1. Introduction

Loyaltics Tech Pvt. Ltd. ("Loyaltics", "Company", "we", "us", or "our") is a Software-as-a-Service (SaaS) technology company incorporated in India. We develop and operate a suite of enterprise and consumer-facing digital platforms, including:

  • BzLoyalty — B2B and B2C Loyalty Management Platform (including FSA – Field Sales Automation)
  • DMS — Distributor Management System
  • ERP — Enterprise Resource Planning Platform
  • Any future products and services offered under the Loyaltics brand

This Privacy Policy describes how Loyaltics collects, uses, stores, shares, and protects personal data and business data across all of its platforms, websites, and related services (collectively, "Services"). It also explains your rights and how to exercise them.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

2. Scope of This Policy

This Privacy Policy applies to:

  • Business clients and their authorised administrators who subscribe to our Services ("Clients");
  • End users of our platforms, including employees, field sales agents, distributors, retailers, and consumers ("End Users");
  • Visitors to our websites and marketing pages;
  • Prospective clients and partners who interact with us during pre-sales or onboarding.

This Policy does not apply to third-party services, websites, or applications that may be linked from our platforms. We encourage you to review the privacy policies of any third-party services you access.

3. Roles Under Data Protection Law

Loyaltics acts in the following capacities depending on the context:

3.1 Data Processor

When processing personal data submitted by Clients in connection with the delivery of Services (for example, employee data loaded into FSA, distributor records in DMS, or consumer loyalty profiles in BzLoyalty), Loyaltics acts as a Data Processor on behalf of the Client, who is the Data Controller. Processing in this capacity is governed by the contractual agreement between Loyaltics and the Client, including any applicable Data Processing Agreement (DPA).

3.2 Data Controller

When Loyaltics independently determines the purposes and means of processing — such as for our own website analytics, marketing communications, platform improvement, and account management — we act as the Data Controller for that data.

4. Data We Collect

The categories of data collected vary by platform and user type:

4.1 BzLoyalty — Loyalty Management (B2B & B2C)
  • Consumer profiles: name, mobile number, email address, demographic information
  • Transaction records: purchase history, reward points earned and redeemed, redemption records
  • Program participation data: loyalty tier, enrollment date, campaign interactions
  • Device identifiers and session data for mobile application access
  • Communication preferences and consent records
4.2 FSA — Field Sales Automation
  • Field agent identity: name, employee ID, contact details
  • Location data: GPS coordinates and location history during working hours for attendance verification and route tracking
  • Attendance and check-in/check-out records
  • Device information: device model, OS version, app version
  • Activity logs: customer visits, order placement, beat plans
4.3 DMS — Distributor Management System
  • Distributor and retailer profiles: business name, contact person, GST number, address
  • Order data: purchase orders, sales orders, invoices, payment records
  • Inventory and stock data
  • Financial data: outstanding balances, credit limits, payment history
  • User account credentials for authorised distributor users
4.4 ERP — Enterprise Resource Planning
  • Organisational data: employee records, departmental information, HR data
  • Financial data: accounts, transactions, budgets, payroll information
  • Operational data: procurement, inventory, production, logistics records
  • Audit logs and system usage records
4.5 Website and Marketing
  • Contact information submitted via enquiry or demo request forms
  • Cookies and similar tracking technologies (see Section 12)
  • IP address, browser type, and referring URLs
  • Email interaction data from marketing communications
5. Purposes of Processing

We process data for the following purposes:

  • Service delivery: To provision, operate, maintain, and support the Services subscribed to by Clients.
  • Account management: To manage Client accounts, billing, and contractual obligations.
  • Product improvement: To analyse usage patterns, conduct research, and improve platform features and performance.
  • Security and fraud prevention: To monitor for unauthorised access, detect and prevent fraudulent activity, and ensure platform integrity.
  • Legal compliance: To comply with applicable laws, regulations, court orders, or government authority requests.
  • Communication: To send transactional notifications, service updates, security alerts, and, where consent has been obtained, marketing communications.
  • Analytics: To generate aggregated and anonymised insights on platform performance and user engagement.
6. Legal Basis for Processing

