Version 2.0

Privacy Policy

This Policy explains how Computer Solutions, operating under the brand Business Ahead, collects, uses, shares, transfers, retains and protects personal data, and sets out your rights and how to exercise them.

  • Version: 2.0
  • Last Updated: 3rd August, 2026
  • Supersedes: Version 1.0 dated 7th July, 2020

Introduction

We respect your right to privacy. This Policy is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under it, and, where they apply, the UK and EU General Data Protection Regulation.

It applies whether you are simply browsing this website, have registered an account, have placed an Order, are an authorised user of a system we operate for our customer, or have contacted us in any other way.

The short version

We collect only what we need in order to run this website, contract with you, deliver and support the Services, take payment, meet our tax and legal obligations, and keep our systems secure. We do not sell personal data, and we do not share it with third parties for their own marketing. Suppliers act on our instructions under written obligations of confidentiality. You can ask us at any time to show you what we hold, correct it, or delete it, subject to records we are legally required to keep. Our Grievance Officer is named in Section 13.

This summary is for convenience only and does not replace the full text below.

  1. Who We Are and What This Covers#

    1. The Data Fiduciary.

      This website, www.BusinessAhead.Net, is operated by Computer Solutions, a proprietorship firm at M-7, Adityapur, Jamshedpur, India, trading as Business Ahead (“we”, “us”, “our”). We are the Data Fiduciary, called the data controller in jurisdictions that use that term, for the personal data described in Section 3. All privacy questions, requests and complaints should go to our Grievance Officer, named in Section 13.1.
    2. What This Policy Covers.

      Personal data processed in connection with your use of this website, the registration and administration of an Account, the placing and fulfilment of Orders, the delivery, hosting, maintenance and support of the Services, billing and collections, our customer communications, and the security and lawful operation of our systems.
    3. Relationship with the Terms of Service.

      This Policy is a separate document from our Terms of Service. It is not a contract, imposes no indemnity or liability obligation on you, and does not create, vary or limit any right under that document. Where a matter is also governed by the Terms of Service, such as backups, security or deletion of data on termination, this Policy explains the privacy consequences and the Terms of Service governs the contractual position. On a contractual question the Terms of Service prevails; on how we handle personal data, this Policy prevails.
    4. Terms Used.

      Personal Data” means any data about an identifiable individual. “Processing” means any operation performed on it. “Data Principal” means the individual to whom it relates, called the data subject in the UK and the EEA. “Data Processor” means a person who processes Personal Data on a Data Fiduciary’s instructions. “End User” means an individual who accesses a system we operate for a customer, including that customer’s staff, members, patients, clients or website visitors. Other capitalised terms have the meaning given in Section 1 of the Terms of Service.
    ↑ Back to top
  2. Our Two Roles#

    Which role we occupy matters, because it determines whom you should approach to exercise your rights.

    1. As Data Fiduciary.

      We are the Data Fiduciary for Personal Data we collect for our own purposes, being the data described in Section 3. We decide why and how it is processed and are answerable to you for it under this Policy.
    2. As Data Processor.

      Where our customer uploads or generates Customer Content within a system we host, and that content contains Personal Data about End Users, our customer is the Data Fiduciary and we act as its Data Processor. In that capacity we process Personal Data only as necessary to provide, secure, support, back up and administer the Services, in accordance with Section 9.3 of the Terms of Service, and as otherwise instructed in writing by the customer or required by Law.
    3. Requests From End Users.

      If you are an End User and wish to exercise rights over data held in a customer’s system, contact that customer first, since we may not alter or release their data without instruction. If you approach us directly, we will refer your request to the relevant customer without undue delay, where we can identify them, and tell you we have done so. Our customers are responsible under Section 9.2 of the Terms of Service for ensuring Customer Content was collected lawfully with all necessary consents, and under Section 9.6 of that document for not placing payment card, health, biometric or government identity data into the Services without a separate written agreement.
    ↑ Back to top
  3. Personal Data We Collect#

    1. Data Minimisation.

      We do not collect Personal Data merely because you visit this website, beyond the technical data in Section 3.3. Personal Data is collected only where you choose to provide it through a clearly labelled form or communication, or where it is generated in the course of providing a Service to you.
    2. Data You Give Us.

      Depending on how you interact with us:
      1. Registration and Account data — name, organisation, designation, email address, telephone number, postal address, country and city, login credentials in hashed form, and communication preferences.
      2. Order, billing and tax data — the Orders you place, billing address, GSTIN or other tax registration number, invoices, receipts and payment status. Where a refund is due we may ask by email for the bank details needed to make the transfer.
      3. Payment data — we do not store complete card numbers, CVV codes or net-banking credentials. Payments are processed by regulated providers, and we receive only the transaction reference, status, amount, method and, where supplied, a masked card identifier. Where you authorise automatic renewal billing under Section 18.3 of the Terms of Service, the payment instrument is stored by the payment provider under its own terms, not by us.
      4. Support and correspondence data — the contents of your emails, support tickets, contact-form submissions, telephone notes and any attachments or diagnostic files you send us.
      5. Survey, feedback and testimonial data, and verification data — the limited information we need to satisfy ourselves that a request under Section 11 genuinely comes from you.
    3. Data Collected Automatically.

      When you visit this website or use a system we operate, we record technical data including your public IP address, browser type and version, device characteristics, operating system, language, referring URL, approximate country derived from the IP address, pages viewed, times of access, and error and diagnostic events. Section 2.3.3 of the Terms of Service also permits us to collect diagnostic, usage, performance and security information about the operation of a Software System. This is used for security, fraud prevention, troubleshooting, capacity planning and analytics, and is generally analysed in aggregate. We may retain and use aggregated and de-identified information for our legitimate business purposes, provided it does not identify you.
    4. Data We Ask You Not to Send.

      Please do not send us, by email, ticket or form, any payment card number, password, health record, biometric identifier or government identity document unless we have asked for it through a secure channel or a separate written agreement is in place. If you do, we may delete it and ask you to resend by a safer route.
    5. Data From Other Sources.

      We may receive limited Personal Data from our payment providers in connection with a transaction, from a colleague who nominates you as an Account contact, from public business sources when verifying a prospective customer, and from sanctions and denied-party screening databases where the checks in Section 18.5 of the Terms of Service are required.
    ↑ Back to top
  4. Cookies#

    1. Categories We Use.

      A cookie is a small text file placed on your device by your browser. References to cookies here include closely related technologies such as local storage and pixels. We use three categories:
      1. Strictly necessary — required for the website and Control Panel to work, including a randomly generated session identifier destroyed when you log out, cross-site request forgery protection, and your currency or language selection. These cannot be switched off without breaking the site, and rest on necessity rather than consent.
      2. Analytics — help us understand how the website is used and where visitors encounter difficulty. Set only with your consent and declinable without loss of functionality.
      3. Marketing — where used, enable measurement of campaign effectiveness and display of our advertising on third-party platforms. Set only with your consent.
    2. Third-Party Cookies and Your Control.

      Some cookies are set by the third-party providers described in Section 7.3, who may act as independent controllers of the data they collect. We do not permit any third party to use cookies on this website for its own unrelated marketing without your consent. Where a cookie banner or preference control is presented you may accept, decline or change your choice at any time; you may also block or delete cookies in your browser, although blocking strictly necessary cookies will prevent you from logging in.
    ↑ Back to top
  5. Why We Process It, and On What Legal Basis#

    1. Purposes and Bases.

      Under the Digital Personal Data Protection Act, 2023 we rely on your consent or, where applicable, on a legitimate use permitted by Section 7 of that Act. Where the UK or EU General Data Protection Regulation applies, we rely on the basis in the final column.
      Purposes of processing and legal bases
      PurposeData usedLegal basis (UK/EU GDPR)
      Creating and administering your Account; accepting and fulfilling Orders; delivering, hosting, maintaining and supporting the ServicesRegistration, Account, Order and support data; technical dataPerformance of a contract
      Invoicing, taking payment, collecting overdue amounts and handling chargebacks under Section 12.7 of the Terms of ServiceOrder, billing, tax and payment dataPerformance of a contract; legal obligation; legitimate interests in recovering sums owed
      Issuing valid invoices and receipts, and keeping books of account and tax recordsOrder, billing and tax dataLegal obligation
      Responding to your enquiries, support requests and complaintsSupport and correspondence dataPerformance of a contract; legitimate interests in responding
      Operating, securing and troubleshooting our systems; detecting and preventing fraud, abuse and unauthorised accessTechnical data; Account dataLegitimate interests in protecting our systems and customers; legal obligation
      Improving the website, analysing usage trends and measuring campaign effectivenessTechnical data; aggregated and de-identified dataConsent (analytics cookies); legitimate interests (aggregated analysis)
      Sending service communications about renewals, releases, maintenance, security and changes to our termsRegistration dataPerformance of a contract; legal obligation
      Sending marketing communications, and publishing a testimonial or customer reference under Section 14.8 of the Terms of ServiceRegistration data and preferences; name, organisation, city or country, service purchased, testimonial textConsent, withdrawable at any time
      Screening against sanctions and denied-party lists under Section 18.5 of the Terms of ServiceName, organisation, countryLegal obligation; legitimate interests in lawful trading
      Establishing, exercising or defending legal claims, and responding to lawful requests from authoritiesAny relevant dataLegal obligation; legitimate interests in the conduct of legal proceedings
    2. What We Do Not Do.

