Embrolink Terms of Service (B2B)
Draft — lawyer review (needs user). Written by the compliance agent for a business-to-business subscription service sold to companies in India and invoiced outside the apps. Not legal advice.
[SQUARE BRACKETS]are values the user must supply. Annex A (Data Processing Agreement), Annex B (Security measures) and Annex C (Sub-processors) are part of these Terms.
Version: 2026-10-01 (must equal TERMS_VERSION) · Effective: [EFFECTIVE DATE]
1. Who these Terms are between
These Terms are between [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("Embrolink", "we") and the business that creates or uses an Embrolink workspace (the "Customer"). The person who signs up confirms they may bind the Customer. Each person who signs in (an "Authorised User") must also follow these Terms.
Embrolink is a business tool. It is not offered to consumers for personal, family or household use.
2. Definitions
- Service: the Embrolink web app, the Android and iOS apps, the API and related support.
- Workspace: the Customer's separate area in the Service.
- Customer Data: everything the Customer or its Authorised Users put into the Workspace, including personal data of employees, workers, parties and contacts.
- Account Data: the data about an Authorised User's own login (Privacy Notice, Part A).
- Order: a quotation, order form, proforma or invoice from us that states the plan, fees and subscription period.
3. Accounts and age
- 18+ only. Every Authorised User must be at least 18 years old. Sign-up and invitation acceptance ask each person to confirm this. The Customer must not invite anyone under 18 to sign in. The Customer may record employees under 18 as employee records (without a login) only where the law allows their employment, and is responsible for doing so lawfully.
- One person, one login. Logins are personal. Do not share passwords or one-time codes. Admins invite users; nobody can see or set another person's password.
- Security. Keep passwords and devices secure; tell us at once at [SUPPORT E-MAIL] if you suspect misuse. We may lock an account to protect it.
- Owners. Each Workspace has at least one owner. Owners manage users, roles, modules, exports and deletion.
4. What we provide
- We provide the Service described on our website and in the Order, with the modules the Customer switches on.
- We may improve and change the Service. We will not materially reduce the core functions of a paid plan during a paid period; if we must (for example because a law changes), we will tell the Customer at least [30] days before and the Customer may end the subscription and get a pro-rata refund (section 7.4).
- Support: by e-mail at [SUPPORT E-MAIL] during [SUPPORT HOURS, IST]. Support may ask the owner for time-limited access to the Workspace; it starts only if the owner approves, is shown on screen, is read-only unless the owner approves write access, and is logged.
- Availability: we aim for high availability but do not promise uninterrupted service unless an Order includes a service-level commitment. We announce planned maintenance in advance where we can.
- Messages: SMS and WhatsApp delivery depends on telecom operators, DLT registration and Meta. We are not responsible for delays or failures caused by them.
5. Customer responsibilities and acceptable use
The Customer and its Authorised Users must not:
- put in data they have no right to hold, or use the Service unlawfully (including against labour, tax, GST, data protection or telecom laws);
- enter a full Aadhaar number anywhere (the Service accepts only the last 4 digits), or upload images of Aadhaar cards, PAN cards or other identity documents unless a lawful purpose requires it and the Customer has enabled that feature;
- send SMS or WhatsApp messages through the Service to people who have not agreed to receive them, or use the Service for marketing messages;
- upload malware, try to break security, probe or scan the Service, access another customer's data, or run load tests without our written permission;
- copy, resell, frame or reverse-engineer the Service, or use it to build a competing product;
- use automated scraping, except through the API and exports we provide.
The Customer is responsible for its Authorised Users, for the accuracy and lawfulness of Customer Data, for giving its employees and contacts any notice the law requires, and for its own statutory records (GST, e-invoicing, e-way bills, labour registers). Embrolink helps prepare documents; filing and legal correctness remain the Customer's responsibility. GST rates and HSN/SAC codes in the Service are editable data and must be checked by the Customer's tax adviser.
6. Customer Data
- The Customer owns Customer Data. We use it only to provide and support the Service, to keep it secure, and as the law requires. We do not sell it, use it for advertising, or use it to train AI models.
- Annex A (Data Processing Agreement) governs our processing of personal data in Customer Data.
