Legal
How we collect, use, share and protect the personal information you give us across our website, Request Portal, WhatsApp support and Careers page.
J P Services ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal data we collect through jpservices.co.in and our related tools — the Request Portal (support and product requests), ticket tracking, feedback form, WhatsApp support, and our Careers page — why we collect it, and how it is used, shared and protected.
We handle personal data in accordance with applicable Indian law, principally:
Both regimes currently operate together. The substantive obligations under the DPDP Act and Rules take full effect on 13 May 2027; until then the SPDI Rules continue to apply, and where the two differ we follow the stricter requirement.
For the purposes of this Policy, J P Services is the Data Fiduciary — the party that decides why and how your personal data is processed — and you are the Data Principal. Sections 1–12 apply to clients and website visitors. Section 13 applies to job applicants. Section 14 covers our own staff.
We only collect information you choose to share with us — typically when you submit a form on the Request Portal, request a quote, raise a support ticket, or message us directly. This may include:
| Category | Examples |
|---|---|
| Contact details | Full name, phone number, email address (optional for Home clients; used as a second verification channel for Business/Government clients) |
| Client & business details | Client type (Home / Business / Government), company or department name, address, area, city, state and pincode — including any additional saved addresses for repeat requests |
| Service & ticket details | Category, sub-category and description of your issue, equipment brand/model, AMC number (if applicable), urgency, preferred contact time, ticket reference number, and any photos, documents or short videos you attach (up to 5MB per file) |
| Verification data | A record that a One-Time Password (OTP) was sent and verified for your phone/email — the OTP code itself is never stored; only a one-way cryptographic hash of it is kept, and only until it expires |
| Feedback | Service star rating and comments submitted after a ticket is resolved, linked to the ticket reference number |
| WhatsApp communications | Messages (text, and any images/files you send) exchanged with our support team over our WhatsApp Business number regarding your ticket, and their delivery/read status |
We do not knowingly collect sensitive personal data (such as financial account details, health information, or government ID numbers) through this Website unless you voluntarily provide it as part of a support request, in which case it is handled with the safeguards described in Section 8. Please avoid including such details in a ticket description or attachment unless they are genuinely necessary for the issue.
Submitting a ticket through the Request Portal requires verifying your phone number with a One-Time Password (OTP). Depending on your client type:
The OTP itself is never stored in plain text — only a one-way SHA-256 hash of it is kept, purely to check what you enter against it, and it automatically expires a few minutes after being sent. Verification attempts are limited, and repeated OTP requests to the same number/email are rate-limited to prevent abuse. We will never ask you to read your OTP back to us over a call or chat — treat any such request as fraudulent.
We process your personal data on the basis of the consent you give when you submit a request, and to perform the service you have asked us for. Specifically:
We do not use your personal data for advertising, behavioural profiling or automated decisions that produce legal effects for you, and we do not sell your personal data to any third party.
When a ticket is assigned, the engineer or delivery staff handling it receives only what they need to complete the visit — your name, phone number, service address, and the category/urgency of your request — sent to them via our WhatsApp system. They do not receive your full ticket history, saved payment details (we don't collect any), or tickets that aren't assigned to them. Our staff are required to use this information solely to deliver the Service and to keep it confidential, in line with Section 29 (Confidentiality & Privacy) of our Terms & Conditions.
Our support team communicates with clients primarily over WhatsApp — using our verified WhatsApp Business number — for ticket confirmations, status updates, and two-way support conversations. These messages (and any files exchanged) are stored against your service ticket for continuity of support. Email is used only for OTPs to Business/Government clients and for transactional account notices.
Every WhatsApp and email message we send is transactional or service-related — tied to a ticket, order or account you have with us. We do not currently send promotional or marketing messages over these channels; if that changes in future, we will ask for your separate opt-in consent as required by law, and you will always be able to opt out of marketing messages without affecting your ability to raise or track a ticket.
