🔒 Privacy Policy for Clepto.io

Effective Date: November 16, 2025
Last Updated: November 16, 2025
Company: CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Registered Address: SNO.107-108, PT-B, ROSEWOOD, SFL-J-603, PIMPLE SAUDAGAR, Sangavi, Pune-411027, Maharashtra, India
Privacy Contact: privacy@clepto.io

1. INTRODUCTION

Welcome to Clepto.io ("we," "us," "our," or "Clepto"). This Privacy Policy explains how CLEPTO.IO SERVICES PRIVATE LIMITED collects, uses, discloses, and protects information from visitors to our website and users of our services.

Our Commitment

We are committed to protecting your privacy and handling your personal information transparently in accordance with applicable data protection laws.

Who We Are

Applicable Laws

This policy is designed to comply with:

2. SCOPE OF THIS POLICY

What This Policy Covers

This Privacy Policy applies to:

What This Policy Does NOT Cover

This policy does not cover how we process data on behalf of our clients in their automation workflows. That relationship is governed by separate Data Processing Agreements (DPAs) where we act as a data processor. For information about that, please see our Data Processing Agreement.

3. INFORMATION WE COLLECT

3.1 Information You Provide Directly

Contact Forms

When you submit a contact form on our website, we collect:

Newsletter Subscriptions

When you subscribe to our newsletter, we collect:

Chat Interactions

When you interact with our AI chatbot (powered by n8n), we collect:

Purpose: We collect this information to respond to your inquiries, provide information about our services, send newsletters and updates (with your consent), improve our customer service, and analyze how visitors interact with our website.

Legal Basis (GDPR): Consent (when you submit forms or subscribe), Legitimate interests (analyzing website usage, improving services), Contract performance (when engaging with prospective clients)

Legal Basis (India DPDP Act): Consent for collection and processing of personal data

3.2 Information Collected Automatically

Website Analytics

We use Google Analytics to understand how visitors use our website. This collects:

Cookies and Similar Technologies

We currently use minimal cookies. In the future, we may implement:

When we implement cookie consent management, you will be able to accept or reject non-essential cookies through our cookie banner.

Purpose: This information helps us understand website traffic patterns, improve user experience, detect and prevent technical issues, and analyze marketing effectiveness.

Legal Basis (GDPR): Legitimate interests (website optimization, security)

Legal Basis (India DPDP Act): Legitimate business purpose

3.3 Information We Do NOT Collect

We do not knowingly collect:

4. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

Primary Purposes

Service Delivery

Communication

Website Improvement

Business Operations

Marketing (with consent)

We Do NOT:
  • Sell your personal information to third parties
  • Use your information for purposes incompatible with those described above
  • Share your information for third-party marketing without your explicit consent
  • Process your data in ways you wouldn't reasonably expect

5. HOW WE SHARE YOUR INFORMATION

5.1 Third-Party Service Providers (Data Processors)

We share information with trusted third-party service providers who help us operate our website and deliver services. These providers are contractually obligated to protect your information and use it only for specified purposes.

Current Service Providers

Provider Service Location Data Processed Safeguards
Supabase Database & backend infrastructure EU (Europe) Contact form data, newsletter subscriptions, chat logs EU-based servers, encryption at rest, GDPR-compliant
Hostinger Website hosting UK (Europe) Website files, server logs EU-based hosting, SSL/TLS encryption
Google Analytics Website analytics USA (with EU presence) Anonymized visitor data, usage patterns IP anonymization, data retention controls, GDPR settings enabled
n8n SMTP Automation Workflow Email communications (custom automation via n8n open-source platform) Hostinger VPS (Ireland/EU-based) Email addresses, newsletter preferences, message content, send timestamps, delivery status GDPR-compliant (EU-hosted), TLS/SSL encryption, data retained until unsubscribe + 30 days, no third-party sharing

AI Providers (for chatbot functionality)

Our n8n chatbot may use the following AI services:

Safeguards for International Transfers

When data is transferred outside India or the EU, we ensure appropriate safeguards:

5.2 Legal Requirements

We may disclose your information if required by law or in good faith belief that such action is necessary to:

Notice: Where legally permitted, we will notify you before disclosing your information in response to legal requests.

