Privacy Policy
Effective Date: January 1, 2026 · Last Updated: August 19, 2026
1. Who We Are
Inictus is a product brand operated by Navkar Infotech Services.
Depending on the service and the nature of the processing, Inictus may act as:
- A data controller/business for information required to create and manage customer accounts, subscriptions, billing, security, and service operations.
- A data processor/service provider when processing business content submitted by an organization or customer for the purpose of providing Inictus services.
Where an organization provides you access to Inictus through its corporate account, that organization determines how your information is processed within its environment.
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed through:
Inictus.com, landing pages, pricing pages, documentation, support portals, and authentication systems.
Mail, Calendar, Chat, Meet, Todo, Docs, Drive, Contacts, Notifications, Search, and Organization Management.
Business Mail, SMTP Relay, delivery tracking, mail queues, email authentication (SPF/DKIM/DMARC), anti-spam protection.
Bulk email campaigns, templates, analytics, suppression lists, CRM, Projects, Workflows, Billing, and APIs.
3. Information We Collect
We collect information necessary to provide, secure, improve, and administer our services including Account Information (Full name, business email, login credentials, phone, organization name, domain, billing address, tax info, roles, and subscriptions).
4. Organization and Workspace Information
We process organization name, domain, configuration, departments, teams, user accounts, roles, permissions, distribution lists, security policies, and subscription assignments configured by workspace administrators.
5. Business Mail & Email Information
We process sender/recipient emails, subjects, body text, attachments, headers, message IDs, delivery timestamps, folder labels, signature preferences, quarantine logs, and SPF/DKIM/DMARC authentication results to deliver and secure your email.
6. SMTP Relay Information
We process SMTP credentials, sending domains, recipient addresses, transaction metadata, IP addresses, authentication results, bounce records, complaint signals, and rate-limit events to maintain relay deliverability and network reliability.
7. Email Marketing Information
We process subscriber names, email addresses, lists, campaign content, templates, opens, clicks, bounces, complaints, and suppression lists. Customers are responsible for recipient opt-in consent compliance.
8. Calendar Information
Processes event titles, descriptions, dates, timezones, locations, attendees, reminders, recurrence rules, availability, and attached meeting links.
9. Chat & Messaging Information
Processes direct messages, channels, attachments, mentions, timestamps, delivery receipts, shared links, and moderation signals.
10. Inictus Meet
Processes meeting IDs, participant accounts, session timestamps, device info, connection metadata, and audio/video stream routing. Cloud recordings are stored only when explicitly enabled by administrators.
11. Todo & Task Management
Processes tasks, descriptions, due dates, priorities, assignees, project tags, and completion tracking.
12. Inictus Docs
Processes documents, real-time collaboration edits, comments, version histories, and sharing permissions.
13. Inictus Drive
Processes files, folders, metadata, file versions, sharing permissions, and previews. Customer content remains 100% customer-owned.
14. CRM & Business Data
Processes lead records, contact pipelines, interaction notes, and sales opportunities provided by customer teams.
15. Projects, Workflows & Automation
Processes milestones, project tasks, workflow triggers, actions, and execution logs configured by the customer.
16. Contacts
Processes contact cards, job titles, phone numbers, email addresses, and organizational tags synchronized across modules.
17. Notifications
Processes notification preferences, device push tokens, and security alert events.
18. Billing & Payment Information
Collects billing addresses, tax IDs, invoice histories, and payment transaction tokens. Full credit card data is securely handled by PCI-compliant payment gateways.
19. Subscription & License Information
Processes plan codes, duration cycles (Monthly, 1Y–4Y), license counts, minimum commitments, enabled features, and usage limits.
20. Master Panel & Administrative Data
Processes organization entitlements, license pools, system configurations, and administrative audit trails.
21. Security & Authentication Information
Collects IP addresses, login timestamps, failed attempts, device signatures, MFA events, and security tokens to prevent unauthorized access.
22. Domain Verification & DNS Information
Processes SPF, DKIM, DMARC, and MX records to verify domain ownership and enforce anti-spoofing controls.
23. Technical Information & Telemetry
Automatically logs browser agents, OS versions, approximate IP location, API request latency, and system error events for performance optimization.
24. API & Integration Data
Processes API tokens, integration credentials, webhook events, and request/response logs for connected external services.
25. Audit Logs
Maintains tamper-evident logs of logins, role changes, file sharing, billing updates, and administrative configurations.
26. How We Use Information
Used to manage accounts, authenticate users, deliver workspace apps, route emails, process billing, enforce security, validate DNS records, prevent spam, troubleshoot issues, and comply with legal obligations.
27. Customer Content Ownership
28. Use of Customer Content for AI
AI features (InMind AI) process content solely to fulfill real-time user requests (e.g. Smart Reply, document summaries). Customer content is never sold or used for public advertising model training.
29. Email Security Processing
Automated scanning detects malware, phishing links, spoofed headers, and spam to protect mailboxes and maintain IP reputation.
30. Legal Bases for Processing
Rely on contractual performance, compliance with legal duties, legitimate security interests, and user consent.
31. Data Sharing
Shared only with trusted infrastructure sub-processors (AWS, Hetzner, Cloudflare, PayPal/Stripe), authorized workspace administrators, or when legally compelled by law enforcement.
32. Third-Party Service Providers
Vetted sub-processors operate under strict confidentiality and security agreements.
33. International Data Transfers
Data is stored in secure regional data centers with standard contractual clauses (SCCs) and GDPR/CCPA safeguards.
34. Data Security
Enforces AES-256 encryption at rest, TLS 1.3 in transit, role-based access control (RBAC), multi-tenant isolation, and rate-limiting.
35. Passwords & Credentials
Stored using salted cryptographic hashes. Users are responsible for credential confidentiality and MFA enforcement.
36. Data Retention
Retained for active subscription periods plus legal compliance windows.
37. Account Cancellation & Data Deletion
Upon account cancellation, customer data enters a 30-day grace period, after which all mailboxes, stored files, and backups are permanently purged.
38. Customer-Controlled Deletion
Workspace admins can delete users, files, documents, messages, and campaigns directly within the console.
39. Cookies & Similar Technologies
Uses essential session cookies (`inmail-token`, CSRF tokens) required for authentication and security.
40. Analytics
Anonymous telemetry evaluates performance and error rates to maintain uptime reliability.
41. Marketing Communications
Transactional and security emails are mandatory; promotional communications include an opt-out link.
42. Email Marketing Compliance
Senders must maintain recipient opt-in consent, SPF/DKIM/DMARC records, and bounce rates below 5%.
43. Children's Privacy
Inictus is intended for commercial organizations and does not knowingly collect data from children.
44. Your Privacy Rights
Supports rights of access, correction, erasure, portability, and restriction under applicable data protection laws.
45. Organization-Controlled Accounts
Corporate account admins control workspace permissions, data access, and user retention rules.
46. Data Protection Requests
Submit data requests to support@inictus.com with account verification details.
47. Data Breach & Security Incidents
Inictus notifies affected account administrators within 72 hours of a confirmed security incident.
48. Changes to This Privacy Policy
Material changes will be notified via website announcement or email notice prior to taking effect.
49. Governing Law
Governed by the applicable legal jurisdiction of Navkar Infotech Services.
50. Contact Us
Navkar Infotech Services — Product Brand: Inictus
Website: https://inictus.com
Support: support@inictus.com
51. Summary of Our Privacy Commitments
- ✓ Customer data remains customer-owned.
- ✓ We do not sell customer business content as a commercial data product.
- ✓ We process data primarily to provide the services customers request.
- ✓ We apply enterprise AES-256 and TLS 1.3 security controls.
