Privacy Policy
This policy explains what Support IT Helpdesk does with personal data — yours, and the personal data your organisation puts into the service about its own people. It is written to the Digital Personal Data Protection Act, 2023, and to be understood without a law degree.
Last updated: · Applies to Support IT Helpdesk, operated by Support IT Ventures.
Our two different roles
This matters more than anything else on this page, so it comes first.
For your ACCOUNT data — the name, work email and billing details of the people who sign up and administer the service — we are the Data Fiduciary. We decide why and how it is processed, and this policy governs it.
For your CONTENT — the tickets, employee records, knowledge base and everything else your team puts in — your organisation is the Data Fiduciary and we are its Data Processor. We process it only on your instructions. That content routinely includes personal data about your employees, so your organisation needs its own notice to them; we assist, but we cannot be their point of contact for a decision that is yours.
If you are an employee of an organisation that uses Support IT Helpdesk and you want to see, correct or erase your record, please approach your employer first. If they ask us, we will help them.
What we collect, and why
We do not collect location beyond the country implied by an IP address, we do not use tracking cookies, and there is no advertising network, analytics script or social pixel anywhere on this site or in the product.
- Account and identity: name, work email, password (stored only as a hash), role, and the organisation you belong to — to create your account and let you sign in.
- Billing: legal entity name, billing address, state, GSTIN and PAN where you give them — to raise a compliant tax invoice. Card and bank details go directly to our payment processor and are never stored on our servers.
- Usage: which features are used and how often, at the level of counts — to enforce plan limits, size our infrastructure and decide what to build.
- Technical logs: IP address, browser, timestamps and error traces — for security, abuse prevention and debugging.
- Support correspondence: what you write to us, so we can answer it and refer back to it.
- Your content: whatever your organisation chooses to put in. We do not inspect it except when you ask us to help with a specific problem.
Consent, and how to withdraw it
We process account and billing data because it is necessary to provide the service you asked for and to meet our tax obligations. Where we rely on your consent — for example, product announcement emails — you can withdraw it at any time from your notification preferences or the unsubscribe link, without affecting the service itself.
Where your data is stored
On infrastructure we control, in India. The database, uploaded files, logs and backups are all held in India and are not replicated abroad.
Only two companies ever touch your data on our behalf: our payment processor, which sees billing identifiers when you pay, and our email provider, which delivers messages you asked us to send. Both are listed, with what they receive and where they are, on our sub-processors page. We give 30 days' notice before that list changes.
We do not run an AI model for customers. Out of the box the assistant works from rules and your own knowledge base, and no AI model is called. Nothing is sent to a model unless your administrator deliberately connects one in AI Studio — typically their own server, such as Ollama on a VPS they run, or a provider they choose — and when they do, the product names the destination host, requires it to be typed to confirm, and records the decision in the audit log.
How long we keep it
- Your content: for as long as your account is open, and for 90 days after termination so you can retrieve it — then deleted permanently.
- Invoices and tax records: eight years, because Indian tax law requires it.
- Technical and security logs: 180 days.
- Enquiries from the website: two years.
- Audit records of who did what inside your account: for the retention period stated by your plan.
How it is protected
- Every request is scoped to one organisation at the query level.
- Passwords are hashed, never stored or recoverable. Integration secrets are encrypted at rest and never shown again once saved.
- All traffic is over TLS. The application sends strict security headers and loads no third-party script, except Razorpay's checkout on the payment page.
- Access to production is limited to named people, is logged, and requires two-factor authentication. When our support staff enter your account, each entry is recorded in your audit log.
- Backups are encrypted, retained on a schedule, and restored on a test schedule — an untested backup is not a backup.
Your rights under the DPDP Act
As a Data Principal you have the right to access a summary of your personal data and how it is processed; to have it corrected or completed; to have it erased where we no longer need it; to nominate someone to exercise your rights if you cannot; and to have a grievance heard.
Most of these you can do yourself from your account screen. For anything else, write to grievance@supportit.in. We acknowledge within 24 hours and resolve within 15 days.
Children
The service is sold to organisations and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe we have, write to grievance@supportit.in and we will delete it.
If something goes wrong
In the event of a personal data breach we will notify the Data Protection Board of India and the affected Data Principals in the manner and timeframe the DPDP Act requires, tell you what happened and what data was involved, and publish what we changed afterwards.
Grievance Officer
In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
Email: grievance@supportit.in. Address: India.
We acknowledge every grievance within 24 hours and resolve it within 15 days.
Automated decisions and profiling
We do not make automated decisions that produce legal or similarly significant effects about any individual. The product suggests a category or a draft reply, and a person decides. Nothing in it scores, ranks or profiles your employees, and we do not build a profile of you across customers.
Artificial intelligence, specifically
Out of the box the assistant works from rules and your own knowledge base, and no AI model is called: your tickets are not sent to any model provider. We do not use anything you write to train a model — not for us, and not for another customer.
We do not run an AI model for customers. An administrator in your organisation can connect a model of their own in AI Studio — for example Ollama on a server they control — or a provider they choose. When they enter its address, the product names the destination host, requires it to be typed to confirm, and records the decision in the audit log. From then on ticket text, chat messages and drafts are sent to that host when the AI is used. On a server you control the text stays with you; with a third-party provider, that provider's terms apply, so choose one you would trust with the same data in an email. It is off by default.
Marketing email, and what we will not send
Transactional messages — a password reset, a receipt, a warning that a payment failed — are part of the service and are not something you can unsubscribe from while the account is open.
Anything else is optional. Product announcements carry a one-click unsubscribe and honour it immediately. We do not run drip sequences against people who filled in a form, we do not buy contact lists, and we do not pass your details to a partner.
When we are legally required to disclose
If we receive a lawful order compelling disclosure of customer data, we will disclose only what the order actually requires, and — unless the law forbids it — we will tell you first so you can respond. We will not hand over data on an informal request.
Questions about any of this
If something here is unclear, or you think we have described our own practice inaccurately, tell us and we will correct the page. A privacy policy that nobody can follow is not protecting anyone.
Changes to this policy
We will post any change here with a new effective date, and email the account owner if the change is material. Past versions are available on request, so you can see what you agreed to at the time.
Something here unclear or unfair? Tell us at support@supportit.in. We would rather fix the wording than argue about it later. See also Terms, Privacy and Grievance redressal.