Transparency in security, privacy, and compliance
At Clepto.io, we believe trust is earned through transparency, robust security practices, and unwavering commitment to data protection. This Trust Center provides comprehensive information about how we protect your data and maintain compliance with global privacy regulations.
GDPR (EU) โข DPDP Act (India) โข Privacy Best Practices
AES-256 Encryption โข TLS 1.2+ โข Role-Based Access Control
Every workflow execution logged for 3 years minimum
Primary data stored in EU โข Optional EU-only processing
Complete visibility into all third-party providers
Rapid incident response and communication
Comprehensive policies covering data collection, processing, and your rights under GDPR and Indian DPDP Act 2023.
Complete list of all third-party service providers we use, including AI providers, hosting, and infrastructure.
GDPR-compliant Data Processing Agreement for clients, including EU Standard Contractual Clauses and comprehensive security measures.
We are working toward industry-standard security certifications as we scale.
ISO 42001 framework-aligned practices โข GDPR-ready infrastructure โข Security best practices
ISO 27001 (Information Security) โข ISO 42001 (AI Management Systems)
SOC 2 Type II (for US enterprise clients) โข Annual penetration testing
Under GDPR and Indian DPDP Act, you have comprehensive rights over your personal data.
Request a copy of all personal data we hold about you
Correct any inaccurate or incomplete data
Request deletion of your personal data ("right to be forgotten")
Receive your data in machine-readable format
Object to processing based on legitimate interests
Limit how we use your data in certain circumstances
To exercise any of these rights, contact us at:
privacy@clepto.ioWe will respond within 30 days (GDPR) or as required by applicable law
We process data across multiple jurisdictions with appropriate safeguards.
Our Location
Registered and headquartered in Pune, Maharashtra
Primary Data Storage
Supabase (EU), Hostinger (UK), Mistral AI (France)
No Cross-Border TransferAI Providers (Optional)
OpenAI, Anthropic, Google (only if selected)
SCCs + TIAEU Commission-approved contracts with all US providers
Risk analysis for each US provider (Schrems II compliance)
Data encrypted in transit, only necessary data transferred
Clients can choose to use only EU-based providers (Mistral AI)
Our commitment to transparency includes rapid communication in case of security incidents.
Immediate identification through monitoring systems or reports
Stop the incident from spreading within minutes
Within 24 hours of becoming aware
Root cause analysis and impact assessment
Within 72 hours if required by GDPR
Fix vulnerabilities and implement preventive measures
Report a Security Concern:
privacy@clepto.ioCIN: U62013PN2025PTC248011
SNO.107-108, PT-B, ROSEWOOD, SFL-J-603, PIMPLE SAUDAGAR
Sangavi, Pune-411027, Maharashtra, India