{"id":4702,"date":"2026-09-04T10:25:23","date_gmt":"2026-09-04T10:25:23","guid":{"rendered":"https://autosmarts.co/en/?page_id=4702"},"modified":"2026-09-04T10:27:57","modified_gmt":"2026-09-04T10:27:57","slug":"privacy-policy","status":"publish","type":"page","link":"https://autosmarts.co/en/privacy-policy/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Effective Date:</strong> April 1, 2026 <strong>Last Updated:</strong> September 1, 2026</p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Introduction</h2>\n\n\n\n<p class=\"wp-block-paragraph\">Autosmart Solutions Private Limited (“AutoSmart,” “we,” “us,” or “our”) provides an audit management platform (the “Platform” or “Service”) to organisations for managing audits, compliance workflows, and related activities.</p>\n\n\n\n<p class=\"wp-block-paragraph\">This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website or use our Platform. It applies to visitors of our website and to authorised users of the Platform acting on behalf of our client organisations.</p>\n\n\n\n<p class=\"wp-block-paragraph\">Where AutoSmart processes personal data on behalf of a client organisation under a service agreement, that client is generally the data controller and AutoSmart acts as a data processor. In such cases, the client’s own privacy notice and instructions govern the processing, and this policy describes our general practices as a processor. Where AutoSmart determines the purposes and means of processing (for example, website visitor data or our own business contacts), AutoSmart acts as the data controller.</p>\n\n\n\n<h2 class=\"wp-block-heading\">2. Information We Collect</h2>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on how you interact with us, we may collect:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Account and profile information:</strong> name, work email, job title, organisation, and login credentials.</li>\n\n\n\n<li><strong>Platform usage data:</strong> audit records, checklists, action plans, comments, and uploaded documents entered by users in the course of using the Platform.</li>\n\n\n\n<li><strong>Technical data:</strong> IP address, browser type, device information, and log data generated through normal use of the website and Platform.</li>\n\n\n\n<li><strong>Communications:</strong> information you provide when you contact us, request support, or complete a form on our website.</li>\n\n\n\n<li><strong>Media inputs for specific features:</strong> where a client enables features such as image capture or voice input for audit action plans, the underlying image or audio is processed to deliver the feature (see Section 6).</li>\n</ul>\n\n\n\n<p class=\"wp-block-paragraph\">We do not knowingly collect special categories of personal data (e.g., health, biometric, or similarly sensitive data) as part of standard Platform use.</p>\n\n\n\n<h2 class=\"wp-block-heading\">3. How We Use Information</h2>\n\n\n\n<p class=\"wp-block-paragraph\">We use personal data to:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide, operate, and maintain the Platform;</li>\n\n\n\n<li>Authenticate users and manage access control;</li>\n\n\n\n<li>Respond to support requests and communications;</li>\n\n\n\n<li>Maintain the security, availability, and integrity of our systems;</li>\n\n\n\n<li>Meet legal, regulatory, and contractual obligations, including audit and certification requirements;</li>\n\n\n\n<li>Improve the Platform based on aggregated or anonymised usage patterns.</li>\n</ul>\n\n\n\n<p class=\"wp-block-paragraph\">We do not sell personal data.</p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Legal Basis for Processing (GDPR)</h2>\n\n\n\n<p class=\"wp-block-paragraph\">Where the GDPR applies, we rely on the following legal bases:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Performance of a contract</strong> — to provide the Platform to our clients and their users;</li>\n\n\n\n<li><strong>Legitimate interests</strong> — to secure our systems, prevent fraud, and improve our services;</li>\n\n\n\n<li><strong>Legal obligation</strong> — to comply with applicable law, including data protection and security regulations;</li>\n\n\n\n<li><strong>Consent</strong> — where required for specific features (for example, certain AI-assisted or media-based features), consent is obtained by the client organisation as controller, or directly by AutoSmart where AutoSmart is the controller for that processing.</li>\n</ul>\n\n\n\n<h2 class=\"wp-block-heading\">5. Data Hosting and Security</h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Primary hosting:</strong> Platform data is hosted on AWS infrastructure in the ap-south-1 (Mumbai, India) region.</li>\n\n\n\n<li><strong>Disaster recovery:</strong> A disaster recovery environment is maintained in the AWS us-east-1 (N. Virginia, USA) region, in accordance with our Business Continuity Procedure (ASPL-ISMS-06).</li>\n\n\n\n<li><strong>Encryption in transit:</strong> TLS 1.2/1.3 is enforced for data in transit; older protocol versions (TLS 1.0/1.1) are disabled.</li>\n\n\n\n<li><strong>Encryption at rest:</strong> Data at rest is encrypted using AWS Key Management Service (KMS).</li>\n\n\n\n<li><strong>Access control:</strong> Role-based access control (RBAC) and multi-factor authentication are used to restrict access to authorised personnel and users.