We do not sell or rent your personal data. To operate the Request Portal and deliver our Services, we share limited information with:
Each of these providers acts as a Data Processor on our behalf. We require them by contract to process your data only on our instructions and to apply security safeguards equivalent to those we apply ourselves.
Some of the providers above operate global infrastructure and may process or store data on servers located outside India. Section 16 of the Digital Personal Data Protection Act, 2023 permits transfer of personal data to any country or territory outside India except one that the Central Government restricts by notification. We do not transfer personal data to any territory that is so restricted. Wherever data is processed, the contractual and security safeguards described in this Policy continue to apply.
All data and operational details accessed by our personnel during service delivery are treated as confidential, as set out in our Terms & Conditions.
We maintain reasonable security safeguards designed to prevent a personal data breach, of the kind required by Rule 6 of the Digital Personal Data Protection Rules, 2025 and by Rule 8 of the SPDI Rules. These include:
While we take these measures, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
If a personal data breach affects your data, we will inform you without delay, describing the nature and likely consequences of the breach and the steps we are taking. We will also intimate the Data Protection Board of India without delay and furnish a detailed report within 72 hours of becoming aware of the breach, as required by Rule 7 of the Digital Personal Data Protection Rules, 2025.
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to keep it. Once both of those are satisfied, we erase or anonymize it.
| Data | How long we keep it |
|---|---|
| OTP verification records | Expire automatically within minutes of being issued |
| Support / product ticket records, including attachments | 3 years from closure of the ticket |
| WhatsApp support conversations | Retained with the linked ticket — 3 years from closure |
| Feedback ratings and comments | 3 years from submission |
| Client contact and address details | While you are an active client, and for 3 years after your last ticket or order |
| Active AMC, rental or project engagements | For the duration of the engagement, and thereafter as above |
| Invoices, GST and accounting records | 8 years from the end of the relevant financial year — the longest applicable statutory period. Section 36 of the CGST Act, 2017 requires 72 months from the due date of the annual return; s. 128(5) of the Companies Act, 2013, where applicable, requires not less than 8 financial years |
| Job application data | See the retention table in Section 13 |
Where a dispute, assessment, audit or legal proceeding is open, we retain the relevant records until that matter closes. You may request earlier erasure as described in Section 11.
This Website does not use third-party advertising or tracking cookies. If we introduce analytics or cookie-based tools in the future to understand site usage, we will update this Policy accordingly and provide appropriate notice and consent options where required by law.
As a Data Principal you have the following rights under the Digital Personal Data Protection Act, 2023:
If you have a question or complaint about how we handle your personal data, please contact our Grievance Officer:
Grievance Officer — J P Services
Email: contact@jpservices.co.in
Phone: +91 82910 98786
Address: J P Services, Thane 400601, Maharashtra, India
These timelines are set to meet the strictest requirement that applies to us: Rule 5(9) of the SPDI Rules requires a designated Grievance Officer to redress grievances within one month; the Consumer Protection (E-Commerce) Rules, 2020 require acknowledgement within 48 hours and redressal within one month; and s. 13 of the Digital Personal Data Protection Act, 2023 requires a readily available grievance mechanism, with the response period prescribed by the DPDP Rules, 2025.
If you are not satisfied with our response, or we do not respond in time, you may escalate your complaint to the Data Protection Board of India in the manner provided under the Digital Personal Data Protection Act, 2023 and the Rules made under it. Nothing in this Policy limits any right you may have to approach a consumer forum or other competent authority — including your right under s. 34(2)(d) of the Consumer Protection Act, 2019 to complain to the District Commission where you reside or personally work for gain.
