How Bizmitra protects your business data — the security we build in, the privacy laws we honour, and how to report a vulnerability responsibly.
Data is encrypted in transit (TLS). Access is least-privilege and role-based; credentials are stored hashed and shown once.
Every legal acceptance, consent change, and data-request is recorded in an append-only audit trail with actor, time, and IP.
Customer data is logically isolated per tenant. Cross-tenant access is denied by construction, not by convention.
Under DPDP, GDPR, and CCPA you can access, export, correct, or delete your personal data, and withdraw consent at any time. We operate a deadline-bound request pipeline for every user type.
Signed-in users can request an export or deletion from their portal's Privacy settings. Everyone else can reach us at the contact below.
We welcome reports from security researchers and will work with you in good faith. Please give us reasonable time to remediate before any public disclosure.
We're transparent about the third parties that help us run the service. See the current list of sub-processors, what they process, and where.
Hosting, email, payments, analytics (consented), and AI inference providers.