Privacy Policy

Last updated: 11 September 2026

What Zrubix Technologies collects when you use SOP3A, why we collect it, who else sees it, and what you can ask us to do about it.

1. Introduction

Zrubix Technologies ("we", "us", or "our") operates SOP3A. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service — the website, the admin application, the shop, and the phone apps.

There are two separate kinds of account, and they do not mix. A staff account belongs to someone in an organisation that uses SOP3A to run its procedures. A customer account belongs to someone buying from the shop. They live in different systems, and signing in to one never signs you in to the other. Where a rule below applies to only one of them, it says so.

2. Information we collect

Information you provide:

  • Name, email address, phone number, and organization details during registration
  • SOPs, documents, images, and other content you create or upload
  • Observation records, training results and other entries your organisation asks you to make
  • A delivery address, when you order something physical from the shop
  • Communication data when you contact our support team

Information collected automatically:

  • Device information (type, operating system, browser)
  • Usage data (pages visited, features used, timestamps)
  • Login and authentication data
  • IP address and approximate location

What we never collect:

  • Card numbers, CVV codes, UPI PINs or net-banking credentials — see section 6
  • Your contacts, photo library, microphone or precise GPS position
  • Anything for advertising, from anyone, ever

3. How we use your information

We use your information to:

  • Provide, maintain, and improve the Service
  • Authenticate your identity and manage your account
  • Send you service-related communications (one-time passcodes, account updates, order confirmations)
  • Take payment, deliver what you bought, and handle refunds
  • Provide customer support
  • Analyze usage patterns to improve user experience
  • Ensure security, investigate abuse and prevent fraud
  • Meet a legal or tax obligation

We do not use your content to train machine-learning models, and we do not read your procedures except when you ask us to look at something in support.

4. Why we are allowed to use it

Every use above rests on one of these:

  • To do what you asked. Running your account, delivering an order, answering a question.
  • Your consent. Anything optional. You may withdraw it at any time, and withdrawing it never affects what we did while it stood.
  • Our legitimate interest. Keeping the Service secure and working, and preventing fraud — weighed against your rights, never over them.
  • The law. Tax records, and a lawful order we are obliged to follow.

If you use SOP3A through your employer, that organisation decides what is collected inside its own account and who in it can see what. We process that data on its instructions.

5. Data storage and security

Your data is stored on secure cloud infrastructure (Google Cloud Platform and Firebase), in managed databases in India and Singapore. We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, audit logging, and regular security review. Passwords are stored only as a one-way hash and cannot be read back by anyone, including us.

While we strive to protect your data, no method of electronic storage is completely secure. If a breach ever affects your personal data, we will tell you and the relevant authority without undue delay, along with what happened and what to do about it.

6. Payments

Payments are handled by a regulated payment gateway. Your card number, CVV, UPI PIN and net-banking credentials are entered on the gateway and never reach our servers — we could not show them to you if you asked. What we keep is the part we need to run a shop honestly: what you bought, what it cost, whether it succeeded, the last four digits or payment reference, and the invoice. Tax law requires us to keep invoices for eight years, which is why section 10 treats them differently from everything else.

7. Data sharing

We do not sell your personal information. We may share your data only in the following cases:

  • Within your organization: SOPs and content are shared with other members of your organization as configured by your administrators
  • Service providers: trusted third parties that process data on our behalf, under contract and only for these purposes — cloud hosting and databases (Google Cloud, Firebase), sign-in (Google), one-time passcodes by SMS or WhatsApp, payment processing, and delivery couriers for physical orders
  • Legal requirements: when required by law, regulation, or legal process
  • Business transfers: in connection with a merger, acquisition, or sale of assets — you would be told before your data moved

A courier is told the delivery address, not what is inside the parcel or anything else about your account.

8. Where your data is held

Our main database is in India (Mumbai region) and parts of the Service run in Singapore. That means your data may be processed outside your own country. Wherever it goes, the protections in this policy travel with it, and we use providers who commit to equivalent safeguards by contract.

9. Your rights

You have the right to:

  • Access your personal data, and get a copy in a portable format
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Withdraw consent for data processing
  • Object to certain uses of your data, or ask us to restrict them
  • Complain to a data protection authority

To exercise these rights, write to support@sop3a.com from the email address on the account. We acknowledge within 2 working days and complete the request within 30 days. There is no charge. If we cannot do something you have asked for, we say which rule stops us rather than declining without a reason.

If you use SOP3A through an employer, ask them first — their administrators control that account, and we will point you to them rather than change their data behind their back.

10. Cookies

We use essential cookies for authentication and session management. These cookies are necessary for the Service to function and cannot be disabled without breaking sign-in. We do not use third-party tracking or advertising cookies, and there is nothing here to opt out of because there is nothing following you.

11. Data retention

We retain your data for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymize your data within 90 days. Two things outlive that:

  • Invoices and payment records, kept for eight years because tax law requires it
  • Backups, which roll off on their own schedule within 90 days and are never used to bring a deleted account back

12. Children's privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.

13. Grievance officer

Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, you may raise a grievance about your data or about the Service. Write to support@sop3a.com with "Grievance" in the subject line. We acknowledge within 2 working days and resolve within 30 days. Full details are on the Contact page.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The date at the top of this page indicates when the policy was last updated.

15. Contact us

If you have any questions or concerns about this Privacy Policy, please contact us at support@sop3a.com. The related policies are the Terms & Conditions and the Refund & Cancellation Policy.