Plain-language summary: we collect the account, billing, usage, device and support information needed to provide and secure the service. We do not store full card numbers, CVVs, UPI PINs or banking passwords. We do not sell personal data.
1. Scope and our roles
This Privacy Policy applies to infinitysolutions.app, Infinity Desk, our business communications and support interactions (together, the “Services”). The provider is [ADD REGISTERED LEGAL NAME], trading as Infinity Solutions, at [ADD FULL REGISTERED ADDRESS].
For personal data used to manage our website, accounts, billing, security, marketing and support, Infinity Solutions determines why and how it is processed and acts as the data fiduciary/controller under applicable law.
For personal data a business customer places in its Infinity Desk workspace (“Customer Content”), that customer generally determines why the data is processed. Infinity Solutions processes it to provide the contracted service. Individuals whose data appears in Customer Content should normally contact the relevant customer first; we will assist that customer where required.
This policy does not apply to a third-party service with its own privacy notice, including the payment provider’s hosted checkout.
2. Personal data we collect
| Category | Examples | Why we need it |
|---|---|---|
| Account and identity | Name, business email, organisation, job role, account ID, profile information and authentication records | Create accounts, authenticate users, administer workspaces and communicate service information |
| Contact and support | Email, phone if provided, message content, attachments, support ticket history and feedback | Answer questions, troubleshoot, provide support and resolve complaints |
| Business and billing | Legal/business name, billing address, GSTIN if supplied, plan, invoice details, transaction amount, date, currency, payment status and processor reference | Process orders, administer subscriptions, issue invoices, prevent fraud and keep tax/accounting records |
| Payment | Payment method type, limited masked details where provided by the processor, token/reference and payment outcome | Confirm and reconcile payments, renew subscriptions, process refunds and address disputes |
| Usage and activity | Features used, actions, timestamps, workspace and record identifiers, settings, audit history and performance/error events | Provide features, maintain reliability, secure the service, support users and improve usability |
| Device and network | IP address, browser, device type, operating system, language, approximate region, referring URL and cookie identifiers | Deliver the website, maintain sessions, diagnose problems, prevent abuse and understand aggregate use |
| Customer Content | Client names and emails, requests, comments, tasks, files, approvals and other data submitted by users | Host and process content at the customer’s direction to provide Infinity Desk |
| Marketing preferences | Subscription choice, campaign interaction and consent/opt-out records | Send requested communications and respect preferences |
| Compliance and risk | Verification information, fraud signals, complaints, legal requests and records needed to enforce policies | Meet legal duties, protect the Services and address misuse |
Please do not send passwords, full payment-card credentials, CVVs, UPI PINs, one-time passcodes, medical records, government authentication secrets or other unnecessary highly sensitive data through support or Customer Content.
3. Where data comes from
We receive personal data:
- from you, when you visit, create an account, purchase, configure a workspace, submit a form, contact us or use the service;
- from your organisation or workspace owner, when it invites you or provides account information;
- automatically, through browser requests, logs, cookies and similar technologies;
- from service providers, such as payment status from a payment processor, email delivery information, fraud signals and support data; and
- from public or lawful business sources, such as a company website or professional profile, where relevant to a business enquiry.
4. How we use personal data
We use personal data to:
- provide, operate, personalise and maintain the Services;
- create accounts, authenticate users and administer workspace access;
- receive orders, confirm payments, issue invoices, manage renewals and process refunds;
- send transactional messages such as verification, security, billing, delivery and service notices;
- answer support, sales, legal and privacy requests;
- detect, investigate and prevent fraud, abuse, security incidents and policy violations;
- monitor reliability, diagnose errors, analyse product use and improve the Services;
- meet accounting, tax, consumer-protection, data-protection and other legal obligations;
- establish, exercise or defend legal claims and enforce agreements; and
- send marketing only as permitted by law, with an unsubscribe method.
We do not use Customer Content to advertise to the people described in it. We do not sell or rent personal data. We do not make decisions producing legal or similarly significant effects using solely automated processing unless we provide required notice and rights.
5. Grounds for processing
Depending on the applicable law and context, we process personal data:
- with your consent, including where you request a communication or opt in to non-essential technology;
- to take steps you request before a contract or to perform our contract with you or your organisation;
- for uses recognised as legitimate under applicable law, such as responding to a voluntarily supplied request, preventing fraud and managing employment-related business accounts;
- to comply with legal obligations and lawful orders; and
- for our legitimate interests or those of another person, where permitted and not overridden by your rights—for example, securing and improving a business service.