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

6. INTERNATIONAL DATA TRANSFERS

Our Location: We are based in India.

Where Your Data May Be Processed

Transfer Safeguards

For transfers outside India or the EU, we implement:

Your Rights: If you are in the EU, you have the right to obtain information about international transfers and request copies of the safeguards in place.

7. DATA RETENTION

How Long We Keep Your Information

Data Type Retention Period Reason
Contact form submissions 3 years from last contact Business relationship management, legal compliance
Newsletter subscriptions Until you unsubscribe + 30 days Marketing communications, unsubscribe processing
Chat logs 3 years Customer service improvement, dispute resolution
Website analytics 26 months (Google Analytics default) Usage analysis, trending
Billing/invoice data 7 years Tax and accounting compliance (Indian law)
Backups 90 days Disaster recovery, data integrity

Deletion: After the retention period expires, we securely delete or anonymize your information so it can no longer identify you.

Legal Holds: We may retain data longer if required by law, to resolve disputes, enforce agreements, or defend legal claims.

7.4 CLIENT DATA RETENTION FOR WORKFLOW DATA

This section applies when Clepto.io processes data in your automated workflows (different from Section 7.1-7.3 which covers website visitor data).

DURING YOUR CONTRACT (While You Use Clepto.io):

Why: Ensure your workflows operate continuously, enable disaster recovery, support workflow history and audit trails.

Your Control: Pause workflows to stop data collection, delete data within workflows manually, or request immediate deletion (contact: contact@clepto.io)

AFTER YOUR CONTRACT ENDS (When You Stop Using Clepto.io):

Timeline: Automatic deletion process

PHASE 1 (Days 1-30): Account Closure

PHASE 2 (Days 31-60): Data Deletion

PHASE 3 (Days 61+): Compliance Retention Only

HOW WE DELETE YOUR DATA:

EXCEPTIONS (We Retain Data Longer If):

HOW TO REQUEST DELETION IMMEDIATELY:

Email: contact@clepto.io

Subject: "Please Delete My Clepto Account and All Data"

Include: Your email address, Account ID (if known), Reason (optional)

We will:

No Penalty: Deletion can happen anytime during contract, no extra charges, no notice period required.

8. DATA SECURITY

Security Measures We Implement

Technical Safeguards

ENCRYPTION IN TRANSIT (Data Moving):

ENCRYPTION AT REST (Data Stored):

AUTHENTICATION & PASSWORD SECURITY:

ACCESS CONTROLS:

Regular Updates: Systems and software regularly updated with security patches

Organizational Safeguards

Third-Party Security

All service providers must meet our security standards and comply with contractual security obligations.

Limitation: While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of information transmitted over the internet.

Breach Notification: In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by law (within 72 hours for GDPR, as prescribed by Indian law).

9. YOUR RIGHTS AND CHOICES

9.1 Rights Under Indian DPDP Act 2023

If you are in India, you have the following rights:

9.2 Rights Under EU GDPR (for EU Visitors/Clients)

If you are in the European Union, you have additional rights:

EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en

9.3 How to Exercise Your Rights

STEP 1: SEND REQUEST EMAIL

Email: contact@clepto.io

Subject Line: "Data Access Request" OR "Data Deletion Request" OR "Data Correction Request"

Include in Your Email:

STEP 2: IDENTITY VERIFICATION (Takes 3-5 Business Days)

What We'll Do:

Why: To protect your privacy from bad actors and ensure only you can access or delete your data.

What You Should Do: Respond to our verification request promptly. Send verification via email to contact@clepto.io

STEP 3: DATA PROCESSING (Takes Up to 30 Days)

For Access Requests:

For Deletion Requests:

For Correction Requests:

For Portability Requests:

For Restriction Requests:

STEP 4: CONFIRMATION & COMPLETION

You Receive:

Timeline:

STEP 5: IF NOT SATISFIED - APPEAL TO REGULATOR

If you're unhappy with our response, you can complain to:

For EU Residents:

For India Residents:

For Ireland-Related Issues:

Important: Filing a complaint with a regulator does not prevent you from seeking legal remedies.

