Privacy and Data Protection Statement

Infilect Technologies Private Limited

Applies to: personal data processed by Infilect Technologies Private Limited and its affiliates as well as subsidiariesApplies to the Infilect mobile applications listed in Section 1


1. Our Commitment

Infilect Technologies Private Limited and its affiliates as well as subsidiaries (“Infilect”, “we”, “us”, “our”) build computer vision, agentic artificial intelligence and analytics products for consumer goods and retail businesses. Our products process very large volumes of imagery and documents captured in commercial environments, and our customers trust us with data that is central to how their businesses run.

This Statement sets out, in one place and in plain language, how we protect personal data across everything we do — as a company that markets and sells software, as a service provider that processes data on behalf of enterprise customers, and as an employer. It is the public expression of the internal Privacy and Personal Data Protection Policy that forms part of our Information Security Management System.

2. Scope of This Statement

This Statement applies to personal data in any form, at every stage of its lifecycle, wherever Infilect processes it — whether Infilect determines the purposes of that processing or processes it on the documented instructions of a customer.

It applies to all systems, people and processes that constitute our information systems, including directors, employees, contractors, interns, suppliers and other third parties who have access to Infilect systems or who process personal data on our behalf.

More specific notices sit beneath this Statement and prevail in respect of the matters they cover:

NoticeWhat it covers
Website Privacy Policy
Personal data collected through www.infilect.com and its
subdomains
Mobile Application Privacy Policy
Personal data collected through the InfiViz mobile applications
Website Terms of Use, Click-Wrap Agreement and Policies
The terms on which the website may be used
End User Licence Agreement
The terms on which our software products are licensed
Data Processing Addendum
Our obligations as processor for a given enterprise customer,
agreed contractually with that customer


3. The Laws We Work To

The principal legal instruments we work to are:

- The Digital Personal Data Protection Act, 2023, and the rules made under it (India);

- The Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India);‍
In each case to the extent they apply to Infilect, or to a customer for whom Infilect processes personal data.

Where a customer’s own regulatory environment imposes additional requirements — for example data localisation, sectoral rules or specific audit rights — those requirements are addressed in the agreement with that customer and implemented at platform level.

4. When We Are a Controller and When We Are a Processor

This distinction determines who you should contact and who is accountable, so we set it out clearly.

SituationInfilect’s roleWhat that means
You visit our website, request a demonstration,
download a resource, attend our event or
apply for a job
Controller / data fiduciary
We decide why and how
your data is processed, and
you can exercise your rights
directly with us
Your employer or principal has deployed an
Infilect product, and you use it or appear in
data captured through it
Processor
Your employer decides why
and how the data is processed;
we act only on its documented
instructions, and you should
contact it first
We operate, secure, diagnose and support our
own platform
Controller, in respect of that
limited processing
We are accountable for diagnostics,
logging, account provisioning and
security telemetry


For each processing activity, the responsible function head, together with Legal, determines and records which role applies. Where we believe a customer instruction infringes applicable law, we will inform that customer and may suspend the relevant processing.

5. Our Data Protection Principles

1. Lawfulness, fairness and transparency. Personal data is processed only where a lawful basis exists and where the individual has been given clear notice.
2. Purpose limitation. Personal data is collected for specified, explicit purposes and is not further processed in a manner incompatible with those purposes.
3. Data minimisation. Only the personal data necessary for the purpose is collected and retained. Where the purpose can be achieved with anonymised or pseudonymised data, that approach is taken.
4. Accuracy. Personal data is kept accurate and, where necessary, up to date; inaccurate data is corrected or erased without undue delay.
5. Storage limitation. Personal data is kept only for as long as necessary for the purpose, or as required by law.
6. Integrity and confidentiality. Personal data is protected by appropriate technical and organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage.
7. Accountability. We document our compliance and are able to demonstrate it.

6. Personal Data in Visual and Document Data

Our products process photographs, video and documents captured in retail and commercial settings. Those materials are captured for the purpose of assessing products, shelves, packaging, pricing, artwork, invoices and logistics documents — not for the purpose of identifying people. We treat the possibility of incidental personal data in that material as a specific risk and manage it accordingly:

- Purpose. Our recognition models are built to identify products, packaging, price labels, shelf structures and document fields. They are not built to identify individuals.
- Incidental capture. Shoppers or staff may occasionally appear in the background of an image. Deploying organisations are instructed to direct field users away from capturing individuals, and capture guidance in our applications reinforces this.
- Masking and deletion. Masking and deletion controls are available so that a deploying organisation can obscure or remove faces or other incidental personal data, and we operate documented deletion procedures on request.
- Biometrics. Without permission, we do not perform biometric identification or facial recognition in the InfiViz product family. Where any Infilect product is deployed in a configuration that processes video of individuals — for example in-store monitoring — that deployment is governed by a specific written agreement with the deploying organisation, which is the controller, and by a documented privacy impact assessment.

7. Notice, Consent and Lawful Basis

Where Infilect acts as controller, an itemised notice in clear and plain language is given to the individual at or before the point of collection. That notice describes the personal data collected, the purpose, how a right may be exercised, how a grievance may be made, and how a complaint may be made to the relevant authority.

