01
Who we are and what this policy covers
This policy explains how StranoInfy Private Limited (“StranoInfy”, “we”, “us”) handles personal data when you visit stranoinfy.vercel.app, submit a form, download a report, subscribe to our newsletter, book a call, apply for a job, or engage us as a client. It covers this website and the sales, marketing and recruitment activity that runs alongside it.
For the purposes of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), StranoInfy is the Data Fiduciary and you are the Data Principal. Our registered office is at Durganagar Station Road, Near Airport, Kolkata 700065, West Bengal, India. We are a private limited company incorporated under the Companies Act, 2013.
Where we deliver services to a client — running their ad accounts, building their CRM, operating their marketing automation — that client is the Data Fiduciary for their own customers’ data and we act as a Data Processor strictly on their written instructions, under the data processing addendum attached to the Master Services Agreement. This policy does not govern that processing; the client’s own privacy notice does.
Reading a page on this site requires no account, no login and no personal data at all. Everything described below begins the moment you choose to tell us something.
02
What we collect
We collect four kinds of data, and we collect as little of each as the job allows. Nothing on this site asks for a government identifier, a payment card, health information or any other sensitive category — if a form ever appears to, it is not ours.
Information you give us
Every field on our forms is either required to answer you or explicitly optional. We do not use hidden fields to collect anything you have not seen.
- Enquiry and proposal forms — your name, work email, phone number, company name, role, website URL, indicative monthly budget band, the services you are interested in, and whatever you write in the message field.
- Growth audit and calculator tools — the URL you submit, the figures you enter, and the email address you ask the result to be sent to. Figures you type into a calculator stay in your browser unless you press send.
- Newsletter subscription — your email address, the page you subscribed from, and the timestamp and IP address of the subscription, which together form our record of your consent.
- Job applications — your name, contact details, CV or portfolio, current and expected compensation, notice period, work authorisation, and your answers to the role-specific questions. Providing demographic information is always optional and never shown to the hiring panel.
- Client onboarding — the names, work emails and phone numbers of the people on your team we work with day to day, plus the billing contact and statutory details needed to raise a compliant tax invoice.
Information collected automatically
Serving a web page necessarily involves your device telling ours where to send the response. We keep that technical record briefly, and we do not build a profile from it.
- Request logs — IP address, user agent, referring URL, requested path, response status and timestamp, generated by our hosting provider’s edge network and retained for 30 days for security, abuse prevention and debugging.
- Aggregate measurement — page views, referrer and country, counted without a cookie and without any identifier stored on your device. Visits are de-duplicated using a hash of IP address and user agent that is regenerated every 24 hours and never retained.
- Performance samples — Core Web Vitals (largest contentful paint, interaction to next paint, cumulative layout shift) sampled from real sessions so we can find slow pages. These carry no identifier.
- Local browser storage — three first-party keys that record your appearance preference, your cookie choice and when we last showed you a newsletter invitation. They never leave your device. The Cookie Policy names each one.
Call and meeting recordings
Discovery calls, strategy calls and quarterly reviews are often recorded, and the recording may be transcribed and summarised automatically so the team that does the work hears the brief in your own words rather than a second-hand note.
We announce the recording at the start of every call and we ask before we start. Declining costs you nothing — we take written notes instead, and it has never changed the outcome of a proposal. You can ask us to stop recording, delete a recording, or send you a copy at any point.
- What is captured — audio, video where cameras are on, the screen share, an automated transcript and a summary of the agreed actions.
- Why — accurate scoping, internal quality review, and training our own team. Recordings are never used to train a third-party AI model, and we do not licence them to anyone.
- Who can see them — the account team on your engagement and the partner who owns it. Access is logged.
- How long — twelve months from the date of the call, then deleted automatically. Recordings that document a scope agreement are kept for the life of the engagement instead, because they protect both sides.
Information from other sources
Before a first meeting we do the reading. That research is limited to business information about a company and a role, drawn from sources that are already public.
- Public business sources — your company website, LinkedIn company and role pages, MCA filings, press coverage and app-store listings, used to prepare for a call and to sanity-check a budget conversation.
- Referrals — when an existing client or partner introduces you, we hold the name, company and context they gave us. We will tell you who referred you if you ask.
- Events — badge scans and delegate lists from conferences we sponsor, where the organiser has obtained consent to share them. We say where we got your details in the first email.
- Advertising platforms — aggregate campaign reporting from Google, Meta and LinkedIn. We do not receive, upload or match individual visitor identities to any advertising audience.
03
Why we process it, and on what basis
Under the DPDP Act every act of processing needs either your consent or a lawful “legitimate use” under Section 7. We do not rely on a single blanket consent buried in a footer; each purpose below stands on its own, and where the basis is consent you can withdraw it as easily as you gave it.
