Privacy Overview & DPDP Compliance
At Satkosh, we practice strict privacy by design. We do not sell personal data, do not engage in behavioural ad tracking, and do not inspect the contents of your backups. Your backup data is encrypted on your machines before it leaves your environment and travels directly to the storage location you choose. You decide who holds the encryption password: under managed encryption we store it for you, and under zero-knowledge encryption you hold it alone, which means we cannot access your backup data and also cannot recover it for you if the password is lost.
1. Who We Are & Scope
Serverstock Datacenter Private Limited ("Serverstock", "we", "us", "our") operates the Satkosh automated backup and disaster recovery platform and the marketing website at satkosh.com. This Privacy Policy explains how we handle personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act)and applicable information technology regulations.
2. Delineation of Roles (Data Fiduciary vs. Data Processor)
Under the DPDP Act framework, data roles are categorized based on the service context:
3. Personal Data We Collect
3.1 Prospective Inquiries & Communications
When you request a product demo, submit an enquiry, or email us: we collect your name, corporate email address, phone number, company name, infrastructure scale, and inquiry message. We use this information solely to schedule demonstrations and respond to technical questions.
3.2 Console Account & Administrative Access
When your organization provisions access to the Satkosh Management Console:
- Account Identity: Name, professional email address, organization affiliation, and assigned administrative role.
- Authentication Credentials: Secure salted password hashes (never plaintext) and encrypted TOTP MFA keys.
- Security Audit Logs: Timestamped records of administrative logins, device enrolments, policy modifications, and restore requests alongside source IP addresses.
- Machine Telemetry: Device hostnames, operating system version, backup job execution time, transfer byte counts, and status indicators. File contents and filenames are never logged in platform telemetry.
4. Data Processing Matrix & Retention Periods
| Category of Data | Purpose of Processing | Legal Basis (DPDP Act) | Retention Period |
|---|---|---|---|
| Account Details (Name, Email, Role) | User authentication & console access control | Performance of Contract | Duration of active customer subscription + 30 days |
| Security Audit Logs (IP, Action, Time) | Platform security, intrusion detection & forensic integrity | Legitimate Interest / Legal Compliance | Rolling 365 days |
| Job Telemetry (Size, Timing, Status) | Automated backup verification & reporting | Performance of Contract | Duration of subscription |
| Billing & Invoicing Records | Financial accounting, GST invoicing & statutory audit | Legal Obligation (Tax & Companies Act) | 8 years (statutory requirement) |
| Demo / Sales Inquiries | Responding to technical & commercial inquiries | Consent / Legitimate Request | 180 days or until requested deletion |
5. Zero Advertising & Non-Disclosure Commitment
Our Core Promise: We never sell, rent, monetize, or trade your personal data. We do not engage in cross-site behavioral ad retargeting, and we do not feed customer information or metadata into public machine-learning training models.
6. Infrastructure Partners & Sub-Processors
We share personal data only with vetted infrastructure partners necessary to deliver platform operations, under strict data protection and confidentiality agreements:
- Datacenter & Cloud Hosting: Certified Tier-3/Tier-4 cloud facilities located in India (Mumbai / Western region) for sovereign data hosting.
- Transactional Communications: Enterprise transactional email relays strictly used for sending automated backup failure alerts and verification codes.
- Statutory Authorities: Disclosures made only when formally compelled under valid judicial process or applicable law of the Republic of India.
7. Rights of Data Principals (Under DPDP Act)
Under the Digital Personal Data Protection Act, you have specific statutory rights regarding your personal data:
- Right to Access: You may request a summary of personal data being processed by Serverstock and the identities of any data fiduciaries or processors with whom it has been shared.
- Right to Correction & Erasure: You may request correction of inaccurate data or erasure of data no longer necessary for the purpose it was collected.
- Right of Grievance Redressal: You may register a formal grievance with our designated Data Protection Grievance Officer.
- Right to Nominate: You have the right to nominate an individual to exercise your data principal rights in the event of death or incapacity.
8. Data Protection Grievance Redressal
In accordance with the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, any inquiries, complaints, or grievance requests should be directed to our designated officer:
Data Protection Grievance Officer
For inquiries regarding personal data processing, rights requests, or regulatory compliance: