Legal
Privacy Policy
What personal data MANUPRIME collects, why we hold it, who we share it with, how long we keep it, and the rights you have over it.
Effective 3 September 2026
In short
We collect only the personal data we need to sell, deliver and support the software. We do not sell it, we do not use your workspace contents for anything but running your workspace, and you can ask us to show, correct, export or delete your data at any time.
This summary is for orientation only. The full text below is what applies.
1. Who we are
MANUPRIME is manufacturing ERP software operated by AnantaTech Hub Private Limited ("MANUPRIME", "we", "us", "our"), a company incorporated in India (CIN U62099GJ2025PTC164561) with its registered office at 202, Avadh Shopping Center, Baben, Bardoli – 394601, Dist. Surat, Gujarat, India.
For personal data processed through the MANUPRIME website and marketing activities, we are the data controller (in Indian terms, the Data Fiduciary).
For personal data that a customer loads into their MANUPRIME workspace — their employees, their customers, their suppliers — the customer is the controller and we act as a processor (Data Processor) on their instructions, under the agreement between us. This policy describes what we do as controller; what we do as processor is governed by that agreement and summarised in section 3.
2. Personal data we collect
We collect only what we need. The categories differ depending on how you interact with us.
| Category | What it includes, and where it comes from |
|---|---|
| Enquiry and demo data | Name, company, phone, email, industry and plant count, provided by you on a form, by email, by phone or on WhatsApp. |
| Account data | Names, work email addresses, roles and login records of the people your organisation authorises to use MANUPRIME. |
| Customer Data | Whatever your organisation enters into its workspace — which may include employee, customer and supplier records. We do not choose this content and we do not use it for our own purposes. |
| Billing data | Company name, GSTIN, billing address, invoices and payment references. Card and payment-instrument details are handled directly by our payment processor, Razorpay; we never see or store them. |
| Support data | Correspondence, tickets, and — with your agreement — screenshots or diagnostic exports you send us. |
| Technical data | IP address, browser and device type, pages viewed and referring URL. Where you have accepted analytics cookies this is collected by Google Analytics with your IP anonymised; where you have not, it is not collected at all beyond ordinary server logs. |
3. Why we use personal data, and our legal basis
We process personal data for the purposes below. Where the GDPR or UK GDPR applies, the legal basis is named; where the Digital Personal Data Protection Act, 2023 applies, we rely on your consent or on a legitimate use as that Act defines it.
| Purpose | Basis |
|---|---|
| Responding to an enquiry or arranging a demo | Steps taken at your request before entering a contract; consent where you asked to be contacted. |
| Providing the software, support and onboarding | Performance of the contract with your organisation. |
| Hosting and processing Customer Data | On the documented instructions of the customer, as processor. |
| Billing, tax records and statutory accounting | Legal obligation under Indian tax and company law. |
| Securing the service, preventing abuse, keeping audit trails | Legitimate interests in protecting our customers and our systems. |
| Product improvement using aggregated, non-identifying usage data | Legitimate interests. This never uses the contents of a customer workspace. |
| Sending product or marketing messages you asked for | Consent, withdrawable at any time. |
4. What we do not do
- We do not sell personal data, and we never have.
- We do not share Customer Data with other customers, and we do not pool it.
- We do not use the contents of a customer workspace to train models — ours or any third party’s — or to build features for anyone else. Where an AI feature sends data to a provider, it is sent to answer that request and under terms that exclude training on it.
- We do not run advertising networks or third-party ad tracking on this website.
5. Consent, and how to withdraw it
Where we rely on your consent, you can withdraw it at any time — by using the unsubscribe link in any message, or by writing to us at the address in section 12. Withdrawal takes effect going forward and does not make earlier processing unlawful.
Withdrawing consent to marketing does not affect messages we must send about your service — invoices, security notices, and changes to these terms.
7. Data storage, residency and international transfers
Customer Data is stored in the region the customer belongs to — Indian customers in India, European customers in the EU, and so on for any market we enter. We are selling into the Indian market today, and every deployment currently runs on cloud infrastructure in India. If you need your data in a specific jurisdiction, name it in the agreement and we will confirm the region before anything is provisioned rather than after. Some of the providers named in section 6 operate outside India, and limited personal data (support correspondence, billing records, message delivery metadata) may be processed in those countries.
Where personal data leaves the UK or the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (or the UK International Data Transfer Addendum) together with an assessment of the destination, unless an adequacy decision applies. Where the Digital Personal Data Protection Act, 2023 restricts a destination, we do not transfer there.
A customer on a dedicated or on-premise deployment can require that their workspace stays within a named jurisdiction; we confirm that in the agreement.
