Skip to content

Legal

Privacy Policy

Softodoor LLP builds software for other people's businesses, which means we are trusted with data that is not ours. This policy sets out exactly what we collect, why we collect it, who we share it with, and how you get it back or get it deleted.

Last updated · 1 September 2026

Scope of this policy

This policy applies to Softodoor LLP (“Softodoor”, “we”, “us”), a limited liability partnership registered in India with its head office at Street No. 17, opposite Manav Palace Apartment, Somana Society, Chandreshnagar, Rajkot, Gujarat 360004.

It covers:

  • the website at softodoor.com and any subdomain of it;
  • enquiries you send us by email, telephone, WhatsApp, or a form on this site;
  • our business messaging channels, including WhatsApp Business and Meta platforms, as described in section 5;
  • the administration of contracts with our clients, suppliers, and job applicants.

It does not cover data we process purely on a client's instructions inside software we built for them — that relationship is described in section 8, and the client's own privacy notice governs it.

Information we collect

Information you give us. When you contact us or engage us, we collect what you choose to send: your name, email address, phone number, company name, job title, and the content of your message, brief, or attachments. If we enter a contract, we also hold billing and tax details such as an address, GSTIN, and bank or payment references.

Information from messaging platforms. If you message us on WhatsApp, we receive your WhatsApp phone number, your WhatsApp profile name, and the messages and media you send, together with delivery and read status for messages we send you.

Information collected automatically. Our web server records standard technical data for every request: IP address, user agent, referring URL, the pages requested, and a timestamp. These logs exist for security and fault diagnosis.

Recruitment data. If you apply for a role, we collect your CV and anything else you send in support of the application.

We do not knowingly collect special-category or sensitive personal data — health, biometric, financial account credentials, caste, religion, or political opinions — and we ask that you do not send it to us. We do not buy personal data from data brokers.

How we use your information

We use personal data only for these purposes:

  • Responding to you — answering an enquiry, preparing a proposal or estimate, and following up on a conversation you started.
  • Delivering our services — running a project, providing support, and handling invoicing and payment.
  • Service messages — project updates, appointment or meeting confirmations, and notices about maintenance or security.
  • Security and integrity — detecting and preventing abuse, fraud, and attacks on our infrastructure.
  • Legal and accounting obligations — keeping the records Indian tax and company law requires us to keep.
  • Recruitment — assessing an application you sent us.

We do not sell personal data, we do not rent or trade it, and we do not use the content of your messages to train machine-learning models.

WhatsApp Business and Meta platforms

We use the WhatsApp Business Platform and related Meta business tools to talk to clients and enquirers who prefer messaging over email. When you message us on those channels:

  • We receive your phone number, profile name, and message content, and we hold that conversation history so we can pick the thread back up.
  • Meta Platforms processes those messages as the operator of the platform, under its own terms and privacy policy. Message delivery over WhatsApp is end-to-end encrypted in transit by WhatsApp; once a message reaches our business account, this policy governs what we do with it.
  • We send you a WhatsApp message only in reply to you, in the course of work you have engaged us for, or after you have opted in. Every marketing or notification thread can be stopped by replying stop, and we will not message you on that channel again.
  • We do not upload your contact details to Meta for advertising, we do not build custom or lookalike advertising audiences from them, and we do not share WhatsApp conversation content with advertisers.

Any access token or credential we hold for a Meta or WhatsApp Business account is stored encrypted, is restricted to the minimum permissions the integration needs, and is revoked when the integration is retired.

Cookies and analytics

This website does not set advertising or cross-site tracking cookies, and it does not run a third-party advertising pixel.

Fonts are self-hosted and served from our own domain, so viewing the site does not send a request to a third-party font CDN. Our web server keeps request logs as described above; those logs are rotated and deleted on a rolling basis.

If we later add privacy-respecting analytics or a cookie that is not strictly necessary, we will ask for consent first and update this section before it goes live.

How we share information

We share personal data only with parties who need it to help us run the business, and only under contract:

  • Infrastructure and hosting providers that run our website, email, and storage.
  • Messaging and communication platforms, including Meta Platforms for WhatsApp Business messaging.
  • Professional advisers — our accountants, auditors, and lawyers, where they need the data to advise us.
  • Authorities, where we are required to disclose by law, a court order, or a lawful government request, or where disclosure is necessary to protect someone's safety or our legal rights.
  • A successor entity in a merger, acquisition, or restructuring — in which case this policy continues to apply to the transferred data until you are told otherwise.

Every processor we use is bound to process the data only on our instructions, to keep it confidential, and to apply appropriate security measures.

Data we process on behalf of clients

When we build or operate software for a client, we may access that client's production data — including personal data about their own customers — in order to develop, migrate, debug, or support the system.

