Overview

This Privacy Policy ("Policy") applies to CRSN.IN along with its affiliates, subsidiaries, group companies, related entities, successors and assigns, herein called as CRSN. We may change or update this Policy at any time, and the same will be updated here. If you are a CRSN user or customer, we shall notify the changes or updates either by sending an email or a notification on the CRSN Website, application(s), platform(s), products or services, as applicable. Please ensure to read such notices carefully.

We sincerely believe that you should always know what data we collect from you, the purposes for which such data is used, and that you should have the ability to make informed decisions about what you want to share with us. Therefore, we want to be transparent about: (i) how and why we collect, store and use your personal data in the various capacities in which you interact with us; and (ii) the rights that you have to determine the contours of this interaction.

This Policy details the critical aspects governing your personal data relationship with CRSN, having its registered office at 169, PAGV, Vaderahalli, Bengaluru - 560049, Karnataka, India. This Policy is a part of and should be read in conjunction with our Terms and Conditions. If you have any queries or concerns, please contact our Grievance Officer as set out below. If you do not agree with this Policy, we would advise you not to visit or use the Website or CRSN application(s)/platform(s)/services.

For any clarifications or support, please reach out to us at connect.admin@crsn.in.

Types of Users

Your personal data relationship with CRSN varies based on the capacity in which you interact with us or avail of our products and solutions ("Services"). You could be:

Based on whether you are a Visitor, Customer, or User, the type of data we collect and the purpose for which we use it will differ, as detailed below.

Personal Information We Collect

Visitor

What Data We May Collect

  • Standard web server logs: your IP address, browser and device type, the pages you request, and the date and time of each request
  • Your name and e-mail, only if you choose to contact us (for example by e-mail or WhatsApp)

How and Why We Use It

The Website does not set cookies and does not use analytics, web beacons, or other tracking technologies. Server logs are processed on the basis of our legitimate interest in operating and securing the Website, and are retained only for a limited period. If you contact us, we use your details to respond to your enquiry. We will only send you newsletters and e-mails marketing other products and services if you give us your consent, which you may withdraw at any time.

Customer

What Data We May Collect

  • The name and e-mail of your representative who signs up for a Service on your behalf
  • Credit Card/Debit Card/UPI/Net Banking/Other Payment Mode information to check your financial qualifications, detect fraud, and facilitate payments for our Services

How and Why We Use It

We collect this data in order to help you register for and facilitate provision of our Services, and to enable you to make payments for our Services. We use a third-party service provider to manage payment processing. This service provider is not permitted to store, retain, or use information you provide except for the sole purpose of payment processing on our behalf. If you give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.

User

What Data We May Collect

  • Your name and e-mail
  • How you behave in the relevant product, service or platform environment and use the features
  • What device you use to access the Website, application, platform or Services and its details, including model, operating system, and browser
  • Cookies and Web Beacon data

How and Why We Use It

We collect this data in order to facilitate provision of our Services. We will occasionally send you e-mails regarding changes or updates to the Service you are using. In the event you report an issue, we may also screen/video record your device only when you use the Website, application, platform or Service for a limited time period to help us better understand how to address the issue, where applicable and subject to your consent where required. If you give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.

For the avoidance of any doubt, in the event we anonymize and aggregate information collected from you, we will be entitled to use such anonymized data freely, without any restrictions other than those set out under applicable law. Where such data is not being used by us to render Services to you, we shall explicitly seek your consent for using the same. You can choose to withdraw this consent at any time by contacting us at connect.admin@crsn.in.

Artificial Intelligence & Data Processing

CRSN uses artificial intelligence (AI) to enhance the services we provide, ensuring that customer data is processed accurately, efficiently, and securely. All AI-driven data processing is performed with a strong commitment to safeguarding customer privacy. We implement strict access controls, encryption, and regular audits to prevent unauthorized access to, or misuse of, your information.

Our AI models are trained only on data necessary to deliver our services, and we adhere to industry best practices to anonymize and aggregate data wherever possible to protect customer identities. We do not use customer data to train external models or for any purpose beyond the agreed-upon scope of our services.

Any personal data processed by our AI systems is handled in compliance with applicable data protection laws, including GDPR and CCPA where relevant.

