Legal · Data Protection
Privacy Policy
How JS PropTech collects, uses, shares and protects personal data across our website, campaigns, WhatsApp and calling systems — written to India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
On this page
- Introduction
- Who we are
- Data we collect
- Why we process it
- Consent and withdrawal
- Automation and AI calling
- Who we share data with
- Transfers outside India
- Cookies and tracking
- How long we keep data
- How we protect data
- Breach notification
- Your rights
- Grievance redressal
- Third-party links
- Visitors outside India
- Changes to this policy
- Contact us
1. Introduction
This Privacy Policy explains how JS PropTech (“JS PropTech”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data when you:
- visit jsproptech.com or any landing page we operate;
- submit an enquiry, book a strategy call, or request a proposal;
- communicate with us by WhatsApp, email, phone or an automated calling assistant;
- engage us as a client for lead generation, marketing or automation services.
We are a business-to-business real estate growth and technology agency. We work with property developers, builders, channel partners and brokerages — primarily across Mohali, Chandigarh, the Tricity region, Punjab and the Punjab NRI corridor.
This policy is issued in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (notified 14 November 2025, with substantive obligations fully enforceable from 13 May 2027, which we are implementing ahead of that date); the Information Technology Act, 2000 and the SPDI Rules, 2011; the Consumer Protection (E-Commerce) Rules, 2020 where applicable; and, for visitors located outside India, the EU/UK GDPR and comparable state privacy laws to the extent they apply to us.
If you do not agree with this policy, please do not submit your information to us or use our services.
2. Who we are and how to reach us
| Business | JS PropTech — The Real Estate Growth & Tech Agency |
| Registered address | 701, CP67, Airport Road, Sector 67, Sahibzada Ajit Singh Nagar (Mohali), Punjab – 160062, India |
| Website | https://jsproptech.com |
| contact@jsproptech.com | |
| Phone / WhatsApp | +91 99130 32030 · +91 63531 30687 |
| Operating region | Mohali, Chandigarh and Tricity, Punjab and pan-India, serving developers and channel partners |
For data you give us directly — through our website forms, calls, WhatsApp messages or our own advertising — we act as a Data Fiduciary and determine why and how that data is processed.
For enquiry and lead data generated on behalf of a client developer — for example, leads captured through a campaign or landing page we run for that developer — we act as a Data Processor on that client’s written instructions. In those cases the developer is the Data Fiduciary, that developer’s own privacy notice governs how the data is ultimately used, and we process the data only as contracted. Requests to exercise rights over such data are forwarded to the relevant client without undue delay.
3. Personal data we collect
We collect only what we need for a stated purpose. We do not sell personal data.
3.1 Information you give us
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact data | Name, business name, designation, mobile or WhatsApp number, email address, city or location | “Book Your Free Strategy Call” form, contact forms, landing pages, WhatsApp, email, phone |
| Business and project data | Current project details, inventory, unit types, price bands, target markets, marketing budget, existing CRM or ad accounts | Discovery calls, proposals, onboarding forms |
| Communication data | Message content, call notes, call recordings and transcripts, WhatsApp chat history, meeting recordings where you have been informed and have consented | Calls, WhatsApp, email, video meetings |
| Commercial data | Billing name, GSTIN, billing address, invoice and payment references | Client onboarding and invoicing |
| Recruitment data | CV, employment history, references, if you apply to work with us | Job applications |
We do not collect your card numbers, CVV, bank credentials or UPI PIN. Payments, where applicable, are handled by regulated third-party payment providers.
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and technical data | IP address, browser type and version, operating system, device type, screen resolution, language |
| Usage data | Pages viewed, time on page, scroll depth, referring URL, exit pages, clicks on buttons and forms |
| Advertising identifiers | Cookie IDs, pixel identifiers, click identifiers (such as fbclid, gclid, wbraid), and hashed identifiers used for conversion measurement |
This is collected through cookies and similar technologies described in Section 9.