In that work we act as a processor (a Data Processor under the DPDP Act): the client decides what is collected and why, and we act only on their documented instructions under a services agreement or data processing addendum. We use production data only where a copy or synthetic dataset will not do, we access it under least-privilege credentials, and we delete or return our working copies at the end of the engagement.

If you are a customer of one of our clients and want your data accessed, corrected, or deleted, please contact that company directly — they control it. If you contact us instead, we will pass the request on to them and tell you we have done so.

How long we keep data

We keep data no longer than the purpose requires:

  • Enquiries that do not become projects — up to 24 months, then deleted.
  • Messaging conversations (including WhatsApp) — up to 24 months after the last message, unless they form part of a live engagement.
  • Client project records and contracts — for the life of the engagement and then as long as limitation periods and Indian tax law require, currently up to 8 years for financial records.
  • Job applications — 12 months from the decision, unless you ask us to keep them on file.
  • Server logs — rotated within 90 days.

When a retention period ends, data is deleted or irreversibly anonymised. Backups are purged on their own cycle, which may take up to a further 90 days.

How we protect data

We apply the measures appropriate to a studio of our size and to the sensitivity of what we hold: TLS on everything served over the public internet, encryption at rest for backups and credentials, access on a least-privilege basis with multi-factor authentication on the accounts that matter, separate environments for development and production, and secrets kept out of source control.

No system is perfectly secure. If a breach affects your personal data, we will notify the Data Protection Board of India and any other regulator we are required to notify, and we will tell affected people without undue delay, describing what happened and what to do about it.

Your rights

Subject to the law that applies to you, you may ask us to:

  • Confirm and access — tell you whether we hold data about you and give you a copy with a summary of how it is processed.
  • Correct — fix data that is inaccurate, misleading, or incomplete.
  • Erase — delete data we no longer need (see section 12).
  • Withdraw consent — where we rely on consent, withdraw it at any time; this does not undo processing already carried out.
  • Object or restrict — object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
  • Port — receive the data you gave us in a structured, machine-readable format, where that right applies.
  • Nominate — under the DPDP Act, nominate someone to exercise these rights on your behalf if you die or become incapacitated.

Write to softodoorllp@gmail.com and we will respond within 30 days. We may ask you to verify your identity first — usually by replying from the address or messaging from the number the data is associated with — so that we do not disclose your data to someone else.

If you are unhappy with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the UK or EU.

How to request deletion of your data

You can have the personal data we hold about you deleted at any time. There is no form and no account to sign into:

  • Email softodoorllp@gmail.com with the subject line data deletion request, or send us a WhatsApp message from the number you contacted us on saying you want your data deleted.
  • Tell us which identifier to search on — the email address, phone number, or WhatsApp number you used. We do not need anything else.
  • We will confirm receipt, verify that the request comes from you, and delete the data within 30 days. That includes your enquiry records, your WhatsApp and email conversation history, and any contact details we hold for you.
  • We will then confirm in writing that the deletion is done, and list anything we had to keep — for example an invoice we are legally required to retain for tax purposes, which we will keep only for that purpose and nothing else.
  • Residual copies in encrypted backups are purged on the backup rotation, within a further 90 days.

If the data you want deleted sits inside a product we run for one of our clients, see section 8 — the client controls that data, and we will forward your request to them.

International transfers

We are based in India and our data is primarily stored in India and the European Union. Some of the providers we rely on — hosting, email, and messaging platforms — may process data in other countries.

Where personal data moves out of the UK or EEA, we rely on the UK/EU Standard Contractual Clauses or an adequacy decision, and we require the provider to apply equivalent protection. We do not transfer data to any territory that the Government of India has restricted under the DPDP Act.

Children's privacy

Our website and services are meant for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18, and we do not carry out behavioural advertising or tracking directed at children.

If you believe a child has given us personal data, write to softodoorllp@gmail.com and we will delete it.

Third-party links and services

This site may link to other websites — a client's product, a partner, a platform we mention. We do not control those sites and we are not responsible for their privacy practices. Read their policies before you give them data.

Changes to this policy

We update this policy when what we do with data changes, or when the law does. The “last updated” date at the top of the page always reflects the current version.

If a change materially affects how we use data you have already given us, we will tell you directly — by email or on the channel you contacted us on — before it takes effect.

Contact and grievance officer

Questions, requests, and complaints about privacy all go to the same place. Our grievance officer under the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules can be reached at:

Grievance Officer, Softodoor LLP

Street No. 17, opposite Manav Palace Apartment, Somana Society, Chandreshnagar, Rajkot, Gujarat 360004.

Email: softodoorllp@gmail.com

Phone: +91 9104670250

Phone: +91 9898878708

We acknowledge every privacy request within 72 hours and resolve it within 30 days.