Privacy Policy

We respect your privacy and are committed to protecting the personal data you share with us.

Last Updated: 1 May 2025   |   Applicable Jurisdiction: India (IT Act 2000 & DPDP Act 2023)
Privacy at a Glance
We do not sell your personal data — ever.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
You can request access, correction, or deletion of your data at any time.
We use minimal cookies — only essential and analytics (opt-out available).
Data is stored in India; no cross-border transfers without your consent.
Privacy queries answered within 30 days as required by DPDP Act 2023.
01

Overview

SRC Data Infotech Private Limited ("SRC Data Infotech", "we", "our", or "us") is a software and IT services company registered in Bhubaneswar, Odisha, India. We operate the website at www.srcdatainfotech.com (the "Site") and related digital properties.

This Privacy Policy explains what personal data we collect when you visit the Site, engage our services, or communicate with us; why we collect it; how we use, store, and protect it; with whom we may share it; and the rights you hold over your information.

By accessing the Site or submitting your information to us, you acknowledge that you have read and understood this policy. If you do not agree, please refrain from using the Site.

This policy is governed by the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act), as applicable.

02

Data We Collect

2.1 Information You Provide Directly

Data TypeWhen CollectedExamples
Contact detailsContact form, email, phoneName, email address, phone number
Business informationEnquiry / project briefCompany name, designation, industry, budget range
Project / service detailsConsultation, proposal requestProject description, technology preferences, timelines
Correspondence contentEmail, calls, meetingsMessages, meeting notes, attachments
Account credentialsClient portal registrationUsername, hashed password

2.2 Data Collected Automatically

When you visit the Site, our servers and analytics tools automatically record:

  • IP address and approximate geographic location (country / city level)
  • Browser type, version, and operating system
  • Pages visited, time on page, referrer URL, and exit page
  • Device type (desktop, tablet, mobile) and screen resolution
  • Date and time of each visit
  • Cookies and similar tracking identifiers (see §6)

2.3 Sensitive Personal Data

We do not intentionally collect Sensitive Personal Data or Information (SPDI) as defined under the IT Rules 2011 (e.g., financial credentials, health data, biometric data) through the Site. If such data is incidentally shared, it will be handled with heightened security controls and deleted promptly unless operationally necessary with your explicit consent.

03

How We Use Your Data

We use the personal data we collect for the following purposes:

Responding to enquiries

Processing contact form submissions, emails, and consultation requests and delivering your requested quote or proposal.

Delivering contracted services

Executing software development, cloud, analytics, or other IT services as agreed in a signed Statement of Work or contract.

Billing & invoicing

Generating invoices, processing payments, and maintaining financial records as required by Indian tax laws.

Service & project communication

Sending project updates, milestone notifications, support tickets, and release notes related to your engagement.

Marketing communications

Sending newsletters, case studies, and product announcements — only with your explicit prior consent. Unsubscribe is available in every email.

Site analytics & improvement

Understanding how visitors use the Site, identifying performance issues, and improving content and user experience.

Security & fraud prevention

Detecting, investigating, and preventing malicious activity, abuse, or unauthorised access to our systems.

Legal & regulatory compliance

Fulfilling our obligations under Indian law including the IT Act, DPDP Act, GST Act, and applicable sector regulations.

05

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We may share it in the limited circumstances below:

5.1 Service Providers (Data Processors)

We engage trusted third-party vendors who process data strictly on our behalf under written data processing agreements:

  • Cloud hosting: Microsoft Azure (India South region) — server infrastructure
  • Email delivery: SendGrid / Microsoft 365 — transactional and marketing emails
  • Analytics: Google Analytics 4 (anonymised, IP masking enabled) — site usage insights
  • CRM: Internal self-hosted system — enquiry and project management
  • Payment processing: Razorpay — invoice payments (PCI-DSS compliant; we never store card data)

5.2 Legal Disclosures

We may disclose personal data if required to do so by law, court order, or governmental authority, or to defend our legal rights, prevent fraud, or protect the safety of individuals.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same protections described in this policy. We will notify you via email or a prominent Site notice.

5.4 Aggregated / Anonymised Data

We may share aggregated, anonymised statistics (e.g., "we served 200+ enterprise clients") that cannot reasonably identify any individual.