- Export at any time: owners can export the whole Workspace (Excel per module plus documents) whatever the billing state, including during read-only periods.
- We process Account Data as described in our Privacy Notice, where we are the Data Fiduciary.
7. Subscription, billing and refunds
- No purchases inside the apps. The Android and iOS apps and the Service's screens do not sell anything, show prices or take payments. Subscriptions are bought directly from us under an Order. Nothing is bought through the Apple App Store or Google Play, so Apple and Google do not process any payment or refund for Embrolink.
- Trial. A new Workspace may start with a free trial of [TRIAL LENGTH — decision ON-Q2] (needs user). No card is needed. If the trial is not converted, the Workspace becomes read-only for 30 days (sign in, view, export), is then soft-deleted and recoverable for 90 days, and is then permanently deleted.
- Fees and invoices. Fees are as stated in the Order ([PRICING UNIT AND PRICES — decision ON-Q3]) (needs user), in Indian rupees, plus GST and other applicable taxes. We issue a GST tax invoice. Payment is due within [N] days of the invoice by bank transfer, UPI or another method we agree in writing.
- Renewal. Unless the Order says otherwise, a subscription renews for the same period at the then-current price. We tell the owner at least [30] days before a renewal or a price change; the Customer can stop renewal by telling us before the renewal date (needs user: confirm auto-renewal model).
- Late payment. If payment is overdue we send reminders for 14 days; after that the Workspace may become read-only until payment. We never delete Customer Data because of late payment without the notices in section 9.
- Refunds. Fees already paid are not refundable, except: (a) if we end the subscription for convenience, or the Customer ends it because of our uncured material breach, or under section 4.2, we refund the prepaid fees for the unused period, pro rata; (b) where the law requires a refund; (c) duplicate or mistaken payments, which we refund in full. Refunds are paid by bank transfer to the account that paid, within [30] days of our confirming them, with a GST credit note. Write to [BILLING E-MAIL] (needs user).
- Plan limits. Plans have limits (for example factories, users, machines). At 80 % of a limit we warn the owner; at 100 % new records of that kind are blocked until the plan changes. Existing data is never removed because of a limit.
8. Intellectual property
We own the Service, its software, designs and documentation. We give the Customer a non-exclusive, non-transferable right to use the Service during the subscription for its internal business. The Customer owns Customer Data and gives us the permission we need to host and process it to provide the Service. Suggestions the Customer gives us may be used freely. Open-source components are licensed under their own licences, listed in the apps and on the website.
9. Term, suspension and ending
- These Terms apply from sign-up until the Workspace is deleted.
- The Customer may end the subscription at any time from Settings → Organisation (owner) or by writing to us; paid fees are handled under section 7.6.
- We may suspend access, after notice where practical, if payment is seriously overdue (section 7.5), if the Customer materially breaches these Terms, or to stop an immediate security risk or unlawful use. Suspension blocks sign-in but does not delete data.
- We may end the subscription for material breach not cured within [30] days of notice, or for convenience on [90] days' notice with a pro-rata refund.
- After ending: read-only for 30 days for export, then soft-deleted and recoverable for 90 days, then permanently deleted, including from backups within the backup cycle. On request we confirm deletion in writing (Annex A, section 9).
10. Confidentiality
Each party keeps the other's confidential information confidential and uses it only for these Terms, except where disclosure is required by law (with notice where lawful).
11. Warranties and disclaimers
We will provide the Service with reasonable skill and care and in line with Annex B. Except as stated in these Terms, the Service is provided "as is". We do not guarantee that calculations (for example GST, payroll, costing, targets) meet the Customer's legal obligations; the Customer must review figures before relying on them.
12. Liability
- Neither party is liable for indirect or consequential loss, or loss of profit, revenue or goodwill.
- Each party's total liability under these Terms in any 12 months is limited to the fees paid or payable by the Customer in those 12 months [or INR [AMOUNT] for free or trial Workspaces] (needs user).
- These limits do not apply to fraud, wilful misconduct, the Customer's payment obligations, or anything the law does not allow to be limited. (needs user: lawyer to set the carve-outs for data protection breaches, given DPDP penalties of up to INR 250 crore sit with the Data Fiduciary.)
