1. Scope & Company Identity
This Privacy Policy is issued by KatirTek Tria Private Limited (“KatirTek”, “Company”, “we”, “us”, or “our”), a company registered under applicable corporate legislation, having its registered operational offices in India. We operate the TriaDek enterprise service desk, ticketing workflow system, SLA automation engine, and customer support infrastructure.
This Policy covers all interactions with the TriaDek platform via web browsers (https://triadek.katirtek.com), native mobile applications distributed on the Apple App Store and Google Play Store, and developer REST APIs.
Data Controller vs. Data Processor:
- Data Processor: For operational ticket summaries, incident descriptions, triage comments, file attachments, and internal notes submitted by our enterprise customer organizations and their authorized users, KatirTek acts strictly as a Data Processor (or Business Associate / Service Provider) on behalf of the customer organization (the Data Controller).
- Data Controller: KatirTek acts as a Data Controller with respect to subscriber account management records, administrator credentials, billing and subscription logs, user authentication tokens, system security audit logs, and direct customer support communications.
2. Information We Collect
We collect only the minimum personal and operational data necessary to deliver secure enterprise ticketing services:
- Account & Profile Data: Full name, corporate email address, username, job role (Global Admin, Support Admin, Support Agent, Client Admin, Client Reporter, End User), organizational department, and one-way cryptographically salted password hashes.
- Ticket & Incident Records: Ticket summaries, incident details, priority classification (Urgent, High, Medium, Low), SLA target timers, resolution notes, Root Cause Analysis (RCA) records, assignee identifiers, and file attachments (screenshots, logs, documentation, error traces).
- Device & Telemetry Data: IP address, device hardware model, operating system type and version, browser user-agent, application release build, crash logs, and localized error reports for diagnostics.
- Authentication & Session Tokens: Secure HTTP-only session cookies, JSON Web Tokens (JWT), SAML 2.0 / OIDC identity federation tokens, and UI state preferences.
3. Mobile Application Disclosures (iOS & Android)
In compliance with Apple App Store Review Guidelines (including Guideline 5.1.1 on Data Collection and Storage) and Google Play Data Safety policies, the TriaDek native mobile application operates under the following transparent mobile-specific standards:
Device Permissions & Data Access
- Camera & Photo Library (Optional / On-Demand): We request camera and photo storage access solely when an authorized user chooses to capture a photo or attach an image screenshot to a technical support ticket. The mobile app never reads your photo library in the background or scans photos unrelated to explicit user submissions.
- Push Notifications (APNs & FCM): The app collects a unique device push token (via Apple Push Notification service on iOS and Google Firebase Cloud Messaging on Android). This token is used exclusively to alert you to ticket assignments, urgent priority escalations, customer responses, and SLA breach warnings. Users can disable notifications at any time via device settings or app preferences.
- Biometric Authentication (Face ID, Touch ID, Biometric Prompt): For enhanced security on mobile devices, users may enable biometric login. Biometric verification is processed entirely on-device by your hardware Secure Enclave / Keystore. TriaDek never accesses, records, or transmits raw biometric data or facial maps to any server.
- Local Encrypted Storage: Secure storage on your device (iOS Keychain and Android EncryptedSharedPreferences) stores authentication tokens and temporary draft responses to ensure offline resilience.
- Zero Third-Party Advertising Trackers: TriaDek does not contain any third-party behavioral advertising SDKs (such as Facebook Audience Network, Google AdMob, or data broker analytics). No device identifiers (such as IDFA or GAID) are ever collected for tracking or monetization.
4. Legal Bases for Processing
Under the European Union GDPR, UK GDPR, and India DPDP Act, our legal grounds for processing personal data include:
- Contractual Performance (Art. 6(1)(b) GDPR): Routing tickets, maintaining SLA clocks, notifying assignees, and fulfilling master service agreements.
- Legitimate Interests (Art. 6(1)(f) GDPR): Protecting cloud infrastructure, preventing DDoS and brute-force attacks, auditing compliance, and ensuring business resilience.
- Legal Compliance (Art. 6(1)(c) GDPR): Fulfilling statutory accounting, tax, corporate recordkeeping, and lawful authority obligations.
- Consent (Art. 6(1)(a) GDPR): Delivering mobile push notifications and optional diagnostic telemetry.
5. How We Use Your Data
All collected data is utilized strictly for business and operational functionality:
- Processing, routing, triaging, and resolving technical support tickets.
- Sending real-time notification alerts (email and mobile push via FCM) regarding ticket updates, assignments, and critical SLA breaches.
