Skip to content
Scope, price and timeline published on every engagement page Engineers assigned within 3 working days of kickoff Your repositories, cloud accounts and licences stay in your name

Legal

Privacy Notice

What personal data UniStack Tech collects when you browse this site or buy an engagement, why we need each piece of it, who else touches it, and what you can require us to do with it.

Last updated 24 August 2026

In plain terms

  • We collect what is needed to invoice you and build what you bought: contact details, billing details, order records, your technical brief and basic site analytics.
  • Card numbers, UPI PINs and banking credentials never reach us. The payment gateway handles those and tells us only whether the payment worked.
  • We do not sell data and we do not build advertising profiles. Four categories of processor help us operate: payments, email, hosting and analytics.
  • You can ask for a copy, a correction or an erasure, or withdraw consent. Write to the Grievance Officer and you get an answer within 30 days.

This box is a summary, not the notice. The sections below carry the detail the Digital Personal Data Protection Act, 2023 requires, and they are what governs.

1. Who this notice covers

This notice applies to everybody who visits UniStack Tech, opens an account, contacts us, submits a technical brief or buys an engagement. It is written against the Digital Personal Data Protection Act, 2023 and the reasonable-security rules made under the Information Technology Act, 2000.

The Act leans on two words, so it is worth being clear about them. You are the Data Principal — the person the data is about. We are the Data Fiduciary — the organisation that decides why and how your data is processed, and that carries the duty to look after it.

It does not cover websites we link to, third-party platforms you sign into separately, or systems that belong to you and that we work inside during an engagement. Section 6 explains that last case.

2. Who is responsible for your data

The Data Fiduciary is UNISTACK SOFTWARE PRIVATE LIMITED, No. 15/1 , 185/2/ 185/A, 18th Main Road, Block 9, Jayanagar, Bengaluru, Bengaluru Urban, Karnataka, 560041..

Day-to-day responsibility sits with our client operations team. Formal requests and complaints go to the Grievance Officer named in section 16, and one named person owns each request from the moment it arrives.

3. What we collect

Five buckets, and nothing beyond what a professional services firm actually needs.

  • Account data — name, email address, mobile number, business name where you give one, and a one-way hash of your password. We never hold a password in readable form, so we cannot tell you what yours is and neither can anybody who steals the database.
  • Billing data — billing name, address, city, state, PIN code and, where you supply it, your GSTIN. Needed to raise a compliant tax invoice.
  • Order data — the engagements bought, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
  • Technical brief content — what you write into the brief so the work can be done: repository and environment names, architecture notes, the problem being solved, access instructions and any files you attach. This is commercial information more than personal information, though it often contains names and work email addresses.
  • Site and device data — IP address, browser and device type, pages viewed, referring source and approximate city, collected through analytics and server logs.

We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials at any point. We do not ask for identifiers such as Aadhaar or PAN unless a specific statutory requirement makes it unavoidable, and we would tell you why at the time.

4. Why we collect it

Every purpose below is specific, and we do not quietly reuse data gathered for one purpose to serve another. That is what purpose limitation means in practice.

What we do with itWhich data
Create, confirm and deliver your orderAccount, billing, order, brief
Raise a GST invoice and keep tax recordsBilling, order
Write to you about an order: confirmation, questions, handover, supportAccount, order
Assign engineers and plan the workBrief, order
Handle a refund, a dispute or a grievanceOrder, billing, correspondence
Keep the site running, prevent fraud and debug faultsSite and device data
Understand which pages are useful, in aggregateSite and device data
Send occasional updates about new engagementsName and email, only where you opted in

We do not build advertising profiles, we do not run behavioural retargeting, and we do not sell, rent or trade personal data to anybody.

5. Consent and lawful basis

We rely on two grounds under the DPDP Act.

  • Consent — freely given, specific, informed and unambiguous, taken at the point you submit a form, open an account, complete a brief or tick a subscription box. Each request says what the data is for before you give it.
  • Legitimate uses — processing necessary to perform the contract you entered when you paid, and processing required by a legal obligation such as tax record-keeping under Indian law.

