Statutory Notice under DPDP Act 2023 & Google Play Policies

Privacy Policy & Data Principal Notice

How scornm collects, processes, encrypts, and protects digital personal data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, India).

Effective Date: September 2026 • Platform Owner: Pranav Soan / Digital Soan
DPDP Act (2023) Statutory Alignment Overview

scornm (accessible via https://scornm.com and the official scornm Android mobile application published on Google Play) is an enterprise Customer Relationship Management (CRM) platform operated from Raipur, Chhattisgarh, India. This policy serves as the official itemised notice under Section 5 and Section 6 of the DPDP Act 2023.

Data Fiduciary: scornm / Pranav Soan (for account holders & visitors)
Data Processor: scornm (for CRM leads processed on behalf of tenant teams)

1. Itemised Notice of Personal Data Collected (Section 5, DPDP Act)

In accordance with Section 5 of the DPDP Act, 2023, the following itemised table sets forth each category of digital personal data collected, the exact purpose for processing, and the statutory legal basis:

Personal Data Category Specific Purpose of Processing Legal Basis (DPDP Act)
Account & Profile Data
Full Name, Work Email, Mobile/WhatsApp Number, Password Hashes, Optional Profile Avatar, Two-Factor Authentication Tokens
Account provisioning, authenticating logins, enforcing Role-Based Access Control (RBAC), multi-tenant partition isolation, sending task reminders, and administrative security alerts. Consent (Sec 6)
Voluntary submission (Sec 7)
CRM Business & Lead Records
Lead Names, Contact Numbers, Deal Values, Pipeline Stages, Follow-up Notes, Dynamic Custom Fields, Form Submissions
Pipeline tracking, sales automation, round-robin lead distribution, call scheduling, and customer communication workflows configured by your team. Data Processing Agreement
Tenant acts as Data Fiduciary
Invoicing & Financial Data
Company Name, GSTIN, Billing Address, Payment Reference IDs (Cashfree/UPI), Invoice History
Subscription plan billing, generating statutory GST invoices, and maintaining accounting ledgers under Indian corporate and tax laws. Legal Obligation (Sec 7)
IT Act 1961 & CGST Act 2017
Technical & Telemetry Data
IP Addresses, Device Identifiers, FCM Push Notification Tokens, Login Timestamps, Browser User-Agents
Detecting unauthorized intrusions, preventing brute-force attacks, multi-tenant session persistence, and delivering real-time push notifications. Legitimate Use
Essential Platform Security

2. Consent & Ease of Withdrawal (Section 6, DPDP Act)

Consent is requested in clear, unambiguous language via an affirmative action (such as checking the terms checkbox during registration or selecting cookie preferences):

  • Unconditional & Specific: Your consent applies solely to the specific purpose of operating your CRM workspace and associated services.
  • Right to Withdraw Consent at Any Time: As mandated by Section 6(4) of the DPDP Act, the ease of withdrawing consent is comparable to the ease with which it was given.
  • How to Withdraw: You can withdraw consent at any time directly through your CRM settings, via our self-serve portal at delete-account.php, or by submitting an email to privacy@scornm.com.
  • Effect of Withdrawal: Upon receiving your withdrawal request, scornm will immediately halt data processing and instruct all third-party processors to do so, except where continued retention is required under statutory Indian tax or accounting laws.

3. Technical & Organizational Security Safeguards (Section 8, DPDP Act)

Under Section 8(5) of the DPDP Act, scornm implements state-of-the-art technical and organizational measures to protect personal data from unauthorized access, breach, or loss:

Application-Level Encryption (ALE AES-256-GCM): Sensitive customer contacts, phone numbers, and timeline notes are encrypted at the application layer using AES-256-GCM with a unique 12-byte cryptographic nonce and 16-byte authentication tag before being stored in the database.
  • Multi-Tenant Data Isolation: Every database query strictly asserts the verified team_id and user session context, preventing cross-tenant leakage or Insecure Direct Object References (IDOR).
  • Encryption in Transit: 100% of data traffic between clients (Web and Android Flutter App) and servers is encrypted using TLS 1.3 / SSL.
  • Password & Key Protection: Passwords are irreversibly hashed using modern PBKDF2/Argon2 algorithms with salted digests; plain-text passwords are never stored.
  • Role-Based Access Control (RBAC): Granular permissions restricting staff, managers, and tenant super-admins to their designated data scope.
  • Personal Data Breach Protocol: In the event of a security incident affecting digital personal data, scornm maintains a protocol to notify the Data Protection Board of India (DPBI) and all affected Data Principals promptly as prescribed under Section 8(6) of the DPDP Act.

