Loyaltics Tech Pvt. Ltd. ("Loyaltics", "Company", "we", "us", or "our") is a Software-as-a-Service (SaaS) technology company incorporated in India. We develop and operate a suite of enterprise and consumer-facing digital platforms, including:
This Privacy Policy describes how Loyaltics collects, uses, stores, shares, and protects personal data and business data across all of its platforms, websites, and related services (collectively, "Services"). It also explains your rights and how to exercise them.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
This Privacy Policy applies to:
This Policy does not apply to third-party services, websites, or applications that may be linked from our platforms. We encourage you to review the privacy policies of any third-party services you access.
Loyaltics acts in the following capacities depending on the context:
When processing personal data submitted by Clients in connection with the delivery of Services (for example, employee data loaded into FSA, distributor records in DMS, or consumer loyalty profiles in BzLoyalty), Loyaltics acts as a Data Processor on behalf of the Client, who is the Data Controller. Processing in this capacity is governed by the contractual agreement between Loyaltics and the Client, including any applicable Data Processing Agreement (DPA).
When Loyaltics independently determines the purposes and means of processing — such as for our own website analytics, marketing communications, platform improvement, and account management — we act as the Data Controller for that data.
The categories of data collected vary by platform and user type:
We process data for the following purposes:
Loyaltics processes personal data on the following legal bases, in accordance with applicable data protection law:
Loyaltics does not sell, rent, or trade personal data to third parties for their own commercial purposes.
We may share data in the following circumstances:
We engage carefully selected third-party providers to support our infrastructure and operations, including:
All sub-processors are bound by Data Processing Agreements and are required to maintain appropriate technical and organisational security measures. A list of active sub-processors is available upon written request.
Data associated with a Client's account is accessible to that Client's authorised administrators as part of the Services. Clients are responsible for managing their administrators' access appropriately.
We may disclose data where required by law, court order, or regulatory authority — including disclosures to CERT-In, MeitY, or law enforcement agencies as required under Indian law.
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction, subject to equivalent privacy protections.
Loyaltics implements a comprehensive set of technical and organisational security measures to protect personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:
Please refer to our Security Policy (Section III of this document) for full details of our security controls and infrastructure.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to perform our contractual obligations, and to comply with applicable legal requirements.
Upon expiry of the applicable retention period, data is securely deleted or anonymised in a manner consistent with industry best practices.
Subject to applicable law, individuals whose personal data we process may have the following rights:
To exercise any of the above rights, please contact us using the details in Section 15. We will respond to verified requests within 30 days. In complex cases, this period may be extended by a further 30 days with notice.
Loyaltics' Services are hosted primarily on Amazon Web Services (AWS) infrastructure. Data may be processed in or transferred to countries outside India in the course of service delivery, including for cloud infrastructure, backup, or support purposes.
Where data is transferred internationally, Loyaltics ensures that appropriate safeguards are in place, which may include:
All international transfers comply with the requirements of the DPDP Act 2023, GDPR (where applicable), and other applicable data protection laws.
Our websites and platforms use cookies and similar tracking technologies to enhance user experience, measure performance, and support analytics. The categories of cookies we use include:
On first visit to our website, you will be presented with a cookie consent banner where you can manage your cookie preferences. You may also manage cookie settings through your browser at any time. Please note that disabling certain cookies may affect the functionality of our Services.
Loyaltics' Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe that a child under 18 has provided personal data to us without appropriate parental consent, please contact us immediately at info@bzloyalty.com and we will take steps to delete such data promptly.
Loyaltics is committed to compliance with all applicable data protection and privacy laws, including but not limited to:
Where Loyaltics' Clients are subject to additional regulatory requirements (such as PDPA in Thailand, PDPPL in Japan, or PIPEDA in Canada), Loyaltics will work with those Clients to ensure that appropriate contractual and technical measures are in place.
In accordance with the Information Technology Act 2000 and DPDP Act 2023, Loyaltics has designated a Grievance Officer to address complaints and inquiries regarding personal data processing.Name: Hanit Vairagi Designation: Grievance Officer / Data Protection OfficerEmail: info@bzloyalty.com Postal Address: Loyaltics Tech Pvt. Ltd., Topaz 36, Silver Springs Phase-II, Indore (MP), IndiaWe aim to acknowledge all grievances within 48 hours and resolve them within 30 days of receipt.
Loyaltics reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will:
Your continued use of our Services after the effective date of any update constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
This Security Policy describes the technical and organisational security measures implemented by Loyaltics Tech Pvt. Ltd. to protect the confidentiality, integrity, and availability of all data processed across its SaaS platforms — including BzLoyalty (Loyalty, FSA), DMS, ERP, and future products.
This Policy applies to all Loyaltics employees, contractors, vendors, and systems involved in the delivery of Services to Clients. It is supplementary to the Privacy Policy and Terms & Conditions, and all three documents form part of Loyaltics' overall Legal & Security Framework.
Information security is governed by Loyaltics' Information Security Officer (ISO), who is accountable for security policy, risk management, compliance oversight, and incident response. The ISO is supported by the engineering, operations, and IT teams.
Security policies are reviewed at least annually and following significant changes to the platform, regulatory environment, or threat landscape. All changes are subject to management approval and documented in the version history.
Loyaltics maintains a formal risk management process covering identification, assessment, treatment, and monitoring of information security risks. Risk assessments are conducted for new services, significant changes, and third-party engagements.