Loyaltics processes personal data on the following legal bases, in accordance with applicable data protection law:

  • Contractual necessity: Processing required to perform our contractual obligations to Clients and End Users.
  • Consent: Processing based on explicit consent provided by the data subject, including for marketing communications and optional features. Consent may be withdrawn at any time.
  • Legitimate interests: Processing necessary for our legitimate business interests — such as fraud prevention, service security, and product improvement — where the rights of data subjects do not override those interests.
  • Legal obligation: Processing required to comply with applicable law, including the Indian Information Technology Act 2000, Digital Personal Data Protection Act 2023 (DPDP Act), and other applicable regulations.
7. Data Sharing and Disclosure

Loyaltics does not sell, rent, or trade personal data to third parties for their own commercial purposes.

We may share data in the following circumstances:

7.1 Sub-Processors and Technology Providers

We engage carefully selected third-party providers to support our infrastructure and operations, including:

  • Cloud infrastructure providers (e.g., Amazon Web Services) for hosting, storage, and compute services
  • SMS and email gateway providers for transactional communications
  • Analytics and monitoring tools for performance management
  • KYC and identity verification providers, where applicable

All sub-processors are bound by Data Processing Agreements and are required to maintain appropriate technical and organisational security measures. A list of active sub-processors is available upon written request.

7.2 Client Administrators

Data associated with a Client's account is accessible to that Client's authorised administrators as part of the Services. Clients are responsible for managing their administrators' access appropriately.

7.3 Legal and Regulatory Requirements

We may disclose data where required by law, court order, or regulatory authority — including disclosures to CERT-In, MeitY, or law enforcement agencies as required under Indian law.

7.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction, subject to equivalent privacy protections.

8. Data Security

Loyaltics implements a comprehensive set of technical and organisational security measures to protect personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of all data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256 where applicable
  • Role-Based Access Control (RBAC) and least-privilege access principles
  • Multi-Factor Authentication (MFA) for all administrative access
  • Continuous monitoring using Amazon CloudWatch and security alerting systems
  • Regular vulnerability scanning and risk-based patch management
  • Logical tenant-level data isolation ensuring no cross-client data access
  • Formal incident response procedures with defined notification timelines

Please refer to our Security Policy (Section III of this document) for full details of our security controls and infrastructure.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to perform our contractual obligations, and to comply with applicable legal requirements.

  • Client and End User account data: Retained for the duration of the active service agreement plus a defined post-termination period as agreed in the contract (typically 30–90 days), after which data is securely deleted or returned to the Client upon request.
  • System and access logs: Retained for a minimum of 90 days online, with the ability to extend retention up to 12 months for compliance or audit purposes.
  • Backup data: Retained for up to 90 days under the standard backup policy, subject to Client-specific configuration.
  • Marketing and enquiry data: Retained until consent is withdrawn or for a period of 24 months from last interaction, whichever is earlier.
  • Legal and financial records: Retained for the period required under applicable law (typically 7 years for financial records under Indian law).

Upon expiry of the applicable retention period, data is securely deleted or anonymised in a manner consistent with industry best practices.

10. Rights of Data Subjects

Subject to applicable law, individuals whose personal data we process may have the following rights:

  • Right of Access: To obtain confirmation of whether we process your personal data and to receive a copy of that data.
  • Right of Correction: To request correction of inaccurate or incomplete personal data.
  • Right of Erasure: To request deletion of personal data where it is no longer necessary for the purpose for which it was collected, or where consent has been withdrawn and no other legal basis applies.
  • Right to Restrict Processing: To request that we limit processing of your data in certain circumstances.
  • Right to Data Portability: To receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Withdraw Consent: To withdraw consent for processing activities based on consent at any time, without affecting the lawfulness of processing prior to withdrawal.
  • Right to Grievance Redressal: Under the DPDP Act 2023, to lodge a complaint with our Grievance Officer (see Section 15) or with the Data Protection Board of India.