13. Indemnity
The Customer indemnifies us against third-party claims arising from Customer Data it had no right to process or from its breach of section 5. We indemnify the Customer against third-party claims that the Service infringes their Indian intellectual-property rights. (needs user)
14. Changes to these Terms
Each version has a date. We tell owners at least [30] days before a change that reduces the Customer's rights, show the new version in the Service, and ask users to accept it; acceptance is recorded with the version and time. If the Customer does not accept, it may end the subscription before the change takes effect with a pro-rata refund of prepaid fees.
15. Law and disputes
Indian law applies. The parties will first try to settle a dispute by talking for 30 days. After that, disputes go to arbitration under the Arbitration and Conciliation Act, 1996 by a sole arbitrator in [CITY], in English; courts at [CITY] have exclusive jurisdiction for interim relief (needs user).
16. Grievances and notices
Grievance Officer: [GRIEVANCE OFFICER], [GRIEVANCE E-MAIL] — acknowledgement within 24 hours, resolution within 15 days ([WEBSITE URL]/legal/grievance). Legal notices to [REGISTERED ADDRESS] and [LEGAL E-MAIL]; we send notices to the owner's registered e-mail or mobile and inside the Service.
17. General
These Terms (with the Order and Annexes) are the whole agreement. If one part is unenforceable, the rest stays. Neither party may assign these Terms without consent, except to a successor of its business. Force majeure excuses delays outside a party's reasonable control. Nothing creates a partnership or agency.
Annex A — Data Processing Agreement (DPA)
This Annex applies to personal data in Customer Data ("Customer Personal Data").
- Roles. The Customer is the Data Fiduciary and Embrolink is its Data Processor under the Digital Personal Data Protection Act, 2023 (s.8(2)) and the DPDP Rules, 2025. Until the DPDP core duties apply (about 13 May 2027), the parties also follow the IT Act, 2000 s.43A and the SPDI Rules, 2011 as they apply.
- Instructions. We process Customer Personal Data only to provide the Service as configured by the Customer and on its documented instructions (these Terms, the Customer's settings and actions in the Service, and written instructions). We tell the Customer if we believe an instruction breaks the law.
- Details of processing. and the post-termination periods in section 9 of the Terms. customers, suppliers, contractors, transporters and brokers, drivers, and people named in its documents. machines, pay type, salary or wage); bank account and IFSC; PF UAN and ESIC numbers; last 4 digits of Aadhaar; attendance times (no location); leave, payroll, payslips, incentives, advances, loans and deductions; production and quality records; photos and documents attached to records; party GSTIN, PAN, addresses, bank details and ledgers; activity logs.
- Subject matter and duration: hosting and processing for the Service, for the subscription
- Data principals: the Customer's employees and workers, its Authorised Users, contacts at its
- Personal data: identity and contact details; employment details (department, shift, skills,
- Not processed: location, biometrics, full Aadhaar numbers, health data, children's accounts.
- Our staff. Only staff who need access, under confidentiality duties. Staff access Customer Data only through an owner-approved, time-limited, logged support session, or where the law requires.
- Security. We apply the measures in Annex B, which address DPDP Rules, Rule 6(1)(a)–(g).
- Sub-processors. The Customer authorises the sub-processors in Annex C. We impose data protection terms on them no less protective than this Annex, and remain responsible for them. We give owners at least [30] days' notice of a new sub-processor; the Customer may object on reasonable data protection grounds and, if we cannot address the objection, end the affected service with a pro-rata refund.
- Personal data breach. We notify the Customer's owner within 24 hours of confirming a personal data breach affecting Customer Personal Data, with what we know then, and update as we learn more: nature, extent, timing and location; categories and approximate number of people and records; likely consequences; what we have done and recommend. We cooperate so the Customer can inform affected people and the Data Protection Board (DPDP Rules, Rule 7: the Board without delay and a full report within 72 hours). We also meet our own duty to report cyber incidents to CERT-In within 6 hours.
- Help with data principals' requests. The Service lets the Customer find, export, correct and delete records itself. If a data principal contacts us, we forward the request to the Customer within [5] business days. We help with requests the Customer cannot handle itself within [10] business days of its written request (well within the 90-day limit in Rule 14(3)).
