Privacy Policy

BoothCRM – Privacy Policy

1. Introduction and Scope

Omnexa Solutions Pvt. Ltd. (“Omnexa”, “BoothCRM”, “we”, “us”, or “our”) respects the privacy of individuals and is committed to protecting Personal Data entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, retain, and otherwise process Personal Data in connection with the BoothCRM platform, our websites, applications, products, services, and related interactions (collectively, the “Services”).

This Privacy Policy applies to:

(a) individuals who visit or interact with our websites;

(b) individuals who create, administer, access, or use BoothCRM Accounts on behalf of our business customers;

(c) individuals who communicate with us regarding sales inquiries, support requests, billing matters, or other business-related interactions; and

(d) individuals whose Personal Data is processed by BoothCRM in connection with the provision of the Services to our business customers, to the extent applicable under relevant data protection laws.

BoothCRM is a business-to-business (B2B) software platform designed to assist organizations in managing leads, customer relationships, event interactions, sales activities, and related business processes. In many cases, BoothCRM processes Personal Data solely on behalf of and under the instructions of its customers.

Where BoothCRM processes Personal Data that is submitted, uploaded, stored, or otherwise provided by a customer through the Services (“Customer Data”), the relevant customer remains responsible for ensuring that such Personal Data has been collected and processed in accordance with applicable laws, including obtaining any necessary notices, consents, permissions, or other lawful bases required under such laws.

This Privacy Policy does not apply to:

(i) third-party websites, products, applications, or services that may be linked to or integrated with the Services;

(ii) Personal Data processed by our customers outside of BoothCRM ; or

(iii) information processed by third parties acting independently of BoothCRM and not under our control.

Our collection and use of Personal Data relating to our customers and users are governed by this Privacy Policy. The processing of Customer Data through the Services is also subject to our Terms and Conditions and any applicable agreements entered into between Omnexa Solutions Pvt. Ltd. and its customers.

By accessing or using the Services, interacting with BoothCRM, or otherwise providing information to us, you acknowledge that you have read and understood this Privacy Policy.

If you do not agree with this Privacy Policy, you should refrain from using the Services or providing Personal Data to us.

2. Information We Collect

Depending on how you interact with BoothCRM and the Services, we may collect the following categories of information:

2.1 Information You Provide Directly to Us

We may collect information that you voluntarily provide when you create an Account, subscribe to the Services, request a demonstration, communicate with us, seek support, purchase Services, or otherwise interact with BoothCRM.

Such information may include:

(a) name;

(b) business name and business contact details;

(c) job title or designation;

(d) email address;

(e) telephone number;

(f) billing and invoicing information;

(g) account credentials and authentication information;

(h) communication preferences;

(i) information provided in support requests, surveys, feedback submissions, or correspondence with BoothCRM; and

(j) any other information that you choose to provide to us.

2.2 Information Collected Automatically

When you access or use the Services, we may automatically collect certain technical and usage-related information necessary for the operation, security, administration, and improvement of the Services.

Such information may include:

(a) IP addresses;

(b) browser type and version;

(c) operating system information;

(d) device identifiers;

(e) date and time of access;

(f) pages viewed and features utilized;

(g) login activity and authentication events;

(h) system activity logs and diagnostic information;

(i) error reports and crash information; and

(j) information collected through cookies and similar technologies, as further described in this Privacy Policy.

2.3 Customer Data Processed Through the Services

Our customers may upload, submit, store, organize, analyze, or otherwise process information through BoothCRM in connection with their use of the Services.

Such information may include Personal Data relating to their employees, customers, prospects, exhibition attendees, business contacts, vendors, partners, or other individuals.

The nature of such Customer Data is determined solely by our customers and may vary depending upon how they use the Services.

BoothCRM processes Customer Data on behalf of and under the instructions of its customers for the purpose of providing the Services.

BoothCRM does not independently determine the purposes for which Customer Data is collected by its customers.

2.4 Information Obtained from Third Parties

We may receive information relating to individuals from third-party sources, including:

(a) payment processors;

(b) authentication providers;

(c) business partners and referral sources;

(d) customer-authorized integrations;

(e) publicly available business sources; and

(f) service providers assisting in the delivery of the Services.

Any such information shall be processed in accordance with this Privacy Policy and applicable laws.

2.5 AI-Related Inputs and Outputs

Where customers utilize AI-enabled functionalities made available through the Services, BoothCRM may process prompts, instructions, Customer Data submitted for analysis, and AI-generated outputs solely for the purpose of providing the requested functionality and supporting the operation of such features.

AI-related processing may be facilitated using third-party service providers engaged by BoothCRM in accordance with applicable contractual and legal safeguards.

BoothCRM does not use Customer Data submitted through AI-enabled functionalities to independently market to individuals or to build customer profiles unrelated to the provision of the Services.

2.6 Information We Do Not Intentionally Collect

BoothCRM does not intentionally collect Personal Data directly from children or individuals below the age required to provide legally valid consent under applicable laws.

