Skip to content
Relicsoft
← All policies

Privacy Policy

What we collect, why, where it is stored, how long we keep it, and how to make us delete it.

Who we are

Relicsoft is a sole proprietorship based in No 37/11, 1st 'A' Street, Gopalpuram, Magadi Road, Bengaluru 560023, Karnataka, India, run by Manikandan R. We build and operate custom software, websites and the infrastructure behind them.

For the purposes of India's Digital Personal Data Protection Act 2023 we are the Data Fiduciary for information collected through this website and our client portal. For the UK and EU GDPR we are the Data Controller for the same. Where we run a system on a client's behalf and they decide what goes into it, they are the controller and we are the processor — that relationship is governed by our Data Processing Addendum, not by this page.

Questions, requests and complaints about personal data go to admin@relicsoft.in. That address reaches the proprietor directly and is the grievance officer contact required under the DPDP Act.

What we collect from website visitors

The enquiry form is the only place this site asks for anything. It collects:

  • Your name and email address — required, because we cannot reply without them.
  • Your phone number, company, the service you are interested in and a budget band — all optional.
  • What you write in the message field.

Alongside the submission we record the time, your browser's user-agent string, and a one-way hash of your IP address. The hash uses a secret salt held only on our server, and the raw IP is never written to storage. It exists to detect a flood of automated submissions from one source and for nothing else — we cannot reverse it to find you, and we do not try.

There is a hidden field on the form that no human can see or reach. If it arrives filled in we discard the submission silently. That is anti-spam, not tracking.

What we collect from portal users

If your organisation is a client, we hold an account for you on the client portal:

  • Your name, work email address and role within your organisation.
  • Your password, stored only as a bcrypt hash — we cannot read it, and nobody here can tell you what it is.
  • A sign-in record: the time, IP address, approximate region, device type and operating system, kept so you and we can spot an account being used by someone who should not have it.
  • Support tickets you raise, including anything you attach to them.
  • Usage and billing records for the services your organisation buys.

Why we are allowed to hold it

To answer your enquiry
You asked us to. Under GDPR this is legitimate interest; under the DPDP Act it is the certain legitimate use of data you voluntarily provided for a stated purpose.
To run services you have bought
Performance of a contract. Without your account details there is no account.
To bill you and keep the records
Legal obligation. Indian tax law requires books and invoices to be retained for a fixed period regardless of what either of us would prefer.
To keep accounts secure
Legitimate interest. The sign-in log exists so that an account takeover is visible rather than silent.

We do not sell personal data, we do not share it for advertising, and we do not profile you. There is no advertising network on this site.

Cookies and analytics

This marketing website sets no cookies and runs no analytics or tracking scripts. Nothing here follows you to another site.

The client portal sets a session cookie once you sign in, because that is how being signed in works. It is strictly necessary, it holds only your session token, and clearing it signs you out.

Where it is stored and who else sees it

Your data lives in a Supabase Postgres database in the Mumbai region and is served through Vercel. We use a small number of third parties, listed on this page under Sub-processors, each doing one specific job. None of them may use your data for their own purposes.

Some of those providers are outside India and outside the EEA. Where personal data crosses a border we rely on the provider's Standard Contractual Clauses and on their own data-protection commitments. If a client requires data to stay within a specific jurisdiction, say so before we build — it is a design decision, not a setting.

How long we keep it

Enquiries that did not become work
24 months from the last contact, then deleted. Long enough that a conversation resumed next year still has its history; short enough that we are not sitting on a decade of strangers' phone numbers.
Client records, contracts and invoices
Retained for the period Indian tax and company law requires — currently eight years from the end of the relevant financial year — and then deleted. We cannot delete these on request while that obligation runs.
Support tickets
For the life of the engagement plus 12 months, so a recurring fault has a history.
Sign-in and audit logs
12 months, then automatically purged.
Backups
Rolling 30 days. A deletion request is applied to live data immediately and works its way out of backups within that window.

Your rights

Whatever country you are in, you can ask us to:

  • Tell you what we hold about you, and give you a copy.
  • Correct anything that is wrong.
  • Delete it, unless we are legally required to keep it — in which case we will tell you which obligation and when it expires.
  • Stop using it for a particular purpose.
  • Nominate someone to exercise these rights on your behalf if you die or become incapacitated (a DPDP Act right specifically).

Write to admin@relicsoft.in. We will reply within 30 days, and usually within two working days — there is one person reading that inbox, not a queue. There is no charge.

If you are not satisfied with how we handle it, you may complain to the Data Protection Board of India, or to your national supervisory authority if you are in the UK or EU.

Breach notification

If personal data we hold is exposed, we will tell the people affected and the relevant authority. Under the DPDP Act that means notifying the Data Protection Board; under GDPR it means the supervisory authority within 72 hours. We will tell you what happened, what data was involved, and what we have done about it — including when the answer is unflattering.

Children

This is a business-to-business service. We do not knowingly collect data from anyone under 18, and the DPDP Act's rules on processing children's data mean we would need verifiable parental consent to do so. If you believe a child has submitted information through this site, tell us and we will delete it.

Changes

If we change this policy in a way that affects you, we will say so on this page and — for portal users — by email. The date at the foot of the page always reflects the current version.

Sub-processors

Every third party that can touch personal data, what it does, and where it runs. Entries marked planned are not yet live — they are listed in advance so this page does not have to be rewritten under time pressure the week they are switched on.

ProviderWhat it doesWhere
Vercel Inc.Website and application hosting, content deliveryGlobal edge network; serverless compute in Mumbai (bom1)
SupabaseDatabase, authentication and file storageMumbai, India (ap-south-1)
Google (Workspace)Business email, calendar and documentsGlobal; Google Ireland Ltd for EEA data
Cashfree PaymentsPlannedPayment processing for invoices and online ordersIndia
ShiprocketPlannedLast-mile and hyperlocal delivery dispatchIndia
Meta Platforms (WhatsApp Business Platform)PlannedOrder, dispatch and verification messagesGlobal
ResendPlannedTransactional email — credentials, password resets, notificationsGlobal