Privacy Policy
This policy explains what personal data Mithavo collects when you use our website and platform, why we process it, who we share it with, how long we keep it, and how you exercise your rights. It is written to be read, not to be survived.
- Data fiduciary
- Mithavo Technologies Pvt. Ltd., India
- Applies to
- mithavo.com and the Mithavo platform
- Hosting region
- India, unless agreed otherwise in a contract
- Contact
- privacy@mithavo.com
01 · Scope
Who we are, and in which role
Mithavo Technologies Pvt. Ltd. ("Mithavo", "we") builds and operates an ERP, CRM and CMS platform for regulated manufacturers. This policy covers two different relationships, and the distinction matters:
As a data fiduciary (controller) — for personal data we decide the purpose of: website visitors, enquiry and demo requests, marketing subscribers, prospective and current customer contacts, job applicants and our own staff.
As a data processor — for personal data our customers load into their Mithavo tenant (their employees, their contacts, their vendors). We process that data only on the customer's documented instructions. The customer is the fiduciary; their own privacy notice governs those individuals. The terms of that processing are set out in our Data Processing Addendum.
02 · Categories
What we collect
| Category | Examples | Source |
|---|---|---|
| Enquiry data | Name, work email, phone, company, role, plant location, stated timeline and requirement | Forms you submit — Early Access drawer, contact form, gated checklist downloads |
| Account data | Name, work email, tenant, role and permissions, login timestamps, password hash, OTP verification records | Created by you or by your organisation's administrator |
| Usage & audit data | Pages and records viewed, actions taken, IP address, browser and device, approval and change history | Generated automatically as you use the platform |
| Website analytics | Page views, referrer, aggregated session behaviour | Cookies and similar technologies — see section 08 |
| Support data | Emails, tickets, call notes, screenshots you send us | You, when you contact support |
| Tenant content | Whatever your organisation stores: products, licences, vendors, documents, and the personal data inside them | Your organisation — processed by us on their instructions |
03 · Purpose
Why we process it
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Respond to enquiries and demos | Enquiry data | Your consent, given when you submit the form |
| Provide and operate the platform | Account, usage, tenant content | Performance of the contract with your organisation / legitimate uses |
| Security, audit trail and fraud prevention | Usage & audit data | Legitimate uses and legal obligation |
| Support and service communication | Account, support data | Contract performance |
| Product improvement | Aggregated, de-identified usage | Legitimate uses |
| Marketing emails | Name, work email, company | Consent — withdrawable at any time via the unsubscribe link |
| Legal, tax and accounting records | Billing and contract contacts | Legal obligation |
We do not sell personal data. We do not use tenant content to train machine-learning models for other customers.
05 · Retention
How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not convert | 24 months from last contact, then deleted |
| Marketing subscribers | Until you unsubscribe, plus a suppression record so we do not re-add you |
| Account data | For the life of the subscription; deleted or returned within 30 days of termination unless your contract says otherwise |
| Tenant content | Per the customer's instructions and their own retention policy; export available on request before deletion |
| Audit logs | Retained for the contracted period, because regulated customers rely on them for reconstruction |
| Invoices and tax records | As required by Indian tax and company law |
06 · Security
How we protect it
Mithavo applies role-based access control, tenant isolation, encryption of data in transit over TLS, encryption at rest for the managed database and object storage, least-privilege administrative access, and an immutable audit trail of record changes and approvals within the platform.
These are the controls we operate today. They are not, and should not be read as, an independent certification or audit outcome. If your procurement process requires certification evidence, a penetration-test summary, or a completed security questionnaire, write to security@mithavo.com and we will tell you exactly what we can and cannot supply at this stage.
07 · Rights
Your rights, and how to use them
Under the Digital Personal Data Protection Act, 2023, you may request access to a summary of the personal data we hold about you and how it is processed; correction, completion or updating of inaccurate data; erasure where the purpose is served and no legal duty requires retention; nomination of another person to exercise your rights in the event of death or incapacity; and grievance redressal.
You may withdraw consent at any time. Withdrawal does not affect processing already carried out, and it may mean we can no longer provide a service that depends on that data.
To make a request: email privacy@mithavo.com from the address you gave us, stating what you want. We acknowledge within 7 working days and respond within 30 days. If we need to verify your identity we will ask for the minimum necessary — we will never ask for a password.
Grievance officer. If you are not satisfied with our response, escalate to the Grievance Officer at grievance@mithavo.com. You retain the right to complain to the Data Protection Board of India.
09 · Contact
Privacy contact and how we handle your request
Every privacy matter has a named route. Use the inbox that matches your issue — it reaches a person, not a ticket queue that no one reads.
Privacy Office
Access, correction, erasure, consent withdrawal, and any question about this policy.
Grievance Officer
Unresolved or unsatisfactory responses, under the DPDP Act, 2023. You may also complain to the Data Protection Board of India.
Security & incidents
Vulnerability reports, suspected breaches, and security questionnaires.
Registered address
Mithavo Technologies Pvt. Ltd.
Attn: Privacy Office, India
Written requests are accepted, but email is faster and easier to verify.
Our data-handling procedure
- You submit a request — through the form below or by email from the address on record. Tell us what you want: a summary of your data, a correction, erasure, or withdrawal of consent.
- We acknowledge within 7 working days with a reference number and, where needed, the minimum information required to verify your identity. We will never ask for a password.
- We locate the data across our systems, and identify whether we hold it as a data fiduciary or as a processor for a customer's tenant. If it is tenant data, we route your request to that customer and tell you who they are.
- We act and respond within 30 days of a verified request. If a legal or tax duty requires us to retain part of the data, we say which part and why.
- You can escalate to the Grievance Officer, and thereafter to the Data Protection Board of India, if the outcome is not satisfactory.
10 · Requests
Submit a data subject request
This form reaches our privacy endpoint and is handled under the procedure in section 09 and the terms of this Privacy Policy. Send only what is needed to identify you — do not include passwords, health data or government identifiers.
11 · Changes
Changes to this policy
We update this policy when our processing changes. Material changes are announced to account administrators by email and reflected in the effective date below. Continued use after the effective date means the updated policy applies.
Mithavo Technologies Pvt. Ltd.
Privacy: privacy@mithavo.com
Security: security@mithavo.com
Grievance Officer: grievance@mithavo.com
Effective date: 1 January 2026. This page is maintained by Mithavo and describes our own practices; it is not legal advice and is not an independent certification.
Procurement asking harder questions?
We will walk your IT and legal teams through data flows, hosting, sub-processors and the DPA in a single call.