Privacy Policy

DataDack Cloud

Effective Date: July 10, 2026 · Last updated: July 10, 2026

DataDack, a sole proprietorship firm based in India ("DataDack", "we", "us", or "our"), operates DataDack Cloud, an infrastructure-as-a-service (IaaS) platform providing virtual machines, networking, storage, and related cloud services. This Privacy Policy explains, in plain language, what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have — in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the rules made under it, and other applicable law.

We do not sell your personal data to anyone.

Because we allocate public IP addresses from our own pool rather than reselling another provider's, Indian law places specific verification and record-keeping obligations on us. Those obligations shape Sections 2.2, 6 and 7 below, and are set out in full on our Identity Verification & KYC page.

1. Who This Policy Covers

This policy applies to you as an account holder, to the IAM users and team members you authorise, to visitors to our website and console, and to anyone who visits our data-centre facility. Where you use DataDack Cloud to process personal data belonging to your own users, you are the Data Fiduciary for that data and we act as your Data Processor under Section 12 of this policy.

2. Personal Data We Collect

2.1 Information You Provide Directly

  • Account & Organization Information: Name, email address, phone number, organization name, billing address, and — for business accounts — company registration and tax details.
  • Billing Information: Billing address and tax identifiers. Payment instrument details are entered directly with our PCI-DSS compliant payment gateway; full card numbers, CVV and bank credentials are never stored on our systems.
  • Unique Identifiers & Credentials: Username, account number, and password. Passwords are stored only as salted hashes. Neither we nor our staff can read your password, and no member of our staff will ever ask you for it.
  • Support & Communication Data: Support ticket content, email correspondence, live-chat transcripts, WhatsApp messages, and call recordings where a call is recorded for quality assurance — in which case you are told at the start of the call.
  • Data-Centre Visit Information: For a physical visit to our facility, the name, contact details and government-ID particulars required for building access, together with entry and exit timestamps and CCTV footage of common areas.

2.2 Identity Verification (KYC) Data

Where a public IP address is allocated to your account, or verification is otherwise triggered, we collect government-issued identity and address documents, entity registration documents (Certificate of Incorporation, PAN, GSTIN), authorised-signatory details, beneficial-ownership declarations, and a liveness capture. We accept only masked Aadhaar or offline e-KYC XML and do not request or store the full 12-digit Aadhaar number.

2.3 Information Collected Automatically

  • Operational & Technical Data: IP addresses, API request logs, console session data, browser type, operating system, device information, and referring and exit pages.
  • Resource Metadata: Configuration of the resources you provision — virtual machines, VPCs, subnets, static IPs, images, resource groups, and tags.
  • Monitoring Data: Uptime, resource utilization (CPU, memory, storage, network), diagnostic logs, and security-event logs generated by our network operations centre to detect abuse, DDoS activity and service faults.
  • Cookies and Similar Technologies: Including web beacons (single-pixel images) used with cookies to compile aggregate statistics about how our website, console and emails are used. See our Cookie Policy.

2.4 Information From Third Parties

  • Payment gateway providers, who return transaction status, payment confirmation, and limited metadata such as the last four digits of a card.
  • Identity-verification providers acting as our processors.
  • Authorised resellers and partners, where you sign up through one.

2.5 Information You Provide About Others

If you supply personal data about another person — for example, when creating an IAM user, adding a billing contact, or nominating an authorised signatory — we use that data only for the specific purpose for which you provided it. You are responsible for having a lawful basis to share it with us and for informing that person.

2.6 Customer Content

Data you store on or transmit through your virtual machines, volumes and other resources. We treat Customer Content as confidential. We do not inspect, index, mine or access the contents of your instances except where strictly necessary to operate or restore the service at your request, to respond to a security incident, or where required by law.

2.7 Sensitive Personal Data

Passwords, financial information and identity documents are treated as sensitive personal data or information under the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and are handled under the reasonable security practices described in Section 8.

3. Consent and Legal Basis

We process your personal data for the specific purpose you were notified of at the time of collection, on the basis of your clear, affirmative consent — except where the DPDP Act permits processing without consent, such as to perform a contract you have asked us to perform, to comply with a legal obligation, or for a legitimate use recognised under the Act.

