Legal

Privacy Policy

Effective Date: 1 March 2025  |  Last Updated: 5 March 2025

This Privacy Policy explains how your personal and business data is collected, used, stored, and protected across Heyo's services. The entity responsible for your data depends on the service you use:

  • Heyo ERP — Data Fiduciary: Techcora Corporation, Chennai, Tamil Nadu – 603202
  • Heyo Marketing — Data Fiduciary: Heyo Technologies, Gudalur, The Nilgiris – 643212

This policy is published in compliance with the Information Technology Act, 2000, the IT (SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Part A

Heyo ERP — Techcora Corporation

Chennai, Tamil Nadu – 603202  |  Data Fiduciary under DPDP Act 2023

A1. Data We Collect

a) Information You Provide

  • Business name, address, GSTIN, and PAN
  • Contact person name, email address, and phone number
  • Employee details (names, roles, login credentials) for ERP user accounts
  • Financial data including invoices, purchase orders, sales records, and payment information entered into the ERP
  • Product/inventory data, vendor information, and customer records
  • Support communications when you contact our team

b) Automatically Collected

  • Device information (browser type, operating system)
  • IP address and approximate geographic location
  • Application usage patterns and session logs

c) From Third Parties

  • Payment transaction data from payment gateways (Razorpay/UPI)
  • GST filing status from government portals (only when you authorise integration)

A2. How We Use Your Data

  • To provide, operate, and maintain Heyo ERP
  • To set up and manage your account and user access
  • To process transactions and generate GST-compliant invoices
  • To provide technical support and respond to queries
  • To send service communications (downtime alerts, update notifications)
  • To improve the product based on usage analytics
  • To comply with legal obligations under the GST Act and Income Tax Act
  • To detect and prevent fraud or unauthorised access

We do not sell, rent, or trade your data to third parties for marketing purposes.

A3. Data Storage & Security

Your data is stored on secure servers in India, hosted on cloud infrastructure compliant with ISO 27001 and SOC 2. We implement:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control — only authorised personnel access your data
  • Regular security audits and vulnerability assessments
  • Automated daily backups with encrypted off-site storage
  • Multi-factor authentication for administrative access

A4. Data Sharing

We share your data only in the following circumstances:

  • Infrastructure providers: Cloud hosting (AWS/GCP) and payment gateways — bound by confidentiality and data processing agreements
  • Legal requirements: When required by Indian law, court order, or government authority
  • Business transfers: In the event of a merger or acquisition — you will be notified in advance
  • With your consent: For any other purpose, explicit consent will be obtained first

A5. Data Retention

Data TypeRetention Period
Account and business dataActive subscription + 90 days after termination
Financial records (invoices, GST data)8 years (Income Tax Act & GST Act requirement)
Support communication logs3 years from last interaction
Usage analytics (anonymised)Indefinitely (no personal identifiers)

Upon account termination, a complete data export (CSV/Excel) will be provided within 30 days of your request. Data is permanently deleted after the retention period.

A6. Your Rights Under DPDP Act 2023

  • Right to Access: Request a summary of your personal data we hold and how it is processed
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion, subject to legal retention requirements
  • Right to Withdraw Consent: Withdraw consent at any time — may limit certain features
  • Right to Grievance Redressal: File a complaint with our Grievance Officer or escalate to the Data Protection Board of India
  • Right to Nominate: Nominate another individual to exercise your rights in case of death or incapacity

A7. Grievance Officer — Heyo ERP

In accordance with the IT Act, 2000 and DPDP Act, 2023:

Grievance Officer

Techcora Corporation

Chennai, Tamil Nadu – 603202

Email: info@heyotechnologies.com

Phone: +91 6369573404

Response Time: Within 48 hours  |  Resolution: Within 30 days (DPDP Act)

Part B

Heyo Marketing — Heyo Technologies

Gudalur, The Nilgiris, Tamil Nadu – 643212  |  Data Fiduciary under DPDP Act 2023

B1. Data We Collect

a) Information You Provide

  • Business name, contact person, email address, and phone number
  • Brand assets, product/service details, and target audience information provided for campaign creation
  • Ad account credentials and access (Google Ads, Meta Business Manager)
  • Payment information for billing

b) Campaign & Performance Data

  • Ad impressions, clicks, conversions, and cost data from connected ad platforms
  • Website visitor analytics (via Google Analytics / Meta Pixel) — anonymised
  • Lead form submissions and WhatsApp campaign responses linked to your business

B2. How We Use Your Data

  • To set up, run, and optimise your marketing campaigns
  • To generate performance reports and share insights with you
  • To manage billing and issue invoices
  • To communicate about campaign status, creative approvals, and strategy
  • To improve our service quality using aggregated, anonymised performance data

We do not share your campaign data or customer data with other clients or third parties for their marketing purposes.

B3. Data Sharing

  • Ad platforms: Google, Meta — data is processed per their respective platform policies; you retain ownership of your ad accounts
  • Tools: Analytics and reporting tools bound by confidentiality agreements
  • Legal requirements: When required by Indian law or government authority

B4. Data Retention

  • Campaign performance data and reports: retained for 1 year after engagement ends
  • Billing and invoice records: 8 years (statutory requirement)
  • Brand assets and creative files: returned or deleted within 30 days of engagement end upon your request

B5. Your Rights Under DPDP Act 2023

The same rights as listed in Section A6 apply. Contact the Grievance Officer below to exercise them.

B6. Grievance Officer — Heyo Marketing

Grievance Officer

Heyo Technologies

Gudalur, The Nilgiris, Tamil Nadu – 643212

Email: info@heyotechnologies.com

Phone: +91 6369573404

Response Time: Within 48 hours  |  Resolution: Within 30 days (DPDP Act)

Common Provisions

Applies to Both Services

C1. Cookies

Our website uses essential cookies for session management and security, and analytics cookies to understand traffic. You can control cookie preferences through your browser settings.

C2. Changes to This Policy

The applicable entity may update this policy from time to time. Material changes will be communicated via email at least 15 days before they take effect. Continued use of the service after the updated policy takes effect constitutes acceptance.