Legal
Privacy Policy
This policy explains what personal data Fluxeentra collects when you use this website or buy a service, what it is used for, who else processes it, and the rights you can exercise.
Last updated 10 September 2026
In short
- We collect only what we need to invoice you and deliver the service you bought: contact and billing details, order records, your technical brief and basic site analytics.
- We never receive card numbers, UPI PINs or banking credentials. The payment gateway processes them and tells us only whether the payment succeeded.
- We do not sell personal data or build advertising profiles. Four categories of processor support us: payments, email, hosting and analytics.
- You can ask for access, correction or erasure, or withdraw consent, by writing to the Grievance Officer. We respond within 30 days.
This summary is provided for convenience. The numbered sections below contain the detail required by the Digital Personal Data Protection Act, 2023 and take precedence over it.
1. Scope
This policy applies to anyone who visits Fluxeentra, creates an account, contacts us, submits a technical brief or buys a service. It is prepared under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the reasonable security practices rules made under the Information Technology Act, 2000.
Two terms from the DPDP Act are used throughout. The Data Principal is you, the individual the data relates to. The Data Fiduciary is us, the organisation that decides why and how the data is processed and is responsible for protecting it.
This policy does not apply to third-party websites we link to, platforms you sign in to separately, or systems you own that we work in during an engagement. Section 6 covers that last situation.
2. Data Fiduciary
The Data Fiduciary is FLUXENTRA LABS PRIVATE LIMITED, 4th Floor, No. 92, VB Arcade, ITI Employees Layout,Nagarabhavi, Mallathahalli, Bengaluru, Bengaluru Urban, Karnataka, 560056..
Formal requests and complaints are handled by the Grievance Officer referred to in section 16. Each request is assigned to one named person from the time we receive it.
3. Data we collect
We collect five categories of data, limited to what is needed to provide our services.
- Account data: name, email address, mobile number, business name if you provide one, and a one-way hash of your password. Passwords are never stored in readable form, so neither we nor anyone who obtained the database could recover yours.
- Billing data: billing name, address, city, state, PIN code and, if you provide it, your GSTIN. We need these to issue a valid tax invoice.
- Order data: the services purchased, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
- Technical brief: the information you give us so the work can be carried out, such as repository and environment names, architecture notes, the problem to be solved, access instructions and attached files. This is mainly business information, but it often includes names and work email addresses.
- Site and device data: IP address, browser and device type, pages viewed, referring source and approximate city, collected through analytics and server logs.
We do not collect or store card numbers, CVV codes, UPI PINs or net banking credentials at any stage. We do not ask for identifiers such as Aadhaar or PAN unless a specific legal requirement makes it necessary, and if that happens we will explain why at the time.
4. How we use it
Each purpose below is specific. Data collected for one purpose is not reused for an unrelated one.
| Purpose | Data used |
|---|---|
| Creating, confirming and delivering your order | Account, billing, order, brief |
| Issuing GST invoices and keeping tax records | Billing, order |
| Contacting you about an order, including confirmation, questions, handover and support | Account, order |
| Assigning engineers and planning the work | Brief, order |
| Handling refunds, disputes and grievances | Order, billing, correspondence |
| Operating the site, preventing fraud and fixing faults | Site and device data |
| Understanding, in aggregate, how pages are used | Site and device data |
| Sending occasional updates about new services | Name and email, only if you opted in |
We do not build advertising profiles or use behavioural retargeting, and we do not sell, rent or trade personal data.
5. Consent and legitimate uses
We process personal data on two grounds under the DPDP Act.
- Consent: given freely, for a specific purpose, on an informed basis and unambiguously, when you submit a form, create an account, complete a brief or opt in to updates. Each request states the purpose before you provide the data.
- Legitimate uses: processing needed to perform the contract formed when you pay, and processing required by law, such as keeping tax records under Indian law.
You can withdraw consent at any time, as easily as you gave it, by writing to the Grievance Officer. Withdrawal stops further processing that relies on consent. It does not affect processing already carried out lawfully, or records that the law requires either of us to keep. If withdrawal would prevent us from continuing a service you have paid for, we will tell you before acting on it.
Consent to marketing is separate from everything else. Declining it has no effect on any order, and every marketing email includes a one-click unsubscribe link that takes effect immediately.
6. Your brief and data in your systems
Our role depends on where the data is held.
- Data we hold about you. For account, billing, order and brief data stored in our systems, we are the Data Fiduciary and this policy applies.
- Data about your users, held in your systems. When an engagement requires us to work in your repositories, databases or cloud accounts, you remain the Data Fiduciary and we act only on your documented instructions. Before that work begins, we sign a data processing agreement covering purpose limitation, security, sub-processing, breach notification and deletion at the end of the engagement.
By default we ask for anonymised, masked or synthetic data instead of production personal data. Where live access cannot be avoided, it is given to named individuals with the minimum privileges needed, logged, limited in time and revoked at handover.
