Privacy Policy

Last updated 9 August 2026

This policy explains what WEBSTRAKE TECHNOLOGIES LLP ("we", "us", "our") does with personal data. It covers our website at webstrake.com, your webStrake account, and our work for business clients.

It does not cover what a school records inside Slate about its students, staff and parents. There, the school decides what is held and why, and we only act on the school's instructions. That is explained in Slate's own privacy policy.

1. Who we are

We are WEBSTRAKE TECHNOLOGIES LLP, a limited liability partnership registered in India, with our office at 2nd Floor, No 143, East Wing, RMZ Millenia Business Park, Chennai, Tamil Nadu 600096.

For the data described in this policy, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). That means we decide what is collected and why, and we are answerable for it.

2. What we collect

When you visit the website. Pages you open, the approximate location your connection comes from, your browser and device type, and the site that referred you. We do not build advertising profiles from this.

When you enquire or fill in a form. Your name, email address, phone number, company name and whatever you choose to write to us.

When you hold a webStrake account. Your name, email address, phone number where you give one, your password in a form we cannot read, your sign-in and security settings, and a record of sign-ins and sessions.

When you are a business client. The details needed to quote, invoice and deliver work, including billing details, tax registration numbers, payment records, and the material you send us for a project.

When you contact support. The messages you send and our replies.

We do not ask for your age, and the website is not directed at children. A webStrake account is for adults; the Account Terms require account holders to be 18 or over.

3. Why we use it, and on what legal basis

Under the DPDP Act we may use personal data where you have consented, or for a "legitimate use" the Act allows, such as a purpose you voluntarily gave the data for.

  • To create and run your account, sign you in and keep it secure — so we can provide the service you asked for.
  • To answer enquiries and provide support — the purpose you gave us the details for.
  • To quote, invoice and deliver client work — to perform our agreement with you.
  • To keep accounting and tax records — required by law.
  • To investigate abuse, fraud and security incidents — to protect users and our service.
  • To improve the website and our products — our legitimate interest, using aggregated data wherever that will do.
  • To send product news and offers to business users — with consent, which you can withdraw at any time.

We do not sell personal data. We do not use it to make automated decisions that produce legal or similarly significant effects.

4. Marketing

We send product news and offers only to business users — people at organisations we work with or who have asked to hear from us. Every message has an unsubscribe link, and withdrawing consent takes effect for future messages. We will still send service messages you cannot opt out of, such as billing notices, security alerts and changes to terms, because they are part of running your account.

5. Who we share it with

We share personal data with service providers who help us operate, and only with what each one needs:

  • Payment processing, to take and reconcile payments.
  • SMS and email delivery, to send messages you or your account require.
  • Hosting, storage and content delivery, to run our servers and serve our sites.
  • Error and performance monitoring, to find and fix faults.

Each is bound by contract to protect the data and to use it only for the service they provide to us, as required by section 8(2) of the DPDP Act. We keep this list general because these providers change as we grow; the current list of providers is available on request from the contact in section 11.

We also share personal data where the law requires it — with a court, regulator or law enforcement agency on a valid request — and with our professional advisers where they need it. If our business is sold or reorganised, data may transfer with it, and you will be told.

6. Where it is stored

Our providers operate data centres in India and in other countries, so personal data may be stored or processed outside India. Where it is, we require the same protections by contract. We do not transfer personal data to any country the Government of India has restricted for this purpose.

7. How long we keep it

  • Invoices, payment and accounting records — for the period Indian tax and company law requires.
  • Your account and profile — until you delete the account, or we close it for a breach of the Account Terms.
  • Server and security logs — 5 years.
  • Enquiries and support messages — while the enquiry is live, then with our business records.
  • Client project material — for the engagement, and afterwards as set out in the Business Terms.

When a retention period ends, we delete the data or remove what identifies you. Copies inside routine backups go as those backups age out.

8. Your rights

Under the DPDP Act you may:

  • Ask what we hold about you and how it is being used.
  • Correct or complete anything inaccurate or out of date.
  • Erase personal data where we no longer need it for the purpose it was given, unless the law requires us to keep it.
  • Withdraw consent where we relied on it. This does not undo what was lawfully done beforehand.
  • Nominate another person to exercise your rights if you die or become incapacitated.
  • Complain to us, and if we do not resolve it, to the Data Protection Board of India.

Write to the contact in section 11. We will respond within a reasonable period, and we may need to verify who you are before we act.

9. Cookies

We use cookies that are necessary for the site and for signing in — they keep your session, remember your preferences and protect forms against cross-site request forgery. We do not use advertising cookies, and we do not allow third parties to track you across other websites from ours.

Your browser can block or delete cookies. Blocking the necessary ones will stop sign-in from working.

10. Security

We protect personal data with encryption in transit, access controls that give our people only what their job needs, logging of access, and regular backups. No system is perfectly secure, but if a personal data breach affects you we will notify you and the Data Protection Board of India as the DPDP Act requires.

11. Contact and grievances

Our Grievance Officer answers questions about this policy and handles complaints about how we use personal data.

Grievance Officer — WEBSTRAKE TECHNOLOGIES LLP

Email: [email protected]

Post: 2nd Floor, No 143, East Wing, RMZ Millenia Business Park, Chennai, Tamil Nadu 600096, India

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

12. Changes

We may update this policy. The date at the top always shows when it last changed, and where a change materially affects you we will tell you before it takes effect.