Privacy Policy & Data Governance

Vortexsoft Innovations Pvt. Ltd. (Vortexsoft Group) is committed to safeguarding your personal data, client disclosures, and proprietary information under international ISO 27001 standards, GDPR, CCPA, and HIPAA compliance frameworks.

ISO 27001:2013 ISMS Certified HIPAA Compliant Safeguards GDPR & CCPA / CPRA Compliant Effective Date: July 28, 2026

1. Introduction & Data Controller Information

Welcome to Vortexsoft Innovations Pvt. Ltd. (operating as Vortexsoft Group). We are a premier IT, publishing, healthcare, real estate, data annotation, financial, logistics, and business process outsourcing provider incorporated in India and operating globally across North America, Europe, Asia-Pacific, and the Middle East.

This Privacy Policy explains how Vortexsoft Group collects, uses, discloses, stores, and protects personal data when you visit our website (www.vortexsoftinnovations.com), submit career applications, communicate with our teams, or engage our IT and Business Process Outsourcing (BPO) services.

Data Controller Details:

Legal Entity: Vortexsoft Innovations Pvt. Ltd. (Vortexsoft Group)

Corporate HQ: Second Floor No.125, Ranganath Complex, Madiwala, Venkatapura, HSR Layout 5th Sector, Bengaluru, Karnataka 560068, India

Pune Regional Office: 502, 4th Floor, Dangat Patil Empire, Kudale Baug, Vadgaon Budruk, Pune, Maharashtra 411041, India

USA Office: 30 N Gould St Ste 100, Sheridan, WY 82801, USA

Registered Office: Nanded, Maharashtra 431808, India

2. Scope & International Regulatory Compliance

Vortexsoft Group operates in compliance with international privacy laws and information security frameworks. Depending on your jurisdiction and the nature of your interaction with us, the following regulations govern our data processing:

  • ISO 27001:2013 ISMS Standard: International standard for Information Security Management Systems ensuring systematic risk assessment, strict access controls, and data confidentiality.
  • General Data Protection Regulation (GDPR - EU & UK): Granting European residents rights over personal data processing and establishing strict standards for lawful data transfers.
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA): Providing California residents transparency, non-discrimination, and opt-out controls.
  • Health Insurance Portability and Accountability Act (HIPAA): Safeguarding Protected Health Information (PHI) processed on behalf of healthcare clinics, hospitals, and medical billing partners under formal Business Associate Agreements (BAAs).
  • Digital Personal Data Protection Act 2023 (DPDP Act - India): Governing digital personal data processing in India with purpose-limitation, consent management, and grievance redressal mechanisms.

3. Categories of Information We Collect

We collect information through three primary channels: direct submissions, service delivery workflows, and automated web analytics.

A. Information Provided Directly by You

  • Contact & Inquiry Details: Full name, professional email address, phone number, company name, country, job title, and project descriptions provided via our contact forms or quotation requests.
  • Career & Employment Data: Resumes/CVs, cover letters, educational background, work history, skill sets, portfolio links, and contact information submitted through our /careers page or candidate application portals.
  • Communication Records: Correspondence logs when you contact us via email, phone (+91-8308906690 / +1-307-205-0681), WhatsApp support, or live chat.

B. Service-Specific & Client Data

When clients engage Vortexsoft Group for specialized BPO and IT solutions, we process datasets governed by Business Associate Agreements (BAAs), Non-Disclosure Agreements (NDAs), and Master Services Agreements (MSAs):

  • Healthcare Services: Medical records, diagnosis codes (ICD-10, CPT), insurance claims data, billing codes, patient demographics, and AR recovery documentation processed under strict HIPAA safeguards.
  • Publishing & Editorial Services: Manuscripts, author details, copyright materials, prepress typesetting files, and accessibility conversion documents.
  • Real Estate & Title Services: Property title documents, lease contracts, tenant rosters, CAM audit records, escrow paperwork, and mortgage files.
  • Data Annotation & AI Training: Images, video clips, audio samples, sensor/LiDAR point clouds, and text corpora processed strictly for training computer vision and AI models.
  • Accounting & Financial Services: General ledgers, accounts receivable/payable statements, tax preparation support documents, and payroll processing records.