You may withdraw consent at any time, and it must be as easy to withdraw as it was to give. Write to the Grievance Officer and we act on it. Withdrawal does not undo processing already carried out lawfully and it does not release either of us from a record the law requires us to keep, but it stops the processing going forward. Where withdrawal would make it impossible to continue an engagement you have paid for, we say so plainly before acting.

Marketing consent stands separate from everything else. Refusing it never affects an order, and every marketing email carries a one-click unsubscribe that we honour immediately.

6. Your brief, and data inside your own systems

Two different roles, and it matters which one we are in.

  • Your data, held by us. Account, billing, order and brief data sits in our systems and we are the Data Fiduciary for it. The rest of this notice describes that.
  • Data about your users, held in your systems. When an engagement takes us inside your repositories, databases or cloud accounts, you remain the Data Fiduciary and we act only on your documented instructions. We sign a data processing agreement before that work starts, covering purpose limitation, security, sub-processing, breach notification and deletion at the end.

Our working rule is that we do not want your production personal data. We ask for anonymised, masked or synthetic data by default, and where live access is genuinely unavoidable it is named, least-privilege, logged, time-boxed and revoked at handover.

7. Who processes it alongside us

Personal data goes to processors who help us run the business, only for the purpose named, and only under contracts that oblige them to protect it. We list them by category rather than by brand, because a supplier can change while the category and the safeguards stay the same.

CategoryWhat it receivesWhy
Payment gatewayName, contact, amount, order referenceTo take a UPI payment, and to confirm or refund it
Email deliveryName, email address, message contentTo send order confirmations, handovers and replies
Hosting and infrastructureEverything the site stores, at restTo run the website, the database and backups
Website analyticsSite and device data, pseudonymousTo see which pages get used and which are broken

Beyond those four categories, data reaches the engineers assigned to your engagement — restricted to the brief and the access the work needs; our accountants and auditors, for statutory filings; and a government body, court or law enforcement agency where a valid legal process requires it. In that last case we ask for the demand in writing, satisfy ourselves that it is lawful, disclose only what is compelled, and tell you unless we are barred from doing so.

No processor is ever permitted to use your data for its own purposes.

8. Cross-border transfer

The website, its database and its backups are hosted in India. Some processors — email delivery and analytics in particular — run infrastructure outside India, so a limited amount of personal data may be processed abroad.

Where that happens we transfer only to countries not restricted by the Central Government under section 16 of the DPDP Act, we keep the transfer to the minimum the purpose needs, and the contract with that processor requires protection equivalent to what this notice promises. If a transfer restriction changes, we move the processing rather than argue about it.

9. How long we keep it

Data is kept for as long as the purpose needs or the law requires, and is then deleted or irreversibly anonymised.

WhatHow longWhy that long
Invoices, order and payment records8 financial yearsIncome-tax and GST record-keeping
Account profileWhile the account is open, then 90 daysSo a deletion made in error can be undone
Technical brief and delivery artefacts12 months after handoverSo you can ask for the handover again
Support and grievance correspondence3 years from closureComplaint records under the e-commerce rules
Marketing consent and unsubscribesUntil you unsubscribe, plus 12 monthsProof that the unsubscribe was honoured
Server and access logs180 daysSecurity investigation and fault diagnosis
Analytics, in aggregate26 monthsYear-on-year comparison, no longer identifying

Ask for erasure and we delete everything not held under one of the statutory rows above. We will tell you exactly what had to stay and under which obligation.

10. How we protect it

We are not going to wave a certificate at you. Here is what we actually do.

