1. About this Notice and who we are
This Notice concerns HQL Solutions CRM, supplied by HQL Solutions Private Limited under the HQL Solutions brand. Business address: G1 Carlisle Court, Clover Village, Wanawadi, Pune 411040, Maharashtra, India.
It covers the service, accounts, public enquiry and booking forms, support and business administration. A customer organization’s own privacy notice also applies to its client and professional activities. Additional rights and obligations may apply depending on your location, the customer’s jurisdiction and applicable law.
2. Our roles and your customer organization
For client, lead, application, case and document information (Customer Data), the subscribing organization ordinarily decides the purposes and instructions. HQL operates the software as its processor or service provider. The organization may be a controller, data fiduciary or equivalent responsible organization.
For its own account administration, software subscriptions and billing relationship, platform security, support and service communications, HQL may act independently as a controller or equivalent responsible organization. A role is determined by the activity and applicable law; a contractual label does not remove either party’s statutory duties.
Authorized staff and external professionals receive access appropriate to their assignments and permissions. Giving a professional access does not make HQL your lawyer, immigration consultant or regulated adviser.
3. Information and sources
Information is supplied by account holders, customer staff, applicants, representatives and family members, public enquiry or booking submissions, uploaded documents, connected services and the service’s own operational records. Categories depend on the selected workflow:
- Accounts and professionals: names, email, phone, organization, roles, authentication identifiers, account status, professional credentials and agreements.
- Applicants, leads and family: identity, birth and contact details, nationality/citizenship, residence, passport or government identifiers, marital and family/dependant information.
- Applications: education, employment and work history, language tests, travel and immigration history, visa/refusal information, application answers and supporting evidence.
- Files and communications: documents, photographs, case notes, messages, document reviews, tasks, appointments and correspondence imported through an enabled integration.
- Billing and payment records: estimates, invoices, accounting amounts, payment status, references and connected provider records. Full payment-card credentials should not be placed in case fields or uploads.
- Operations: audit events, service requests, errors, authentication activity and request/network information used to operate and protect the service.
4. Sensitive information and document uploads
Case checklists and uploads can contain health/medical records, police certificates or criminal-history information, financial evidence, national identifiers and photographs. Relevant application questionnaires also ask about political, social or professional organizational memberships, military/intelligence/armed-group history, and security or human-rights declarations. Biometrics-related case steps and records are distinct from a claim that the CRM itself captures fingerprints or performs biometric identification.
Document contents are not confined to the structured fields. Customers must check necessity and authority before submitting sensitive material, restrict access and avoid unrelated information. Where special-category, criminal-data or other heightened rules apply, the appropriate legal condition and any required authorization must be established separately from ordinary account acceptance.
5. Children and dependants
Family and immigration records can contain information about children and dependants. The CRM is a professional/business service and is not designed for independent use by children. An authorized adult, guardian, representative or professional should provide dependant information only for a lawful, necessary case purpose and with any authority or consent required by applicable law.
6. Purposes and processing responsibilities
| Information | Purpose and HQL role | Retention principle |
|---|---|---|
| Accounts and business contacts | Access, subscription administration, support and service communications; independent processing where HQL determines these purposes. | Active relationship and justified administration or legal needs. |
| Client, lead, case and document information | Case administration, communications, document review and customer-enabled assistance; customer-instructed processing. | Customer instructions and applicable professional or legal obligations. |
| Financial records | Customer billing workflows as processor; HQL’s own commercial/accounting administration independently. | Applicable accounting obligations and dispute needs. |
| Audit and security records | Accountability, troubleshooting, access protection and incident investigation; role depends on the event and purpose. | Justified security, accountability and legal needs. |
Customer Data is provided for the contracted service. This Notice does not authorize unrelated advertising, data brokerage or unrestricted reuse of client files.
HQL will not use immigration-client files for unrelated advertising, data brokerage or sale of personal information.
7. Legal grounds and consent where applicable
The responsible organization must identify the lawful ground for each activity. Where the relevant law uses these grounds, they may include a contract with the individual, a legal obligation, legitimate interests subject to the required balancing and safeguards, or valid consent. A company’s subscription contract is not automatically a contract with each employee, applicant or dependant.
For customer-instructed case processing, the customer determines and documents the appropriate ground and any additional sensitive-data condition. HQL remains responsible for grounds and duties applicable to its own independent processing. India and other jurisdictions have their own consent and lawful-processing rules; a GDPR ground is not automatically sufficient elsewhere.
Acknowledging this Notice or accepting software terms is not blanket consent to all personal-data processing. Where consent is relied on, withdrawal can affect the related optional processing; it does not invalidate earlier lawful processing or erase independent legal retention duties.
8. Recipients and connected services
Recipients can include authorized customer users and assigned professionals; personnel with a legitimate support/security need; infrastructure and communications providers; customer-enabled accounting, email, calendar, signature, payment or AI services; and authorities where disclosure is lawfully required. A corporate transaction may involve appropriate confidential due diligence and lawful transfer arrangements.
