Arboreal Labs
Privacy Policy
FlowForge OS — Inventory Management System
1. Introduction
This Privacy Policy (“Policy”) describes how Arboreal Labs (“we”, “us”, or “our”) collects, processes, stores, and protects information within the FlowForge OS inventory management platform (“System”) developed and maintained on behalf of our clients. This Policy applies exclusively to each client’s internal staff who access the System in the course of their employment or engagement.
This System is not accessible to the general public and does not collect data from end customers or third-party users. By accessing and using the System, all authorised users acknowledge and agree to the terms set out in this Policy.
Arboreal Labs is committed to handling all data in a lawful, transparent, and responsible manner, in compliance with applicable Indian data protection laws, including the Information Technology Act, 2000 (as amended), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDPA”) to the extent applicable.
2. Scope and Applicability
This Policy applies to:
- All employees, contractors, and authorised personnel who have been granted access to the System.
- All data entered into, stored within, or processed by the System, including but not limited to login credentials, business information, inventory records, financial data, and employee details.
- All devices, browsers, and access points used to connect to the System.
This Policy does not apply to external third-party websites, services, or platforms that may be linked to or referenced by the System.
3. Categories of Data Collected
The System collects and processes the following categories of data solely for the purpose of enabling inventory management functions:
3.1 User Login Credentials
- Email addresses and cryptographically hashed passwords used to authenticate access. Password hashing and authentication is delegated to Amazon Web Services Cognito (“AWS Cognito”) — plaintext passwords are never stored or accessible by Arboreal Labs.
- Session tokens, access logs, and multi-factor authentication (“MFA”) credentials managed by AWS Cognito.
- Device identifiers recorded during authentication.
3.2 Employee Information
- Names, job titles, and department details of staff members who use the System.
- Internal email addresses used for account management and invitation workflows.
- Role-based access permissions and activity logs associated with each user.
3.3 Business and Company Details
- Organisational information such as the client’s registered business name, address, and relevant identifiers.
- Vendor and supplier names, contact persons, and business addresses where applicable to inventory operations.
- Internal operational data required to configure and run the System.
3.4 Product and Inventory Data
- Stock keeping unit (SKU) details, product names, descriptions, and category classifications.
- Inventory quantities, stock levels, warehouse locations, and movement histories.
- Purchase orders, goods received notes, and stock transfer records.
- Supplier and vendor-related product data.
3.5 Financial and Billing Data
- Purchase prices, cost of goods, and procurement budgets associated with inventory.
- Invoice references, billing records, and payment terms linked to inventory transactions.
- Financial summaries and reports generated within the System.
No sensitive personal data as defined under the SPDI Rules (such as biometric data, health information, or financial passwords) is knowingly collected through the System unless explicitly required and separately disclosed.
4. Purpose of Data Processing
All data collected through the System is processed for the following legitimate business purposes only:
- To authenticate and authorise user access to the System and its features.
- To enable the client’s staff to manage, track, and report on inventory levels and movements.
- To maintain accurate records of procurement, stock, and financial transactions related to inventory.
- To generate operational reports and analytics that assist the client in making business decisions.
- To ensure system security, detect unauthorised access, and investigate any incidents.
- To fulfil contractual obligations between Arboreal Labs and the client.
- To comply with applicable legal and regulatory requirements.
Data will not be used for any purpose beyond those stated above without obtaining appropriate authorisation from the client.
5. Access to Data
Access to data within the System is strictly limited and governed by a role-based access control (“RBAC”) framework. This means:
- Each user is granted access only to the data and functions necessary for their specific role and responsibilities.
- Administrative privileges are limited to designated system administrators authorised by the client.
- Arboreal Labs personnel may access the System solely for maintenance, technical support, security auditing, and bug resolution, and only with prior authorisation from the client.
- No unauthorised personnel, third parties, or external entities are granted access to the System or the data it contains.
All access events are logged and may be reviewed by the client’s authorised administrators at any time.
6. Data Sharing and Disclosure
Arboreal Labs does not sell, rent, or trade any data processed through the System. Data may be disclosed only in the following limited circumstances:
- To the client’s authorised personnel as part of normal System operations and support.
- To Arboreal Labs’ internal technical team members who are bound by confidentiality obligations and require access to provide development or support services.
- To third-party sub-processors listed in Section 6A below, strictly to the extent necessary to operate the System.
- To competent government authorities, regulators, or law enforcement agencies where required by applicable law, court order, or legal process.
- In the event of a genuine emergency where disclosure is necessary to protect the vital interests of any individual.
In all cases of third-party disclosure required by law, Arboreal Labs will endeavour to inform the client promptly unless prohibited from doing so by applicable law.