Legal Grounds for Processing

The data provided by you will be processed for the purpose of rendering Services to you or in order to take steps prior to rendering such Services, at your request. Additionally, we may process your data to serve legitimate interests. The grounds on which we engage in processing are as follows:

Visitor Data
Legitimate Interest (website operation and security); Consent (marketing communications)
Account Registration Data
Compliance with applicable laws; Legitimate Interest
Service Usage Data
Performance of a Contract; Legitimate Interest
Data for Marketing our Services
Consent; Legitimate Interest

If you believe we have used your personal data in violation of the rights above or have not responded to your objections, you may lodge a complaint with your local supervisory authority.

We do not collect any Special Categories of Personal Data. If you are a Customer/User, you agree and acknowledge that you shall not, under any circumstances, use our Services to collect or process Special Categories of Personal Data (including data pertaining to race, ethnic origin, genetics, political affiliations, biometrics, health, or sexual orientation) or transfer any such data to us.

Your Rights Under GDPR

If you are a European resident, subject to the GDPR and applicable law's limitations, you have the following rights regarding your personal data:

Right to Be Informed

You have a right to be informed about the manner in which any of your personal data is collected or used, which we have endeavoured to do by way of this Policy.

Right of Access

You have a right to access the personal data you have provided by requesting us to provide you with the same.

Right to Rectification

You have a right to request us to amend or update your personal data if it is inaccurate or incomplete.

Right to Erasure

You have a right to request us to delete your personal data.

Right to Restrict Processing

You have a right to request us to temporarily or permanently stop processing all or some of your personal data.

Right to Object

You have a right, at any time, to object to our processing of your personal data under certain circumstances. You have an absolute right to object to us processing your personal data for the purposes of direct marketing.

Right to Data Portability

You have a right to request us to provide you with a copy of your personal data in electronic format and to transmit that personal data for use with another third party's product or service.

Right Not to Be Subject to Automated Decision-Making

You have a right not to be subject to a decision based solely on automated decision making, including profiling.

To exercise any of these rights, please contact our Grievance Officer whose details are set out below. Please also note that if you are a European resident, your personal data will be transferred to and stored in India, where CRSN Private Ltd. is established and where CRSN Private Ltd. is established. Where CRSN manages the hosting environment, our infrastructure sub-processor is named in Annex 2 to our Data Protection Addendum; where you host VIV.EKA in your own cloud, your data stays in your infrastructure. Your personal data may also be transferred to other countries outside the European Economic Area in which our service providers operate. India has not been the subject of an adequacy decision by the European Commission. Where we transfer personal data to India, or to any other country not deemed 'adequate' by the European Commission, we rely on the Standard Contractual Clauses approved by the European Commission Decision of 4 June 2021, supported by a transfer impact assessment and by supplementary technical and organisational measures including encryption in transit and at rest and strict, logged access controls. For transfers originating in the United Kingdom we additionally rely on the International Data Transfer Addendum issued by the Information Commissioner's Office. You may request a copy of the transfer safeguards applicable to your personal data by writing to connect.admin@crsn.in.

Your Rights Under CCPA

CRSN complies with the California Consumer Privacy Act (CCPA) by giving you the following five privacy rights for California consumers:

Right to Know

You have a right to be informed about the personal information CRSN collects about you and how it is used and shared, as detailed in this Policy.

Right to Delete

You have the right to request us to delete your personal data.

Right to Opt-Out of Sale

CRSN does not sell any data of any of its users, customers, or leads.

Right to Non-Discrimination

CRSN assures no discrimination against consumers exercising their privacy rights under CCPA, and will not ask for waiver of privacy rights from California consumers.

Right to Correct

You have a right to request correction of inaccurate personal information that we hold about you.

To exercise any of these rights, please contact our Grievance Officer whose details are set out below.

Your Rights Under IT (SPDI) Rules, 2011

CRSN adheres to the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) to ensure your data is secure.

Right to Be Informed & Give Consent
Before CRSN collects any of your personal data, we will clearly explain what information we need, why we need it, and how we will use it. We will only collect your personal data with your explicit consent.
Right to Access Your Data
You have the right to request access to the personal information CRSN holds about you, including the ability to review and verify its accuracy and completeness.
Right to Correct Mistakes
If you find any errors or missing information in your data held by CRSN, you have the right to request corrections. We will take reasonable steps to update your information promptly upon verification of your request.
Right to Withdraw Consent
You can withdraw your consent for CRSN to process your sensitive personal data at any time. Once you withdraw consent, we will stop using your data for the purpose originally agreed upon, unless there is a legal reason for continued processing, such as a court order. To withdraw consent, please contact connect.admin@crsn.in.