8. Transfers outside India
The website, its database and its backups are hosted in India. Some processors, particularly for email delivery and analytics, operate infrastructure outside India, so a limited amount of personal data may be processed abroad.
Such transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act, are limited to what the purpose requires, and are covered by contracts requiring protection equivalent to this policy. If a transfer restriction changes, we will move the processing to comply with it.
9. Retention
We keep personal data only for as long as the purpose requires or the law demands. After that it is deleted or irreversibly anonymised.
| Data | Retention period | Reason |
|---|---|---|
| Invoices, order and payment records | 8 financial years | Income tax and GST record-keeping |
| Account profile | While the account is open, then 90 days | Allows an accidental deletion to be reversed |
| Technical brief and delivery materials | 12 months after handover | Allows the handover pack to be sent again on request |
| Support and grievance correspondence | 3 years from closure | Complaint records under the e-commerce rules |
| Marketing consent and unsubscribe records | Until you unsubscribe, plus 12 months | Evidence that the unsubscribe was honoured |
| Server and access logs | 180 days | Security investigations and fault diagnosis |
| Aggregated analytics | 26 months | Year-on-year comparison, without identifying individuals |
If you ask for erasure, we delete all data that is not covered by a statutory retention period above, and we tell you what had to be kept and under which obligation.
10. Security measures
Our safeguards include:
- HTTPS with modern TLS across the whole site, so data is encrypted in transit;
- passwords stored as salted one-way hashes that cannot be recovered, including by us;
- database backups encrypted at rest, with restores tested;
- individual named administrator accounts protected by multi-factor authentication, with no shared logins;
- least-privilege access to customer data, reviewed whenever someone changes role or leaves;
- no payment credentials processed or stored on our servers;
- client credentials kept in a secrets manager, never in email, chat, spreadsheets or source code;
- dependencies patched on a schedule, with platform security updates applied outside business hours;
- confidentiality obligations for all staff that continue after they leave.
No system is completely secure. If you find a vulnerability in this site, please report it to us. We will investigate and fix it promptly and, if you wish, credit you for the report.
12. Your rights
As a Data Principal under the DPDP Act, you have the following rights.
- Access: a summary of the personal data we hold about you, how we use it and the categories of processor that have received it.
- Correction: inaccurate data corrected, incomplete data completed and outdated data updated.
- Erasure: data deleted once it is no longer needed for the purpose it was collected for, subject to the statutory retention periods in section 9.
- Withdrawal of consent: for any processing based on consent, as easily as it was given.
- Nomination: appointing another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal: a readily available way to complain to us, answered within a published timeline, before you approach any other body.
The Act also places duties on Data Principals: provide authentic information, do not impersonate another person, and do not file false or frivolous complaints.
Making a request. From the email address linked to your account, write to our Grievance Officer, Sreenivasulu Balayellugari and SAGILI SAI LELA SAGAR, at grievance@fluxeentra.com, stating which right you want to exercise. We may ask a few questions to confirm your identity before acting. We respond within 30 days. If a complex request needs longer, we will tell you within those 30 days, with the reason and an expected date.
There is no charge for exercising these rights.
13. Children and guardians
Our services are sold to businesses and this site is not directed at children. We do not knowingly collect personal data from anyone under 18, and we never track, profile or target advertising at children.
If you believe a child has given us personal data, tell us and we will delete it promptly. Where an account has to be operated on behalf of a child, or of a person with a disability who has a lawful guardian, verifiable consent from the parent or guardian must be obtained first, as the DPDP Act requires.
14. Data breaches
If a personal data breach occurs, we will investigate and contain it immediately, and notify the Data Protection Board of India and each affected Data Principal in the form and within the time required by the DPDP Act.
Our notice to you will explain what happened, which data was affected, the likely consequences, the steps we have already taken and any steps we recommend you take. We will not delay a notification for reputational reasons.
15. Changes to this policy
We update this policy when our processing or the law changes. The date at the top of the page shows the current version, and material changes are highlighted on this page. If a change requires fresh consent, we will ask for it. Previous versions are available on request.
16. Contact and complaints
For privacy questions, data requests or complaints, contact:
- Grievance Officer (Sreenivasulu Balayellugari and SAGILI SAI LELA SAGAR): grievance@fluxeentra.com, 9502021636
- Support: care@fluxeentra.com
- Post: 4th Floor, No. 92, VB Arcade, ITI Employees Layout,Nagarabhavi, Mallathahalli, Bengaluru, Bengaluru Urban, Karnataka, 560056.
We acknowledge complaints within 48 hours and give a substantive response within 15 days. The full escalation process, including the external bodies you can approach, is set out on our grievance redressal page.
If you are not satisfied with our response, you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer. This policy is governed by the laws of India.