- Enforcing strict Role-Based Access Control (RBAC) across organizational divisions.
- Generating operational reports, resolution velocity heatmaps, and SLA performance summaries for customer tenant administrators.
- Investigating security anomalies, preventing unauthorized system intrusions, and maintaining non-repudiation audit trails.
6. Multi-Tenant Isolation & Sub-processors
TriaDek operates on an enterprise-grade multi-tenant architecture. Every tenant organization is strictly isolated at the database, query, cache, and attachment storage tiers. No customer organization can view, modify, or query another tenant’s ticket data or directory.
We engage vetted sub-processors bound by formal Data Processing Agreements (DPAs):
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Tier-4 Cloud Infrastructure (AWS / GCP / Cloud VPS) | Primary database, computing instances, encrypted attachment storage | US / EU / APAC (as contracted) |
| Google Firebase (FCM) | Mobile push notification token relay (Android & iOS) | Global / US |
| Apple Push Notification service (APNs) | Native iOS notification gateway | Global |
| Enterprise Identity Providers (SAML/OIDC) | Customer-directed Single Sign-On authentication | Customer-configured endpoints |
7. No Sale or Monetization of Personal Data
Our Binding Enterprise Guarantee:
KatirTek Tria Private Limited does NOT sell, rent, lease, trade, or monetize personal data, customer ticket content, diagnostic telemetry, or business workflows to any third party, advertising network, or data broker. We do not use customer proprietary ticket text or code attachments to train public artificial intelligence or machine learning models without explicit written agreement.
8. Security & Encryption Controls
We enforce defense-in-depth safeguards across all layers of our software and cloud environment:
- Encryption in Transit: All HTTP and WebSocket connections are encrypted using TLS 1.3 with modern cipher suites and HTTP Strict Transport Security (HSTS).
- Encryption at Rest: Database volumes, operational backups, and uploaded attachments are secured using AES-256 encryption.
- Credential Hashing: Passwords are cryptographically salted and hashed using bcrypt/argon2 algorithms with high cost factors.
- Administrative Safeguards: Mandatory Multi-Factor Authentication (MFA) for administrative staff, automated session timeouts, and least-privilege role boundaries.
9. Data Retention & Mobile Account Deletion Procedures
We retain customer data for the duration of the active enterprise subscription agreement. Upon account termination or written request from the customer organization:
- Customer tickets, work notes, and file attachments are securely purged within 30 calendar days, subject to statutory legal holding mandates.
- App Store & Google Play Account Deletion Requirement: In accordance with Apple App Store Guideline 5.1.1(v) and Google Play policy, mobile users have the right to request complete deletion of their account and personal data:
How to request deletion:
1. In-App: Navigate to Mobile App → Profile / Settings → Account Security → Request Account Deletion.
2. Direct Privacy Request: Email our Data Protection Office at
privacy@katirtek.comwith your registered email and organization name.Upon verification, all personal profile attributes, mobile push tokens, and active credentials will be permanently erased within 30 days.
10. Cross-Border Data Transfers
Where data is transferred internationally, KatirTek ensures compliance through Standard Contractual Clauses (SCCs) approved by the European Commission, UK International Data Transfer Agreements (IDTAs), and equivalent cross-border data transfer mechanisms under applicable privacy legislation.
11. User & Data Subject Rights
Depending on your jurisdiction (GDPR, CCPA/CPRA, DPDP Act 2023), you possess the following statutory rights:
- Right of Access & Portability: Request a copy of your personal data in structured JSON or CSV format.
- Right to Rectification: Correct inaccurate or out-of-date personal information.
- Right to Erasure (“Right to be Forgotten”): Permanently delete your user profile and access credentials.
- Right to Restrict or Object: Restrict non-essential data processing.
- Non-Discrimination: We never deny service or degrade feature quality when you exercise your privacy rights.
12. Children’s Privacy
TriaDek is an enterprise B2B workflow system strictly designed for authorized business personnel and corporate IT departments. We do not solicit or knowingly collect personal information from individuals under 18 years of age. If we identify unauthorized minor data collection, we immediately execute secure data destruction.
13. Corporate Information & Data Protection Officer (DPO)
To exercise any privacy rights, request data exports, submit inquiries, or lodge a data protection concern, please contact our Data Protection Office:
KatirTek Tria Private Limited
Data Protection Officer & Legal Compliance
Privacy Inquiries: privacy@katirtek.com
Legal Inquiries: legal@katirtek.com
Enterprise Support: support@katirtek.com
Official Web Portal: https://triadek.katirtek.com