Trust Center.
Transparency in security, privacy, and compliance.
Our Commitment to Trust
At Clepto.in, we believe trust is earned through transparency, robust security practices, and unwavering commitment to data protection. This Trust Center provides comprehensive information about how we protect your data and maintain compliance with global privacy regulations.
Security & Compliance at a Glance
Multi-Jurisdictional Compliance
GDPR (EU) · DPDP Act (India) · Privacy best practices
Enterprise-Grade Security
AES-256 encryption · TLS 1.2+ · Role-based access control
Full Audit Trails
Every workflow execution logged for 3 years minimum
EU Data Residency
Primary data stored in EU · Optional EU-only processing
100% Sub-Processor Transparency
Complete visibility into all third-party providers
24-Hour Breach Notification
Rapid incident response and communication
Compliance Documentation
Privacy & Cookie Policies
Comprehensive policies covering data collection, processing, and your rights under GDPR and Indian DPDP Act 2023.
Sub-Processor Transparency
Complete list of all third-party service providers we use, including AI providers, hosting, and infrastructure.
🔗 Sub-Processors List →Updated November 16, 2025 · 8 providers
Featured Providers
- Supabase (EU) — Database hosting with EU data residency
- Hostinger (UK) — Website and application hosting
- Mistral AI (France) — EU-only AI provider option
- OpenAI, Anthropic, Google — AI language models with SCCs
Data Processing Agreement (DPA)
GDPR-compliant Data Processing Agreement for clients, including EU Standard Contractual Clauses and comprehensive security measures.
- ✓ EU Standard Contractual Clauses (SCCs)
- ✓ Transfer Impact Assessments for US providers
- ✓ Security measures documentation (Annex II)
- ✓ Data subject rights assistance procedures
- ✓ Sub-processor management framework
- ✓ Incident response and breach notification
Security Certifications
We are working toward industry-standard security certifications as we scale.
ISO 42001 framework-aligned practices · GDPR-ready infrastructure · Security best practices
ISO 27001 (Information Security) · ISO 42001 (AI Management Systems)
SOC 2 Type II (for US enterprise clients) · Annual penetration testing
Security Architecture
🔐 Data Protection
- Hosting: Hostinger VPS (Ireland)
- Database: PostgreSQL with encrypted storage on Hostinger VPS
- Encryption in Transit: TLS 1.2/1.3 HTTPS (all connections encrypted)
- Access Control: Role-based access controls
- Authentication: Secure password requirements with bcrypt hashing
- Backups: Regular encrypted backups by Hostinger
👥 Access Control
- Role-Based Access (RBAC): Minimum necessary access
- Multi-Factor Authentication: Required for admin access
- Strong Passwords: 12+ characters, complexity requirements
- Access Logging: All access to personal data logged
📊 Monitoring & Logging
- Comprehensive Audit Logs: Every workflow execution tracked
- Security Monitoring: 24/7 monitoring for anomalies
- Log Retention: Minimum 3 years for compliance
- Immutable Logs: Cannot be altered after creation
🔄 Business Continuity
- Daily Backups: Automated, encrypted, geographically distributed
- Disaster Recovery: RPO < 24 hours, RTO < 48 hours
- Redundancy: Multi-availability zone architecture
- Backup Testing: Monthly restoration tests
🛡 Organizational Security
- Security Training: Regular staff training on data protection
- Confidentiality: All team members bound by NDAs
- Incident Response: Documented procedures, 24-hour notification
- Vendor Management: Security assessment of all sub-processors
🔍 Compliance Controls
- Data Minimization: Collect only necessary data
- Privacy by Design: Privacy built into workflow design
- Data Retention: Automated deletion after retention period
- Client Data Isolation: Multi-tenant architecture with separation
Your Data Rights
Under GDPR and Indian DPDP Act, you have comprehensive rights over your personal data.
