Trust Center

Trust Center.

Transparency in security, privacy, and compliance.

Our Commitment to Trust

At Clepto.in, we believe trust is earned through transparency, robust security practices, and unwavering commitment to data protection. This Trust Center provides comprehensive information about how we protect your data and maintain compliance with global privacy regulations.

Security & Compliance at a Glance

🌍

Multi-Jurisdictional Compliance

GDPR (EU) · DPDP Act (India) · Privacy best practices

🔐

Enterprise-Grade Security

AES-256 encryption · TLS 1.2+ · Role-based access control

📊

Full Audit Trails

Every workflow execution logged for 3 years minimum

🇪🇺

EU Data Residency

Primary data stored in EU · Optional EU-only processing

👁

100% Sub-Processor Transparency

Complete visibility into all third-party providers

24-Hour Breach Notification

Rapid incident response and communication

Compliance Documentation

✓ Complete

Privacy & Cookie Policies

Comprehensive policies covering data collection, processing, and your rights under GDPR and Indian DPDP Act 2023.

✓ Complete

Sub-Processor Transparency

Complete list of all third-party service providers we use, including AI providers, hosting, and infrastructure.

🔗 Sub-Processors List →

Updated November 16, 2025 · 8 providers

Featured Providers

  • Supabase (EU) — Database hosting with EU data residency
  • Hostinger (UK) — Website and application hosting
  • Mistral AI (France) — EU-only AI provider option
  • OpenAI, Anthropic, Google — AI language models with SCCs
📧 Available on Request

Data Processing Agreement (DPA)

GDPR-compliant Data Processing Agreement for clients, including EU Standard Contractual Clauses and comprehensive security measures.

  • ✓ EU Standard Contractual Clauses (SCCs)
  • ✓ Transfer Impact Assessments for US providers
  • ✓ Security measures documentation (Annex II)
  • ✓ Data subject rights assistance procedures
  • ✓ Sub-processor management framework
  • ✓ Incident response and breach notification
🚧 Roadmap

Security Certifications

We are working toward industry-standard security certifications as we scale.

● Current (2025)

ISO 42001 framework-aligned practices · GDPR-ready infrastructure · Security best practices

○ 2026 Target

ISO 27001 (Information Security) · ISO 42001 (AI Management Systems)

○ 2027 Target

SOC 2 Type II (for US enterprise clients) · Annual penetration testing

Security Architecture

🔐 Data Protection

  • Hosting: Hostinger VPS (Ireland)
  • Database: PostgreSQL with encrypted storage on Hostinger VPS
  • Encryption in Transit: TLS 1.2/1.3 HTTPS (all connections encrypted)
  • Access Control: Role-based access controls
  • Authentication: Secure password requirements with bcrypt hashing
  • Backups: Regular encrypted backups by Hostinger

👥 Access Control

  • Role-Based Access (RBAC): Minimum necessary access
  • Multi-Factor Authentication: Required for admin access
  • Strong Passwords: 12+ characters, complexity requirements
  • Access Logging: All access to personal data logged

📊 Monitoring & Logging

  • Comprehensive Audit Logs: Every workflow execution tracked
  • Security Monitoring: 24/7 monitoring for anomalies
  • Log Retention: Minimum 3 years for compliance
  • Immutable Logs: Cannot be altered after creation

🔄 Business Continuity

  • Daily Backups: Automated, encrypted, geographically distributed
  • Disaster Recovery: RPO < 24 hours, RTO < 48 hours
  • Redundancy: Multi-availability zone architecture
  • Backup Testing: Monthly restoration tests

🛡 Organizational Security

  • Security Training: Regular staff training on data protection
  • Confidentiality: All team members bound by NDAs
  • Incident Response: Documented procedures, 24-hour notification
  • Vendor Management: Security assessment of all sub-processors

🔍 Compliance Controls

  • Data Minimization: Collect only necessary data
  • Privacy by Design: Privacy built into workflow design
  • Data Retention: Automated deletion after retention period
  • Client Data Isolation: Multi-tenant architecture with separation

Your Data Rights

Under GDPR and Indian DPDP Act, you have comprehensive rights over your personal data.

📋
Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct any inaccurate or incomplete data

🗑
Right to Erasure

Request deletion of your personal data (right to be forgotten)

📦
Right to Data Portability

Receive your data in machine-readable format

🚫
Right to Object

Object to processing based on legitimate interests

Right to Restriction

Limit how we use your data in certain circumstances

Exercise Your Rights

To exercise any of these rights, contact us at:

contact@clepto.in

We will respond within 30 days (GDPR) or as required by applicable law.