The Services are designed and intended solely for use by businesses and authorized users acting on behalf of businesses.

If we become aware that Personal Data has been collected in violation of applicable laws, we may take appropriate steps to delete such information or otherwise address the matter in accordance with applicable legal requirements.

3. How We Use Information

BoothCRM uses Personal Data and other information collected in connection with the Services for the following purposes:

3.1 Provision and Administration of the Services

We may use information to:

(a) establish, maintain, administer, and secure Accounts;

(b) provide access to the Services and make functionalities available to authorized users;

(c) authenticate users and manage permissions and access controls;

(d) facilitate customer onboarding and implementation activities; and

(e) otherwise provide, operate, maintain, and support the Services.

3.2 Customer Support and Communications

We may use information to:

(a) respond to inquiries, requests, and support tickets;

(b) troubleshoot technical issues and investigate reported problems;

(c) communicate regarding updates, service-related notices, billing matters, and administrative information;

(d) conduct customer satisfaction surveys and collect feedback relating to the Services; and

(e) provide assistance in connection with the use of the Services.

3.3 Billing and Commercial Administration

We may use information to:

(a) process subscriptions and purchases;

(b) generate invoices and maintain billing records;

(c) process payments and manage payment-related activities;

(d) administer AI Credit purchases and usage-based offerings; and

(e) collect outstanding amounts and enforce our commercial rights.

3.4 Security, Fraud Prevention, and Service Protection

We may use information to:

(a) detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, security incidents, or violations of our Terms and Conditions;

(b) monitor the integrity, security, and performance of the Services;

(c) conduct audits, investigations, and compliance verification activities where reasonably necessary;

(d) maintain logs and records relating to access, authentication, and system activity; and

(e) protect the rights, property, safety, and legitimate interests of BoothCRM, our customers, users, and other third parties.

3.5 Service Improvement and Analytics

We may use information to:

(a) analyze usage trends and customer interactions with the Services;

(b) improve the functionality, reliability, usability, and performance of the Services;

(c) develop reports, statistics, and insights using aggregated or de-identified information that does not reasonably identify any individual; and

(d) evaluate and enhance customer support, operational processes, and service delivery.

3.6 Compliance with Legal Obligations

We may use information to:

(a) comply with applicable laws, regulations, legal processes, governmental requests, and regulatory requirements;

(b) establish, exercise, or defend legal claims;

(c) enforce our Terms and Conditions and other contractual arrangements; and

(d) maintain records required under applicable laws.

3.7 AI-Enabled Functionalities

Where customers utilize AI-enabled functionalities made available through the Services, BoothCRM may process prompts, instructions, Customer Data submitted for analysis, and AI-generated outputs solely for the purpose of providing the requested AI functionality.

BoothCRM may engage third-party service providers to facilitate the operation of AI-enabled functionalities, subject to appropriate contractual and operational safeguards.

BoothCRM does not use Customer Data submitted through AI-enabled functionalities to train, fine-tune, or improve BoothCRM’s own artificial intelligence models or the general-purpose artificial intelligence models of third parties.

AI-generated outputs are intended to assist customers in their business processes. Customers remain solely responsible for independently reviewing, validating, and determining the appropriateness of any AI-generated outputs before relying upon or acting upon them.

3.8 Customer Data Processed on Behalf of Customers

Where BoothCRM processes Customer Data on behalf of customers, such processing is carried out solely for the purpose of providing the Services in accordance with the customer’s instructions, applicable agreements, and applicable laws.

BoothCRM does not independently determine the purposes for which Customer Data is collected by customers using the Services.

3.9 Business Communications

We may use contact information to communicate with customers and prospective customers regarding:

(a) service-related announcements;

(b) account administration matters;

(c) billing and payment communications;

(d) updates relating to the Services;

(e) security notices and legal disclosures; and

(f) information relating to products or services offered by BoothCRM where permitted under applicable law or where appropriate consent has been obtained.

Where required by applicable law, individuals may opt out of receiving promotional communications from BoothCRM by following the instructions provided in such communications or by contacting us using the details set forth in this Privacy Policy.

4. Legal Bases for Processing (Where Applicable)

Depending on the circumstances in which Personal Data is collected and processed, BoothCRM may rely on one or more of the following legal bases or lawful grounds for processing, to the extent recognized under applicable laws:

4.1 Performance of a Contract

We may process Personal Data where such processing is necessary to:

(a) provide, operate, maintain, and support the Services;

(b) establish and administer customer Accounts;

(c) fulfill our obligations under our Terms and Conditions, Subscription Plans, statements of work, invoices, or other contractual arrangements;

(d) process transactions and manage billing activities; and

(e) deliver products, services, features, or functionalities requested by customers.

4.2 Compliance with Legal Obligations

We may process Personal Data where necessary to comply with applicable laws, regulations, court orders, governmental directives, lawful requests from competent authorities, tax obligations, accounting requirements, or other legal responsibilities imposed upon BoothCRM.

