1. Introduction
Indirectix is a Procurement-as-a-Service platform operated by TishPrish Solutions Pvt. Ltd. (CIN: U82199KA2024PTC190633), a company incorporated in India (“Indirectix”, “we”, “our”, or “us”). We provide managed indirect procurement services – including sourcing, supplier management, spend analytics, and platform access – to manufacturing enterprises across India.
This Privacy Policy explains how we collect, use, share, store, and protect information relating to our clients, their authorised users, our registered suppliers, and visitors to our digital properties (collectively, ‘you’ or ‘Data Subjects’). By engaging with Indirectix — whether through our platform, a service agreement, or a supplier registration — you acknowledge this policy.
We are committed to handling personal and business-confidential data responsibly and in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable rules notified thereunder, as well as any contractual data-protection obligations agreed with our clients.
2. Scope of This Policy
This policy applies to:
â–¸ Client Personnel: Directors, procurement officers, finance teams, plant managers, and any other individuals authorised by a client organisation to access or use Indirectix services.
â–¸ Suppliers & Vendors: Proprietors, partners, directors, contact persons, and representatives of organisations registered in the Indirectix supplier network.
â–¸ Platform Users: Any individual accessing the ProcureFlow portal, MaintainFlow portal, or any Indirectix-hosted web application.
â–¸ Prospect & Marketing Contacts: Individuals who have expressed interest in Indirectix services via enquiry forms, LinkedIn, email, or events.
This policy does not govern data processed solely by our clients or suppliers within their own systems.
3. Data We Collect
3.1 Data Collected from Client Organisations
â–¸ Identity Data: Name, designation, employee ID, and authorisation level of client users.
â–¸ Contact Data: Business email address, office phone number, plant/site location.
â–¸ Transactional Data: Purchase requisitions, purchase orders, goods receipt notes, and invoice records created or managed through the platform.
â–¸ Spend & Category Data: Procurement categories, item masters, rate contracts, spend amounts, and supplier selections.
â–¸ Approval & Workflow Data: Digital approval trails, timestamps, comments, and audit logs generated by platform activity.
â–¸ Technical Data: IP addresses, browser type, session data, and login logs collected automatically during platform use.
3.2 Data Collected from Suppliers
â–¸ Business Identity: Company name, registered address, GSTIN, PAN, MSME registration (if applicable), and bank account details for payment.
â–¸ Contact Persons: Name, designation, email address, and mobile number of primary and secondary contacts.
â–¸ Commercial Data: Quotation submissions, pricing data, delivery performance records, and quality ratings.
â–¸ Compliance Documents: ISO certificates, statutory licences, and any other documents submitted during supplier onboarding or audits.
3.3 Data Collected Automatically
Our platform collects server logs, session identifiers, device fingerprints, and usage analytics to maintain security, diagnose errors, and improve service performance. No marketing cookies or third-party trackers are deployed without your knowledge.
3.4 Data We Do Not Collect
Indirectix does not intentionally collect sensitive personal data as defined under the DPDPA — including Aadhaar numbers, biometric identifiers, health data, financial account credentials, or data relating to children — unless specifically required by a client’s procurement process and explicitly consented to.
4. Legal Basis for Processing
We process personal data on one or more of the following grounds:
â–¸ Consent: Where you have given explicit consent, including during supplier registration and platform onboarding.
â–¸ Contractual Necessity: Where processing is required to fulfil our obligations under a client or supplier agreement.
â–¸ Legitimate Interests: For fraud prevention, platform security, service improvement, and commercial communications with business contacts.
â–¸ Legal Obligation: Where we are required to process or retain data under applicable Indian law (GST records, MSME payment tracking, audit requirements, etc.).
5. How We Use Your Data
We use the data described in Section 3 for the following purposes:
â–¸ Service Delivery: To operate the ProcureFlow and MaintainFlow platforms, manage procurement workflows, process purchase orders, and facilitate supplier communications on behalf of clients.
â–¸ Supplier Management: To onboard, evaluate, rate, and manage supplier relationships; to conduct RFQ processes; and to maintain approved vendor lists.
â–¸ Compliance & Audit: To generate immutable audit trails, support GST reconciliation, and comply with MSMED Act payment-term obligations.
â–¸ Analytics & Reporting: To produce spend analytics, savings reports, and category intelligence for clients.
â–¸ Platform Security: To detect and prevent unauthorised access, data breaches, and fraudulent activity.
▸ Communications: To send operational notifications, invoices, service updates, and — with consent — commercial communications about new Indirectix offerings.
â–¸ Legal Defence: To establish, exercise, or defend legal claims where necessary.
6. Sharing of Data
We share data only as necessary and as described below:
â–¸ Within the Client Engagement: Data shared by or about a client’s organisation is accessible only to that client’s authorised personnel and to Indirectix staff servicing that engagement.
▸ Supplier ↔ Client: Supplier quotation and performance data is shared with the relevant client for evaluation and decision-making. Client purchase order data is shared with the selected supplier to fulfil the order.
â–¸ Technology Subprocessors: Our platform is hosted on [cloud provider] infrastructure. Subprocessors are bound by data-processing agreements aligned with DPDPA requirements.
â–¸ Professional Advisors: Accountants, lawyers, and auditors acting under professional confidentiality obligations.
â–¸ Regulatory & Legal Authorities: Where disclosure is required by law, court order, or regulatory direction.
We do not sell, rent, or trade personal data to third parties for marketing purposes.
7. Data Retention
We retain personal and transactional data for as long as required by the applicable service agreement and by law. Our standard retention schedule is:
â–¸ Active Engagement Data: Retained for the duration of the client contract plus 7 years (aligned with GST record-keeping requirements).
â–¸ Supplier Records: Retained for 5 years post last transaction or post de-listing, whichever is later.
â–¸ Audit Logs: Retained for 7 years in an immutable, tamper-evident store.
â–¸ Marketing Contact Data: Retained until withdrawal of consent or 3 years of inactivity, whichever is earlier.
Upon expiry of the retention period, data is securely deleted or anonymised.
8. Data Security
We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration, or disclosure, including:
â–¸ Encryption: Data encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.
â–¸ Access Controls: Role-based access controls ensure that users can only access data relevant to their function. Multi-plant data is logically separated.
â–¸ Audit Trail: All procurement transactions are recorded in an SHA-256 immutable audit log.
â–¸ Incident Response: A documented breach response procedure is in place, including notification to affected Data Principals and the Data Protection Board as required under DPDPA.
â–¸ Vendor Due Diligence: Third-party subprocessors are assessed for security practices before onboarding.
No system can guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials and for notifying us immediately of any suspected unauthorised use.
9. Your Rights as a Data Principal
Under the DPDPA and our contractual commitments, you have the following rights with respect to your personal data:
â–¸ Right to Access: Request a summary of personal data we hold about you and the purposes for which it is processed.
â–¸ Right to Correction: Request correction of inaccurate or incomplete personal data.
â–¸ Right to Erasure: Request deletion of personal data where processing is no longer necessary, subject to legal retention obligations.
â–¸ Right to Grievance Redressal: Raise a complaint about how your data has been handled.
â–¸ Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact our Data Principal Grievance Officer (see Section 12). We will respond within 30 days of receiving a valid request.
10. Cookies and Tracking
Our platform uses only essential session cookies required for platform functionality and security. We do not use advertising cookies, behavioural tracking technologies, or third-party analytics SDKs that transfer personal data outside our platform boundary without your explicit consent.
11. Cross-Border Data Transfers
Indirectix operates primarily within India. Where any data is processed or stored outside India (for example, in connection with cloud infrastructure), such transfers are conducted in accordance with Section 16 of the DPDPA and any applicable Adequacy Regulations notified by the Central Government. We will update this section as the cross-border transfer framework under the DPDPA is operationalised.
12. Contact & Grievance Redressal
| Data Principal Grievance Officer Satyen Maladahiyar- Founder Director| TishPrish Solutions Pvt. Ltd. Email: support@indirectix.com Address: 307 Meenakshi Paradise, Apt PKM Layout, Hosapalya, Bommanahalli, Bangalore South, Bangalore, Karnataka, India – 560068 Response SLA: 30 days from receipt of written request |
If you are not satisfied with our response, you may approach the Data Protection Board of India once constituted under the DPDPA.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. Material changes will be communicated to active clients and registered suppliers via email or in-platform notification at least 14 days before they take effect. The current version will always be available on our website and platform.
© 2026 TishPrish Solutions Pvt. Ltd. All rights reserved. Indirectix is a brand of TishPrish Solutions Pvt. Ltd.