8. How long we keep personal data
| Data | Retention |
|---|---|
| Enquiry data where no contract follows | Up to 24 months from last contact, then deleted. |
| Customer Data | For the life of the subscription. On termination, see the Account Deletion Policy — active systems within 30 days of a confirmed request, backups within a further 90 days. |
| Invoices, tax and statutory accounting records | Eight years, as Indian tax and company law requires. |
| Audit trails inside the product | Per the customer’s plan — one year on Starter, three on Growth, seven on Enterprise, and to the customer’s own policy on Dedicated. |
| Customer correspondence | For the term of the agreement, then eight years, to meet the same Indian tax and company-law record-keeping requirements as the records above. |
| Analytics data, where you accepted it | Fourteen months, set on the Google Analytics property. Declining means there is nothing to retain. |
9. Your rights
Subject to the law that applies to you, you have the rights below. Exercising them is free, and we will not treat you differently for doing so.
- Access — to be told what personal data we hold about you and to receive a copy.
- Correction — to have inaccurate or incomplete data corrected.
- Erasure — to have data deleted where we no longer have a basis to keep it.
- Portability — to receive data you gave us in a structured, machine-readable format.
- Restriction and objection — to limit or object to certain processing, including profiling.
- Withdrawal of consent — at any time, as described in section 5.
- Nomination — under the Digital Personal Data Protection Act, 2023, to nominate someone to exercise your rights in the event of death or incapacity.
- Non-discrimination — under the California Consumer Privacy Act, not to be discriminated against for exercising a right. We do not sell or share personal information as those terms are defined there.
- Complaint — to a supervisory authority, or to the Data Protection Board of India.
10. Making a request
Write to contact@anantatechhub.com with enough detail to identify the data you mean. We respond within 30 days; if a request is complex we will tell you why and when to expect a full answer.
Where you are an employee, customer or supplier of one of our customers, the data about you sits in their workspace and they control it. Send your request to them; if it reaches us we will pass it on and tell you we have done so.
We may ask for enough information to verify who you are. We ask for the minimum that makes verification meaningful, and we do not use it for anything else.
11. How we protect personal data
No system is perfectly secure, and we do not claim otherwise. What we commit to is a defined standard of care and honest, prompt disclosure when something goes wrong.
If a personal data breach occurs that is likely to affect you, we will notify the Data Protection Board of India and every affected person as the Digital Personal Data Protection Act requires, and any other regulator the law requires, without undue delay. Where an incident falls within the CERT-In Directions of 28 April 2022, we report it to CERT-In within the six hours those Directions specify. Where the GDPR applies to a transfer, we also meet its 72-hour notification requirement.
- Data in transit is encrypted using TLS, on every connection to the app, the API and the shop-floor entry screens.
- Role-based access control inside the product, and access to production systems limited to the people whose role requires it and removed when that role ends.
- Credentials and API tokens are held server-side and are never exposed to a browser.
- Passwords, where we hold them, are stored only as salted hashes and never in a readable form.
- Audit logging of access to production systems.
- Segregation of each customer workspace; a dedicated instance is separated at the database level.
- Systems are patched, and backups are taken and access-controlled to the same standard as the live data.
- Confidentiality obligations on every employee and contractor.
12. Children
MANUPRIME is business software and is not directed at children. We do not knowingly collect personal data of anyone under 18. If you believe a child’s data has reached us, tell us and we will delete it.
14. Grievance Officer and data protection contact
Indian law requires us to publish who handles complaints about personal data. Those details are below and are not hidden behind a form.
| Contact point | Details |
|---|---|
| Name | Amit Parekh |
| Designation | Grievance Officer |
| Company | AnantaTech Hub Private Limited |
| contact@anantatechhub.com | |
| Telephone | +91 97376 99595 |
| Post | 202, Avadh Shopping Center, Baben, Bardoli – 394601, Dist. Surat, Gujarat, India |
| Response | Acknowledged within 24 hours, resolved within 15 days |
15. Changes to this policy
We update this policy when what we do changes. The effective date at the top always reflects the current version. Where a change materially affects your rights we will tell customers directly rather than relying on you noticing the date.
Written with reference to
- Digital Personal Data Protection Act, 2023 (India)
- Information Technology Act, 2000 and the SPDI Rules, 2011 (India)
- General Data Protection Regulation (EU) 2016/679, and the UK GDPR
- California Consumer Privacy Act, as amended by the CPRA
- ISO/IEC 27001 and ISO/IEC 27701 as the framework for our security and privacy controls
Questions about this policy can be sent tocontact@anantatechhub.com, or raised with our Grievance Officer under theGrievance Redressal Policy.