4.3 Legitimate Business Interests

To the extent permitted under applicable laws, we may process Personal Data where such processing is reasonably necessary for our legitimate business interests, including:

(a) improving, maintaining, and securing the Services;

(b) preventing fraud, abuse, unauthorized access, and other harmful activities;

(c) administering customer relationships and responding to inquiries;

(d) conducting internal reporting, business planning, and operational analysis;

(e) protecting the rights, property, safety, and legitimate interests of BoothCRM, our customers, users, and third parties; and

(f) enforcing our contractual rights and resolving disputes.

Where required by applicable law, we shall ensure that such legitimate interests are appropriately balanced against the rights and interests of affected individuals.

4.4 Consent

We may process Personal Data on the basis of consent where consent is required under applicable laws or where we otherwise choose to rely upon consent.

Where processing is based upon consent:

(a) consent may be withdrawn at any time, subject to applicable legal or contractual restrictions; and

(b) the withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.

Withdrawal of consent may affect our ability to provide certain Services or functionalities where such processing is necessary for their operation.

4.5 Customer Instructions

Where BoothCRM processes Customer Data on behalf of customers using the Services, such processing is carried out pursuant to the instructions of the applicable customer and in accordance with the agreements governing the provision of the Services.

Customers are responsible for ensuring that they have an appropriate lawful basis for the collection, use, disclosure, transfer, and processing of Customer Data submitted through the Services, including obtaining any notices, consents, permissions, or other authorizations required under applicable laws.

BoothCRM does not independently determine the purposes for which Customer Data is collected by customers and processes such information solely for the purpose of providing the Services and fulfilling its contractual obligations.

4.6 Multiple Legal Bases

In certain circumstances, more than one lawful basis may apply to the same processing activity.

Nothing in this Section shall be construed as limiting BoothCRM’s ability to process Personal Data where such processing is otherwise permitted or required under applicable laws.

5. Customer Data and Roles in Data Processing

BoothCRM is a business-to-business (B2B) software platform that enables customers to collect, organize, manage, analyze, and otherwise process information relating to leads, customers, prospects, exhibition attendees, employees, vendors, partners, and other business contacts (“Customer Data”).

The Customer determines the nature, categories, and purposes for which Customer Data is collected and processed through the Services.

Accordingly, with respect to Customer Data processed through the Services:

(a) the Customer is responsible for determining the purposes and means of such processing;

(b) the Customer is responsible for ensuring that the collection, use, disclosure, transfer, retention, and processing of Customer Data complies with applicable laws;

(c) the Customer is responsible for providing any required notices and obtaining any consents, permissions, authorizations, or other lawful bases necessary for the processing of Customer Data through the Services;

(d) the Customer is responsible for responding to requests, inquiries, complaints, or claims relating to Customer Data submitted to the Services; and

(e) the Customer remains responsible for the accuracy, quality, integrity, and legality of Customer Data.

BoothCRM processes Customer Data solely:

(i) to provide, operate, maintain, secure, and support the Services;

(ii) in accordance with the Customer’s instructions communicated through the normal use of the Services;

(iii) to comply with applicable legal obligations; and

(iv) as otherwise permitted under applicable agreements between BoothCRM and the Customer.

BoothCRM does not independently determine the purposes for which Customer Data is collected by customers and does not use Customer Data for BoothCRM’s own marketing activities directed toward the individuals whose information forms part of Customer Data.

Where individuals seek to exercise rights relating to Customer Data controlled by a Customer, such individuals should direct their requests to the relevant Customer.

To the extent BoothCRM receives a request directly relating to Customer Data that is processed on behalf of a Customer, BoothCRM may:

(a) refer the individual to the relevant Customer;

(b) notify the Customer of the request where appropriate and legally permissible; and

(c) provide reasonable assistance to the Customer in responding to such requests, subject to applicable agreements, technical feasibility, and legal requirements.

BoothCRM may engage subprocessors and service providers to support the delivery of the Services, including providers of cloud hosting, authentication services, communication services, payment services, analytics services, artificial intelligence services, customer support tools, and other operational services.

BoothCRM takes reasonable steps to ensure that such subprocessors are subject to appropriate confidentiality, security, and data protection obligations consistent with the nature of the services they provide.

Nothing in this Privacy Policy shall relieve Customers of their independent obligations under applicable laws relating to Customer Data or transfer responsibility for Customer Data processing decisions from Customers to BoothCRM.

For the avoidance of doubt, this Section applies solely to Customer Data processed through the Services and does not limit BoothCRM’s ability to process information relating to its own users, employees, contractors, website visitors, or other individuals in accordance with this Privacy Policy.

6. AI-Enabled Features and Processing

BoothCRM may offer certain artificial intelligence (“AI”) enabled functionalities as part of the Services or through optional add-on offerings. Such functionalities may include, without limitation, lead intelligence, sentiment analysis, conversation summaries, content generation, recommendations, predictive insights, workflow assistance, and other AI-assisted capabilities made available from time to time.

