Privacy Policy
In short: we collect what we need to run your account and the apps you use, we never sell personal data, and the records your organization keeps in our apps belong to your organization. This policy applies to every Reywin Solutions application, website, mobile app and API, and is written to meet India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
- 1. Who we are and our role
- 2. Information we collect
- 3. How we use it
- 4. Data your organization stores
- 5. Children's and health data
- 6. Who we share it with
- 7. Cookies
- 8. Where data is stored
- 9. How long we keep it
- 10. Security
- 11. Your rights
- 12. Grievance officer
- 13. Changes to this policy
1. Who we are and our role
Reywin Solutions ("Reywin", "we", "us") builds and operates cloud software for businesses, schools, clinics, restaurants and other organizations. We handle personal data in two different roles:
- As data fiduciary for information about the people who sign up for and use our Services: account holders, users, website visitors and people who contact us. This policy explains how we handle that information.
- As data processor for the records an organization keeps in our apps, such as its customers, students, parents, patients, staff and suppliers. The organization decides how that data is used and is the data fiduciary for it; we process it only on its instructions and under our Terms of Service. If your details are held by an organization that uses Reywin, please contact that organization first.
2. Information we collect
You give us
- Account details: name, email address, mobile number, password (stored only as a one-way hash), profile photo and preferences.
- Organization details: organization name, country, state, address, currency, time zone, tax registration such as GSTIN, and billing contacts.
- Payment details: plan, invoices and payment status. Card, UPI and bank details are entered directly with our payment gateway; we do not store full card numbers.
- Communications: messages, support requests, enquiries and feedback you send us.
From sign-in providers
If you choose to continue with Google or Microsoft, we receive your name, email address, whether the email is verified, a provider account identifier and, where available, your profile photo. We do not receive your provider password.
Collected automatically
- Usage and device data: IP address, browser and device type, operating system, pages and features used, dates and times of access, and referring links.
- Security logs: sign-in attempts, verification codes issued, permission changes and other audit events used to protect accounts.
- Cookies and similar technologies (see section 7).
3. How we use it
We use the information above, based on your consent or for the legitimate uses permitted by law, to:
- create and secure your account, verify your email or mobile number and let you sign in;
- provide, maintain and support the apps your organization subscribes to;
- process subscriptions, issue invoices and collect payments;
- send service messages such as verification codes, security alerts, invoices, reminders and notices about changes to the Services;
- detect, prevent and investigate fraud, abuse, spam and security incidents;
- understand how the Services are used, using aggregated data, so we can fix problems and improve them;
- send product news or offers, only where you have agreed. You can unsubscribe at any time;
- meet legal, tax, accounting and regulatory obligations and respond to lawful requests.
We do not sell or rent personal data, and we do not use the records your organization stores in our apps for advertising.
4. Data your organization stores
Organizations decide what records to keep in Reywin apps. Depending on the app, this can include customer and supplier contacts, invoices and payments, accounting entries, leads and deals, student, parent and staff records, attendance and fees, patient records and appointments, restaurant orders, and website content. We:
- keep each organization's data logically separate from every other organization's;
- access it only to provide the Services, to give support the organization asks for, to keep the Services secure, or where the law requires;
- delete or return it when the organization's subscription ends, as described in our Terms;
- help the organization respond to requests from the people its data is about.
5. Children's and health data
Our Services are meant for adults; we do not knowingly let anyone under 18 create an account. Schools using EduSmart may record information about students who are children. The school is responsible for obtaining verifiable consent from a parent or lawful guardian wherever the Digital Personal Data Protection Act, 2023 and its Rules require it. We process that data only for the school's educational and administrative purposes, never for tracking, behavioural monitoring or targeted advertising directed at children.
Clinics using our Clinic app may record health information. It is treated as confidential and processed only on the clinic's instructions. Where a clinic links records to the Ayushman Bharat Digital Mission, sharing happens only with the patient's consent through the ABDM consent framework.
6. Who we share it with
We share personal data only as follows:
- Within your organization: with the administrators and users your organization authorizes.
- Service providers who help us run the Services, under contracts that require confidentiality and security: hosting and infrastructure, email and SMS delivery, payment gateways such as Razorpay, sign-in providers (Google, Microsoft), messaging and error monitoring.
- Integrations you turn on, such as GST and e-invoice portals, ABDM, WhatsApp or other apps you connect, to the extent needed for that integration.
- Legal reasons: when required by law, court order or a government authority, or to protect the rights, safety or property of our users, the public or Reywin.
- Business transfers: to a successor in a merger, acquisition or sale of assets, which must continue to protect the data as this policy describes.
7. Cookies
We use essential cookies to keep you signed in, remember your selected organization and branch, protect forms against forgery, and remember display preferences. These are needed for the Services to work. Our sign-up and sign-in pages use a CAPTCHA service to block automated abuse, which may set its own cookies. We do not use cookies for third-party advertising. You can clear or block cookies in your browser, but the apps will not work without the essential ones.
8. Where data is stored
Data is stored on servers operated by our hosting providers. Where personal data is processed outside India, we do so only to the extent permitted under Indian law and with safeguards that protect it to the standard described in this policy.
9. How long we keep it
- Account information is kept while your account is active and deleted or anonymized within a reasonable time after you ask us to close it, unless we need it to meet legal obligations, resolve disputes or enforce our agreements.
- Organization records are kept for the life of the subscription and for 60 days after it ends so they can be exported, then deleted, subject to any longer period the law requires.
- Invoices and payment records are kept for as long as GST, income-tax and company laws require (commonly up to eight years).
- Security and access logs are kept for a limited period appropriate to their purpose.
- Backups are overwritten on a regular cycle; deleted data may persist in them until then.
10. Security
We use reasonable security practices consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including encrypted connections (HTTPS), hashed passwords, encryption of stored secrets, verification codes for new accounts, role-based access controls, separation between organizations, audit logs, regular backups and restricted staff access. No system is perfectly secure. If a personal data breach occurs, we will notify affected organizations, individuals and the Data Protection Board of India as the law requires.
11. Your rights
Subject to applicable law, you can:
- access a summary of the personal data we hold about you and how it is processed;
- correct, complete or update inaccurate data (most of this is in your profile settings);
- ask us to erase your personal data where it is no longer needed;
- withdraw consent you have given, for example to marketing messages, without affecting processing done before;
- nominate another person to exercise your rights if you die or become incapacitated;
- raise a grievance with us, and if it is not resolved, complain to the Data Protection Board of India.
To use these rights, email support@reywin.com from your registered address. We may need to verify your identity first. If your data was added by an organization that uses Reywin (for example your school, clinic or a supplier), we will refer your request to that organization and assist it.
12. Grievance officer
For any concern about how your personal data is handled, or about content on our Services, contact our Grievance Officer, Edwin Raj, at support@reywin.com with the subject line "Grievance", or write to the address below. We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. If you are not satisfied with our response, you may approach the Data Protection Board of India.
13. Changes to this policy
You may ask for this policy in English or any language listed in the Eighth Schedule to the Constitution of India by writing to support@reywin.com.
We may update this policy as our Services or the law change. We will post the updated version here with a new effective date and, for material changes, notify account administrators by email or in the app before they take effect.
Contact us
Reywin Solutions
185-2, Madurai Road Main
Sivagangai - 630561
Tamil Nadu
India
Support: support@reywin.com
Grievance Officer: Edwin Raj, support@reywin.com
Website: reywin.com