1. Introduction
Bitloom Infoserv Pvt. Ltd. ("Bitloom," "we," "us," or "our") operates the Clienox CRM platform, accessible at https://clienox.com (the "Website"), the Clienox web application, and the Clienox Mobile application (collectively, the "Service" or "Clienox").
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use Clienox as an account holder, administrator, employee, field sales representative, or other authorized user. It also describes your rights and choices regarding your personal data.
By creating an account, downloading Clienox Mobile, or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. If you use Clienox on behalf of an organization, you represent that you have authority to accept this policy on behalf of that organization and to bind its users to these practices where applicable.
2. Scope & Applicability
This Privacy Policy applies to personal information processed through Clienox CRM, including field sales management, employee tracking, lead management, attendance management, and related business operations features offered on the Website and mobile applications.
Clienox is a business-to-business (B2B) platform. In most cases, your employer or the organization that provisions your account ("Customer Organization") controls the business data entered into Clienox, including leads, contacts, and employee activity records. Bitloom processes such data on behalf of the Customer Organization as a data processor. Bitloom acts as a data controller for account registration information, billing details, product analytics, and communications directly with account administrators.
This policy is designed to meet the disclosure requirements of the Google Play Store, Google Firebase services, the EU General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act, 2023 of India (DPDP Act), and Android background location policies.
3. Information We Collect
We collect information that you, your organization, or your device provides to us. The categories of information depend on how you use Clienox and the features enabled by your organization.
3.1 Account Information
- Full name
- Email address
- Mobile phone number
- Company name, business address, and other organization details
- Job title, role, and team assignment within your organization
- Login credentials and authentication tokens
3.2 CRM Data
Data entered or generated through Clienox in the course of sales and customer relationship management, including:
- Leads and lead source information
- Contacts and customer profiles
- Sales activities, meetings, and call logs
- Notes, comments, and internal communications
- Follow-up schedules, reminders, and task assignments
- Deal stages, pipeline status, and related commercial records
3.3 Location Data
When location features are enabled by your organization and you grant the required device permissions, Clienox Mobile may collect:
- Precise GPS location (latitude and longitude)
- Background location while the app is not in the foreground
- Attendance check-in and check-out location coordinates
- Field visit validation coordinates and timestamps
- Route tracking data during active work shifts
- Location history associated with field employee monitoring features
3.4 Device Information
- Device model and manufacturer
- Operating system name and version
- Application version and build number
- Firebase Cloud Messaging (FCM) notification token
- Device language, time zone, and network connectivity status
- Unique device identifiers required for app functionality and security
3.5 Notifications
- Push notification delivery tokens and subscription status
- Notification preferences and read/delivery status where supported
- Reminder notifications for follow-ups, tasks, attendance, and visits
3.6 Analytics and Diagnostic Data
We use Google Firebase and related tools to understand app performance and reliability. This may include:
- Firebase Analytics event data (feature usage, session duration, screen views)
- Firebase Crashlytics crash reports, stack traces, and error logs
- Firebase Performance Monitoring metrics (app start time, network latency)
- Aggregated and pseudonymized usage statistics
Analytics data is not used to sell your personal information or to deliver third-party advertising through Clienox.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: Creating and managing user accounts, authenticating users, and delivering CRM, attendance, lead management, and field sales features.
- Field workforce management: Enabling attendance tracking, visit verification, route monitoring, and sales activity validation for authorized field employees.
- Communications: Sending push notifications, reminders, service announcements, and security alerts.
- Customer support: Responding to inquiries, troubleshooting issues, and resolving technical problems.
- Security and fraud prevention: Detecting unauthorized access, protecting accounts, and maintaining platform integrity.
- Product improvement: Analyzing aggregated usage patterns, monitoring crashes, and optimizing performance through Firebase services.
- Legal compliance: Meeting applicable legal obligations, responding to lawful requests, and enforcing our terms.
- Billing and administration: Processing subscriptions, invoices, and account management for Customer Organizations.
5. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract performance: Processing necessary to provide Clienox under our agreement with you or your organization.
- Legitimate interests: Securing the platform, improving product quality, preventing misuse, and supporting business operations, balanced against your rights and expectations.
- Consent: Where required for background location access, push notifications, and certain optional features. You may withdraw consent through device settings or by contacting us, without affecting the lawfulness of processing before withdrawal.
- Legal obligation: Where processing is required to comply with applicable laws and regulations.
Under the DPDP Act, we process personal data for lawful purposes connected with the provision of Clienox, with your consent where required, and in accordance with applicable notice and rights provisions.
6. Background Location Usage
Clienox Mobile requests background location access only when your organization has enabled location-based workforce features and your role requires field tracking. Background location is not used for advertising, unrelated profiling, or purposes outside the core business functions described below.
Clienox uses background location only for:
- Employee attendance tracking, including check-in and check-out validation
- Field visit validation to confirm presence at customer or work sites
- Route tracking during active assigned work periods
- Sales activity verification for authorized field representatives
Background location collection begins only after you grant the "Allow all the time" (or equivalent) location permission on Android, or the corresponding background location permission on iOS where applicable. Your organization's administrator may enable or disable tracking features for your account.