Where processing relies on consent, you may withdraw it using the same channel or another equally accessible method. Withdrawal does not affect earlier lawful processing, and some service features may no longer function if the data is necessary for them.
6. Payment information
Checkout is provided by the payment provider identified on the payment page. It collects and processes payment credentials under its own privacy policy and security obligations. Infinity Solutions does not store your full card number, CVV, UPI PIN, online-banking password or one-time passcode.
We receive limited transaction data such as the payer/account reference, amount, currency, time, method type, masked details where applicable, payment status, fraud/risk outcome and processor transaction ID. We use it to activate access, maintain records, prevent fraud, process cancellations and refunds, and handle disputes.
9. International processing
We operate from India and may use service providers that process information in other countries. Those countries may have different data-protection rules. Where applicable law requires safeguards for a transfer, we use an approved contractual or legal mechanism and assess provider protections. We do not transfer personal data to a country or territory prohibited by applicable Indian law.
10. Data retention
We keep personal data only as long as reasonably necessary for the purposes described, including service delivery, account administration, security, dispute resolution, legal compliance and legitimate business records.
| Data | Typical retention approach |
|---|---|
| Active account and Customer Content | For the subscription term and a limited export/recovery period after closure |
| Support records | Normally up to 3 years after the matter closes, unless needed longer for a dispute |
| Invoices, payment and tax records | For the period required by applicable accounting and tax law, commonly up to 8 years |
| Security and access logs | Normally up to 12 months unless required for an investigation |
| Marketing preferences | Until opt-out, plus a minimal suppression record to respect the opt-out |
| Backups | Removed on a rolling schedule after deletion from active systems |
Actual periods may vary where law, litigation hold, fraud prevention, technical backup cycles or an active dispute requires retention. We delete or de-identify data when it is no longer needed.
11. Security
We use reasonable technical, organisational and administrative safeguards designed to protect personal data, including access controls, encryption in transit, logging, backup procedures, provider review and incident-response processes appropriate to the service. Payment credentials are handled by the payment processor rather than stored by us.
No transmission or storage method is completely secure. You are responsible for using unique credentials, safeguarding authentication messages, maintaining authorised-user access and promptly reporting suspected compromise to security@infinitysolutions.app. Where required by law, we will notify affected people and authorities of a personal-data breach.
12. Your choices and rights
Depending on applicable law and your relationship with us, you may have the right to:
- receive clear information about processing;
- request a summary of personal data and processing activities;
- access, correct, complete or update personal data;
- request erasure where retention is not required;
- withdraw consent and opt out of marketing;
- raise a grievance and, where applicable, complain to the competent data-protection authority or Data Protection Board;
- nominate another person to exercise rights in the event of death or incapacity where applicable under Indian law;
- object to or restrict certain processing under applicable law; and
- request a portable copy where applicable.
Submit a request to legal@infinitysolutions.app from the relevant account email. Describe the right and data involved. We may verify identity and authority, ask for clarification, or retain information required by law. We aim to acknowledge privacy grievances promptly and respond within the period required by applicable law.
If your data is in a customer-controlled workspace, contact that customer first. We will assist it as required. You will not be discriminated against for exercising a privacy right, though we may be unable to provide a feature that genuinely requires the deleted data.
13. Children
The Services are intended for business users aged 18 or older and are not directed to children. Do not create an account for a child or intentionally submit a child’s personal data. If you believe a child’s data was supplied, contact us so we can investigate and delete it where required.
14. Third-party sites and services
The Services may link to third-party websites or integrate with services chosen by a customer. Their privacy practices are governed by their own notices. Review those notices before supplying personal data. We are not responsible for a third party’s independent processing.
15. Changes to this policy
We may update this policy to reflect product, provider or legal changes. We will post the revised version with a new effective date and give additional notice of a material change where required. If consent is required for a new purpose, we will request it rather than relying only on this notice.
16. Privacy contact and grievance
Questions, requests and complaints may be sent to:
Infinity Solutions / Data Grievance Contact
Legal entity: [ADD REGISTERED LEGAL NAME]
Grievance Officer: [ADD FULL NAME AND DESIGNATION]
Registered office: [ADD STREET, CITY, STATE, PIN, INDIA]
Phone: [ADD +91 BUSINESS PHONE]
Email: legal@infinitysolutions.app
Website: infinitysolutions.app
For customer-service complaints unrelated to privacy, see the Contact page. If we cannot resolve a privacy grievance, you may have the right to approach the Data Protection Board of India or another competent authority when the relevant legal provisions apply.