Privacy Policy
Comprehensive Statutory Notice under Section 5 of the Digital Personal Data Protection Act, 2023.
Statutory Privacy Commitment
PINSOFTEK ("Company", "We", "Us", "Our"), operating the Kare®- 360° Data Migration platform, is committed to safeguarding the privacy, confidentiality, and integrity of digital personal data. This Privacy Policy constitutes a statutory notice under Section 5 of the Digital Personal Data Protection Act, 2023 (DPDPA) and outlines our technical and organizational practices for processing personal and enterprise data.
1LEGAL STATUS: FIDUCIARY VS. PROCESSOR
1.1. Account & Administrative Data (Data Fiduciary): For account registration, billing credentials, technical contacts, and consent logs, Pinsoftek acts as a Data Fiduciary under the DPDPA 2023.
1.2. Migrated Payload Content (Data Processor): For Customer Data transferred between third-party cloud tenants (Google Workspace, Microsoft 365, Dropbox, etc.), the Customer acts as the Data Fiduciary, and Pinsoftek acts strictly as a Data Processor under Section 8 of the DPDPA 2023.
2DATA COLLECTED & PURPOSES OF PROCESSING
| Category | Data Points Collected | Lawful Basis (DPDPA Sec 4) |
|---|---|---|
| Administrator Profile | Full Name, Work Email, Personal Email, Mobile No, Organization | Explicit Consent (Sec 6) |
| Consent Audit Logs | IP Address, Timestamp, Terms Version, Verification Status | Statutory Mandate (Sec 6(10)) |
| Migration Metadata | Object count, transfer volume, source/dest IDs, error codes | Contract Performance (Sec 4(1)) |
| Security & CERT-In Logs | System access logs, API rate telemetry, authentication records | Cybersecurity Direction (Sec 70B IT Act) |
3STATELESS STREAMING & ZERO-STORAGE GUARANTEE
Pinsoftek operates a strictly stateless migration engine. When files, emails, calendars, or drive objects are transferred:
- Payload chunks are streamed directly from Source API to Destination API in volatile RAM buffers.
- No customer payload content is written to hard disks, relational databases, or persistent staging volumes.
- Upon job completion or termination, all ephemeral transfer buffers are purged instantly.
4RIGHTS OF DATA PRINCIPALS (SECTIONS 11-14 DPDPA)
As a Data Principal under Indian Law, you are entitled to exercise the following statutory rights directly via our Privacy Portal or by contacting our Grievance Officer:
Right to Access (Sec 11)
Obtain a summary of personal data processed and identities of processors with whom data has been shared.
Right to Correction & Erasure (Sec 12)
Request correction of inaccurate data, completion of incomplete data, or erasure of personal data.
Right to Grievance Redressal (Sec 13)
Readily available grievance redressal mechanism with resolution within statutory timeframes.
Right to Nominate (Sec 14)
Nominate any other individual to exercise your rights in the event of death or incapacity.
5CYBERSECURITY & CERT-In MANDATORY LOG RETENTION
In compliance with the Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000 issued by the Indian Computer Emergency Response Team (CERT-In), Pinsoftek securely maintains ICT system logs within the Indian jurisdiction for a rolling statutory period of 180 days to facilitate incident reporting and forensic validation.
Data Protection Officer & Inquiries
For any privacy inquiries, consent withdrawal requests, or to exercise your rights under the DPDP Act 2023, please reach out to our appointed Data Protection Officer: