Treta Infotech (“Company,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, and security of personal information collected through our web properties, software-as-a-service (SaaS) products, software add-ins, mobile and cloud applications, and developer interfaces (collectively referred to as the “Services”).
This Master Privacy Policy applies comprehensively to:
a) Corporate Web Properties: Visitors to our official website (https://www.tretainfotech.com) and associated subdomains.
b) Microsoft Marketplace & SaaS Apps: Users, administrators, and organizations who license, install, deploy, or interact with Treta Infotech applications procured through Microsoft AppSource, Microsoft Azure Marketplace, or the Microsoft 365 Store.
c) Future Offerings: Any future software applications, web extensions, APIs, integrations, or digital solutions released by Treta Infotech.
d) Commercial Inquiries: Prospects, enterprise representatives, and partners communicating with our technical, commercial, or support teams.
Data Controller vs. Data Processor Distinction: Under applicable data protection frameworks (such as the EU General Data Protection Regulation [GDPR], UK GDPR, and the Indian Digital Personal Data Protection Act [DPDPA 2023]):
a) Data Controller: Treta Infotech acts as a Data Controller regarding account registration data, contact information, billing records, and direct telemetry collected from website visitors and subscribing enterprise administrators.
b) Data Processor / Service Provider: Treta Infotech acts as a Data Processor when hosting, processing, or transmitting organizational data, documents, records, or metadata uploaded or generated by Customer's authorized users within our SaaS applications. The customer's enterprise serves as the Data Controller.
We gather information necessary to provide enterprise-grade SaaS functionality, maintain secure authentication, fulfill commercial orders, and improve user experience across all deployed applications.
A. Information You Voluntarily Provide
i. Account & Registration Credentials: Full name, business email address, company name, department, job title, phone number, physical corporate address, and encrypted authentication credentials when registering an account, requesting a trial, or onboarding.
ii. Commercial & Billing Information: Billing contact details, tax identification numbers (e.g., GSTIN, VAT), corporate invoicing records, and transactional history. For direct payments, financial data is processed via PCI-DSS compliant payment gateways; for Marketplace purchases, billing data is handled directly by Microsoft.
iii. Customer Service & Technical Telemetry: Communications, issue descriptions, configuration files, error logs, and screen captures submitted to our support helpdesk or customer success personnel.
B. Information Collected from Microsoft Cloud Ecosystem (SSO & Microsoft Graph): When our SaaS applications are deployed or accessed within the Microsoft ecosystem (such as Microsoft 365, Microsoft Entra ID / Azure Active Directory, Microsoft Teams, or Power Platform), we may receive information authorized by your tenant administrator:
i. Single Sign-On (SSO) Profile: Microsoft Tenant ID, User Principal Name (UPN), assigned email address, display name, and organizational profile data.
ii. Marketplace License Tokens: Active subscription status, plan tier, licensed seat count, and renewal dates transmitted via Microsoft Commercial Marketplace SaaS Fulfillment APIs.
iii. Application-Specific Permissions: Metadata, user scopes, or directory data strictly within the consent boundaries granted during tenant administrator consent workflows.
iv. Password Exclusion: Treta Infotech NEVER collects, accesses, or stores your Microsoft account passwords or multi-factor authentication secrets.
C. Information Collected Automatically via Application Telemetry
i. Device & System Metadata: IP address, operating system, browser type, application build version, client locale, and hardware architecture.
ii. Operational Telemetry: API endpoint latency, crash diagnostics, feature usage frequency, session start/end timestamps, and error traces utilized strictly for service reliability and bug remediation.
iii. Cookies & Session Storage: Minimal session storage and functional tokens utilized to sustain authenticated user sessions across our web applications.