Where customers utilize AI-enabled functionalities, BoothCRM may process prompts, instructions, Customer Data submitted for analysis, contextual information necessary to perform the requested task, and AI-generated outputs solely for the purpose of providing the requested functionality.

BoothCRM may engage third-party service providers to facilitate the operation of AI-enabled functionalities. Such providers may process information submitted through AI-enabled functionalities strictly for the purpose of enabling the requested Services and subject to appropriate contractual, technical, and organizational safeguards.

BoothCRM does not use Customer Data submitted through AI-enabled functionalities to train, fine-tune, or improve BoothCRM’s own artificial intelligence models or the general-purpose artificial intelligence models of third parties.

BoothCRM does not use Customer Data submitted through AI-enabled functionalities to independently market to individuals or to create customer profiles unrelated to the provision of the Services.

Customers remain responsible for determining whether the use of AI-enabled functionalities is appropriate for their intended purposes and for ensuring that their use of such functionalities complies with applicable laws, contractual obligations, and internal policies.

AI-generated outputs may contain inaccuracies, omissions, biases, or other limitations inherent in AI technologies. Customers remain solely responsible for independently reviewing, validating, and determining the appropriateness of any AI-generated outputs before relying upon or acting upon such outputs.

BoothCRM does not make decisions that produce legal effects or similarly significant effects on individuals solely through automated means without meaningful human involvement. Customers remain responsible for decisions made using information generated through AI-enabled functionalities.

Where AI-enabled functionalities involve the processing of Customer Data, BoothCRM shall process such information in accordance with the customer’s instructions, applicable agreements governing the Services, this Privacy Policy, and applicable laws.

BoothCRM may maintain operational records relating to the use of AI-enabled functionalities, including information reasonably necessary for security monitoring, fraud prevention, troubleshooting, service administration, AI Credit accounting, billing purposes, and compliance with legal obligations.

The availability, scope, and capabilities of AI-enabled functionalities may change from time to time as BoothCRM enhances the Services, introduces new offerings, modifies existing features, or responds to technological, legal, operational, or commercial developments.

7. Cookies and Similar Technologies

BoothCRM and its authorized service providers may use cookies and similar technologies to operate, secure, and improve the Services and our websites.

Cookies are small text files that are stored on a user’s device when visiting a website. Similar technologies may include local storage, pixels, tags, software development kits (SDKs), session identifiers, and other technologies used for comparable purposes.

We may use the following categories of cookies and similar technologies:

7.1 Essential Cookies

These cookies are necessary for the operation of the Services and our websites and enable core functionality such as:

(a) user authentication;

(b) session management;

(c) security and fraud prevention;

(d) maintaining user preferences; and

(e) ensuring the proper functioning of the Services.

Because these technologies are essential to the operation of the Services, disabling them may affect the availability or functionality of certain features.

7.2 Analytics and Performance Technologies

We may use analytics and performance technologies to understand how users interact with the Services and our websites, including to:

(a) analyze usage patterns and trends;

(b) improve functionality and user experience;

(c) identify and diagnose technical issues; and

(d) evaluate the effectiveness of features and operational processes.

Where required by applicable law, such technologies shall be used only after obtaining the necessary permissions or consents.

7.3 Functional Technologies

We may use functional technologies to enhance convenience and improve the user experience by remembering settings, preferences, and configuration choices made by users.

7.4 Managing Cookies

Most web browsers allow users to manage cookies through browser settings, including the ability to:

(a) review stored cookies;

(b) delete existing cookies;

(c) block certain categories of cookies; and

(d) configure browser preferences regarding future cookie placement.

Please note that disabling or restricting certain cookies or similar technologies may impact the availability, performance, or functionality of the Services.

7.5 Third-Party Technologies

Certain third-party service providers engaged by BoothCRM, such as analytics providers, authentication providers, customer support providers, or other authorized subprocessors, may utilize cookies or similar technologies in connection with the Services.

The use of such technologies by third parties is governed by their respective privacy practices and contractual arrangements with BoothCRM, as applicable.

BoothCRM does not use cookies or similar technologies to sell Personal Data or to facilitate third-party behavioral advertising unrelated to the provision of the Services.

8. Disclosure of Information

BoothCRM may disclose Personal Data and other information collected in connection with the Services only in the circumstances described in this Privacy Policy or as otherwise permitted or required by applicable laws.

8.1 Service Providers and Subprocessors

BoothCRM may engage third-party service providers and subprocessors to support the operation, delivery, maintenance, and improvement of the Services.

Such providers may include, without limitation:

(a) cloud hosting and infrastructure providers;

(b) authentication and identity management providers;

(c) payment processing providers;

(d) communication and notification service providers;

(e) customer support and helpdesk providers;

(f) analytics and monitoring providers;

(g) artificial intelligence service providers;

(h) backup, disaster recovery, and security service providers; and

(i) other vendors reasonably necessary to support the provision of the Services.

Such service providers and subprocessors shall be authorized to access and process information only to the extent reasonably necessary to perform services on BoothCRM’s behalf and shall be subject to appropriate contractual confidentiality, security, and data protection obligations.

