Privacy Policy

Last updated: August 5, 2026

At InfraMinds AI Private Limited ("InfraMinds," "we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-native construction ERP platform, including all associated websites, applications, APIs, and services (collectively, the "Platform"). By accessing or using the Platform, you consent to the practices described in this policy. If you do not agree with any part of this policy, please discontinue use of the Platform immediately.

We are committed to protecting the confidentiality, integrity, and availability of your data. Our approach to data privacy is grounded in the principles of transparency, purpose limitation, data minimization, and accountability, aligned with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 of India, and globally recognized standards including GDPR where applicable.

1. Information We Collect

We collect information you provide directly when creating an account, configuring your organization profile, and using the Platform. Account data includes your name, email address, phone number, company name, designation, and professional credentials. When you authenticate via Google Single Sign-On, we receive your Google profile information (name, email, and profile picture) in accordance with the OAuth 2.0 consent scope you authorize.

Project data encompasses all information uploaded, generated, or managed within the Platform, including but not limited to: project schedules, budgets, BOQs, drawings, BIM models, site diaries, inspection reports, RFIs, correspondence logs, safety records, subcontractor details, material inventories, and equipment registers. This data may contain commercially sensitive information belonging to your organization and your project stakeholders.

Payment data is collected when you subscribe to a paid plan. This includes billing address, GST identification number, and transaction records. Full payment instrument details (credit/debit card numbers, UPI IDs, net banking credentials) are never stored on our servers; they are processed directly by our PCI-DSS compliant payment gateway partners, who provide us with tokenized references for recurring billing purposes.

2. How We Use Information

We use the information we collect to provide, operate, maintain, and improve the Platform. This includes authenticating users, processing subscription payments, delivering the core ERP functionality (project tracking, analytics, reporting, collaboration tools), and providing customer support. Account data enables us to personalize your experience, send service-related communications, and notify you of feature updates, maintenance windows, or changes to our terms.

Aggregated and anonymized usage patterns help us understand how organizations interact with the Platform, identify usability bottlenecks, and prioritize feature development. We may use de-identified project metadata for benchmarking and industry analytics, but never in a form that reveals individual project details or proprietary construction methodologies. Automated processing, including machine learning models that power our predictive analytics, risk assessment, and productivity optimization features, operates on encrypted data within isolated tenant boundaries.

We do not sell your personal data or project data to third parties. We do not use your project data to train foundational AI models that benefit other customers. Your data remains yours; our AI capabilities serve your organization exclusively within your secure tenant environment.

3. Data Storage and Security

Infrastructure: All Platform data is hosted on Amazon Web Services (AWS) within the ap-south-1 (Mumbai) region, ensuring data residency within India. We employ multi-AZ deployment architecture with automated failover, encrypted EBS volumes, and VPC isolation. Data at rest is encrypted using AES-256, and data in transit is protected with TLS 1.3. Database backups are performed continuously with point-in-time recovery, encrypted, and stored across multiple availability zones.

Compliance: InfraMinds maintains SOC 2 Type II certification, demonstrating independent validation of our security, availability, and confidentiality controls. Our Information Security Management System is certified under ISO/IEC 27001:2022. We undergo annual third-party penetration testing by CREST-certified security assessors, and we maintain a comprehensive vendor risk management program for all sub-processors.

Organizational measures include mandatory security awareness training for all personnel, role-based access controls enforced through IAM policies, multi-factor authentication for administrative access, audit logging of all data access events, and a dedicated incident response team available 24/7. Access to production data is restricted to authorized engineering personnel on a need-to-know basis and requires just-in-time privilege escalation with manager approval.

4. Data Sharing and Disclosure

We may share your information with trusted third-party service providers who perform functions on our behalf, including cloud infrastructure (AWS), payment processing, email delivery, customer relationship management, and analytics. These providers are bound by data processing agreements that restrict their use of your data to the specific services they provide to us and require equivalent security standards.

We may disclose information if required by law, regulation, legal process, or governmental request. We will notify you of such requests where legally permissible and will challenge overly broad or unlawful demands. In the event of a merger, acquisition, or asset sale, your data may be transferred as a business asset; we will provide notice before your data becomes subject to a different privacy policy.

We never share your project data, BIM models, financial records, or proprietary construction data with other customers, competitors, or unauthorized third parties. Aggregated, de-identified data that cannot reasonably be linked to any individual or organization may be used for industry research, whitepapers, or public reporting.