  • The whole site is served over HTTPS with modern TLS, so data in transit is encrypted.
  • Passwords are stored as salted one-way hashes and are unrecoverable, including by us.
  • Database backups are encrypted at rest, and restoring them is tested rather than assumed.
  • Administrative access uses individual named accounts with multi-factor authentication. Shared logins are not permitted.
  • Access to customer data follows least privilege and is reviewed whenever somebody changes role or leaves.
  • Payment credentials never touch our servers, so there is nothing there for anyone to take.
  • Client credentials live in a secrets manager, never in email, chat, spreadsheets or source code.
  • Dependencies are patched on a schedule and security updates to the platform are applied out of hours.
  • Everyone here is bound by confidentiality obligations that outlast their employment.

No system is perfectly secure and we will not pretend otherwise. What we can promise is that a security report gets taken seriously and acted on quickly — if you find a weakness in this site, tell us, and we will fix it and credit you if you want the credit.

11. Cookies and analytics

A small number of cookies and similar browser storage, in two groups.

  • Strictly necessary — session and security cookies that keep you signed in, hold your scope together between pages and protect forms against cross-site request forgery. Switching these off breaks the site, so they run without consent.
  • Analytics — used only where analytics is enabled, to count page views and find broken journeys. They are pseudonymous and, where consent is required, they run only after you give it.

The engagements in your scope are held in your own browser storage rather than on our servers, so clearing site data removes them and nobody else can read them. Browser do-not-track signals are respected where the analytics provider supports them, and you can block or clear cookies in your browser at any time.

12. Your rights as a Data Principal

Under the DPDP Act you can require the following of us.

  • Access — a summary of the personal data we hold about you, what we do with it, and which categories of processor have received it.
  • Correction — fix anything inaccurate, complete anything incomplete, update anything out of date.
  • Erasure — delete data we no longer need for the purpose it was collected for, subject to the statutory retention rows in section 9.
  • Withdrawal of consent — for any processing that rests on consent, as easily as it was given.
  • Nomination — name another person to exercise these rights for you if you die or become incapable of exercising them yourself.
  • Grievance redressal — a readily available means of complaining to us, answered inside a published timeline, before you need to go anywhere else.

The Act gives you duties too: give authentic details, do not impersonate somebody else, and do not file a false or frivolous complaint.

How to exercise a right. Write to YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR, our Grievance Officer, at grievance@unistacktech.com from the email address on your account, saying which right you want to exercise. We may ask a question or two to confirm it is really you before acting. We respond within 30 days, and where a request is complex enough to need longer we say so inside those 30 days, with a reason and a date.

None of this carries a charge.

13. Children and guardianship

These engagements are sold to businesses and this site is not directed at children. We do not knowingly collect the personal data of anybody under 18, and we do not track, profile or advertise to children in any circumstances.

If a child has given us data, tell us and we will delete it promptly. Where an account genuinely has to be operated for a child, or for a person with a disability who has a lawful guardian, verifiable guardian consent must be obtained first, as the DPDP Act requires.

14. If something goes wrong

If a personal data breach occurs we investigate immediately, contain it, and notify the Data Protection Board of India and every affected Data Principal in the form and within the time the DPDP Act requires.

Our notice to you will say, in plain language, what happened, which data was involved, what the likely consequences are, what we have already done about it and what we suggest you do. We will not delay a notification while we work out how it looks.

15. Changes to this notice

We update this notice when our processing changes or the law does. The date at the top always reflects the current version, material changes are flagged on this page, and where a change needs fresh consent we ask for it rather than assume it. Earlier versions are available on request.

16. Contact and complaints

For any privacy question, data request or complaint:

  • Grievance Officer — YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR: grievance@unistacktech.com · +917207465764
  • General support: info@unistacktech.com
  • By post: No. 15/1 , 185/2/ 185/A, 18th Main Road, Block 9, Jayanagar, Bengaluru, Bengaluru Urban, Karnataka, 560041.

Complaints are acknowledged within 48 hours and answered substantively within 15 days. The full escalation route, including the external bodies you can approach, is on the grievance redressal page.

If our answer does not satisfy you, you may complain to the Data Protection Board of India, having first raised the matter with our Grievance Officer. This notice is governed by the laws of India.

Capacity open this month

Read the scope. Know the price. Start on Monday.

No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.