To exercise any of the above rights, please contact us using the details in Section 15. We will respond to verified requests within 30 days. In complex cases, this period may be extended by a further 30 days with notice.

11. International Data Transfers

Loyaltics' Services are hosted primarily on Amazon Web Services (AWS) infrastructure. Data may be processed in or transferred to countries outside India in the course of service delivery, including for cloud infrastructure, backup, or support purposes.

Where data is transferred internationally, Loyaltics ensures that appropriate safeguards are in place, which may include:

  • Standard Contractual Clauses (SCCs) or equivalent contractual mechanisms
  • Transfers to countries or organisations recognised as providing adequate data protection
  • Binding contractual security and data protection obligations on all recipients

All international transfers comply with the requirements of the DPDP Act 2023, GDPR (where applicable), and other applicable data protection laws.

12. Cookies and Tracking Technologies

Our websites and platforms use cookies and similar tracking technologies to enhance user experience, measure performance, and support analytics. The categories of cookies we use include:

  • Strictly Necessary Cookies: Required for the operation of the platform; cannot be disabled.
  • Performance and Analytics Cookies: Used to understand how visitors interact with our website (e.g., page views, session duration). Data collected is aggregated and anonymised.
  • Functional Cookies: Enable personalised features and user preferences.
  • Marketing Cookies: Used to deliver relevant advertising where consent has been provided.

On first visit to our website, you will be presented with a cookie consent banner where you can manage your cookie preferences. You may also manage cookie settings through your browser at any time. Please note that disabling certain cookies may affect the functionality of our Services.

13. Children's Data

Loyaltics' Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe that a child under 18 has provided personal data to us without appropriate parental consent, please contact us immediately at info@bzloyalty.com and we will take steps to delete such data promptly.

14. Regulatory Compliance

Loyaltics is committed to compliance with all applicable data protection and privacy laws, including but not limited to:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act) — India
  • The Information Technology Act, 2000 and the IT (Amendment) Act, 2008 — India
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — India
  • CERT-In Directions on Information Security Practices (April 2022)
  • General Data Protection Regulation (GDPR) — European Union, applicable to processing of personal data of EU/EEA data subjects
  • Other applicable national or sector-specific data protection regulations in jurisdictions where Loyaltics operates or its Clients are based

Where Loyaltics' Clients are subject to additional regulatory requirements (such as PDPA in Thailand, PDPPL in Japan, or PIPEDA in Canada), Loyaltics will work with those Clients to ensure that appropriate contractual and technical measures are in place.

15. Grievance Officer and Contact Details
Grievance Officer — Loyaltics Tech Pvt. Ltd.

In accordance with the Information Technology Act 2000 and DPDP Act 2023, Loyaltics has designated a Grievance Officer to address complaints and inquiries regarding personal data processing.Name: Hanit Vairagi Designation: Grievance Officer / Data Protection OfficerEmail: info@bzloyalty.com Postal Address: Loyaltics Tech Pvt. Ltd., Topaz 36, Silver Springs Phase-II, Indore (MP), IndiaWe aim to acknowledge all grievances within 48 hours and resolve them within 30 days of receipt.

16. Changes to This Privacy Policy

Loyaltics reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will:

  • Update the Effective Date at the top of this Policy
  • Notify active Clients and registered users via email or in-platform notification
  • Post the updated Policy on our website

Your continued use of our Services after the effective date of any update constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.

SECURITY POLICY

1. Purpose and Scope

This Security Policy describes the technical and organisational security measures implemented by Loyaltics Tech Pvt. Ltd. to protect the confidentiality, integrity, and availability of all data processed across its SaaS platforms — including BzLoyalty (Loyalty, FSA), DMS, ERP, and future products.