See the Subprocessor List for providers verified in the reviewed production configuration. Connecting an external account can disclose information to that service under the customer’s authorization and its own contractual terms. An integration’s presence in the product does not mean it is enabled for every customer.
9. International processing and data residency
The reviewed configuration places the primary Supabase database in Canada and the Vercel web/function runtime in the United States. These locations are not a promise that all storage, backups, communications, support access or connected-provider processing remains there. Remote access and onward transfers also matter.
No customer-selectable country-only residency commitment is made by this Notice. Any residency requirement must be expressly agreed and checked against the whole processing chain. Foreign authorities may have lawful access under the laws where information is processed.
Where required, the responsible parties must establish appropriate transfer safeguards and assessments before transferring information. A general DPA is not itself an executed EU SCC, UK IDTA/Addendum or CNDP transfer authorization. Ask the contracting contact for the arrangements applicable to your service. See Regional Privacy Information.
10. Retention framework
- Case and customer records: retained for the service and the customer’s lawful instructions, subject to professional retention requirements and legal holds.
- Accounts and business contacts: managed for the active relationship and justified support, account-administration or legal needs.
- Invoices and accounting: retained according to applicable accounting and contractual requirements, separately from case-workflow status.
- Audit, security and communications: retention must reflect accountability, investigation, service and applicable legal needs.
- Backups and residual copies: erasure and recovery depend on the actual provider arrangements and any legal hold; no fixed backup deletion cycle is promised here.
There is no universal retention period stated for these categories. Case closure, subscription cancellation, archival status or removal of a visible record does not by itself establish complete erasure. Return/deletion arrangements after termination should be agreed with HQL before access ends.
11. Access, export and deletion in practice
Authorized Managers have an organization-record export facility. Its scope is limited: document and chat-attachment binary files are excluded, and some records or large datasets may require separate retrieval. It is not a complete individual-rights export or a verified backup.
Individuals should request access, correction or deletion from the organization managing their case. Requests affecting HQL’s independent processing should use the contact process below. Deletion requires a review of authority, retained copies and legal/professional obligations; this Notice does not promise a one-click account erasure feature.
12. Security and incidents
The Security & Data Handling page describes verified safeguards and their limits. Customer access management, lawful instructions and endpoint protection remain essential.
HQL will investigate suspected incidents affecting the service and take reasonable containment and remediation steps, with notifications to affected customers, individuals or authorities where applicable law and contracts require. A completed investigation is not a prerequisite to any earlier notification required by applicable law or contract. The customer retains notification duties attached to its role; HQL retains its own duties. Different jurisdictions have different triggers, recipients and deadlines.
13. AI, extraction and administrative automation
The product includes deterministic document parsing, application calculations, reminders and workflow rules. Customer-enabled AI assistance can also send structured case information to OpenAI for case-preparation review, or document contents, including complete uploaded files, through Vercel AI Gateway to a model provider for extraction and document analysis. The reviewed document-analysis fallback defaults to an Alibaba/Qwen model; the actual enabled route and provider arrangements must be checked for the customer’s configuration. Resume analysis can use local parsing and an AI fallback where enabled.
These features can process personal and sensitive information present in the input. They support extraction, completeness checks, inconsistencies and professional review; output may be incorrect. The responsible professional must review it. The software does not determine a government’s immigration decision, and a readiness score is not an approval probability.
Enabling AI does not establish legal consent, a valid transfer mechanism, provider training restrictions or zero retention. Customers should confirm the provider/model, processing locations, contractual protections and appropriate data minimization before enabling it for a file. This Notice does not claim that AI never processes client data or that all case automation is free of consequential effects.
15. Individual rights
Depending on applicable law and the circumstances, you may have rights including information about processing, access, correction, deletion, restriction, objection, qualifying portability, withdrawal of consent and a complaint or appeal. Conditions and exemptions differ; every listed right does not apply everywhere.
See Regional Privacy Information for the relevant frameworks and regulator complaint routes. Software terms and a chosen governing law do not remove rights or obligations that cannot lawfully be excluded.
16. Requests, contact and complaints
For immigration/client information, contact the customer organization that provided your account or collected your enquiry. For HQL’s independent account, support, security or business processing, contact Prasad Bhange at admin@hqlsolutions.com. This public channel accepts privacy requests and complaints; an HQL customer agreement is not required to contact it. Postal correspondence may be sent to G1 Carlisle Court, Clover Village, Wanawadi, Pune 411040, Maharashtra, India.
Identify the request and relevant organization with enough detail to locate it, without sending unnecessary sensitive documents. Identity and, where relevant, a representative’s authority may need to be verified proportionately. Requests and complaints must be handled within the requirements of applicable law, including any lawful extension or explanation of refusal. No single response deadline is promised for all countries.
You can also complain to the relevant data-protection authority where that right applies. Asking HQL or your customer first does not limit a statutory complaint right.
