Inictus Workspace
Navkar Infotech Services · Product Brand: Inictus

Privacy Policy

Effective Date: January 1, 2026 · Last Updated: August 19, 2026

At Inictus, a product brand of Navkar Infotech Services, we are committed to protecting the privacy, security, and confidentiality of information entrusted to us. This document governs Inictus Workspace, Business Mail, SMTP Relay, Email Marketing, Calendar, Chat, Meet, Todo, Docs, Drive, and platform services.

1. Who We Are

Inictus is a product brand operated by Navkar Infotech Services.

Depending on the service and the nature of the processing, Inictus may act as:

  • A data controller/business for information required to create and manage customer accounts, subscriptions, billing, security, and service operations.
  • A data processor/service provider when processing business content submitted by an organization or customer for the purpose of providing Inictus services.

Where an organization provides you access to Inictus through its corporate account, that organization determines how your information is processed within its environment.

2. Scope of This Privacy Policy

This Privacy Policy applies to information processed through:

Inictus Website & Public Services:

Inictus.com, landing pages, pricing pages, documentation, support portals, and authentication systems.

Inictus Workspace Suite:

Mail, Calendar, Chat, Meet, Todo, Docs, Drive, Contacts, Notifications, Search, and Organization Management.

Communication & Delivery:

Business Mail, SMTP Relay, delivery tracking, mail queues, email authentication (SPF/DKIM/DMARC), anti-spam protection.

Marketing & Administration:

Bulk email campaigns, templates, analytics, suppression lists, CRM, Projects, Workflows, Billing, and APIs.

3. Information We Collect

We collect information necessary to provide, secure, improve, and administer our services including Account Information (Full name, business email, login credentials, phone, organization name, domain, billing address, tax info, roles, and subscriptions).

4. Organization and Workspace Information

We process organization name, domain, configuration, departments, teams, user accounts, roles, permissions, distribution lists, security policies, and subscription assignments configured by workspace administrators.

5. Business Mail & Email Information

We process sender/recipient emails, subjects, body text, attachments, headers, message IDs, delivery timestamps, folder labels, signature preferences, quarantine logs, and SPF/DKIM/DMARC authentication results to deliver and secure your email.

6. SMTP Relay Information

We process SMTP credentials, sending domains, recipient addresses, transaction metadata, IP addresses, authentication results, bounce records, complaint signals, and rate-limit events to maintain relay deliverability and network reliability.

7. Email Marketing Information

We process subscriber names, email addresses, lists, campaign content, templates, opens, clicks, bounces, complaints, and suppression lists. Customers are responsible for recipient opt-in consent compliance.

8. Calendar Information

Processes event titles, descriptions, dates, timezones, locations, attendees, reminders, recurrence rules, availability, and attached meeting links.

9. Chat & Messaging Information

Processes direct messages, channels, attachments, mentions, timestamps, delivery receipts, shared links, and moderation signals.

10. Inictus Meet

Processes meeting IDs, participant accounts, session timestamps, device info, connection metadata, and audio/video stream routing. Cloud recordings are stored only when explicitly enabled by administrators.

11. Todo & Task Management

Processes tasks, descriptions, due dates, priorities, assignees, project tags, and completion tracking.

12. Inictus Docs

Processes documents, real-time collaboration edits, comments, version histories, and sharing permissions.

13. Inictus Drive

Processes files, folders, metadata, file versions, sharing permissions, and previews. Customer content remains 100% customer-owned.

14. CRM & Business Data

Processes lead records, contact pipelines, interaction notes, and sales opportunities provided by customer teams.

15. Projects, Workflows & Automation

Processes milestones, project tasks, workflow triggers, actions, and execution logs configured by the customer.

16. Contacts

Processes contact cards, job titles, phone numbers, email addresses, and organizational tags synchronized across modules.

17. Notifications

Processes notification preferences, device push tokens, and security alert events.

18. Billing & Payment Information

Collects billing addresses, tax IDs, invoice histories, and payment transaction tokens. Full credit card data is securely handled by PCI-compliant payment gateways.

19. Subscription & License Information

Processes plan codes, duration cycles (Monthly, 1Y–4Y), license counts, minimum commitments, enabled features, and usage limits.

20. Master Panel & Administrative Data

Processes organization entitlements, license pools, system configurations, and administrative audit trails.

