Privacy Policy
Effective 28 August 2026 · Last updated 28 August 2026 · Version 1.0
1. Who we are
This Privacy Policy explains how KONOFT (“KONOFT”, “we”, “us”), which operates ITEMZAP (the “Service”, at itemzap.com), collects, uses, shares and protects personal data. Our registered office is at Coimbatore, Tamil Nadu, India.
For personal data we handle for our own purposes — your account, billing, service email — we act as a Data Fiduciary / Controller. For personal data your organisation uploads about its people or assets, we act as a Data Processor on your instructions; see section 12.
Representatives in the EU and UK. Because we offer the Service to people in the European Economic Area and the United Kingdom without being established there, we are required to appoint representatives under Article 27 of the EU and UK GDPR. These appointments are in progress and this section will name them as soon as they are made. In the meantime, write to privacy@itemzap.com and we will deal with your request directly.
2. Scope
This policy applies to visitors, individual users, and business customers and their authorised users, worldwide. Where a stricter local law grants you additional rights — GDPR in the EU/UK, DPDP in India, LGPD in Brazil — we honour those rights for users in that jurisdiction.
3. The personal data we collect
- Account data: name, email, phone, password (stored only as a hash), company, role, workspace.
- Profile and team data: job title, branch or department, permissions.
- Postal address — address lines, city, state and postal code, collected at sign-up.
- GSTIN or tax identifier, where you register a business account. We also read GSTINs off the bills you upload.
- Asset and operational data you enter: asset records, photographs, and documents such as invoices and warranty cards. Uploaded bills routinely contain personal data — names, addresses, GSTINs — belonging to you, your staff or your vendors. That data is yours and you control it.
- Billing data: your plan and, once paid plans launch, transaction records. We hold no card details today and will never receive or store full card numbers — when payments launch they will be handled entirely by a regulated payment provider, named here before any of your data reaches it.
- Technical data: IP address, device and browser, log data and cookies. We do not currently run any product-analytics or advertising tracking.
- Communications: support requests, email, feedback.
- Consent records: the fact, time and document version of your agreement to our terms, kept as proof of valid consent.
We do not knowingly collect data from anyone under 18 — see section 10.
4. Why we use it, and on what basis
| Purpose | Basis (GDPR) / ground (DPDP) |
|---|---|
| Create and run your account | Performance of contract / consent |
| Provide the features you use, including bill scanning | Performance of contract |
| Billing and payments | Contract / legal obligation |
| Security, fraud prevention, audit logs | Legitimate interests / legal obligation |
| Support and service communications | Contract / legitimate interests |
| Product improvement, using aggregated non-identifying information | Legitimate interests |
| Marketing email (you can opt out at any time) | Consent |
| Legal compliance and defence of claims | Legal obligation / legitimate interests |
Automated processing and AI. When you upload a bill, its image is sent to Google Cloud Vision to be converted into text, and that text is sent to Anthropic to identify fields such as product, price, purchase date and warranty period. Results are always presented to you for confirmation, and nothing is written to your asset or warranty records until you confirm it. A low-confidence reading is flagged for your review. The raw text read from the bill is stored against the document as soon as the scan finishes, so there is a record of what was read. We do not use your content to train any model, and no decision with a legal or similarly significant effect on you is made solely by automated means.
5. Cookies
We use strictly-necessary cookies to keep you signed in and make the application work. We do not use advertising or analytics cookies. You can manage cookies through our banner and your browser settings. Our pages load their fonts from our own servers, so no request goes to a font provider when you visit.
6. How we share data
We share personal data only with the following, and we do not sell it. They act on our instructions and may not use your data for their own purposes.
No payment processor is listed, because we are not yet taking payments. When we begin, the provider will be named here and on the checkout page before your first charge. A payment provider decides for itself how it handles card data and is responsible for that in its own right, under its own privacy policy.
| Sub-processor | Purpose | Processing region |
|---|---|---|
| Supabase | Database, authentication and file storage | Singapore / EU |
| Vercel | Application hosting and content delivery | Global edge |
| Optical character recognition on uploaded bills (Cloud Vision); sign-in with Google | Global | |
| Anthropic | Reading structured fields from bill text; asset classification and valuation suggestions; AI-assisted lookup of service centres, which sends the asset brand, category and your city | United States |
| Resend | Transactional and notification email | United States |
| Sentry | Error monitoring and diagnostics | European Union |
- Within your organisation and linked companies, as your administrators configure the sharing and asset-transfer features.