C. Automated & Technical Information

When navigating our website, technical details are automatically logged to ensure security and optimize performance:

  • IP address, geolocation (city/country level), device type, operating system, browser type and version.
  • Page request URLs, timestamps, referral sources, duration of visit, and service worker cache state.

4. How We Use & Process Your Information

Vortexsoft Group uses collected data strictly for legitimate operational, contractual, and legal purposes:

  • Delivering Contracted Services: Executing IT development, healthcare revenue cycle management, publishing workflows, real estate lease abstraction, and data annotation as specified in client agreements.
  • Communication & Proposal Responses: Responding to client inquiries, issuing cost estimates, scheduling technical consultations, and fulfilling SLA commitments.
  • Recruitment & HR Processing: Evaluating job applicants for active remote, hybrid, or full-time vacancies across our Bengaluru, Pune, and global teams.
  • Information Security & Audit Compliance: Monitoring system logs, preventing unauthorized access, conducting ISO 27001 vulnerability assessments, and preventing fraudulent activities.
  • Service Improvement & Analytics: Analyzing website navigation patterns to optimize user experience, performance loading, and accessibility across devices.

5. Legal Bases for Processing (GDPR & DPDP Act)

We process your personal data under one or more of the following legal grounds:

  • Consent: Where you have provided clear, affirmative consent (e.g., submitting contact forms, requesting service quotes, or uploading career resumes). You may withdraw consent at any time.
  • Contractual Necessity: Where processing is necessary to execute a contract with you or your organization, or to take pre-contractual steps at your request.
  • Legal Obligations: Where processing is required to comply with statutory accounting, tax, labor, or regulatory standards in India, the USA, or international jurisdictions.
  • Legitimate Business Interests: Where processing is necessary for security monitoring, ISO 27001 compliance, defending legal claims, and enhancing infrastructure reliability, provided such interests do not override your privacy rights.

6. Information Security & ISO 27001:2013 Safeguards

As an ISO 27001:2013 certified organization, Vortexsoft Group adheres to strict physical, technical, and administrative security measures designed to protect information from loss, misuse, unauthorized access, disclosure, or destruction.

Technical & Operational Security Measures:
  • Encryption Standards: Data in transit is protected using TLS 1.3/SSL protocols. Confidential client databases and backups are encrypted at rest using AES-256 standards.
  • Access Control & Authentication: Role-Based Access Control (RBAC), multi-factor authentication (MFA), and least-privilege permissions govern access to all client files and operational infrastructure.
  • HIPAA Safeguards: Physical work environments handling healthcare PHI feature restricted badge access, zero-tolerance clean-desk policies, network isolation, and disabled external storage media.
  • Vulnerability Management: Periodic penetration testing, vulnerability scanning, and third-party ISO 27001 ISMS surveillance audits are routinely conducted.

7. Cookie Policy & Web Tracking

Our website utilizes cookies and local storage tokens to deliver smooth navigation, remember layout preferences, and measure website interaction.

Types of Cookies We Use:

  • Essential Cookies: Required for fundamental website functionality, sticky navigation behavior, and security verification.
  • Performance & Analytics Cookies: Aggregated, non-personally identifiable cookies used to analyze traffic volume, page load speeds, and popular service pages.
  • Service Worker Cache: Offline caching (via sw.js) to accelerate page loading and improve mobile performance.

You can control or disable cookies through your web browser settings at any time. Disabling essential cookies will not affect your ability to read general website content.

8. Data Sharing & Non-Disclosure Policy

Vortexsoft Group NEVER sells, rents, leases, or monetizes personal data or client datasets to third parties for marketing purposes.

