Legal
Privacy Notice
What personal data UniStack Tech collects when you browse this site or buy an engagement, why we need each piece of it, who else touches it, and what you can require us to do with it.
Last updated 24 August 2026
In plain terms
- We collect what is needed to invoice you and build what you bought: contact details, billing details, order records, your technical brief and basic site analytics.
- Card numbers, UPI PINs and banking credentials never reach us. The payment gateway handles those and tells us only whether the payment worked.
- We do not sell data and we do not build advertising profiles. Four categories of processor help us operate: payments, email, hosting and analytics.
- You can ask for a copy, a correction or an erasure, or withdraw consent. Write to the Grievance Officer and you get an answer within 30 days.
This box is a summary, not the notice. The sections below carry the detail the Digital Personal Data Protection Act, 2023 requires, and they are what governs.
1. Who this notice covers
This notice applies to everybody who visits UniStack Tech, opens an account, contacts us, submits a technical brief or buys an engagement. It is written against the Digital Personal Data Protection Act, 2023 and the reasonable-security rules made under the Information Technology Act, 2000.
The Act leans on two words, so it is worth being clear about them. You are the Data Principal — the person the data is about. We are the Data Fiduciary — the organisation that decides why and how your data is processed, and that carries the duty to look after it.
It does not cover websites we link to, third-party platforms you sign into separately, or systems that belong to you and that we work inside during an engagement. Section 6 explains that last case.
2. Who is responsible for your data
The Data Fiduciary is UNISTACK SOFTWARE PRIVATE LIMITED, No. 15/1 , 185/2/ 185/A, 18th Main Road, Block 9, Jayanagar, Bengaluru, Bengaluru Urban, Karnataka, 560041..
Day-to-day responsibility sits with our client operations team. Formal requests and complaints go to the Grievance Officer named in section 16, and one named person owns each request from the moment it arrives.
3. What we collect
Five buckets, and nothing beyond what a professional services firm actually needs.
- Account data — name, email address, mobile number, business name where you give one, and a one-way hash of your password. We never hold a password in readable form, so we cannot tell you what yours is and neither can anybody who steals the database.
- Billing data — billing name, address, city, state, PIN code and, where you supply it, your GSTIN. Needed to raise a compliant tax invoice.
- Order data — the engagements bought, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
- Technical brief content — what you write into the brief so the work can be done: repository and environment names, architecture notes, the problem being solved, access instructions and any files you attach. This is commercial information more than personal information, though it often contains names and work email addresses.
- Site and device data — IP address, browser and device type, pages viewed, referring source and approximate city, collected through analytics and server logs.
We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials at any point. We do not ask for identifiers such as Aadhaar or PAN unless a specific statutory requirement makes it unavoidable, and we would tell you why at the time.
4. Why we collect it
Every purpose below is specific, and we do not quietly reuse data gathered for one purpose to serve another. That is what purpose limitation means in practice.
| What we do with it | Which data |
|---|---|
| Create, confirm and deliver your order | Account, billing, order, brief |
| Raise a GST invoice and keep tax records | Billing, order |
| Write to you about an order: confirmation, questions, handover, support | Account, order |
| Assign engineers and plan the work | Brief, order |
| Handle a refund, a dispute or a grievance | Order, billing, correspondence |
| Keep the site running, prevent fraud and debug faults | Site and device data |
| Understand which pages are useful, in aggregate | Site and device data |
| Send occasional updates about new engagements | Name and email, only where you opted in |
We do not build advertising profiles, we do not run behavioural retargeting, and we do not sell, rent or trade personal data to anybody.
5. Consent and lawful basis
We rely on two grounds under the DPDP Act.
- Consent — freely given, specific, informed and unambiguous, taken at the point you submit a form, open an account, complete a brief or tick a subscription box. Each request says what the data is for before you give it.
- Legitimate uses — processing necessary to perform the contract you entered when you paid, and processing required by a legal obligation such as tax record-keeping under Indian law.
You may withdraw consent at any time, and it must be as easy to withdraw as it was to give. Write to the Grievance Officer and we act on it. Withdrawal does not undo processing already carried out lawfully and it does not release either of us from a record the law requires us to keep, but it stops the processing going forward. Where withdrawal would make it impossible to continue an engagement you have paid for, we say so plainly before acting.
Marketing consent stands separate from everything else. Refusing it never affects an order, and every marketing email carries a one-click unsubscribe that we honour immediately.
6. Your brief, and data inside your own systems
Two different roles, and it matters which one we are in.
- Your data, held by us. Account, billing, order and brief data sits in our systems and we are the Data Fiduciary for it. The rest of this notice describes that.
- Data about your users, held in your systems. When an engagement takes us inside your repositories, databases or cloud accounts, you remain the Data Fiduciary and we act only on your documented instructions. We sign a data processing agreement before that work starts, covering purpose limitation, security, sub-processing, breach notification and deletion at the end.
Our working rule is that we do not want your production personal data. We ask for anonymised, masked or synthetic data by default, and where live access is genuinely unavoidable it is named, least-privilege, logged, time-boxed and revoked at handover.