</li>\n\n\n\n<li><strong>Monitoring:</strong> Cloud infrastructure is monitored using industry-standard security tooling for threat detection, vulnerability management, and audit logging, in accordance with our Cloud Security Policy (ASPL-ISMS-74).</li>\n\n\n\n<li><strong>Backups:</strong> Data is backed up with a defined retention period, and disaster recovery targets a Recovery Time Objective (RTO) of 4–6 hours and a Recovery Point Objective (RPO) of 24 hours for core infrastructure.</li>\n\n\n\n<li><strong>Certification:</strong> AutoSmart’s Information Security Management System is certified to ISO/IEC 27001:2022 for the scope of software design, development, and support of the audit management application (Certificate No. 99 310 00665, TÜV SÜD South Asia Private Limited).</li>\n</ul>\n\n\n\n<h2 class=\"wp-block-heading\">6. AI-Assisted Features</h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Platform includes optional, client-configurable features that use automated processing, including:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Image anonymization</strong> for images submitted through the Platform, using computer vision models;</li>\n\n\n\n<li><strong>AI-assisted validation</strong> to support audit approval workflows;</li>\n\n\n\n<li><strong>Voice-to-text transcription</strong> for action plan fields, where enabled by a client.</li>\n</ul>\n\n\n\n<p class=\"wp-block-paragraph\">For voice transcription, audio is processed to generate a text transcript; the audio recording itself is not retained after transcription — only the resulting text is stored as part of the audit record. Where a feature involves a third-party AI service provider, that provider acts as a sub-processor under contractual data protection terms consistent with this policy and applicable law. Clients requiring the specific sub-processor details for a particular feature may request this information from their AutoSmart account contact.</p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Human review of AI-assisted outputs:</strong> AI-assisted features support the audit workflow but do not make final decisions on their own. No audit finding, transcript, or approval is published or finalised without review by an authorised human user. Individuals are not subject to a decision based solely on automated processing that produces legal or similarly significant effects without human involvement.</p>\n\n\n\n<h2 class=\"wp-block-heading\">7. Data Retention and Deletion</h2>\n\n\n\n<p class=\"wp-block-paragraph\">We retain personal data only for as long as necessary for the purpose it was collected, as follows:</p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Data category</th><th>Retention period</th></tr></thead><tbody><tr><td>Account and login data (name, work email, role, credentials)</td><td>For the duration of the active client relationship</td></tr><tr><td>Platform usage data (audit records, checklists, findings, action plans, uploaded evidence)</td><td>For the duration of the active client relationship, per the applicable service agreement</td></tr><tr><td>Voice transcription output (text only; audio is not retained)</td><td>Retained as part of the associated audit record, per the Platform usage data period above</td></tr><tr><td>Rolling database and application backups</td><td>7 days on a rolling basis, then overwritten in the ordinary backup cycle</td></tr><tr><td>Critical system, administrator, and security logs</td><td>180 days, per our IT Manual (ASPL-ISMS-02)</td></tr><tr><td>Website enquiry / support communications</td><td>For as long as needed to resolve the enquiry, and thereafter only if required for legal or record-keeping purposes</td></tr></tbody></table></figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Post-termination deletion:</strong> Following termination of a client agreement, Platform data is deleted in accordance with our Data Deletion Policy (ASPL-ISMS-77) within <strong>30 days</strong> of the end of the applicable notice period, unless a longer retention period is required by law or the client agreement. Deletion from backups follows the routine 7-day backup rotation described above; access to data pending deletion from backups is restricted in the interim.</p>\n\n\n\n<h2 class=\"wp-block-heading\">8. Data Sharing</h2>\n\n\n\n<p class=\"wp-block-paragraph\">We do not sell personal data. We may share personal data with:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Sub-processors and service providers</strong> who support the Platform (e.g., cloud infrastructure, and, where a client enables specific AI-assisted features, the relevant AI service provider), under data protection terms;</li>\n\n\n\n<li><strong>Professional advisers and auditors</strong>, where necessary for certification, audit, or legal compliance;</li>\n\n\n\n<li><strong>Regulators or authorities</strong>, where required by applicable law.</li>\n</ul>\n\n\n\n<p class=\"wp-block-paragraph\">Any international transfer of personal data outside the region in which it was collected is carried out under appropriate safeguards, such as standard contractual clauses or an equivalent legal mechanism, where required.