Privacy Policy
We believe privacy should be simple, transparent, and built on trust. Here is how Binds handles and protects your personal data in accordance with the laws of India.
- No data selling: We do not sell, rent, or monetize your personal information to third parties.
- Data minimization: We collect only the data strictly necessary to provide and secure our services.
- Data Principal Rights: Access, correct, or request deletion of your data at any time under DPDP Act 2023.
- Reasonable security: Modern encryption in transit and at rest pursuant to Indian IT statutory standards.
01 Introduction & Scope
Binds (“we”, “us”, “our”) operates binds.si and its family of software products, including ESignify, Class Hero, Click2Fix, and Social Posty. We respect your fundamental right to privacy.
This Privacy Policy is formulated and published in compliance with:
- The Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- The Information Technology Act, 2000 (Section 43A and Section 72A); and
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
This Policy describes how we collect, store, process, and protect personal data when you interact with our websites, software, and services.
02 Information We Collect
We adhere strictly to the principle of data minimization and only process personal data that is necessary for the purposes set out below:
- Information You Provide Voluntarily: When you register an account, join a workspace, or reach out to us, you may provide your name, work email address, organization name, role, and message content.
- Product & Workflow Data: Data you input into our tools to accomplish your tasks (such as email signature configurations in ESignify, classroom assignments in Class Hero, ticket queries in Click2Fix, or scheduled post drafts in Social Posty).
- Technical & Telemetry Data: Standard internet logs including IP address, browser type, device operating system, access timestamps, and error logs, collected automatically to safeguard platform stability and prevent denial-of-service abuse.
What We Do NOT Collect: We do not collect government identification numbers, biometrics, religious or health data, or unnecessary sensitive personal categories. Payment processing (when applicable) is handled through certified PCI-DSS compliant payment gateways, and we do not store sensitive credit/debit card numbers on our servers.
03 Lawful Purpose for Processing (DPDP Act 2023)
In compliance with the DPDP Act, 2023, we process personal data only for clear, specific, and lawful purposes based on your consent or legitimate operational use:
- To provide, operate, maintain, and troubleshoot Binds products and platform features.
- To authenticate user sessions, prevent fraudulent logins, and protect system security.
- To communicate with you regarding service announcements, updates, security alerts, and administrative messages.
- To respond to your support inquiries, customer feedback, and technical requests.
- To comply with statutory and regulatory obligations under applicable Indian laws.
04 Absolute No-Sale of Personal Data
We do not sell, rent, lease, trade, or monetize your personal information to third parties, advertising exchanges, or data brokers.
We do not track your activity across unrelated websites to display targeted behavioral advertisements. Your data belongs to you.
05 Data Sharing & Third-Party Processors
We share personal data only in limited and transparent circumstances necessary to operate our platform:
- Infrastructure Providers: Trusted cloud hosting providers, database clusters, and transactional email services that act strictly as Data Processors bound by written confidentiality and security obligations.
- Compliance with Law: When required by a valid court order, government agency, or statutory law enforcement authority in the Republic of India pursuant to applicable legal processes.
- Protection of Rights: Where disclosure is necessary to investigate potential security violations, fraud, or threats to system integrity.
06 Data Security (Reasonable Security Standards)
In compliance with Section 43A of the Information Technology Act, 2000 and the SPDI Rules, Binds maintains comprehensive managerial, technical, operational, and physical security controls to safeguard personal data against unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmissions are encrypted using modern Transport Layer Security (TLS/HTTPS).
- Encryption at Rest: Stored user records and authentication credentials are encrypted using industry-standard cryptographic algorithms.
- Access Control: Strict role-based access controls (RBAC) ensuring only authorized engineers with a verified need have access to operational infrastructure.
- Vulnerability Monitoring: Regular dependency auditing, logging, and security patching.
07 Data Retention & Deletion
We retain personal data only for as long as your account remains active or as strictly required to fulfill the operational purposes stated in this Policy, or as mandated by statutory Indian record-retention laws.
Upon receiving an account deletion request or when data is no longer necessary, we securely delete or irreversibly anonymize personal records within 30 days, subject to technical backups which are rotated and purged according to routine schedules.
08 Your Rights as a Data Principal (DPDP Act 2023)
Under Chapter III of the Digital Personal Data Protection Act, 2023, you (as the “Data Principal”) have the following statutory rights regarding your personal data:
- Right to Access & Summary: You may request a summary of the personal data being processed about you and the identities of any data processors with whom it has been shared.
- Right to Correction & Erasure: You may request the correction of inaccurate or misleading data, the completion of incomplete data, or the deletion of data that is no longer necessary.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time without retroactive penalty.
- Right of Grievance Redressal: You have the right to readily register a grievance with our Grievance Officer and receive timely resolution.
- Right to Nominate: You have the right to nominate another individual who may exercise your data protection rights in the event of death or incapacity.
To exercise any of these rights, submit a request via our Privacy & Data Rights Desk. We will verify your identity and process your request within the statutory timeframe.
09 Cookies & Local Storage
We use only essential session cookies and technical storage strictly necessary for website functionality, user authentication, and layout preferences. We do not use third-party tracking pixels, marketing cookies, or invasive profiling scripts.
10 Children's Privacy
Certain Binds products (such as Class Hero) may be utilized within educational institutions. In adherence to Section 9 of the DPDP Act, 2023:
- We do not engage in targeted advertising directed at children or behavioral monitoring of minors.
- Accounts for minors are administered with verifiable authorization from parents, legal guardians, or educational institutions acting in loco parentis.
11 Statutory Grievance Redressal Officer
In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, Binds has designated a Grievance Officer to handle data privacy concerns, grievances, and inquiries:
Please mark your communication with the subject line “Privacy Grievance - DPDP Act” to facilitate immediate routing.
12 Policy Updates & Contact
We may update this Privacy Policy from time to time to maintain alignment with technological advancements or changes in Indian statutory law. Any modifications will be posted here with an updated “Last Updated” date.
If you have questions, feedback, or concerns regarding our privacy practices, please contact us at:
Binds
Contact: Communications & Privacy Desk
Website: https://binds.si
Review our Terms of Service
Read about permitted platform usage, intellectual property, and service agreements.