Privacy Policy
1. ABOUT THIS POLICY
Phoenix Innovations LLC (“we,” “us,” or “our”) is committed to protecting the privacy and security of personal data processed in connection with TruWipe™. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have.
This Policy should be read alongside the End User License Agreement (EULA) and the Software License Agreement. In case of conflict, data protection law shall prevail.
2. WHO WE ARE
2.1 Data Controller / Data Fiduciary
For personal data collected directly from Licensee organizations and their Authorized Users:
- Phoenix Innovations LLC acts as a Data Controller/Data Fiduciary for data collected in connection with account management, licensing, and support.
- Licensees act as Data Controllers/Data Fiduciaries for personal data their employees process through the Software itself.
2.2 Data Protection Contact
For all privacy-related enquiries, requests, or complaints, please contact:
Data Protection Officer, Phoenix Innovations LLC
Email: dpo@phoenixinnovations.com
Postal Address: [Registered Address], Austin, Texas, USA
For EU/EEA Users – EU Representative: [EU Representative Name and Address]
For India Users – Grievance Officer: grievance@phoenixinnovations.com (Response within 48 hours as required by DPDP Act)
3. WHAT PERSONAL DATA WE COLLECT
3.1 Data We Collect Directly
Account & Licensing Data: Name, job title, business email address, company name, billing information, and license key details collected when Licensees register for or purchase TruWipe™.
Support & Communications Data: Communications you send us, including support tickets, feedback, and correspondence — may contain personal data you choose to include.
Technical & Usage Data: Device identifiers, IP addresses, software version, license status, crash logs, and usage telemetry collected for licensing verification and product improvement.
3.2 Data We Do Not Collect or Use
TruWipe™ is designed to operate on-premises on Licensee-controlled infrastructure. Consistent with The Phoenix Group’s overarching privacy practices, we do not:
- Use any tracking technologies to collect information from users of the Software;
- Collect the content of files processed by the Software;
- Collect Sensitive Personal Data (as defined under the DPDP Act) or Special Categories of Data (under GDPR) without explicit consent and a documented lawful basis;
- Sell personal data to third parties for commercial purposes.
We use information that you provide to us, including any personal information, to provide you with information on our products or services that you request from us, or to fulfill any other purpose for which you provide it.
4. LEGAL BASIS FOR PROCESSING
We rely on the following lawful bases under GDPR (Article 6) and the DPDP Act (Section 4):
- Contract Performance: Processing necessary to fulfill the Software License Agreement, provide support, and manage your account.
- Legitimate Interests: Security monitoring, fraud prevention, product improvement, and internal analytics — subject to a legitimate interest assessment confirming individual rights are not overridden.
- Legal Obligation: Compliance with applicable laws (tax, export control, regulatory requirements).
- Consent: Where required by law (e.g., non-essential cookies or marketing communications). You may withdraw consent at any time without affecting the lawfulness of prior processing.
- DPDP Act — Consent or Legitimate Use: Processing of Digital Personal Data in India is based on free, specific, informed, and unconditional consent of the Data Principal, or a legitimate use as enumerated under Section 7 of the DPDP Act.
5. HOW WE USE YOUR PERSONAL DATA
We use personal data for the following purposes:
- License provisioning, activation, and management;
- Providing technical support and responding to enquiries;
- Security monitoring, threat detection, and audit logging;
- Product improvement, bug fixing, and feature development (using anonymized/aggregated data where possible);
- Billing, invoicing, and financial record-keeping;
- Compliance with legal, regulatory, and contractual obligations;
- Communicating important product and legal updates (with the ability to opt out of marketing).
6. DATA SHARING AND DISCLOSURE
6.1 Third Parties
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction. We may disclose personal information that we collect or you provide as described in this Privacy Policy to:
- Subsidiaries and Affiliates: Phoenix Innovations LLC is part of The Phoenix Group (phoenix.tech). Personal data may be shared with other entities within The Phoenix Group to deliver and support the Software, subject to equivalent data protection standards.
- Service Providers / Sub-Processors: Cloud hosting, payment processing, CRM, and analytics providers, bound by data processing agreements consistent with GDPR and the DPDP Act.
- Legal & Regulatory Authorities: Where required by applicable law, court order, or regulatory request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets — subject to confidentiality obligations and notification to affected parties.
6.2 International Transfers
Personal data processed by Phoenix Innovations LLC may be transferred to, and processed in, countries outside the EU/EEA or India. We ensure such transfers comply with:
- GDPR Chapter V — including Standard Contractual Clauses (SCCs) or adequacy decisions;
- DPDP Act Section 16 — transfers only to countries/territories approved or not restricted by the Central Government of India;
- Applicable US state data protection laws.
A full list of our sub-processors and the safeguards applicable to international transfers is available on request at dpo@phoenixinnovations.com.
7. DATA RETENTION
We retain personal data only as long as necessary for the purposes described in this Policy or as required by law:
- Account & Licensing Data: Duration of the Software License Agreement plus 7 years (to meet tax and audit requirements).
- Support Records: 3 years from date of last interaction, or as required by applicable law.
- Technical/Usage Logs: 90 days for operational logs; up to 12 months for security audit trails.
Upon expiry of the retention period, data is securely deleted or anonymized in accordance with our data destruction standards.
8. YOUR RIGHTS
8.1 Rights Under GDPR (EU/EEA Data Subjects)
Under GDPR Articles 15–22, you have the following rights:
- Right to access your personal data;
- Right to rectification of inaccurate data;
- Right to erasure (“right to be forgotten”) in applicable circumstances;
- Right to restriction of processing;
Right to data portability in a structured, machine-readable format;
Right to object to processing based on legitimate interests or direct marketing;
Rights related to automated decision-making and profiling.
To exercise any of these rights, submit a request to dpo@phoenixinnovations.com. We will respond within 30 days (extendable to 90 days for complex requests). You also have the right to lodge a complaint with your national supervisory authority.
8.2 Rights Under the DPDP Act (India — Data Principals)
Under the DPDP Act 2023, you have the following rights:
- Right to access information about your personal data and processing (Section 11);
- Right to correction and erasure of inaccurate, incomplete, or outdated data (Section 12);
- Right to grievance redressal through our Grievance Officer within 48 hours of acknowledgement (Section 13);
- Right to nominate another individual to exercise rights on your behalf (Section 14);
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing (Section 6).
To exercise DPDP Act rights, contact: grievance@phoenixinnovations.com. Complaints unresolved within the stipulated period may be escalated to the Data Protection Board of India.
9. SECURITY
We work hard to safeguard your data using a range of technological and organizational security controls. We implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:
- Maintaining and protecting the security of computer storage and network equipment;
- Security procedures that require employees to authenticate themselves to access sensitive data;
- Limiting access to personal information only to those with jobs requiring such access;
- Requiring callers and online users to authenticate themselves before we provide account information;
- Encryption at rest and in transit (TLS 1.3 / AES-256);
Role-based access controls and multi-factor authentication;
Regular vulnerability assessments and penetration testing;
Incident response and breach notification procedures consistent with GDPR (72-hour notification to supervisory authority) and the DPDP Act (mandatory notification to the Data Protection Board).
Unfortunately, the transmission of information via the internet is not completely secure. We cannot guarantee that your information will never be disclosed in a manner inconsistent with this Policy. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk.
10. TRACKING TECHNOLOGIES AND DO NOT TRACK
Consistent with The Phoenix Group’s practices, we do not use any tracking technologies to collect information through TruWipe™ Software.
10.1 Website and Portal
If you access our licensing portal or support website, those platforms may use session-based technical cookies strictly necessary for authentication and functionality. We do not use advertising, analytics, or behavioral tracking cookies on Software-related platforms.
10.2 Do Not Track
The TruWipe™ application does not support “Do Not Track” (DNT) requests. As we do not use tracking technologies, the presence or absence of a DNT signal does not affect how the Software operates or how we process data.
11. CHILDREN'S DATA
TruWipe™ is an enterprise B2B software product not directed to individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from children. In India, processing of children’s personal data is subject to the additional requirements of Section 9 of the DPDP Act, including verifiable parental consent.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect changes in law, regulation, or our practices. Material changes will be communicated via:
- Email to the Licensee’s designated contact;
- Notice within the Software or licensing portal;
- Updated version published on our website with a revised effective date.
Continued use of the Software after the effective date of an updated Policy constitutes acceptance of the revised terms, to the extent permitted by applicable law.
13. CONTACT US
For any privacy-related questions, requests, or concerns:
- General Privacy: privacy@phoenixinnovations.com
- Data Protection Officer (GDPR): dpo@phoenixinnovations.com
- Grievance Officer (DPDP Act, India): grievance@phoenixinnovations.com | Response within 48 hours
- Postal: Phoenix Innovations LLC, Legal / Privacy, [Registered Address], Austin, Texas, USA