This Policy applies to all Loyaltics employees, contractors, vendors, and systems involved in the delivery of Services to Clients. It is supplementary to the Privacy Policy and Terms & Conditions, and all three documents form part of Loyaltics' overall Legal & Security Framework.

2. Security Governance
2.1 Responsibility

Information security is governed by Loyaltics' Information Security Officer (ISO), who is accountable for security policy, risk management, compliance oversight, and incident response. The ISO is supported by the engineering, operations, and IT teams.

2.2 Policies and Reviews

Security policies are reviewed at least annually and following significant changes to the platform, regulatory environment, or threat landscape. All changes are subject to management approval and documented in the version history.

2.3 Risk Management

Loyaltics maintains a formal risk management process covering identification, assessment, treatment, and monitoring of information security risks. Risk assessments are conducted for new services, significant changes, and third-party engagements.

3. Infrastructure Security
3.1 Cloud Hosting

All Loyaltics production services are hosted on Amazon Web Services (AWS), a globally recognised cloud infrastructure provider that maintains certifications including ISO 27001, SOC 2 Type II, PCI DSS, and compliance with applicable regional regulatory frameworks. Loyaltics operates under the AWS Shared Responsibility Model, under which AWS is responsible for the security of the underlying cloud infrastructure and Loyaltics is responsible for the security of its applications and data within that infrastructure.

3.2 Network Security

The production environment is protected by:

  • AWS Virtual Private Cloud (VPC) with network segmentation and security groups
  • Web Application Firewall (WAF) to protect against common application-layer attacks
  • Intrusion detection and behaviour monitoring tools
  • DDoS mitigation through AWS Shield
  • All inbound and outbound traffic managed through controlled access points
3.3 Physical Security

Physical security of data centres is managed by AWS in accordance with their certified physical security controls, including 24/7 security personnel, multi-factor physical access controls, CCTV surveillance, and resilient facility design. Loyaltics does not operate its own physical data centres.

3.4 Multi-Region and Availability

Loyaltics utilises multiple AWS availability zones and, where applicable, multiple AWS regions to ensure high availability and resilience. Security controls are consistently applied across all environments and regions.

4. Data Encryption
4.1 Encryption in Transit

All data transmitted between End Users and Loyaltics' platforms is encrypted using Transport Layer Security (TLS) version 1.2 or higher. All public-facing web interfaces, APIs, and administrative portals enforce HTTPS. Unencrypted communication is not permitted for any Service endpoint.

4.2 Encryption at Rest

Databases and object storage containing Client and End User data are encrypted at rest using AES-256 encryption managed through AWS Key Management Service (KMS). Backups are encrypted using the same standard.

4.3 Application-Level Protection

At the application level, additional data protection controls are implemented:

  • Passwords are hashed using strong adaptive algorithms (bcrypt or equivalent); plaintext passwords are never stored
  • Sensitive credentials, API keys, and configuration secrets are managed using AWS Secrets Manager
  • Encryption is applied to additional sensitive data elements at the application layer as appropriate
4.4 Encryption Compliance

All encryption implementations comply with applicable regulatory requirements, including CERT-In guidelines and DPDP Act 2023 obligations, and use widely accepted, industry-standard cryptographic algorithms.

5. Access Control
5.1 Role-Based Access Control (RBAC)

Access to all Loyaltics systems, platforms, and data is governed by Role-Based Access Control (RBAC), ensuring that users and system accounts are granted only the minimum permissions necessary to perform their function (principle of least privilege). Roles and permissions are explicitly defined and documented for each platform.

5.2 Multi-Factor Authentication (MFA)

Multi-Factor Authentication is enforced for:

  • All administrative access to the Loyaltics production environment
  • All Client administrator accounts within the platform
  • All remote access to backend infrastructure

End User MFA is enforced via OTP-based authentication delivered to registered mobile numbers or email addresses, as applicable to the platform and access channel.