Location collection stops when tracking is disabled by your organization or when you log out of Clienox Mobile. You may also revoke location permissions at any time through your device settings; however, doing so may prevent attendance, visit, and route features from functioning as intended.
We do not sell background location data. Location information is shared only with your authorized organization administrators and service providers that help us operate Clienox, as described in this policy.
7. How Location Data Is Used
Location data collected through Clienox is used strictly for legitimate business purposes authorized by your Customer Organization:
- Recording attendance events with geographic proof of check-in and check-out
- Validating that field visits occurred at designated customer or prospect locations
- Displaying route history and travel patterns to authorized managers for operational oversight
- Correlating location with CRM activities such as meetings, follow-ups, and site visits
- Generating reports on field productivity, territory coverage, and compliance with work schedules
- Detecting anomalies such as missed visits or unauthorized absence from assigned territories
Foreground location may be collected when you actively use location-dependent features within the app. Background location is collected only during enabled tracking periods as described in Section 6.
9. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
- Account information: Retained for the duration of your organization's active subscription and for up to 90 days after account closure to facilitate recovery, billing resolution, and legal compliance.
- CRM data: Retained according to your Customer Organization's subscription terms and configuration. Organizations may export or request deletion of CRM data subject to administrator authorization.
- Location and attendance data: Retained for the period configured by your organization, typically aligned with payroll, audit, and field operations requirements, and deleted or anonymized upon organization request or account termination in accordance with our data processing agreements.
- Analytics and crash data: Firebase analytics and diagnostic data are retained according to Google Firebase retention settings, generally between 14 and 60 days for event data unless configured otherwise, and up to 90 days for crash reports.
- Support communications: Retained for up to 24 months to resolve disputes and improve support quality.
When retention periods expire, we delete or irreversibly anonymize personal information using commercially reasonable methods.
10. Data Security
Bitloom implements administrative, technical, and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest on our servers and databases
- Role-based access controls and authentication for administrative access
- Regular security assessments and monitoring of infrastructure
- Secure development practices and access logging
- Employee confidentiality obligations and limited access on a need-to-know basis
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials and promptly notifying us of any suspected unauthorized access.
11. International Data Transfers
Bitloom Infoserv Pvt. Ltd. is based in India. Your information may be processed and stored in India and in other countries where we or our service providers maintain facilities, including countries that may have different data protection laws than your jurisdiction.
Where personal data is transferred from the EEA, UK, or Switzerland to countries without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms as required by applicable law.
12. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to legal and contractual limitations.
- Restriction: Request restriction of processing in certain circumstances.
- Portability: Request a portable copy of your data in a structured, commonly used format where technically feasible.
- Objection: Object to processing based on legitimate interests, including profiling, where applicable.
- Withdraw consent: Withdraw consent for processing that relies on consent, such as background location or push notifications, without affecting prior lawful processing.
- Complaint: Lodge a complaint with your local data protection authority. In India, you may contact the Data Protection Board of India once fully constituted under the DPDP Act.
If your organization is the data controller of CRM and employee data, workplace data requests may need to be directed to your employer or organization administrator. We will assist Customer Organizations in fulfilling data subject requests as required by our agreements and applicable law.
EEA and UK residents may contact us to exercise GDPR rights. We will respond within 30 days, or as otherwise required by applicable law.
13. Children's Privacy
Clienox is not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us at privacy@clienox.com and we will take steps to delete such information promptly.
14. Data Deletion Requests
You may request deletion of your personal data at any time. The process depends on your relationship with Clienox:
Individual users within an organization
Contact your organization's Clienox administrator to request deletion of your employee profile, CRM assignments, location history, and attendance records. Administrators can deactivate accounts and initiate data removal through the Clienox admin panel or by contacting our support team.
Account administrators and direct requests
Send a verified deletion request to privacy@clienox.com with the subject line "Data Deletion Request." Include your full name, registered email address, mobile number, organization name, and a description of the data you wish to delete.
We will:
- Acknowledge your request within 5 business days
- Verify your identity and authority to make the request
- Complete deletion or provide a substantive response within 30 days, or inform you of any extension required by law
- Confirm deletion of data from active systems, noting that residual copies may persist in encrypted backups for a limited period before automatic purging
Clienox Mobile app data
Logging out of Clienox Mobile stops active location collection immediately. Uninstalling the app removes locally stored app data from your device. Server-side data deletion requires a request through your administrator or to privacy@clienox.com.
We may retain certain information where required for legal compliance, dispute resolution, enforcement of agreements, or legitimate business records, and will inform you when such limitations apply.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or Service features. When we make material changes, we will post the updated policy on this page with a revised "Last updated" date and, where appropriate, notify account administrators by email or in-app notice.
Your continued use of Clienox after the effective date of an updated policy constitutes acceptance of the revised terms, except where further consent is required by law.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Bitloom Infoserv Pvt. Ltd.
- Product: Clienox CRM
- Website: https://clienox.com
- Mobile App: Clienox Mobile
- Privacy inquiries: privacy@clienox.com
For general product support unrelated to privacy, please use the contact options available on our website.