NO FEES: We do not charge for most data requests. Excessive or repetitive requests (same request 5+ times per year) may incur reasonable administrative fees ($25-50 USD).

9.4 Communication Preferences

Newsletter Unsubscribe

Every marketing email contains an "Unsubscribe" link. Click it to stop receiving newsletters immediately.

Cookie Preferences

When we implement cookies, you will be able to manage preferences via our cookie banner or by contacting privacy@clepto.io.

Do Not Track

Our website does not currently respond to "Do Not Track" browser signals, but you can disable cookies in your browser settings.

10. CHILDREN'S PRIVACY

Our services are not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18.

If We Learn: If we discover we have inadvertently collected information from a child under 18, we will delete it immediately.

Parental Notice: If you are a parent or guardian and believe your child has provided us with personal information, please contact privacy@clepto.io.

11. COOKIES AND TRACKING TECHNOLOGIES

Current Status

We currently use minimal cookies (primarily for website functionality and Google Analytics).

Future Cookie Use

We plan to implement the following cookie types:

Essential Cookies (Always Active)

Analytics Cookies (Requires Consent)

Marketing Cookies (Requires Consent)

Cookie Consent: Before implementing non-essential cookies, we will deploy a cookie consent banner allowing you to accept or reject them.

Cookie Policy: A detailed cookie policy will be published at clepto.io/cookies when we implement additional cookies.

Your Control

13. CHANGES TO THIS PRIVACY POLICY

Updates

We may update this Privacy Policy from time to time to reflect:

Notice of Changes

Your Acceptance: Continued use of our website after changes constitutes acceptance of the updated policy.

Archive: Previous versions available upon request at privacy@clepto.io.

15. DATA CONTROLLER AND PROCESSOR ROLES

When We Are the Data Controller

For information collected through our website (contact forms, newsletters, analytics), Clepto.io is the data controller. We determine the purposes and means of processing.

When We Are a Data Processor

When we build AI automation workflows for clients and process their customers' data, we are a data processor. Our clients are the data controllers.

Client Data Processing

Governed by separate Data Processing Agreements (DPAs) that define:

Contact for Client Workflow Data: If your data is being processed in a client's workflow, contact that client directly. We can only act on instructions from the client (the controller).

16. CROSS-BORDER DATA TRANSFERS - DETAILED SAFEGUARDS

India to EU/EEA

India to USA

EU to USA (for EU visitors)

Documentation Available: Copies of our SCCs and Transfer Impact Assessments available upon request at privacy@clepto.io (for legitimate requests only).

17. SPECIFIC PROCESSING DISCLOSURES

AI Chatbot (n8n-powered)

⚠️ IMPORTANT: ARTIFICIAL INTELLIGENCE DISCLOSURE

Our chatbot uses multiple AI models to provide customer support. Please be aware of the following:

AI MODELS WE USE:

LIMITATIONS OF AI YOU SHOULD KNOW:

OUR SAFEGUARDS:

YOUR RIGHTS & CONTROL:

PROCESSING DETAILS:

Questions about AI? Email contact@clepto.io

Google Analytics

Newsletter (Future Implementation)

18. AUTOMATED DECISION-MAKING

Current Status

We do not use automated decision-making with legal or similarly significant effects.

AI Chatbot

While our chatbot uses AI, it does not make decisions that legally affect you. It's purely informational.

Future Use

If we ever implement automated decision-making (e.g., credit scoring, hiring), we will:

19. SUPERVISORY AUTHORITIES AND COMPLAINTS

India

If you have complaints about our data practices in India:

European Union (for EU residents)

Ireland (for EU complaints related to Clepto)

Since some of our service providers are in the EU:

We Encourage Direct Contact: Before filing complaints with authorities, please contact privacy@clepto.io so we can resolve issues directly.

20. CONTACT US

For any questions, concerns, or requests regarding this Privacy Policy or your personal information:

Primary Contact

Company Details

General Inquiries

Response Time

21. EFFECTIVE DATE AND VERSION HISTORY

Version History: Available upon request at privacy@clepto.io

22. ACKNOWLEDGMENT

By using our website, submitting forms, subscribing to our newsletter, or engaging with our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

END OF PRIVACY POLICY