6A. Third-Party Service Providers (Sub-Processors)
To deliver the System, Arboreal Labs engages the following third-party infrastructure providers that process data on our behalf. These providers act as data processors and do not use the data for any independent purpose.
| Provider | Service | Data Processed | Infrastructure |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS Cognito) | Authentication & Identity Management | Email addresses, hashed passwords, session tokens, MFA credentials, device identifiers | United States (AWS globally distributed) |
| Supabase Inc. | Database Hosting & Storage (PostgreSQL) | All application data including user profiles, inventory records, sales orders, work orders, and operational data | United States (AWS infrastructure) |
Both providers maintain industry-standard security certifications including SOC 2 Type II and ISO 27001. Arboreal Labs maintains data processing agreements with each provider in accordance with applicable law.
International Data Transfers: The use of the above providers involves the transfer and storage of data on infrastructure located outside India, including in the United States. Arboreal Labs ensures that appropriate contractual and technical safeguards are in place for any such cross-border data transfers, in accordance with the DPDPA and applicable Indian data protection law. Users and clients who require further information regarding these safeguards may contact us at the address set out in Section 14.
7. Data Storage and Security
Arboreal Labs implements appropriate technical and organisational security measures to protect data against unauthorised access, accidental loss, alteration, or destruction. These measures include:
- Encryption of all data in transit using TLS 1.2 or higher (HTTPS enforced at all entry points).
- Authentication credentials are managed exclusively through AWS Cognito, which employs modern hashing algorithms and never exposes plaintext passwords.
- Application data is stored in a Supabase-managed PostgreSQL database with encryption at rest, row-level security policies, and restricted access credentials.
- Regular security reviews and vulnerability assessments of the System and its dependencies.
- Access logs and audit trails maintained for all user activity within the System.
- Role-based access control enforced at both the application and database layer.
While Arboreal Labs takes all reasonable precautions, no system can guarantee absolute security. In the event of a data breach that is likely to result in risk to individuals, Arboreal Labs will notify the client without undue delay and take all necessary remedial action in accordance with applicable law.
8. Data Retention
Data processed through the System will be retained for as long as is necessary to fulfil the purposes described in this Policy, or as required by applicable law and the client’s internal data retention policies. Specifically:
- User account data will be retained for the duration of the user’s employment or engagement and for a reasonable period thereafter for audit and compliance purposes.
- Inventory and transaction records will be retained in accordance with applicable accounting, tax, and regulatory requirements under Indian law, typically for a period of not less than seven (7) years.
- System access logs will be retained for a minimum of twelve (12) months for security and audit purposes.
Upon termination of the agreement between Arboreal Labs and the client, all data will be returned to the client in an agreed format and/or securely deleted from Arboreal Labs’ systems within a mutually agreed timeframe.
9. Rights of Users
Authorised users of the System have the following rights in respect of their personal data, subject to applicable law and the client’s internal policies:
- Right to Access: Users may request confirmation of what personal data relating to them is held within the System.
- Right to Correction: Users may request correction of inaccurate or incomplete personal data.
- Right to Erasure: Users may request deletion of their personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right to Grievance Redressal: Users have the right to raise concerns about how their data is handled and have those concerns addressed in a timely manner.
Requests to exercise any of the above rights should be directed to the client’s designated system administrator in the first instance. Where appropriate, the client may escalate such requests to Arboreal Labs for technical assistance.
10. Cookies and System Tracking
The System uses session cookies and similar technologies to maintain authenticated user sessions and ensure the correct functioning of the platform. These cookies are strictly necessary for System operation and do not track users for advertising or marketing purposes.
AWS Cognito may set additional browser storage entries as part of its session management. These are used solely for authentication and session continuity.
Access and activity logs are maintained as described in Section 7 for security and operational purposes only. Users are advised that their activity within the System may be monitored by the client’s administrators in accordance with the client’s internal IT and acceptable use policies.
11. User Responsibilities
All authorised users of the System are responsible for:
- Maintaining the confidentiality of their login credentials and not sharing them with any other person.
- Reporting any suspected security incidents, unauthorised access, or data breaches to the system administrator immediately.
- Using the System only for authorised business purposes in accordance with the client’s internal policies.
- Ensuring that data entered into the System is accurate, complete, and up to date.
Any misuse of the System or deliberate breach of this Policy may result in disciplinary action in accordance with the client’s internal HR and IT policies.
12. Governing Law and Jurisdiction
This Policy is governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts in India.
Relevant legislation includes but is not limited to:
- The Information Technology Act, 2000 (as amended by the IT Amendment Act, 2008).
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- The Digital Personal Data Protection Act, 2023.
13. Changes to This Policy
Arboreal Labs reserves the right to update or amend this Policy from time to time to reflect changes in the System, applicable law, or our data handling practices. Any material changes will be communicated to the client, who shall in turn inform all authorised users through appropriate internal channels.
Continued use of the System following notification of any changes shall constitute acceptance of the revised Policy.
14. Contact and Grievance Officer
If you have any questions, concerns, or complaints regarding this Privacy Policy or the handling of your data, please contact:
Arboreal LabsEmail: founders@arboreallabs.com
Website: www.arboreallabs.com
We are committed to resolving any concerns promptly and in a fair and transparent manner, in compliance with applicable Indian law.
Document Version: 1.0 | Effective Date: 13 May 2026 | Prepared by: Arboreal Labs
Questions? founders@arboreallabs.com