Ilonnati Innovations
Water IOT
Ilonnati Innovations Private Limited
Privacy NoticeTerms of ServiceHelp & Support
←Back to Home
DPDP Act 2023 & GDPR Enterprise Compliance•Ilonnati Innovations Private Limited

Privacy Notice & Data Governance Framework

Formal policy detailing data roles, multi-sector governance (B2B, B2C, B2G), military-grade AES-256 encryption, Indian data sovereignty, and compliance standards.

Table of Contents
📋Scope & Role Identification (Data Fiduciary vs Processor)🏢Multi-Sector Governance (B2B, B2C, B2G)📡Categories of Data Collected⚖️Lawful Bases for Processing (DPDP Act & GDPR)🛡️Military-Grade Cryptographic Security Standards🇮🇳Indian Data Sovereignty & Localization🔗Sub-Processors & Data Sharing⏳Data Retention & Secure Disposal👤Your Rights & Grievance Redressal (DPDP Act)📧Data Protection Officer & Grievance Contact⚡Technical Infrastructure & Engineering Maintenance
Legal Documentation
Effective Date: Jan 1, 2026
Version: 2.4 (Enterprise/Gov)

📋1. Scope & Role Identification (Data Fiduciary vs Processor)

This Privacy Notice outlines how Ilonnati Innovations Private Limited ("Ilonnati," "we," "us," or "our") collects, processes, encrypts, stores, and safeguards personal data, technical telemetry, and operational logs across the Water IOT Enterprise Infrastructure Platform, edge IoT gateways, mobile applications, and web dashboards.

To maintain transparency under global privacy frameworks (including the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and the General Data Protection Regulation (GDPR)), our legal role is identified as follows:

A. Data Fiduciary / Controller: Ilonnati acts as a Data Fiduciary regarding personal information collected directly from website visitors, primary account administrators, billing contacts, and commercial leads.
B. Data Processor: For water utility meter telemetry, municipal pipeline SCADA data, and end-consumer meter readings uploaded by our Enterprise (B2B) or Government (B2G) clients, Ilonnati acts strictly as a Data Processor operating under contractually binding Data Processing Addendums (DPAs).

🏢2. Multi-Sector Governance (B2B, B2C, B2G)

Water IOT manages water distribution telemetry across three distinct operating tiers, each governed by specialized data privacy protocols:

  • Enterprise B2B Operations: Governs commercial real estate, industrial manufacturing plants, private utility networks, and bulk water distributors. Commercial flow rates and factory intake volumes are classified as Proprietary Commercial Telemetry and restricted from public disclosure.
  • Consumer B2C Citizen Portal: Governs residential water meters, housing societies, and apartment tenants. Adheres to strict individual data minimization rules, ensuring consumption profiles are never monetized, profiled for advertising, or disclosed to unauthorized parties.
  • Public Sector B2G Municipalities: Governs Municipal Corporations, Urban Local Bodies (ULBs), Smart City Missions, and Jal Jeevan Mission projects. Municipal pipeline topologies, regional pressure mapping, and district metered area (DMA) balances are classified as Confidential Critical Infrastructure Data.

📡3. Categories of Data Collected

We process data across distinct technical categories:

A. Infrastructure Telemetry & Sensor Metrics

  • Instantaneous flow rate (L/min, m³/hr), cumulative meter index, forward/reverse totalizers, and differential line pressure.
  • Battery state of charge, ambient sensor temperature, tamper detection signals, signal strength (RSSI/SNR), and valve actuator status (Open/Closed/Fault).
  • Hardware DevEUI, IMEI, serial numbers, firmware version, and assigned spatial DMA coordinates.

B. Account & Identity Information

  • Work email address, user display name, telephone number, job title, and organization affiliation.
  • Salted and hashed password credentials (Bcrypt cost factor 12) and multi-factor authentication (MFA) tokens.
  • IP sign-in logs, browser user-agent strings, session identifiers, and cryptographic audit records of valve actuation commands.

⚖️4. Lawful Bases for Processing (DPDP Act & GDPR)

We process data only when supported by legitimate, lawful grounds:

  • Performance of Contract: Necessary to ingest meter readings, execute valve automation rules, generate consumption invoices, and fulfill enterprise SLA commitments.
  • Explicit Consent (DPDP Act 2023): For B2C residential users, processing relies on informed, specific, unbundled consent obtained during account setup. Consent may be revoked at any time via portal settings.
  • Legal Obligation & Public Interest: Compliance with statutory utility reporting mandates, municipal health emergencies, or CERT-In directives.
  • Legitimate Technical Interest: Preventing cyber intrusion, enforcing multi-tenant database isolation, and maintaining system availability.

🛡️5. Military-Grade Cryptographic Security Standards

Ilonnati enforces military-grade security architecture to protect critical water networks:

🔐 AES-256-GCM Encryption at Rest
FIPS 140-3 compliant hardware disk encryption protecting database clusters, PostGIS mapping, and snapshot backups.
🌐 TLS 1.3 & mTLS In Transit
Mutual TLS X.509 client certificate verification for IoT edge gateways and SCADA bridges.
🔑 Hardware Security Modules (HSM)
FIPS 140-2 Level 3 certified HSM key management for master root certificates and token signing.

🇮🇳6. Indian Data Sovereignty & Localization

All government (B2G), enterprise (B2B), and citizen (B2C) telemetry processed by Water IOT is stored exclusively within MeitY-empaneled Tier-IV data centers located physically within the territory of India.

  • No critical water infrastructure telemetry or municipal SCADA topography is exported abroad without express written government clearance.
  • Government clients may opt for dedicated air-gapped on-premise deployments or private government cloud instances.

🔗7. Sub-Processors & Data Sharing

We do not sell, monetize, or rent data. We share telemetry and personal data only with authorized sub-processors bound by strict Data Processing Addendums (DPAs):

Sub-Processor EntityProcessing PurposeData Location
Google Cloud Platform (MeitY Empaneled)Cloud Hosting, DB Clusters & Telemetry StorageMumbai & Delhi, India
Twilio & Local SMS Telephony GatewaysEmergency SMS Leak Alarms & OTP VerificationIndia Data Residency

⏳8. Data Retention & Secure Disposal

Data retention follows strict technical timelines:

  • High-Resolution Telemetry (15-min intervals): Retained for 24 months for active analytics and leak diagnosis.
  • Aggregated Monthly Volume Totals: Retained for 7 years for utility billing audit compliance.
  • Account Disposal: Upon contract termination, personal data is permanently purged within 30 days using NIST SP 800-88 compliant cryptographic sanitization.

👤9. Your Rights & Grievance Redressal (DPDP Act)

Under the DPDP Act 2023 and applicable privacy laws, users have the right to:

  • Access a summary of personal data being processed.
  • Correct or update inaccurate account credentials.
  • Withdraw consent for optional notification feeds.
  • Nominate an authorized representative in the event of incapacity.

To exercise rights or file a privacy grievance, contact our Data Protection Officer below. Grievances are acknowledged within 24 hours and resolved within 15 business days.

📧10. Data Protection Officer & Grievance Contact

🏢 Designated Data Protection Officer / Grievance Officer:
Dr. RVRK Chalam, Nodal Lead & Compliance Desk
Ilonnati Innovations Private Limited
📍 Plot No. 42 & 43, Smart Water IoT Tech Park, Phase II, HITEC City, Jubilee Hills, Hyderabad, Telangana - 500081, India
✉️ Email: dpo@ilonnatiinnovations.com / support@ilonnatiinnovations.com
📞 Hotline: +91 9866740428 / +91 40 2956 4000

⚡11. Technical Infrastructure & Engineering Maintenance

Water IOT software systems, real-time analytics engines, and edge device interfaces are Architected, Engineered & Maintained by Sripto Corporation Private Limited.

🛡️ Systems Maintenance & Data Security Assurance:
  • Data Protection Alignment: Sripto Corporation Private Limited adheres to statutory DPDP Act 2023 principles and enterprise Data Processing Addendums (DPAs).
  • Zero-Access Telemetry Safeguards: Edge telemetry data is processed in transit using AES-256-GCM and TLS 1.3 encryption with strict tenant boundary isolation.
  • Engineering Governance: Platform development, security hardening, continuous updates, and systems maintenance are managed by Sripto Corporation Private Limited.
⚡
Enterprise Platform Architecture & Core Systems
Architected, Engineered & Maintained bySripto Corporation Private Limited
Mission-Critical SCADA & IoT Telemetry Core
Water IOT|Smart Water Infrastructure•© 2026
Privacy•Terms•Help
|
Product ofIlonnati Innovations Private Limited
•
Architected, Engineered & Maintained bySripto Corporation Private Limited