      We do not sell, rent or trade Personal Data, and we do not disclose it to third parties for their own marketing purposes. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
    3. New Purposes.

      If we intend to process your Personal Data for a purpose materially different from those in Section 5.1, we will notify you and, where the law requires, obtain your consent first.
    ↑ Back to top
  6. Consent and Your Choices#

    1. How Consent Is Obtained.

      Where we rely on consent we ask for it separately from any other agreement, by a clear affirmative action such as ticking an unticked box. Consent is never bundled into your acceptance of the Terms of Service, and we do not treat silence or continued browsing as consent for any purpose that requires it.
    2. Withdrawing Consent.

      You may withdraw consent at any time, and doing so is as easy as giving it: use the unsubscribe link in any marketing email, change your preferences in the Control Panel or cookie control, or write to the Grievance Officer named in Section 13.1. Withdrawal takes effect prospectively; it does not affect the lawfulness of earlier processing, nor processing resting on another basis such as our legal obligation to retain invoices. Where consent is withdrawn for processing necessary to provide a Service, we may be unable to continue providing it, and Fees already paid remain subject to Section 12.9 of the Terms of Service.
    3. Service Communications.

      Some communications are not marketing and cannot be opted out of while you hold an Account, because they are necessary to the contract or required by law: invoices and payment reminders, renewal notices, security and incident notifications, scheduled maintenance notices, and notices of changes to our terms or policies.
    ↑ Back to top
  7. Who We Share It With#

    1. Service Providers.

      We share Personal Data with suppliers who perform functions on our behalf and need access to do so: cloud hosting and data centre providers; content delivery and security providers; domain registrars and certificate authorities; email and transactional messaging providers; payment gateways and banks; analytics providers; backup and monitoring providers; and our accountants, auditors and legal advisors. Section 20.9 of the Terms of Service permits us to perform our obligations through such suppliers, and we remain responsible for our own obligations.
    2. Obligations on Suppliers.

      We engage suppliers only where they offer adequate assurances as to security and confidentiality, we bind them to confidentiality obligations at least as protective as those in Section 13 of the Terms of Service, and we permit them to process Personal Data only on our instructions and for the purpose for which it was disclosed.
    3. Third-Party Services and Links.

      This website and the Services may interoperate with Third-Party Services as described in Section 7.3 of the Terms of Service, including payment gateways, Google and Meta services, content delivery networks, analytics providers and other external interfaces. Where such a provider collects Personal Data directly from you or your device, it does so under its own privacy policy and often as an independent controller. We do not control those providers or the external websites we link to, and are not responsible for their content, security or practices. We do not pass your Personal Data to a website merely because we link to it.
    4. Publication of Limited Information.

      With your consent, and in accordance with Section 14.8 of the Terms of Service, we may publish your name or organisation name, city or country, the service purchased and any testimonial you have given, in our portfolio, case studies and marketing materials. We will not publish your Confidential Information, your non-public commercial terms, or End User Personal Data. You may withdraw consent at any time and we will remove the material from our own properties within a reasonable period, although we cannot always recall material already distributed or cached by others.
    5. Law, Rights and Business Transfers.

      We may disclose Personal Data where required by applicable Law or in response to a valid court order, regulatory direction or lawful request by a public authority, and we will tell you first where we are lawfully able to. We may also disclose it where reasonably necessary to investigate or act on suspected fraud, a violation of our terms, a threat to anyone’s safety or an illegal act, or to establish, exercise or defend legal claims, including in any arbitration under Section 20.15 of the Terms of Service. If we are involved in a merger, acquisition, financing or sale of our business, Personal Data may be transferred to the counterparty subject to confidentiality obligations and to its continuing to handle the data under a policy no less protective than this one, and we will notify you of any such transfer affecting your data.
    ↑ Back to top
  8. Artificial Intelligence Tools#

    1. Where AI Tools Are Used.

      As disclosed in Section 8.8 of the Terms of Service, we may use AI Tools when performing the Services, for example to draft content, generate images, produce code suggestions or summarise material.
    2. Personal Data and AI Tools.

      Our practice is not to submit Personal Data to AI Tools, and in particular not Customer Content containing End User Personal Data, unless it is necessary for an agreed purpose and the tool operates under terms that prohibit the provider from using the submitted material to train its models. Where a customer instructs us to use a particular AI Tool, that instruction is a Change Request under Section 8.3 of the Terms of Service and the customer remains the Data Fiduciary for any Personal Data submitted. AI Tools can produce inaccurate output; if AI-assisted material published on a system we operate contains inaccurate Personal Data about you, tell us and we will correct it under Section 11.
    ↑ Back to top
  9. Storage, Security and International Transfers#

    1. Where Data Is Stored.

      Personal Data is stored on servers in data centres in India and the United States, and may be processed in any other country where we or our suppliers maintain facilities. Section 7.1 of the Terms of Service permits us to select, change or replace our data centres and infrastructure suppliers, and we will update this Section if the countries involved change materially.
    2. International Transfers.

      Where Personal Data is transferred outside India we do so in accordance with Section 16 of the Digital Personal Data Protection Act, 2023, and we will not transfer it to any country in respect of which the Central Government has restricted transfers. Where Personal Data protected by the UK or EU General Data Protection Regulation is transferred to a country without an adequacy decision, we put in place an appropriate safeguard, ordinarily the applicable Standard Contractual Clauses together with any supplementary measures required following a transfer risk assessment; a copy may be requested from the Grievance Officer named in Section 13.1.
    3. Security Measures.

      Consistent with Section 10.5 of the Terms of Service, we maintain commercially reasonable technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include encryption in transit using current transport layer security, storage of passwords in salted and hashed form, role-based access control on a need-to-know basis, network and application-level restrictions, logging and monitoring, timely security patching, and the physical controls operated by our data centre providers. No system or transmission over the internet is completely secure, and as recorded in Section 10.6 of that document we cannot warrant absolute security.
    4. Your Part.

      You are responsible for keeping your Account credentials confidential, using a strong and unique password, enabling multi-factor authentication where offered, removing access promptly when a colleague leaves, and telling us without delay if you suspect your Account has been compromised. Section 3.3 of the Terms of Service sets out the corresponding contractual obligation.
    5. Personal Data Breaches.

      If we become aware of a personal data breach affecting your Personal Data, we will notify you and the competent authority to the extent and within the timescales required by applicable Law. Where we act as Data Processor for a customer, we will notify that customer without undue delay under Section 10.8 of the Terms of Service so that it can meet its own obligations. Notification is not an admission of fault or liability.
    ↑ Back to top
  10. How Long We Keep It#

    1. General Principle.

      We keep Personal Data only for as long as necessary for the purpose for which it was collected, or for as long as the law requires us to keep it, whichever is longer. When a retention period ends we delete the data or irreversibly anonymise it.
      Indicative retention periods
      CategoryRetention periodReason
      Account and registration dataFor the life of the Account, then as required by the rows belowProvision of the Services
      Orders, invoices, receipts, payment and tax recordsNot less than eight (8) years from the end of the financial year concernedAccounting, tax and record-keeping obligations in India
      Contracts and records of acceptance of our termsDuration of the contract plus the applicable limitation periodEstablishing and defending legal claims
      Support tickets and correspondenceUp to three (3) years from closureService quality and dispute handling
      Server, application and access logsUp to one hundred and eighty (180) daysSecurity and incident investigation
      Operational backups of hosted systemsThe seven (7) most recent daily backups, on a rolling basis, under Section 10.1 of the Terms of ServiceDisaster recovery
      Marketing contact data and consent recordsUntil consent is withdrawn, then a minimal suppression record kept indefinitelyHonouring your withdrawal and proving we did
      Cookie and consent preferencesUp to twelve (12) months, or until changed by youRespecting your choices
      Customer Content in a hosted systemDeleted after termination under Section 18.6 of the Terms of ServiceContractually agreed offboarding
    2. Closed Accounts and Backups.

      If you stop using the Services and ask us to remove your Personal Data, we will close your Account and remove or minimise your data except for the records identified above that we are required or entitled to retain. Where you have only registered on this website and never purchased a Service, we will delete your Personal Data in full on request. Data already written to a backup cannot be selectively edited, so residual copies may persist until those backups are overwritten in the ordinary cycle; backups are stored securely, isolated from live systems, and used only for restoration.
    ↑ Back to top
  11. Your Rights and How to Exercise Them#

    1. Rights Under Indian Law.

      Subject to the conditions and exemptions in the Digital Personal Data Protection Act, 2023, you have the right:
      1. to obtain a summary of the Personal Data we process about you and of the processing undertaken;
      2. to obtain the identities of other Data Fiduciaries and Data Processors with whom it has been shared, and a description of what was shared;
      3. to have it corrected, completed or updated;
      4. to have it erased, where it is no longer necessary for the purpose collected and we are not required by Law to retain it;
      5. to readily available grievance redressal, as set out in Section 13; and
      6. to nominate another individual to exercise your rights in the event of your death or incapacity.
    2. Additional Rights in the UK and the EEA.

