This Privacy Policy explains how Clavrit Digital Solutions Pvt. Ltd. ("Clavrit", "we", "us") collects, uses, stores, and protects personal data in connection with the Resorcia platform ("Service") available at resorcia.ai. This Policy applies globally to all customers and Authorised Users of the Service, regardless of where they are located.
The Service is designed exclusively for business customers. We do not knowingly collect personal data from individuals under the age of 18, nor is the Service directed at children.
For customers in the European Union or European Economic Area, this Policy is also intended to satisfy the transparency requirements under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
The data controller for personal data processed through the Service is:
We process the following categories of personal data solely to the extent entered into the platform by the Customer (Admin or Planner) or generated through use of the Service:
We do not collect or process any sensitive or special-category personal data as defined under GDPR Article 9 — including health data, racial or ethnic origin, political opinions, biometric data, or genetic data. We do not generate or store biometric templates, facial recognition data, or audio/video recordings. We do not use AI, machine learning, or large language model processing on Customer Data.
Tracker or screen capture functionality, if used, retains data only within the Customer's environment for the duration of the active subscription. No such data is transmitted to third-party systems.
We process personal data to provide, maintain, and operate the Resorcia platform. The legal basis under GDPR is the performance of a contract (Article 6(1)(b)) between Clavrit and the Customer, and where applicable, the legitimate interests of Clavrit in delivering a functional service (Article 6(1)(f)).
Name and email addresses are used for account creation, login, and role-based access control (RBAC). Legal basis: contract performance and legitimate interests.
We may access account or log data when assisting with support queries raised by the Customer. Legal basis: contract performance.
Audit logs and access records are maintained to detect unauthorised access or misuse. Legal basis: legitimate interests in system security (GDPR Article 6(1)(f)).
We may process and retain certain data where required to comply with applicable legal obligations. Legal basis: compliance with a legal obligation (Article 6(1)(c)).
To be entirely clear, Clavrit does not:
We retain Customer Data for the duration of the active subscription. Specifically:
All Customer Data is hosted and processed exclusively in India. The hosting infrastructure is provided by RackMonk, operating data centres in India. Backup and disaster recovery systems are also located within India.
No Customer Data is transferred to, processed in, or made accessible from the European Union, the United States, or any other country outside India. Clavrit does not currently offer customers the option to select an alternative hosting region.
Email notifications to users are sent via Clavrit's self-managed SMTP infrastructure. No third-party email delivery provider is used.
The only infrastructure sub-processor used by Clavrit in connection with the Service is:
| Sub-processor | Service | Location |
|---|---|---|
| RackMonk | Hosting and data centre services | India |
No other sub-processors, cloud providers, analytics platforms, or third-party integrations receive Customer Data. Clavrit will notify customers of any material changes to sub-processors prior to such changes taking effect.
Clavrit implements the following technical and organisational security measures:
Clavrit does not currently hold ISO 27001, SOC 2, or equivalent certifications. We are committed to maintaining appropriate security standards in line with the sensitivity of the data we process.
Where applicable under GDPR or other applicable data protection legislation, individuals whose personal data is processed through the Service may have the following rights:
Because Clavrit acts as a data processor on behalf of its business customers (who are data controllers), individual data subject requests should in the first instance be directed to the relevant Customer (the employer or organisation). If necessary, the Customer may raise a data subject request on the individual's behalf with Clavrit at [email protected].
EU/EEA data subjects also have the right to lodge a complaint with their local supervisory authority.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Customers will be notified of material changes via email or a notice within the platform prior to the changes taking effect. Continued use of the Service after such notification constitutes acceptance of the updated Policy.
For any questions, concerns, or requests related to this Privacy Policy or the handling of personal data, please contact: