Privacy Policy
What personal data Eleserv Softech Pvt Ltd processes for Customer360, why, and your rights.
Last updated 30 September 2026
This policy explains how Eleserv Softech Pvt Ltd handles personal data in connection with Customer360. It covers two groups of people: customers' users (people who sign in to the dashboard) and website visitors of our customers' sites, whose data we process on our customers' behalf.
1. Dashboard users (we are the controller)
- Account data: name, work email, phone, job title, company details, time zone and language.
- Security data: password hash (Argon2id), two-factor settings (encrypted), sign-in sessions with device/browser and a hashed IP address, and an audit log of important actions.
- Billing data: company legal name, address, GSTIN/PAN and invoices.
- Sign-in with Google or Microsoft: we receive your name, email and account id from that provider; we do not receive your password.
We use this data to provide and secure the Service, send service emails (verification, invites, alerts, invoices, reports you schedule, and a weekly summary you can switch off) and meet legal obligations such as tax records. Marketing emails are sent only if you opted in, and you can opt out at any time.
2. Website visitors (we are the processor)
When a customer installs the Customer360 script, we process visitor data on that customer's instructions. The customer is the controller and their privacy notice applies. Depending on the visitor's consent and the customer's settings, this can include:
- A random visitor id and session id stored in first-party cookies (
_ex_id,_ex_ses) and the consent choice (_ex_consent). - Pages viewed, referrer, campaign (UTM) parameters, clicks, scroll depth, form submissions (not their contents unless the customer sends them as a lead), performance metrics and custom events.
- Device type, browser, operating system and screen size.
- Approximate location (country, state/region, city) derived from the request. IP addresses are not stored with analytics; a salted hash is used for abuse protection.
- Contact details a visitor chooses to submit (for example in a popup form), stored encrypted.
- Where the customer turns them on: click positions for heatmaps, and session recordings of a sample of visits: a rebuilt copy of the page and the visitor's mouse, scroll and click activity. Everything typed into form fields is masked before it leaves the browser; recordings are deleted after 30 days.
Visitors should contact the website owner to exercise their rights; we help our customers respond, including deleting a visitor's data on request.
3. Sharing
- Infrastructure and email providers that host the Service and deliver emails, under contracts requiring confidentiality and security.
- AI provider (Anthropic), only for organizations that switch on AI summaries: aggregate numbers such as visits, conversions, channels and page paths: never contact details, visitor ids or IP addresses.
- Integrations a customer enables (for example Google Analytics, Meta, HubSpot): data is sent only when the customer turns them on and only as configured.
- Authorities, where required by law.
- We do not sell personal data and do not use visitor data for our own advertising.
4. Where data is stored
Each customer chooses a data region (India, EU or US) or its own MongoDB database. Visitor data stays in that location. Dashboard account data is stored in our primary region. Where data crosses borders, we rely on safeguards permitted by the applicable law.
5. Retention
- Raw analytics are deleted automatically after the retention period of the customer's plan (typically 14 months or longer on higher plans).
- Consent records are kept for 5 years as legal proof.
- Audit logs are kept for about 13 months; buffered tracking data during a database outage for at most 72 hours.
- Account data is kept while the account is active and deleted or anonymised afterwards, except invoices and records we must keep by law.
6. Security
Encryption in transit (TLS) and at rest for sensitive fields, strict tenant isolation, two-factor authentication, rate limiting, least-privilege roles and audit logging. No system is perfectly secure; we will notify affected customers and authorities of a personal data breach as required by law.
7. Your rights
Depending on where you live (for example under India's Digital Personal Data Protection Act, 2023 or the EU GDPR) you can ask to access, correct or delete your data, withdraw consent, nominate a person to act for you, and complain to a data protection authority. Dashboard users can update most details in their account; for anything else, contact us below.
8. Cookies in the dashboard
The dashboard uses only strictly necessary cookies: a secure session cookie and a theme preference. We do not use advertising cookies in the dashboard.
Contact and grievances
Questions about these documents or your data: use the contact option inside your workspace.
Grievances can be raised at the contact above; we acknowledge them within 24 hours and resolve them within 15 days.