01Who we are and how to reach us
Shasam Technologies is a software product engineering company based in Chennai, Tamil Nadu, India. We build SaaS platforms, mobile applications, and internal systems for other organizations, and we develop our own products.
For the information described in this policy, Shasam Technologies is the Data Fiduciary - the term the Digital Personal Data Protection Act, 2023 uses for the party that decides why and how personal data is handled. In jurisdictions that use different language, this is the role usually called the controller.
- Privacy and data-rights contact: support@shasamtechnologies.com
- General and commercial contact: contact@shasamtechnologies.com
- Place of business: Chennai, Tamil Nadu, India
02The two roles we play, and why the difference matters to you
Almost every question about our handling of personal data has a different answer depending on which of two roles we are in at the time. This is the most important section of this policy.
As a Data Fiduciary, for our own information
When you visit this website, send us an enquiry, apply for a job, or deal with us as a supplier, we decide what happens to that information. This policy governs it in full, and the rights described in Your rights are exercised directly against us.
As a Data Processor, for our clients' information
When we build or operate a system for a client, that system may hold personal data about the client's own customers, staff, or suppliers. We handle that data only on the client's documented instructions, under a written contract. We do not decide what is collected, why, or how long it is kept, and we never use it for our own purposes.
If you are a customer or employee of one of our clients and want to see, correct, or delete your data, the organization you deal with is the Data Fiduciary and holds that decision - not us. Ask them. If you contact us instead, we will not act on the request ourselves, because we have no authority to; we will pass it to the client and tell you we have done so.
03What this website collects
This site is deliberately plain. It runs no analytics, no advertising tags, no tracking pixels, and no third-party trackers of any kind, and it sets no cookies. There is no cookie banner because there is nothing to consent to.
| What | When | Where it goes |
|---|---|---|
| Name, email address, enquiry topic, and message | Only when you submit the contact form | Emailed to our team mailbox. Not written to any database. |
| Email address, optional phone or reference, request type, and details | Only when you submit a data request | Emailed to the privacy mailbox. Not written to any database. |
| A timestamp recording that you dismissed the policy notice | When you acknowledge the notice | Stays in your own browser's local storage. Never sent to us. |
| IP address | On form submission only | Held in server memory to cap submissions per address, then discarded. Not stored, not written to disk, not used to identify you. |
| Standard server and security logs kept by our hosting provider | On every request, as with any website | Retained briefly by that provider for security and reliability. See Who else sees it. |
We do not collect special or sensitive categories of personal data through this website, and we ask you not to send them to us in a form or an email. If you send more than we need, we keep only what is relevant and delete the rest.
04Information we handle away from the website
Business correspondence and prospective clients
Names, roles, contact details, and the substance of discussions with people at organizations we work with or might work with. Used to respond, to scope work, and to keep a record of what was agreed.
Clients and their teams
Contact and access details for the people we work with day to day, plus records of the work performed. Where we hold administrative access to a client system, that access is logged.
Job applicants
Whatever you send when you apply: your CV, work history, links to things you have built, and our notes from any conversation or exercise. Used only to assess that application. We do not run automated screening or automated decision-making on applications.
Suppliers and contractors
Contact details, contractual terms, and the payment information needed to engage and pay them.
05Why we use it, and on what basis
Under the DPDP Act, 2023 personal data is processed either with your consent or for a legitimate use the Act specifically permits. Nothing here is used for advertising or profiling. We do not sell or rent personal data to anyone, in any circumstances.
| Purpose | Basis |
|---|---|
| Replying to an enquiry you sent us | Your consent, given by voluntarily submitting the form - you asked us to reply. |
| Scoping, quoting, delivering, and supporting work | Performance of a contract, or steps taken at your request before entering one. |
| Assessing a job application | Your consent, given by applying, and steps taken at your request before employment. |
| Keeping accounting, tax, and statutory records | Compliance with law - a legitimate use under the Act. |
| Preventing abuse of our forms and protecting our systems | Legitimate use: maintaining the security and integrity of our services. |
| Establishing, exercising, or defending a legal claim | Compliance with law and enforcement of legal rights. |
Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it: write to support@shasamtechnologies.com and say so. Withdrawal does not undo anything lawfully done beforehand, and it may mean we can no longer continue a conversation you started.
07How we protect it
These are the same controls we build into client systems, applied to our own. They are engineering decisions rather than policy statements:
- Access rules are enforced at the data layer, not merely hidden in an interface, so a direct request cannot reach what a screen conceals.
- Sensitive files are stored privately and are never publicly addressable; access is granted through short-lived signed links rather than permanent URLs.
- Sensitive actions are logged with who performed them and when, in a durable record.
- Administrative access requires multi-factor authentication and is limited to the few people who need it.
- Data is encrypted in transit, and at rest by our infrastructure providers.
- Access to a client's production data is exceptional, taken only when needed to operate or support the system, and the client is told.
No system is perfectly secure and we will not claim otherwise. If a personal-data breach occurs we will notify the Data Protection Board of India and every affected person as the DPDP Act requires, and we aim to notify affected people within 72 hours of confirming it. Where a breach concerns a client system we operate, we notify the client without undue delay so they can meet their own obligations.
08How long we keep it
We keep personal data only while it serves the purpose it was collected for, then delete or anonymise it. Some records carry a statutory minimum we cannot shorten - tax and accounting records in particular.
Every category, its period, and the reason for it are set out in the Data Retention and Deletion Policy.
09Your rights, and how to use them
As a Data Principal under the DPDP Act, 2023 you have the right to:
- Access - a summary of the personal data we hold about you and how we are processing it.
- Correction and completion - to have inaccurate or misleading data corrected, and incomplete data completed.
- Erasure - to have your data deleted, unless the law requires us to keep it.
- Grievance redressal - a readily available means of complaining to us, described in the final section.
- Nomination - to nominate someone to exercise these rights for you if you die or become incapacitated.
Ask through the Manage my data page, or write to support@shasamtechnologies.com. We respond substantively within 30 days, free of charge.
We will ask you to verify your identity before acting, because handing someone else's data to the wrong person is itself a breach. We ask for the minimum needed to be confident, and we do not keep verification material beyond the life of the request.
The Act also asks Data Principals to give accurate information and not to file false or frivolous requests. If your request concerns data we hold as a processor for a client, see The two roles we play.
10Children
This website is intended for a business audience and is not directed at children. We do not knowingly collect the personal data of anyone under 18, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children - all of which the DPDP Act prohibits.
If you believe a child has given us personal data, write to support@shasamtechnologies.com and we will delete it.
11Changes to this policy
We update this policy when our practices, our products, or the law change. Every version carries a version number and an effective date at the top of the page. Where a change materially affects your rights we will give notice prominently on this website, and directly where we hold a contact address for you and the change warrants it.
This is version 2.0, effective 26 July 2026. It replaces all earlier versions.
12Grievances and how to reach a person
If anything in this document, or anything we have done with your information, is not right, raise it with our Grievance Officer. You do not need to use any particular form of words.
- Grievance Officer: Peter Yogaesh J
- Email: support@shasamtechnologies.com
- Address: Chennai, Tamil Nadu, India
We acknowledge grievances within 48 hours and aim to resolve them within 15 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
If you are not satisfied with our response on a personal-data matter, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023. Approaching us first is not a precondition, but it is usually faster.