Legal
Privacy policy
Overview
Indorize Technologies Pvt. Ltd. (“20fourr”, “we”, “us”) is committed to protecting your privacy. This policy explains what personal data we collect from clients and security providers who use the 20fourr platform, how we use it, and the rights you have over your data.
This policy is written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
By using 20fourr, you consent to the collection and processing of your personal data as described in this policy. You may withdraw consent at any time, subject to the conditions described under Your rights (Section 7).
Data we collect
From clients
- Full name, email address, phone number
- Deployment address and service requirements
- GST registration number (business clients)
- Payment information, processed via Razorpay — we do not store card details
- Booking history, shift OTPs, and service reviews
- Device and usage data (IP address, browser type, pages visited)
From security providers
- Business name, registered address, PSARA licence details
- GSTIN, PAN, and bank account details for payouts
- Director or proprietor identity documents
- Personnel records, including police verification and training certificates
- Profile information and service listings
Collected automatically
- Log data: access timestamps, API calls, error logs
- Analytics: session duration, feature usage, funnel metrics, via anonymised analytics tools
- Location data: approximate location for service-area matching, not real-time GPS tracking
How we use your data
Account registration and authentication
Name, email, phone, ID documents
Legal basis · Contract performance
Booking and service facilitation
Deployment address, booking details, OTP records
Legal basis · Contract performance
Payment processing and payouts
Bank details, GSTIN, PAN
Legal basis · Contract / legal obligation
PSARA licence verification
Licence number, issuing authority, expiry
Legal basis · Legal obligation
GST invoicing and tax compliance
GSTIN, invoice data
Legal basis · Legal obligation
Fraud prevention and platform safety
Transaction patterns, login history
Legal basis · Legitimate interest
Customer support
Communications, booking history
Legal basis · Contract / legitimate interest
Platform improvement
Anonymised usage analytics
Legal basis · Legitimate interest
Marketing communications
Email, phone
Legal basis · Consent
Data sharing
We do not sell your personal data. We share it only in the following circumstances.
With service providers
- Razorpay — payment processing and payout settlement
- Cloud infrastructure — secure data hosting
- SMS/OTP providers — OTP and delivery notifications
- Analytics providers — anonymised usage data only
Between clients and providers
When a booking is confirmed, limited information is shared between the client and the provider — specifically the deployment address, shift timings, and contact details necessary to fulfil the service.
Legal and regulatory authorities
We may disclose personal data to government authorities, courts, or law enforcement agencies where required by law, court order, or to protect the rights and safety of users or the public.
Every third-party service provider we use is contractually bound to process data only for the stated purpose and to maintain appropriate security standards.
Data retention
We retain personal data for as long as your account is active or as required to provide services. After account closure:
- Transaction and invoice records: 7 years — GST and accounting obligations
- PSARA-related provider records: 5 years from last engagement
- Shift OTP and attendance logs: 2 years
- Marketing consent records: 3 years from last interaction
- Support communications: 2 years
After the applicable retention period, data is securely deleted or anonymised.
Data security
We implement reasonable security practices under the IT (SPDI) Rules, 2011, including:
- AES-256 encryption for data at rest; TLS 1.2+ for data in transit
- Role-based access controls limiting internal data access to authorised personnel
- Regular security reviews and vulnerability assessments
- Secure OTP-based authentication for critical actions
- No storage of payment card data — handled exclusively by Razorpay’s PCI-DSS-compliant infrastructure
In the event of a data breach likely to result in a risk to your rights or freedoms, we will notify you and the relevant authority as required under applicable law.
Your rights
As a Data Principal under the DPDP Act, 2023, you have the right to:
- Access — request a summary of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data, subject to legal retention obligations
- Grievance redressal — file a complaint with our Grievance Officer
- Withdraw consent — withdraw consent for marketing communications at any time via your account settings or by emailing [email protected]
- Nominate — nominate an individual to exercise your rights in the event of your death or incapacity
To exercise any right, write to [email protected] from your registered email address. We will respond within 30 days.
Cookies and tracking
We use cookies and similar technologies to operate the platform and improve your experience.
- Essential cookies — required for login sessions and security, cannot be disabled
- Functional cookies — remember your preferences, such as language and location filters
- Analytics cookies — anonymised data on platform usage, can be opted out
You can manage cookie preferences through your browser settings. Disabling essential cookies will impair platform functionality. We do not use third-party advertising cookies.
Children’s privacy
The platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has registered an account, we will delete the account and associated data promptly. If you believe a minor has provided us with personal information, contact us at [email protected].
DPDP Act, 2023 compliance
In compliance with the Digital Personal Data Protection Act, 2023:
- We collect only data necessary for the stated purposes — data minimisation
- We obtain free, specific, and informed consent before processing personal data where required
- We have appointed a Grievance Officer accessible to Data Principals
- We maintain a record of consent and purpose for all personal data processed
- Significant Data Fiduciary obligations will be adopted as and when notified by the Government of India
Changes to this policy
We may update this privacy policy from time to time. Material changes will be notified via email or a platform notice at least 15 days before taking effect. The “Last updated” date at the top reflects the most recent revision. Continued use of the platform constitutes acceptance of the revised policy.
Contact us
For privacy-related queries or to exercise your data rights:
For escalated grievances, see the Grievance Officer page.