Legal
Privacy Policy
ILMORA AI Technologies Private Limited · Effective date: [ effective date ] · Last updated: [ effective date ]
This policy explains how ILMORA AI Technologies Private Limited (“ILMORA”, “we”, “us”) handles personal data when you visit www.ilmora-ai.com, contact us, or use our products including BillFlow India. It is written to be consistent with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules made under it.
1. Who we are
ILMORA AI Technologies Private Limited, CIN U62099TS2026PTC213579, registered office at 21-4-1132, Hussainialam, Bahadurpura, Hyderabad – 500064, Telangana, India.
When you deal with us directly — as a website visitor, an enquirer, or a customer organisation — we are the Data Fiduciary for that personal data. When our customer organisation uses BillFlow India to bill its own payers, that organisation is the Data Fiduciary for the payer data it uploads, and ILMORA acts as a Data Processor on its instructions under a written agreement.
2. Personal data we collect
- Enquiry and account data: name, organisation, work email, phone number, role, the vertical you select, and the content of messages you send us through our forms or by email.
- Product usage data: for customers, account identifiers, activity logs, configuration settings and support correspondence generated while using BillFlow India.
- Payer data processed on behalf of customers: names, mobile numbers, addresses, bill particulars, amounts due, payment status and receipt records uploaded or generated by a customer organisation.
- Technical data: IP address, browser and device type, pages viewed and timestamps, collected through server logs for security and reliability purposes.
We do not knowingly collect personal data of children through this website, and we do not run behavioural advertising or third-party ad trackers on it.
3. Purposes for which we use it
- To respond to your enquiry and to assess and administer the BillFlow design partner programme.
- To provide, operate, secure and support our products — including delivering bills, processing payments, reconciling receipts and issuing GST-compliant documents on a customer's instruction.
- To communicate about service status, security matters, and changes to terms or policies.
- To meet legal, tax, accounting and regulatory obligations in India.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To improve product reliability and quality using aggregated or de-identified information.
We do not use customer or payer personal data to train general-purpose AI models for our own unrelated purposes.
4. Lawful basis and consent
We process personal data on the basis of your consent, given through a clear affirmative action such as submitting a form, or on the basis of legitimate uses permitted by the DPDP Act — including performance of a contract you have entered into with us and compliance with law. Where consent is the basis, our notice tells you what is collected and why, and you may withdraw consent at any time by writing to the grievance contact below. Withdrawal does not affect processing already carried out, and may mean we can no longer provide a service that depends on that data.
5. Sharing and disclosure
We do not sell, rent or broker personal data. Ever. We share it only with:
- Processors and infrastructure providers acting on our instructions under contract — cloud hosting, communication delivery, payment gateways and analytics of our own product's health.
- Payment system participants and regulated financial institutions, to the extent necessary to execute and reconcile a payment you initiate.
- Professional advisers, auditors and authorities, where required by applicable law, court order or a lawful request.
- An acquirer or successor entity in the event of a merger, reorganisation or sale of business, subject to this policy continuing to apply.
6. Data residency and security
Personal data we process is stored and processed in cloud regions located in India, with backups also held in India. We apply encryption in transit and at rest, role-based least-privilege access, network isolation, audit logging, secure software development practices and periodic review of access rights. No system is perfectly secure; where a personal data breach occurs we will notify the Data Protection Board of India and affected individuals as required by law.
7. Retention
We keep personal data only as long as the purpose for which it was collected requires, or as long as Indian law requires us to retain it — for example, financial and tax records that must be preserved for statutory periods. Enquiry data that does not result in a relationship is deleted or de-identified within 24 months. Payer data processed for a customer organisation is retained per that organisation's instructions and deleted or returned on termination of its agreement, subject to legal retention requirements.
8. Your rights as a Data Principal
Subject to the DPDP Act, you may:
- Access a summary of the personal data we hold about you and how it is processed.
- Have inaccurate or incomplete personal data corrected, completed or updated.
- Request erasure of personal data where the purpose is served and no law requires its retention.
- Withdraw consent previously given, as described in section 4.
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
- Register a grievance with us and, if unsatisfied, escalate to the Data Protection Board of India.
Write to the contact in section 10 with enough detail to identify your records. We respond within 30 days. If you are a payer billed through BillFlow India by an organisation, we will direct your request to that organisation as the Data Fiduciary and support them in fulfilling it.
9. Cookies and similar technologies
This website uses only essential cookies and equivalent local storage needed for security, session integrity and basic aggregate traffic measurement. We do not use advertising or cross-site tracking cookies. Product applications may use strictly necessary cookies to keep you signed in.
10. Grievance and data protection contact
Grievance Officer / Data Protection contact: [ Data Protection Officer contact — name, designation and email to be inserted ]
In the interim, privacy queries and data-principal requests may be sent to [ hello@ilmora-ai.com ] or by post to the registered office address in section 1, marked “Attention: Privacy”. Phone: +91 88975 99958.
11. Changes to this policy
We may update this policy as our products and obligations evolve. Material changes will be notified on this page with a revised effective date and, where the change is significant and we hold your contact details, by email.