Legal
Privacy Policy
Last updated: 24 September 2026
1. Overview
HVAC Flow ("Platform", "we", "us", or "our") is a cloud-based ERP platform purpose-built for HVAC contractors and MEP businesses, operated by Teqnodux (a software product company registered in India). This Privacy Policy explains what data we collect when you use HVAC Flow, why we collect it, how we store and protect it, and the rights you hold over it.
By creating an account or using any part of the Platform, you agree to the practices described in this Policy. If you do not agree, please discontinue use and contact us to delete your data.
2. Data We Collect
We collect data in two categories:
2.1 Account & Identity Data
When you register a tenant account we collect your name, business name, email address, phone number, and GST number (where provided). This data is used to create and identify your workspace.
2.2 Business Operational Data
Everything you enter into the Platform is your business data. This includes but is not limited to:
Sales leads, contacts, call logs, and pipeline stages (CRM module)
Opportunity records, room-wise load calculations, and Bill of Quantities (BOQ)
Request for Quotation (RFQ) submissions and vendor price comparisons
Purchase Orders, Goods Received Notes, and Goods Issue Notes
Delivery Challans and inventory stock records
GST-compliant invoices and receipt records
Preventive Maintenance Schedules (PMS) and Annual Maintenance Contracts (AMC)
Service visit logs and technician activity records
Custom fields, PDF templates, and workflow configurations
2.3 Usage & Technical Data
We automatically collect IP addresses, browser type, device identifiers, session timestamps, and feature-usage events to monitor platform health, detect abuse, and improve the product. This data is aggregated and never sold.
3. How We Use Your Data
We use collected data solely for the following purposes:
Delivering the service — Operating, maintaining, and improving the Platform for your tenant workspace.
Authentication & access control — Verifying user identity, enforcing role-based permissions, and maintaining session security.
Notifications — Sending service-related emails such as password resets, subscription reminders, PMS due-date alerts, and AMC renewal notices.
Support — Diagnosing issues and responding to support requests. Our team accesses your data only when explicitly required to resolve a reported problem.
Billing — Processing subscription payments and issuing invoices for your plan.
Legal compliance — Meeting obligations under Indian law, including the IT Act 2000 and applicable data protection regulations.
We do not use your business data to train machine learning models, run advertising, or benchmark against other tenants.
4. Multi-Tenancy & Data Isolation
HVAC Flow is a multi-tenant platform. Each business that signs up is provisioned as an isolated tenant with a dedicated database schema. This means:
Your data is logically separated from every other tenant at the database level.
No user from another tenant can ever query, view, or access your records.
All API requests are authenticated and tenant-scoped server-side before any data is returned.
Tenant provisioning, token issuance, and data access are governed by a strict middleware layer that validates identity on every request.
If you are on the Enterprise plan, additional data residency and dedicated infrastructure options may be available — contact us for details.
5. Data Storage & Security
Your data is stored on cloud infrastructure hosted in India. We apply the following security controls:
Encryption in transit — All data between your browser and our servers is encrypted via TLS 1.2+.
Encryption at rest — Database volumes and file storage (attachments, PDF exports) are encrypted at rest using AES-256.
Access control — Production database access is restricted to authorised engineers via VPN and multi-factor authentication. No direct public access is permitted.
Backups — Daily automated backups are retained for 30 days. Backups are stored in a geographically separate location.
Audit logs — Critical actions (login, data exports, user role changes) are logged with timestamps and user identifiers.
Despite these measures, no system is completely immune to breach. In the event of a security incident affecting your data, we will notify affected tenants within 72 hours of becoming aware of the breach.
6. Third-Party Services
We use a limited number of third-party services to operate the Platform. Each is bound by its own privacy policy and applicable data processing agreements:
Cloud infrastructure provider — Hosts our servers and databases in India.
Email delivery service — Used exclusively for transactional emails (OTPs, reminders, invoices). We do not send marketing emails without explicit consent.
Payment processor — Handles subscription billing. We do not store card numbers or banking credentials on our servers.
Error monitoring — Anonymised stack traces are logged to help us fix bugs faster. No personally identifiable data is included in error reports.
We do not sell, rent, or share your data with advertisers, data brokers, or any third party for commercial purposes.
7. Data Retention
We retain your data for as long as your account is active. Specific retention rules:
Active subscription — All data is retained and accessible in full.
Expired / cancelled subscription — Data is held for 90 days after expiry to allow reactivation or export. You will receive a reminder before permanent deletion.
Account deletion request — Upon a verified deletion request, all tenant data is permanently purged within 30 days. Backups containing your data are overwritten within the normal backup rotation cycle (up to 30 days).
Legal hold — Where required by law, certain records may be retained beyond the above periods.
You can export your data at any time from the Platform settings or by contacting support.
8. Your Rights
As a data subject, you have the following rights:
Access — Request a copy of all personal and business data we hold for your account.
Correction — Request correction of inaccurate or incomplete data.
Deletion — Request permanent deletion of your account and all associated data.
Portability — Export your operational data (leads, BOQs, invoices, etc.) in machine-readable format (CSV / JSON).
Restriction — Request that we restrict processing of your data in specific circumstances.
Objection — Object to processing where we rely on legitimate interest as the legal basis.
To exercise any of these rights, email us at info@teqnodux.com with the subject line "Data Rights Request — [your business name]". We will respond within 15 business days.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or platform features. When we do:
The "Last updated" date at the top of this page will be revised.
For material changes, we will notify active account holders via email at least 14 days before the change takes effect.
Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
We recommend reviewing this page periodically.
11. Contact Us
For any privacy-related questions, data requests, or concerns, contact us at:
Teqnodux
Email: info@teqnodux.com
Website: teqnodux.com
We take privacy seriously and will respond to all genuine enquiries within 15 business days.