HomeServicesProcessAboutBlogFAQsContact

Webeta Privacy Policy & Data Protection Standards

We are committed to safeguarding personal privacy in strict compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000.

Last Updated: July 02, 2026
💡

Webeta Privacy & Data Protection Key Takeaways

Architectural Brief

A privacy policy is a legally binding disclosure that defines how our web design and software engineering agency collects, processes, and protects client and visitor personal data in strict compliance with India's Digital Personal Data Protection Act (DPDP Act, 2023) and Information Technology Act, 2000.

Audience & Scope: Website visitors, prospective clients, and commercial partners seeking transparent data governance under India's DPDP Act 2023.
100%DPDPA 2023 Compliant
30-DayGrievance Redressal SLA
ZeroThird-Party Data Sales
256-BitSSL Data Encryption
  • Strict DPDPA Compliance: Webeta adheres to Indian data protection regulations, processing personal data solely for lawful, explicit business purposes.
  • Zero Third-Party Data Sales: We never monetize, rent, or sell client data or visitor contact information to external brokers or advertising networks.
  • Data Subject Rights: Clients and site visitors retain full rights to access, update, review, or request complete erasure of their personal information at any time.
Reference Source:Digital Personal Data Protection Act 2023 (MeitY) ↗— Webeta operates under data protection standards established by the Ministry of Electronics and Information Technology.

1. Introduction & Statutory Framework

Welcome to Webeta. This Privacy Policy ("Policy") governs the collection, processing, storage, and protection of personal data by Webeta ("we," "us," or "our") in our capacity as a Data Fiduciary under Indian law.

This Policy is drafted in strict adherence to:

In this policy, you—as the natural person visiting our website, contacting our team, or engaging our software services—are recognized as the Data Principal. Any third-party infrastructure vendor processing data on our behalf acts as a Data Processor under a binding data protection agreement. For commercial terms governing client deliverables and milestone disbursements, please review our Terms of Service.

2. Personal Data We Collect & Lawful Grounds

In compliance with the data minimization principle (Section 4 and Section 8 of the DPDP Act), Webeta collects only the personal data strictly necessary to fulfill the specific purposes of our business relationship:

  • Identity & Contact Data: Full name, professional email address, mobile/WhatsApp telephone number, company or brand name, and job title provided when submitting contact forms or discovery requests.
  • Project & Commercial Specifications: Business vertical, desired technical scope, budget expectations, timeline goals, design assets, and architectural requirements.
  • Billing & Transaction Information: Tax identification numbers (GSTIN/PAN for Indian entities; corporate registration IDs for international clients), invoicing contact details, and milestone transaction records. All financial transactions are routed directly through PCI-DSS and RBI-compliant gateways; Webeta never stores credit card credentials or online banking passwords on our web servers.
  • Technical & Telemetry Data: Anonymized IP addresses, browser specifications, operating system telemetry, and page interaction timestamps gathered to safeguard platform security and maintain sub-second performance.

Lawful Grounds for Processing: We process your personal data based on: (a) your unambiguous and informed consent under Section 6 of the DPDP Act; (b) the performance of a contractual agreement or pre-contractual discovery initiated by you; and (c) compliance with statutory legal obligations under Indian law.

4. Purpose of Data Processing

Webeta strictly processes personal data for specified, explicit, and legitimate commercial purposes:

  • To evaluate incoming project requirements and schedule architectural discovery calls.
  • To engineer, test, deliver, and maintain custom web applications, APIs, and digital systems.
  • To generate formal Statements of Work (SOW), execute service agreements, and issue compliant tax invoices.
  • To deliver automated uptime monitoring, security updates, and warranty support during contracted periods.
  • To comply with statutory legal mandates under the IT Act 2000, CERT-In cybersecurity directives, and tax laws.

5. Data Processors & Third-Party Sharing

Zero Data Monetization: Webeta does not sell, rent, lease, trade, or commercialize your personal information to third-party data brokers, advertising aggregators, or unsolicited telemarketers.