8.2 Customer-Authorized Integrations

Where a Customer elects to enable integrations, applications, or services provided by third parties, BoothCRM may disclose information necessary to facilitate such integrations in accordance with the Customer’s instructions and configuration choices.

The Customer acknowledges that BoothCRM is not responsible for the privacy practices, security measures, or data handling activities of third-party providers operating independently of BoothCRM.

8.3 Payment Processing

BoothCRM may disclose information necessary to facilitate billing, payment processing, fraud prevention, charge management, accounting, and related financial activities through authorized payment processors, banking partners, and financial service providers.

BoothCRM does not store complete payment card information except to the extent necessary to fulfill legal obligations or as otherwise permitted under applicable law.

8.4 Artificial Intelligence Service Providers

Where customers utilize AI-enabled functionalities, BoothCRM may disclose prompts, instructions, Customer Data submitted for analysis, and other information reasonably necessary to enable the requested functionality through authorized AI service providers engaged by BoothCRM.

BoothCRM requires such providers to process such information solely for the purpose of delivering the requested functionality and not for independent model training purposes, to the extent supported by BoothCRM’s contractual arrangements with such providers.

8.5 Legal and Regulatory Requirements

BoothCRM may disclose information where such disclosure is reasonably necessary to:

(a) comply with applicable laws, regulations, court orders, governmental directives, or lawful requests from competent authorities;

(b) establish, exercise, or defend legal claims;

(c) investigate, prevent, or address suspected fraud, security incidents, unlawful activities, or violations of our Terms and Conditions; or

(d) protect the rights, property, safety, security, or legitimate interests of BoothCRM, our customers, users, or third parties.

8.6 Corporate Transactions

BoothCRM may disclose information in connection with a proposed or actual merger, acquisition, investment transaction, corporate restructuring, sale of assets, financing arrangement, change in control, or other similar corporate transaction involving Omnexa Solutions Pvt. Ltd.

Where legally required, appropriate safeguards or notices shall be implemented in connection with such transactions.

8.7 Professional Advisors

BoothCRM may disclose information to professional advisors, including legal counsel, auditors, accountants, consultants, insurers, and other advisors, where such disclosure is reasonably necessary for legitimate business purposes and subject to appropriate confidentiality obligations.

8.8 With Consent or Direction

BoothCRM may disclose information where the relevant individual has provided consent or where the disclosure is otherwise directed, requested, or authorized by the applicable customer or user.

8.9 No Sale of Personal Data

BoothCRM does not sell Personal Data to third parties.

BoothCRM does not disclose Personal Data to third parties for their own independent marketing purposes unrelated to the provision of the Services.

Any disclosures carried out by BoothCRM shall be limited to those reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with applicable laws, or provide the Services requested by customers.

9. International Data Transfers

BoothCRM primarily hosts and stores Customer Data within data centers located in India.

However, in the course of providing the Services, certain information may be accessed, processed, transmitted, stored, or otherwise handled outside India by BoothCRM, its affiliates, authorized subprocessors, or service providers engaged to support the operation of the Services.

Such international processing activities may arise in connection with, without limitation:

(a) cloud infrastructure and hosting services;

(b) customer-authorized integrations;

(c) communication and notification services;

(d) payment processing activities;

(e) customer support and technical assistance functions;

(f) analytics and monitoring services;

(g) artificial intelligence functionalities requested by customers; and

(h) other operational activities reasonably necessary for the provision of the Services.

Where BoothCRM transfers or permits the processing of Personal Data outside India, BoothCRM shall take reasonable steps to ensure that such transfers are carried out in accordance with applicable laws and subject to appropriate safeguards proportionate to the nature of the information involved.

Such safeguards may include:

(i) contractual obligations relating to confidentiality, security, and data protection;

(ii) assessments of the nature and necessity of the transfer;

(iii) restricting access to authorized personnel and service providers with a legitimate business need to access the information; and

(iv) implementing technical and organizational measures designed to protect Personal Data during transmission and processing.

Customers acknowledge and agree that the use of certain functionalities, integrations, or service providers selected by BoothCRM or authorized by the Customer may result in the processing of information outside India.

Nothing in this Privacy Policy shall be construed as preventing BoothCRM from engaging reputable service providers located outside India where such engagement is reasonably necessary to provide, secure, maintain, improve, or support the Services, provided that BoothCRM takes reasonable steps to protect Personal Data in accordance with this Privacy Policy and applicable laws.

Customers remain responsible for evaluating whether their own legal, regulatory, contractual, or internal policy requirements impose additional restrictions relating to international data transfers and for configuring their use of the Services accordingly.

10.  Information Security

BoothCRM implements and maintains reasonable technical, organizational, and administrative measures designed to protect Personal Data and Customer Data against unauthorized access, acquisition, disclosure, alteration, destruction, loss, misuse, or other unlawful forms of processing.