5.3 Privileged Access Management

Access to production systems by Loyaltics engineering and operations personnel is restricted to authorised individuals and is subject to IP allowlisting, MFA, and full activity logging. All privileged access sessions are recorded in audit logs. Production access is granted on a need-to-access basis and reviewed periodically.

5.4 User Lifecycle Management

A formal user provisioning and de-provisioning process is in place. Access rights are revoked promptly upon role change, project completion, or termination of employment or contract. Client administrators can independently manage their own users' access through the platform's administration interface.

6. Application Security
6.1 Secure Development Lifecycle (SDLC)

Loyaltics follows a formal Software Development Lifecycle (SDLC) incorporating security at every stage:

  • Security requirements are defined and reviewed during design
  • Code reviews are mandatory for all changes to production code
  • Static analysis and dependency vulnerability scanning are integrated into the CI/CD pipeline
  • All changes are validated in an isolated staging environment before production deployment
  • Production deployments follow the documented Change Management Process with rollback capability
6.2 API Security

All Loyaltics APIs are secured with:

  • Authentication using secure token-based mechanisms (JWT or equivalent)
  • HTTPS/TLS enforcement on all endpoints
  • Input validation and output encoding to prevent injection attacks
  • Rate limiting to prevent abuse and denial-of-service
  • API activity logging for audit and anomaly detection
6.3 Vulnerability Management

Loyaltics maintains an ongoing vulnerability management programme including:

  • Regular automated vulnerability scanning of infrastructure and application components
  • Monitoring of CVE databases, security advisories, and vendor bulletins for all technologies in use
  • Risk-based patch management with critical patches applied on an expedited basis
  • Bimonthly scheduled patching cycles for standard security updates
  • Planned engagement of independent third-party penetration testing as part of the security maturity programme
7. Tenant Data Isolation

Loyaltics' platforms implement strict logical data isolation at the application layer. Each Client's data is segregated using tenant-specific identifiers, access controls, and query scoping. No cross-tenant data access is architecturally possible. Data exports, reports, and backups are generated and managed on a per-client basis. Tenant isolation controls are tested as part of the application security review process.

8. Monitoring and Logging
8.1 Centralised Monitoring

All platform and infrastructure activity is monitored using Amazon CloudWatch, which provides centralised logging, performance metrics collection, and automated alerting. Monitoring covers:

  • API activity, error rates, and latency
  • Infrastructure resource utilisation and availability
  • Security events, failed access attempts, and anomalous behaviour
  • Third-party integration health and availability
8.2 Audit Logging

Comprehensive audit logs are maintained for all significant user and administrative actions, including:

  • User logins and logouts
  • Configuration and settings changes
  • Data access, creation, modification, and deletion events
  • Privilege escalations and role changes
  • Administrative operations on tenant data

Audit logs are stored in protected, tamper-evident storage with restricted access. Log retention meets a minimum of 90 days online, with up to 12 months available through configuration, aligned with Client requirements and applicable regulatory standards.

8.3 Alerting and Response

Security alerts are configured for predefined conditions including unusual login patterns, elevated error rates, and indicators of potential security incidents. Alerts are routed to the on-call engineering and security team for immediate investigation and response.

9. Backup and Disaster Recovery
9.1 Backup

Production data, application components, and system configurations are backed up daily using AWS-managed backup services. Backups are encrypted at rest using AES-256. Standard backup retention is 90 days, configurable to meet Client-specific requirements. Backup integrity is verified periodically through restoration testing.

