+91-9822310009 , amitmuthaps@decospaacloud.com
DPDP COMPLIANCE & DATA PRIVACY
Our Commitment to Responsible Data Protection
At Decospaa Cloud Technology LLP, we recognize that personal data is valuable and must be handled responsibly.
We are committed to implementing appropriate privacy, security, governance, and data protection practices in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and other applicable data protection requirements in India.
Our objective is to ensure that personal data entrusted to us is collected, used, stored, processed, shared, and protected responsibly.
Our Approach to Data Protection
Our data protection framework is based on the following principles:
Purpose Limitation
We use personal data only for legitimate and specified business purposes.
Transparency
We aim to clearly communicate what personal data we collect, why we collect it, and how it is used.
Data Minimisation
We seek to collect only the personal data reasonably required for the intended purpose.
Security
We implement appropriate technical and organizational safeguards to protect personal data.
Accountability
We maintain processes and controls to support responsible handling of personal data.
Data Retention
We seek to retain personal data only for as long as necessary for the relevant purpose or as required by applicable law.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India's principal framework governing the processing of digital personal data.
The Act establishes obligations for organizations processing digital personal data and provides rights and duties relating to individuals whose personal data is processed.
The Government of India has also notified the Digital Personal Data Protection Rules, 2025, which provide further operational requirements and a phased commencement framework.
Personal Data We May Collect
Depending on the services or interaction involved, Decospaa may collect or process information such as:
Name
Business/organization name
Email address
Telephone/mobile number
Business address
Billing and transaction information
Account and login information
Service and support information
Website enquiry information
Communication records
Technical information required to provide our services
Information provided voluntarily through forms, emails, applications, or other communications
We do not seek to collect personal data that is unnecessary for the relevant business purpose.
Why We Process Personal Data
Personal data may be processed for legitimate business purposes, including:
Providing products and services
Managing customer and vendor relationships
Processing enquiries and requests
Preparing quotations and proposals
Billing and payment processing
Providing technical support
Managing service accounts
Communicating service updates
Improving our products and services
Maintaining security and preventing misuse
Meeting contractual, regulatory, accounting, tax, and legal obligations
Managing business operations
The specific purpose and basis for processing will depend on the nature of the relationship and the service involved.
Consent and Lawful Processing
Where consent is required under applicable law, Decospaa will seek consent through an appropriate mechanism.
Where applicable, individuals may withdraw consent through the mechanism provided by Decospaa.
Withdrawal of consent may affect our ability to provide certain services where the relevant processing is necessary for those services.
The DPDP framework recognizes consent as one of the permitted grounds for processing personal data and provides requirements relating to notice and consent management.
Subject to applicable law and the relevant circumstances, a Data Principal may have rights relating to their personal data, including:
Right to Access Information
You may request information about personal data being processed and relevant processing activities.
Right to Correction
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of personal data where applicable.
Right to Grievance Redressal
You may raise a privacy-related grievance with Decospaa.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent, subject to applicable legal and contractual requirements.
The DPDP Act provides Data Principal rights including access to information, correction and erasure, subject to the conditions and limitations specified in the Act.
Decospaa recognizes the importance of protecting personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Depending on the nature of the service and risk involved, our security practices may include:
Access controls
Role-based access management
Multi-factor authentication
Encryption
Firewall and endpoint security
Security monitoring and logging
Backup and recovery mechanisms
Vulnerability management
Security updates and patch management
Incident response procedures
Employee confidentiality obligations
Physical security controls where applicable
Security controls may vary depending on the service, infrastructure, technology environment, and risk profile.
Data Breach Management
Decospaa maintains processes for identifying, assessing, responding to, and managing personal data security incidents.
Where a personal data breach occurs, we will take appropriate steps to:
Identify and contain the incident.
Assess the nature and potential impact of the incident.
Take reasonable corrective and mitigation measures.
Maintain appropriate records.
Make applicable notifications or disclosures as required by law.
Cooperate with relevant customers, service providers, and authorities where required.
Where Decospaa processes personal data on behalf of a customer, applicable contractual obligations and the relevant Data Processing Agreement may also govern breach notification and cooperation requirements.
Customers, Vendors and Data Processors
Decospaa may work with third-party service providers, technology partners, hosting providers, cloud providers, consultants, and other vendors that may process personal data as part of providing services.
Where appropriate, we require such parties to maintain suitable confidentiality, security, and data protection obligations.
Where Decospaa processes personal data on behalf of a customer, the respective roles and responsibilities may be documented through a Data Processing Agreement (DPA) or applicable contractual terms.
Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide services, maintain business records, meet contractual obligations, resolve disputes, maintain security, or comply with applicable legal and regulatory requirements.
When personal data is no longer required, we seek to securely delete, anonymize, or otherwise dispose of it in accordance with applicable requirements and our internal processes.
Third-Party Services
Our services may involve third-party technology, cloud, payment, communication, analytics, hosting, security, or other service providers.
Where such providers process personal data, the processing may be subject to their respective contractual obligations, privacy practices, and applicable data protection requirements.
We take reasonable steps to assess and manage third-party data processing risks appropriate to the services involved.
International Data Transfers
Where personal data is processed or transferred outside India, Decospaa will take appropriate steps to comply with applicable requirements relating to such processing or transfer.
The availability and use of particular cloud or technology services may also depend on the service configuration selected by the customer.
Employee and Internal Data Protection
Data protection applies not only to customer information but also to personal data relating to employees, applicants, consultants, partners, and other individuals associated with Decospaa.
We seek to ensure that such information is accessed only by authorized personnel and used for legitimate business and employment-related purposes.
Privacy by Design
We aim to consider privacy and data protection requirements when introducing new systems, applications, services, technologies, or business processes involving personal data.
Where appropriate, we assess:
What personal data is required
Why it is required
Who can access it
How it will be protected
How long it should be retained
Whether third parties will process it
Potential privacy and security risks
Decospaa is developing and maintaining a structured data protection framework covering:
01 — Data Inventory
Identifying personal data collected, processed, stored, and shared.
02 — Data Mapping
Understanding where personal data originates, where it is stored, and with whom it is shared.
03 — Purpose & Consent
Documenting processing purposes and implementing appropriate consent mechanisms where required.
04 — Security Controls
Implementing appropriate technical and organizational safeguards.
05 — Vendor Management
Assessing and managing third-party processors and service providers.
06 — Data Retention
Establishing appropriate retention and deletion practices.
07 — Individual Rights
Establishing mechanisms to support Data Principal requests.
08 — Incident Management
Maintaining procedures for handling personal data breaches and security incidents.
09 — Governance & Training
Promoting privacy awareness, accountability, and responsible data handling.
10 — Continuous Improvement
Periodically reviewing our privacy and security practices as applicable laws, technologies, and business requirements evolve.
This webpage describes Decospaa Cloud Technology LLP’s data protection approach and privacy practices. It is intended for general information and transparency purposes and should be read together with applicable contracts, service agreements, privacy notices, Data Processing Agreements, and other relevant policies.
References to the DPDP Act, 2023 and DPDP Rules, 2025 do not constitute a certification by the Government of India or the Data Protection Board of India that Decospaa Cloud Technology LLP is “DPDP certified” or legally compliant in every respect.
The applicability and commencement of specific provisions may depend on the applicable law and notified implementation timeline. Decospaa will update its policies and practices as applicable requirements come into force.
Last Updated: 21 August 2026