Welcome to CenterManager ("we", "our", "us"), operated by CenterManager Technologies Private Limited, registered in India. This Privacy Policy explains how we collect, use, disclose and safeguard your personal data when you access or use the CenterManager platform (centersaas.test) and any related services, mobile applications or integrations (collectively, the "Service").
By using CenterManager you agree to the practices described in this policy. If you do not agree, please discontinue use of the Service immediately.
Introduction
CenterManager is a multi-tenant SaaS platform designed for service center management in India. Our platform is used by three types of users: Super Admins (our team), Center Admins (business owners who register a center), and Operators (staff added by Center Admins).
This policy applies to all users of the platform regardless of their role. We process personal data only as necessary to deliver the Service and to comply with applicable law, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
Our registered office is at: 4th Floor, Tech Park, MG Road, Bangalore — 560 001, Karnataka, India. Our Data Protection Officer can be reached at privacy@centersaas.test.
Information We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
- Account Data: name, email address, phone number, role, and password (hashed) when registering or being added as an operator.
- Center Profile: business name, address, subscription plan, and service types configured by Center Admins.
- Task Data: task descriptions, assignments, completion status, carry-over records.
- Attendance Records: daily check-in status (Present / Half-Day / Absent) per operator.
- Salary Information: monthly base salary, calculated pay based on attendance.
- Documents: files uploaded through the Client Document Upload portal (scanned IDs, forms, etc.).
- Contact Form: name, email, message and inquiry type submitted via our website.
2.2 Information Collected Automatically
- Log Data: IP address, browser type, pages visited, timestamps, referrer URL.
- Session Data: login sessions stored in our encrypted session database.
- Device Information: screen resolution, operating system, browser version — used for UI rendering only.
2.3 Information We Do Not Collect
We do not collect payment card numbers, bank account details, Aadhaar numbers, or biometric data. Payments (if applicable) are handled by third-party processors who are PCI-DSS compliant.
| Data Category | Examples | Source |
|---|---|---|
| Identity Data | Name, email, phone | You (registration) |
| Operational Data | Tasks, attendance, salary | You & your operators |
| Technical Data | IP, browser, session ID | Automatically |
| Document Data | Uploaded files via portal | Your clients / operators |
| Communication Data | Contact form messages | You (contact page) |
How We Use Your Data
We use the personal data we collect for the following purposes:
- Service Delivery: create and manage accounts, enable task management, attendance tracking, and salary computation.
- Subscription Management: activate, suspend, or modify your center subscription plan.
- Communication: send transactional emails (password resets, plan expiry notices), respond to support requests.
- Security & Fraud Prevention: detect unauthorised access, enforce role-based access control, audit logs.
- Analytics & Improvement: aggregated, anonymised usage patterns to improve features — we never sell this.
- Legal Compliance: retain records as required under applicable Indian law.
We do not use your data for targeted advertising, behavioural profiling, or any automated decision-making that produces legal or significant effects without human review.
Legal Basis for Processing (DPDP Act 2023)
We process your personal data under the following lawful grounds as defined by the Digital Personal Data Protection Act, 2023:
- Consent: you have provided explicit, free, informed consent during registration.
- Contractual Necessity: processing is necessary to perform the subscription contract and deliver the Service you subscribed to.
- Legal Obligation: we may process data to comply with court orders, government requests, or statutory requirements.
- Legitimate Interests: security monitoring, fraud prevention, and product improvement — balanced against your privacy rights.
You may withdraw consent at any time by contacting us at privacy@centersaas.test. Withdrawal will not affect the lawfulness of any processing carried out before withdrawal.
Data Sharing & Disclosure
We are not in the business of selling or renting your personal data. We share data only in the following limited circumstances:
5.1 Within the Platform
Data is scoped to the appropriate panel. Operators see only their own tasks and attendance. Center Admins see all data within their center. Super Admins can access all centers for support and administration purposes.
5.2 Trusted Service Providers
- Hosting & Infrastructure: cloud servers hosted in India (or with data residency guarantees) — bound by strict data processing agreements.
- Email Delivery: transactional email providers for password resets and notifications.
- Payment Processors: if applicable, PCI-DSS certified third parties — they receive only the data necessary to process your payment.
5.3 Legal Requirements
We may disclose data if required by law, regulation, court order, or governmental authority, or to protect the rights, property, or safety of CenterManager, our users, or the public.
We never share, sell, or rent your personal data to brokers, advertisers, or analytics platforms. Any third party we engage is bound by a Data Processing Agreement aligned with Indian data protection law.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account & Profile Data | Duration of active subscription + 90 days | Account recovery window |
| Task & Attendance Records | 2 years from creation | Operational audit trail |
| Salary Records | 7 years | Tax & labour law compliance |
| Uploaded Documents | As configured by Center Admin (max 5 years) | Regulatory compliance |
| Support / Contact Messages | 2 years | Customer service history |
| Server Logs | 90 days | Security monitoring |
After the applicable retention period, data is securely deleted or anonymised. You may request earlier deletion — see Your Rights.
Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction:
- Encryption in Transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2+.
- Password Hashing: all passwords are one-way hashed using bcrypt (cost factor 12) — we never store plaintext passwords.
- Role-Based Access Control: three distinct panels with scoped permissions ensure operators cannot access other operators' data.
- Session Security: sessions are stored in an encrypted database and invalidated on logout.
- CSRF Protection: all form submissions are protected with Laravel's built-in CSRF tokens.
- Regular Backups: encrypted daily backups with 30-day retention.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Please notify us immediately at security@centersaas.test if you suspect a security breach.
Your Rights
Under the Digital Personal Data Protection Act, 2023 and applicable Indian law, you have the following rights regarding your personal data:
📋 Right to Access
Request a copy of the personal data we hold about you and how it is used.
✏️ Right to Correction
Request correction of inaccurate or incomplete personal data.
🗑️ Right to Erasure
Request deletion of your data when it is no longer necessary, subject to legal retention obligations.
🚫 Right to Withdraw Consent
Withdraw your consent to processing at any time without affecting prior lawful processing.
📦 Right to Portability
Receive your data in a structured, machine-readable format (CSV / JSON) upon request.
🛑 Right to Object
Object to processing based on legitimate interests, including for direct marketing.
To exercise any of these rights, email privacy@centersaas.test with the subject line "Data Rights Request". We will acknowledge within 72 hours and respond fully within 30 days. We may ask you to verify your identity before processing the request.
If you are unsatisfied with our response, you may lodge a complaint with the Data Protection Board of India once it is constituted under the DPDP Act, 2023.
Cookies & Tracking
We use cookies and similar technologies to operate and improve our Service. We do not use third-party advertising cookies or behavioural tracking pixels.
| Cookie Name | Type | Purpose | Expiry |
|---|---|---|---|
centersaas_session | Essential | Maintain login session | Session |
XSRF-TOKEN | Essential | CSRF attack prevention | Session |
remember_web_* | Functional | "Remember Me" login (optional) | 30 days |
Essential cookies cannot be disabled as they are required for the platform to function. You can manage cookies in your browser settings; however, disabling session cookies will prevent you from logging in.
Children's Privacy
CenterManager is a business-to-business platform intended for use by adults operating or working in service centers. We do not knowingly collect personal data from individuals under the age of 18 years.
If you believe a minor has provided us with personal data without appropriate consent, please contact us immediately at privacy@centersaas.test and we will take prompt steps to delete such data.
Third-Party Links
Our platform or website may contain links to third-party websites or services (e.g., payment gateways, social media). These external sites operate under their own privacy policies, which we do not control.
We recommend reviewing the privacy policy of any third-party site you visit. CenterManager is not responsible for the privacy practices of external sites and services.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or product features. When we make material changes we will:
- Update the "Last Updated" date at the top of this page.
- Display a prominent notice within the CenterManager platform dashboard for at least 14 days.
- Send an email notification to the registered Center Admin email address.
Your continued use of the Service after the effective date constitutes acceptance of the revised policy. If you do not agree with the changes, please contact us to discuss your options or close your account.
Contact Us & Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
🔏 Data Protection Officer
CenterManager Technologies Pvt. Ltd.
4th Floor, Tech Park, MG Road, Bangalore — 560 001
Email: privacy@centersaas.test
Response time: within 72 hours