Last updated: August 10, 2026

1. Overview

Startup IT Solution Infotech Pvt Ltd is committed to protecting the personal data of our clients, users, and employees. This policy outlines our data protection practices in compliance with applicable data protection laws including the IT Act, 2000 (India) and GDPR (where applicable).

2. Data Collection Principles

  • Lawfulness: Data is collected with consent or legitimate business purpose.
  • Purpose Limitation: Data is collected for specified, explicit purposes only.
  • Data Minimization: Only necessary data is collected.
  • Accuracy: We maintain accurate and up-to-date data.
  • Storage Limitation: Data is retained only as long as necessary.

3. Data Security Measures

  • SSL/TLS encryption for all data in transit.
  • AES-256 encryption for data at rest.
  • Role-based access control (RBAC) with multi-factor authentication.
  • Regular security audits and penetration testing.
  • Automated daily backups with encrypted storage.
  • Firewall and intrusion detection systems.

4. Data Subject Rights

Individuals have the right to: access their data, request correction, request deletion, data portability, and object to processing. Requests can be submitted to info@startupitsolution.com.

5. Data Breach Response

In the event of a data breach, we will: contain the breach, assess the impact, notify affected parties within 72 hours, and implement corrective measures to prevent recurrence.

6. International Data Transfers

When data is transferred internationally, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) and adequacy assessments.

7. Data Retention

  • Active client data: Retained for the duration of the engagement.
  • Inactive client data: Deleted or anonymized after 3 years.
  • Financial records: Retained for 7 years as per legal requirements.
  • Marketing data: Retained until consent is withdrawn.

8. Contact

For data protection inquiries, contact our Data Protection Officer at info@startupitsolution.com.