- Deletion or return. At any time the owner can export Customer Data. When the subscription ends, we delete Customer Data on the schedule in section 9.5 of the Terms, including from backups within the backup cycle ([BACKUP RETENTION]), unless the law requires us to keep it. We keep the minimum personal data, traffic data and logs needed for the one-year retention in DPDP Rules, Rule 8(3), restricted and then erased. On request we confirm deletion in writing.
- Location and transfers. We host Customer Data in India ([HOSTING REGION]) (needs user). Some sub-processors (WhatsApp) may process message data outside India; transfers follow s.16 of the DPDP Act and any Government restriction.
- Government requests. We disclose Customer Personal Data to authorities only when the law requires, after checking the request, and tell the Customer unless the law forbids it.
- Audit. We provide on request the information reasonably needed to show compliance with this Annex (for example our security summary and sub-processor list). On-site audits: once a year, on [30] days' notice, at the Customer's cost, under confidentiality (needs user).
- Customer warranties. The Customer confirms that it has a lawful basis for the personal data it puts in (including employment as a legitimate use under s.7(i) where it applies), has given the notices the law requires, collects written consent where the SPDI Rules still require it (for example employee bank details), records WhatsApp opt-in only for contacts who agreed, never enters full Aadhaar numbers, and does not give logins to anyone under 18.
- Our own purposes. We do not use Customer Personal Data for our own purposes, except security logs and the retention record required by law, where we act as Data Fiduciary and follow our Privacy Notice.
Annex B — Security measures
| Area | Measure |
|---|---|
| Transit | HTTPS/TLS on every connection; the apps block cleartext in production; cookies Secure, HttpOnly, SameSite=Lax |
| Isolation | Every business table carries the organisation ID; PostgreSQL row-level security is enabled and forced; the application database role cannot bypass it; an automated test checks every table |
| Encryption of sensitive fields | Bank account numbers, PF UAN and ESIC numbers encrypted with AES-256-GCM; masked (last 4) in lists, exports and screens; full value only through an audited "reveal" for permitted roles |
| Authentication | Argon2id password hashes; common passwords refused (local list, no external service); one-time codes and session tokens stored as hashes; 10-minute codes, 5 attempts; invitation acceptance proven by a one-time code to the invited mobile; lock after 5 wrong passwords for 15 minutes; limits on sign-in attempts and code requests per account, per mobile number and per network; sessions revocable by the user |
| Access control | Roles with per-resource permissions and scopes (all / factory / unit / own); money fields hidden without permission |
| Logging | Immutable activity (audit) log in the same transaction as each change; security logs kept 180 days in India and 1 year overall; clocks synchronised to NTP servers of NIC/NPL (CERT-In) |
| Minimisation | No location, no full Aadhaar, no date of birth, EXIF removed from photos, masked mobiles in logs, query strings and secret tokens removed from request logs; QR codes decoded on the device |
| Support access | Owner approval, time-limited, on-screen banner, read-only by default, fully logged |
| Resilience | Encrypted backups on a [BACKUP RETENTION] cycle; restore tested [QUARTERLY] (needs user) |
| People | Confidentiality undertakings, least-privilege access, access reviews (needs user) |
| Incidents | Written incident process with CERT-In 6-hour and customer 24-hour clocks |
Field-encryption keys are separate from session and cookie secrets. (needs user: hold them in a managed key service with a rotation procedure.)
Annex C — Sub-processors
| Sub-processor | Service | Data | Location |
|---|---|---|---|
| [HOSTING PROVIDER] (needs user) | Servers, database, file storage, backups | All Customer Data | India ([REGION]) |
| MSG91 — [MSG91 LEGAL ENTITY, confirm] (needs user) | SMS delivery (codes, alerts) | Mobile number, message text | India |
| Meta Platforms, Inc. / WhatsApp (optional, only if WhatsApp is enabled) (needs user) | WhatsApp delivery | Mobile number, message text | May be outside India |
| [E-MAIL PROVIDER, e.g. Amazon Web Services — SES, Mumbai] (needs user) | E-mail delivery | E-mail address, message | India |
The mobile apps contain no third-party analytics, advertising or crash-reporting code; QR codes are decoded on the device.