06

Cookies & Tracking Technologies

We use cookies and similar technologies on the Site. You can manage your preferences via our cookie banner or browser settings.

CategoryPurposeCan Opt Out?
Strictly Necessary Session management, CSRF protection, load balancing No — required for the Site to function
Analytics Aggregate page-view statistics (Google Analytics 4, anonymised) Yes — via cookie banner or GA opt-out extension
Preferences Remember your language or accessibility settings Yes — via cookie banner
Marketing / Retargeting Not currently used N/A

Most browsers allow you to block or delete cookies via their settings. Note that disabling necessary cookies may affect the Site's functionality.

07

Data Retention

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law.

Data CategoryRetention Period
Website enquiry / contact form submissions2 years from last interaction, then anonymised
Client project records & contracts7 years after project completion (Companies Act 2013)
Financial & invoicing records8 years (GST Act requirement)
Marketing consent recordsUntil withdrawal of consent + 3 years
Server / application logs90 days rolling
Backup archives180 days, then securely deleted

Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised using NIST SP 800-88 guidelines.

08

Security Measures

We implement a layered security programme aligned with ISO/IEC 27001:2022 and the IT (Reasonable Security Practices) Rules, 2011:

Encryption

TLS 1.3 for all data in transit; AES-256 for data at rest on Azure infrastructure.

Access Controls

Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege.

Security Audits

Annual third-party penetration tests and quarterly vulnerability assessments.

Monitoring

24/7 SIEM-based monitoring with automated anomaly detection and incident alerting.

Employee Training

Mandatory security awareness training for all staff with annual refreshers.

Incident Response

Documented incident response plan; affected users notified within 72 hours of a confirmed breach.

While we implement industry-standard safeguards, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and to contact us immediately at info@srcdatainfotech.com if you suspect unauthorised access to your account.

09

Your Data Rights

Under the DPDP Act 2023 and applicable Indian law, you have the following rights regarding your personal data. To exercise any of these rights, email us at info@srcdatainfotech.com. We will respond within 30 calendar days.

Right to Access

Request a copy of all personal data we hold about you, including details of how it is being used and with whom it has been shared.

Right to Correction

Request correction of any inaccurate, incomplete, or outdated personal data without undue delay.

Right to Erasure

Request deletion of your personal data where it is no longer necessary for the purpose it was collected, or where you withdraw consent.

Right to Restrict Processing

Ask us to suspend processing of your data in certain circumstances — for example, while a correction request is being assessed.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format (JSON / CSV) to transfer to another provider.

Right to Object

Object to processing based on legitimate interest, including direct marketing. We will stop unless we demonstrate compelling grounds.

Right to Withdraw Consent

Withdraw any previously given consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right to Lodge a Complaint

File a complaint with the Data Protection Board of India if you believe we have mishandled your data. We encourage you to contact us first.

We may need to verify your identity before processing a rights request. Requests relating to data held under a contractual obligation may be subject to legal retention requirements that override erasure requests.

10

Children's Privacy

Our services and Site are directed exclusively to businesses and professionals. We do not knowingly collect, use, or store personal data from individuals under the age of 18 years.

If we become aware that a minor has submitted personal data to us, we will delete it promptly. If you believe a minor's data has been submitted, contact us immediately at info@srcdatainfotech.com.

11

Third-Party Links & Integrations

The Site may contain links to external websites, social media platforms (LinkedIn, Twitter/X, GitHub), or partner portals that are not operated by us. This Privacy Policy does not apply to those third-party sites.

We encourage you to review the privacy policies of any external site you visit. We have no control over and accept no responsibility for their content, privacy practices, or data handling.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Display a prominent notice on the Site homepage for 30 days
  • Send an email notification to registered users and active clients

Your continued use of the Site after any update constitutes acceptance of the revised policy. We recommend revisiting this page periodically.

13

Contact Us & Data Protection Officer

For any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact:

Data Protection Officer

info@srcdatainfotech.com

Registered Office

Bhubaneswar, Odisha 751001
India

+91 99 2071 0011

We aim to acknowledge all privacy requests within 5 business days and resolve them within 30 calendar days as mandated by the DPDP Act 2023. Complex requests may take up to 60 days — we will inform you if this is the case.