Privacy Policy
1. Introduction and Scope
Green Call Technology Private Limited (“GREEN CALL”, “GreenCall”, “we”, “our” or “us”) is committed to protecting personal information and respecting the privacy of individuals who interact with our organization, websites, products, software platforms, mobile applications and services.
This Privacy Policy explains how GREEN CALL may collect, use, store, protect, disclose, transfer and dispose of personal information in connection with our business activities.
This Privacy Policy applies to, as relevant:
Visitors to GREEN CALL websites and digital properties; prospective customers, customers and their authorized representatives; users and administrators of GREEN CALL products, SaaS platforms, web applications and mobile applications; individuals whose data is processed by GREEN CALL while delivering contracted software development, managed IT, BPO, call centre, implementation, support or other services; job applicants and other individuals who voluntarily submit information through approved channels; and employees, consultants, contractors, vendors and service providers where their information is processed in connection with a business relationship.
This policy covers the lifecycle of personal information, including collection, use, storage, access, sharing, retention and secure disposal.
2. Definitions
Personal Data / Personal Information – Information relating to an identified or identifiable individual.
Data Principal / Data Subject – The individual to whom personal data relates.
Data Fiduciary / Controller – Depending on the processing context, GREEN CALL may act as a data fiduciary/controller or as a processor/service provider on behalf of a client.
Processor / Service Provider – A party that processes personal information on behalf of another entity under an authorized contractual arrangement.
Consent – A free, informed, specific and unambiguous agreement to the processing of personal information, where consent is the applicable basis.
3. Information We May Collect
Business and organization information, including organization name, business profile, address, official contact information, registration or tax identifiers where applicable, and contractual or billing information.
Authorized representative and user information, including name, designation, organization details, official email address, mobile number, login credentials and role/access information.
Website, application and system usage information, including IP address, device/browser information, login activity, access logs, usage history, technical logs, diagnostic information and security events.
Information processed through products and services, including information supplied by customers or authorized users that is necessary for the contracted service. Depending on the product or service, this may include employee, user, customer, applicant, operational, transactional, communication or other business information.
Mobile application permissions such as camera, location, storage or telephone/device-related access may be requested only where required for application functionality and subject to applicable law and platform requirements.
4. Purpose of Processing
GREEN CALL may collect and process personal information for legitimate business and operational purposes, including responding to enquiries, demo requests, quotations and communications; customer onboarding and account administration; delivery of software development, SaaS, implementation, managed IT, BPO, call centre and related services; operation and improvement of websites, products and applications; customer support; authentication and access management; reporting and analytics; contract administration and billing; recruitment-related activities; fraud prevention and security; and compliance with legal, regulatory and contractual obligations.
Personal information will be processed for purposes communicated at the time of collection or otherwise permitted or required under applicable law.
5. Legal Basis and Consent
Where applicable, GREEN CALL processes personal information on the basis of consent where required, performance of a contract, compliance with legal or regulatory obligations, and legitimate business, security and operational purposes where permitted by applicable law.
Where processing is based on consent, individuals may seek to withdraw consent through the relevant account, support channel or contact process, subject to applicable legal, contractual, security and retention requirements.
6. Data Minimization and Accuracy
GREEN CALL seeks to collect and process only information reasonably necessary for the relevant purpose. Customers and users are encouraged to keep information accurate and up to date. Where GREEN CALL processes information on behalf of a customer, the customer remains responsible for ensuring that the information provided is lawfully collected and appropriately maintained, except where otherwise agreed in writing.
7. Data Sharing and Disclosure
GREEN CALL follows a no-selling and no-unauthorized-sharing approach to personal information.
Personal information may be shared only as reasonably necessary with authorized customer organizations and representatives; authorized employees, consultants or teams with a legitimate business need; approved cloud, communication or other service providers; professional advisers, auditors or authorities where required; and other parties where permitted by law or required for a lawful corporate transaction.
Where feasible and appropriate for analytics and internal reporting, personal information may be masked, aggregated or anonymized.
8. Information Security Measures
GREEN CALL implements technical and organizational safeguards appropriate to the nature of the information and services involved. Controls may include HTTPS/TLS protection for web and API communications; encryption of sensitive information in transit and, where appropriate, at rest; role-based access control and least-privilege principles; additional authentication controls for privileged access where implemented; network, firewall, web application and intrusion-prevention controls; centralized logging and monitoring; vulnerability assessment and security reviews; secure software development and change management; backup and recovery controls; and incident response and escalation procedures.
