Privacy Policy
Effective for users in India under the Digital Personal Data Protection Act, 2023 (DPDP Act). Indobase Code Pvt. Ltd. ("Indobase", "we", "us") is the Data Fiduciary for personal data described here.
1. Personal data we process
- Account data: name, email, authentication identifiers, organization membership, billing contact details.
- Service data: project metadata, usage telemetry, support tickets, audit logs, and security events.
- Payment data: billing records processed via Razorpay (we do not store full card numbers).
- Customer content: databases, files, and logs in your projects are processed solely to provide the platform. You remain the Data Fiduciary for your end-users' data.
2. Lawful purposes
We process personal data to create and administer accounts, provide the Indobase platform, secure our services, comply with law, bill subscriptions, and—with your consent—for product analytics and marketing communications. We do not sell personal data.
3. Consent
Where consent is the lawful basis, we collect it through sign-up checkboxes, cookie/telemetry controls in the dashboard, and explicit opt-ins. You may withdraw consent at any time via Account → Data & privacy or by contacting privacy@indobase.in. Withdrawal does not affect prior processing.
4. Rights of Data Principals (DPDP)
You may exercise the following rights:
- Access a copy of personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request erasure when retention is no longer necessary
- Nominate another individual to exercise rights on your behalf
- Raise a grievance with our Grievance Officer
Use the Studio dashboard (Account → Data & privacy) or email grievance@indobase.in. See our DPDP notice for timelines.
5. Retention
Account metadata is retained while your account is active. After account deletion, control-plane data is removed within 30 days except where longer retention is required for tax, fraud prevention, or legal obligations. Application data in your projects is deleted when you delete the project or organization, subject to your own legal duties to your users.
6. Security
We use encryption in transit, access controls, row-level security on multi-tenant metadata, audit logging, and least-privilege operations practices. No method of transmission or storage is 100% secure; report concerns to privacy@indobase.in.
7. Cross-border transfers
Primary hosting for Indian customers is intended to remain in India where configured. If personal data is transferred outside India, we do so only where permitted under applicable law and with appropriate safeguards (contractual clauses, vendor due diligence).
8. Children
Indobase is not directed at children under 18. We do not knowingly collect personal data from children without verifiable parental consent as required by law.
9. Data breaches
We maintain incident response procedures. Where required, we will notify the Data Protection Board of India and affected Data Principals in accordance with the DPDP Act.
Cookies & telemetry
We use essential cookies for authentication and session security. Optional analytics cookies are used only with your consent. Manage preferences in Studio under Account → Data & privacy.
10. Contact
Privacy: privacy@indobase.in
Grievance Officer: grievance@indobase.in
Indobase Code Pvt. Ltd.