3.3 Information from third parties
- Advertising and analytics platforms (Meta, Google) — aggregated campaign performance and, where you submitted an instant form on those platforms, the details you entered there;
- Our clients, where they share their own lead or CRM data with us so that we can run campaigns or automations for them;
- Publicly available business sources, such as company websites and business directories, for B2B outreach to developers and channel partners.
3.4 Sensitive data and children’s data
We do not knowingly collect sensitive categories of personal data such as health, biometric, financial-account, caste, religious or political data, and we ask you not to send it to us.
Our services are directed at businesses and are not intended for children. Consistent with Section 9 of the DPDP Act, we do not knowingly process the personal data of a child (a person under 18 years of age) or of a person with a disability who has a lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we learn that we have inadvertently collected such data without verifiable parental or guardian consent, we will delete it promptly. If you believe a child has provided us data, contact our Grievance Officer (Section 14).
4. Why we process your data, and on what basis
Under the DPDP Act, we process personal data either with your consent or for a legitimate use permitted by Section 7 of the Act. Each purpose below is separate — we do not bundle consents.
| Purpose | What we do | Basis |
|---|---|---|
| Responding to your enquiry | Contacting you about a strategy call, proposal or quote, by phone, WhatsApp or email | Consent / voluntary provision |
| Automated first response | Sending an automated WhatsApp acknowledgement and, where you have opted in, placing an AI-assisted voice call to qualify your requirement | Consent |
| Service delivery | Building landing pages, running Meta and Google campaigns, delivering qualified leads, CRM integration, site-visit scheduling, reporting | Contract performance / consent |
| Client account management | Onboarding, dedicated success-manager support, reviews, renewals | Contract performance |
| Billing and tax | Raising invoices, GST filings, statutory books | Legal obligation |
| Analytics and improvement | Understanding which pages and ads perform, improving the site and our offers | Consent (analytics cookies) |
| Advertising and remarketing | Measuring conversions and showing relevant ads to business audiences | Consent (advertising cookies) |
| Marketing communications | Sending updates, case notes and offers to business contacts, with an opt-out in every message | Consent |
| Security and fraud prevention | Detecting bot submissions, abuse, spam and unauthorised access | Legitimate use |
| Legal claims and compliance | Responding to lawful requests, exercising or defending legal claims | Legal obligation |
If we ever wish to use your data for a materially new purpose, we will tell you and, where required, ask for fresh consent.
5. Consent, and how to withdraw it
Where we rely on consent, that consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the purpose stated at the point of collection.
You may withdraw consent at any time, and withdrawing it is as easy as giving it. To withdraw:
- email contact@jsproptech.com with the subject line “Withdraw Consent”; or
- reply STOP to any marketing WhatsApp message; or
- use the unsubscribe link in any marketing email; or
- tell our caller or success manager that you wish to opt out.
Withdrawal takes effect for future processing. It does not affect processing already carried out lawfully before withdrawal, and it does not remove data we must retain to meet a legal obligation. Where consent is withdrawn and no other basis applies, we will cease processing and erase the data, and require our processors to do the same, within a reasonable period.
6. Automated calling, WhatsApp and AI-assisted processing
Part of our service uses automation, and we want that to be plain:
- WhatsApp automation. If you share a WhatsApp number, we may send automated messages relating to your enquiry or the service you have engaged. Messages are sent through WhatsApp Business Platform infrastructure operated by Meta.
- AI-assisted voice calls. We operate an in-house AI voice assistant that may place or receive calls to qualify enquiries and schedule site visits. Where a call is recorded or transcribed, you will be informed at the start of the call and may decline; you may also ask to speak to a human at any point.
- Lead scoring. We may score or prioritise enquiries based on the information supplied (such as budget, location and timeline) to decide who follows up and how quickly.