| Data Category | Collected Elements | Processing Purpose | Legal Basis (GDPR / DPDPA) |
|---|---|---|---|
| Account & Identity Data | Name, corporate email, job title, company name, Tenant ID | Account creation, tenant provisioning, SSO authentication, license verification | Contractual Necessity (Art. 6(1)(b)) |
| Operational Telemetry | IP address, browser type, crash logs, API latency, feature clicks | Application stability, threat detection, bug resolution, performance monitoring | Legitimate Interests (Art. 6(1)(f)) |
| Customer Application Data | Business records, configuration files, workflows processed in-app | Executing core SaaS software functionality requested by the user/tenant | Performance of Contract (Art. 6(1)(b)) |
| Commercial & Billing | Billing email, company address, invoice numbers, tax ID | Payment invoicing, tax calculation, financial compliance, renewal handling | Legal Obligation (Art. 6(1)(c)) |
Treta Infotech processes personal and operational information strictly for legitimate commercial and operational purposes:
a) Provisioning and Managing Services: Setting up enterprise tenant workspaces, authenticating authorized users, validating software licenses, and executing SaaS core features.
b) Platform Reliability and Security: Detecting anomalous login attempts, monitoring DDoS attempts, auditing API throughput, and mitigating technical vulnerabilities.
c) Support and Operational Assistance: Resolving customer inquiries, tracking bug tickets, delivering technical patches, and administering training.
d) Transactional Communications: Sending essential administrative notices, renewal invoices, security alerts, policy modifications, and service outage advisories.
e) Legal and Regulatory Compliance: Complying with accounting standards, responding to legitimate court orders, and protecting the intellectual property of Treta Infotech.
We maintain rigorous vendor governance. Treta Infotech relies on enterprise-grade cloud service providers and sub-processors committed to strict confidentiality and data protection standards:
a) Cloud Hosting Infrastructure: Tier-1 cloud environments including Microsoft Azure (utilizing regional data centers compliant with ISO 27001, SOC 2, and FedRAMP) and Amazon Web Services (AWS) to host application code, databases, and backup snapshots.
b) Authentication & Identity: Microsoft Entra ID (Azure AD) Single Sign-On and OAuth 2.0 / OpenID Connect frameworks.
c) Helpdesk & Diagnostics: Cloud-hosted error reporting and customer support ticketing software operated under strict Data Processing Addenda (DPAs).
Sub-processor Oversight: All sub-processors are bound by written agreements obligating them to implement security safeguards no less stringent than those outlined in this Privacy Policy.
Zero Commercial Sale Pledge: Treta Infotech has NEVER sold, rented, monetized, or shared personal data with third-party data brokers or behavioral advertisers, and will NEVER do so.
We disclose information exclusively in the following limited circumstances:
a) Authorized Sub-processors: Service providers providing hosting, billing, or telemetry services under contractual processing terms.
b) Customer Enterprise Direction: Disclosures initiated directly by customer-configured workflows or integration connectors (e.g., Power BI dashboards, SharePoint sync).
c) Legal Necessity: When legally required by applicable statute, court subpoena, national security directive, or law enforcement agency having competent jurisdiction.
d) Corporate Reorganization: In the event of a merger, divestiture, acquisition, or sale of company assets, wherein the surviving entity assumes the privacy covenants outlined herein.
We enforce robust multi-layered administrative, physical, and technical safeguards designed to protect personal and business data:
a) Cryptographic Standards: All data in transit is encrypted using modern protocols (TLS 1.2 and TLS 1.3). Data stored at rest across cloud databases, storage blobs, and disks is protected using AES-256 encryption.
b) Logical Tenant Isolation: Our multi-tenant architecture employs virtual boundaries, schema-level segregation, and tenant-scoped keys to ensure Customer A's data can never be accessed or viewed by Customer B.
c) Access Governance: Internal access to production infrastructure is governed by the Principle of Least Privilege, Multi-Factor Authentication (MFA), role-based access control (RBAC), and audited access logs.
d) Incident Response Framework: In the event of a confirmed security incident impacting customer personal data, Treta Infotech maintains formal procedures to notify affected customer administrators within seventy-two (72) hours of confirmation, in compliance with GDPR and applicable state notification laws.
