Data Privacy &
User Sovereignty.

This document details how Firdaus Creations Private Limited acts as a fiduciary for your sensitive enterprise and personal data within the KwikSuite ecosystem.

DPDP Act 2023 Compliant
GDPR Ready
ISO 27001 Certified Infrastructure
01

Legal Identity & Brand Scope

KwikSuite is a proprietary Unified Enterprise Operating System owned and operated by Firdaus Creations Private Limited ("FCPL", "The Company", "We", "Us").

Registered Address: H No. MCB Z-5 000574, Street No. 1/7A, Baba Farid Nagar, Near Bibi Wala Chowk, BATHINDA, Punjab, India - 151001.

This Privacy Policy serves as the definitive statement of our commitment to data protection under the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

02

Financial Intermediaries & Payout APIs

A core function of KwikSuite is the automated settlement of financial obligations, including employee payroll, vendor invoices, and expense reimbursements. To facilitate these transfers, we utilize high-security API integrations with India's leading financial institutions and payment aggregators.

AUTHORIZED PARTNERS

IDFC FIRST BANK
CASHFREE PAYMENTS
RAZORPAY

Fiduciary Data Restriction Clause

In our capacity as the technology orchestrator, KwikSuite relays specific financial data to Cashfree, IDFC FIRST Bank, and Razorpay solely for the execution of payouts.

Non-Negotiable Contractual Terms
  • No Secondary Use: These partners are legally and contractually prohibited from using any data shared via KwikSuite APIs for their own marketing, cross-selling, or analytics.
  • Strict Isolation: All relayed Personally Identifiable Information (PII) is isolated within the transaction tunnel and cannot be harvested by the partner for any purpose outside transaction reconciliation.
  • Zero Profiling: Our partners are bound to ensure no behavioral profiling or credit-scoring of KwikSuite users is performed based on transaction data.
03

Taxonomy of Data Collection

KwikSuite collects information that is essential for the management of human capital and enterprise workflows. This is categorized as:

1. Individual Identity Data (PII)

  • Full Legal Name, Date of Birth, and Gender.
  • Contact information (Personal/Professional Email, Verified Phone Numbers).
  • Residential and Permanent Address for statutory compliance (Form-16, etc.).

2. Sensitive Personal Data (SPD)

  • Financial Information: Bank Account Numbers, IFSC codes, and PAN (for TDS filings).
  • Biometric/Attendance Metadata: Geolocation tags for field force tracking (where enabled) and timestamp logs.
  • Health/Insurance data: Limited to records required for employee benefits and group insurance.

3. Organizational & Usage Data

  • Device Metadata: IP Address, Browser Fingerprint, OS Version, and Login Timestamps.
  • Operational Logs: Audit trails of every action performed within the CRM, HRMS, and Payroll modules.
04

Processing Logic & Lawfulness

We process data only when we have a lawful basis to do so, primarily:

Contractual Necessity

To fulfill the service agreement between FCPL and your organization.

Statutory Obligation

To comply with Labor Laws, Tax Laws (Income Tax Act), and RBI regulations.

05

Security Architecture

KwikSuite is built on a "Privacy-by-Design" philosophy. Our security stack includes:

  • Data Encryption: All data is encrypted at rest using AES-256 and in transit using TLS 1.3.
  • Logical Isolation: Multi-tenant architecture ensures that data from one organization is logically and physically separated from another.
  • Audit Persistence: We maintain immutable logs of all administrative data access for 7 years to facilitate forensic audits if required.

Your Statutory Rights

As a Data Principal under the DPDP Act 2023, you have the following rights:

Right to Access

Request a summary of personal data being processed by us.

Right to Correction

Correct inaccurate or incomplete information in our records.

Right to Erasure

Request deletion of data after the purpose of processing is completed.

Right to Withdraw Consent

Revoke consent for processing (subject to contractual/legal overrides).

07

Data Retention Policy

We retain data only as long as required to provide services or as mandated by law. Employee records are generally retained for the duration of employment plus 5 to 7 years to satisfy Labor Law and Tax audit requirements.

End of Formal Disclosure