Surge

Privacy Policy

Effective Date: August 2026

Information We Collect

We collect essential business information required to operate our solar CRM services. This includes account credentials, contact information (name, email, phone number), and any client or lead data you actively input into your dedicated CRM instance.

Our Role

For your own account and business data, Surge acts as a Data Fiduciary. For personal data of your own leads/customers that you input into your dedicated instance, Surge acts as a Data Processor on your behalf as the Data Fiduciary — you remain responsible for your own end-customers' consent and rights requests under applicable law.

How We Use Your Data

Your data is processed under the principle of Purpose Limitation. We use it solely to provide, secure, and improve the Surge CRM application. We do not sell, rent, or share your leads, customer details, or financial data with third-party marketers or aggregators.

Data Storage & Security

We operate on a Dedicated Instance / Isolated Database architecture. Your data is stored in a completely siloed database, eliminating the risk of cross-tenant leakage. We employ strict access controls, hashing algorithms for credentials, and localized storage protocols.

Data Storage Location: All data is securely hosted on servers physically located in [confirm data center location].

Data Retention

Your data is retained for the duration of an active subscription plus [X days] after cancellation before permanent deletion.

Data Breach Notification

In the event of a personal data breach, we are committed to notifying affected account holders and the Data Protection Board of India in accordance with the requirements of the DPDP Act.

Your Rights under DPDP Act 2023

In compliance with the Digital Personal Data Protection Act of 2023, you retain the following rights over your personal data:

Grievance Officer

For any privacy-related inquiries, grievances, or data requests, please contact our designated Grievance Officer: