Legal
Privacy notice
What we collect, why we collect it, who else ever sees it, and how to make us delete it. Written to be read rather than to be technically survivable.
Last updated 2 September 2026
The short version. We collect what you type into the demo form and nothing else. We do not sell it, we set no advertising or analytics cookies on this website, and one email to gediya.kalpesh@gmail.com gets it deleted. Everything below is the same thing said carefully.
1. What this notice covers
This notice is about information you send us through this website — krushnayerp.com — principally the demo request form.
It is not about the data inside a customer workspace. Your catalogue, your purchase orders, your stock movements, your staff records and your vendors' details belong to you, and how we handle them is set by the written agreement we sign with you before your workspace is created. In that relationship you are the controller of the data and we process it on your instructions. If you are an existing customer looking for that document, ask us and we will send it.
2. Who we are
Krushnay ERP is back-of-house software for restaurants and hotel groups operating in the United Arab Emirates and India. For anything in this notice, the person responsible is reachable at gediya.kalpesh@gmail.com or 07227993344. We are a small team, so that reaches a person rather than a queue.
3. What we collect
When you request a demonstration
The form asks for:
- Your name and the restaurant or group you work for — so we know who we are speaking to.
- A work email address — required, because it is how we reply.
- A phone or WhatsApp number — optional, and only used if you would rather we called.
- The country you operate in and how many branches you have — so the call is about your situation rather than a generic script.
- What you are trying to solve — optional, free text. Please do not put anything confidential in it.
We also record, automatically:
- The time you sent it.
- The IP address the request came from. The form is open to the internet, and this is how we stop the same script submitting a thousand times — three requests from one address is the limit, after which that address is refused for thirty days.
- What your browser told us about itself — the user agent string, and the browser, operating system and device type we read from it, plus your browser's language preference. A wave of fake enquiries is far easier to recognise by this than by its content.
- Approximately where the address is registered — country, region and city, and the internet provider. This is worked out from the IP address alone. It is not a street address and not a landmark: an IP does not carry one, and it frequently resolves to wherever your provider terminates the connection rather than to where you are sitting. We use it to notice patterns, not to find anybody.
We keep this so that if somebody uses the form to send abuse or threats, there is a record to give to the police — who can ask an internet provider to identify the subscriber behind an address at a particular moment. We cannot do that ourselves and we would not try.
When you simply read the site
Our web server keeps ordinary access logs — the page requested, the time, the browser and the IP address — as every web server does. They are used to keep the site running and to notice when something is broken or being attacked. They are not used to build a profile of you, and they are not joined to anything else.
What we never ask for
This website never asks for payment card details, passwords, identity documents or anything about your customers. If a page ever appears to, it is not ours — please tell us.
4. Why we hold it
To answer the enquiry you made and to prepare for that conversation. That is the whole purpose. Concretely, we use it to reply to you, to look up your market before the call so the demonstration uses realistic figures, and to remember the conversation if it pauses and picks up weeks later.
We rely on your request as the basis for contacting you: you asked us to get in touch, and you can tell us to stop at any moment and we will. We do not add demo requesters to a newsletter, and we do not use your details to advertise to you elsewhere.
5. Who else sees it
Nobody buys it, and nobody receives it for their own purposes. A small number of suppliers process it strictly on our instructions in order to run the service:
| Who | What they handle | Where |
|---|---|---|
| DigitalOcean | Hosting for this website, the application and its database; storage for files | India and Singapore |
| Brevo | Sending the notification email when you submit the form, and sign-in codes | European Union |
| Google (Fonts) | Serving the two typefaces this site uses; your browser requests them directly | Global |
We would also disclose information if a law or a valid order required it. If that ever happened and we were permitted to tell you, we would.
6. Where it is stored
Enquiries are stored in a PostgreSQL database on a server in Bangalore, India. Files uploaded inside a customer workspace — logos, purchase order PDFs, delivery photographs and signatures — are stored in Singapore. Notification email passes through Brevo in the European Union.
If you are in a country whose law restricts where your data may go, tell us before you send anything and we will confirm whether we can accommodate it.
7. How long we keep it
- Demo requests: two years. Long enough that a conversation which paused can be picked up without asking you to type it all again, then deleted.
- Server access logs: about thirty days, then rotated away.
- Email we exchange with you: kept while the conversation is live and for as long as we may need it to answer a question about it afterwards.
Ask us to delete any of it sooner and we will, without asking why.