DPDP Act, 2023 — India

India's Digital Personal Data Protection Act, 2023 applies to the personal data we hold about people in India. Under it you are the Data Principal and CLEPTO.IO SERVICES PRIVATE LIMITED is the Data Fiduciary. Our full obligations are set out in the Privacy Policy; this section covers how we secure that data, what happens if it is ever breached, and where it goes.

Safeguards for Contact Data

The only personal data this website collects is what you submit through the contact form — name, email, phone, company, country, service interest and your message. It is protected by the same controls as the rest of our stack:

🔐
Encrypted in Transit

TLS 1.2/1.3 on every connection to this site and to our systems

🗄
Encrypted at Rest

Stored on encrypted infrastructure with encrypted backups

👤
Access Controlled

Role-based access; only the people handling your enquiry can read it

Time Limited

Deleted 12 months after your enquiry is resolved, or sooner on request

We do not sell personal data, and contact form submissions are never used for advertising or profiling.

Breach Notification

Section 8(6) of the DPDP Act requires a Data Fiduciary to report a personal data breach to both the Data Protection Board of India and every affected Data Principal — not only the regulator. Our commitment:

1
Notify You Directly

Every affected person is contacted, in addition to any regulator. Within 24 hours of confirming the breach.

2
Notify the Board

The Data Protection Board of India is notified without delay, in the form and manner the Act prescribes.

3
Tell You What Matters

What was exposed, when, what we have done about it, and what you should do — in plain language, not a legal notice.

Where GDPR also applies, the 72-hour supervisory authority deadline runs in parallel. The two regimes are additive; we meet whichever is stricter.

Cross-Border Transfers

Section 16 of the DPDP Act permits transferring personal data outside India, except to countries the Central Government restricts by notification. Our position:

  • We transfer personal data only to the sub-processors listed on our Sub-processors page, and only where it is needed to deliver the service.
  • We monitor the Central Government's notified list and will stop transfers to any country that appears on it.
  • Transfers out of India carry the same safeguards described under Transfer Safeguards below — contractual protections, encryption, and data minimisation.
  • The DPDP Act does not require data localisation for our processing, and we do not claim to hold data exclusively in India.

India-specific transfer duties sit alongside, and do not replace, the EU-outbound safeguards described in the next section.

Grievance Officer

Mr. Narendra Singh Parmar
CLEPTO.IO SERVICES PRIVATE LIMITED
Email: contact@clepto.in (subject line: "Grievance")

Acknowledged within 7 working days, resolved within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India.

International Data Transfers

We process data across multiple jurisdictions with appropriate safeguards.

🇮🇳

India

Our Location

Registered office in Pune, Maharashtra, with an additional office in Indore, Madhya Pradesh.

🇪🇺

European Union

Primary Data Storage

Supabase (EU), Hostinger (UK), Mistral AI (France).

No Cross-Border Transfer
🇺🇸

United States

AI Providers (Optional)

OpenAI, Anthropic, Google (only if selected).

SCCs + TIA

Transfer Safeguards

  • Standard Contractual Clauses (SCCs): EU Commission-approved contracts with all US providers
  • Transfer Impact Assessments: Risk analysis for each US provider (Schrems II compliance)
  • Encryption & Minimization: Data encrypted in transit, only necessary data transferred
  • EU-Only Option Available: Clients can choose to use only EU-based providers (Mistral AI)

Incident Response

Our commitment to transparency includes rapid communication in case of security incidents.

1
Detection

Immediate identification through monitoring systems or reports

2
Containment

Stop the incident from spreading within minutes

3
Client Notification

Within 24 hours of becoming aware

4
Investigation

Root cause analysis and impact assessment

5
Authority Notification

Within 72 hours if required by GDPR

6
Remediation

Fix vulnerabilities and implement preventive measures

Report a Security Concern

contact@clepto.in

Questions About Trust & Security?

📧

Privacy Inquiries

Data protection, privacy rights, DPA requests

contact@clepto.in
🔒

Security Questions

Security practices, compliance documentation

contact@clepto.in
📋

Documentation Requests

DPA, security questionnaires, audit reports

contact@clepto.in
CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Registered office — SNO.107-108, PT-B, ROSEWOOD, SFL-J-603, PIMPLE SAUDAGAR
Pune, India
Office — Indore, India