All Loyaltics production services are hosted on Amazon Web Services (AWS), a globally recognised cloud infrastructure provider that maintains certifications including ISO 27001, SOC 2 Type II, PCI DSS, and compliance with applicable regional regulatory frameworks. Loyaltics operates under the AWS Shared Responsibility Model, under which AWS is responsible for the security of the underlying cloud infrastructure and Loyaltics is responsible for the security of its applications and data within that infrastructure.
The production environment is protected by:
Physical security of data centres is managed by AWS in accordance with their certified physical security controls, including 24/7 security personnel, multi-factor physical access controls, CCTV surveillance, and resilient facility design. Loyaltics does not operate its own physical data centres.
Loyaltics utilises multiple AWS availability zones and, where applicable, multiple AWS regions to ensure high availability and resilience. Security controls are consistently applied across all environments and regions.
All data transmitted between End Users and Loyaltics' platforms is encrypted using Transport Layer Security (TLS) version 1.2 or higher. All public-facing web interfaces, APIs, and administrative portals enforce HTTPS. Unencrypted communication is not permitted for any Service endpoint.
Databases and object storage containing Client and End User data are encrypted at rest using AES-256 encryption managed through AWS Key Management Service (KMS). Backups are encrypted using the same standard.
At the application level, additional data protection controls are implemented:
All encryption implementations comply with applicable regulatory requirements, including CERT-In guidelines and DPDP Act 2023 obligations, and use widely accepted, industry-standard cryptographic algorithms.
Access to all Loyaltics systems, platforms, and data is governed by Role-Based Access Control (RBAC), ensuring that users and system accounts are granted only the minimum permissions necessary to perform their function (principle of least privilege). Roles and permissions are explicitly defined and documented for each platform.
Multi-Factor Authentication is enforced for:
End User MFA is enforced via OTP-based authentication delivered to registered mobile numbers or email addresses, as applicable to the platform and access channel.
Access to production systems by Loyaltics engineering and operations personnel is restricted to authorised individuals and is subject to IP allowlisting, MFA, and full activity logging. All privileged access sessions are recorded in audit logs. Production access is granted on a need-to-access basis and reviewed periodically.
A formal user provisioning and de-provisioning process is in place. Access rights are revoked promptly upon role change, project completion, or termination of employment or contract. Client administrators can independently manage their own users' access through the platform's administration interface.
Loyaltics follows a formal Software Development Lifecycle (SDLC) incorporating security at every stage:
All Loyaltics APIs are secured with:
Loyaltics maintains an ongoing vulnerability management programme including:
Loyaltics' platforms implement strict logical data isolation at the application layer. Each Client's data is segregated using tenant-specific identifiers, access controls, and query scoping. No cross-tenant data access is architecturally possible. Data exports, reports, and backups are generated and managed on a per-client basis. Tenant isolation controls are tested as part of the application security review process.
All platform and infrastructure activity is monitored using Amazon CloudWatch, which provides centralised logging, performance metrics collection, and automated alerting. Monitoring covers:
Comprehensive audit logs are maintained for all significant user and administrative actions, including:
Audit logs are stored in protected, tamper-evident storage with restricted access. Log retention meets a minimum of 90 days online, with up to 12 months available through configuration, aligned with Client requirements and applicable regulatory standards.
Security alerts are configured for predefined conditions including unusual login patterns, elevated error rates, and indicators of potential security incidents. Alerts are routed to the on-call engineering and security team for immediate investigation and response.
Production data, application components, and system configurations are backed up daily using AWS-managed backup services. Backups are encrypted at rest using AES-256. Standard backup retention is 90 days, configurable to meet Client-specific requirements. Backup integrity is verified periodically through restoration testing.
Loyaltics maintains a Business Continuity and Disaster Recovery (BCDR) plan that covers:
Loyaltics maintains a formal Incident Response Plan covering the full lifecycle of security incidents:
In the event of a confirmed security incident that affects Client Data:
Security Incident Reporting
To report a suspected security incident or vulnerability, please contact:Email: info@info@bzloyalty.com Subject: Security Incident ReportAcknowledgement: Within 4 business hours of receiptResolution target: In accordance with incident severity classification
Loyaltics manages third-party security risk through a formal vendor management programme:
All Loyaltics employees and contractors undergo background verification checks in accordance with applicable local laws prior to engagement.
All personnel are required to sign employment or contractor agreements that include confidentiality obligations and information security responsibilities. Non-Disclosure Agreements are executed with all employees, contractors, and third parties prior to access to Confidential Information or Client Data.
All employees receive security awareness training upon joining and on an ongoing basis. Training covers data protection obligations, phishing and social engineering awareness, acceptable use policies, and incident reporting procedures.
Access to all systems, applications, and data is revoked promptly upon termination of employment or contract, as part of a standardised off-boarding procedure.
Loyaltics maintains a formal disciplinary procedure to address violations of security policy, with actions proportionate to the severity and intent of the breach.
All changes to production systems, applications, and infrastructure follow Loyaltics' documented Change Management Process, which includes:
Loyaltics' security programme is designed to meet the requirements of applicable regulations and widely recognised security frameworks, including:
Loyaltics will cooperate with Client audit requirements and provide documentation of relevant security controls upon request, subject to confidentiality protections.
Security Enquiries — Loyaltics Tech Pvt. Ltd.
For security-related questions, audit inquiries, or to report a vulnerability or incident:Email: info@bzloyalty.com Postal Address: Loyaltics Tech Pvt. Ltd., Topaz 36, Silver Springs Phase-II, Indore (MP), IndiaWe are committed to responding to all legitimate security inquiries promptly and transparently.