Privacy Policy
Last updated: 4 August 2026
This policy explains what personal data {{LEGAL ENTITY NAME}} ("we"), trading as IndiaWebHost, collects, why we collect it, and what you can do about it. It is written to comply with the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices) Rules, 2011.
We collect what we need to sell you hosting, run it, bill you and support you. We do not sell your data, we do not run advertising trackers on this site, and we do not read the content you host except when you ask us to help or the law requires it.
1. What we collect
| Data | Why | Basis |
|---|---|---|
| Name, email, phone, address | Creating your account, invoicing, statutory GST records, domain registration | Contract; legal obligation |
| GSTIN, if you give it | Issuing a compliant tax invoice so you can claim input credit | Legal obligation |
| Payment reference and last four digits of card | Matching payments to invoices, handling refunds and disputes | Contract |
| Server and access logs (IP, timestamps, requests) | Security, abuse investigation, diagnosing faults | Legitimate interest; legal obligation |
| Support tickets and emails | Answering you, and keeping a history so you need not repeat yourself | Contract |
| Contact form submissions | Replying to your enquiry | Consent |
What we do not collect
- Full card numbers. Payments are handled by a PCI-DSS compliant gateway. Card details go from you to them; they never reach our servers.
- Analytics or advertising profiles. This site runs no Google Analytics, no Facebook pixel, no third-party tag of any kind. There is nothing to opt out of because we did not put it there.
2. Cookies
The public website sets no cookies at all. The customer control panel sets a single session cookie required to keep you logged in, which expires when you close the browser or after 24 hours. There are no tracking, advertising or analytics cookies anywhere on our systems.
3. Content you host
Files, databases and email on your hosting account are yours. We access them only when:
- you ask us to, in a support request or migration;
- an automated security scan flags a file as malware, in which case it is quarantined and you are notified;
- we are compelled by a lawful order from an Indian authority or court.
If your site processes other people's personal data, you are the Data Fiduciary for it under the DPDP Act and we are your Data Processor. You are responsible for having your own privacy notice and lawful basis.
4. Who we share data with
We share the minimum necessary with:
- Payment gateway — to take payment and process refunds;
- Domain registries and registrars — NIXI, Verisign, PIR and our registrar partner, who require registrant details by their own rules;
- Data centre operator — physical hosting only; they hold no customer records;
- Our accountant and auditors — for statutory filings;
- Law enforcement — only against a valid legal order, and we will tell you unless legally barred from doing so.
We do not sell personal data, and we do not share it for anyone else's marketing.
5. Where data is stored
Customer data and hosted content are stored on servers physically located in India. Backups remain in India. We do not transfer personal data outside India except where a domain registry outside India requires registrant details to register the name you asked for.
6. How long we keep it
| Data | Retained |
|---|---|
| Account and contact details | While you are a customer, then 12 months |
| Invoices and GST records | 8 years — required by tax law, not our choice |
| Server and access logs | 180 days |
| Support tickets | 3 years after closure |
| Hosted content after termination | 28 days, then permanently deleted |
| Contact form enquiries | 12 months |
7. Security
Data in transit is encrypted with TLS. Passwords are stored hashed, never in plain text or reversible encryption. Administrative access requires multi-factor authentication and is logged. Servers are patched on a defined schedule and access is restricted to named staff on a need-to-know basis.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as required by the DPDP Act, with a description of what happened and what you should do.
8. Your rights
Under the DPDP Act you may:
- Access — get a copy of the personal data we hold about you;
- Correct — have inaccurate or incomplete data fixed;
- Erase — have data deleted where we no longer need it and no law requires us to keep it;
- Withdraw consent — where we relied on consent;
- Nominate — appoint someone to exercise these rights if you die or become incapacitated;
- Complain — to our grievance officer, and then to the Data Protection Board of India.
Email {{PRIVACY EMAIL}} to exercise any of these. We respond within 30 days and charge nothing. We may ask you to confirm your identity first — an email from your registered address is normally enough.
9. Grievance officer
Name: {{GRIEVANCE OFFICER NAME}}
Email: {{GRIEVANCE EMAIL}}
Address: {{FULL REGISTERED ADDRESS}}
Complaints are acknowledged within 24 hours and resolved within 15 days, as the IT Rules require.
10. Changes
We will email registered customers at least 30 days before any material change to this policy. The "last updated" date above always reflects the current version.
Draft prepared for {{LEGAL ENTITY NAME}}; not yet reviewed by a lawyer. Have an Indian advocate check it before you take your first payment, then remove this notice.