Privacy Policy
What personal data we collect when you contact us, why we hold it, how long we keep it, and what you can require us to do with it.
1. Who this policy is from
Astratech Solutions ("we", "us") manufactures wire harnesses and cable assemblies to customer drawings. This policy covers personal data we collect through this website and through the enquiry correspondence that follows from it.
In the language of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for that data, and you are the Data Principal. We process personal data in accordance with that Act and the rules made under it as they come into force, and with the Information Technology Act, 2000 and the SPDI Rules, 2011.
You can reach us about anything in this policy at contact@astratechsolutions.in.
2. What we collect
We collect only what an enquiry needs to be answered. There is no account to create and nothing to sign up for.
| What | Where it comes from | Why we need it |
|---|---|---|
| Name | You, on an enquiry form | To address a reply to a person |
| Company name | You, on an enquiry form | To quote against the right account |
| Email address | You, on an enquiry form | To send the quotation or datasheet |
| Enquiry details — assembly type, quantities, drawings, part numbers | You, on an enquiry form or in later correspondence | To understand and price what you need built |
| Anything else you choose to put in a message | You | Only what you decide to tell us |
We do not ask for and have no use for financial account details, government identifiers, biometric data, health data, or any of the other categories the SPDI Rules class as sensitive personal data. Please do not send them.
Drawings and specifications you send us are usually your commercial confidential information rather than personal data. We treat them as confidential either way, and we do not use them for anything except quoting and building your assembly.
3. What this website does and does not do
This site is deliberately plain in how it handles visitors:
- It sets no cookies of any kind — not for analytics, not for advertising, not for preferences.
- It stores nothing in your browser’s local or session storage.
- It runs no analytics, no tracking pixels, no advertising tags and no session recording.
- It builds no profile of you and makes no automated decision about you.
Our typefaces are served from our own domain rather than from Google Fonts, so simply reading this site discloses your IP address to nobody but our web host.
One request leaves your browser to a third party, and only if you choose to make it: submitting an enquiry form passes its contents to Web3Forms, which relays them to our inbox as email. Nothing is sent until you press the button.
Our web host records standard server logs, including IP addresses, as a normal part of serving a page. We do not have access to those logs and do not use them.
4. Why we are allowed to process it
Under the DPDP Act, we rely on your consent. You give it by choosing to send us an enquiry, having been told on the form what the data is for. That is the only basis we rely on for enquiry data.
You can withdraw consent at any time by emailing us. Withdrawal is as easy as giving consent, and we will stop processing and delete the data unless we are required by law to keep a record of a transaction that has already happened — a completed sale, for example, carries statutory retention obligations we cannot waive.
Withdrawing consent does not make anything we did beforehand unlawful, and it will usually mean we can no longer progress your enquiry.
5. Who else sees it
We do not sell personal data, we do not share it for anyone else’s marketing, and we do not disclose it to any party except as set out here.
| Recipient | What they receive | Why |
|---|---|---|
| Web3Forms | The contents of a submitted enquiry form | To relay it to our inbox |
| Our email provider | Enquiry correspondence | To deliver and store our mail |
| Our web host | Standard server request logs | To serve the website |
| Professional advisers, or a public authority | Only what is strictly necessary | Where we are required by law, or need advice on a dispute |
Some of these providers operate outside India, so enquiry data may be processed abroad. We will not transfer personal data to any territory that the Central Government restricts under section 16 of the DPDP Act.
We do not pass your drawings or specifications to a third party without your instruction. Where a job needs an outside process, we tell you who and get your agreement first.
6. How long we keep it
We keep personal data only while it is doing a job, then delete it.
| Data | Kept for | Then |
|---|---|---|
| An enquiry that does not become an order | 24 months from last contact | Deleted |
| Correspondence relating to a quotation issued | 24 months from the date of the quotation | Deleted |
| Contact details on a customer account | For as long as the account is active | Deleted on request, or 24 months after the last order |
| Records of a completed sale | As required by applicable tax and company law | Deleted at the end of the statutory period |
| Customer drawings and specifications | For as long as we may need to rebuild or support the assembly | Returned or destroyed on request |
If you ask us to erase your data sooner, we do so unless a statutory retention obligation covers it. Where that applies we tell you which record we are keeping and why.
7. How we protect it
We maintain reasonable security practices and procedures as required by section 43A of the Information Technology Act, 2000, proportionate to the fact that we hold business contact details and engineering drawings rather than financial or sensitive personal data.
- The website is served over HTTPS, and enquiry forms submit over an encrypted connection.
- Access to enquiry correspondence is limited to the people who need it to quote or build the job.
- Accounts used to access that correspondence are protected by multi-factor authentication.
- Customer drawings are held as confidential and are not published, reused for another customer, or used as portfolio material without written permission.
- Providers are chosen on the basis that they offer security appropriate to what they handle.
No system is immune. If a personal data breach occurs we will notify the Data Protection Board of India and every affected person, in the form and within the time the DPDP Act and its rules require.
8. Your rights
Under the DPDP Act you may:
- ask for a summary of the personal data we hold about you and what we are doing with it;
- ask us to correct anything inaccurate, complete anything incomplete, or update anything stale;
- ask us to erase your personal data, where no legal obligation requires us to keep it;
- nominate another person to exercise these rights for you in the event of your death or incapacity; and
- raise a grievance with us, and escalate it if our answer does not satisfy you.
To exercise any of these, email contact@astratechsolutions.in. We may need to confirm who you are before we act, so that we do not disclose one person’s data to another. There is no charge.
We will respond within the period prescribed under the DPDP Act and its rules, and in any event without undue delay.
9. If you are in the EEA or the United Kingdom
We sell into the European Union and the United Kingdom, so for visitors and customers there the GDPR and the UK GDPR apply in addition to everything above. Where anything in this section differs from the rest of the policy, this section governs for you.
Astratech Solutions is the controller of your personal data. We are established in India, not in the EEA or the UK.
Our legal bases. We do not rely on consent alone:
| What we do | Legal basis |
|---|---|
| Answer your enquiry, prepare a quotation, and correspond about it | Article 6(1)(b) — steps taken at your request before entering a contract |
| Perform an order you place, and support the assembly afterwards | Article 6(1)(b) — performance of a contract |
| Keep records of quotations and correspondence for our own protection | Article 6(1)(f) — our legitimate interest in being able to evidence what was agreed |
| Retain invoices and accounting records | Article 6(1)(c) — compliance with a legal obligation |
We do not process special categories of personal data under Article 9, we do not use your data for direct marketing unless you ask us to, and we carry out no profiling or automated decision-making that produces legal or similarly significant effects on you (Article 22).
Your rights. In addition to the rights already described, you may:
- ask for access to your personal data and a copy of it (Article 15);
- have inaccurate data corrected and incomplete data completed (Article 16);
- have your data erased, where one of the grounds in Article 17 applies;
- have our processing restricted while a dispute about it is resolved (Article 18);
- receive the data you gave us in a portable, machine-readable form, or have it sent to another controller (Article 20);
- object to processing carried out on the basis of our legitimate interests (Article 21), including any direct marketing, which we will stop on request without exception; and
- withdraw consent at any time where we have relied on it, without affecting what was lawful beforehand (Article 7(3)).
Write to contact@astratechsolutions.in. We answer within one month, and will tell you if we need to extend that by up to two further months because a request is complex — we will not simply go quiet.
International transfers. We are in India, which is not covered by a UK or EU adequacy decision, and some of our providers are elsewhere again.
- When you send us an enquiry, you are disclosing your data to us directly. Under EDPB Guidelines 05/2021 that is not itself a restricted transfer, because there is no EU-established exporter in the chain.
- Where we then disclose your data to a provider outside the EEA or the UK, we rely on an adequacy decision where one covers that provider, and otherwise on the European Commission’s Standard Contractual Clauses, together with the UK Addendum for UK data.
- We will tell you which mechanism applies to a named provider, and send you a copy of the relevant clauses, on request.
Complaints. If you think we have handled your data unlawfully, we would rather you told us first, but you have the right to complain to a supervisory authority without doing so — in the EEA, the authority in the member state where you live, work, or where the issue arose, and in the UK, the Information Commissioner’s Office.
You may raise any data protection matter with us directly at contact@astratechsolutions.in, and we will deal with it rather than routing you elsewhere.
We have not appointed a Data Protection Officer, because our processing does not meet any of the conditions in Article 37(1): we are not a public authority, we do not carry out large-scale systematic monitoring, and we do not process special-category data at scale.
10. Children
This is a business-to-business site. It is not directed at children, and we do not knowingly collect the personal data of anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it.
11. Grievances
If you are unhappy with how we have handled your personal data, contact the Grievance Officer at contact@astratechsolutions.in with the word "Grievance" in the subject line. We will acknowledge and address the complaint within the time the SPDI Rules and the DPDP Act require.
If our response does not resolve the matter, you may complain to the Data Protection Board of India in accordance with the DPDP Act.
12. Changes
We update this policy when what we do changes. The version in force is always the one on this page, and the date it was last revised is shown at the top. If we make a change that materially affects how we handle data you have already given us, we will tell you directly rather than rely on you noticing it here.