Skip to content
Back to site

Privacy Policy

What personal data we collect when you contact us, why we hold it, how long we keep it, and what you can require us to do with it.

Last updated
9 September 2026
Applies to
Astratech Solutions
Written against
Digital Personal Data Protection Act, 2023 · Information Technology Act, 2000 & SPDI Rules, 2011 · EU General Data Protection Regulation (2016/679) · UK GDPR & Data Protection Act 2018

1. Who this policy is from

Astratech Solutions ("we", "us") manufactures wire harnesses and cable assemblies to customer drawings. This policy covers personal data we collect through this website and through the enquiry correspondence that follows from it.

In the language of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for that data, and you are the Data Principal. We process personal data in accordance with that Act and the rules made under it as they come into force, and with the Information Technology Act, 2000 and the SPDI Rules, 2011.

You can reach us about anything in this policy at contact@astratechsolutions.in.

2. What we collect

We collect only what an enquiry needs to be answered. There is no account to create and nothing to sign up for.

WhatWhere it comes fromWhy we need it
NameYou, on an enquiry formTo address a reply to a person
Company nameYou, on an enquiry formTo quote against the right account
Email addressYou, on an enquiry formTo send the quotation or datasheet
Enquiry details — assembly type, quantities, drawings, part numbersYou, on an enquiry form or in later correspondenceTo understand and price what you need built
Anything else you choose to put in a messageYouOnly what you decide to tell us

We do not ask for and have no use for financial account details, government identifiers, biometric data, health data, or any of the other categories the SPDI Rules class as sensitive personal data. Please do not send them.

Drawings and specifications you send us are usually your commercial confidential information rather than personal data. We treat them as confidential either way, and we do not use them for anything except quoting and building your assembly.

3. What this website does and does not do

This site is deliberately plain in how it handles visitors:

  • It sets no cookies of any kind — not for analytics, not for advertising, not for preferences.
  • It stores nothing in your browser’s local or session storage.
  • It runs no analytics, no tracking pixels, no advertising tags and no session recording.
  • It builds no profile of you and makes no automated decision about you.

Our typefaces are served from our own domain rather than from Google Fonts, so simply reading this site discloses your IP address to nobody but our web host.

One request leaves your browser to a third party, and only if you choose to make it: submitting an enquiry form passes its contents to Web3Forms, which relays them to our inbox as email. Nothing is sent until you press the button.

Our web host records standard server logs, including IP addresses, as a normal part of serving a page. We do not have access to those logs and do not use them.

4. Why we are allowed to process it

Under the DPDP Act, we rely on your consent. You give it by choosing to send us an enquiry, having been told on the form what the data is for. That is the only basis we rely on for enquiry data.

You can withdraw consent at any time by emailing us. Withdrawal is as easy as giving consent, and we will stop processing and delete the data unless we are required by law to keep a record of a transaction that has already happened — a completed sale, for example, carries statutory retention obligations we cannot waive.

Withdrawing consent does not make anything we did beforehand unlawful, and it will usually mean we can no longer progress your enquiry.

5. Who else sees it

We do not sell personal data, we do not share it for anyone else’s marketing, and we do not disclose it to any party except as set out here.

RecipientWhat they receiveWhy
Web3FormsThe contents of a submitted enquiry formTo relay it to our inbox
Our email providerEnquiry correspondenceTo deliver and store our mail
Our web hostStandard server request logsTo serve the website
Professional advisers, or a public authorityOnly what is strictly necessaryWhere we are required by law, or need advice on a dispute

Some of these providers operate outside India, so enquiry data may be processed abroad. We will not transfer personal data to any territory that the Central Government restricts under section 16 of the DPDP Act.

We do not pass your drawings or specifications to a third party without your instruction. Where a job needs an outside process, we tell you who and get your agreement first.

6. How long we keep it

We keep personal data only while it is doing a job, then delete it.

DataKept forThen
An enquiry that does not become an order24 months from last contactDeleted
Correspondence relating to a quotation issued24 months from the date of the quotationDeleted
Contact details on a customer accountFor as long as the account is activeDeleted on request, or 24 months after the last order
Records of a completed saleAs required by applicable tax and company lawDeleted at the end of the statutory period
Customer drawings and specificationsFor as long as we may need to rebuild or support the assemblyReturned or destroyed on request

If you ask us to erase your data sooner, we do so unless a statutory retention obligation covers it. Where that applies we tell you which record we are keeping and why.

7. How we protect it

We maintain reasonable security practices and procedures as required by section 43A of the Information Technology Act, 2000, proportionate to the fact that we hold business contact details and engineering drawings rather than financial or sensitive personal data.

  • The website is served over HTTPS, and enquiry forms submit over an encrypted connection.
  • Access to enquiry correspondence is limited to the people who need it to quote or build the job.
  • Accounts used to access that correspondence are protected by multi-factor authentication.
  • Customer drawings are held as confidential and are not published, reused for another customer, or used as portfolio material without written permission.
  • Providers are chosen on the basis that they offer security appropriate to what they handle.

No system is immune. If a personal data breach occurs we will notify the Data Protection Board of India and every affected person, in the form and within the time the DPDP Act and its rules require.

8. Your rights

Under the DPDP Act you may:

  • ask for a summary of the personal data we hold about you and what we are doing with it;
  • ask us to correct anything inaccurate, complete anything incomplete, or update anything stale;
  • ask us to erase your personal data, where no legal obligation requires us to keep it;
  • nominate another person to exercise these rights for you in the event of your death or incapacity; and
  • raise a grievance with us, and escalate it if our answer does not satisfy you.

To exercise any of these, email contact@astratechsolutions.in. We may need to confirm who you are before we act, so that we do not disclose one person’s data to another. There is no charge.

We will respond within the period prescribed under the DPDP Act and its rules, and in any event without undue delay.

9. If you are in the EEA or the United Kingdom

We sell into the European Union and the United Kingdom, so for visitors and customers there the GDPR and the UK GDPR apply in addition to everything above. Where anything in this section differs from the rest of the policy, this section governs for you.

Astratech Solutions is the controller of your personal data. We are established in India, not in the EEA or the UK.

Our legal bases. We do not rely on consent alone:

What we doLegal basis
Answer your enquiry, prepare a quotation, and correspond about itArticle 6(1)(b) — steps taken at your request before entering a contract
Perform an order you place, and support the assembly afterwardsArticle 6(1)(b) — performance of a contract
Keep records of quotations and correspondence for our own protectionArticle 6(1)(f) — our legitimate interest in being able to evidence what was agreed
Retain invoices and accounting recordsArticle 6(1)(c) — compliance with a legal obligation

We do not process special categories of personal data under Article 9, we do not use your data for direct marketing unless you ask us to, and we carry out no profiling or automated decision-making that produces legal or similarly significant effects on you (Article 22).

Your rights. In addition to the rights already described, you may:

  • ask for access to your personal data and a copy of it (Article 15);
  • have inaccurate data corrected and incomplete data completed (Article 16);
  • have your data erased, where one of the grounds in Article 17 applies;
  • have our processing restricted while a dispute about it is resolved (Article 18);
  • receive the data you gave us in a portable, machine-readable form, or have it sent to another controller (Article 20);
  • object to processing carried out on the basis of our legitimate interests (Article 21), including any direct marketing, which we will stop on request without exception; and
  • withdraw consent at any time where we have relied on it, without affecting what was lawful beforehand (Article 7(3)).

Write to contact@astratechsolutions.in. We answer within one month, and will tell you if we need to extend that by up to two further months because a request is complex — we will not simply go quiet.

International transfers. We are in India, which is not covered by a UK or EU adequacy decision, and some of our providers are elsewhere again.

  • When you send us an enquiry, you are disclosing your data to us directly. Under EDPB Guidelines 05/2021 that is not itself a restricted transfer, because there is no EU-established exporter in the chain.
  • Where we then disclose your data to a provider outside the EEA or the UK, we rely on an adequacy decision where one covers that provider, and otherwise on the European Commission’s Standard Contractual Clauses, together with the UK Addendum for UK data.
  • We will tell you which mechanism applies to a named provider, and send you a copy of the relevant clauses, on request.

Complaints. If you think we have handled your data unlawfully, we would rather you told us first, but you have the right to complain to a supervisory authority without doing so — in the EEA, the authority in the member state where you live, work, or where the issue arose, and in the UK, the Information Commissioner’s Office.

You may raise any data protection matter with us directly at contact@astratechsolutions.in, and we will deal with it rather than routing you elsewhere.

We have not appointed a Data Protection Officer, because our processing does not meet any of the conditions in Article 37(1): we are not a public authority, we do not carry out large-scale systematic monitoring, and we do not process special-category data at scale.

10. Children

This is a business-to-business site. It is not directed at children, and we do not knowingly collect the personal data of anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it.

11. Grievances

If you are unhappy with how we have handled your personal data, contact the Grievance Officer at contact@astratechsolutions.in with the word "Grievance" in the subject line. We will acknowledge and address the complaint within the time the SPDI Rules and the DPDP Act require.

If our response does not resolve the matter, you may complain to the Data Protection Board of India in accordance with the DPDP Act.

12. Changes

We update this policy when what we do changes. The version in force is always the one on this page, and the date it was last revised is shown at the top. If we make a change that materially affects how we handle data you have already given us, we will tell you directly rather than rely on you noticing it here.