Where consent is the lawful basis, that consent is free, specific, informed, unconditional and unambiguous; it is obtained through a clear affirmative action, recorded with a timestamp, and is capable of being withdrawn as easily as it was given. Withdrawal triggers cessation of the relevant processing and, where no other basis applies, deletion within a reasonable period. Pre-ticked boxes, bundled consent and silence are not valid consent.

8. Artificial Intelligence and Model Development

Because our products are built on machine learning, we are explicit about how customer and personal data relate to model development:

- Segregation. Data belonging to one customer is logically segregated from that of every other customer.• 
- No cross-customer training by default.
We do not use one customer’s data to train or improve models made available to another customer, except where that customer has expressly agreed in writing.
- Aggregated and anonymised data.
We may use aggregated, anonymised or de-identified data that does not identify a customer or any individual to develop, improve, benchmark and support our products. Such data cannot reasonably be used to re-identify a customer or an individual.
- Human oversight.
Our outputs are probabilistic. Recognition, extraction and classification results may contain errors, and customers remain responsible for the business decisions they take. We recommend human review wherever an output drives a consequential decision.
- No automated decisions about individuals. Without agreed in writing, we do not use our products to make automated decisions producing legal or similarly significant effects about individuals on our own behalf. Where a customer configures a deployment in a way that could do so, that customer is the controller and is responsible for the required safeguards.
- Assessment. Any processing involving the identification of individuals from imagery triggers a mandatory privacy impact assessment before it proceeds.

9. Suppliers and Sub-Processors

No third party may process personal data on Infilect’s behalf without a written contract containing confidentiality, security, sub-processing, audit, breach notification, and deletion or return obligations.

Suppliers are assessed before engagement and periodically thereafter, with the depth of assessment proportionate to the sensitivity and volume of personal data involved. We maintain a register of sub-processors, and customers are notified of additions where their agreement requires it. Our principal infrastructure sub-processor is Google Cloud Platform.

A current list of sub-processors relevant to a given product is available to customers on request from privacy@infilect.com.

10. Cross-Border Transfers

Transfers of personal data outside the country of collection are permitted only where a lawful transfer mechanism is in place and recorded.

For transfers from the European Economic Area or the United Kingdom, this means an adequacy decision, the European Commission Standard Contractual Clauses, or the UK International Data Transfer Addendum, supported where necessary by a transfer impact assessment and supplementary measures.

Transfers of personal data out of India are restricted to territories not notified as restricted under the Digital Personal Data Protection Act, 2023. Any customer-imposed data localisation requirement is implemented at platform level and recorded in our record of processing.

11. Retention and Deletion

Personal data is retained in accordance with our records retention schedules, recorded against each processing activity. Where Infilect acts as processor, the retention period is the one agreed with the customer.

On expiry of the retention period, on withdrawal of consent where no other basis applies, or on satisfaction of an erasure request, personal data is deleted or irreversibly anonymised using documented methods, with the result of deletion recorded as evidence. Deletion obligations extend to backups, test environments and third-party systems.

12. Privacy by Design and Impact Assessment

Privacy requirements are addressed at the design stage of every new product, feature, system, integration or supplier engagement that involves personal data.

A privacy impact assessment is carried out where processing is likely to result in a high risk to individuals — including large-scale processing, processing of sensitive personal data, systematic monitoring, the use of a new technology, or any processing involving the identification of individuals from imagery. The assessment is documented, reviewed by the Chief Information Security Officer, and where residual risk remains high, escalated to our Information Security Group.

13. Personal Data Breach Management

Any actual or suspected personal data breach must be reported immediately to the Chief Information Security Officer through our defined incident reporting channels. The incident is triaged, contained, investigated and recorded in the incident register with a root cause analysis.

Where Infilect acts as controller, we notify the relevant supervisory authority and affected individuals within the timescales required by applicable law. Where Infilect acts as processor, we notify the affected customer without undue delay so that it can meet its own notification obligations, and we provide the information and assistance reasonably required for it to do so.

To report a suspected security or privacy incident involving Infilect, contact security@infilect.com.

14. Changes to This Statement

We may update this Statement from time to time. The version in force is the one published on this page, with the effective date shown at the top. Where a change is material we will provide prominent notice.

15. Contact and Grievance Redressal

Privacy contactsupport@infilect.com
Security incident reporting
support@infilect.com
Legal
legal@infilect.com
Grievance Officer (India)
Anand Prabhu Subramanian — support@infilect.com
India office
Indiqube Ascent, No. 420, Mahakavi Vemana Road, KHB Block, Koramangala 4-B, 5th Block,
Bengaluru, Karnataka 560034, India
US office
Infilect Inc., 1401 21st Street, Suite 6028, Sacramento, California 95811, United States


A grievance will be acknowledged within 120 hours of receipt and resolved within 30 days. If you are dissatisfied with our response, you may complain to your supervisory authority or, in India, to the Data Protection Board of India.