Privacy Policy

How we collect, use, share and protect your personal data, and the rights you have over it.

Softphoria ("Softphoria", "we", "us" or "our") is a sole proprietorship based in India. We design, build and support websites, software, cloud infrastructure and integrations for clients in India and around the world. This Privacy Policy explains what personal data we collect through localhost:8080 (the "Website"), why we collect it, who we share it with, how long we keep it, and the rights you have over it.

We have written this policy to meet the requirements of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules made under it, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and, where they apply to you, the EU and UK General Data Protection Regulation (GDPR) and applicable United States state privacy laws.

1. Who is responsible for your data

Softphoria is the Data Fiduciary (under the DPDP Act) and the controller (under the GDPR) for personal data collected through this Website.

  • Business: Softphoria (a sole proprietorship)

  • Address: Monalisa Mansion, Nayabad Avenue, Kolkata, West Bengal, India

  • Email: contact@softphoria.com

When we build or run systems for a client, the personal data inside those systems (for example, our client's own customers) is processed on the client's instructions. In that case the client is the Data Fiduciary or controller, we act as their Data Processor, and the terms agreed with that client apply instead of this policy.

2. Personal data we collect

Information you give us

  • Contact and enquiry forms (the Contact page, the quick-contact popup, the side contact tab and contact sections on other pages): your name, email address, phone number (optional), subject and category (optional), and your message.

  • Newsletter sign-up: your email address.

  • Member accounts: your name, email address and password. Passwords are stored only in a securely hashed form that we cannot read.

  • Blog comments, reactions and reports: the text of your comments, the reactions you leave on articles, and the reason and details of any comment you report.

  • Client engagements: the business contact details and project information you share with us when we prepare a proposal or deliver services.

Information collected automatically

  • Enquiry context: when you send an enquiry, we record the page you sent it from (its address and title), which form you used, the button you clicked to open it, and the website that referred you to us. This tells us which service you are asking about so we can respond properly.

  • Device and connection data: your IP address and browser type (user agent) when you submit a form, comment or react, and in our server logs.

  • Approximate location: when you comment on or react to a blog post, we look up the approximate city, region, country and network provider associated with your IP address. We use this only to protect the Website against spam and abuse, and it is visible only to our administrators.

  • Cookies and similar technologies: see our Cookie Policy.

We do not ask for, and ask you not to send us, sensitive personal data such as financial account details, health information, biometric data or government identification numbers through the Website. The only sensitive data we hold is your account password, which is stored in hashed form.

3. How and why we use your data

  • To respond to your enquiries and to prepare proposals, estimates and quotations you ask for.

  • To deliver and support our services, and to manage our relationship with clients, including invoicing and record-keeping.

  • To run member accounts, including email verification, sign-in and password resets.

  • To publish and moderate blog discussions, including handling reports and removing content that breaks our Terms of Service.

  • To send our newsletter if you have subscribed. Every newsletter includes a way to unsubscribe.

  • To keep the Website secure: to detect spam, fraud and abuse, and to investigate security incidents.

  • To comply with the law, including tax, accounting and lawful requests from authorities.

  • To improve the Website and understand which content and services interest visitors.

We do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you. We use analytics or advertising tools only with your consent; any in use are listed under Analytics and marketing tools at the end of this policy.

Under the DPDP Act, we process your personal data on the basis of your consent, which you give when you submit a form, create an account, subscribe, comment or react after being shown this notice. We may also rely on the legitimate uses permitted by Section 7 of the DPDP Act, for example where you voluntarily provide data for a specific purpose, or where we must comply with a law or court order.

Under the GDPR, we rely on:

  • Contract: to take steps you request before entering into a contract, and to perform our contract with you;

  • Legitimate interests: to respond to enquiries, keep the Website secure and prevent abuse, and understand how our services are found. We balance these interests against your rights;

  • Consent: for our newsletter and for any optional cookies. You can withdraw consent at any time;

  • Legal obligation: where the law requires us to keep or disclose information.

4. Who we share your data with

We share personal data only as needed to run the Website and our business, and only with parties bound to protect it:

  • Hosting and infrastructure providers, such as Amazon Web Services, which host the Website and our databases;

  • Email delivery providers, which send confirmation, account and newsletter emails on our behalf;

  • IP geolocation provider (IPinfo), which returns the approximate location of the IP address when you comment or react. Private or local network addresses are never sent;

  • Embedded content providers (such as YouTube or Vimeo), only when you choose to play an embedded video;

  • Analytics and advertising providers, only if you consent to the related cookies — see Analytics and marketing tools below;

  • Professional advisers, such as accountants and lawyers, under a duty of confidentiality;

  • Government, regulatory or law-enforcement authorities, when we are legally required to share data or need to protect our rights, our users or the public;

  • A successor business, if our business is transferred, in which case this policy continues to protect your data.