4. Protection of Children's Personal Data (Section 9, DPDP Act)

In strict adherence to Section 9 of the DPDP Act:

  • scornm is an Enterprise CRM Tool: The platform is designed and intended exclusively for business entities, sales professionals, and adults aged 18 and older.
  • We do not knowingly collect, process, or maintain personal data belonging to children under 18 years of age without verifiable consent of a parent or lawful guardian.
  • We do not engage in any behavioral monitoring, tracking, or targeted advertising directed at children. If you believe a child has provided us with personal data, please contact our Grievance Officer for immediate permanent deletion.

5. Third-Party Data Processors & Integrations

We do NOT sell, rent, or monetize your personal or business data to third parties.

Data is transferred only to trusted Data Processors operating under strict confidentiality and DPDP-compliant obligations:

  • Hosting & Server Infrastructure: Hostinger / Cloudflare (encrypted server hosting & DDOS mitigation).
  • Payment Gateway: Cashfree Payments (PCI-DSS compliant payment processing for UPI, Net Banking, and Cards).
  • Transactional Communication: Resend (transactional email alerts) and Kapso / Meta Cloud API (WhatsApp notifications).
  • User-Configured Integrations: Google Workspace APIs (Sheets sync) and Meta Lead Ads (webhook ingestion) executed strictly according to user permissions.
Google API & AI Limited Use Policy Compliance
scornm strictly complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not use, transfer, or sell Google user data to create, train, or improve foundational or generalized artificial intelligence / machine learning models.

6. Statutory Rights of the Data Principal (Sections 11–14, DPDP Act)

Under Chapter III of the DPDP Act, every Data Principal whose personal data is processed by scornm possesses the following enforceable statutory rights:

Right to Access Information (Sec 11)

You have the right to request a summary of the personal data being processed by scornm, as well as the identities of all third-party Data Processors with whom your data has been shared.

Right to Correction & Completion (Sec 12)

You have the right to correct inaccurate or misleading personal data, complete incomplete personal data, and update your profile and business details at any time.

Right to Erasure (Sec 12)

You have the right to request permanent deletion of your account and associated CRM records through our dedicated Data Deletion Portal with OTP authentication.

Right to Nominate (Sec 14)

You have the right to nominate an individual who shall, in the event of your death or incapacity, exercise your Data Principal rights on your behalf.

To exercise any of these rights, visit https://scornm.com/delete-account.php or contact our Data Grievance Redressal Officer.

7. Data Retention & Mandatory Statutory Records

Personal data is retained only as long as necessary to fulfill the specified CRM service purpose or until consent is withdrawn.

  • Active Accounts: Retained while your subscription or free account remains active.
  • Deleted Accounts: Subject to a 30-day grace period for accidental deletion appeals, after which all operational records, lead databases, and attachments are permanently purged.
  • Mandatory Tax Records (Section 8(7), DPDP Act): Statutory accounting records (GST invoices, transaction references) are retained for 5 to 7 years as required under Section 44AA of the Indian Income-tax Act, 1961, Section 36 of the CGST Act, 2017, and the Companies Act, 2013.

8. Grievance Redressal Mechanism & Officer (Section 13, DPDP Act)

If you have any questions, concerns, requests, or complaints regarding the processing of your personal data, you may reach our designated Data Grievance Redressal Officer:

Designated Grievance Officer

Pranav Soan

Master Platform Owner & Data Protection Officer

Raipur, Chhattisgarh, India - 492001

Right of Escalation to the Data Protection Board of India (DPBI):
If your complaint is not resolved within 30 days or if you are unsatisfied with the resolution provided by our Grievance Officer, you have the statutory right under Section 13(3) and Section 18 of the DPDP Act, 2023 to file a formal complaint with the Data Protection Board of India (DPBI).

9. डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 — हिन्दी सारांश (Section 5(3))

scornm भारत के डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 (DPDP Act) का पूर्णतः अनुपालन करता है। हम आपका व्यक्तिगत डेटा (नाम, ईमेल, मोबाइल नंबर, बिज़नेस लीड्स) केवल आपकी स्पष्ट सहमति और सीआरएम सेवाओं के निष्पादन हेतु एकत्र करते हैं। आपका डेटा अत्याधुनिक AES-256-GCM एन्क्रिप्शन द्वारा सुरक्षित रहता है। आपके पास अपने डेटा को प्राप्त करने (Access), संशोधित करने (Correction), और पूर्णतः मिटाने (Erasure) का विधिक अधिकार है। डेटा संबंधी किसी भी शिकायत या अधिकार का उपयोग करने के लिए आप हमारे शिकायत निवारण अधिकारी (प्रणव सोन) से privacy@scornm.com पर संपर्क कर सकते हैं।