This Privacy Policy explains how Sompalli & Co Technologies ("we", "us", "Provider") handles personal and organisational information in connection with the Fixed Asset Register application at www.fixedassetregister.in, our marketing website, contact forms, demos and related support channels. By using the Service or submitting information to us, you acknowledge this Policy. Our Terms & Conditions (including NDA provisions) also apply.
1. Who we are
Fixed Asset Register is operated by Sompalli & Co Technologies, India. For privacy queries, contact us using the details in Section 15.
2. Scope of this Policy
This Policy covers:
- Visitors to our public website (landing, insights, contact, about, legal pages);
- Prospective customers who request demos or contact us;
- Registered account administrators and Authorized Users of the Fixed Asset Register Service;
- Information processed when we provide support, billing, or implementation assistance.
It does not replace your organisation’s own privacy notices to employees or third parties regarding asset, custodian or employee data you upload into the Service — see Section 13.
3. Data we collect
3.1 Account and billing data
- Name, email, phone, company name, designation;
- Login credentials (passwords stored using industry-standard hashing — we do not store plaintext passwords);
- Subscription plan, invoices, payment status and payment gateway references (card data is handled by the payment partner; we do not store full card numbers);
- Role, branch and permission settings within your organisation’s tenant.
3.2 Client Data you upload (organisation content)
- Fixed asset masters, depreciation parameters, locations, transfers, disposals;
- Custodian / assignee names and related operational fields you choose to store;
- Documents, images, QR verification evidence and audit logs generated in the Service;
- Optional endpoint-agent hardware telemetry linked to assets (e.g. hostname, IP, hardware specs) when you enable that feature.
3.3 Website and technical data
- IP address, browser type, device type, approximate region;
- Pages visited, referrer, and cookie consent choices;
- Server logs for security, diagnostics and abuse prevention;
- Communications you send via contact forms, email or WhatsApp.
4. How we use data
- Provide, secure, maintain and improve the Service;
- Authenticate users, enforce access controls and prevent fraud or abuse;
- Process subscriptions, invoices and customer support;
- Send service notices (security, downtime, material Terms/Privacy updates);
- Respond to demos, sales and support requests;
- Produce aggregated, anonymised product analytics that do not identify your organisation;
- Comply with legal obligations and enforce our Terms.
We do not sell personal data or Client Data.
5. Legal bases (where applicable)
Depending on your relationship with us and applicable Indian law (including the Digital Personal Data Protection Act, 2023, when and as applicable), we process data based on:
- Contract — to provide the Service you subscribe to;
- Consent — for optional cookies/marketing preferences and certain communications;
- Legitimate use / legitimate interests — security, product improvement, fraud prevention, and responding to business enquiries, balanced against your rights;
- Legal obligation — tax, accounting, and lawful requests from authorities.
6. Sharing and processors
We may share information with:
- Infrastructure providers — cloud hosting, databases, file storage and CDN;
- Communication providers — transactional email / SMS / WhatsApp gateways;
- Payment processors — e.g. Razorpay for subscription payments;
- Professional advisors — auditors, lawyers, accountants under confidentiality;
- Authorities — when required by law or to protect rights, safety and security.
Processors are engaged under contractual terms requiring appropriate confidentiality and security. We do not permit them to use Client Data for their own marketing.
7. Retention
- Active accounts — Client Data retained while the subscription/account remains active;
- After termination — we delete or anonymise Client Data within a reasonable period, subject to legal retention and backup cycles (typically up to 30–90 days for disaster-recovery copies);
- Billing & support records — retained as required for tax, accounting and dispute resolution;
- Cookie consents — stored for compliance evidence as described in our cookie notice;
- Marketing contacts — until you ask us to stop or the enquiry is closed.
Export your data before account closure where export features are available.
8. Security
We use reasonable technical and organisational measures, including access controls, encrypted transport (HTTPS), password hashing, logical tenant isolation, and monitoring for suspicious activity. No method of transmission or storage is 100% secure. You must protect account credentials and configure roles appropriately.
9. Cookies and similar technologies
Our public website uses essential cookies and, with your consent, optional analytics/marketing cookies. Details and controls are described in the Cookie notice and via Cookie settings. The application may also use session cookies or local storage required to keep you signed in and secure.
10. Your rights
Subject to applicable law, you may request to:
- Access personal data we hold about you as a website visitor or account contact;
- Correct inaccurate personal data;
- Withdraw consent for optional cookies or marketing communications;
- Request deletion of personal data where we are the controller and retention is not required by law;
- Raise a grievance with us using the contact details below.
If you are an Authorized User of a customer organisation, many requests (e.g. correcting custodian names inside the FAR) should be directed to your organisation’s administrator — they control Client Data in the tenant.
11. Children
The Service is intended for business and professional use. We do not knowingly collect personal data from children under 18 for the purpose of providing the Service. If you believe we have received such data, contact us to delete it.
12. International transfers
Primary operations and hosting are intended for customers in India. If processors or backups involve facilities outside India, we take steps consistent with applicable law and our security standards. Enterprise customers with data-residency requirements may discuss private-cloud or on-premises options under a separate agreement.
13. When your organisation is the controller
For Client Data uploaded into Fixed Asset Register (assets, employees/custodians, documents, verification photos, etc.), your organisation typically acts as the data controller / data fiduciary, and we act as a processor / data processor providing the SaaS platform. You are responsible for:
- Having a lawful basis to upload personal data of employees, contractors or third parties;
- Informing those individuals as required by your policies and applicable law;
- Configuring access roles and retention inside your account appropriately;
- Responding to data subject requests relating to Client Data (we will reasonably assist where contractually agreed).
14. Changes to this Policy
We may update this Privacy Policy by posting a new version on this page with a revised “Last updated” date. Material changes may also be notified by email or in-app notice. Continued use after the effective date constitutes acceptance where permitted by law.
15. Contact
For privacy questions, requests or grievances:
- Sompalli & Co Technologies
- Email: praveen@sompalliandco.com
- Phone: +91 8686018476
- Website: www.fixedassetregister.in
- Related: Terms & Conditions
This Privacy Policy is provided for transparency regarding Fixed Asset Register and related websites. It does not constitute legal advice. Organisations with complex compliance needs should obtain independent legal review.