Such measures may include, as appropriate and proportionate to the nature of the Services and the information involved:

(a) access controls and authentication mechanisms designed to restrict access to authorized personnel and users;

(b) role-based permissions and account management controls;

(c) encryption of data during transmission using industry-standard security protocols;

(d) network security measures intended to protect the confidentiality, integrity, and availability of systems supporting the Services;

(e) logging, monitoring, and security event detection mechanisms;

(f) backup and recovery processes designed to support business continuity objectives;

(g) secure software development and deployment practices;

(h) periodic review and enhancement of security measures in response to evolving risks and operational requirements;

(i) employee and contractor confidentiality obligations; and

(j) the use of service providers and subprocessors that are subject to appropriate contractual obligations relating to confidentiality, security, and data protection.

Access to Personal Data and Customer Data by BoothCRM personnel shall be limited to individuals who have a legitimate business need to access such information in connection with their responsibilities and who are subject to appropriate confidentiality obligations.

Customers are responsible for maintaining the confidentiality and security of their Account credentials, managing user access permissions appropriately, and taking reasonable steps to prevent unauthorized access to their Accounts.

Customers shall promptly notify BoothCRM if they become aware of any actual or suspected unauthorized access to their Accounts, compromise of credentials, security incident, or other event that may affect the security of the Services or Customer Data.

While BoothCRM endeavors to implement and maintain appropriate safeguards, no method of transmission over the internet, electronic storage system, or information security program can guarantee absolute security.

Accordingly, BoothCRM does not warrant or guarantee that the Services will be immune from security incidents, cyberattacks, unauthorized access attempts, system failures, or other events beyond BoothCRM’s reasonable control.

BoothCRM may investigate suspected security incidents affecting the Services and may take such actions as BoothCRM reasonably determines necessary to protect the Services, Customer Data, Personal Data, customers, users, and other affected parties.

Where BoothCRM determines that notification of a security incident is required under applicable laws or contractual obligations, BoothCRM shall provide such notifications in accordance with the requirements of such laws or obligations.

Nothing in this Privacy Policy shall be construed as creating any security obligations beyond those expressly required under applicable laws, contractual commitments, or BoothCRM’s documented security practices.

11. Data Retention

BoothCRM retains Personal Data and Customer Data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with applicable laws, enforce contractual rights, resolve disputes, maintain security, and support the provision of the Services.

The retention period applicable to specific categories of information may vary depending upon the nature of the information, the purposes for which it was collected, applicable legal requirements, and the relationship between BoothCRM and the relevant customer or user.

11.1 Account and Business Information

BoothCRM may retain information relating to Accounts, subscriptions, billing records, communications, support requests, and other business interactions for as long as necessary to:

(a) administer customer relationships;

(b) maintain business and financial records;

(c) comply with applicable legal, tax, accounting, and regulatory obligations;

(d) establish, exercise, or defend legal claims; and

(e) enforce BoothCRM’s contractual rights and obligations.

11.2 Customer Data

Customer Data processed through the Services shall generally be retained for the duration of the applicable Subscription Term and any applicable Grace Period.

Where a Subscription expires and is not renewed, BoothCRM may provide a grace period of fifteen (15) calendar days, during which the Customer may continue to access and use the Services in accordance with the applicable Terms and Conditions.

If the Subscription is not renewed before the expiration of the applicable Grace Period, the Subscription shall terminate in accordance with the applicable Terms and Conditions.

Following such termination, BoothCRM shall generally make Customer Data available to the Customer for retrieval for a period of thirty (30) calendar days (“Retrieval Period”), during which the Customer may:

(a) export or otherwise retrieve Customer Data; and

(b) renew or reactivate the applicable Subscription in accordance with BoothCRM’s then-current commercial terms.

If the applicable Subscription is not renewed or reactivated before the expiration of the Retrieval Period, BoothCRM may permanently delete Customer Data from its production systems in accordance with its retention and deletion practices.

11.3 Backup and Archival Records

Residual copies of information may continue to exist within backup systems, archival media, disaster recovery environments, system logs, and other operational records for a limited period following deletion from production systems.

Such residual copies shall remain subject to applicable confidentiality, security, and data protection obligations and shall not ordinarily be restored except where reasonably necessary for operational recovery purposes or as required by applicable laws.

11.4 Legal and Regulatory Retention Requirements

BoothCRM may retain Personal Data and Customer Data beyond the retention periods otherwise described in this Privacy Policy where reasonably necessary to:

(a) comply with applicable laws, regulations, court orders, governmental directives, or lawful requests from competent authorities;

(b) maintain records required for tax, accounting, audit, or regulatory purposes;

(c) establish, exercise, or defend legal claims;

(d) investigate fraud, security incidents, violations of applicable agreements, or other unlawful activities; or

(e) enforce BoothCRM’s rights and remedies.

11.5 Customer Responsibilities

Customers are responsible for exporting and retaining any Customer Data that they wish to preserve before the expiration of the applicable Retrieval Period.

BoothCRM shall not be responsible for any inability to recover Customer Data following deletion carried out in accordance with this Privacy Policy, the applicable Terms and Conditions, or applicable laws.