We do not make any decision about you by automated means alone, and we do not profile visitors for advertising.
| Purpose | Data used | Basis under the DPDP Act, 2023 |
|---|---|---|
| Answering an enquiry | Name, work email, phone, company, message | Section 7(a) — data voluntarily provided for a purpose you approached us with, and for which you have not indicated you do not consent |
| Sending a requested report or calculator result | Email address, the resource requested | Consent under Section 6, given at the point of download |
| Newsletter and marketing email | Email address, engagement history | Consent under Section 6, withdrawable from every email in one click |
| Delivering services under a contract | Contact details of your team, project records, invoices | Section 7 legitimate use for performance of the engagement, together with the DPA in your MSA |
| Recruitment | Application, CV, interview notes and scorecards | Consent under Section 6, given when you submit the application |
| Security, abuse prevention and debugging | Request logs, rate-limit counters | Section 7 legitimate use — maintaining the integrity and security of our own systems |
| Statutory books, GST and tax records | Invoices, contracts, payment records | Section 7(b) — compliance with the Companies Act, 2013, the CGST Act, 2017 and the Income-tax Act, 1961 |
05
How long we keep it
Section 8(7) of the DPDP Act requires personal data to be erased once the purpose is served and retention is no longer required by law. We implement that with fixed schedules rather than a vague promise, and deletion runs automatically.
| Record | Retention period | Why that period |
|---|---|---|
| Enquiry that does not become an opportunity | 24 months from last contact | Buying cycles for a growth retainer commonly run 12–18 months; after two years the record has no purpose |
| Open opportunity in the CRM | Life of the opportunity, then 36 months | Commercial history and dispute record |
| Client contracts, invoices and GST records | 8 financial years | Section 128 of the Companies Act, 2013 and CGST record-keeping requirements |
| Call and meeting recordings | 12 months | Long enough for scope disputes, short enough that nothing lingers |
| Unsuccessful job applications | 12 months | Reconsideration for later roles; extended to 24 months only if you opt into the talent pool |
| Newsletter subscription | Until you unsubscribe, plus a suppression record | The suppression list is what stops us emailing you again by mistake |
| Web server and edge request logs | 30 days | Security investigation and debugging |
| Consent and withdrawal records | Life of the relationship, plus 3 years | Evidence that consent was validly obtained, as the DPDP Act requires |
07
International transfers
Several processors above operate outside India. Section 16 of the DPDP Act permits transfer to any country other than those the Central Government restricts by notification; as at the date of this policy, no notification restricts any country in which our processors operate. If that changes, we will migrate or terminate the affected processing rather than continue it.
Where a client’s contract requires Indian data residency, we can pin hosting, meeting recordings and CRM records to Indian regions. That is a scoping decision made at onboarding, and it is written into the data processing addendum rather than promised verbally.
For personal data of individuals in the European Economic Area or the United Kingdom, transfers out of those regions are made under the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with the UK International Data Transfer Addendum, supported by a transfer impact assessment we will share on request.
08
How we protect it
Section 8(5) of the DPDP Act requires reasonable security safeguards to prevent a personal data breach. Ours are the controls we would want applied to our own data, and we audit them rather than assume them.
- In transit and at rest — TLS 1.3 for every connection to this site, HSTS enforced, and AES-256 encryption at rest across hosting, CRM and document storage.
- Access control — single sign-on with mandatory multi-factor authentication on every system holding personal data, least-privilege roles, quarterly access reviews, and revocation within four business hours of someone leaving.
- Environment separation — production personal data is never copied into development or staging. Engineers work against synthetic fixtures.
- Application security — automated dependency and secret scanning on every commit, rate limiting on all public form endpoints, and rate limiting on all public form endpoints.
- People — background verification on hire, confidentiality obligations that survive employment, and annual data-protection training with a documented pass mark.
- Breach response — a written incident plan with named owners. In a personal data breach we notify the Data Protection Board of India and every affected Data Principal without delay, in the form and manner the DPDP Act and its rules prescribe, and we publish what happened, what we did and what changed.
- The honest caveat — no system is perfectly secure. We can promise diligence and transparency, not invulnerability, and we would rather say so here than in an incident notice.
09
Your rights as a Data Principal
Chapter III of the DPDP Act gives you the following rights over the personal data we hold as a Data Fiduciary. Exercising them is free, and doing so never affects the commercial terms of an engagement or an application.
- Right to access information (Section 11) — a summary of the personal data we process about you, the processing activities it is used in, and the identities of the other Data Fiduciaries and Data Processors with whom it has been shared, together with a description of what was shared.
- Right to correction, completion, updating and erasure (Section 12) — have inaccurate data corrected, incomplete data completed, stale data updated, and data erased where it is no longer needed for the purpose it was collected for and no law requires us to keep it.
- Right to withdraw consent (Section 6) — withdraw consent at any time, as easily as it was given. Every marketing email carries a one-click unsubscribe; anything else takes one message to the Grievance Officer.