5. International transfers

We are based in India, and some of our service providers store or process data in other countries, including the United States and the European Union. Where we transfer personal data outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Government of India. Where the GDPR applies and your data is transferred from the EU/EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (or the UK equivalent) offered by our providers.

6. How long we keep your data

  • Enquiries that do not lead to an engagement: up to 3 years from our last contact with you, so we can follow up on the conversation.

  • Client and billing records: for as long as the engagement lasts, and afterwards for the period required by Indian tax and accounting laws.

  • Newsletter subscriptions: until you unsubscribe.

  • Member accounts: until you ask us to delete your account. Published comments are deleted or anonymised along with it.

  • Security data (IP addresses, approximate location, logs): up to 12 months, unless we need it longer to investigate an incident or meet a legal obligation.

When personal data is no longer needed, we delete or anonymise it. Under the DPDP Act, we also erase your personal data when you withdraw consent or when the purpose for which it was collected is no longer being served, unless the law requires us to keep it.

7. How we protect your data

We follow reasonable security practices and procedures, as required by Section 43A of the Information Technology Act, 2000, including:

  • encryption in transit (HTTPS) across the Website;

  • password hashing;

  • restricted, role-based administrator access;

  • audit logging of administrative actions;

  • protection of stored secrets;

  • automated spam and abuse controls;

  • regular updates to our software.

No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India, and any other authority, as the law requires.

8. Your rights

Under the DPDP Act, you have the right to:

  • obtain a summary of the personal data we process about you and how we process it, and the identities of those we have shared it with;

  • have inaccurate or incomplete data corrected or completed, and have your data updated;

  • have your data erased, unless the law requires us to keep it;

  • withdraw your consent at any time. Withdrawing consent does not affect processing that happened before you withdrew it;

  • have your grievances addressed by our Grievance Officer;

  • nominate another person to exercise your rights if you die or become incapacitated.

Under the GDPR, you also have the rights of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. You also have the right to complain to your local data protection supervisory authority.

If you live in a U.S. state with a consumer privacy law (such as California), you may have the right to know, access, correct and delete your personal information. We do not sell personal information. Any advertising tools that could involve "sharing" for cross-context behavioural advertising run only with your consent, which you can withdraw at any time using the cookie preferences icon on every page. We will not discriminate against you for exercising your rights.

To exercise any of these rights, email our Grievance Officer at contact@softphoria.com. We may need to verify your identity before acting on your request. We will respond as quickly as possible and in any case within 30 days. You can also update your account details yourself from your account page, and you can unsubscribe from the newsletter using the link in any newsletter email.

9. Grievance Officer

In accordance with the DPDP Act and the Information Technology Act, 2000 and the rules made under them, our Grievance Officer is:

  • Grievance Officer, Softphoria

  • Email: contact@softphoria.com

  • Address: Monalisa Mansion, Nayabad Avenue, Kolkata, West Bengal, India

We acknowledge grievances promptly and resolve them within the time limits set by applicable law, and in any case within 30 days of receipt. If you are not satisfied with our response, you may complain to the Data Protection Board of India. Residents of the EU/EEA or UK may also contact their local supervisory authority.

10. Children

The Website and our services are intended for businesses and adults. We do not knowingly collect personal data from anyone under 18 years of age (a "child" under the DPDP Act), and member accounts may only be created by adults. If you believe a child has given us personal data, please contact us and we will delete it.

The Website may link to other websites and services, such as social networks or client projects we showcase. Their privacy practices are their own, and we encourage you to read their privacy policies.

12. Language of this notice

This notice is published in English. On request, we will make it available in any language listed in the Eighth Schedule to the Constitution of India. To ask for a translation, email contact@softphoria.com.

13. Changes to this policy

We may update this Privacy Policy from time to time. The "Effective date" at the top shows when it last changed. If we make material changes, we will highlight them on the Website and, where appropriate, notify you by email or ask for your consent again.

14. Contact us

If you have questions about this policy or how we handle your data, email contact@softphoria.com or write to Softphoria, Monalisa Mansion, Nayabad Avenue, Kolkata, West Bengal, India.

Analytics and marketing tools

We do not currently use any analytics or marketing tools on this Website, so no analytics, tracking or advertising cookies are set. If we introduce any, they will be listed here and will only run with your consent.

Questions about this policy?

Our team is happy to help — reach out any time.

Contact us

Quick contact

Let's start a conversation

Tell us a little about what you need — we'll get back to you personally.

Prefer the full form?

We use your details only to respond to your enquiry and never sell them. See our Privacy Policy.