1. Who we are
Inoviq Labs (“Inoviq Labs”, “we”, “us”, “our”) is a B2B commerce studio based in India that designs and builds customised wholesale ecommerce websites. We are the controller of personal information processed through this website (inoviqlabs.com) and through the sales and project-delivery activities described below.
2. Scope of this policy
This policy covers personal information that:
- You provide to us directly — for example when you send us an email, message us on WhatsApp, fill in a contact form, or speak with us during a scoping call.
- We collect automatically when you visit the website (for example, basic technical and usage information).
- We process on behalf of our clients while delivering their B2B ecommerce projects.
This policy does not cover third-party websites linked from inoviqlabs.com (such as LinkedIn, WhatsApp, GitHub, or any of our integration partners). Please review their own privacy notices.
3. Personal information we collect
3.1 Information you give us
When you contact us about a potential project or during an engagement, we typically collect:
- Your name, job title, and the name of your company.
- Your business email address, phone number, or WhatsApp number.
- Information about your business and project (for example, the products you sell, your existing ERP or commerce system, your buyer base, and the problem you want us to solve).
- Any other information you choose to share with us in messages, calls, documents, or meetings.
3.2 Information collected automatically
When you visit inoviqlabs.com, our hosting provider and infrastructure may automatically receive:
- Your IP address and approximate location derived from it.
- Browser type, operating system, device type, and language.
- The pages you view, the date/time of the visit, and the referring URL.
This information is collected through standard server logs and is used to operate the site securely, to detect abuse, and to understand which content is useful to visitors. We do not run advertising trackers or third-party analytics scripts on this site at the date of this policy. If we add analytics in future, we will update this section before doing so.
3.3 Cookies and similar technologies
inoviqlabs.com does not set tracking cookies. We may use strictly necessary cookies or local storage to remember site preferences (such as a closed banner) and to support security features. Web fonts are loaded from Google Fonts, which means Google may receive technical information about your browser when fonts are requested. You can disable cookies in your browser settings; doing so will not prevent you from using the site.
3.4 Information about our clients' end-users
When we build a B2B ecommerce platform for a client, that platform may process personal information about the client's own buyers, sales representatives, and staff (for example, names, email addresses, order history, and pricing). In that context, our client is the data controller and Inoviq Labs acts as a data processor. The handling of that information is governed by the engagement contract between us and the client, not by this Privacy Policy.
4. How we use personal information
We use the personal information described above to:
- Respond to your enquiry and assess whether your project is a good fit.
- Prepare quotations, Statements of Work, and other commercial documents.
- Deliver and support the Services we have agreed to provide, including project communications, status updates, and invoicing.
- Operate, secure, monitor, and improve the website.
- Send occasional service-related emails (for example, contract documents, project updates, or invoices). We do not send unsolicited marketing emails.
- Comply with our legal, tax, and accounting obligations, and to defend or enforce our legal rights.
5. Legal bases for processing
Where applicable data-protection law requires it, we rely on the following legal bases:
- Performance of a contract — to deliver services you've engaged us for, or to take pre-contract steps such as preparing a quotation.
- Legitimate interests — to operate, secure, and improve our website and business, and to communicate with prospective clients who have reached out to us, in a way that does not override your rights.
- Legal obligation — to keep tax, accounting, and other records that we are legally required to retain.
- Consent — where you have given it, for example by voluntarily sending us a message or sharing materials about your project.
6. Who we share personal information with
We do not sell personal information. We share it only with:
- Service providers and infrastructure partners who help us operate our business — including hosting, cloud (such as AWS), email, calendar, source-control, and document-collaboration tools. These providers process personal information only on our instructions and under appropriate contractual protections.
- Professional advisers such as accountants and legal counsel, where reasonably necessary.
- Authorities when required by applicable law, court order, or to protect our rights, property, or safety, or that of others.
- Successors in the event of a merger, acquisition, or sale of business assets, subject to standard confidentiality protections.
7. International transfers
We are based in India. Some of the service providers we rely on (for example, cloud hosting, email, or productivity tools) may store or process personal information outside India. Where this happens, we take reasonable steps to ensure your information is protected through appropriate technical and contractual safeguards.
8. How long we keep personal information
We keep personal information for only as long as we need it for the purposes set out in this policy, including to deliver agreed Services, to maintain business and financial records, and to comply with legal obligations. Typical retention periods are:
- Sales enquiries that do not lead to an engagement: up to 24 months from last contact, then deleted or anonymised.
- Client engagement records (contracts, project communications, invoices): for the duration of the engagement and for as long as required by applicable accounting, tax, and limitation-period laws after the engagement ends.
- Server logs: a rolling short retention window, typically a few weeks, unless retained longer to investigate a security incident.
9. How we protect personal information
We apply reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, and destruction — including encrypted connections (HTTPS), access controls on internal tools, principle-of-least-privilege access to client data, and use of reputable cloud and infrastructure providers. No system is perfectly secure, however, and we cannot guarantee absolute security.
10. Your rights
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information where we no longer have a lawful basis to keep it.
- Object to or restrict certain types of processing.
- Withdraw consent at any time, where we rely on consent (this does not affect the lawfulness of processing carried out before withdrawal).
- Request a copy of your information in a portable format.
- Lodge a complaint with a data-protection authority in your jurisdiction.
To exercise any of these rights, please contact us using the details in section 13. We may need to verify your identity before responding, and we will respond within the timeframe required by applicable law.
11. Children
Our website and Services are intended for businesses and the professionals working for them, not for children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our business, technology, legal requirements, or the services we use. The “Last updated” date at the top of this page shows when the latest version became effective. For material changes, we will take additional steps to bring the update to your attention where appropriate.
13. Contact us
If you have a question about this Privacy Policy or about how we handle your personal information, please contact: