📋1. Scope & Role Identification (Data Fiduciary vs Processor)
This Privacy Notice outlines how Ilonnati Innovations Private Limited ("Ilonnati," "we," "us," or "our") collects, processes, encrypts, stores, and safeguards personal data, technical telemetry, and operational logs across the Water IOT Enterprise Infrastructure Platform, edge IoT gateways, mobile applications, and web dashboards.
To maintain transparency under global privacy frameworks (including the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and the General Data Protection Regulation (GDPR)), our legal role is identified as follows:
🏢2. Multi-Sector Governance (B2B, B2C, B2G)
Water IOT manages water distribution telemetry across three distinct operating tiers, each governed by specialized data privacy protocols:
- Enterprise B2B Operations: Governs commercial real estate, industrial manufacturing plants, private utility networks, and bulk water distributors. Commercial flow rates and factory intake volumes are classified as Proprietary Commercial Telemetry and restricted from public disclosure.
- Consumer B2C Citizen Portal: Governs residential water meters, housing societies, and apartment tenants. Adheres to strict individual data minimization rules, ensuring consumption profiles are never monetized, profiled for advertising, or disclosed to unauthorized parties.
- Public Sector B2G Municipalities: Governs Municipal Corporations, Urban Local Bodies (ULBs), Smart City Missions, and Jal Jeevan Mission projects. Municipal pipeline topologies, regional pressure mapping, and district metered area (DMA) balances are classified as Confidential Critical Infrastructure Data.
📡3. Categories of Data Collected
We process data across distinct technical categories:
A. Infrastructure Telemetry & Sensor Metrics
- Instantaneous flow rate (L/min, m³/hr), cumulative meter index, forward/reverse totalizers, and differential line pressure.
- Battery state of charge, ambient sensor temperature, tamper detection signals, signal strength (RSSI/SNR), and valve actuator status (Open/Closed/Fault).
- Hardware DevEUI, IMEI, serial numbers, firmware version, and assigned spatial DMA coordinates.
B. Account & Identity Information
- Work email address, user display name, telephone number, job title, and organization affiliation.
- Salted and hashed password credentials (Bcrypt cost factor 12) and multi-factor authentication (MFA) tokens.
- IP sign-in logs, browser user-agent strings, session identifiers, and cryptographic audit records of valve actuation commands.
⚖️4. Lawful Bases for Processing (DPDP Act & GDPR)
We process data only when supported by legitimate, lawful grounds:
- Performance of Contract: Necessary to ingest meter readings, execute valve automation rules, generate consumption invoices, and fulfill enterprise SLA commitments.
- Explicit Consent (DPDP Act 2023): For B2C residential users, processing relies on informed, specific, unbundled consent obtained during account setup. Consent may be revoked at any time via portal settings.
- Legal Obligation & Public Interest: Compliance with statutory utility reporting mandates, municipal health emergencies, or CERT-In directives.
- Legitimate Technical Interest: Preventing cyber intrusion, enforcing multi-tenant database isolation, and maintaining system availability.
🛡️5. Military-Grade Cryptographic Security Standards
Ilonnati enforces military-grade security architecture to protect critical water networks:
🇮🇳6. Indian Data Sovereignty & Localization
All government (B2G), enterprise (B2B), and citizen (B2C) telemetry processed by Water IOT is stored exclusively within MeitY-empaneled Tier-IV data centers located physically within the territory of India.
- No critical water infrastructure telemetry or municipal SCADA topography is exported abroad without express written government clearance.
- Government clients may opt for dedicated air-gapped on-premise deployments or private government cloud instances.
🔗7. Sub-Processors & Data Sharing
We do not sell, monetize, or rent data. We share telemetry and personal data only with authorized sub-processors bound by strict Data Processing Addendums (DPAs):
| Sub-Processor Entity | Processing Purpose | Data Location |
|---|---|---|
| Google Cloud Platform (MeitY Empaneled) | Cloud Hosting, DB Clusters & Telemetry Storage | Mumbai & Delhi, India |
| Twilio & Local SMS Telephony Gateways | Emergency SMS Leak Alarms & OTP Verification | India Data Residency |
⏳8. Data Retention & Secure Disposal
Data retention follows strict technical timelines:
- High-Resolution Telemetry (15-min intervals): Retained for 24 months for active analytics and leak diagnosis.
- Aggregated Monthly Volume Totals: Retained for 7 years for utility billing audit compliance.
- Account Disposal: Upon contract termination, personal data is permanently purged within 30 days using NIST SP 800-88 compliant cryptographic sanitization.
👤9. Your Rights & Grievance Redressal (DPDP Act)
Under the DPDP Act 2023 and applicable privacy laws, users have the right to:
- Access a summary of personal data being processed.
- Correct or update inaccurate account credentials.
- Withdraw consent for optional notification feeds.
- Nominate an authorized representative in the event of incapacity.
To exercise rights or file a privacy grievance, contact our Data Protection Officer below. Grievances are acknowledged within 24 hours and resolved within 15 business days.
📧10. Data Protection Officer & Grievance Contact
Dr. RVRK Chalam, Nodal Lead & Compliance Desk
Ilonnati Innovations Private Limited
📍 Plot No. 42 & 43, Smart Water IoT Tech Park, Phase II, HITEC City, Jubilee Hills, Hyderabad, Telangana - 500081, India
✉️ Email: dpo@ilonnatiinnovations.com / support@ilonnatiinnovations.com
📞 Hotline: +91 9866740428 / +91 40 2956 4000
⚡11. Technical Infrastructure & Engineering Maintenance
Water IOT software systems, real-time analytics engines, and edge device interfaces are Architected, Engineered & Maintained by Sripto Corporation Private Limited.
- Data Protection Alignment: Sripto Corporation Private Limited adheres to statutory DPDP Act 2023 principles and enterprise Data Processing Addendums (DPAs).
- Zero-Access Telemetry Safeguards: Edge telemetry data is processed in transit using AES-256-GCM and TLS 1.3 encryption with strict tenant boundary isolation.
- Engineering Governance: Platform development, security hardening, continuous updates, and systems maintenance are managed by Sripto Corporation Private Limited.