These processes assist human decision-making about follow-up. They do not produce legal effects or similarly significant automated decisions about you. No consumer credit, tenancy, employment or eligibility decision is made about you by our systems. You may ask us for a plain-language explanation of how a scoring outcome was reached, and ask a human to review it, by writing to our Grievance Officer.
7. Who we share your data with
We share personal data only as set out below, and only to the extent necessary.
a. Our clients
Where you submit an enquiry through a campaign or landing page for a specific developer or project, your details are passed to that developer so they can respond. That developer then acts as an independent Data Fiduciary for its own use of your data.
b. Service providers
Reputable third parties who run parts of our operations, each bound by written contracts that restrict them to our instructions and require appropriate security. Categories are listed below.
c. Legal and regulatory
Where required by law, court order, or a lawful request from a government agency or the Data Protection Board of India, and to establish, exercise or defend legal claims.
d. Business transfer
If our business or a part of it is restructured, merged or acquired, personal data may transfer as part of that transaction, subject to this policy or a policy at least as protective.
| Category | Typical providers |
|---|---|
| Advertising and measurement | Meta Platforms (Facebook, Instagram, Conversions API), Google (Ads, Analytics, Tag Manager) |
| Messaging and communications | WhatsApp Business Platform, email delivery providers, cloud telephony providers |
| CRM and workflow | The CRM and automation platforms used by us or specified by our client |
| Hosting and infrastructure | Website hosting, cloud storage and database providers |
| Payments, accounting and tax | Payment gateways, accounting software, our chartered accountant |
| Professional advisers | Legal, audit and compliance advisers |
We do not sell personal data, and we do not share it with data brokers.
8. Transfers outside India
We are an India-based business and store data primarily in India. Some of our service providers — notably advertising, messaging, analytics and cloud platforms — process data on servers located outside India.
Under Section 16 of the DPDP Act, such transfers are permitted except to territories that the Central Government may restrict by notification. Where a transfer occurs, we take reasonable steps to ensure a comparable standard of protection, including contractual data-protection terms, standard contractual clauses where the recipient is subject to EU or UK law, and limits on onward transfer. We will comply with any restriction the Central Government notifies.
9. Cookies and tracking technologies
Strictly necessary
Keep the site working — security, load balancing, form submission. These cannot be switched off.
Analytics
Tell us how the site is used, in aggregate, so we can improve it.
Advertising
The Meta pixel and Google Ads tags measure which ads led to an enquiry and allow us to show relevant ads to business audiences.
Your control
Non-essential cookies are set only with your consent, which you can change or withdraw at any time through our cookie banner or your browser settings.
Where our conversion tools transmit contact details for matching, those details are hashed before transmission. Blocking cookies may affect how parts of the site function. We honour browser-level opt-out signals such as Global Privacy Control (GPC) where our systems receive them.
10. How long we keep data
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law.
| Data | Indicative retention |
|---|---|
| Enquiries that do not convert | Up to 24 months from last contact, then deleted or anonymised |
| Client contract and project records | Duration of the engagement plus 8 years (contractual and limitation periods) |
| Invoices, GST and accounting records | 8 years, as required under Indian tax and company law |
| Call recordings and transcripts | Up to 12 months, unless needed for a dispute |
| Website analytics data | Up to 26 months, in aggregated or pseudonymised form where possible |
| Unsuccessful job applications | 12 months, unless you ask us to delete sooner |
| Suppression list (people who opted out) | Retained indefinitely, minimally, solely to honour your opt-out |
Where the DPDP Rules require erasure after a defined period of user inactivity, we will erase the relevant data and give you advance notice before doing so, unless retention is necessary for compliance with law.
11. How we protect your data
We maintain reasonable security safeguards appropriate to the risk, including:
- encryption of data in transit (TLS) and encryption or access-control protection of data at rest;
- role-based access, so staff see only what their role requires;
- multi-factor authentication on administrative and advertising accounts;
- logging and monitoring of access to systems holding personal data, retained for at least one year;
- contractual security obligations on all processors;
- staff confidentiality obligations and privacy training;
- backups, and a documented incident-response process.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we take our obligations under Section 8(5) of the DPDP Act seriously.