Nothing in this Privacy Policy shall require BoothCRM to retain information beyond the periods reasonably necessary to fulfill the purposes described herein or as otherwise required by applicable laws.

12. Your Rights and Choices

Depending upon the nature of your relationship with BoothCRM and the requirements of applicable laws, you may have certain rights and choices relating to your Personal Data.

The availability and scope of such rights may vary depending upon the applicable legal framework and the circumstances in which the information is processed.

12.1 Rights Relating to Information Controlled by BoothCRM

Where BoothCRM determines the purposes and means of processing Personal Data, individuals may, subject to applicable laws, exercise the following rights:

(a) request access to Personal Data maintained by BoothCRM relating to them;

(b) request correction, updating, or completion of inaccurate or incomplete Personal Data;

(c) request the deletion of Personal Data where retention is no longer necessary or where required under applicable laws;

(d) withdraw consent previously provided for specific processing activities, where such processing is based on consent;

(e) object to or request restrictions on certain processing activities, where such rights are recognized under applicable laws;

(f) request information regarding the categories of Personal Data processed by BoothCRM and the purposes for which such information is used; and

(g) submit complaints or grievances relating to the handling of Personal Data.

BoothCRM may request reasonable information necessary to verify the identity of the individual making the request before taking action in response to such requests.

BoothCRM may decline, limit, or defer action on requests to the extent permitted or required under applicable laws, including where the request:

(i) cannot reasonably be verified;

(ii) adversely affects the rights or freedoms of other individuals;

(iii) relates to information that BoothCRM is required or permitted to retain under applicable laws; or

(iv) falls within any other exemption recognized under applicable laws.

12.2 Requests Relating to Customer Data

BoothCRM generally processes Customer Data on behalf of and under the instructions of its customers.

Accordingly, where an individual seeks to exercise rights relating to Personal Data contained within Customer Data processed through the Services, such requests should ordinarily be directed to the relevant customer that collected the information.

BoothCRM does not independently determine the purposes for which Customer Data is collected by customers and may not be in a position to respond directly to such requests.

Where BoothCRM receives a request directly relating to Customer Data processed on behalf of a customer, BoothCRM may:

(a) refer the individual to the relevant customer;

(b) notify the relevant customer of the request, where legally permissible; and

(c) provide reasonable assistance to the customer in responding to the request, subject to applicable agreements, technical feasibility, and legal requirements.

12.3 Managing Account Information

Authorized users may review and update certain Account information directly through the functionalities made available within the Services.

Customers remain responsible for administering user access permissions, maintaining the accuracy of information submitted through the Services, and managing Customer Data processed through their Accounts.

12.4 Marketing Communications

Individuals may opt out of receiving promotional communications from BoothCRM by following the unsubscribe instructions contained in such communications or by contacting BoothCRM using the contact details provided in this Privacy Policy.

Please note that BoothCRM may continue to send service-related, transactional, legal, billing, security, or other non-promotional communications where such communications are necessary for the administration of Accounts or the provision of the Services.

12.5 Exercising Rights

Requests relating to Personal Data processed by BoothCRM may be submitted using the contact information provided in this Privacy Policy.

BoothCRM shall endeavor to respond to such requests within a reasonable period and in accordance with applicable laws.

Nothing in this Section shall limit any rights or remedies available to individuals under applicable laws.

13. Grievance Redressal and Complaints

BoothCRM is committed to addressing questions, concerns, requests, and complaints relating to the processing of Personal Data in a fair and timely manner.

Individuals who wish to raise concerns regarding the manner in which BoothCRM processes Personal Data, seek clarification regarding this Privacy Policy, exercise applicable rights, or submit privacy-related complaints may contact BoothCRM using the contact details provided below.

Privacy and Grievance Contact

Omnexa Solutions Pvt. Ltd.
5th Floor, Shilp The Address,
Shilaj Rd, Thaltej,
Ahmedabad, Gujarat 380059, India

Email: support@boothcrm.net

Upon receipt of a grievance, complaint, or privacy-related request, BoothCRM may take reasonable steps to verify the identity and authority of the individual submitting the request before providing information or taking any action.

BoothCRM shall endeavor to acknowledge and address grievances and complaints within a reasonable period, taking into account the nature and complexity of the matter and any requirements imposed under applicable laws.

Where a request or complaint relates to Customer Data processed by BoothCRM on behalf of a customer, BoothCRM may:

(a) direct the individual to the relevant customer that controls such Customer Data;

(b) notify the relevant customer of the request or complaint, where legally permissible; and

(c) provide reasonable assistance to the customer in responding to the matter, subject to applicable agreements, technical feasibility, and applicable laws.

Submission of a grievance or complaint to BoothCRM does not limit any rights or remedies that may otherwise be available to individuals under applicable laws.

BoothCRM encourages individuals to first contact BoothCRM directly so that we may have an opportunity to understand and address the matter promptly and effectively.

