and
- WhatsApp Business account identifiers and message content through the WhatsApp Business Platform.
We use this data only to sync leads into the Organisation’s CRM and run the Platform features the Organisation enables for those leads, including WhatsApp messaging and AI voice calling. We do not sell it or use it outside providing the Platform.
Access tokens and Lead Ads data are encrypted at rest, and Meta data is transmitted over TLS.
Lead data obtained through Meta may be processed by our service providers as described in this Policy, including for AI voice calling and message delivery. It is never sold, and access is restricted to the Organisation’s authorised Users.
Use of the WhatsApp Business Platform is subject to Meta’s WhatsApp Business Terms and Commerce Policy.
Requests to delete personal data obtained through Meta may be sent to the Grievance Officer at govind@quinite.co. We handle those requests under the rights and grievance provisions in this Policy, subject to any retention required by law.
AI calls and automated processing
An Organisation may use Onward to place outbound calls through an AI voice agent. Calls may be recorded, transcribed and analysed only where the Organisation has a lawful basis and has obtained every consent required for those activities.
Customer duty: The Organisation must identify itself and the AI caller and comply with applicable TRAI commercial-communications and DLT sender-ID requirements, including NCPR/DND screening.
AI outputs may be inaccurate or incomplete. The Organisation must apply human review before relying on a transcript, score, summary or recommendation for a closure, commitment, payment or other critical action.
Service providers
We engage service providers to operate the Platform — covering hosting, telephony, AI processing, messaging, payments, and analytics. They process personal data only on our documented instructions and under written contracts requiring confidentiality and appropriate security. A current list of sub-processors is available on request from the Grievance Officer.
International data transfers
Some sub-processors operate in India, the United States, the European Union and other countries. Customer Data may therefore be processed outside India. We use contractual controls and other safeguards required for the relevant transfer. We also comply with any transfer restriction notified under Indian data-protection law.
A provider’s processing location may depend on the service plan or technical configuration. An Organisation that requires data to remain in a specific country or region must contact us before it uploads Customer Data.
How long we keep data
| Data | Typical retention |
|---|---|
| Lead data | Subscription term plus 90 days |
| Call transcripts and recordings | 12 months |
| WhatsApp messages | 12 months |
| Billing and payment records | 7 years |
| Audit logs | 2 years |
| Analytics data | Up to 13 months |
| Deleted leads | Soft-deleted, then hard-purged after 30 days |
| Cancelled account data | Up to 90 days after cancellation, then purged |
These periods apply unless a law, court order, legal hold or active dispute requires longer retention. Encrypted backups may keep a copy for a short additional period until the backup is overwritten.
Your privacy rights
Applicable law may allow a person to ask how their personal data is processed, request correction or erasure, withdraw consent or raise a grievance.
If an Organisation collected your data, contact that Organisation first. We will assist it with the response. You may also write to our Grievance Officer. We will acknowledge a grievance within 48 hours.
Cookies and tracking
Essential cookies support login, session management and security. Google Analytics 4 is live and measures website and product use. Meta Pixel is live and measures campaign conversions.
Our cookie control offers Essential, Analytics and Marketing choices. Essential cookies remain active because the service cannot operate without them. Where consent is required, Analytics and Marketing cookies do not run until the person selects those categories. The person may later change the choice through the same control.
How we protect data
We use account authentication and permissions based on each User’s role. Database rules restrict an Organisation’s Users to the records their roles allow. Audit logs record important account activity. We encrypt data in transit and use encryption at rest where the relevant provider supports it. Access is limited to people and systems that need it for their work. We monitor the Platform and follow an incident-response process.
No security measure removes every risk. Each Organisation must protect its credentials, assign the correct roles and tell us without delay if it suspects unauthorised access.
Changes and contact
We may change this Policy when the Platform, our processing or the law changes. We will update the date shown on this page. We will give any notice required by law.