Digital Personal Data Protection Act (DPDP Act 2023) & IT Act Compliant

Privacy & Data Protection Policy

This comprehensive policy outlines how Solanacy Technologies collects, encrypts, processes, and safeguards corporate intellectual property, patient healthcare records, and personal data across our Websoft software solutions, D-DEY PMS, and cloud ecosystems.

📅 Effective Date: September 2026
🛡️ Version: 2.4 (Enterprise Edition)
📍 Jurisdiction: Howrah, West Bengal, India
🔒 Data Sovereignty: AWS Mumbai (ap-south-1)
Section 01

Scope & Applicable Entities

This Privacy and Data Protection Policy ("Policy") governs all interactions between users, enterprise clients, business partners, and Solanacy Technologies ("Solanacy", "we", "us", or "our"), headquartered in Howrah, West Bengal, India.

This Policy applies universally to:

  • Solanacy Websoft Suite: Custom website engineering, client portals, and bespoke business web applications.
  • Industry Showcase Platforms: Dedicated showcases for Grocery & Supermarkets, Restaurants & Cafes, E-Commerce & Retail, Services & Agencies, and Custom Enterprise ERPs.
  • D-DEY PMS Ecosystem: Advanced AI-powered Pharmacy Management System, doctor prescription OCR engines, clinic registers, and chronic patient refill automation (ddey.solanacy.in).
  • Backend APIs & Cloud Microservices: All endpoints operating under api.solanacy.in and regional Indian server clusters.
Legal Grounding: This document is constructed in strict compliance with the Digital Personal Data Protection Act (DPDP Act, 2023), the Information Technology Act, 2000 (including Reasonable Security Practices Rules, 2011), and aligns with global benchmarks including the EU General Data Protection Regulation (GDPR).
Section 02

Information We Collect & Processing Channels

We collect personal and corporate data exclusively to deliver high-performance software, process legitimate commercial transactions, and fulfill statutory obligations under Indian law.

Data Category Examples of Data Collected Collection Method
Identity & Commercial Full Name, Corporate Designation, Business Name, GSTIN, Trade License details, WhatsApp Phone Number, and Official Email Address. Direct intake forms, onboarding surveys, service contracts.
Project Specifications Product catalogs, branch addresses, inventory hierarchies, courier credentials, and software feature requests. Technical scoping calls, intake submissions, client portal uploads.
Technical & Telemetry IP address, browser user-agent, operating system, edge CDN latency, request timestamps, and error diagnostic logs. Automated web server logs, edge network analytics (anonymized).
Financial & Billing GST invoice details, transaction IDs, UPI reference numbers, payment gateway settlement logs. (Raw debit/credit card numbers are NEVER collected or stored). Encrypted webhooks from authorized gateways (Cashfree, Razorpay, PhonePe).
Section 03

Purpose & Legal Basis of Processing

Under the DPDP Act 2023, processing of personal and business data is conducted strictly under lawful consent and legitimate business execution:

  • Software Provisioning: Designing, hosting, deploying, and maintaining bespoke web applications and ERP databases.
  • Commercial Communications: Responding to client inquiries, sending technical proposals, milestone delivery alerts, and system uptime notices.
  • Security & Fraud Mitigation: Detecting unauthorized penetration attempts, defending against DDoS attacks, and ensuring database integrity.
  • Statutory Compliance: Generating tax-compliant GST e-invoices, maintaining audit ledgers, and cooperating with lawful government inquiries.
No Data Monetization Guarantee: Solanacy Technologies does not sell, rent, monetize, or trade your corporate information, client customer databases, or personal identifiers to any data broker or advertising network under any circumstances.
Section 04

Healthcare, Patient & D-DEY PMS Data Protection

Our flagship pharmacy and clinic platform, D-DEY PMS (ddey.solanacy.in), handles sensitive pharmaceutical and diagnostic records. We enforce strict compliance with Indian healthcare standards and the Drugs and Cosmetics Rules, 1945:

  • Schedule H & H1 Statutory Data: Patient names, prescribing doctor details, drug batch numbers, and dispensing quantities required under drug control laws are securely partitioned and archived for statutory inspection periods.
  • Prescription OCR & Diagnostic Records: Digital prescription uploads processed by D-DEY PMS AI OCR are encrypted at rest using AES-256 and transmitted over TLS 1.3. Unredacted scans are strictly accessible only to authorized chemist staff.
  • DISHA / HIPAA Principles: Patient identifiers are anonymized in analytical reporting, preventing any cross-linking with commercial advertising.
  • Chemist Data Isolation: Each pharmacy or clinic operating on D-DEY PMS operates on an isolated multi-tenant or dedicated database schema, preventing accidental cross-tenant data leakage.
Section 05

WhatsApp Cloud API & Automated Messaging

Solanacy software incorporates the official Meta WhatsApp Cloud API for client communication, order confirmations, chronic refill reminders, and appointment scheduling.