      If you are in the United Kingdom or the European Economic Area you additionally have the right of access to a copy of your Personal Data, to restrict processing, to data portability in a structured, commonly used and machine-readable format, to object to processing based on our legitimate interests, and to object at any time to direct marketing.
    3. Making a Request.

      Much of your Personal Data can be viewed and corrected directly in your Control Panel, which is also a contractual obligation under Section 9.1 of the Terms of Service. Otherwise, write to the Grievance Officer named in Section 13.1, describing the right you wish to exercise and the data concerned. There is no fee. We will take reasonable steps to verify your identity first, and may ask for further information for that purpose only.
    4. Our Response Time.

      We will acknowledge your request within seventy-two (72) hours and respond substantively within thirty (30) days of a verified request. If a request is complex, or we have received several from you, we may extend that period once by up to a further thirty (30) days and will tell you within the original period.
    5. When We May Decline.

      We may decline a request in whole or in part where the law permits or requires it, for example where complying would delete a record we must keep for tax purposes or would adversely affect another person’s rights, or where the request is manifestly unfounded or excessive. If we decline we will tell you why and inform you of your right to complain. Where your request concerns data we process for a customer, Section 2.3 applies.
    6. Your Duties as a Data Principal.

      The Digital Personal Data Protection Act, 2023 requires you, in summary, to comply with applicable Law when exercising your rights, not to impersonate another person when providing Personal Data, not to suppress material information when providing data for any State-issued document or identifier, not to register a false or frivolous grievance, and to furnish only verifiably authentic information when seeking correction or erasure.
    ↑ Back to top
  12. Children#

    1. Not Directed at Children.

      This website and the Services are intended for business use by persons aged eighteen (18) or over. No part of this website is designed to appeal to children, we do not knowingly collect Personal Data from a child, we do not carry out behavioural monitoring of children, and we do not direct advertising at children.
    2. Parental Consent and Deletion.

      Where the Services are to be used for the benefit of a person under eighteen, the parent or lawful guardian must register and place the Order, and by doing so consents to the processing described in this Policy on that person’s behalf. If we learn that we have collected a child’s Personal Data without verifiable parental consent, we will delete it promptly; if you believe this has happened, contact the Grievance Officer named in Section 13.1.
    ↑ Back to top
  13. Grievances, Changes and Governing Law#

    1. Grievance Officer.

      In accordance with the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the following officer is designated to answer questions and address grievances about the processing of Personal Data:
      • Name: Rajeev Kumar
      • Designation: Grievance Officer and Chief Executive Officer, Computer Solutions
      • Address: M-7, Adityapur, Jamshedpur 831013, Jharkhand, India
      • Email:
      • Hours: 09:00 to 17:00 Indian Standard Time, Monday to Friday, excluding public holidays
    2. How We Handle a Grievance.

      We will acknowledge your grievance within seventy-two (72) hours and redress it within thirty (30) days, keeping you informed and explaining the reason if a matter requires longer.
    3. Escalation.

      If you are not satisfied with our response, or we do not respond within that period, you may complain to the Data Protection Board of India in the manner prescribed under the Digital Personal Data Protection Act, 2023. If you are in the United Kingdom or the EEA you may lodge a complaint with your national supervisory authority, in the United Kingdom the Information Commissioner’s Office. We would nevertheless appreciate the chance to resolve your concern first. This Section deals with privacy grievances; a commercial dispute under the Terms of Service is dealt with under Section 20.15 of that document, and nothing here requires you to arbitrate a privacy complaint or restricts your right to approach a supervisory authority.
    4. Changes to This Policy.

      We may update this Policy as our services develop and as data protection law evolves. The current version is always the one published on this page, identified by the “Version” and “Last Updated” fields above. Where a change materially affects how we process your Personal Data or materially reduces your rights, we will give notice before it takes effect, by prominently posting a notice on this website and, where you hold an Account, by email or an alert in your dashboard. Where a change requires your consent, we will obtain it separately and will not rely on your having continued to browse. Earlier versions may be requested from the Grievance Officer.
    5. Governing Law.

      This Policy is governed by the Laws of the Republic of India, consistent with Section 20.14 of the Terms of Service. This does not deprive you of the protection of any mandatory data protection Law applying to you in your country of residence, nor of your right to approach that country’s supervisory authority. If any part of this Policy is held invalid, the remainder continues in effect. This Policy is published in English, and if translated the English version prevails.
    ↑ Back to top