</p>\n\n\n\n<h2 class=\"wp-block-heading\">9. Data Subject Rights</h2>\n\n\n\n<p class=\"wp-block-paragraph\">Subject to applicable law (including GDPR, where relevant), individuals may have the right to:</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Request access to, correction of, or deletion of their personal data;</li>\n\n\n\n<li>Object to or restrict certain processing;</li>\n\n\n\n<li>Request data portability;</li>\n\n\n\n<li>Withdraw consent, where processing is based on consent;</li>\n\n\n\n<li>Lodge a complaint with a relevant data protection supervisory authority.</li>\n</ul>\n\n\n\n<p class=\"wp-block-paragraph\">Where AutoSmart processes data as a processor on behalf of a client, requests should generally be directed to that client (the data controller). AutoSmart will support its clients in fulfilling such requests in line with the applicable service agreement. Requests directed to AutoSmart as controller (e.g., regarding our website or business contacts) can be submitted using the contact details in Section 13.</p>\n\n\n\n<h2 class=\"wp-block-heading\">10. Data Breach Notification</h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the event of a personal data breach, AutoSmart follows its Incident Management Procedure (ASPL-ISMS-18):</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where AutoSmart acts as a data processor, affected clients (as controllers) are notified without undue delay so they can meet their own regulatory notification obligations.</li>\n\n\n\n<li>Where AutoSmart acts as a data controller and a breach is likely to result in a risk to individuals’ rights and freedoms, affected individuals and/or the relevant supervisory authority will be notified in accordance with applicable law and contractual timelines.</li>\n</ul>\n\n\n\n<h2 class=\"wp-block-heading\">11. Cookies</h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our website uses a cookie consent management tool (CookieYes) to disclose and manage cookies in line with applicable cookie consent requirements, including the EU ePrivacy rules and GDPR.</p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Necessary/essential cookies</strong> required for the website to function are set automatically.</li>\n\n\n\n<li><strong>Non-essential cookies</strong> (which may include analytics, functional, performance, or advertising cookies, depending on current configuration) are not activated until you provide consent through the cookie banner.</li>\n\n\n\n<li>You can review or change your cookie preferences at any time using the cookie settings link available on our website, and can withdraw consent for non-essential cookies at any point.</li>\n\n\n\n<li>A current, itemised list of the specific cookies in use, their purpose, and their duration is available via the cookie consent banner/settings panel on our website, which reflects the live configuration more accurately than a static list here.</li>\n</ul>\n\n\n\n<h2 class=\"wp-block-heading\">12. Marketing Communications</h2>\n\n\n\n<p class=\"wp-block-paragraph\">AutoSmart does not currently send marketing communications through this website. If we introduce marketing communications in the future, we will provide a clear opt-out option with every such communication, in accordance with applicable law.</p>\n\n\n\n<h2 class=\"wp-block-heading\">13. Contact Us</h2>\n\n\n\n<p class=\"wp-block-paragraph\">For questions about this Privacy Policy or to exercise your data protection rights, please contact:</p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Autosmart Solutions Private Limited</strong> 4, 31/835, V Square, Pulikillam West, Kakkanad, Ernakulam – 682 030, Kerala, India</p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data Protection Officer:</strong> Chackochan K Shaiju Email: info@autosmarts.co</p>\n\n\n\n<h2 class=\"wp-block-heading\">14. Changes to This Policy</h2>\n\n\n\n<p class=\"wp-block-paragraph\">We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Last Updated” date at the top of this page indicates when this policy was last revised. Material changes will be communicated to clients in accordance with their service agreement.</p>\n","protected":false},"excerpt":{"rendered":"<p>Effective Date: April 1, 2026 Last Updated: September 1, 2026 1. Introduction Autosmart Solutions Private Limited (“AutoSmart,” “we,” “us,” or “our”) provides an audit management platform (the “Platform” or “Service”) to organisations for managing audits, compliance workflows, and related activities. This Privacy Policy explains how we collect, use, store, and protect personal data when you […]</p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"difl_page_category":[],"class_list":["post-4702","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https://autosmarts.co/en/wp-json/wp/v2/pages/4702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https://autosmarts.co/en/wp-json/wp/v2/pages"}],"about":[{"href":"https://autosmarts.co/en/wp-json/wp/v2/types/page"}],"author":[{"embeddable":true,"href":"https://autosmarts.co/en/wp-json/wp/v2/users/3"}],"replies":[{"embeddable":true,"href":"https://autosmarts.co/en/wp-json/wp/v2/comments?post=4702"}],"version-history":[{"count":1,"href":"https://autosmarts.co/en/wp-json/wp/v2/pages/4702/revisions"}],"predecessor-version":[{"id":4703,"href":"https://autosmarts.co/en/wp-json/wp/v2/pages/4702/revisions/4703"}],"wp:attachment":[{"href":"https://autosmarts.co/en/wp-json/wp/v2/media?parent=4702"}],"wp:term":[{"taxonomy":"difl_page_category","embeddable":true,"href":"https://autosmarts.co/en/wp-json/wp/v2/difl_page_category?post=4702"}],"curies":[{"name":"wp","href":"https://api.w.org/{rel}","templated":true}]}}