Our WhatsApp integrations operate under the following parameters:

  • Explicit Opt-In: Messages are sent only when a client or end-customer explicitly submits an inquiry form, books an appointment, or initiates an order.
  • Instant Opt-Out (STOP Protocol): Recipients can immediately opt out of automated WhatsApp sequences at any time by replying with the word STOP or UNSUBSCRIBE.
  • End-to-End Encryption: Communications leverage WhatsApp's native security protocols, ensuring messages in transit cannot be intercepted by third parties.
Section 06

Payment Gateways & PCI-DSS Tokenization

All financial transactions for Solanacy Websoft development services and integrated customer storefronts are processed through RBI-authorized payment aggregators (including Cashfree, Razorpay, and PhonePe).

PCI-DSS Compliant Tokenization: Solanacy servers never receive, store, or log raw credit card numbers, debit card CVVs, or net banking passwords. Payments are processed via encrypted iframes and tokenized gateway APIs certified to PCI-DSS Level 1.
Section 07

Data Security Standards & Encryption Protocols

We implement bank-grade administrative, technical, and physical safeguards to prevent unauthorized data access, loss, or destruction:

  • Encryption in Transit: Mandatory TLS 1.3 / HTTPS encryption across all web domains, subdomains, and API sockets with HSTS preloading.
  • Encryption at Rest: Enterprise databases (PostgreSQL, MongoDB, Redis) and file storage volumes are encrypted using AES-256.
  • Role-Based Access Control (RBAC): Administrative backend access is strictly restricted by least-privilege principles with multi-factor authentication (MFA) and IP whitelisting.
  • Automated Encrypted Backups: Daily incremental backups with geographic redundancy across secure Indian cloud storage facilities.
Section 08

Third-Party Disclosures & Cloud Subprocessors

We engage trusted third-party infrastructure providers ("Subprocessors") solely to deliver hosting, database storage, messaging, and courier logistics:

Subprocessor Service Category Data Location
Amazon Web Services (AWS) Cloud Infrastructure & Database Hosting Mumbai, India (ap-south-1)
Google Cloud Platform (GCP) Application Backends & Analytics Mumbai / Delhi, India
Netlify Inc. Global CDN Edge Hosting & Static Delivery Global Edge CDN with Indian PoPs
Meta Platforms Inc. WhatsApp Cloud API Infrastructure Encrypted Global Meta Network
Delhivery & Shiprocket E-Commerce Courier Shipping & Tracking India
Section 09

Data Retention & Source Code Ownership

Data retention timelines depend on the category of data and our commercial contract with the client:

  • Inquiry & Lead Data: Retained for 180 days post-inquiry, after which inactive leads are automatically purged.
  • Active Client Project Data: Retained for the full duration of the active software agreement and maintenance warranty.
  • Full Source Code Ownership: Upon completion and final payment for custom Websoft projects, clients receive 100% full source code ownership. Solanacy retains zero residual IP claims or backdoor access to proprietary client repositories.
  • Statutory Tax Records: Invoices and GST tax ledgers are archived for 8 years in compliance with Section 128 of the Companies Act, 2013.
Section 10

Your Rights Under the DPDP Act & GDPR

As a data principal, you hold explicit, legally enforceable rights regarding your personal and corporate information:

  • Right to Access & Summary: Request a summary of all personal data held and processed by Solanacy.
  • Right to Correction & Rectification: Request immediate correction of inaccurate or outdated commercial or personal records.
  • Right to Erasure (Right to Be Forgotten): Request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, subject to statutory retention mandates.
  • Right to Withdraw Consent: Withdraw your consent for non-essential marketing or WhatsApp updates at any time.

To exercise any of these rights, please submit a written request to our Grievance Officer at [email protected]. Requests are verified and processed within 15 working days.

Section 11

Protection of Minors & Children's Privacy

Solanacy Technologies develops enterprise, business-to-business (B2B), and professional software. Our web applications, developer APIs, and showcases are not targeted at or intended for individuals under eighteen (18) years of age.

We do not knowingly solicit or collect personal data from minors. In the event that we learn a minor's data has been collected without verified parental or legal guardian consent, we take immediate administrative measures to permanently expunge that information from our production databases.

Section 12

Grievance Redressal & Statutory Contact

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the designated Grievance Officer for Solanacy Technologies is detailed below:

Designated Entity
Solanacy Technologies
Official Legal Email
Direct WhatsApp Escalation
Registered Office & Jurisdiction
Howrah, West Bengal 711101, India
Statutory Resolution Timeline
All formal grievances and data privacy queries receive formal acknowledgement within 48 hours and complete resolution within 30 days.