Legal
Privacy policy
Last updated 18 September 2026
This policy explains how A & S Software Consultancy Pvt Ltd ("A&S", "we", "us"), the Indian partner of OLT ERP Limited, collects, uses, shares and protects personal data when you use this customer portal and our subscription applications — Eudemonic AI, OLT ERP SIS, MDP / Executive Programme Management and Admission Management System. It is written to meet India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), and the EU GDPR where it applies.
1. Who we are
A & S Software Consultancy Pvt Ltd is the data controller (UK GDPR) and Data Fiduciary (DPDP Act) for personal data processed through this portal: account, organisation, billing, payment, support and enquiry data. OLT ERP Limited, our UK partner, publishes the applications sold here and processes personal data on our instructions where support or hosting requires it; it is the contracting supplier for customers invoiced from the United Kingdom. Our registered office is at G-14, First Floor, South Extension Part 1, New Delhi 110049, India.
Inside the applications your institution subscribes to (for example student, applicant or participant records), your institution is the controller / Data Fiduciary and we act as its processor / Data Processor, processing that data only on the institution's documented instructions under our subscription terms. Requests about that data should go to the institution first; we will help it respond.
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, work email, phone number, job title | You, or your organisation's administrator |
| Organisation and billing | Institution name, billing address, GSTIN / VAT number, purchase order numbers | You |
| Account and security | Sign-in identifiers, multi-factor authentication status, roles, audit logs of actions, IP address, browser details | Generated when you use the portal |
| Transactions | Subscriptions, invoices, payment status, gateway transaction and order IDs, bank transfer references (UTR) and proof of payment you upload | You and our payment providers |
| Communications | Support tickets, demo requests, emails and their delivery status | You |
We never receive or store card numbers, CVVs, UPI PINs or net-banking passwords. These are entered directly on the payment provider's secure page. We do not knowingly collect sensitive data such as health or biometric data through this portal.
3. Why we use it and our legal basis
| Purpose | UK / EU GDPR basis | DPDP Act basis |
|---|---|---|
| Creating and securing your account; providing and supporting the subscribed service | Contract | Consent given at registration; voluntarily provided data for a specified purpose |
| Invoicing, collecting payment, preventing fraud and duplicate charges | Contract; legitimate interests | Consent; legitimate use |
| Keeping tax, accounting and audit records (e.g. GST and VAT invoices) | Legal obligation | Legitimate use — compliance with law |
| Service emails: verification, invoices, receipts, renewal and security notices | Contract; legitimate interests | Consent |
| Responding to demo requests and enquiries | Legitimate interests; steps before a contract | Consent |
| Protecting the service, investigating misuse, responding to legal claims or lawful requests | Legitimate interests; legal obligation | Legitimate use |
We do not sell personal data, use it for third-party advertising, or make decisions with legal or similarly significant effects about you by automated means alone.
4. Consent and withdrawing it
Where we rely on consent, you can withdraw it at any time as easily as you gave it, by emailing privacy@assoftwaregroup.com. Withdrawal does not affect processing already carried out. Because an account cannot operate without certain data, withdrawing consent for that data will mean closing the account; tax and accounting records we must keep by law are retained as described below.
5. Who we share it with
We share personal data only as needed to run the service, with providers bound by contract to protect it and use it only on our instructions:
- Amazon Web Services — hosting, databases, file storage, sign-in (Amazon Cognito) and email delivery (Amazon SES), in Mumbai, India (ap-south-1) and London, UK (eu-west-2).
- Payment providers — Razorpay and PayU (India), and for international card payments a provider we will name here before use. They process payment details as independent controllers under their own privacy policies and the RBI and PCI DSS rules that apply to them.
- Banks — to receive and reconcile transfers and issue refunds.
- Professional advisers and authorities — auditors, tax advisers, and regulators, courts or law-enforcement bodies when the law requires it.
- A buyer or successor — if our business is reorganised or sold, under equivalent protections.
6. International transfers
We operate in India and the UK and serve institutions in both and elsewhere, so personal data may be transferred between India and the UK. Transfers out of the UK or EEA rely on UK adequacy regulations or the UK International Data Transfer Agreement / EU Standard Contractual Clauses. Transfers out of India are made in line with the DPDP Act and are not made to any country the Government of India has restricted.
7. How long we keep it
- Account and organisation data — while the account is active, then deleted or anonymised within 90 days of closure unless needed below.
- Invoices, payments and tax records — 8 years, to meet Indian GST (at least 72 months after the annual return due date) and UK accounting and VAT requirements.
- Audit records of account and billing actions — kept with the financial records they relate to (up to 8 years). Server logs containing IP addresses — 30 days, longer only if needed for an investigation.
- Demo requests and enquiries that do not become customers — 2 years from last contact.
Under the DPDP Act, we erase personal data once its purpose has been served and no law requires us to keep it, and we tell you before erasing data held on the basis of your consent where the Rules require it.
8. Your rights
Everyone can ask us to:
- confirm whether we hold your personal data, give you a copy and a summary of how it has been processed and with whom it has been shared;
- correct, complete or update inaccurate data;
- erase data we no longer need or no longer have a lawful basis to keep;
- withdraw consent (see section 4).
Under UK / EU GDPR you can also ask us to restrict processing, object to processing based on legitimate interests, and receive data you gave us in a portable format.
Under the DPDP Act you can also nominate another individual to exercise your rights if you die or become incapacitated, and use our grievance redressal process (section 10).
Email privacy@assoftwaregroup.com. We may need to verify your identity. We respond within one month (UK GDPR), extendable by two months for complex requests, and within the period prescribed by the DPDP Rules. There is no fee in normal cases.
9. Security
Data is encrypted in transit (TLS) and at rest (AWS KMS). Each customer organisation's data is isolated at the application and database level. Staff access requires multi-factor authentication, is limited by role and is audit-logged. Payment callbacks are cryptographically verified. If a personal data breach occurs we will notify the Data Protection Board of India and affected individuals as the DPDP Act requires, and the UK Information Commissioner's Office within 72 hours where UK GDPR requires, and affected customers without undue delay.
10. Grievances and complaints
Our privacy team, who also act as the contact for grievance redressal under the DPDP Act, can be reached at privacy@assoftwaregroup.com. Please give details of your concern; we will acknowledge it promptly and respond within the period prescribed by the DPDP Rules.
You must use our grievance process first before complaining to the Data Protection Board of India. In the UK you may complain to the Information Commissioner's Office (ico.org.uk), and in the EU to your local supervisory authority — we would appreciate the chance to resolve it first.
11. Children
This portal is for institutional staff and is not intended for anyone under 18. Where our applications process data about children or students under 18 on behalf of an institution, the institution is responsible for obtaining verifiable parental or guardian consent where the DPDP Act requires it, and we do not use that data for tracking, behavioural monitoring or targeted advertising.
12. Cookies
We use only strictly necessary cookies: to keep you signed in, protect forms against cross-site request forgery and route your session securely. We do not use analytics or advertising cookies, so no cookie consent banner is needed. Payment providers may set their own cookies on their checkout pages.
13. Changes to this policy
We will post any changes here with a new "last updated" date and, for material changes, notify account administrators by email.
Related: Cancellation and refund policy · Terms of service