8. How it is protected
The site and the application are served only over HTTPS. The database is not exposed to the internet. Files that are not meant to be public — invoices, signatures, delivery photographs — are private and are served only through the application, which checks who is asking and which organization they belong to before handing anything over. Sign-in uses a one-time code sent by email rather than a password, and repeated failed attempts lock an address for the rest of the day.
We are a small company and we are not going to claim a certification we do not hold. If your procurement process needs specific assurances, ask and we will answer honestly about what we do and do not do.
9. Cookies and tracking
This website sets no cookies at all. Nothing is stored in your browser, there is no advertising pixel, no session recording and no third-party tracker on any page you are reading here. That is why you have not been shown a cookie banner: there is nothing stored on your device to consent to.
We do count page views. When a page loads it tells our own server which page was opened and, if you followed a link, which site you came from. The server adds the same things it sees on any request — the IP address, what your browser says about itself, and roughly which country and city the address is registered to.
What it does not do is recognise you. No identifier is stored in your browser, so two visits on two different days are two unconnected records; we cannot tell that they were the same person and we do not try. It answers how many people looked at a page, on what sort of device, and from roughly where — and it is deliberately not capable of anything more than that. This data goes to nobody else and is used for no advertising.
The application behind the sign-in page does store a token in your browser to keep you signed in. That is necessary for it to work at all, it is not used for advertising, and signing out removes it.
Typefaces are requested from Google Fonts, which means your browser contacts Google to fetch them and Google sees that request. If you would rather it did not, tell us — serving the fonts from our own server is a small change and we will make it.
10. The law we work under
We operate in two jurisdictions, and the rules differ. Rather than claim a single blanket compliance, here is what applies where.
United Arab Emirates
Personal data of people in the UAE is handled with reference to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL) and its implementing regulations. In practice this means we collect only what we need for a purpose we have told you about, we do not process it for anything else afterwards, and you may withdraw consent or ask for erasure at any time.
Customers using Krushnay ERP to run a UAE business also hold obligations of their own that this software is built to support — a Trade Licence from the emirate's Department of Economic Development, a Tax Registration Number where VAT applies under Federal Decree-Law No. 8 of 2017, and municipality food safety permits. The system records those registrations and prints them on purchase orders so the documents you issue carry what they are supposed to carry. Meeting those obligations remains yours; we make it easier to evidence, not automatic.
India
Personal data of people in India is handled with reference to the Digital Personal Data Protection Act, 2023 and, where still applicable, the Information Technology Act, 2000 together with the 2011 rules on sensitive personal data. You are a data principal, we are a data fiduciary for what you send through this website, and the rights in the section below are the ones that Act gives you.
Indian customers of the product hold their own registrations — a GSTIN for tax, an FSSAI licence for food handling, and a shop and establishment or municipal trade licence. As in the UAE, the system stores these and puts them on the documents that need them.
Raising a grievance
Both regimes expect a named route for complaints rather than a general inbox. Write to gediya.kalpesh@gmail.com with Data grievance in the subject line, or call 07227993344. We will acknowledge within seven days and answer substantively within thirty. If you are not satisfied you may escalate — in the UAE to the UAE Data Office, and in India to the Data Protection Board once it is receiving complaints.
A note on what this page is. It describes what we actually do, written in plain language. It is not legal advice, and it is not a substitute for the agreement we sign with a customer. If your own counsel needs something specific — a data processing agreement, a record of processing, confirmation of where a particular category of data sits — ask and we will provide it rather than point you back at this page.
11. Your rights
You can ask us to:
- Show you what we hold about you.
- Correct anything that is wrong.
- Delete it.
- Stop contacting you, permanently.
- Send it to you in a portable format, or to somebody else.
Email gediya.kalpesh@gmail.com. We will answer within thirty days and usually a great deal sooner. We will not ask you to justify the request, and exercising any of these will never affect the service you receive.
12. Children
This is business software. It is not directed at children, and we do not knowingly collect anything from anyone under sixteen. If you believe a child has sent us information, tell us and we will remove it.
13. Changes to this notice
If we change how we handle information, we will update this page and change the date at the top. If a change is significant and we hold an address for you, we will email you about it rather than relying on you noticing.
14. How to reach us
Krushnay ERP
Email: gediya.kalpesh@gmail.com
Phone: 07227993344
Web: www.krushnayerp.com
If you have raised something with us and are not satisfied with how we handled it, you may complain to the data protection authority where you live.