Version 1.0

Privacy Policy

This Privacy Policy (“Privacy Policy”) forms an integral part of, and is expressly incorporated by reference into, the Terms & Conditions governing the Platform, Website and Services, and explains how SutraOS Technologies Private Limited (“SutraOS”, “We”, “Us” or “Our”) as the legal entity owning and operating the SutraFin platform (“Platform”) and brand (“SutraFin”), collects, receives, uses, processes, shares, discloses, stores, retains and protects Personal Information relating to Users, including individuals representing Businesses and other persons interacting with the Platform (“User”, “Users” or “You”). SutraOS is the licensee, author, owner and publisher of the Software and operates the Platform and Services under the name of SutraFin.

BY ACCESSING OR USING THE PLATFORM, WEBSITE OR SERVICES, OR BY OTHERWISE PROVIDING US WITH YOUR INFORMATION, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. WHERE PROCESSING OF YOUR PERSONAL INFORMATION REQUIRES YOUR CONSENT UNDER APPLICABLE LAW, SUCH CONSENT SHALL BE OBTAINED THROUGH AN APPROPRIATE AFFIRMATIVE MECHANISM. IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, YOU MUST NOT ACCESS OR USE THE PLATFORM, WEBSITE OR SERVICES, OR PROVIDE US WITH YOUR INFORMATION. IF YOU ACT ON BEHALF OF AN INDIVIDUAL OR AN ENTITY, YOU REPRESENT AND WARRANT THAT YOU ARE DULY AUTHORISED TO ACT ON SUCH INDIVIDUAL’S OR ENTITY’S BEHALF AND, WHERE APPLICABLE, TO PROVIDE OR AUTHORISE THE PROCESSING OF INFORMATION IN ACCORDANCE WITH THIS PRIVACY POLICY.

REGULATORY BASIS AND SCOPE

This Privacy Policy is formulated and implemented in accordance with applicable Indian data-protection, privacy and information-technology laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), to the extent applicable and in force from time to time, the Information Technology Act, 2000 and rules made thereunder, and other applicable laws and regulatory requirements relating to the processing and protection of Personal Data (collectively, “Applicable Data Protection Laws”). We shall process Personal Data in accordance with the Applicable Data Protection Laws applicable to the relevant processing activity.

This Privacy Policy applies to Personal Data processed by Us in connection with the Platform, Website and Services, including information collected during registration, business onboarding, transactions, delivery, communications and customer support. Where a User accesses or uses the Platform on behalf of a Business or other legal entity, such User represents that the User is duly authorised to provide the relevant information and, where required, has obtained the necessary permissions or consents. Where Personal Data is transferred or processed across jurisdictions, We and the relevant parties shall comply with the Applicable Data Protection Laws governing such transfer or processing. We do not currently provide lending, credit or financing services through the Platform and do not currently process Personal Data for credit underwriting, credit-bureau assessment, loan servicing, loan recovery or collections.

DEFINITIONS

“Applicable Law” means all applicable laws, statutes, ordinances, rules, regulations, notifications, circulars, directions, orders, judgments and other legal or regulatory requirements applicable to SutraOS, the Platform, the Services, the relevant User or the relevant processing activity, as amended, modified, supplemented or replaced from time to time.

“Business” means any retailer, distributor, supplier, seller, proprietorship, partnership, company, LLP or other business or legal entity that accesses or uses the Platform or Services, whether directly or through an authorised representative.

“Data Fiduciary” shall have the meaning assigned to such term under the DPDP Act or corresponding Applicable Data Protection Laws and generally means a person who, alone or in conjunction with other persons, determines the purpose and means of processing Personal Data.

“Data Principal” shall have the meaning assigned to such term under the DPDP Act or corresponding Applicable Data Protection Laws and, where applicable, means the individual to whom the Personal Data relates.

“Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under the Applicable Data Protection Laws. For purposes of this Privacy Policy, the terms “Personal Data” and “Personal Information” may be used interchangeably, unless the context or Applicable Data Protection Laws require otherwise.

“Platform” means the digital platform made available under the name of SutraFin, including the website, mobile application, software, interfaces, systems and associated digital functionalities made available from time to time.

“Processing” shall have the meaning assigned to such term under Applicable Data Protection Laws and includes any operation or set of operations performed on Personal Data, whether or not by automated means.

“Services” means the services, features and functionalities made available by SutraFin through or in connection with the Platform and Website from time to time.

“User” means any natural person who accesses, registers on, or uses the Platform, Website or Services, whether independently or on behalf of a Business, legal entity or other organization, and includes Businesses, End-Users and General Users, as applicable.

“Website” means the website or web-based interface through which Platform or Services are made available, including any successor or replacement website.