9.2 Disaster Recovery

Loyaltics maintains a Business Continuity and Disaster Recovery (BCDR) plan that covers:

  • Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) aligned with service level commitments
  • Use of multiple AWS availability zones for resilience against single-zone failures
  • Documented recovery procedures for common failure scenarios
  • Periodic disaster recovery testing and plan review
10. Incident Response
10.1 Incident Response Process

Loyaltics maintains a formal Incident Response Plan covering the full lifecycle of security incidents:

  • Detection: Continuous monitoring and alerting to identify potential incidents promptly
  • Triage and Containment: Immediate assessment to classify the incident severity and implement containment measures
  • Investigation: Root cause analysis to determine the nature, scope, and impact of the incident
  • Eradication and Recovery: Removal of the threat and restoration of affected systems and data
  • Post-Incident Review: Documentation of lessons learned and implementation of corrective actions
10.2 Client Notification

In the event of a confirmed security incident that affects Client Data:

  • Initial notification will be provided to affected Clients within 72 hours of Loyaltics confirming the incident
  • Periodic updates will be provided during active investigation based on severity and impact
  • A final incident report will be shared upon resolution, including details of the incident, its impact, and remediation actions taken
10.3 Incident Contact

Security Incident Reporting

To report a suspected security incident or vulnerability, please contact:Email: info@info@bzloyalty.com Subject: Security Incident ReportAcknowledgement: Within 4 business hours of receiptResolution target: In accordance with incident severity classification

11. Third-Party and Vendor Security

Loyaltics manages third-party security risk through a formal vendor management programme:

  • All vendors and sub-processors are assessed for security risk and suitability prior to engagement
  • Vendors handling personal data are required to execute Data Processing Agreements (DPAs) and meet defined security standards
  • Key vendor relationships are reviewed at least annually
  • Vendor service availability and security posture are monitored on an ongoing basis
  • Third-party access to Loyaltics systems is governed by time-bound, role-limited access controls, MFA, and activity logging
12. Employee and Contractor Security
12.1 Background Checks

All Loyaltics employees and contractors undergo background verification checks in accordance with applicable local laws prior to engagement.

12.2 Security Agreements

All personnel are required to sign employment or contractor agreements that include confidentiality obligations and information security responsibilities. Non-Disclosure Agreements are executed with all employees, contractors, and third parties prior to access to Confidential Information or Client Data.

12.3 Security Awareness Training

All employees receive security awareness training upon joining and on an ongoing basis. Training covers data protection obligations, phishing and social engineering awareness, acceptable use policies, and incident reporting procedures.

12.4 Access Revocation

Access to all systems, applications, and data is revoked promptly upon termination of employment or contract, as part of a standardised off-boarding procedure.

12.5 Disciplinary Process

Loyaltics maintains a formal disciplinary procedure to address violations of security policy, with actions proportionate to the severity and intent of the breach.

13. Change Management

All changes to production systems, applications, and infrastructure follow Loyaltics' documented Change Management Process, which includes:

  • Formal change request logging and categorisation
  • Impact and risk assessment prior to approval
  • Required code review and peer approval for all production changes
  • Validation in an isolated staging environment before production deployment
  • Defined rollback procedure for all changes
  • Post-deployment monitoring and verification
  • Advance client notification for changes that may affect Service availability (see Section II, Clause 11)
14. Regulatory and Compliance Alignment

Loyaltics' security programme is designed to meet the requirements of applicable regulations and widely recognised security frameworks, including:

  • Digital Personal Data Protection Act 2023 (DPDP Act) — India
  • Information Technology Act 2000 and IT (Amendment) Act 2008 — India
  • CERT-In Directions on Information Security Practices (2022) — India
  • General Data Protection Regulation (GDPR) — EU/EEA
  • ISO/IEC 27001 principles (information security management)
  • NIST Cybersecurity Framework guidelines
  • AWS Shared Responsibility Model

Loyaltics will cooperate with Client audit requirements and provide documentation of relevant security controls upon request, subject to confidentiality protections.

15. Contact for Security Enquiries

Security Enquiries — Loyaltics Tech Pvt. Ltd.

For security-related questions, audit inquiries, or to report a vulnerability or incident:Email: info@bzloyalty.com Postal Address: Loyaltics Tech Pvt. Ltd., Topaz 36, Silver Springs Phase-II, Indore (MP), IndiaWe are committed to responding to all legitimate security inquiries promptly and transparently.

Contact Us
  • If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at info@bzloyalty.com