12. Data breach notification
If a personal data breach occurs, we will:
- notify the Data Protection Board of India without delay with the available particulars, and provide a detailed report within 72 hours (or such longer period as the Board allows); and
- notify each affected individual without delay, in clear and plain language, describing the nature and extent of the breach, its likely consequences, the measures we have taken to mitigate risk, and the safety measures you may take.
13. Your rights
Subject to verification of your identity, you have the following rights as a Data Principal under the DPDP Act:
| Right | What it means |
|---|---|
| Access | A summary of the personal data we process about you, the processing activities, and the identities of other Data Fiduciaries and processors with whom it has been shared. |
| Correction and completion | To have inaccurate or misleading data corrected, and incomplete data completed or updated. |
| Erasure | To have your data erased where you withdraw consent or the purpose is no longer served, unless retention is required by law. |
| Grievance redressal | A readily available means of raising a grievance with us — see Section 14. |
| Nomination | To nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. |
Email contact@jsproptech.com with the subject line “DPDP Rights Request”, stating which right you wish to exercise and the phone number or email address you used with us. We may ask for information to verify your identity. We will respond within 30 days. Exercising these rights is free; we may decline manifestly unfounded or excessive requests, and will explain why.
If your data is held on behalf of one of our clients, we will identify the relevant client, forward your request to them promptly, and tell you that we have done so.
14. Grievance Officer and escalation
If you have a concern about how we handle personal data, contact our Grievance Officer first.
| Grievance Officer | The Grievance Officer, JS PropTech |
| contact@jsproptech.com (subject line: “Grievance — Data Protection”) | |
| Registered address | 701, CP67, Airport Road, Sector 67, Sahibzada Ajit Singh Nagar (Mohali), Punjab – 160062, India |
| Phone | +91 99130 32030 |
| Acknowledgement | Within 48 hours of receipt |
| Resolution | Within 30 days of receipt |
If you are not satisfied with our response, or we fail to respond within that period, you may lodge a complaint with the Data Protection Board of India through its digital complaint facility, in accordance with the DPDP Act and the DPDP Rules.
15. Third-party links
Our website, landing pages and messages may link to third-party sites, including developer project pages, social platforms and payment pages. We do not control those sites and are not responsible for their privacy practices. Please read their privacy notices before sharing information with them.
16. Visitors from outside India
Where the EU or UK GDPR applies to our processing, our lawful bases are consent (Article 6(1)(a)), performance of a contract (Article 6(1)(b)), legal obligation (Article 6(1)(c)) and our legitimate interests in operating and marketing a B2B service (Article 6(1)(f)). In addition to the rights in Section 13, you have the rights to restriction, to object (including to direct marketing at any time), to data portability, and to lodge a complaint with your local supervisory authority. Transfers to India are made on the basis of appropriate safeguards, including standard contractual clauses where required.
Where a US state privacy law applies, you may request access to, correction of, deletion of, and a copy of your personal data, and may opt out of targeted advertising and of any sharing for cross-context behavioural advertising. We do not sell personal information and do not process it for profiling with legal or similarly significant effects. We will not discriminate against you for exercising these rights. Use the contacts in Section 14.
17. Changes to this policy
We may update this policy to reflect changes in our services, technology or the law — including as the remaining provisions of the DPDP Rules, 2025 come into force on 13 May 2027. The current version is always posted at https://jsproptech.com/privacy-policy/ with the effective date at the top. Where a change materially affects how we use your data, we will give prominent notice and, where required, seek fresh consent.
18. Contact us
Talk to us about your data
Questions, corrections, opt-outs or grievances — we respond to every request.
Sahibzada Ajit Singh Nagar (Mohali), Punjab – 160062
This Privacy Policy is provided for information and does not constitute legal advice. JS PropTech reviews this policy periodically and as its data processing activities change.