Privacy Policy.
How CLEPTO.IO SERVICES PRIVATE LIMITED collects, uses, and protects your information.
November 16, 2025
August 4, 2026
CLEPTO.IO SERVICES PRIVATE LIMITED
U62013PN2025PTC248011
Pune, India (registered)
Indore, India
Table of Contents
- Introduction
- Scope of This Policy
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- International Data Transfers
- Data Retention
- Data Security
- Your Rights and Choices
- Children’s Privacy
- Cookies and Tracking Technologies
- Third-Party Links
- Changes to This Privacy Policy
- Legal Basis for Processing (GDPR)
- Data Controller and Processor Roles
- Cross-Border Data Transfers — Detailed Safeguards
- Specific Processing Disclosures
- Automated Decision-Making
- Supervisory Authorities and Complaints
- Contact Us
- Effective Date and Version History
- Your Rights Under the DPDP Act, 2023
- Acknowledgment
1. Introduction
Welcome to Clepto.in ("we," "us," "our," or "Clepto"). This Privacy Policy explains how CLEPTO.IO SERVICES PRIVATE LIMITED collects, uses, discloses, and protects information from visitors to our website and users of our services.
Our Commitment
We are committed to protecting your privacy and handling your personal information transparently in accordance with applicable data protection laws.
Who We Are
- Company Name: CLEPTO.IO SERVICES PRIVATE LIMITED
- Corporate Identity Number (CIN): U62013PN2025PTC248011
- Registered Address: Pune, India
- Additional Office: Indore, India
- Primary Business: AI automation services and workflow automation solutions
- Privacy Contact: contact@clepto.in
Applicable Laws
This policy is designed to comply with:
- The Digital Personal Data Protection Act, 2023 (India)
- General Data Protection Regulation (GDPR) for EU visitors and clients
- Privacy best practices for international operations
2. Scope of This Policy
What This Policy Covers
This Privacy Policy applies to:
- Visitors to our website (clepto.in)
- Individuals who contact us through forms, email, or chat
- Newsletter subscribers
- Prospective and current clients engaging with our website
What This Policy Does NOT Cover
This policy does not cover how we process data on behalf of our clients in their automation workflows. That relationship is governed by separate Data Processing Agreements (DPAs) where we act as a data processor. For information about that, please see our Data Processing Agreement.
3. Information We Collect
3.1 Information You Provide Directly
Contact Forms
When you submit a contact form on our website, we collect:
- Full name
- Email address
- Phone number (if provided)
- Company name (if provided)
- Message content
- Any other information you choose to provide
Newsletter Subscriptions
When you subscribe to our newsletter, we collect:
- Email address
- Subscription preferences
- Date and time of subscription
Chat Interactions
When you interact with our AI chatbot (powered by n8n), we collect:
- Chat messages and conversation history
- Timestamp of interactions
- Basic technical information (browser type, device type)
Purpose: We collect this information to respond to your inquiries, provide information about our services, send newsletters and updates (with your consent), improve our customer service, and analyze how visitors interact with our website.
Legal Basis (GDPR): Consent (when you submit forms or subscribe), Legitimate interests (analyzing website usage, improving services), Contract performance (when engaging with prospective clients)
Legal Basis (India DPDP Act): Consent for collection and processing of personal data
3.2 Information Collected Automatically
Website Analytics
We use Google Analytics to understand how visitors use our website. This collects:
- IP address (anonymized)
- Browser type and version
- Device type (desktop, mobile, tablet)
- Operating system
- Pages visited and time spent
- Referring website
- Geographic location (country/city level)
- Language preferences
Cookies and Similar Technologies
We currently use minimal cookies. In the future, we may implement:
- Essential cookies (necessary for website functionality)
- Analytics cookies (Google Analytics)
- Marketing cookies (with your explicit consent)
When we implement cookie consent management, you will be able to accept or reject non-essential cookies through our cookie banner.
Purpose: This information helps us understand website traffic patterns, improve user experience, detect and prevent technical issues, and analyze marketing effectiveness.