We share personal data exclusively with vetted Data Processors under written agreements requiring strict confidentiality and reasonable security safeguards:

  • Cloud Infrastructure & CDN Providers: High-security cloud hosts (e.g., Render, AWS, Cloudflare) providing container isolation, automated backups, and global SSL termination.
  • Communication & Form Routing Gateways: Encrypted email transmission providers and security verification APIs (e.g., Cloudflare Turnstile for anti-spam protection).
  • Legal & Regulatory Authorities: Only when strictly mandated by a valid judicial court order, statutory subpoena, or authorized governmental directive under Indian law.

6. Data Principal Statutory Rights (DPDP Act, 2023)

Under Chapter III (Sections 11 through 14) of the Digital Personal Data Protection Act, 2023, you—as a Data Principal—are entitled to exercise the following statutory rights free of charge:

  • Right to Access Information (Section 11): You have the right to request a concise summary of the personal data undergoing processing, the processing activities undertaken, and the identities of any Data Processors with whom data has been shared.
  • Right to Correction & Completion (Section 12): You may request the correction of inaccurate or misleading data, the completion of incomplete records, or the updating of your business profile.
  • Right to Erasure / Right to be Forgotten (Section 12): You may demand the complete erasure of your personal data when the initial purpose of collection has been served, when consent has been withdrawn, or when retention is no longer required by statutory law.
  • Right of Grievance Redressal (Section 13): You have the right to accessible, readily available grievance redressal through our designated Grievance Officer.
  • Right to Nominate (Section 14): You have the statutory right to designate another individual who shall, in the event of your death or legal incapacity, exercise your data protection rights on your behalf.
  • Right to Approach the Data Protection Board of India (DPBI): If you do not receive a satisfactory resolution from our Grievance Officer within 30 statutory days, you retain the legal right to lodge a formal complaint with the Data Protection Board of India.

7. Protection of Children & Minors

In strict compliance with Section 9 of the DPDP Act, 2023, Webeta does not knowingly process, collect, or store personal data belonging to children (defined as individuals under the age of 18 years) or persons with disabilities without verifiable parental or guardian consent.

Webeta's digital engineering services are directed exclusively at business entities, adult professionals, and corporate decision-makers. We do not engage in behavioral tracking, behavioral profiling, or targeted advertising directed toward minors. If we discover that personal data of a minor has been collected unintentionally without verifiable parental consent, we will permanently purge the record from our databases within 24 hours.

8. Reasonable Security Safeguards & Breach Protocol

As required by Section 8(5) of the DPDP Act and the SPDI Rules 2011, Webeta implements robust technical, organizational, and operational security safeguards:

  • Cryptographic Protection: Universal HTTPS with 256-bit TLS encryption in transit, strict HSTS policies, and AES-256 encrypted database backups at rest.
  • Decoupled Architecture: Complete segregation between frontend static rendering and backend database operations, preventing direct SQL injection and unauthorized schema traversal.
  • Role-Based Access Control (RBAC): Employee access to customer submissions is restricted on a strict need-to-know basis and audited with multi-factor authentication (MFA).
  • Statutory Breach Protocol (Section 8(6)): In the unlikely event of a security compromise affecting personal data, Webeta maintains an active incident response plan to notify the Data Protection Board of India (DPBI) and all affected Data Principals without undue delay, outlining the nature of the breach, affected records, and remedial mitigations implemented.
  • Storage Limitation: Personal data is retained only for the duration necessary to satisfy the commercial engagement, fulfill warranty commitments, or comply with statutory accounting and tax regulations (typically up to 5 years under Indian tax statutes), after which data is securely overwritten or purged.

9. Cross-Border Data Transfers

Under Section 16 of the DPDP Act, personal data may be transferred outside India unless specifically restricted or blacklisted by the Central Government of India.

Webeta collaborates actively with international clients across the United States, United Kingdom, European Union, United Arab Emirates, Australia, and Canada. When international data transfers occur, we implement enterprise-grade technical protections, bilateral Non-Disclosure Agreements (NDAs), and GDPR-aligned Standard Contractual Clauses (SCCs) to ensure that your data enjoys equivalent protections regardless of geographical location.

10. Cookies & Tracking Preferences

Our website utilizes privacy-respecting cookies and client-side storage tokens strictly to maintain essential site operations, authenticate administrative sessions, and analyze anonymized aggregate traffic:

  • Essential Cookies: Required for CSRF security protection, secure administrative login, and form validation. These cannot be disabled without breaking website functionality.
  • Performance & Telemetry Cookies: Anonymized metrics measuring page load speeds, Core Web Vitals, and aggregate user journeys without recording personally identifiable keystrokes.

You can manage your cookie preferences at any time using our on-site Cookie Consent Banner or through your web browser settings. Disabling non-essential cookies will not prevent you from browsing our website or submitting project inquiries.

11. Designated Grievance Officer & Redressal Mechanism

In compliance with Section 8(9) and Section 13 of the DPDP Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines) Rules, 2021, Webeta has appointed a designated statutory Grievance Officer:

Designated Grievance Officer: Utsab Halder

Role: Data Protection Lead & Grievance Redressal Officer

Organization: Webeta

Email: webeta03@gmail.com

Postal Address: Barasat, Kolkata, West Bengal 700124, India

Telephone / WhatsApp: +91 9749883224

• Acknowledgment SLA: Within 48 business hours of receipt.

• Statutory Redressal SLA: Complete resolution within a maximum period of 30 statutory days.

• Escalation: In the event you remain unsatisfied with our internal resolution, you may submit a formal complaint to the Data Protection Board of India (DPBI).

12. Policy Revisions & Updates

Webeta reserves the right to amend, update, or revise this Privacy Policy periodically to reflect emerging statutory notifications issued under the DPDP Act 2023, judicial interpretations, or technological changes in our digital services.

When modifications are published, the "Last Updated" date at the top of this document will be revised. In the event of material alterations affecting your substantive privacy rights, prominent notices will be displayed across our website before the changes take effect.

Have questions regarding our DPDP Act compliance or data governance? Speak directly with our team.

DECISION FRAMEWORK

Webeta Privacy Standard vs. Traditional Template Platforms

How Webeta's custom architecture safeguards client and visitor data compared to third-party website builders.

Security & Privacy FactorStandard Third-Party CMS / PluginsWebeta Engineered Architecture
Data Brokerage & Advertising Trackers✗Dozens of third-party trackers, beacons, and ad network scripts✓Zero advertising trackers or data brokerage scripts installed
Database Credential Exposure✗Shared database connection strings exposed to web server root✓Completely decoupled frontend with zero direct database exposure
Statutory Compliance✗Unverified overseas servers with vague cross-border data routing✓Strict compliance with India's DPDP Act, 2023 & IT Act, 2000
Data Subject Erasure (Right to be Forgotten)✗Manual ticket queues that often fail to purge orphaned backups✓Guaranteed 30-day complete data deletion upon written request
DIRECT ANSWERS

Privacy & Data Protection FAQs

Direct answers regarding Webeta's data collection, storage protocols, and statutory DPDP Act compliance.

How does Webeta collect and use personal data?

+

Webeta collects personal data such as names, business emails, and phone numbers when users submit inquiry forms or engage our web development services. Data is used strictly for project delivery, invoicing, and direct client support.

Does Webeta sell or share personal data with third-party advertisers?

+

No. Webeta never sells, rents, or commercializes personal data to third parties. We share data only with trusted infrastructure providers (such as hosting and email gateways) necessary to deliver contracted services.

What rights do users have under the DPDP Act 2023?

+

Under the Digital Personal Data Protection Act, 2023, you have the right to access a summary of your personal data, request correction or erasure, withdraw consent, nominate a representative, and seek grievance redressal within 30 days.

How can I contact Webeta regarding data privacy or submit a grievance?

+

You can contact our designated Grievance Officer, Utsab Halder, by emailing webeta03@gmail.com with your query or deletion request. We acknowledge all inquiries within 48 hours, resolve grievances within 30 days, and advise on appeals to the Data Protection Board of India.

Need a personalized recommendation?Speak with a digital architect →