We retain personal information only for as long as necessary to satisfy the purposes for which it was gathered:
a) Active Subscriptions: Data is maintained throughout the active subscription term of the customer.
b) Post-Termination Grace Period: Upon subscription cancellation, termination, or license expiration, Treta Infotech provides a thirty (30) to ninety (90) day grace period allowing tenant administrators to export their data. Following this period, all tenant database records and backups are securely purged or cryptographically sanitized.
c) Financial & Statutory Records: Transactional billing logs, invoice records, and tax filings are retained for statutory retention periods (typically 7 years) required by applicable tax authorities.
Treta Infotech serves international clients. Your data may be processed on secure servers located in various geographic regions, including the European Union, United States, United Kingdom, and India, depending on customer tenant configuration.
When personal data originated in the EEA, UK, or Switzerland is transferred internationally, Treta Infotech relies upon European Commission approved Standard Contractual Clauses (SCCs), UK International Data Transfer Addenda, or adequacy decisions to ensure an unbroken chain of data protection.
Depending on your jurisdiction (such as the EU/EEA, United Kingdom, California, Virginia, or India), you possess specific statutory rights regarding your personal information:
a) Right of Access: Request verification and a portable copy of the personal data we maintain about you.
b) Right to Rectification: Correct inaccurate, misleading, or obsolete personal data.
c) Right to Erasure (‘Right to be Forgotten’): Request the permanent deletion of personal information where no statutory retention exception applies.
d) Right to Restrict or Object: Restrict specific processing routines or object to processing founded upon legitimate business interests.
e) Right to Data Portability: Obtain your data in a structured, standard, and machine-readable format (e.g., JSON or CSV).
Enterprise User Protocol: Where our applications are licensed by your employer or an enterprise entity, Treta Infotech is the Data Processor and does not possess authority to modify tenant data directly. Please direct your privacy requests to your enterprise IT administrator. Treta Infotech cooperates with administrators to fulfill such requests promptly.
To exercise individual rights regarding direct web accounts, contact our compliance team at contact@tretainfotech.com.
Our public website and web applications use minimal and functional cookies:
a) Strictly Necessary Cookies: Essential for user authentication, session security, and load-balancer routing. Disabling these cookies impairs core application access.
b) Functional Preferences: Remember user interface choices, language settings, and localized tenant parameters.
c) Performance & Diagnostics: Aggregated telemetry tools tracking site performance and page load metrics. We do not utilize third-party cross-site advertising tracking cookies.
You can control or disable cookies via your browser settings. However, disabling essential session tokens will prevent SaaS applications from functioning correctly.
Our Services, website, and SaaS products are designed strictly for enterprise, business, and commercial deployment. We do not knowingly market to, solicit, or collect personal data from minors under eighteen (18) years of age. Any inadvertent collection brought to our attention will be investigated and purged immediately.
Treta Infotech reserves the right to amend this Privacy Policy periodically to reflect technological progress, statutory updates, or additions to our product portfolio. When revisions occur, the updated policy will be published on our website with a refreshed ‘Last Updated’ timestamp. For substantial changes impacting existing subscription rights, we will provide advance notification via administrator email or in-app notification.
For questions, privacy inquiries, compliance assessments, or to contact our Data Protection Officer / Grievance Officer, please reach out to:
Company Legal Entity: Treta Infotech Pvt. Ltd.
Data Protection & Privacy Desk: contact@tretainfotech.com
Customer Support & Inquiries: contact@tretainfotech.com
Corporate Website: https://www.tretainfotech.com
Registered Headquarters: Surat, Gujarat, India [Insert Complete Registered Street Address & Postal Code]
Designated Grievance / Privacy Officer: [Insert Name / Designation, e.g., Head of Information Security, Treta Infotech]