Legal & Compliance

Privacy Policy

How Aquorio collects, uses, protects, and respects your personal data — in full compliance with Indian law.

Effective Date: 16 May 2026  ·  Version 1.0

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Collect Data
  4. Purpose of Processing
  5. Legal Basis
  6. We Do Not Sell Your Data
  7. Data Sharing & Disclosure
  8. Data Security
  9. Data Retention
  10. Your Rights
  11. Cookies & Tracking
  12. Children's Privacy
  13. Grievance Officer
  14. Changes to This Policy
Applicable Law: This Privacy Policy is governed by the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection Act, 2023 (DPDPA) of India, along with any amendments or regulations issued thereunder.
01

Who We Are

Aquorio Infolabs Private Limited ("Aquorio", "we", "us", or "our") is an enterprise technology company offering AI agents, CRM implementation, data intelligence, and conversational commerce solutions. Our registered office is at:

AWFIS ZEN, 8, Square EON, Plot No. 9, Sector 142, Noida, Uttar Pradesh – 201305, India.

For the purposes of the DPDPA 2023 and SPDI Rules, Aquorio acts as the Data Fiduciary in respect of personal data collected through our website, products, and services.

02

Data We Collect

We collect only the data that is necessary to provide our services. The categories of data we may collect include:

CategoryExamplesSensitivity
Identity DataName, job title, company nameStandard
Contact DataEmail address, phone number, WhatsApp numberStandard
Business DataCompany size, industry, use-case requirementsStandard
Usage DataPages visited, time on site, clickstream, browser type, device, IP addressStandard
Communication DataMessages, enquiries, support tickets submitted via contact forms or WhatsAppStandard
Technical DataLog files, session tokens, API usage data (for platform clients)Standard
Customer Enterprise DataData processed on behalf of enterprise clients within our platform (governed separately by Data Processing Agreements)Varies
Sensitive Personal Data (SPDI): Under SPDI Rules 2011, we do not intentionally collect sensitive personal data such as passwords (beyond hashed credentials), financial information, health data, biometric data, or sexual orientation through our public website. If such data is shared during enterprise engagement, it is handled under a separate Data Processing Agreement.
03

How We Collect Data

We collect personal data through the following means:

04

Purpose of Processing

We process your personal data only for the following defined purposes:

We do not process your personal data for any purpose beyond those listed above without your explicit consent.

06

We Do Not Sell Your Data

Absolute Commitment: Aquorio does not sell, rent, trade, or otherwise transfer your personal data to third parties for commercial gain. Your data is not a product. We do not operate data broking, advertising networks, or any form of data monetisation involving personal information.

Any sharing of data with third parties is strictly limited to service delivery purposes (see Section 7 below) and is always governed by contractual data protection obligations.

07

Data Sharing & Disclosure

We may share your personal data with the following categories of parties, only to the extent necessary:

All third-party recipients are required to maintain equivalent or higher standards of data protection. We enter into Data Processing Agreements (DPAs) with all processors who handle personal data on our behalf.

08

Data Security

We implement robust, multi-layered security measures in accordance with the SPDI Rules 2011 and industry best practices, including:

No security measure is absolute. While we take every reasonable precaution, no digital transmission or storage system is 100% secure. We urge you to maintain strong, unique passwords and to contact us immediately if you suspect any unauthorised access to your data.
09

Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law:

Upon expiry of the retention period, personal data is securely deleted or anonymised in a manner that it can no longer identify an individual.

10

Your Rights

Under the DPDPA 2023 and SPDI Rules, you have the following rights as a Data Principal:

Right to Access

Request a summary of the personal data we hold about you and how it is being processed.

Right to Correction

Request correction or completion of inaccurate or incomplete personal data we hold.

Right to Erasure

Request deletion of your personal data, subject to legal retention obligations.

Right to Grievance

Raise a grievance with our designated Grievance Officer and receive a response within 48 hours.

Withdraw Consent

Withdraw previously given consent at any time without affecting prior lawful processing.

Nominate a Representative

Under DPDPA 2023, nominate another person to exercise your rights in the event of your death or incapacity.

To exercise any of the above rights, please contact our Grievance Officer (see Section 13). We will respond to verified requests within 30 days, unless a shorter or longer period is specified by applicable law.

11

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to operate correctly and to understand how visitors use our site. The categories of cookies we use are:

We do not use advertising or behavioural profiling cookies. You may control or disable non-essential cookies through your browser settings. Disabling certain cookies may affect site functionality.

12

Children's Privacy

Our services are designed for enterprise and business clients and are not directed at individuals below the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it promptly.

13

Grievance Officer

In compliance with the IT Act 2000 and DPDPA 2023, we have designated a Grievance Officer to address your privacy concerns. You may raise a grievance within 30 days of the incident or concern, and we will acknowledge it within 48 hours and resolve it within 30 days.

Grievance Officer — Aquorio

Reach us for any data privacy concern, access request, or grievance.

Name:  Grievance Officer, Aquorio Infolabs Pvt. Ltd.
Address:  AWFIS ZEN, 8, Square EON, Plot No. 9, Sector 142, Noida, UP – 201305
Hours:  Monday to Friday, 9:30 AM – 6:30 PM IST

If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India once constituted under the DPDPA 2023, or the adjudicating officer under the IT Act 2000.

14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, or our data practices. Any material changes will be communicated via a prominent notice on our website or directly to you via email where you have provided contact details.

The date at the top of this page reflects the most recent version. We encourage you to review this policy periodically. Continued use of our website or services after changes are posted constitutes acceptance of the revised policy.

Previous versions of this policy are available upon request from our Grievance Officer.

Chat with us