1. Scope
This Policy covers personal data processed when you visit our website, sign up for a Workspace, or use the Rostan DMS application (collectively, the "Service"). Where we process personal data on your behalf as part of providing the Service to your organisation, we act as a processor and your organisation is the controller; the additional terms in our Data Processing Agreement apply.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, password hash, organisation, country, time zone, language, GSTIN, PAN | You during sign-up |
| Workspace content | Documents you upload, metadata, tags, comments, workflow state | You during use |
| Usage telemetry | Page views, feature usage, API request volume, error logs | Automatic |
| Device data | IP address, browser, OS, device fingerprint (only for trusted-device MFA) | Automatic |
| Payment metadata | Last 4 digits of card, payment method type, Razorpay token (we never see full card numbers) | From Razorpay |
| Communications | Support tickets, email replies, in-product messages | You |
2.1 What we do not collect
- We do not require or store full payment card numbers; these are tokenised by Razorpay.
- We do not collect biometric data centrally; passkey credentials remain on your device.
- We do not run third-party advertising or social-media trackers on our marketing site.
3. How we use data
- To provide and maintain the Service, including AI extraction, search, and notifications.
- To process payments and issue invoices.
- To respond to support requests and improve the Service via aggregate analytics.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations including KYC, tax, and lawful requests from authorities.
- To send service notifications (welcome email, magic sign-in link, password reset, payment receipt). These are operational and cannot be unsubscribed from while you have an active account.
We do not use your Workspace content (documents, extracted data) to train third-party AI models. AI extraction runs against Workspace content only for your benefit and within your tenant boundary.
4. Legal bases
- Contract: processing necessary to provide the Service you have signed up for.
- Legitimate interests: securing the Service, preventing fraud, improving features.
- Legal obligation: tax, audit, KYC, lawful authority requests.
- Consent: only where required, for example optional marketing emails.
5. Sharing & sub-processors
We share personal data only with the sub-processors listed below, each contractually bound to confidentiality and to processing only on our instructions.
| Sub-processor | Purpose | Region |
|---|---|---|
| Oracle Cloud Infrastructure | Database + application hosting | Mumbai (ap-mumbai-1) |
| Razorpay Software Pvt Ltd | Payment processing (UPI, cards, NetBanking, wallets) | India |
| Microsoft Office 365 (Exchange Online) | Transactional email delivery via SMTP relay | Multi-region (Microsoft) |
| Let's Encrypt | TLS certificate issuance | USA |
We do not sell personal data. We do not share personal data for advertising. The current sub-processor list is published here and we notify customers of changes at least 30 days in advance.
6. International transfers
Primary processing occurs in India. Email delivery via Microsoft Office 365 may transit through Microsoft's global infrastructure. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards for transfers outside India or the EEA.
7. Retention
- Workspace content: retained while your account is active. After termination, retained for 90 days then deleted (subject to legal hold).
- Account data: retained while your account is active plus 7 years for tax/audit (Indian Companies Act, GST).
- Audit log: retained for 7 years (immutable hash chain).
- Usage telemetry: raw retained 90 days, aggregated retained 24 months.
- Support tickets: retained 3 years after closure.
8. Security
- TLS 1.2 / 1.3 in transit; AES-256 at rest.
- Row-level multi-tenant isolation via Oracle Virtual Private Database (VPD) — zero cross-tenant leak design.
- Passwords stored as PBKDF2-SHA256 with per-user salt; never reversible.
- Optional Multi-Factor Authentication (TOTP / SMS / Passkey) per user.
- Optional E2EE Vault add-on for zero-knowledge documents.
- Optional Customer-Managed Keys (BYOK) on the Enterprise tier.
- Quarterly third-party security testing; SOC 2 Type II in progress.
- Hash-chained audit log of every administrative action.
9. Your rights
Subject to applicable law (DPDP, GDPR), you have the right to:
- Access a copy of your personal data.
- Correct inaccurate or incomplete data.
- Delete personal data (subject to legal retention).
- Restrict or object to processing.
- Portability — receive your data in a machine-readable format.
- Withdraw consent where processing is based on consent.
- Complain to a supervisory authority (Data Protection Board of India, or your local EU DPA).
To exercise these rights write to notification@rostantechnologies.com. We will respond within 30 days (DPDP) or one month (GDPR).
10. DSAR self-service
Workspace administrators can fulfil data-subject access and erasure requests directly from the in-product DSAR module without contacting us. The module produces an audit-grade response packet within the regulatory deadline.
11. Cookies
The marketing site uses a single first-party session cookie required for the sign-up and sign-in flows. We do not use third-party advertising, analytics, or social-media cookies on the marketing site. The application itself uses session cookies necessary for authentication and CSRF protection. You can disable cookies in your browser, but the application will not function without them.
12. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without verified parental consent, we will delete it.
13. Changes
We may update this Policy from time to time. We will notify customers of material changes by email and in-product banner at least 30 days before the effective date. The version history is maintained in our public changelog.
14. Contact & DPO
For privacy questions or to exercise your rights, contact:
- Email: notification@rostantechnologies.com
- Postal: Rostan Technologies Pvt Ltd, Bengaluru, Karnataka, India
- Data Protection Officer: appointed and contactable via the email above
A signed DPA (under GDPR Article 28 / DPDP) and a current sub-processor list are available on request. This document is a template provided in good faith and is not a substitute for legal advice tailored to your situation.