Data We Collect
We collect account details (name, email, phone, role), organization profile information (company name, address, GSTIN, PAN, business registration), supplier and buyer records, product catalogs, inquiries, quote metadata, messages, uploaded documents, audit events, device/session data, IP addresses, browser fingerprint signals for fraud prevention, and limited usage telemetry needed to operate and secure the platform.
How Data Is Used
Data is used to authenticate users, maintain company workspaces, support supplier discovery, route product inquiries and quote proposals, generate audit logs, enforce permissions, detect and prevent abuse, comply with legal obligations, improve reliability, and communicate platform updates. We do not use personal data for automated decision-making or profiling that produces legal effects.
Public vs Private Data
Public marketplace profile data is separated from private procurement data. BOMs, quotes, approvals, internal documents, chat records, supplier notes, budgets, and audit trails are scoped to the authorized organization workspace and are never publicly indexed or searchable.
GDPR Compliance (EU/EEA Users)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR). We process your data based on: (a) consent for optional cookies and marketing, (b) contract necessity for platform services, (c) legal obligation for regulatory compliance, (d) legitimate interests for security and fraud prevention. You may request data portability, restriction of processing, and object to processing based on legitimate interests. Our Data Protection Officer can be reached at dpo@indnetglobal.com.
CCPA Compliance (California Users)
California residents have the right to know what personal information we collect, request deletion, opt out of the sale of personal information (we do not sell data), and non-discrimination for exercising these rights. To exercise your CCPA rights, contact privacy@indnetglobal.com with your account email and specify "CCPA Request" in the subject line. We will verify your identity before processing.
DPDP Act Compliance (India)
As an India-based platform, we comply with the Digital Personal Data Protection Act, 2023. Data fiduciaries and principals may exercise their rights regarding personal data processing. Grievances may be addressed to our Grievance Officer at grievance@indnetglobal.com. We respond to all verified requests within the timelines prescribed under applicable law.
International Data Transfers
Your data may be transferred to and processed in countries other than your own. When we transfer personal data from the EEA, UK, or Switzerland, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms. Infrastructure providers may store data in multiple regions. We ensure equivalent protection through contractual agreements.
Third-Party Processors
We engage trusted third-party service providers who process data on our behalf. These include: cloud infrastructure (hosting), email delivery services, payment processing (Razorpay), analytics providers, map tile services (OpenStreetMap), and error monitoring tools. Each processor is contractually bound to process data only for agreed purposes, maintain security, and comply with applicable data protection laws.
Data Retention
Records are retained while accounts or workspaces remain active, or longer where contracts, tax, audit, dispute, security, or legal requirements apply. Account data is retained for 90 days after account closure for recovery purposes, then anonymized or deleted within 180 days. Transaction and audit records may be retained for 7 years to comply with Indian tax and statutory requirements.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of confirmation, as required under applicable law. Notifications will include the nature of the breach, categories of data affected, mitigation steps, and recommended actions.
Your Rights
Depending on applicable law (GDPR, CCPA, DPDP Act, or others), you may request: access to your data, correction of inaccuracies, deletion (right to be forgotten), restriction of processing, data portability, objection to processing, and withdrawal of consent. Organization administrators may manage many records directly from the workspace. Submit requests to privacy@indnetglobal.com.
Children Privacy
IndNetGlobal is a B2B platform and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has provided personal data without parental consent, we will delete it promptly. If you believe a minor has submitted data, contact us immediately.
Cookies and Tracking
We use essential cookies for authentication and security, preference cookies for platform customization, and analytics cookies to understand usage. You can manage preferences through your browser settings. See our full Cookie Policy for detailed information on cookie types, purpose, duration, and how to control them.
Contact and Grievance
For privacy requests, security concerns, data processing questions, or complaints: (a) Email privacy@indnetglobal.com, (b) Grievance Officer: grievance@indnetglobal.com, (c) DPO: dpo@indnetglobal.com. We may verify requester identity and authority before acting. We respond to all verified requests within 30 days (or shorter where required).