  • Consent requests are presented separately for each purpose — service communication and marketing communication are never bundled together.
  • You may withdraw consent at any time, as easily as you gave it, from Account → Privacy in the console or by emailing privacy@datadack.com.
  • Withdrawal does not affect the lawfulness of processing carried out before it, and may limit or prevent our ability to continue providing some or all of the Services.
  • Where a statutory retention obligation under Section 7 applies, withdrawal of consent does not remove our duty to retain those records.

4. How We Use Your Data

  • Provision, operate, monitor, and secure your cloud resources.
  • Verify your identity before allocating a public IP address, raising a public-IP quota, or enabling outbound mail, and maintain the customer register Indian law requires of a cloud and data-centre operator.
  • Meter usage, calculate consumption charges, process payments, and generate invoices.
  • Provide technical support and respond to support tickets and NOC escalations.
  • Detect, prevent, and investigate abuse, fraud, and security incidents — including attributing reported abuse from an IP address in our range to the account responsible for it.
  • Send mandatory service notices — maintenance windows, security alerts, balance and renewal reminders, and notices under our Service Level Agreement — by email, SMS or WhatsApp. These are not marketing and cannot be opted out of while your account is active.
  • Send marketing communication only where you have opted in, and only until you opt out.
  • Manage physical access and security at our data-centre facility.
  • Comply with legal, tax, and regulatory obligations.

We do not use your verification documents, Customer Content, or support conversations for marketing, profiling, behavioural advertising, credit scoring, or the training of any machine-learning model.

5. Automated Processing

We use automated checks for fraud scoring, abuse detection, document validation and liveness matching during verification. Where an automated check would result in a refusal, a quota restriction, or a suspension, a trained reviewer examines the case before the decision takes effect, and you may contest the outcome by writing to privacy@datadack.com.

6. Sharing Your Data

We do not sell your personal data. We share it only with:

  • Our Billing Entity: HRIDYANSH SAVINU ENTERPRISES (GSTIN 03GDFPM1564R1Z2), which presently issues invoices and collects payments for the Services, receives your billing contact details, tax identifiers and transaction records — and nothing more. It does not receive Customer Content, resource configuration, support conversations or verification documents. See Section 1 of the Billing & Credits Terms.
  • Infrastructure & Service Providers: Data-centre operators, network and transit partners, payment processors, identity-verification providers, and communication vendors — each bound by contract to use the data only to provide the service to us, under confidentiality obligations, and as our processors.
  • Compliance with Law: With CERT-In, a regulator, a court, or a law-enforcement agency acting under lawful process, and where disclosure is necessary in good faith to protect our rights, investigate fraud, or protect the safety of our users or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to notice to you and to the acquirer being bound by this policy.

Verification documents, Customer Content, and the IP allotment register are never disclosed to other customers or to commercial third parties. A current list of sub-processors is available on request to privacy@datadack.com.

7. Data Retention

We keep personal data only as long as necessary for the purpose it was collected, or as required by law. Certain records are held on periods fixed by regulation rather than by preference:

  • Verification documents and KYC records: five years from the end of the hire or closure of the account, whichever is later, in line with CERT-In Direction No. 20(3)/2022.
  • IP allotment records — which address was held by which account, and when: five years after the address is released back into our pool.
  • System and network logs: a rolling 180 days, maintained securely within Indian jurisdiction, then purged.
  • Support tickets and chat transcripts: retained for a limited period for quality and dispute-resolution purposes, then deleted or anonymised.
  • Data-centre visitor logs and access records: retained for facility security and audit purposes, then purged.
  • Billing, invoice and tax records: for the period required by Indian tax and accounting law, independently of the above.
  • Customer Content: until you delete the resource or terminate your account, subject to short-term backup and log-retention windows.

While a statutory retention period is running we cannot delete the records it covers, even at your request. During that period they are held solely to meet the obligation and are used for nothing else. Your other rights under Section 10 continue to apply.