INFORMATION WE COLLECT

Depending upon the nature of the User’s interaction with the Platform, We may collect information such as the User’s name, mobile telephone number, email address, designation, business role, authorised representative details and other information reasonably necessary to establish or maintain the User’s account or business relationship with Us.

Where a User registers or participates on the Platform on behalf of a Business, We may collect business-related information including the legal or trade name of the Business, constitution or type of business, registered or business address, GSTIN, PAN or other applicable business identifiers, licences, registrations, documents and other information reasonably necessary for business verification, onboarding, compliance or transaction purposes. Where documents relating to a Business contain Personal Data of individuals, such Personal Data may also be processed to the extent reasonably necessary for the relevant purpose.

Where transaction or order functionality is enabled through the Platform, We may process information relating to orders, products, quantities, prices, discounts, invoices, taxes, returns, cancellations, credit notes, payment status and transaction history. Such information may be associated with a User or Business account where necessary to operate the Platform, maintain transaction records, provide support, resolve disputes or comply with Applicable Law.

Where delivery or fulfilment services are enabled through the Platform, We may process information necessary for delivery, including delivery addresses, recipient names, contact details, delivery instructions, delivery status and delivery confirmation. Such information may be shared with relevant logistics or delivery providers where necessary to complete the relevant transaction or provide the requested service.

When a User accesses or uses the Platform, We may automatically collect or receive certain technical and security information, including IP address, browser type, operating system, device or application information, login records, timestamps, session information, security logs, error logs and other technical information generated through use of the Platform. Such information may be processed for authentication, security, fraud prevention, troubleshooting, system administration, analytics and improvement of the Platform.

Where a User contacts Us, submits a complaint, raises a grievance, requests assistance, provides feedback or otherwise communicates with Us, We may process the information contained in such communication, including correspondence, attachments, support tickets, feedback and grievance-related information.

We may process Personal Data voluntarily provided by a User through account registration, forms, document uploads, customer-support interactions, communications or other Platform features, provided that such processing is undertaken for a lawful and relevant purpose and in accordance with Applicable Data Protection Laws.

We may receive Personal Data from participating Businesses, authorised representatives, transaction counterparties, service providers or other persons in connection with the Platform. Where such information is received, We shall process it in accordance with Applicable Data Protection Laws and this Privacy Policy.

GENERAL PRIVACY STATEMENTS (APPLICABLE TO ALL USERS)

We shall process Personal Data for specified, lawful and relevant purposes connected with the operation of the Platform, provision of requested Services, business transactions, security, compliance, support and other purposes disclosed to the User or otherwise permitted under Applicable Data Protection Laws.

Where consent is required under Applicable Data Protection Laws, We shall provide an appropriate notice and obtain consent through an affirmative mechanism. Where processing is permitted on another lawful basis recognised under Applicable Data Protection Laws, We may process Personal Data on such basis without separately relying on consent. For purposes of the DPDP Act, We act as the Data Fiduciary in respect of Personal Data processed by Us in connection with the Platform and Services, except where We process Personal Data on behalf of another person in a capacity recognised under Applicable Data Protection Laws.

We shall provide Users with clear information regarding the Personal Data proposed to be collected, the purposes for which such Personal Data is proposed to be processed, the manner in which applicable rights may be exercised and such other information as may be required under Applicable Data Protection Laws.

Where consent forms the basis of processing, such consent shall, where required by Applicable Data Protection Laws, be specific, informed and capable of being demonstrated through appropriate records. Consent records may include information concerning the relevant account, notice or document version, date and time of consent and appropriate audit information.

Where processing is based on consent and Applicable Data Protection Laws permit withdrawal of such consent, the User may withdraw consent through the mechanism made available by Us or by contacting Us through the details specified in this Privacy Policy. Withdrawal of consent shall not affect the lawfulness of processing undertaken before such withdrawal. Where withdrawal affects Our ability to provide a particular Platform feature or Service, the consequences of such withdrawal may be communicated to the User.

We seek to collect and process Personal Data that is reasonably necessary and proportionate for the relevant purposes.

We may rely upon information provided by Users and participating Businesses for the purposes for which such information is collected. Users are expected to provide accurate, complete and updated information and to promptly notify Us where material information requires correction or updating.

Where the Platform requests access to device features such as a camera, selected files or photographs, notifications or location, such permissions shall be requested only where reasonably necessary for a specific Platform functionality or User-initiated activity. A User may manage device-level permissions through the relevant device settings, subject to the effect that withdrawal of a permission may have on the relevant Platform functionality.

We do not sell Personal Data of Users as a standalone commercial asset. Personal Data may, however, be shared with transaction counterparties, Third-Party Service Providers and other recipients in accordance with this Privacy Policy and Applicable Data Protection Laws.

We may process and retain Personal Data where necessary to comply with applicable tax, accounting, corporate, regulatory, judicial, law-enforcement, cybersecurity or other legal obligations, or to establish, exercise or defend legal rights and claims.

We may process Personal Data for detecting, preventing and investigating fraud, unauthorised access, misuse of accounts, cybersecurity incidents, abuse of Platform functionality and other activities that may threaten the security or integrity of the Platform.

TERMS APPLICABLE TO BUSINESSES

Where a User accesses or uses the Platform on behalf of a retailer, distributor, supplier, seller, proprietorship, partnership, company, LLP or other business, We may process Personal Data of such User and other individuals whose information is provided in connection with the relevant Business account.

The relevant Business shall be responsible for ensuring that information submitted to the Platform is accurate, lawful and appropriately authorised. Where a Business provides Personal Data relating to employees, representatives, delivery personnel or other individuals, the Business shall be responsible for ensuring that such disclosure to Us is lawful and permitted under Applicable Data Protection Laws.

Business information may be processed for onboarding, business verification, account administration, authentication, transaction management, invoicing, delivery, customer support, fraud prevention, compliance, audit, dispute resolution and other purposes connected with the Business’s participation on the Platform.

We may share relevant Business and transaction information with another Business participating in the same transaction where such disclosure is reasonably necessary to enable the transaction, fulfil an order, issue an invoice, coordinate delivery, resolve a dispute or provide another requested Platform service.

We shall not be responsible for the independent privacy practices of a Business or third party that receives Personal Data from another User or otherwise processes Personal Data outside Our control. Such processing shall be governed by the privacy practices and legal obligations of the relevant Business or third party, without prejudice to Our obligations under Applicable Data Protection Laws.

COOKIES AND SIMILAR TECHNOLOGIES

The Platform may use cookies, software development kits, pixels, local storage, logs and similar technologies to enable essential functionality, remember preferences, maintain sessions, improve security, understand Platform usage and support analytics.

Cookies and similar technologies may be categorised as necessary, preference-related, analytics-related or otherwise based on their purpose and applicable legal requirements.

Where consent is legally required for a particular cookie or similar technology, We shall seek such consent through an appropriate mechanism. Users may also manage certain cookie preferences through their browser or device settings, although disabling certain technologies may affect the availability or functionality of certain features of the Platform.

Where a separate Cookie Policy is provided by Us, such Cookie Policy shall be read together with this Privacy Policy and shall provide further information concerning the cookies and similar technologies used by the Platform.

CONFIDENTIALITY AND SECURITY

We recognise that Personal Data should be protected against unauthorised access, alteration, disclosure, misuse, loss or destruction and shall maintain reasonable technical and organisational safeguards appropriate to the nature of the Personal Data processed and the risks associated with such processing.

Such safeguards may include appropriate access controls, authentication, encryption, monitoring, logging, backup, vulnerability management and incident-response measures.

Access to Personal Data within Our organisation shall be restricted to persons who require such access for legitimate business, operational, technical, compliance or support purposes and, where appropriate, shall be subject to confidentiality obligations.

No electronic transmission or storage system can be guaranteed to be completely secure. Accordingly, while We shall take reasonable measures to protect Personal Data, We cannot guarantee absolute security against every possible security incident, cyberattack, unauthorised access or technical failure.

In the event of a Personal Data breach or other security incident, We shall take reasonable and legally required measures to investigate, contain, mitigate and remediate the incident and shall provide notices to affected individuals and/or competent authorities where required under Applicable Data Protection Laws.

SUB-PROCESSORS AND THIRD-PARTY SERVICE PROVIDERS

We may engage Third-Party Service Providers and technology vendors to support the operation of the Platform and to perform services on Our behalf.

Such Third-Party Service Providers may include cloud-hosting providers, data-storage providers, payment service providers, logistics and delivery providers, communications providers, authentication providers, cybersecurity providers, analytics providers, customer-support providers and other technology or operational vendors.

We may disclose or provide access to Personal Data to such Third-Party Service Providers only to the extent reasonably necessary for the relevant service and subject to appropriate contractual, technical or organisational safeguards and Applicable Data Protection Laws.

Where a third party independently determines the purposes and means of processing Personal Data, such third party may process the relevant Personal Data in accordance with its own privacy practices and Applicable Data Protection Laws.

We may also disclose Personal Data where required or permitted by Applicable Law, including pursuant to a court order, governmental direction, regulatory requirement, law-enforcement request or other lawful process.

We may disclose Personal Data where reasonably necessary to protect Our rights, property, safety or security, or those of Users, participating Businesses or other persons, or to detect, prevent or investigate fraud, misuse or unlawful activity, subject to Applicable Data Protection Laws.

RETENTION AND DELETION

We shall retain Personal Data only for as long as reasonably necessary to fulfil the purpose for which it was collected or processed, or for such additional period as may be required or permitted under Applicable Data Protection Laws.

The applicable retention period may depend on the nature and purpose of the information, applicable legal or contractual requirements and the need to establish, exercise or defend legal claims.

Certain records, including invoices, GST and tax records, accounting and transaction records, fraud and dispute records, audit records and other statutory or regulatory records may be retained for the period required under Applicable Law, notwithstanding closure or deletion of a User account.

Upon expiry of the applicable retention period, We shall delete, anonymise or otherwise dispose of Personal Data in accordance with Our retention procedures and Applicable Data Protection Laws. Personal Data contained in backups may be deleted in accordance with the applicable backup cycle, subject to applicable legal and security requirements.

CHANGES TO THIS PRIVACY POLICY

We may modify or update this Privacy Policy from time to time to reflect changes in Applicable Data Protection Laws, regulatory requirements, Platform functionality, business practices, security measures or operational requirements.

The updated version shall be made available through the Platform and shall specify the applicable version and effective date.

Where a change materially affects the processing of Personal Data and Applicable Data Protection Laws require additional notice or consent, We shall provide such notice or obtain such consent as required by law.

MINORS’ PRIVACY

The Platform is a B2B platform intended for adult business users and is not directed towards or intended for children.

We do not knowingly seek to collect or process Personal Data of children except where permitted or required under Applicable Data Protection Laws. Where such processing is subject to specific legal requirements, We shall comply with the applicable requirements.

GRIEVANCE REDRESSAL AND DATA PROTECTION CONTACT

Users may contact Us regarding questions, requests, concerns or grievances relating to the processing of Personal Data or this Privacy Policy.

Subject to Applicable Data Protection Laws, Users may have the right to seek information regarding the processing of their Personal Data, request correction, updating or completion of inaccurate or incomplete Personal Data, request erasure where applicable, withdraw consent where processing is based on consent, and raise grievances regarding the processing of Personal Data.

Privacy / Grievance Contact

Email: support@sutrafin.com

Address: 5th Floor, Watermark, Technopark, Kondapur, Madhapur, Hyderabad, Shaikpet, Telangana, India, 500081

We may require reasonable information to verify the identity or authority of the person submitting a request, particularly where the request concerns access, correction, deletion or other rights relating to Personal Data.

We shall address grievances and requests within the timelines prescribed under Applicable Data Protection Laws and applicable internal procedures.

Nothing in this Privacy Policy shall restrict any statutory right or remedy available to a User or Data Principal under Applicable Data Protection Laws.

GOVERNING LAW AND DISPUTE RESOLUTION

This Privacy Policy shall be governed by and construed in accordance with the laws of India, subject to Applicable Data Protection Laws.

Any dispute arising out of or in connection with this Privacy Policy shall, to the extent legally permissible, be dealt with in accordance with the dispute-resolution mechanism prescribed under the applicable Terms of Use governing the User’s use of the Platform.

Nothing in this Privacy Policy shall restrict any statutory right or remedy available to a User or Data Principal under Applicable Data Protection Laws.

NOTICES

We may provide notices relating to privacy, data processing, security incidents, changes to this Privacy Policy or other relevant matters through the Platform, registered email address, mobile number, in-app notifications or other appropriate electronic means.

Where Applicable Data Protection Laws prescribe a particular form or manner of notice, We shall provide such notice in accordance with the applicable requirements.

RELATIONSHIP WITH THE TERMS OF USE AND CONSENT

This Privacy Policy shall be read together with the Terms & Conditions and other applicable policies, notices and terms governing use of the Platform. The Terms & Conditions govern the contractual relationship between Us and the User concerning access to and use of the Platform, whereas this Privacy Policy explains how We process Personal Data in connection with such use.

Where processing is based on consent, We shall obtain such consent through an appropriate affirmative mechanism where required under Applicable Data Protection Laws. A User’s acknowledgement or acceptance of this Privacy Policy shall not, by itself, constitute consent where separate consent is required under Applicable Data Protection Laws. Consent for processing Personal Data and promotional communications may be obtained separately where required or appropriate. Withdrawal or refusal of consent for promotional communications shall not affect necessary service, security or transactional communications.

A User’s refusal to provide Personal Data that is necessary for a particular Platform service or functionality may result in Our inability to provide such service or functionality.

In the event of any inconsistency between this Privacy Policy and a mandatory requirement of Applicable Data Protection Laws, the applicable legal requirement shall prevail.