Legal
Privacy Policy
LAST UPDATED: May 4, 2026
Prospecx ("Prospecx", "we", "us") operates the Prospecx platform. This Privacy Policy explains what personal data we collect, how we use it, and your rights under applicable law including India's Digital Personal Data Protection Act 2023 (DPDP Act) and principles aligned with the EU General Data Protection Regulation.
1. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, phone number, and company name provided at registration.
- Usage data: feature interactions, session duration, clicks, and navigation paths within the Service.
- Communication data: emails, messages, or support tickets you send to us.
- Prospect data: contact information and notes about leads that you import or create inside the Service. This data belongs to you.
- Billing data: transaction records, invoice IDs, and GST details. Full payment card details are handled exclusively by our payment gateway and are never stored on our servers.
- Device and log data: IP address, browser or app version, operating system, crash reports, and error logs collected automatically.
2. How We Use Your Data
We process your personal data for the following purposes:
- Providing, operating, and improving the Service.
- Processing transactions and issuing GST-compliant invoices.
- Sending transactional communications such as OTP codes, subscription confirmations, and account security alerts.
- Sending product updates, changelog announcements, and marketing communications — only with your consent or where permitted by applicable law. You may opt out at any time.
- Detecting and preventing fraud, abuse, and security incidents.
- Complying with legal obligations including audit requirements under the Information Technology Act 2000 and the DPDP Act 2023.
3. Legal Basis for Processing
We process your data under the following legal bases: (a) performance of the contract between you and Prospecx; (b) your consent, which you may withdraw at any time; (c) our legitimate interests in operating and improving the Service, provided these do not override your rights; and (d) compliance with legal obligations.
4. Third-Party Processors
We share your data only with carefully selected sub-processors who are contractually bound to handle it securely and only for the purposes we specify. Categories of processors include:
- Transactional email provider (OTP delivery, account notifications)
- Payment gateway (billing and invoicing)
- Cloud infrastructure provider (hosting, storage, compute)
- Product analytics provider (usage metrics, session data — anonymised where possible)
- Error monitoring provider (crash reports and error logs)
We do not sell your personal data. We do not share your prospect data with advertising networks or data brokers.
5. Data Residency
All personal data and prospect data processed through Prospecx is stored on servers located in India. We do not transfer your data outside India except where you explicitly instruct us to do so or where required by law.
6. Data Retention
We retain your account data for the duration of your subscription plus 30 days following cancellation, after which it is permanently deleted. You may request earlier deletion under your rights described below. Billing records are retained for 7 years as required by Indian tax law. Anonymised aggregate analytics data may be retained indefinitely.
7. Your Rights
Under the DPDP Act 2023 and aligned best practices, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data. We will complete verified erasure requests within 30 days.
- Data portability: Export your prospect and account data in CSV format at any time from your account settings.
- Withdraw consent: Withdraw consent for optional processing (such as marketing emails) at any time.
- Grievance: Lodge a complaint with our Data Protection Officer or with the Data Protection Board of India once established.
To exercise any of these rights, email privacy@prospecx.in. We will respond within 30 days.
8. Cookies and Tracking
Our web application uses essential cookies required for authentication and session management. We use analytics cookies to understand how visitors use the Service; these can be declined via your browser settings or our cookie consent manager. We do not use advertising cookies or cross-site tracking technologies.
9. Security
We implement industry-standard security measures including encryption at rest and in transit (TLS 1.3), role-based access control, multi-factor authentication for privileged access, and periodic security audits. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by law.
10. Children's Privacy
The Service is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, contact us immediately and we will delete it promptly.
11. Contact and Grievance Redressal
For privacy questions or to exercise your rights, contact our Data Protection Officer:
- Email: privacy@prospecx.in
- Address: Prospecx, Bengaluru, Karnataka, India
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once the Board is constituted under the DPDP Act 2023.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify you by email and via a banner in the Service at least 14 days before material changes take effect.