Data Protection & Privacy Policy · Webczar Solutions

Privacy Policy

How Webczar Solutions collects, manages, encrypts, and safeguards your personal data, business assets, and usage telemetry across our websites, applications, and client engagements.

📅Updated: October 3, 2026
⏱️7 min read
⚖️Version v2.4 Global
📍Jurisdiction: India & Global
🏢Webczar Solutions
Executive Summary (TL;DR)Plain English Overview

Zero Data Sale Guarantee

We never sell, rent, monetize, or trade your personal information, corporate telemetry, or contact records to data brokers or third parties.

Enterprise Grade Encryption

All client transmissions and internal databases are secured with modern TLS 1.3 encryption in transit and AES-256 protocols at rest.

Global Legal Compliance

Architected to adhere strictly to India's DPDPA (2023), the European Union's GDPR, and the California Consumer Privacy Act (CCPA).

You Retain Full Control

Exercise your fundamental rights to access, inspect, modify, transfer, or permanently expunge your personal records at any time.

01

Scope, Commitment & Data Controller Identification

Webczar Solutions ("Webczar", "Company", "we", "us", or "our"), led by Founder & Technology Director Subhadeep Chanda, respects your fundamental privacy rights and is dedicated to preserving the confidentiality of personal and business data entrusted to us.

This comprehensive Privacy Policy ("Policy") delineates how we collect, store, process, transmit, and protect data when you visit our website (https://webczarsolutions.com), engage our engineering and marketing services, communicate via email or WhatsApp, or utilize any digital software solutions developed by us.

Under applicable privacy frameworks—including the Indian Digital Personal Data Protection Act, 2023 (DPDPA), the General Data Protection Regulation (EU GDPR), and the UK GDPR—Webczar Solutions operates as the Data Fiduciary / Data Controller for personal data gathered directly via our digital properties and sales channels.

💡Client Codebases & Data Ownership

When building custom software for clients, Webczar operates strictly as a Data Processor. The client remains the sole Data Controller of their end-users' application databases.

02

Categories of Information We Collect

We collect personal and technical data to deliver exceptional digital solutions, ensure platform security, and maintain transparent business communications. The data categories we collect include:

  • Direct Contact & Identity Details: Full name, business email address, phone number, physical corporate address, job title, and organization name submitted via contact forms, inquiries, or project briefs.
  • Billing & Commercial Records: Tax identification numbers (GST/PAN/VAT), billing addresses, payment transaction references, and invoicing records. (Note: sensitive credit/debit card numbers are processed directly by certified PCI-DSS compliant payment gateways and are never stored on Webczar servers).
  • Client Project Assets & Credentials: Wireframes, brand guidelines, API access tokens, code repositories, staging server credentials, and proprietary content shared under confidentiality for project development.
  • Telemetry & Device Data: Internet Protocol (IP) addresses, browser type, operating system, device hardware profiles, referring URLs, pages visited, session duration, and clickstream interactions.
  • Direct Communications: Transcripts, messages, and attachment history received through email exchanges, WhatsApp Business conversations, video conferences, or phone inquiries.
03

Methods & Sources of Data Collection

We obtain data through three primary mechanisms:

1. Direct Voluntary Submissions: When you fill out an inquiry form on our website, subscribe to our technical newsletter, request a project proposal, schedule a consultation call, or message us via WhatsApp or email.

2. Automated Digital Telemetry: When you browse our website, our server logs and analytics engines automatically log standard access telemetry, including timestamps, page performance metrics, and device diagnostics.

3. Authorized Third-Party Partners: In corporate engagements, we may receive professional business data from professional networking networks (such as LinkedIn), public business registries, or mutual referral partners.

Collection ChannelData CollectedPrimary Business Purpose
Contact & Proposal FormsName, Email, Phone, Project BriefPreparing quotes, consulting, replying to inquiries
Newsletter SubscriptionEmail AddressDelivering technical and business insights (opt-out anytime)
WhatsApp / Direct ChatPhone number, Chat logsDirect client communication and sales support
Website TelemetryIP address, Device profile, PageviewsOptimizing UI/UX, debugging, security threat prevention
04

Legal Basis & Business Purposes for Data Processing

We only process personal information where a valid legal basis exists under applicable data protection laws. Our processing operations are anchored upon:

Contractual Necessity: To evaluate project requirements, draft formal proposals, execute Statements of Work, build bespoke software, and fulfill contractual obligations.

Legitimate Business Interests: To protect our digital infrastructure from cyber threats, diagnose technical defects, refine our user experience, and analyze engagement trends.

Explicit Consent: Where you have granted unambiguous affirmative consent, such as opting into our newsletter or consenting to marketing communications.

Statutory Compliance: To maintain accurate financial books, comply with tax laws (GST/income tax), and satisfy lawful regulatory or judicial directives.

07

Data Sharing, Sub-Processors & Third-Party Disclosures

Webczar Solutions adheres to a strict non-monetization policy: We DO NOT sell, lease, trade, or monetize your personal or business data under any circumstances.