Request a copy of all personal data we hold about you
Correct any inaccurate or incomplete data
Request deletion of your personal data (right to be forgotten)
Receive your data in machine-readable format
Object to processing based on legitimate interests
Limit how we use your data in certain circumstances
Exercise Your Rights
To exercise any of these rights, contact us at:
We will respond within 30 days (GDPR) or as required by applicable law.
DPDP Act, 2023 — India
India's Digital Personal Data Protection Act, 2023 applies to the personal data we hold about people in India. Under it you are the Data Principal and CLEPTO.IO SERVICES PRIVATE LIMITED is the Data Fiduciary. Our full obligations are set out in the Privacy Policy; this section covers how we secure that data, what happens if it is ever breached, and where it goes.
Safeguards for Contact Data
The only personal data this website collects is what you submit through the contact form — name, email, phone, company, country, service interest and your message. It is protected by the same controls as the rest of our stack:
TLS 1.2/1.3 on every connection to this site and to our systems
Stored on encrypted infrastructure with encrypted backups
Role-based access; only the people handling your enquiry can read it
Deleted 12 months after your enquiry is resolved, or sooner on request
We do not sell personal data, and contact form submissions are never used for advertising or profiling.
Breach Notification
Section 8(6) of the DPDP Act requires a Data Fiduciary to report a personal data breach to both the Data Protection Board of India and every affected Data Principal — not only the regulator. Our commitment:
Every affected person is contacted, in addition to any regulator. Within 24 hours of confirming the breach.
The Data Protection Board of India is notified without delay, in the form and manner the Act prescribes.
What was exposed, when, what we have done about it, and what you should do — in plain language, not a legal notice.
Where GDPR also applies, the 72-hour supervisory authority deadline runs in parallel. The two regimes are additive; we meet whichever is stricter.
Cross-Border Transfers
Section 16 of the DPDP Act permits transferring personal data outside India, except to countries the Central Government restricts by notification. Our position:
- We transfer personal data only to the sub-processors listed on our Sub-processors page, and only where it is needed to deliver the service.
- We monitor the Central Government's notified list and will stop transfers to any country that appears on it.
- Transfers out of India carry the same safeguards described under Transfer Safeguards below — contractual protections, encryption, and data minimisation.
- The DPDP Act does not require data localisation for our processing, and we do not claim to hold data exclusively in India.
India-specific transfer duties sit alongside, and do not replace, the EU-outbound safeguards described in the next section.
Grievance Officer
Mr. Narendra Singh Parmar
CLEPTO.IO SERVICES PRIVATE LIMITED
Email: contact@clepto.in (subject line: "Grievance")
Acknowledged within 7 working days, resolved within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India.
International Data Transfers
We process data across multiple jurisdictions with appropriate safeguards.
India
Our Location
Registered office in Pune, Maharashtra, with an additional office in Indore, Madhya Pradesh.
European Union
Primary Data Storage
Supabase (EU), Hostinger (UK), Mistral AI (France).
No Cross-Border TransferUnited States
AI Providers (Optional)
OpenAI, Anthropic, Google (only if selected).
SCCs + TIATransfer Safeguards
- ✓ Standard Contractual Clauses (SCCs): EU Commission-approved contracts with all US providers
- ✓ Transfer Impact Assessments: Risk analysis for each US provider (Schrems II compliance)
- ✓ Encryption & Minimization: Data encrypted in transit, only necessary data transferred
- ✓ EU-Only Option Available: Clients can choose to use only EU-based providers (Mistral AI)
Incident Response
Our commitment to transparency includes rapid communication in case of security incidents.
Immediate identification through monitoring systems or reports
Stop the incident from spreading within minutes
Within 24 hours of becoming aware
Root cause analysis and impact assessment
Within 72 hours if required by GDPR
Fix vulnerabilities and implement preventive measures
Report a Security Concern
Questions About Trust & Security?
Pune, India
Office — Indore, India