- Right of grievance redressal (Section 13) — a readily available means of raising a complaint with us, and an answer inside the statutory period, before you escalate.
- Right to nominate (Section 14) — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Send the nominee’s name, relationship and contact details to the Grievance Officer and we will record it against your data.
- Your duties (Section 15) — the Act asks Data Principals not to impersonate another person, not to suppress material information, and not to file frivolous or false complaints. We mention this only because the Act does; we have never had cause to invoke it.
How to exercise them
Email the Grievance Officer at support@stranoinfy.com from the address you gave us, with “DPDP request” in the subject line and one line describing what you want. If we cannot match the address to a record, we will ask for one additional piece of information to verify you — never a government identifier.
We acknowledge in writing within three working days and give a substantive answer within thirty days of receipt. If a request is genuinely complex we will say so before that deadline, explain why, and give a date. There is no fee, and there is no form to fill in.
If we decline a request in whole or in part — for example because a statutory retention period overrides an erasure request — we tell you which record, which law and for how long.
10
Grievance Officer and how to complain
Section 13 of the DPDP Act requires every Data Fiduciary to publish the contact details of a person who answers questions about processing. Ours sits inside the operations team, not in an outsourced queue, and reads every message personally.
- Role — Grievance Officer, StranoInfy Private Limited
- Email — support@stranoinfy.com, with “Grievance” or “DPDP request” in the subject line
- Post — Grievance Officer, StranoInfy Private Limited, Durganagar Station Road, Near Airport, Kolkata 700065, West Bengal, India
- Phone — +91 93304 04914, Monday to Friday, 9:30 AM to 7:00 PM IST
- Response — acknowledged within three working days, answered substantively within thirty days of receipt
If our answer does not resolve it
The DPDP Act asks you to exhaust our grievance process first. If you have done so and remain dissatisfied, you may complain to the Data Protection Board of India, which is empowered to inquire into breaches and impose penalties. Its contact details are published by the Ministry of Electronics and Information Technology.
You do not need our permission to escalate, and we will not treat a complaint to the Board as a reason to change how we deal with you. On request we will send you the full correspondence trail so you are not reconstructing it from memory.
11
Children’s data
StranoInfy sells to businesses. Nothing on this site is directed at children, and we do not knowingly collect the personal data of anyone the DPDP Act defines as a child — an individual who has not completed eighteen years of age.
Section 9 of the Act prohibits processing that is likely to cause a detrimental effect on the well-being of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do none of these, on this site or in any campaign we run for a client.
Applicants for roles at StranoInfy, including internships, must be at least eighteen. If we discover that we hold a child’s personal data without verifiable consent from a parent or lawful guardian, we delete it within seven days and confirm the deletion. A parent or guardian can raise this with the Grievance Officer using the details above, and we will treat it as a priority.
12
A note for visitors in the EU and the UK
We are established in India and are not established in the European Union or the United Kingdom. Because we offer services to organisations in those regions, the UK GDPR and the EU General Data Protection Regulation may apply to that processing, and this section sets out how we meet them. Where the GDPR and the DPDP Act both apply, we follow whichever gives you the stronger protection.
- Legal bases — Article 6(1)(b) where we are performing or preparing a contract, Article 6(1)(f) legitimate interests for business-to-business outreach, security and service improvement, Article 6(1)(a) consent for marketing email and gated downloads, and Article 6(1)(c) where a legal obligation applies.
- Your rights — access, rectification, erasure, restriction of processing, data portability in a machine-readable format, objection to processing based on legitimate interests, and an absolute right to object to direct marketing at any time.
- Automated decisions — we take no decision producing legal or similarly significant effects about you by automated means, and we carry out no profiling for that purpose.
- Transfers — personal data leaving the EEA or the UK travels under the Standard Contractual Clauses and the UK International Data Transfer Addendum, with a transfer impact assessment available on request.
- Representative — we have not appointed an Article 27 representative, as our EU-facing processing is occasional, limited to business contact data and involves no large-scale processing of special categories. You can reach us directly at the postal address and email above.
- Complaints — you may lodge a complaint with your local supervisory authority, or with the Information Commissioner’s Office in the United Kingdom, without contacting us first — although we would rather you gave us the chance to fix it.
13
Changes to this policy
We revise this policy when the law changes, when we add or remove a processor, or when we start doing something new with data. The date at the top of this page always reflects the current version.
For a material change — a new purpose, a new category of data, a new processor with access to personal data, or a longer retention period — we publish the change at least fourteen days before it takes effect, notify newsletter subscribers by email, and show a notice on the site. Continuing to use the site after that date means the updated policy applies; where the change requires fresh consent under the DPDP Act, we ask for it rather than assume it.
Previous versions are archived. Ask the Grievance Officer for any earlier version, or for a redline showing exactly what changed and when.