We only share limited necessary data with vetted third-party infrastructure providers ("Sub-Processors") who operate under strict Data Processing Agreements (DPAs) and confidentiality covenants. These providers include:

  • Cloud Hosting & Edge Infrastructure: Vercel Inc., Amazon Web Services (AWS), and Google Cloud Platform for hosting web applications and secure data repositories.
  • Communication & Email Infrastructure: Google Workspace, Resend, or SendGrid for sending transactional project notifications and client correspondence.
  • Analytics & Performance Monitoring: Google Analytics (with IP anonymization) and Vercel Analytics for tracking aggregated website telemetry.
  • Compliance & Legal Authorities: We will only disclose personal data to regulatory or law enforcement bodies if mandated by a formal subpoena, court order, or binding statutory obligation.
08

International & Cross-Border Data Transfers

Webczar Solutions serves clients across India, North America, Europe, the Middle East, and the Asia-Pacific region. Consequently, data may be transferred to and maintained on cloud servers situated outside your home country or jurisdiction.

Whenever we transfer personal data across international borders, we ensure adequate protective mechanisms are deployed in compliance with applicable law, including Standard Contractual Clauses (SCCs) approved by the European Commission, robust data encryption standards, and adherence to equivalent data security protocols.

09

Information Security Protocols & Storage Architecture

We implement rigorous technical, operational, and organizational security measures to protect your data against unauthorized access, loss, alteration, or disclosure:

  • Transport Layer Security (TLS 1.3 / SSL): All traffic to and from our web properties is encrypted using industry-standard TLS protocols.
  • AES-256 Storage Encryption: Sensitive project files, databases, and credentials stored within our internal environments are encrypted at rest using AES-256 encryption.
  • Role-Based Access Control (RBAC): Engineering access to client repositories and infrastructure credentials is strictly restricted to designated developers assigned to that project.
  • Routine Vulnerability Assessments: We perform ongoing dependency audits, automated vulnerability scanning, and code reviews prior to production releases.
⚠️Transmission Advisory

While we employ cutting-edge industry safeguards, no method of digital transmission over the internet is 100% impenetrable. We advise clients to transmit sensitive credentials exclusively via encrypted password managers.

10

Data Retention Schedule & Erasure Standards

We retain personal data only for as long as necessary to fulfill the commercial purposes for which it was gathered, satisfy legal obligations, or resolve commercial disputes.

Inquiry Data: General inquiries and contact submissions are maintained for a maximum of 24 months, after which they are systematically purged.

Active Project Records: Client project source code, correspondence, and technical specifications are retained during the active contract and for a standard archive period of 36 months to assist with subsequent maintenance or upgrades, unless an earlier purge is requested by the Client.

Financial & Invoicing Ledgers: Invoicing and accounting records are maintained for seven (7) years in accordance with statutory Indian taxation and corporate compliance mandates.

11

Your Data Protection Rights (GDPR, CCPA & Indian DPDPA)

Depending on your geographical location and applicable laws, you hold fundamental rights regarding your personal information:

  • Right of Access & Confirmation: You have the right to request a formal copy of the personal data we hold about you and verify our processing activities.
  • Right to Rectification: You may request the correction of any incomplete, inaccurate, or outdated personal data.
  • Right to Erasure ("Right to Be Forgotten"): You have the right to request the permanent deletion of your personal records, subject to statutory retention obligations.
  • Right to Restrict or Object to Processing: You can object to specific data processing operations, including direct marketing communications.
  • Right to Data Portability: You may request that your personal data be delivered in a structured, machine-readable format for transfer to another service provider.
  • Right to Withdraw Consent: Where processing relies on your consent, you may revoke that consent at any time without affecting the lawfulness of prior processing.
12

Children's Privacy Protection

Our digital platforms, consulting services, and software solutions are strictly targeted at businesses, commercial enterprises, and adults aged 18 and older.

We do not knowingly collect, solicit, or store personal information from individuals under the age of 18. If we discover that a minor has provided us with personal data without verified parental consent, we will take immediate steps to permanently delete such information from our records.

13

Policy Revisions & Transparency Updates

Webczar Solutions reserves the right to periodically update this Privacy Policy to reflect evolving industry practices, technology advancements, or regulatory modifications.

Whenever material changes occur, we will update the "Last Updated" timestamp at the top of this document. For significant updates impacting client data rights, we will provide prominent notice on our website or notify active clients directly via email.

We encourage you to review this page periodically to stay informed about our data safeguarding measures.

14

Grievance Officer & Official Privacy Contact

In accordance with the Indian Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, as well as global GDPR provisions, our designated Grievance & Data Protection Officer is:

  • Data Protection Officer: Subhadeep Chanda
  • Role: Founder & Technology Director, Webczar Solutions
  • Official Email: info@webczarsolutions.com / subhadeep@webczarsolutions.com
  • Direct Phone / WhatsApp: +91 99882 21729
  • Headquarters: Chandigarh · Mohali · Panchkula · Zirakpur (Tricity), Punjab / Haryana, India
  • Response Timetable: We acknowledge all privacy inquiries within 48 hours and provide substantive resolution within 15 business days.
TRANSPARENCY & TRUST

Questions about our terms or data privacy?

Our leadership team is available to discuss custom enterprise Master Services Agreements (MSA), Non-Disclosure Agreements (NDA), or specific regulatory compliance needs.