This section applies if you apply for a role with us through our Careers page. It sits alongside, not inside, the client-facing sections above.
| Category | Examples |
|---|---|
| Contact details | Full name, phone number, email address, current city |
| Application details | Role or area of interest, willingness to work at the location, notice period, experience level, current designation, expected monthly salary |
| Resume / CV | The document you upload (PDF, DOC or DOCX, up to 5MB) and any information contained in it |
| Qualification details | Highest qualification, course/specialisation, year of passing, skills, and an optional LinkedIn profile link |
| Referral information | How you heard about us, and the name of the employee who referred you, if applicable |
| Assessment records | Interview notes, screening answers, test or skill-assessment results, and our internal evaluation of your application |
| Correspondence | Emails, WhatsApp messages and call records relating to your application |
We process your application on the basis of the consent you give when you submit the Careers form — consent as defined in s. 6 of the Digital Personal Data Protection Act, 2023. You may withdraw that consent at any time by writing to our Grievance Officer (Section 12). Withdrawing consent means we will stop considering you for the role, and we will erase your application data unless we are required by law to retain it.
If you accept an offer of employment with us, your data moves into your employee record. From that point it is handled under the employment-related legitimate use recognised by s. 7(i) of that Act, and under our internal Employee Privacy Notice, which you receive at onboarding (see Section 14).
Where a role requires it, we may verify the information you have given us — including previous employment, education, and, for certain roles, a criminal record check. We will tell you before any verification begins and ask for your specific consent at that point. It is not bundled into your application consent, and you may decline. Declining may mean we cannot proceed with your application for roles where verification is a genuine requirement.
If you give us a referee's contact details, you confirm you have that person's permission to share them with us. We contact referees only at a late stage of the process, and only after telling you we intend to.
We do not sell candidate data and we do not share it with recruitment aggregators or job boards. We will not share your profile with any third party — including a client organisation considering you for placement — without first asking for your separate, specific consent. You may refuse without it affecting any other application you have with us. We may share your data with our email and messaging providers (to communicate with you), our cloud infrastructure provider (where the application is stored), a background verification agency (only with your specific consent, as above), and with authorities where required by law.
| Situation | Retention |
|---|---|
| Application unsuccessful, no consent to stay on file | Erased within 90 days of the outcome being communicated |
| Application unsuccessful, you consented to stay on file | Retained up to 12 months, then erased unless you renew consent |
| Application withdrawn by you | Erased within 30 days |
| Offer made and accepted | Transferred to your employee record (see Section 14) |
| Offer made and declined | Erased within 90 days |
You can ask us at any time for a copy of your application data, to correct it, to erase it, or to take you off our talent pool. Write to our Grievance Officer (Section 12) quoting the role you applied for. The 48-hour acknowledgement and 30-day response commitment in Section 11 applies equally to applicants.
Applications are accepted only from individuals aged 18 years or above. We do not knowingly process the personal data of a child through our Careers page.
J P Services employees who use our internal staff dashboard have separate account data — login credentials, two-factor authentication details, role, leave and HR records. Employee passwords are stored only as salted cryptographic hashes, and authenticator (TOTP) secrets are encrypted at rest.
When a candidate accepts an offer, their application data moves from the recruitment process described in Section 13 into their employee record. From that point it is governed by our internal Employee Privacy Notice, which is provided at onboarding, rather than by the client-facing sections of this Policy. Employees retain the same rights of access, correction, erasure and grievance redressal described in Sections 11 and 12, subject to our statutory record-keeping obligations as an employer.
The Digital Personal Data Protection Act, 2023 treats anyone under the age of 18 as a child. Section 9 requires a Data Fiduciary to obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, or the personal data of a person with a disability who has a lawful guardian.
If we become aware that we have inadvertently collected a child's personal data without verifiable parental consent, we will delete it promptly. If you believe this has happened, please contact our Grievance Officer (Section 12).
We may update this Privacy Policy from time to time to reflect changes in our practices, our Request Portal or Careers functionality, or applicable law. The "Last Updated" date at the top of this page indicates when this Policy was last revised. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention.
For any questions about this Policy, contact our Grievance Officer using the details in Section 12, or reach us using the contact details in the footer below.