Draft — requires legal review before publication. Drafted to reflect how the product actually handles data and to cover DPDP Act 2023 obligations. Not a substitute for legal review.
1. Who we are
Aesoni operates AesoniONE FranchiseOS. For data you enter about your own business and customers, you are the Data Fiduciary and we act as a Data Processor on your instructions.
2. What we collect
From you as a customer: business name and address, contact details of the people who use the service, billing information, and support correspondence.
From your use of the service: the business data you enter — branches, staff, menu, stock, sales, customers — plus technical logs (IP address, device and browser, timestamps, error diagnostics).
From visitors to this website: anonymised usage analytics.
3. Why we use it
- To provide and operate the service
- To bill you
- To provide support
- To diagnose faults and improve reliability
- To meet legal and tax obligations
We do not sell your data and do not use your business data to advertise to you or anyone else.
4. Your customers’ data
Where you record your customers’ details (for example a phone number for a bill), that data belongs to you. We hold and process it only to run the service for you. You are responsible for having a lawful basis to collect it and for telling those individuals what you do with it.
5. Sharing
We share data only with service providers necessary to run the service — hosting, error monitoring, payment processing, and messaging where you have enabled it — and where required by law.
6. Where data is stored
Data is stored on cloud infrastructure. Some providers may process data outside India; where they do, we take steps to ensure appropriate protection.
7. Retention
We keep your data while your subscription is active. After cancellation it is available for export for 30 days, then permanently deleted. Some records may be retained longer where law requires.
8. Security
Data is encrypted in transit and at rest. Access is role-based, so people in your organisation see only what their role permits. We log administrative access to production systems.
No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Board as required by the DPDP Act 2023.
9. Your rights
Under the DPDP Act 2023 you may request access to your personal data, ask for corrections, request erasure, and raise a grievance.
To exercise any of these, email admin@aesoni.in.
10. Grievance officer
11. Changes
We will update this page when our practices change, and note the date at the top.