Please contact our Grievance Officer if you would like to exercise the rights listed above.

Links to Other Websites

Our website may contain links to third-party websites that are not owned or controlled by us. We are not responsible for the privacy practices of those websites. We encourage you to review the privacy statement of every website you visit that may collect personal information.

Retention of Personal Information

We will store any personal data we collect from you as long as it is necessary in order to facilitate your use of the Services and for ancillary legitimate and essential business purposes — these include, without limitation, improving our Services, attending to technical issues, and dealing with disputes.

We may need to retain your personal data even if you seek deletion thereof, if it is needed to comply with our legal obligations, resolve disputes, and enforce our agreements.

If you are a customer, please be advised that: (i) you will need to inform your Leads about how you store and deal with any data you collect from them using one of our Services, in compliance with applicable laws including the GDPR; and (ii) after you terminate your usage of a Service, we may, unless legally prohibited, delete all data provided or collected by you from our servers.

Tools Used by Our Customers

If you are a Customer, you are empowered to use proprietary or other third-party technologies and integrate with our Website, application, platform or Services. If you do, you agree and acknowledge that it is your sole obligation to inform your stakeholders about any data you collect by using such technologies and the policies by which such collection is bound.

Transfer of Information

In order for us to facilitate our operations, we may transfer and store the data we collect and process in accordance with this Policy to our database server in a third country for Disaster Recovery purposes. Your rights and protections will, under no circumstances, be diluted by this transfer.

In the ordinary course of business, we may employ other companies and people to assist us in providing certain components of our Services. To do so, we may need to share your data with them. Some examples of where we may sub-contract processing activities to third parties include data analysis, marketing assistance, processing credit card payments, and providing customer service.

Information Security

We implement industry-standard technical and organizational measures using a variety of security technologies and procedures to help protect your data from unauthorized access, use, loss, destruction, or disclosure. When we collect particularly sensitive data, it is encrypted using industry-standard cryptographic techniques including but not limited to SSL, TLS, RSA, and AES. Our Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022, an internationally recognized framework for information security; our controls are independently audited under SOC 2; and we process personal data in accordance with the GDPR.

In compliance with the SPDI Rules, 2011, we adhere to the following reasonable security practices and procedures:

Access Control
Access to personal data is granted only to authorized personnel on a need-to-know basis, and such access is logged and monitored.
Data Encryption
Sensitive personal data is encrypted both in transit and at rest using strong encryption methods such as AES-256.
Network Security
We employ secure network architecture, including firewalls and intrusion detection systems, to prevent unauthorized access.
Regular Audits
We conduct regular security audits and assessments to identify potential vulnerabilities and ensure compliance with our security policies.
Incident Management
We have established protocols for managing and responding to security incidents, including data breaches, to mitigate any potential impact on your personal data.
Employee Training
We conduct regular training programs for our employees to ensure they are aware of and comply with our security policies and procedures.
Third-Party Compliance
We ensure that any third-party service providers who handle personal data on our behalf adhere to equivalent security standards and practices.
Physical & Environmental Security
We have implemented robust physical security controls to protect our data centers and other facilities from unauthorized access, damage, and interference.
Business Continuity Management
We have developed and tested business continuity plans to ensure the availability of critical information and systems in the event of a disruption.
Risk Assessment & Treatment
We conduct regular risk assessments to identify potential security threats and vulnerabilities, and implement appropriate risk treatment plans to mitigate identified risks.
Audit & Compliance
We conduct regular internal and external audits to ensure ongoing compliance with ISO 27001 and SOC 2 requirements and continuously improve our ISMS.

However, no data transmission over the internet or a wireless network can be fully guaranteed. We store information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure.

Legal Disclosure & Compelled Disclosure

We will disclose any information we collect, use, or receive if required or permitted by law. This includes disclosure in the following circumstances:

Grievance Officer & Contact Information

If you would like to understand more about this Policy, or wish to contact us regarding your personal information and individual rights, or wish to exercise any rights listed in this Policy, please reach out to our Grievance Officer.

Registered Address CRSN Private Limited
169, PAGV, Vaderahalli,
Bengaluru - 560049,
Karnataka, India
Send your privacy-related queries to connect.admin@crsn.in
Website: https://www.crsn.in/  ·  Terms: https://www.crsn.in/terms-and-conditions