8. Cross-border transfer
The website, its database and its backups are hosted in India. Some processors — email delivery and analytics in particular — run infrastructure outside India, so a limited amount of personal data may be processed abroad.
Where that happens we transfer only to countries not restricted by the Central Government under section 16 of the DPDP Act, we keep the transfer to the minimum the purpose needs, and the contract with that processor requires protection equivalent to what this notice promises. If a transfer restriction changes, we move the processing rather than argue about it.
9. How long we keep it
Data is kept for as long as the purpose needs or the law requires, and is then deleted or irreversibly anonymised.
| What | How long | Why that long |
|---|---|---|
| Invoices, order and payment records | 8 financial years | Income-tax and GST record-keeping |
| Account profile | While the account is open, then 90 days | So a deletion made in error can be undone |
| Technical brief and delivery artefacts | 12 months after handover | So you can ask for the handover again |
| Support and grievance correspondence | 3 years from closure | Complaint records under the e-commerce rules |
| Marketing consent and unsubscribes | Until you unsubscribe, plus 12 months | Proof that the unsubscribe was honoured |
| Server and access logs | 180 days | Security investigation and fault diagnosis |
| Analytics, in aggregate | 26 months | Year-on-year comparison, no longer identifying |
Ask for erasure and we delete everything not held under one of the statutory rows above. We will tell you exactly what had to stay and under which obligation.
10. How we protect it
We are not going to wave a certificate at you. Here is what we actually do.
- The whole site is served over HTTPS with modern TLS, so data in transit is encrypted.
- Passwords are stored as salted one-way hashes and are unrecoverable, including by us.
- Database backups are encrypted at rest, and restoring them is tested rather than assumed.
- Administrative access uses individual named accounts with multi-factor authentication. Shared logins are not permitted.
- Access to customer data follows least privilege and is reviewed whenever somebody changes role or leaves.
- Payment credentials never touch our servers, so there is nothing there for anyone to take.
- Client credentials live in a secrets manager, never in email, chat, spreadsheets or source code.
- Dependencies are patched on a schedule and security updates to the platform are applied out of hours.
- Everyone here is bound by confidentiality obligations that outlast their employment.
No system is perfectly secure and we will not pretend otherwise. What we can promise is that a security report gets taken seriously and acted on quickly — if you find a weakness in this site, tell us, and we will fix it and credit you if you want the credit.
12. Your rights as a Data Principal
Under the DPDP Act you can require the following of us.
- Access — a summary of the personal data we hold about you, what we do with it, and which categories of processor have received it.
- Correction — fix anything inaccurate, complete anything incomplete, update anything out of date.
- Erasure — delete data we no longer need for the purpose it was collected for, subject to the statutory retention rows in section 9.
- Withdrawal of consent — for any processing that rests on consent, as easily as it was given.
- Nomination — name another person to exercise these rights for you if you die or become incapable of exercising them yourself.
- Grievance redressal — a readily available means of complaining to us, answered inside a published timeline, before you need to go anywhere else.
The Act gives you duties too: give authentic details, do not impersonate somebody else, and do not file a false or frivolous complaint.
How to exercise a right. Write to YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR, our Grievance Officer, at grievance@unistacktech.com from the email address on your account, saying which right you want to exercise. We may ask a question or two to confirm it is really you before acting. We respond within 30 days, and where a request is complex enough to need longer we say so inside those 30 days, with a reason and a date.
None of this carries a charge.
13. Children and guardianship
These engagements are sold to businesses and this site is not directed at children. We do not knowingly collect the personal data of anybody under 18, and we do not track, profile or advertise to children in any circumstances.
If a child has given us data, tell us and we will delete it promptly. Where an account genuinely has to be operated for a child, or for a person with a disability who has a lawful guardian, verifiable guardian consent must be obtained first, as the DPDP Act requires.
14. If something goes wrong
If a personal data breach occurs we investigate immediately, contain it, and notify the Data Protection Board of India and every affected Data Principal in the form and within the time the DPDP Act requires.
Our notice to you will say, in plain language, what happened, which data was involved, what the likely consequences are, what we have already done about it and what we suggest you do. We will not delay a notification while we work out how it looks.
15. Changes to this notice
We update this notice when our processing changes or the law does. The date at the top always reflects the current version, material changes are flagged on this page, and where a change needs fresh consent we ask for it rather than assume it. Earlier versions are available on request.
16. Contact and complaints
For any privacy question, data request or complaint:
- Grievance Officer — YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR: grievance@unistacktech.com · +917207465764
- General support: info@unistacktech.com
- By post: No. 15/1 , 185/2/ 185/A, 18th Main Road, Block 9, Jayanagar, Bengaluru, Bengaluru Urban, Karnataka, 560041.
Complaints are acknowledged within 48 hours and answered substantively within 15 days. The full escalation route, including the external bodies you can approach, is on the grievance redressal page.
If our answer does not satisfy you, you may complain to the Data Protection Board of India, having first raised the matter with our Grievance Officer. This notice is governed by the laws of India.