Privacy Policy
Version 2.1 • Last Updated: October 08, 2026
1. Overview & Commitment
MUFAD (operated by proprietor MD MURSALIM, located in Katihar, Bihar, India) is committed to safeguarding your personal data and digital privacy.
This Privacy Policy outlines how we collect, handle, store, and process your personal and business information across our SaaS CRM application, responsive website (mufad.in), Android application, online webinar registration portals, and related digital services.
2. Personal & Business Information We Collect
We collect information that you directly provide when you register an account, subscribe to our CRM, or sign up for webinars/courses:
• Identity & Contact Details: Full Name, Email Address, Mobile Number, WhatsApp Number, and Business/Designation.
• Account Credentials: Usernames and encrypted password hashes. Passwords are never stored in plaintext.
• Billing Information: Billing name, business name, address, state, and pincode for invoice generation.
• Form & CRM Data: Lead details, notes, and custom form configuration created by you to operate your business.
• Technical & Usage Logs: IP address, device type, browser user-agent, operating system, and access timestamps for security and session authorization.
3. How We Handle Payment & Financial Information
• Secure Payment Gateway Processing: MUFAD does NOT store, process, or hold raw debit/credit card numbers, CVVs, expiry dates, net banking passwords, or UPI PINs on our servers.
• All payment transactions are routed securely through Reserve Bank of India (RBI) authorized payment aggregators and gateways adhering to PCI-DSS Level 1 compliance standards.
• We only receive and retain payment transaction references, gateway order IDs, transaction timestamps, payment method type (e.g., UPI, Netbanking, Card), and payment status (Success, Failed, Pending) for accounting, taxation, and subscription provisioning.
4. Purpose & Use of Collected Information
Your information is utilized strictly for lawful business functions, including:
• Provisioning and managing your SaaS CRM dashboard and cloud synchronization.
• Processing registrations and issuing secure webinar/course meeting links via email and WhatsApp.
• Generating authentic tax invoices and verifying payment transactions.
• Providing customer support, responding to grievances, and sending vital account security notifications.
• Ensuring platform security, detecting fraud, and preventing automated bot abuse.
• We do NOT sell, rent, or trade your personal data or your CRM leads to third-party advertisers or data brokers.
5. Cookies & Tracking Technologies
• Essential Authentication Cookies: We use secure HTTP-only cookies strictly necessary to maintain your logged-in session and protect your account from CSRF attacks.
• Preference Cookies: We store user interface preferences (such as light/dark theme selection).
• Zero Third-Party Tracker Injection: We do not sell user behavioral data to external data brokers.
6. Data Security Measures
We employ robust administrative, technical, and physical security procedures including:
• Transport Layer Security (TLS 1.3 / HTTPS encryption) for all data in transit.
• Strong cryptographic password hashing using industry standard algorithms (bcrypt / Argon2).
• Server-side authorization checks preventing unauthorized cross-tenant data access.
• Continuous database backup, automated intrusion monitoring, and rate limiting.
7. Data Retention & Erasure
• Account and lead data is retained for as long as your account remains active.
• Financial and transaction records are retained for the statutory period mandated under Indian tax, GST, and accounting regulations.
• Users may request deletion of their account and associated CRM data at any time by contacting our support desk.
8. Third-Party Service Providers
We partner only with verified infrastructure and communication partners bound by confidentiality and data protection obligations:
• Cloud Hosting & Database Infrastructure: Secure cloud data centers hosting our application.
• Payment Aggregators: RBI-licensed payment gateways for domestic and international payment clearance.
• Transactional Email & Messaging: Service providers for OTP delivery, invoice transmission, and webinar link dispatch.
9. Customer & User Rights
Under applicable data protection laws, you retain the right to:
• Access and review the personal information we hold about you.
• Rectify inaccurate or incomplete contact and profile details.
• Request deletion of non-statutory personal data.
• Opt out of non-essential promotional messages while retaining critical transaction alerts.
10. Grievance Officer & Contact Details
In accordance with the Information Technology Act 2000 and rules made thereunder, the Grievance Officer for MUFAD is:
Name: MD MURSALIM
Designation: Grievance Officer & Proprietor
Address: BRAHAM CHARI TOLA HATHIYA DIYARA, DALAN KATIHAR, BIHAR, India - 854337
Email: support@mufad.in
Contact Phone: +91 91285 24050
Working Hours: Monday to Saturday, 10:00 AM – 06:00 PM IST
Grievances are acknowledged within 24 hours and resolved within 15 working days.
11. Policy Modifications
We may update this Privacy Policy periodically to reflect changes in our operational procedures or applicable legal frameworks.
Material changes will be notified via our website or email. Continued use of our software after notice constitutes acceptance.