๐Ÿ”’ Trust Center

Transparency in security, privacy, and compliance

Our Commitment to Trust

At Clepto.io, we believe trust is earned through transparency, robust security practices, and unwavering commitment to data protection. This Trust Center provides comprehensive information about how we protect your data and maintain compliance with global privacy regulations.

Security & Compliance at a Glance

๐ŸŒ

Multi-Jurisdictional Compliance

GDPR (EU) โ€ข DPDP Act (India) โ€ข Privacy Best Practices

๐Ÿ”

Enterprise-Grade Security

AES-256 Encryption โ€ข TLS 1.2+ โ€ข Role-Based Access Control

๐Ÿ“Š

Full Audit Trails

Every workflow execution logged for 3 years minimum

๐Ÿ‡ช๐Ÿ‡บ

EU Data Residency

Primary data stored in EU โ€ข Optional EU-only processing

๐Ÿ‘๏ธ

100% Sub-Processor Transparency

Complete visibility into all third-party providers

โšก

24-Hour Breach Notification

Rapid incident response and communication

Compliance Documentation

โœ“ Complete

Privacy & Cookie Policies

Comprehensive policies covering data collection, processing, and your rights under GDPR and Indian DPDP Act 2023.

โœ“ Complete

Sub-Processor Transparency

Complete list of all third-party service providers we use, including AI providers, hosting, and infrastructure.

Featured Providers:

  • Supabase (EU) - Database hosting with EU data residency
  • Hostinger (UK) - Website and application hosting
  • Mistral AI (France) - EU-only AI provider option
  • OpenAI, Anthropic, Google - AI language models with SCCs
๐Ÿ“ง Available on Request

Data Processing Agreement (DPA)

GDPR-compliant Data Processing Agreement for clients, including EU Standard Contractual Clauses and comprehensive security measures.

โœ“ EU Standard Contractual Clauses (SCCs)
โœ“ Transfer Impact Assessments for US providers
โœ“ Security measures documentation (Annex II)
โœ“ Data subject rights assistance procedures
โœ“ Sub-processor management framework
โœ“ Incident response and breach notification
Request DPA
๐Ÿšง Roadmap

Security Certifications

We are working toward industry-standard security certifications as we scale.

โ—
Current (2025)

ISO 42001 framework-aligned practices โ€ข GDPR-ready infrastructure โ€ข Security best practices

โ—‹
2026 Target

ISO 27001 (Information Security) โ€ข ISO 42001 (AI Management Systems)

โ—‹
2027 Target

SOC 2 Type II (for US enterprise clients) โ€ข Annual penetration testing

Security Architecture

๐Ÿ” Data Protection

  • Hosting: Hostinger VPS (Ireland)
  • Database: PostgreSQL with encrypted storage on Hostinger VPS
  • Encryption in Transit: TLS 1.2/1.3 HTTPS (all connections encrypted)
  • Access Control: Role-based access controls
  • Authentication: Secure password requirements with bcrypt hashing
  • Backups: Regular encrypted backups by Hostinger

๐Ÿ‘ฅ Access Control

  • Role-Based Access (RBAC): Minimum necessary access
  • Multi-Factor Authentication: Required for admin access
  • Strong Passwords: 12+ characters, complexity requirements
  • Access Logging: All access to personal data logged

๐Ÿ“Š Monitoring & Logging

  • Comprehensive Audit Logs: Every workflow execution tracked
  • Security Monitoring: 24/7 monitoring for anomalies
  • Log Retention: Minimum 3 years for compliance
  • Immutable Logs: Cannot be altered after creation

๐Ÿ”„ Business Continuity

  • Daily Backups: Automated, encrypted, geographically distributed
  • Disaster Recovery: RPO < 24 hours, RTO < 48 hours
  • Redundancy: Multi-availability zone architecture
  • Backup Testing: Monthly restoration tests

๐Ÿ›ก๏ธ Organizational Security

  • Security Training: Regular staff training on data protection
  • Confidentiality: All team members bound by NDAs
  • Incident Response: Documented procedures, 24-hour notification
  • Vendor Management: Security assessment of all sub-processors

๐Ÿ” Compliance Controls

  • Data Minimization: Collect only necessary data
  • Privacy by Design: Privacy built into workflow design
  • Data Retention: Automated deletion after retention period
  • Client Data Isolation: Multi-tenant architecture with separation

Your Data Rights

Under GDPR and Indian DPDP Act, you have comprehensive rights over your personal data.

๐Ÿ“‹

Right to Access

Request a copy of all personal data we hold about you

โœ๏ธ

Right to Rectification

Correct any inaccurate or incomplete data

๐Ÿ—‘๏ธ

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

๐Ÿ“ฆ

Right to Data Portability

Receive your data in machine-readable format

๐Ÿšซ

Right to Object

Object to processing based on legitimate interests

โธ๏ธ

Right to Restriction

Limit how we use your data in certain circumstances

Exercise Your Rights

To exercise any of these rights, contact us at:

privacy@clepto.io

We will respond within 30 days (GDPR) or as required by applicable law

International Data Transfers

We process data across multiple jurisdictions with appropriate safeguards.

๐Ÿ‡ฎ๐Ÿ‡ณ India

Our Location

Registered and headquartered in Pune, Maharashtra

โ†’

๐Ÿ‡ช๐Ÿ‡บ European Union

Primary Data Storage

Supabase (EU), Hostinger (UK), Mistral AI (France)

No Cross-Border Transfer
โ†’

๐Ÿ‡บ๐Ÿ‡ธ United States

AI Providers (Optional)

OpenAI, Anthropic, Google (only if selected)

SCCs + TIA

Transfer Safeguards:

โœ“
Standard Contractual Clauses (SCCs)

EU Commission-approved contracts with all US providers

โœ“
Transfer Impact Assessments

Risk analysis for each US provider (Schrems II compliance)

โœ“
Encryption & Minimization

Data encrypted in transit, only necessary data transferred

โœ“
EU-Only Option Available

Clients can choose to use only EU-based providers (Mistral AI)

Incident Response

Our commitment to transparency includes rapid communication in case of security incidents.

1

Detection

Immediate identification through monitoring systems or reports

2

Containment

Stop the incident from spreading within minutes

3

Client Notification

Within 24 hours of becoming aware

4

Investigation

Root cause analysis and impact assessment

5

Authority Notification

Within 72 hours if required by GDPR

6

Remediation

Fix vulnerabilities and implement preventive measures

Report a Security Concern:

privacy@clepto.io

Questions About Trust & Security?

๐Ÿ“ง Privacy Inquiries

Data protection, privacy rights, DPA requests

privacy@clepto.io

๐Ÿ”’ Security Questions

Security practices, compliance documentation

privacy@clepto.io

๐Ÿ“‹ Documentation Requests

DPA, security questionnaires, audit reports

privacy@clepto.io

CLEPTO.IO SERVICES PRIVATE LIMITED

CIN: U62013PN2025PTC248011

SNO.107-108, PT-B, ROSEWOOD, SFL-J-603, PIMPLE SAUDAGAR
Sangavi, Pune-411027, Maharashtra, India