Privacy & Security

GDPR & Security Policy

How Nectar Infotel collects, uses, protects and retains personal data, and the rights available to you.

Our commitments

What this policy covers

This policy explains our approach to privacy, data protection and information security. If anything is unclear, please contact us.

Overview

This page is maintained by Nectar Infotel to answer common security and privacy questions about our website and services. It describes the personal data we process, the security controls we apply, and the rights available to individuals under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

The statements on this page reflect Nectar Infotel's current practices and the capabilities of the Lovable platform on which this site is built. It is not an independent certification, audit report or legal advice. If you need a Data Processing Addendum (DPA), signed security questionnaire or specific compliance attestation, please contact us directly.

Data controller

Nectar Infotel is the data controller for personal data collected through this website and our direct customer engagements.

Registered office: Pune, Maharashtra, India. Delivery centres: Indore, Raipur, Dubai and Africa.

For privacy and data-protection questions, please email privacy@nectarinfotel.com. For security incidents or vulnerability reports, please see the Reporting sections below.

What data we collect and why

We collect only the personal data needed to respond to enquiries, deliver services, support customers and comply with legal obligations. This typically includes contact details (name, email, phone, company), job-application information submitted through our careers form, and limited technical data such as IP addresses and browser information.

We do not sell personal data. We do not use it for automated decision-making that produces legal or similarly significant effects. Where we process data on behalf of customers, we act as a processor and follow the customer's documented instructions.

Security controls

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These measures include encrypted data transmission (TLS/HTTPS), access controls, role-based permissions, regular dependency and vulnerability reviews, and secure development practices.

Our quality and security management practices are supported by ISO/IEC 27001:2022 and ISO 9001:2015 certifications, and by CMMI-DEV V2.0 Maturity Level 5 software-development processes. Certification scope and reports can be requested through our sales or compliance team.

Hosting and subprocessors

This website is hosted on the Lovable platform, which provides managed infrastructure, edge delivery and backend services. Personal data may be processed by a small number of subprocessors engaged by Nectar Infotel or by the platform provider for hosting, analytics, email and support purposes.

A current list of subprocessors is available on request. We review subprocessors for appropriate security and privacy practices before onboarding them and include data-protection obligations in our contracts where required.

International transfers

Nectar Infotel operates delivery centres in India, the Middle East and Africa, and serves customers globally. Personal data may be transferred between these locations and to the jurisdictions where our subprocessors operate.

When personal data is transferred outside the European Economic Area (EEA), we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and adequacy decisions, where applicable, to help protect the rights of data subjects.

Cookies and analytics

We use cookies and similar technologies that are necessary for the site to function, and, where permitted, analytics cookies to understand how visitors interact with the site. You can manage cookie preferences through your browser settings.

Analytics data is aggregated and used to improve site performance and content. We do not use it to personally identify visitors unless they voluntarily submit a form or otherwise identify themselves.

Retention and deletion

We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law, contract or legitimate business needs. Enquiry data is generally retained for up to two years after the last interaction; application data is retained for the duration of the recruitment process plus a limited period for legal defence and record-keeping.

When data is no longer needed, we delete or anonymise it in a secure manner. You can request earlier deletion by contacting privacy@nectarinfotel.com, subject to any legal or contractual retention obligations.

Your rights

Depending on your location and applicable law, you may have the right to access, correct, delete or restrict processing of your personal data, to object to processing, to request data portability, and to withdraw consent.

To exercise these rights, please email privacy@nectarinfotel.com with enough detail for us to identify you and understand your request. We aim to respond within one month, or as required by local law.

Incident reporting

If you believe you have discovered a security issue that affects Nectar Infotel systems or data, please report it responsibly to security@nectarinfotel.com. Include a clear description, steps to reproduce, and any evidence you can share safely.

We will acknowledge receipt, investigate in good faith, and work to resolve verified issues promptly. We do not take legal action against security researchers who follow responsible disclosure practices.

Changes to this policy

We may update this GDPR and Security Policy from time to time to reflect changes in our practices, services or legal requirements. The updated version will be posted on this page with a revised date.

Last updated: July 2026.

Questions or requests?

For privacy questions, data-subject requests, DPA enquiries or security incident reports, please reach out to our team.

Disclaimer: This page is app-owned editable content maintained by Nectar Infotel. It is not an independent legal certification, audit report or guarantee of compliance with any specific regulation. Platform features described are provided by Lovable and are subject to the platform's own terms and capabilities. Shared responsibility applies: Nectar Infotel is responsible for its data, content and business practices, while the platform provider is responsible for the underlying infrastructure and services it operates.