Privacy

Privacy Policy

What personal data we handle, why, and the rights you have over it.

Version
2.0
Effective
26 July 2026
Applies to
This website, our business correspondence, and hiring
Scope

This is a general, company-level document. It covers this website and the way Shasam Technologies handles information as a company. No Shasam Technologies product is currently available to the public, so nothing here describes a consumer app. When a product ships it will publish its own notice, which will add to this document and override it only where it says so explicitly.

Trackers on this site
None. No analytics, no advertising tags, no cookies.
Sale of personal data
Never, to anyone, in any circumstances.
Client data
Handled only on the client’s instructions, under contract.
Rights request
Answered within 30 days, free of charge.

01Who we are and how to reach us

Shasam Technologies is a software product engineering company based in Chennai, Tamil Nadu, India. We build SaaS platforms, mobile applications, and internal systems for other organizations, and we develop our own products.

For the information described in this policy, Shasam Technologies is the Data Fiduciary - the term the Digital Personal Data Protection Act, 2023 uses for the party that decides why and how personal data is handled. In jurisdictions that use different language, this is the role usually called the controller.

02The two roles we play, and why the difference matters to you

Almost every question about our handling of personal data has a different answer depending on which of two roles we are in at the time. This is the most important section of this policy.

As a Data Fiduciary, for our own information

When you visit this website, send us an enquiry, apply for a job, or deal with us as a supplier, we decide what happens to that information. This policy governs it in full, and the rights described in Your rights are exercised directly against us.

As a Data Processor, for our clients' information

When we build or operate a system for a client, that system may hold personal data about the client's own customers, staff, or suppliers. We handle that data only on the client's documented instructions, under a written contract. We do not decide what is collected, why, or how long it is kept, and we never use it for our own purposes.

If you are a customer or employee of one of our clients and want to see, correct, or delete your data, the organization you deal with is the Data Fiduciary and holds that decision - not us. Ask them. If you contact us instead, we will not act on the request ourselves, because we have no authority to; we will pass it to the client and tell you we have done so.

03What this website collects

This site is deliberately plain. It runs no analytics, no advertising tags, no tracking pixels, and no third-party trackers of any kind, and it sets no cookies. There is no cookie banner because there is nothing to consent to.

WhatWhenWhere it goes
Name, email address, enquiry topic, and messageOnly when you submit the contact formEmailed to our team mailbox. Not written to any database.
Email address, optional phone or reference, request type, and detailsOnly when you submit a data requestEmailed to the privacy mailbox. Not written to any database.
A timestamp recording that you dismissed the policy noticeWhen you acknowledge the noticeStays in your own browser's local storage. Never sent to us.
IP addressOn form submission onlyHeld in server memory to cap submissions per address, then discarded. Not stored, not written to disk, not used to identify you.
Standard server and security logs kept by our hosting providerOn every request, as with any websiteRetained briefly by that provider for security and reliability. See Who else sees it.

We do not collect special or sensitive categories of personal data through this website, and we ask you not to send them to us in a form or an email. If you send more than we need, we keep only what is relevant and delete the rest.

04Information we handle away from the website

Business correspondence and prospective clients

Names, roles, contact details, and the substance of discussions with people at organizations we work with or might work with. Used to respond, to scope work, and to keep a record of what was agreed.

Clients and their teams

Contact and access details for the people we work with day to day, plus records of the work performed. Where we hold administrative access to a client system, that access is logged.

Job applicants

Whatever you send when you apply: your CV, work history, links to things you have built, and our notes from any conversation or exercise. Used only to assess that application. We do not run automated screening or automated decision-making on applications.

Suppliers and contractors

Contact details, contractual terms, and the payment information needed to engage and pay them.

05Why we use it, and on what basis

Under the DPDP Act, 2023 personal data is processed either with your consent or for a legitimate use the Act specifically permits. Nothing here is used for advertising or profiling. We do not sell or rent personal data to anyone, in any circumstances.

PurposeBasis
Replying to an enquiry you sent usYour consent, given by voluntarily submitting the form - you asked us to reply.
Scoping, quoting, delivering, and supporting workPerformance of a contract, or steps taken at your request before entering one.
Assessing a job applicationYour consent, given by applying, and steps taken at your request before employment.
Keeping accounting, tax, and statutory recordsCompliance with law - a legitimate use under the Act.
Preventing abuse of our forms and protecting our systemsLegitimate use: maintaining the security and integrity of our services.
Establishing, exercising, or defending a legal claimCompliance with law and enforcement of legal rights.

Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it: write to support@shasamtechnologies.com and say so. Withdrawal does not undo anything lawfully done beforehand, and it may mean we can no longer continue a conversation you started.

06Who else sees it

We share personal data only with service providers who help us operate, only to the extent they need it, and only under contracts that require them to protect it and use it for nothing else.

ProviderWhat it does for usWhat it sees
ResendDelivers the emails this website's forms generateThe contents of the form you submitted, including your email address
Our hosting and content-delivery providerServes this websiteRequest metadata including IP address, in standard server logs
Our email and office software providerRuns our mailboxes and internal documentsCorrespondence you send us
Cloud infrastructure providersHost the systems we build and operateData held in those systems, under the relevant client contract

We may also disclose personal data where the law requires it, where it is necessary to establish or defend a legal claim, or to a successor if the business or part of it is transferred. In a business transfer the recipient remains bound by this policy until it publishes its own and gives you notice.

Some providers operate outside India, so your data may be processed abroad. We use providers offering contractual protections consistent with Indian law, and we do not transfer personal data to any territory restricted by the Central Government under section 16 of the DPDP Act.

07How we protect it

These are the same controls we build into client systems, applied to our own. They are engineering decisions rather than policy statements:

  • Access rules are enforced at the data layer, not merely hidden in an interface, so a direct request cannot reach what a screen conceals.
  • Sensitive files are stored privately and are never publicly addressable; access is granted through short-lived signed links rather than permanent URLs.
  • Sensitive actions are logged with who performed them and when, in a durable record.
  • Administrative access requires multi-factor authentication and is limited to the few people who need it.
  • Data is encrypted in transit, and at rest by our infrastructure providers.
  • Access to a client's production data is exceptional, taken only when needed to operate or support the system, and the client is told.

No system is perfectly secure and we will not claim otherwise. If a personal-data breach occurs we will notify the Data Protection Board of India and every affected person as the DPDP Act requires, and we aim to notify affected people within 72 hours of confirming it. Where a breach concerns a client system we operate, we notify the client without undue delay so they can meet their own obligations.

08How long we keep it

We keep personal data only while it serves the purpose it was collected for, then delete or anonymise it. Some records carry a statutory minimum we cannot shorten - tax and accounting records in particular.

Every category, its period, and the reason for it are set out in the Data Retention and Deletion Policy.

09Your rights, and how to use them

As a Data Principal under the DPDP Act, 2023 you have the right to:

  • Access - a summary of the personal data we hold about you and how we are processing it.
  • Correction and completion - to have inaccurate or misleading data corrected, and incomplete data completed.
  • Erasure - to have your data deleted, unless the law requires us to keep it.
  • Grievance redressal - a readily available means of complaining to us, described in the final section.
  • Nomination - to nominate someone to exercise these rights for you if you die or become incapacitated.

Ask through the Manage my data page, or write to support@shasamtechnologies.com. We respond substantively within 30 days, free of charge.

We will ask you to verify your identity before acting, because handing someone else's data to the wrong person is itself a breach. We ask for the minimum needed to be confident, and we do not keep verification material beyond the life of the request.

The Act also asks Data Principals to give accurate information and not to file false or frivolous requests. If your request concerns data we hold as a processor for a client, see The two roles we play.

10Children

This website is intended for a business audience and is not directed at children. We do not knowingly collect the personal data of anyone under 18, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children - all of which the DPDP Act prohibits.

If you believe a child has given us personal data, write to support@shasamtechnologies.com and we will delete it.

11Changes to this policy

We update this policy when our practices, our products, or the law change. Every version carries a version number and an effective date at the top of the page. Where a change materially affects your rights we will give notice prominently on this website, and directly where we hold a contact address for you and the change warrants it.

This is version 2.0, effective 26 July 2026. It replaces all earlier versions.

12Grievances and how to reach a person

If anything in this document, or anything we have done with your information, is not right, raise it with our Grievance Officer. You do not need to use any particular form of words.

We acknowledge grievances within 48 hours and aim to resolve them within 15 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

If you are not satisfied with our response on a personal-data matter, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023. Approaching us first is not a precondition, but it is usually faster.

Have a question or an idea worth moving?