GREEN CALL seeks to align relevant operational and security practices with applicable information-security and privacy requirements, including ISO/IEC 27001-aligned practices, GDPR considerations where applicable, and India's Digital Personal Data Protection - 2023 framework.
9. Access Control and Internal Authorization
Access to personal and business information is restricted based on role, authorization and legitimate business necessity. Administrative and infrastructure access is subject to internal approval and access-control procedures and may be periodically reviewed.
10. Data Retention
GREEN CALL retains personal information only for as long as reasonably necessary for the purposes for which it was collected or processed, including service delivery, contractual obligations, dispute management, security and legal or regulatory requirements. Retention periods may vary by data type, contractual commitments, system architecture and applicable law.
11. Secure Disposal of Data
Personal information and records that are no longer required may be securely deleted or destroyed using appropriate methods intended to prevent unauthorized recovery, taking into account active systems, archives and applicable backup retention cycles.
12. Cookies and Similar Technologies
GREEN CALL websites and digital services may use cookies and similar technologies for maintaining secure sessions and authentication, supporting essential functionality, improving performance and user experience, and understanding usage and operational performance.
Where legally required, applicable cookie notices or consent mechanisms may be provided.
13. Rights of Individuals
Subject to applicable law and the processing context, individuals may have rights relating to their personal information, including requests for access, correction, updating, withdrawal of consent, grievance handling, deletion or deactivation, restriction or objection to certain processing, and data portability where applicable.
Where GREEN CALL acts as a processor/service provider on behalf of a customer, relevant requests may need to be directed to the customer that controls the information.
14. Incident and Personal Data Breach Management
GREEN CALL maintains processes for managing security incidents. In the event of a relevant incident or personal data breach, actions may include investigation, containment, remediation, impact assessment, evidence preservation, notification to customers, affected individuals or authorities where required, and corrective and preventive action.
15. Third-Party and Vendor Management
Vendors and service providers that process personal information on behalf of GREEN CALL may be subject to contractual confidentiality, data-protection and security obligations. They may process information only for defined purposes and may be reviewed based on service risk.
16. International or Cross-Border Processing
Where personal information is processed across jurisdictions or outside India, GREEN CALL will seek to apply appropriate contractual, technical or organizational safeguards consistent with applicable law and the relevant processing arrangement.
17. Compliance with Applicable Laws and Standards
GREEN CALL seeks to comply with applicable privacy and data-protection laws relevant to its operations and services. Depending on the processing context, this may include India's Digital Personal Data Protection Act, 2023 and related applicable rules when in force, applicable provisions of the GDPR where relevant, contractual privacy obligations, and recognized information-security practices.
This Privacy Policy does not replace project-specific, customer-specific or statutory obligations that may apply under a separate agreement.
18. Client and User Responsibilities
Customers and authorized users are expected to provide only information they are legally authorized to provide or process; obtain any notices, permissions or consents required by law; maintain appropriate access controls; use GREEN CALL products and services in accordance with applicable law and contractual terms; and promptly notify GREEN CALL of relevant security or privacy incidents where required by contract.
19. Policy Enforcement
Violation of applicable privacy, security or data-handling requirements by employees, contractors, partners or other authorized parties may result in disciplinary action, suspension of access, contractual remedies or other appropriate action.
20. Changes to this Privacy Policy
GREEN CALL may update this Privacy Policy from time to time to reflect changes in law, technology, security practices, business operations or services. The latest version may be published through GREEN CALL's official website or other appropriate communication channels.
21. Contact for Privacy Requests and Grievances
Privacy & Compliance Team
Green Call Technology Private Limited
Corporate Office: A-43, Sector-67, Noida, Uttar Pradesh – 201301, India
Email: reachus@greencall.in
Website: www.greencall.in
22. Acknowledgement
By accessing GREEN CALL websites, using GREEN CALL products or services, submitting information to GREEN CALL, or otherwise interacting with GREEN CALL in a context where this Privacy Policy applies, you acknowledge that your information may be processed in accordance with this Privacy Policy and applicable law.