Privacy Policy
How AJNA Asset Management Services collects, uses and protects your personal data.
This Privacy Policy explains how AJNA Asset Management Services (“AJNA”, “we”, “us” or “our”) collects, uses, shares, retains and protects personal data when you visit ajnaassets.com (the “Website”), contact us, or engage us for asset management, facility management and allied security services (together, the “Services”).
We are committed to handling personal data lawfully, fairly and transparently, in line with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and other applicable Indian law.
Please read this Policy carefully. By using the Website or submitting information to us, you acknowledge that you have read and understood it.
1. Who we are
AJNA Asset Management Services is a provider of integrated asset management, facility management and allied security services, operating from 4th Floor, SBR Horizon, Hoskote Road, Vastu Bhoomi, Whitefield, Bengaluru – 560067, Karnataka, India.
For personal data where we decide the purpose and means of processing — such as enquiries submitted through the Website — AJNA is the Data Fiduciary (also referred to as a data controller). Where we handle personal data strictly on the instructions of a client under a service contract, we act as a Data Processor; see section 8.
2. Scope of this Policy
This Policy applies to:
- visitors to and users of the Website;
- individuals who contact us through the Website enquiry form, by email, by telephone or in person;
- representatives of our clients, prospective clients, vendors and business partners; and
- applicants and other individuals whose personal data we receive in the course of providing the Services.
It does not apply to the privacy practices of any third-party website, platform or client premises that we do not control.
3. Personal data we collect
3.1 Information you give us directly
When you submit the “Get in touch” form on the Website, or write or speak to us, we collect:
- Name — required by the enquiry form;
- Email address — required by the enquiry form;
- Telephone number — required by the enquiry form;
- Message content — any details you choose to include about your requirement, site or organisation;
- Any further information you volunteer in later correspondence, meetings or site visits, such as company name, designation, site address and service requirements.
Please do not send us sensitive personal data (for example financial account details, health information, biometric data or government identifiers) through the Website enquiry form. If such information is genuinely needed to deliver a Service, we will request it through a secure and appropriate channel.
3.2 Information collected automatically
The Website does not use advertising trackers, analytics tags or third-party marketing pixels. However, like virtually all websites, our hosting provider’s servers automatically record standard technical information each time a page or file is requested, which may include:
- IP address and the approximate location derived from it;
- date and time of the request and the pages or files requested;
- browser type and version, operating system and device type;
- referring URL and HTTP status or error codes.
These server logs are used for security monitoring, abuse prevention, troubleshooting and measuring the general load on our infrastructure. We do not use them to build marketing profiles of individual visitors.
3.3 Information from other sources
We may receive personal data about you from your employer or organisation, from a client who engages us at a site where you work, live or visit, from publicly available sources such as business directories and company registries, or from referrals and business introductions.
4. How and why we use personal data
We use personal data only for the purposes for which it was provided or collected, including to:
- respond to your enquiry, quotation request or complaint, and follow up with you about it;
- prepare proposals, estimates and contracts, and assess whether we can serve your requirement;
- deliver, administer and support the Services, including facility management, maintenance, manpower deployment and security operations;
- manage our relationship with clients, vendors and business partners, including invoicing, payment and account administration;
- maintain the safety and security of the sites we manage and of the people at them;
- operate, secure, troubleshoot and improve the Website;
- keep proper business records and comply with legal, regulatory, tax, statutory and contractual obligations;
- establish, exercise or defend legal claims and prevent fraud, misuse or unlawful activity; and
- send you service-related updates and, where you have asked for them or where otherwise permitted by law, occasional business communications about our Services.
We do not sell personal data, and we do not rent, trade or otherwise make personal data available to third parties for their own independent marketing purposes.
5. Consent and legal basis
Where the DPDP Act applies, we process personal data on the basis of:
- Your consent — for example, when you voluntarily submit the enquiry form so that we can contact you. Your consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the purposes described in this Policy.
- Certain legitimate uses recognised by law — including where you voluntarily provide personal data for a specified purpose and have not indicated that you object to its use for that purpose, and where processing is necessary to comply with a legal obligation or with a judgment, order or direction of a competent authority.
- Performance of a contract — where processing is necessary to enter into or perform a contract with you or with the organisation you represent.
You may withdraw your consent at any time by writing to us at the contact details in section 16. Withdrawal takes effect prospectively: it does not affect the lawfulness of processing carried out before withdrawal, and it does not affect processing we are required or permitted to continue under applicable law. Withdrawing consent may mean we can no longer respond to your enquiry or provide part or all of a Service.
6. Cookies and analytics
The Website does not set advertising, profiling or cross-site tracking cookies, and we do not run third-party analytics or social media tracking scripts on it. Fonts, stylesheets and scripts used by the Website are served from our own domain rather than from external content networks.
Your browser may still store data locally as part of its normal operation, for example page and image caching. If we introduce cookies or analytics in future, we will update this Policy and, where the law requires it, request your consent before those technologies are used.
7. How we share personal data
We disclose personal data only as described below, and only to the extent necessary:
- Within AJNA — to employees, supervisors and site personnel who need the information to perform their duties, on a need-to-know basis.