Data is disclosed strictly under the following limited circumstances:

  • Authorized Service Providers: Trusted cloud hosting providers (e.g., AWS, Azure), secure email dispatch infrastructure, and background verification partners bound by strict Data Processing Agreements (DPAs) and Non-Disclosure Agreements (NDAs).
  • Corporate Affiliates: Wholly-owned entities and subsidiaries under the Vortexsoft Group umbrella operating in India and the USA, adhering to identical privacy standards.
  • Legal & Regulatory Authorities: When required by court orders, subpoenas, law enforcement requests, or to enforce our legal rights and protect the safety of our infrastructure.

9. Cross-Border International Data Transfers

Vortexsoft Group serves clients globally, with operational delivery facilities in Bengaluru, Pune, and Nanded (India), alongside registered office representation in Sheridan, Wyoming (USA).

When personal data is transferred across international borders (such as between the EEA/UK/USA and India), we enforce legal protection mechanisms including EU Standard Contractual Clauses (SCCs), HIPAA Business Associate Agreements, and ISO 27001 encrypted data pipelines to ensure recipient facilities maintain equivalent levels of data protection.

10. Data Retention & Disposal Policy

We retain personal data and project records only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, satisfy contractual commitments, or comply with statutory record-keeping regulations (e.g., tax, audit, labor laws).

  • Contact Inquiries: Retained for 24 months from last communication unless an ongoing client relationship is established.
  • Candidate Applications & Resumes: Retained for 12 months for active job evaluation and potential future vacancies, unless deletion is requested earlier.
  • Client Contract Datasets: Retained or purged strictly in accordance with individual Master Services Agreements (MSAs) and HIPAA data destruction guidelines upon contract completion.

11. Your Rights & Privacy Choices

Depending on your jurisdiction (GDPR, CCPA, DPDP Act), you possess specific rights regarding your personal information:

  • Right of Access: Request confirmation and copies of personal data held about you.
  • Right to Rectification: Request correction of inaccurate, incomplete, or outdated personal information.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data where processing is no longer required by law.
  • Right to Restrict or Object: Object to processing based on legitimate interests or request restriction of processing.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Non-Discrimination: Exercising your privacy rights will never result in denied service, inferior quality, or price penalties.

To submit a privacy rights request, please email our Data Protection Officer at privacy@vortexsoftinnovations.com. Requests will be verified and responded to within statutory timeframes (generally within 30 days).

12. Children's Privacy Protection

Vortexsoft Group's website and commercial services are strictly intended for corporate clients, business partners, and professional job applicants aged 18 and older. We do not knowingly collect or solicit personal data from children under the age of 16 (or 18 in applicable jurisdictions). If we discover that personal data of a minor has been collected without verified parental consent, it will be deleted immediately.

13. Updates to This Privacy Policy

Vortexsoft Group reserves the right to modify or update this Privacy Policy periodically to reflect changes in legal requirements, technological advances, or operational enhancements.

Any modifications will be posted directly on this page with an updated "Effective Date" at the top of the document. We encourage users to review this page periodically to remain informed about how we safeguard personal data.

14. Contact Information & Grievance Redressal

If you have questions, comments, concerns, or grievances regarding this Privacy Policy or our data governance practices, please reach out to our dedicated Data Protection Officer (DPO) and privacy compliance team:

Electronic Contact

Privacy & DPO Email: privacy@vortexsoftinnovations.com

Support Email: support@vortexsoftinnovations.com

General Queries: info@vortexsoftinnovations.in

Telephone Helplines

India & WhatsApp: +91-8308906690

USA Desk: +1-307-205-0681

Hours: Mon–Sat, 9:00 AM – 6:00 PM IST

Grievance Redressal (India DPDP Act): Individuals in India may submit privacy complaints to the Grievance Officer via privacy@vortexsoftinnovations.com. We endeavor to acknowledge grievances within 24 hours and resolve inquiries within 30 days.