8. Security

We implement reasonable technical and organizational safeguards to protect your data, including per-account network isolation (VPCs), encryption in transit, encryption of verification documents at rest, salted password hashing, strict need-to-know access controls with audit logging, and continuous monitoring. You remain responsible for securing the operating systems, applications, credentials, and data within your own resources under the shared responsibility model.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. What we can guarantee is that we will never ask you for your card PIN, CVV, net-banking password, one-time passcode, SSH private key, or account password. No member of our staff has any legitimate reason to request these.

8.1 Physical Security

Our Noida facility uses restricted access control, visitor logging, escorted access and surveillance systems to protect physical infrastructure and any personal data collected during a facility visit. Visitor and access data is used strictly for security and audit purposes.

8.2 Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected user as required under Section 8(6) of the DPDP Act. Separately, cyber security incidents of the classes specified by CERT-In are reported to CERT-In within six hours of being noticed, as required by Direction No. 20(3)/2022.

9. Data Location & Cross-Border Transfers

All customer resources, Customer Content, verification documents and system logs are stored and processed exclusively within India, at our Noida region. There is no cross-border replication by default. Limited account and billing metadata may be processed by service providers operating elsewhere; any such transfer complies with Section 16 of the DPDP Act and is never made to a country restricted by the Central Government. See our Compliance page for our full residency posture.

10. Your Rights

Under the DPDP Act and, where applicable, other data protection law, you may:

  • Access a summary of the personal data we hold about you and how it is processed.
  • Correct data that is inaccurate, incomplete or out of date, and update it directly in the console.
  • Erase your personal data once it is no longer needed for the purpose it was collected — except where a statutory retention period under Section 7 still applies.
  • Withdraw consent for any purpose you previously consented to.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Raise a grievance about how your data has been handled.

Most account data can be reviewed and updated directly in the console. To exercise any other right, email privacy@datadack.com with the subject line "Data Rights Request". We respond within 30 days.

11. Marketing Communications

We send marketing email only where you have opted in. You can opt out at any time from the unsubscribe link in any marketing message, from Account → Notifications in the console, or by emailing privacy@datadack.com. Opting out of marketing does not stop transactional and service notices described in Section 4, which are necessary to operate your account.

12. Business Customers and Data Processing

Where you use DataDack Cloud to process personal data of your own users, you are the Data Fiduciary (or Controller) and DataDack acts as your Data Processor: we process that data only on your documented instructions, apply the safeguards in Section 8, assist you with data-principal requests and breach notification, and delete or return the data on termination. A Data Processing Agreement is available on request to privacy@datadack.com.

13. Users in the European Economic Area and United Kingdom

Where the GDPR or UK GDPR applies to your use of the Services, you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your local supervisory authority. Our default posture of processing exclusively within India means we do not transfer EEA or UK personal data out of the region you selected without an appropriate transfer mechanism. Contact privacy@datadack.com to exercise these rights or to request our standard contractual clauses.

14. Third-Party Websites and Services

Our website, console and documentation contain links to third-party sites, marketplace images, and integrations whose privacy practices differ from ours. Cookies set by our analytics providers, partners and affiliates are not covered by this policy and are outside our control. If you submit personal data to a third-party site, that site's privacy statement governs it. We encourage you to read it.

15. Children's Data

DataDack Cloud is intended for businesses and for individuals aged 18 and above. We do not knowingly collect the personal data of children, and we do not process children's data for tracking, behavioural monitoring, or targeted advertising.

16. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or in the law. Where a change is material, we will notify you by email to the address on your account, or by a notice in the console or on this page, before the change takes effect. The "Last updated" date at the top reflects the latest revision.

17. Grievance Redressal

  • Designation: DataDack Cloud Grievance Officer
  • Email: privacy@datadack.com (subject line: "Grievance")
  • Postal address: DataDack, 2841 Sector-22C, Chandigarh 160022, India
  • Timelines: acknowledgement within 7 days; substantive response within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India as provided under the DPDP Act.

18. Contact Us

DataDack
2841 Sector-22C, Chandigarh 160022, India
Phone: +91 87080 45050

  • Privacy and data rights: privacy@datadack.com
  • General and technical support: support@datadack.com
  • Billing: billing@datadack.com
  • Identity verification: verification@datadack.com
  • Abuse reports: abuse@datadack.com