5. Your Rights

Under the Digital Personal Data Protection Act, 2023 and applicable privacy regulations, you have the right to access the personal data we hold about you, request correction of inaccurate or incomplete data, request deletion of your data (subject to legal retention obligations), and obtain a portable copy of your data in a structured, machine-readable format. You also have the right to withdraw consent where processing is based on consent, and to file a grievance with our Data Protection Officer.

Account administrators for your organization can access, export, and manage most project data directly through the Platform interface. For personal data requests, write to us at the contact details below; we will respond within 30 days as required by law. Identity verification may be required to process certain requests to prevent unauthorized access.

Data portability requests are fulfilled in JSON or CSV format within 45 days. If you terminate your account, your project data will be available for export for 30 days before deletion commences per our data retention policy.

6. Cookies and Tracking

The Platform uses essential cookies required for authentication, session management, and security (CSRF protection). These cookies are strictly necessary for the Platform to function and cannot be disabled without impairing core functionality. We do not use third-party advertising cookies, tracking pixels for ad retargeting, or browser fingerprinting techniques.

We use functional cookies to remember your preferences (language, dashboard layout, unit system) and analytics cookies (self-hosted, not third-party) to understand aggregate usage patterns, page load performance, and feature adoption. Analytics data is anonymized and does not track individual users across websites. You can manage cookie preferences through your browser settings, though disabling essential cookies may prevent Platform access.

7. Third-Party Services

Google Single Sign-On: When you choose to authenticate using your Google account, Google's privacy policy governs the collection and use of your Google account credentials. We receive only the profile information you authorize during the OAuth consent flow. You can revoke this access at any time through your Google Account settings; subsequent Platform access will require an alternative authentication method.

Payment Gateways: Subscription payments are processed through PCI-DSS Level 1 certified payment gateways operating in India (including Razorpay and Stripe). These gateways collect and process your payment instrument details directly on their secure infrastructure. We receive only transaction references, payment status, and the last four digits of card numbers for reconciliation purposes. We recommend reviewing the privacy policies of these payment providers for details on their data handling practices.

Integration partners (cloud storage, ERP connectors, accounting software) may receive data that you explicitly authorize through API integrations. Each integration's data scope is transparently displayed during the authorization flow, and you can revoke access at any time from your integration settings panel.

8. International Data Transfers

InfraMinds processes and stores all primary Platform data within India. However, certain ancillary services (global CDN for static assets, email delivery services, and monitoring tools) may involve limited data transfers to servers outside India. For any such transfers, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by relevant authorities, adequacy decisions where applicable, and contractual commitments requiring equivalent levels of protection.

Organizations operating across multiple jurisdictions should note that cross-border project collaboration features may result in project data being accessible to team members located in different countries. It is the responsibility of the account administrator to configure access controls appropriate to their regulatory environment.

9. Data Retention

We retain your personal data and project data for the duration of your active subscription plus a 30-day grace period following termination. During the grace period, you may export your data. After the grace period, we commence secure deletion of all tenant data, including backups, within 90 days. Certain residual information may be retained in encrypted backups for up to an additional 12 months as part of our disaster recovery protocol before final purge.

Notwithstanding the above, we may retain information as required by applicable law, to resolve disputes, enforce our agreements, or for legitimate business interests such as fraud prevention and audit trails. Financial transaction records are retained for 8 years per Indian tax law requirements under the Income Tax Act, 1961.

10. Children's Privacy

The Platform is designed for use by construction and real estate professionals and is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a person under 18 has provided us with personal data, we will take steps to delete such information promptly. If you believe a minor has provided us with personal data, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or operational needs. Material changes will be communicated via email to account administrators and through an in-Platform notification at least 30 days before the changes take effect. The "Last updated" date at the top of this page will be revised accordingly.

Continued use of the Platform after the effective date of any changes constitutes acceptance of the revised policy. We encourage you to review this policy periodically. Archived versions of previous privacy policies are available upon request.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:

Data Protection Officer

InfraMinds AI Private Limited
Email: dpo@inframinds.ai
Response time: Within 30 days as per statutory requirement

You also have the right to lodge a complaint with the Data Protection Board of India or your local supervisory authority if you believe your data protection rights have been violated.