14. Third-Party Websites and Services

The Services may contain links to third-party websites, applications, products, services, integrations, or other resources that are not owned, operated, or controlled by BoothCRM.

In addition, customers may elect to enable or utilize third-party integrations in connection with their use of the Services. The use of such third-party offerings is subject to the terms, conditions, and privacy practices established by the respective third parties.

BoothCRM does not control and is not responsible for:

(a) the content, availability, functionality, or security of third-party websites or services;

(b) the privacy practices, data handling activities, or policies of third parties;

(c) the accuracy, completeness, or reliability of information made available by third parties; or

(d) any acts, omissions, products, services, or practices of independent third parties.

Customers and users are encouraged to review the applicable privacy policies, terms of service, and other relevant documentation of any third-party services with which they choose to interact.

The inclusion of links to third-party websites or the availability of integrations through the Services shall not be construed as an endorsement, sponsorship, recommendation, or representation by BoothCRM regarding such third parties or their offerings.

Nothing in this Section shall limit BoothCRM’s obligations with respect to subprocessors and service providers engaged directly by BoothCRM to support the provision of the Services, which remain subject to the safeguards described elsewhere in this Privacy Policy.

15. Changes to This Privacy Policy

BoothCRM may revise, amend, update, or otherwise modify this Privacy Policy from time to time to reflect changes in applicable laws, regulatory requirements, industry practices, technologies, business operations, service offerings, security practices, or other legitimate business needs.

The “Last Updated” date appearing at the beginning or end of this Privacy Policy shall indicate the date on which the most recent revision became effective.

Where BoothCRM determines that changes to this Privacy Policy materially affect the manner in which Personal Data is collected, used, disclosed, retained, or otherwise processed, BoothCRM shall use reasonable efforts to provide notice of such changes through one or more of the following methods:

(a) publication of the updated Privacy Policy on the BoothCRM website;

(b) notifications displayed within the Services;

(c) electronic mail communications sent to the contact details associated with the relevant Account; or

(d) any other method reasonably designed to bring such changes to the attention of affected users or customers.

Unless otherwise required by applicable laws, the revised Privacy Policy shall become effective upon the date specified in the updated version of the Privacy Policy.

The continued access to or use of the Services following the effective date of a revised Privacy Policy shall constitute acknowledgment of the updated Privacy Policy to the extent permitted under applicable laws.

Nothing in this Section shall limit any rights that individuals may have under applicable laws with respect to the processing of their Personal Data.

Customers and users are encouraged to review this Privacy Policy periodically to remain informed regarding BoothCRM’s privacy practices.

16. Contact Us

If you have any questions regarding this Privacy Policy, wish to exercise rights available under applicable laws, submit a privacy-related request, or raise a grievance relating to the processing of Personal Data by BoothCRM, you may contact us using the details set forth below:

Omnexa Solutions Pvt. Ltd.
5th Floor, Shilp The Address,
Shilaj Rd, Thaltej,
Ahmedabad, Gujarat 380059, India

Privacy and Grievance Contact Email: support@boothcrm.net

General Support Email: support@boothcrm.net

BoothCRM may request additional information reasonably necessary to verify the identity and authority of individuals submitting requests before disclosing information or taking action in response to such requests.

Where a request relates to Customer Data processed by BoothCRM on behalf of a customer, BoothCRM may direct the individual to the relevant customer that controls such Customer Data or otherwise coordinate with the customer in accordance with applicable laws, contractual obligations, and this Privacy Policy.

BoothCRM shall endeavor to respond to privacy-related inquiries and requests within a reasonable period and in accordance with applicable legal requirements.

BoothCRM may update the contact information set forth in this Privacy Policy from time to time. Any such changes shall become effective upon publication of the updated Privacy Policy or through such other notice as BoothCRM may provide.

17. Supplemental Provisions

Nothing in this Privacy Policy shall be construed as limiting any rights, obligations, exemptions, or protections available to BoothCRM, its customers, users, or individuals under applicable laws.

To the extent required by applicable laws, BoothCRM may publish additional privacy notices, disclosures, schedules, or supplemental statements addressing specific products, services, jurisdictions, processing activities, technologies, integrations, or categories of Personal Data.

In the event of any inconsistency between this Privacy Policy and any supplemental privacy notice expressly applicable to a particular Service or processing activity, the provisions of such supplemental notice shall prevail solely with respect to the matters specifically addressed therein.

BoothCRM may maintain separate privacy practices, notices, or contractual arrangements applicable to employees, job applicants, contractors, vendors, enterprise customers, or other categories of individuals where required or appropriate under applicable laws.

Nothing in this Privacy Policy shall prevent BoothCRM from adopting additional safeguards, operational controls, or privacy-enhancing practices that provide greater protection to Personal Data than those expressly described herein.

This Privacy Policy shall be interpreted in a manner consistent with applicable laws. If any provision of this Privacy Policy is determined to be invalid, unlawful, or unenforceable under applicable laws, such provision shall be interpreted or modified to the minimum extent necessary to achieve compliance, and the remaining provisions shall continue in full force and effect.