21. Security & Authentication Information

Collects IP addresses, login timestamps, failed attempts, device signatures, MFA events, and security tokens to prevent unauthorized access.

22. Domain Verification & DNS Information

Processes SPF, DKIM, DMARC, and MX records to verify domain ownership and enforce anti-spoofing controls.

23. Technical Information & Telemetry

Automatically logs browser agents, OS versions, approximate IP location, API request latency, and system error events for performance optimization.

24. API & Integration Data

Processes API tokens, integration credentials, webhook events, and request/response logs for connected external services.

25. Audit Logs

Maintains tamper-evident logs of logins, role changes, file sharing, billing updates, and administrative configurations.

26. How We Use Information

Used to manage accounts, authenticate users, deliver workspace apps, route emails, process billing, enforce security, validate DNS records, prevent spam, troubleshoot issues, and comply with legal obligations.

27. Customer Content Ownership

★ Customer data remains 100% customer-owned. Inictus does NOT acquire ownership over emails, files, or documents stored in the platform, nor do we sell customer content for advertising.

28. Use of Customer Content for AI

AI features (InMind AI) process content solely to fulfill real-time user requests (e.g. Smart Reply, document summaries). Customer content is never sold or used for public advertising model training.

29. Email Security Processing

Automated scanning detects malware, phishing links, spoofed headers, and spam to protect mailboxes and maintain IP reputation.

30. Legal Bases for Processing

Rely on contractual performance, compliance with legal duties, legitimate security interests, and user consent.

31. Data Sharing

Shared only with trusted infrastructure sub-processors (AWS, Hetzner, Cloudflare, PayPal/Stripe), authorized workspace administrators, or when legally compelled by law enforcement.

32. Third-Party Service Providers

Vetted sub-processors operate under strict confidentiality and security agreements.

33. International Data Transfers

Data is stored in secure regional data centers with standard contractual clauses (SCCs) and GDPR/CCPA safeguards.

34. Data Security

Enforces AES-256 encryption at rest, TLS 1.3 in transit, role-based access control (RBAC), multi-tenant isolation, and rate-limiting.

35. Passwords & Credentials

Stored using salted cryptographic hashes. Users are responsible for credential confidentiality and MFA enforcement.

36. Data Retention

Retained for active subscription periods plus legal compliance windows.

37. Account Cancellation & Data Deletion

Upon account cancellation, customer data enters a 30-day grace period, after which all mailboxes, stored files, and backups are permanently purged.

38. Customer-Controlled Deletion

Workspace admins can delete users, files, documents, messages, and campaigns directly within the console.

39. Cookies & Similar Technologies

Uses essential session cookies (`inmail-token`, CSRF tokens) required for authentication and security.

40. Analytics

Anonymous telemetry evaluates performance and error rates to maintain uptime reliability.

41. Marketing Communications

Transactional and security emails are mandatory; promotional communications include an opt-out link.

42. Email Marketing Compliance

Senders must maintain recipient opt-in consent, SPF/DKIM/DMARC records, and bounce rates below 5%.

43. Children's Privacy

Inictus is intended for commercial organizations and does not knowingly collect data from children.

44. Your Privacy Rights

Supports rights of access, correction, erasure, portability, and restriction under applicable data protection laws.

45. Organization-Controlled Accounts

Corporate account admins control workspace permissions, data access, and user retention rules.

46. Data Protection Requests

Submit data requests to support@inictus.com with account verification details.

47. Data Breach & Security Incidents

Inictus notifies affected account administrators within 72 hours of a confirmed security incident.

48. Changes to This Privacy Policy

Material changes will be notified via website announcement or email notice prior to taking effect.

49. Governing Law

Governed by the applicable legal jurisdiction of Navkar Infotech Services.

50. Contact Us

Navkar Infotech Services — Product Brand: Inictus

Website: https://inictus.com

Support: support@inictus.com

51. Summary of Our Privacy Commitments

  • ✓ Customer data remains customer-owned.
  • ✓ We do not sell customer business content as a commercial data product.
  • ✓ We process data primarily to provide the services customers request.
  • ✓ We apply enterprise AES-256 and TLS 1.3 security controls.
Need full compliance details across all 10 policies?Legal & Compliance Hub