Legal Basis (GDPR): Legitimate interests (website optimization, security)
Legal Basis (India DPDP Act): Legitimate business purpose
3.3 Information We Do NOT Collect
We do not knowingly collect:
- Sensitive personal data (health information, biometric data, financial information beyond basic billing details)
- Information from children under 18 years of age
- Data from our client workflows (that is processed separately under DPA terms)
4. How We Use Your Information
We use the information we collect for the following purposes:
Service Delivery
- Respond to your inquiries and requests
- Provide information about our AI automation services
- Process service agreements and deliver contracted services
- Provide customer support
Communication
- Send newsletters and updates (only with your consent)
- Send important service announcements
- Respond to questions via email or chat
- Follow up on inquiries
Website Improvement
- Analyze website usage patterns
- Improve user experience and functionality
- Develop new features and services
- Troubleshoot technical issues
Business Operations
- Maintain records of communications
- Comply with legal and regulatory requirements
- Protect against fraud and abuse
- Enforce our terms of service
Marketing (with consent)
- Send promotional materials about our services
- Share relevant industry insights and content
- Invite you to webinars or events
We Do NOT:
- Sell your personal information to third parties
- Use your information for purposes incompatible with those described above
- Share your information for third-party marketing without your explicit consent
- Process your data in ways you wouldn’t reasonably expect
5. How We Share Your Information
5.1 Third-Party Service Providers (Data Processors)
We share information with trusted third-party service providers who help us operate our website and deliver services. These providers are contractually obligated to protect your information and use it only for specified purposes.
Current Service Providers
| Provider | Service | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Supabase | Database & backend infrastructure | EU (Europe) | Contact form data, newsletter subscriptions, chat logs | EU-based servers, encryption at rest, GDPR-compliant |
| Hostinger | Website hosting | UK (Europe) | Website files, server logs | EU-based hosting, SSL/TLS encryption |
| Google Analytics | Website analytics | USA (with EU presence) | Anonymized visitor data, usage patterns | IP anonymization, data retention controls, GDPR settings enabled |
| n8n SMTP Automation Workflow | Email communications (custom automation via n8n open-source platform) | Hostinger VPS (Ireland/EU-based) | Email addresses, newsletter preferences, message content, send timestamps, delivery status | GDPR-compliant (EU-hosted), TLS/SSL encryption, data retained until unsubscribe + 30 days, no third-party sharing |
AI Providers (for chatbot functionality)
Our n8n chatbot may use the following AI services:
- OpenAI (USA)
- Anthropic (USA)
- Google Gemini (USA/EU)
- Mistral AI (EU — France)
- Other AI providers as needed
Safeguards for International Transfers
When data is transferred outside India or the EU, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all processors
- Encryption in transit and at rest
- Regular security assessments
5.2 Legal Requirements
We may disclose your information if required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations (court orders, subpoenas, regulatory requests)
- Protect and defend our rights or property
- Prevent fraud or abuse
- Protect the safety of our users or the public
- Respond to government or law enforcement requests
Notice: Where legally permitted, we will notify you before disclosing your information in response to legal requests.
5.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
6. International Data Transfers
Our Location: We are based in India, with offices in Pune (registered) and Indore.
Where Your Data May Be Processed
- India (primary location)
- European Union (Supabase, Hostinger servers)
- United States (Google Analytics, AI providers)
- Other locations where our service providers operate
Transfer Safeguards
For transfers outside India or the EU, we implement:
- Standard Contractual Clauses (SCCs): EU-approved contract terms for international data transfers
- Data Processing Agreements: Written contracts with all processors defining security obligations
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Transfer Impact Assessments: For transfers to countries without adequacy decisions (e.g., USA), we assess risks and implement supplementary measures
Your Rights: If you are in the EU, you have the right to obtain information about international transfers and request copies of the safeguards in place.
7. Data Retention
How Long We Keep Your Information
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form submissions | 12 months after the enquiry is resolved | Responding to your enquiry and continuity if you follow up |
| Newsletter subscriptions | Until you unsubscribe + 30 days | Marketing communications, unsubscribe processing |
| Chat logs | 3 years | Customer service improvement, dispute resolution |
| Website analytics | 26 months (Google Analytics default) | Usage analysis, trending |
| Billing/invoice data | 7 years | Tax and accounting compliance (Indian law) |
| Backups | 90 days | Disaster recovery, data integrity |
Deletion: After the retention period expires, we securely delete or anonymize your information so it can no longer identify you.
Legal Holds: We may retain data longer if required by law, to resolve disputes, enforce agreements, or defend legal claims.
7.4 Client Data Retention for Workflow Data
This section applies when Clepto.in processes data in your automated workflows (different from Sections 7.1–7.3 which cover website visitor data).
During Your Contract (While You Use Clepto.in)
- Timeline: Entire duration of your service
- Data Kept: All your workflow data, as configured by you
- Backups: Regular backups by Hostinger VPS
- Why: Ensure your workflows operate continuously, enable disaster recovery, support workflow history and audit trails.
Your Control: Pause workflows to stop data collection, delete data within workflows manually, or request immediate deletion (contact: contact@clepto.in).
After Your Contract Ends
Timeline: Automatic deletion process
Phase 1 (Days 1–30): Account Closure
- Your account marked for deletion
- Workflows stopped and disabled
- You can request data export before this completes
- Contact: contact@clepto.in for final data export
Phase 2 (Days 31–60): Data Deletion
- Account data permanently deleted from database
- Backups scheduled for deletion
- Hostinger performs secure deletion
Phase 3 (Days 61+): Compliance Retention Only
- Legal/audit logs retained (required by law for 7 years in India)
- Personal data fully deleted
- Workflow configurations removed
- Cannot be recovered
How We Delete Your Data
- Secure Deletion: Account data marked for deletion in database, automated deletion process runs, backup cleanup by Hostinger, verification that data is inaccessible
- Certificate of Deletion: We provide confirmation of deletion via email to contact@clepto.in
Exceptions (We Retain Data Longer If)
- Legal Hold: Court order requires data retention, tax audit or investigation ongoing, dispute resolution in progress. You will be notified immediately.
- Regulatory Compliance: Indian tax law (7-year retention for business records), GDPR (legal basis for retention documented), audit requirements specific to your industry.
- Your Request: You can ask us to retain data for archival purposes. Contact: contact@clepto.in
How to Request Deletion Immediately
Email: contact@clepto.in
Subject: "Please Delete My Clepto Account and All Data"
Include: Your email address, Account ID (if known), Reason (optional)
We will:
- Acknowledge within 24 hours
- Begin deletion within 48 hours
- Confirm completion within 30 days
No Penalty: Deletion can happen anytime during contract, no extra charges, no notice period required.
8. Data Security
Technical Safeguards
Encryption in Transit (Data Moving)
- Protocol: TLS 1.2 and TLS 1.3 with modern encryption standards
- Standard: HTTPS enforced on all connections
- Certificate: SSL/TLS certificate management through Hostinger VPS
- Verification: All connections must use HTTPS (secure)
Encryption at Rest (Data Stored)
- Storage: Hostinger VPS with PostgreSQL encrypted database storage
- Database Password: Strong authentication required
- Access Control: Role-based database access
- Backups: Encrypted backup storage by Hostinger
Authentication & Password Security
- Algorithm: Industry-standard password hashing (bcrypt or similar)
- Minimum Requirements: Strong password requirements enforced
- Session Management: Secure session tokens
- Failed Attempts: Rate-limiting on failed login attempts
Access Controls
- Role-Based: Different access levels for different users
- Monitoring: Access logs maintained for security
- Admin Access: Limited to authorized personnel only
- Regular Audits: Periodic review of access logs
Regular Updates: Systems and software regularly updated with security patches.
Organizational Safeguards
- Employee Training: Staff trained on data protection and security best practices
- Confidentiality Agreements: Employees and contractors bound by confidentiality obligations
- Data Minimization: We collect only information necessary for specified purposes
- Security Monitoring: Regular monitoring for suspicious activity and security incidents
Third-Party Security
All service providers must meet our security standards and comply with contractual security obligations.
Limitation: While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of information transmitted over the internet.
Breach Notification: In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by law (within 72 hours for GDPR, as prescribed by Indian law).
9. Your Rights and Choices
9.1 Rights Under Indian DPDP Act 2023
If you are in India, you have the following rights:
- Right to Access: Request confirmation of whether we are processing your data and obtain a copy
- Right to Correction: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Withdraw Consent: Withdraw consent at any time (without affecting prior processing)
- Right to Nominate: Nominate another person to exercise your rights in case of death or incapacity
- Right to Grievance Redressal: File complaints with the Data Protection Board of India
9.2 Rights Under EU GDPR (for EU Visitors/Clients)
If you are in the European Union, you have additional rights:
- Right to Access (Art. 15): Obtain a copy of your personal data we hold
- Right to Rectification (Art. 16): Correct inaccurate data
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion in certain circumstances
- Right to Restriction of Processing (Art. 18): Limit how we use your data
- Right to Data Portability (Art. 20): Receive your data in machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right Not to Be Subject to Automated Decision-Making (Art. 22): (Note: We do not make automated decisions with legal or significant effects)
- Right to Lodge a Complaint: File complaints with your local Data Protection Authority
EU Data Protection Authorities: edpb.europa.eu/about-edpb/board/members_en
9.3 How to Exercise Your Rights
Step 1: Send Request Email
Email: contact@clepto.in
Subject Line: "Data Access Request" OR "Data Deletion Request" OR "Data Correction Request"
Include in Your Email:
- Your full name
- Email address associated with your account/data
- Specific request type (choose one):
- Access: "Please provide a copy of all my personal data"
- Deletion: "Please permanently delete all my personal data"
- Correction: "Please correct/update the following information: [details]"
- Portability: "Please provide my data in machine-readable format"
- Restriction: "Please restrict processing of my data"
- Additional details to help us locate your information
Step 2: Identity Verification (Takes 3–5 Business Days)
What We’ll Do:
- Verify your identity (for security, to prevent unauthorized access)
- May request: Email verification, password confirmation, or account details
Why: To protect your privacy from bad actors and ensure only you can access or delete your data.
What You Should Do: Respond to our verification request promptly. Send verification via email to contact@clepto.in.
Step 3: Data Processing (Takes Up to 30 Days)
For Access Requests:
- We compile all data we hold about you
- Format as CSV or PDF file
- Send download link via email
For Deletion Requests:
- We permanently delete all personal data
- Secure deletion process: Data removal + backup cleanup
- Send confirmation email with deletion date
For Correction Requests:
- We update incorrect information
- Send confirmation of what was changed
- Verify changes applied
For Portability Requests:
- We provide data in machine-readable format (CSV/JSON)
- Include all data associated with your account
For Restriction Requests:
- We limit processing to storage only
- Mark your data as restricted
- Contact you when restriction can be removed
Step 4: Confirmation & Completion
You Receive:
- Email confirming request was processed
- For access: Download link with all your data
- For deletion: Deletion confirmation + date deleted
- For correction: List of changes made
- For portability: Data in format you requested (CSV/JSON)
- For restriction: Confirmation restriction is in effect
Timeline:
- Step 2 (verify): 3–5 business days
- Step 3 (process): Up to 30 days from verification
- Total typical time: 1–3 weeks
Step 5: If Not Satisfied — Appeal to Regulator
If you’re unhappy with our response, you can complain to:
For EU Residents:
- Your local Data Protection Authority (DPA)
- Find yours: edpb.europa.eu/about-edpb/board/members_en
- No fees required (free to file)
For India Residents:
- Data Protection Board of India (once established)
- Or contact: contact@clepto.in (reference your case)
For Ireland-Related Issues:
- Data Protection Commission (Ireland)
- Website: dataprotection.ie
- Email: info@dataprotection.ie
Important: Filing a complaint with a regulator does not prevent you from seeking legal remedies.
No Fees: We do not charge for most data requests. Excessive or repetitive requests (same request 5+ times per year) may incur reasonable administrative fees ($25–50 USD).
9.4 Communication Preferences
Newsletter Unsubscribe
Every marketing email contains an "Unsubscribe" link. Click it to stop receiving newsletters immediately.
Cookie Preferences
When we implement cookies, you will be able to manage preferences via our cookie banner or by contacting contact@clepto.in.
Do Not Track
Our website does not currently respond to "Do Not Track" browser signals, but you can disable cookies in your browser settings.
10. Children’s Privacy
Our services are not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18.
If We Learn: If we discover we have inadvertently collected information from a child under 18, we will delete it immediately.
Parental Notice: If you are a parent or guardian and believe your child has provided us with personal information, please contact contact@clepto.in.
11. Cookies and Tracking Technologies
Current Status
We currently use minimal cookies (primarily for website functionality and Google Analytics).
Future Cookie Use
We plan to implement the following cookie types:
Essential Cookies (Always Active)
- Session management
- Security
- Website functionality
Analytics Cookies (Requires Consent)
- Google Analytics
- Usage tracking
- Performance monitoring
Marketing Cookies (Requires Consent)
- Advertising tracking
- Remarketing campaigns
- Conversion tracking
Cookie Consent: Before implementing non-essential cookies, we will deploy a cookie consent banner allowing you to accept or reject them.
Cookie Policy: A detailed cookie policy is published at clepto.in/cookies.
Your Control
- Accept or reject cookies via our consent banner
- Manage preferences in browser settings
- Clear cookies at any time
12. Third-Party Links
Our website may contain links to third-party websites, plugins, or applications. This Privacy Policy does not apply to those third parties.
Responsibility: We are not responsible for the privacy practices of external websites. We encourage you to review their privacy policies before providing information.
Examples of Third-Party Links
- Social media platforms (LinkedIn, Twitter, etc.)
- Partner websites
- AI provider documentation
- Industry resources
13. Changes to This Privacy Policy
Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Legal or regulatory requirements
- New features or services
- User feedback
Notice of Changes
- Material Changes: We will provide prominent notice on our website and/or email notification
- Minor Changes: Updated "Last Updated" date at the top of this policy
- Effective Date: Changes take effect on the date specified in the updated policy
Your Acceptance: Continued use of our website after changes constitutes acceptance of the updated policy.
Archive: Previous versions available upon request at contact@clepto.in.
14. Legal Basis for Processing (GDPR)
For EU visitors, we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis |
|---|---|
| Contact form responses, service delivery | Contract performance (Art. 6(1)(b)) |
| Newsletter subscriptions | Consent (Art. 6(1)(a)) |
| Website analytics, improvement | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance, dispute resolution | Legal obligation (Art. 6(1)(c)) / Legal claims (Art. 9(2)(f)) |
| Fraud prevention, security | Legitimate interests (Art. 6(1)(f)) |
Legitimate Interests: When we process data based on legitimate interests, we balance our interests against your rights and freedoms. You have the right to object to such processing.
15. Data Controller and Processor Roles
When We Are the Data Controller
For information collected through our website (contact forms, newsletters, analytics), Clepto.in is the data controller. We determine the purposes and means of processing.
When We Are a Data Processor
When we build AI automation workflows for clients and process their customers’ data, we are a data processor. Our clients are the data controllers.
Client Data Processing
Governed by separate Data Processing Agreements (DPAs) that define:
- Scope of processing
- Security obligations
- Sub-processor management
- Data subject rights assistance
- Breach notification procedures
Contact for Client Workflow Data: If your data is being processed in a client’s workflow, contact that client directly. We can only act on instructions from the client (the controller).
16. Cross-Border Data Transfers — Detailed Safeguards
India to EU/EEA
- Mechanism: Supabase hosting in EU region ensures data stays within EU
- Adequacy: India does not have an EU adequacy decision
- Safeguards: Standard Contractual Clauses with Supabase
India to USA
- Providers: Google Analytics, OpenAI, Anthropic
- Adequacy: USA does not have an EU adequacy decision (Schrems II)
- Safeguards:
- Standard Contractual Clauses
- Transfer Impact Assessments (TIA) for each provider
- Data minimization (only necessary data transferred)
- Encryption in transit and at rest
EU to USA (for EU Visitors)
- Google Analytics: Configured with IP anonymization, consent-based tracking
- AI Providers: Used only when necessary; chat logs minimized
Documentation Available: Copies of our SCCs and Transfer Impact Assessments available upon request at contact@clepto.in (for legitimate requests only).
17. Specific Processing Disclosures
AI Chatbot (n8n-powered)
⚠ Important: Artificial Intelligence Disclosure
Our chatbot uses multiple AI models to provide customer support. Please be aware of the following.
AI Models We Use
- OpenAI (Latest GPT models)
- Anthropic (Claude — Latest versions)
- Google Gemini (Latest models)
- Mistral (Latest models)
- Perplexity (Latest models)
Limitations of AI You Should Know
- AI May Provide Inaccurate Information: AI generates text based on training data, which may be outdated. AI can "hallucinate" or confidently state false information. Always verify important information with a human.
- AI Can Be Biased: Training data reflects biases in historical information. Responses may reflect demographic or contextual biases. We review responses but cannot eliminate bias completely.
- AI Lacks Real-Time Information: Cannot access current real-time data. May not understand your specific business context. Recommendations may not fit your unique situation.
- AI Cannot Make Binding Decisions: AI responses are informational only. Not legal advice, medical advice, or financial advice. You should verify before taking action.
Our Safeguards
- Response Review: Our team reviews AI responses for quality
- Multiple Models: We use multiple AI models for comparison and accuracy
- Feedback Loop: We improve responses based on user feedback
- Human Escalation: Important queries routed to humans
Your Rights & Control
- Talk to Human: Every chat has "Contact us" or request human support option
- Delete History: You can request deletion of your chat history anytime
- Opt Out: You can use email support instead: contact@clepto.in
- Data Access: Request your chat logs anytime: contact@clepto.in
Processing Details
- Purpose: Provide automated customer support and answer questions
- Data Collected: Chat messages, timestamps, basic browser info
- AI Providers Used: OpenAI, Anthropic, Google Gemini, Mistral, Perplexity (selected based on query complexity)
- Data Retention: Chat logs retained for 3 years (for service improvement)
- Human Review: Our team reviews chat logs to improve responses and fix errors
- Your Control: Delete your chat history anytime or email contact@clepto.in
Questions about AI? Email contact@clepto.in
Google Analytics
- Purpose: Understand website traffic and user behavior
- Data Collected: Anonymized IPs, page views, session duration, device info
- Configuration: IP anonymization enabled, data retention set to 26 months
- Your Control: You can opt out via browser plugins (e.g., Google Analytics Opt-out Browser Add-on)
Newsletter (Future Implementation)
- Purpose: Send updates about our services, AI automation insights, industry news
- Frequency: Approximately 1–2 emails per month (you control frequency)
- Opt-out: Every email includes unsubscribe link
- Data Sharing: We do not share subscriber lists with third parties
18. Automated Decision-Making
Current Status
We do not use automated decision-making with legal or similarly significant effects.
AI Chatbot
While our chatbot uses AI, it does not make decisions that legally affect you. It’s purely informational.
Future Use
If we ever implement automated decision-making (e.g., credit scoring, hiring), we will:
- Notify you clearly
- Obtain explicit consent where required
- Provide information about the logic involved
- Allow you to contest decisions and request human review
19. Supervisory Authorities and Complaints
India
If you have complaints about our data practices in India:
- Authority: Data Protection Board of India
- Website: (To be established under DPDP Act 2023)
- First Step: Contact us at contact@clepto.in to resolve issues directly
European Union (for EU Residents)
- Authority: Your local Data Protection Authority (DPA)
- Contact: Find your DPA at edpb.europa.eu/about-edpb/board/members_en
- Right: You have the right to lodge a complaint without prejudice to other remedies
Ireland (for EU Complaints Related to Clepto)
Since some of our service providers are in the EU:
- Authority: Data Protection Commission (Ireland)
- Website: dataprotection.ie
- Contact: info@dataprotection.ie
We Encourage Direct Contact: Before filing complaints with authorities, please contact contact@clepto.in so we can resolve issues directly.
20. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal information:
Primary Contact
- Email: contact@clepto.in
- Phone: +91-8383898958
- Subject Line: Please use clear subject lines (e.g., "Privacy Policy Question", "Data Access Request", "Unsubscribe Request")
Company Details
- Company: CLEPTO.IO SERVICES PRIVATE LIMITED
- CIN: U62013PN2025PTC248011
- Registered Address: Pune, India
- Additional Office: Indore, India
- Website: clepto.in
Response Time
- We aim to respond to privacy inquiries within 5 business days
- Formal data subject rights requests: 30 days (GDPR) or as required by Indian law
21. Effective Date and Version History
- Current Version: 1.1
- Effective Date: November 16, 2025
- Last Updated: August 4, 2026
- Previous Versions: 1.0 (November 16, 2025)
- Changes in 1.1: Added section 22 setting out rights under India's DPDP Act, 2023, named a Grievance Officer, and shortened contact form retention from 3 years to 12 months
- Version History: Available upon request at contact@clepto.in
22. Your Rights Under the DPDP Act, 2023
India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") governs how we handle the personal data of people in India. Under that Act you are the Data Principal — the person the data is about — and CLEPTO.IO SERVICES PRIVATE LIMITED is the Data Fiduciary, the company that decides why and how your data is processed. This section sets out, in plain terms, what we collect from this website, why, how long we keep it, and how you can exercise your rights.
22.1 What We Collect From This Website, and Why
The only personal data this website collects from you is what you type into the contact form and the newsletter field. We do not require an account, and we do not sell personal data.
| What we collect | Where from | Why |
|---|---|---|
| Name | Contact form | To address you correctly in our reply |
| Email address | Contact form, newsletter | To reply to your enquiry; to send the newsletter if you subscribed |
| Phone number | Contact form (optional) | To reply by phone if you prefer |
| Company name or website | Contact form (optional) | To understand the context of your enquiry |
| Country | Contact form | To route your enquiry and apply the right time zone |
| Service of interest | Contact form (optional) | To direct your enquiry to the right person |
| Your message | Contact form | To answer what you actually asked |
We use this information for one purpose: responding to your enquiry. We do not use contact form data for advertising, we do not build profiles from it, and we do not pass it to third parties for their own marketing.
22.2 The Consent We Ask For
Before the contact form can be submitted you must tick a consent box. It is not pre-ticked, it is not bundled with anything else, and the form will not send without it. That box covers exactly one thing: storing and using the details above to respond to your enquiry.
22.3 How Long We Keep It
Contact form submissions are kept for 12 months after your enquiry is resolved, then deleted. We keep them that long so we can pick up a conversation you started earlier and so we have a record if a dispute arises. If you ask us to delete them sooner, we will — see 22.5.
Newsletter subscriptions are kept until you unsubscribe, plus 30 days to process the removal. Other retention periods are set out in section 7.
22.4 Withdrawing Your Consent
You can withdraw your consent at any time, and it is as easy as giving it: email contact@clepto.in with the word "withdraw" and the email address you used. No form, no explanation required.
Once you withdraw, we stop processing your data and delete it within 30 days unless we are legally required to keep it. Withdrawing does not make anything we did beforehand unlawful, and it does not affect data we must retain for tax or accounting purposes.
22.5 Access, Correction and Erasure
Under sections 11 to 13 of the DPDP Act you can ask us to:
- Show you what we hold — a summary of your personal data and what we have done with it
- Correct or complete it — if anything is wrong or out of date
- Erase it — unless we are required by law to keep it
- Nominate someone — to exercise these rights on your behalf if you die or become incapacitated
Email contact@clepto.in from the address you originally contacted us with. If you write from a different address we will ask one or two questions to confirm the request is genuinely yours, because handing your data to the wrong person would be the greater harm. We respond within 30 days. There is no charge.
22.6 Grievance Officer
Section 13 of the DPDP Act requires us to publish a contact point for complaints. If you are unhappy with how we have handled your personal data or your request, you can raise it directly with:
CLEPTO.IO SERVICES PRIVATE LIMITED
SNO.107-108, PT-B, Rosewood, SFL-J-603, Pimple Saudagar, Pune, Maharashtra, India
Email: contact@clepto.in
Please put "Grievance" in the subject line so it is routed correctly.
We acknowledge grievances within 7 working days and resolve them within 30 days of receipt.
22.7 Escalating to the Data Protection Board
If we have not resolved your grievance to your satisfaction, you may complain to the Data Protection Board of India, the authority established under the DPDP Act. We ask that you raise it with our Grievance Officer first, as the Act expects, but that is your route if we cannot settle it.
22.8 Your Obligations
The DPDP Act also places duties on you as a Data Principal: give accurate information, do not impersonate someone else, and do not file frivolous or false complaints. We mention this only because the Act requires us to; in practice we simply ask that the details you send us are your own and are correct.
23. Acknowledgment
By using our website, submitting forms, subscribing to our newsletter, or engaging with our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.