- Service providers and data processors — including our website hosting provider, email and communication providers, IT support, accounting and payroll providers, and professional advisers. Enquiries submitted through the Website are delivered to and stored in AJNA email accounts operated by our email service providers. These parties may process personal data only on our instructions and under confidentiality and security obligations.
- Clients and site owners — where necessary for the delivery of contracted Services at their premises, such as deployment records and incident reports.
- Authorities and legal disclosures — to courts, law enforcement, regulators or other government bodies where required by law, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the safety of any person, or establish, exercise or defend legal claims.
- Business transfers — in connection with a merger, acquisition, restructuring or transfer of all or part of our business, in which case the recipient will be bound to treat personal data in a manner consistent with this Policy.
8. Data we process on behalf of clients
In delivering facility and security services, we may handle personal data that belongs to our client’s operations rather than our own — for example visitor and gate-entry registers, attendance and duty records, QR-based patrol and checkpoint logs, incident and complaint registers, and footage from CCTV systems owned and operated by the client.
For that data we generally act as a Data Processor: we process it only on the documented instructions of the client (the Data Fiduciary), for the purposes set out in our service contract, and we do not use it for any independent purpose of our own. If you are a resident, tenant, employee or visitor at a site we manage and you wish to exercise rights over such data, please contact the site owner or management directly. You may also write to us using the details in section 16, and we will forward your request to the relevant client and support them in responding.
9. Data retention
We keep personal data only for as long as it is needed for the purpose for which it was collected, and then delete or erase it, unless a longer period is required or permitted by law. In practice:
- Website enquiries that do not lead to an engagement are retained for a reasonable period to answer follow-up correspondence, and are then deleted;
- Client, vendor and contractual records are retained for the duration of the relationship and thereafter for the period prescribed by applicable tax, accounting, labour and limitation laws;
- Server logs are retained for a short period for security and diagnostic purposes;
- Data processed for clients is retained in accordance with the retention schedule agreed in the relevant service contract, and is returned or deleted on termination as that contract requires.
10. How we protect personal data
We maintain reasonable security safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. These include access controls and role-based permissions, password protection for accounts and devices, encryption of the Website in transit using HTTPS, restricted physical access to records and offices, confidentiality obligations in employment and vendor contracts, and staff awareness of data handling responsibilities.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach, we will act promptly to contain and remedy it, and we will notify the Data Protection Board of India and affected individuals where and as required by applicable law.
11. Your rights and choices
Subject to applicable law and to verification of your identity, you have the right to:
- Access — obtain a summary of the personal data we hold about you, the processing activities we undertake with it, and the identities of those with whom it has been shared;
- Correction and updating — have inaccurate or misleading personal data corrected, incomplete data completed and outdated data updated;
- Erasure — request deletion of personal data that is no longer necessary for the purpose for which it was collected, unless retention is required by law;
- Withdraw consent — withdraw consent previously given, as described in section 5;
- Grievance redressal — raise a grievance with us about our handling of your personal data, and escalate it to the Data Protection Board of India if you are not satisfied with our response;
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity;
- Opt out of marketing — ask us to stop sending you business or promotional communications at any time.
To exercise any of these rights, write to us using the details in section 16, describing your request and the personal data concerned. We will respond within a reasonable period, and in any case within the timeframes prescribed by applicable law. You are responsible for providing information that is accurate and complete, and for not making false or frivolous requests.
12. Children’s data
The Website and the Services are intended for businesses and adults. We do not knowingly collect the personal data of children under 18 years of age through the Website, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Where processing of a child’s personal data is unavoidable in the course of a Service, we will obtain verifiable consent from a parent or lawful guardian as required by the DPDP Act. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Storage and international transfers
Personal data is stored on our systems and on infrastructure operated by our hosting and email service providers. Some of those providers may store or process data on servers located outside India. Where personal data is transferred outside India, we take reasonable steps to ensure it continues to receive an adequate level of protection through contractual safeguards, and we make such transfers only to the extent permitted under applicable Indian law and any restrictions notified by the Central Government.
14. Third-party links
The Website may contain links to third-party websites, maps or resources. Following such a link takes you to a site we do not operate or control, governed by that site’s own privacy policy. We are not responsible for the content or privacy practices of third-party sites, and we encourage you to read their policies before providing personal data to them.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal and regulatory requirements. The revised version will be posted on this page with an updated “Last updated” date, and takes effect when posted. Where changes are material, we will take reasonable steps to bring them to your notice. Please review this page periodically.
16. Contact us and grievance redressal
If you have questions about this Policy, wish to exercise your rights, or want to raise a grievance about how we handle personal data, please contact our Grievance Officer:
Grievance Officer — AJNA Asset Management Services
4th Floor, SBR Horizon, Hoskote Rd, Vastu Bhoomi,
Whitefield, Bengaluru – 560067, Karnataka, India
Email: info@ajnaassets.com
Phone: +91-9741855949 · +91-9035386582
We aim to acknowledge every request or grievance promptly and to resolve it within the time prescribed by applicable law. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India in accordance with the DPDP Act.