Privacy Policy.
How Kothari IT Services Private Limited handles personal data, in plain language.
Last updated: 14 August 2026
Who we are
Kothari IT Services Private Limited (“KIT”, “we”, “us”) is a software company based in Pune, India. We design, build, and operate business software: ERP, CRM, and HR systems, websites, and AI-assisted tools, both as our own products and as systems built for business clients.
This policy covers four distinct situations, because they work differently: data collected by this website, data in products KIT operates, data we process on behalf of business clients, and data flowing through third-party integrations. For any question about this policy, write to info@kothariit.com.
1. Data collected by this website
The only personal information this website collects is what you type into the contact form: your name, company, contact details, and your message. It lands in KIT's internal lead system so we can reply to you, is used for that conversation, and nothing else. We do not sell it, share it for marketing, or add you to a mailing list.
This site sets no advertising trackers and uses no third-party analytics cookies. Your theme preference (light or dark) is stored in your own browser and never sent to us. To have your contact-form details removed, email info@kothariit.com or use the process on our data deletion page.
2. Data in KIT-operated products
KIT builds and operates business software products. Depending on the product and how your organization uses it, these systems may process:
- Account and contact data: names, work email addresses, phone numbers, roles, and login identifiers.
- Employee and business data: attendance, payroll inputs, incentives, and related HR records, in HR products.
- Customer and CRM data: enquiries, contact details, follow-up history, and sales-pipeline records.
- Operational and financial records: quotations, invoices, orders, dispatch and service records, and plan-versus-actual figures.
- Files and photos uploaded by users as part of their work in the system.
- Location data, only where a specific product feature uses it (for example, attendance check-in), and only while that feature is in use.
- Business communications, where a product integrates with messaging channels such as the WhatsApp Business Platform: message content and delivery metadata needed to provide the feature.
- Authentication and session information: login timestamps, session tokens, and device or browser details needed to keep accounts secure.
- Audit and security data: records of consequential actions in a system, kept so that changes are traceable.
No single product collects all of these. Which categories apply depends on the specific product and the features your organization has enabled. Product-specific details are available on request, and mobile apps will carry their own store-level data disclosures generated from what each app actually does.
3. Data we process on behalf of business clients
Much of the data in KIT-operated systems belongs to our business clients: their employee records, their customer lists, their operational and financial data. For that data, the client organization decides what is collected and why; KIT processes it to provide and operate the system, under the terms of a written engagement agreement, and does not use it for any other purpose.
If your employer, or a business you deal with, uses a KIT-operated system, your relationship is with that organization. Direct your questions or requests about your data to them first; we support our clients in fulfilling such requests. Where a request reaches us directly, our data deletion page explains how we handle it.
4. Third-party integrations
Some products integrate with third-party platforms, for example the WhatsApp Business Platform for business messaging, email delivery providers, and hosting infrastructure. Data that passes through such an integration is also handled by that platform under its own terms and privacy policy; a WhatsApp message, for instance, exists on Meta's systems as well as in the product that sent or received it. We choose integrations deliberately and configure them to the data they need, and we do not sell data to anyone.
5. Retention
We keep personal data only as long as it is needed for the purpose it was collected: for the duration of a conversation, an account, or an engagement, plus any period required by law. Some records must be retained beyond a deletion request, for statutory, accounting, payroll, tax, audit, or security reasons; the data deletion page explains this in detail.
6. Security
KIT operates its systems with access controls, authenticated sessions, audit logs on consequential actions, monitored services, and backups with tested restore procedures. Releases to production are reviewed and approved by a person. No system can be guaranteed absolutely secure, and we do not claim that; we do claim a discipline of running software as if the data in it matters, because it does.
7. Your choices and rights
You can ask us what personal data we hold about you, ask for it to be corrected, or ask for it to be deleted, subject to the retention obligations above and to the client-controlled situations described in section 3. Requests go to info@kothariit.com, and the data deletion page describes exactly how they are handled.
8. Changes to this policy
When this policy changes, the date at the top of this page changes with it. Material changes to how a product handles data are communicated to the affected clients directly.