Data Sharing & Disclosure Policy
This Data Sharing & Disclosure Policy explains when ARZAQ INSIGHTS may share, transfer, disclose, or otherwise provide access to information associated with its centralized services.
1. Purpose & 2. Scope
This policy details how data boundaries are enforced across centralized accounts, identity services, billing, payment processors, infrastructure cloud providers, and connected software platforms.
3. No Default Cross-Product Data Sharing
Logging into multiple ecosystem products with a single ARZAQ account does not grant those products access to each other's databases. Product A cannot inspect or retrieve Product B's operational records without explicit user consent.
4. User-Controlled Integrations
Cross-product data exchange occurs only when you intentionally connect applications (e.g. synchronizing student contact lists with an automated communication dispatch tool).
6. Scope of Consent & 7. Revoking Access
Users maintain full control to disconnect integrations at any time via Account settings. Upon disconnection, automated synchronization immediately halts across the relevant connectors.
8. Centralized Authentication vs 9. Product Authorization
When you log in, ARZAQ INSIGHTS transmits verified cryptographic identity tokens (user ID, verified email/phone, active subscription plan). The connected product independently calculates granular permissions within its own software environment.
10. Payment Service Providers
Transactional data (order totals, customer name, transaction IDs) is securely shared with licensed payment gateways for processing and invoicing:
11. AWS Infrastructure (Mumbai Region) & 12. Operational Providers
Central databases are hosted on Amazon Web Services in Mumbai, India. Specialized operational vendors (e.g. transactional email relays, SMS/OTP gateways) receive only the minimum information necessary to execute requested operations.
13. Zero Third-Party Trackers & 14. No Sale of Personal Data
We do not embed third-party tracking pixels or ad networks across our central identity and account management surfaces.
15. Legal Compliance & 16. Security & Fraud Protection
We may disclose limited information when required by valid court orders, statutory law enforcement demands under Indian law, or to investigate criminal cyberattacks and payment fraud.
17. Business Transfers & 18. International Transfers
In the event of a merger, acquisition, or restructuring, transferred data remains protected under the commitments outlined in this policy. International routing complies with applicable cross-border data frameworks.
21. Data Minimization Standard
We restrict outgoing API payloads strictly to fields necessary for the requested transaction or workflow, preventing over-exposure of user records.
22. Product-to-Product Data Isolation & 24. Information Not Shared
Operational databases, customer files, private documents, and internal telemetry belonging to one product are strictly isolated from all other products by default.
25. Transmission Security
All inter-service API communications use encrypted mutual TLS connections and scoped OAuth 2.0 authorization tokens.
27. Interconnected Policies
Read in conjunction with our Privacy Policy, Data Security Policy, and Data Retention & Deletion Policy.