Rostan DMS
Features Pricing Industry Packs Docs
Sign in Start free
Legal

Privacy Policy

Effective date: 24 May 2026 · Last updated: 24 May 2026
This Privacy Policy explains how Rostan Technologies Pvt Ltd ("Rostan", "we", "us") collects, uses, shares, and protects personal data when you use Rostan DMS. We comply with India's Digital Personal Data Protection Act 2023 (DPDP) and the EU General Data Protection Regulation (GDPR) where applicable.
Contents
  1. Scope
  2. Data we collect
  3. How we use data
  4. Legal bases
  5. Sharing & sub-processors
  6. International transfers
  7. Retention
  8. Security
  9. Your rights
  10. DSAR self-service
  11. Cookies
  12. Children
  13. Changes
  14. Contact & DPO

1. Scope

This Policy covers personal data processed when you visit our website, sign up for a Workspace, or use the Rostan DMS application (collectively, the "Service"). Where we process personal data on your behalf as part of providing the Service to your organisation, we act as a processor and your organisation is the controller; the additional terms in our Data Processing Agreement apply.

2. Data we collect

CategoryExamplesSource
Account dataName, email, password hash, organisation, country, time zone, language, GSTIN, PANYou during sign-up
Workspace contentDocuments you upload, metadata, tags, comments, workflow stateYou during use
Usage telemetryPage views, feature usage, API request volume, error logsAutomatic
Device dataIP address, browser, OS, device fingerprint (only for trusted-device MFA)Automatic
Payment metadataLast 4 digits of card, payment method type, Razorpay token (we never see full card numbers)From Razorpay
CommunicationsSupport tickets, email replies, in-product messagesYou

2.1 What we do not collect

  • We do not require or store full payment card numbers; these are tokenised by Razorpay.
  • We do not collect biometric data centrally; passkey credentials remain on your device.
  • We do not run third-party advertising or social-media trackers on our marketing site.

3. How we use data

  • To provide and maintain the Service, including AI extraction, search, and notifications.
  • To process payments and issue invoices.
  • To respond to support requests and improve the Service via aggregate analytics.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations including KYC, tax, and lawful requests from authorities.
  • To send service notifications (welcome email, magic sign-in link, password reset, payment receipt). These are operational and cannot be unsubscribed from while you have an active account.

We do not use your Workspace content (documents, extracted data) to train third-party AI models. AI extraction runs against Workspace content only for your benefit and within your tenant boundary.

4. Legal bases

  • Contract: processing necessary to provide the Service you have signed up for.
  • Legitimate interests: securing the Service, preventing fraud, improving features.
  • Legal obligation: tax, audit, KYC, lawful authority requests.
  • Consent: only where required, for example optional marketing emails.

5. Sharing & sub-processors

We share personal data only with the sub-processors listed below, each contractually bound to confidentiality and to processing only on our instructions.

Sub-processorPurposeRegion
Oracle Cloud InfrastructureDatabase + application hostingMumbai (ap-mumbai-1)
Razorpay Software Pvt LtdPayment processing (UPI, cards, NetBanking, wallets)India
Microsoft Office 365 (Exchange Online)Transactional email delivery via SMTP relayMulti-region (Microsoft)
Let's EncryptTLS certificate issuanceUSA

We do not sell personal data. We do not share personal data for advertising. The current sub-processor list is published here and we notify customers of changes at least 30 days in advance.

6. International transfers

Primary processing occurs in India. Email delivery via Microsoft Office 365 may transit through Microsoft's global infrastructure. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards for transfers outside India or the EEA.

7. Retention

  • Workspace content: retained while your account is active. After termination, retained for 90 days then deleted (subject to legal hold).
  • Account data: retained while your account is active plus 7 years for tax/audit (Indian Companies Act, GST).
  • Audit log: retained for 7 years (immutable hash chain).
  • Usage telemetry: raw retained 90 days, aggregated retained 24 months.
  • Support tickets: retained 3 years after closure.

8. Security

  • TLS 1.2 / 1.3 in transit; AES-256 at rest.
  • Row-level multi-tenant isolation via Oracle Virtual Private Database (VPD) — zero cross-tenant leak design.
  • Passwords stored as PBKDF2-SHA256 with per-user salt; never reversible.
  • Optional Multi-Factor Authentication (TOTP / SMS / Passkey) per user.
  • Optional E2EE Vault add-on for zero-knowledge documents.
  • Optional Customer-Managed Keys (BYOK) on the Enterprise tier.
  • Quarterly third-party security testing; SOC 2 Type II in progress.
  • Hash-chained audit log of every administrative action.

9. Your rights

Subject to applicable law (DPDP, GDPR), you have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate or incomplete data.
  • Delete personal data (subject to legal retention).
  • Restrict or object to processing.
  • Portability — receive your data in a machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Complain to a supervisory authority (Data Protection Board of India, or your local EU DPA).

To exercise these rights write to notification@rostantechnologies.com. We will respond within 30 days (DPDP) or one month (GDPR).

10. DSAR self-service

Workspace administrators can fulfil data-subject access and erasure requests directly from the in-product DSAR module without contacting us. The module produces an audit-grade response packet within the regulatory deadline.

11. Cookies

The marketing site uses a single first-party session cookie required for the sign-up and sign-in flows. We do not use third-party advertising, analytics, or social-media cookies on the marketing site. The application itself uses session cookies necessary for authentication and CSRF protection. You can disable cookies in your browser, but the application will not function without them.

12. Children

The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without verified parental consent, we will delete it.

13. Changes

We may update this Policy from time to time. We will notify customers of material changes by email and in-product banner at least 30 days before the effective date. The version history is maintained in our public changelog.

14. Contact & DPO

For privacy questions or to exercise your rights, contact:

  • Email: notification@rostantechnologies.com
  • Postal: Rostan Technologies Pvt Ltd, Bengaluru, Karnataka, India
  • Data Protection Officer: appointed and contactable via the email above

A signed DPA (under GDPR Article 28 / DPDP) and a current sub-processor list are available on request. This document is a template provided in good faith and is not a substitute for legal advice tailored to your situation.

Rostan DMS
Pricing Features Terms Privacy
© 2026 Rostan Technologies Pvt Ltd