- External advisors and auditors your administrators invite — for example a chartered accountant given read-only access to your tax records, or an external auditor invited to conduct a stock audit. These people are outside your organisation and are invited by you, not by us.
- Legal and safety: where required by law or court order, or to protect rights and safety.
- Business transfers: in a merger or acquisition, subject to this policy.
6a. If your details appear on someone else’s bill
Our customers upload purchase invoices, and those documents often name other people — a vendor’s proprietor, a delivery contact, an engineer who signed a service report. If that is how your data reached us, you did not give it to us and you may never have heard of us, so this section is for you.
We hold that information only as part of the document our customer uploaded, and only to provide the Service to them. We do not use it to contact you, build a profile of you, or market anything. The customer who uploaded the document controls it — if you want it corrected or removed, write to privacy@itemzap.com and we will help you reach them, and act ourselves where the law requires us to.
7. International transfers
We are based in India and some of the providers above process data outside it, as the table shows. For EU and UK data we rely on Standard Contractual Clauses (India has no adequacy decision), and on equivalent contractual safeguards elsewhere. Copies are available on request at privacy@itemzap.com.
8. How long we keep it
We do not yet run automated deletion on a timetable. We would rather say that than publish a schedule we do not keep. In practice:
- Account data — kept while your account is open. To have it erased, write to privacy@itemzap.com and we action it within 30 days. Your name, email, phone, address and profile photo are removed and your sign-in is destroyed. What happens to files you uploaded depends on whether you share a workspace. If you are the only person in yours, the workspace is closed and your uploaded documents and photos are deleted from storage. If others share it, those records belong to that organisation and remain with it, no longer linked to your name — to have them removed as well, ask the workspace owner. We are building a self-service control for erasure; until it ships, email is the route and it is a real one.
- Billing and tax records — at least 8 years, because the Companies Act, 2013 requires it.
- Asset and operational data — until you or your organisation deletes it, or your contract ends.
- Audit logs — our audit log is append-only and tamper-evident by design: a database trigger rejects every update and delete, so no part of ITEMZAP can alter or remove entries once written. This means historical entries keep the name, email and user ID recorded at the time of the action, and erasing your account does not remove them. We keep them because an audit trail that can be rewritten is not an audit trail, and because asset and compliance records depend on it. They are never used to contact you or to build a profile.
- Completed calibration records — retained at least 7 years where AERB, NABH or Factory Act rules require it. These cannot be deleted on request.
If you want data removed sooner, write to privacy@itemzap.com and we will do it manually.
9. Your rights
Subject to your local law you may access your data, correct it, erase it, withdraw consent, object to or restrict processing, request portability, and — under DPDP — nominate someone to exercise these rights for you. Write to privacy@itemzap.com; we respond within 30 days. You may also complain to your regulator — in India, the Data Protection Board; in the EU, your supervisory authority.
10. Children
ITEMZAP is not intended for anyone under 18 and we do not knowingly process children’s data. If you believe a child has provided data, write to privacy@itemzap.com and we will delete it.
11. How we protect data
We apply security safeguards proportionate to the risk: encryption in transit, row-level access controls in the database, audit logging of changes, and least-privilege access. Your password is handled by our authentication provider and stored only as a hash — we never see it.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board and, where the law requires, affected individuals, within the timeframes the law sets, counted from when we become aware of it. Report a suspected security issue to privacy@itemzap.com.
One thing you should know: profile photos are stored in a public bucket, which means anyone holding the direct URL can view them. Do not upload a photo you would not want served publicly.
12. Business customers
Where your organisation uses ITEMZAP, you are the controller of the personal data you upload and we are your processor, acting on your documented instructions. A Data Processing Agreement covering sub-processors, security measures, cross-border safeguards and breach notification is available on request at legal@itemzap.com; write to us and we will provide it.
13. Grievance Officer
As required by the IT Act and Rules and the DPDP Act, our Grievance Officer is:
Siva K
KONOFT, Coimbatore, Tamil Nadu, India
grievance@itemzap.com
We acknowledge grievances within 24 hours and aim to resolve them within 7 days. Data-protection queries go to privacy@itemzap.com.
14. Changes
We may update this policy. Material changes will be notified by email or in the application, and the “last updated” date above will change. Continued use after the effective date means you accept the update.
15. Contact
KONOFT, Coimbatore, Tamil Nadu, India · privacy@itemzap.com