Satej Infotech Pvt Ltd is a private limited company registered in India. We are a digital transformation agency. We build websites, run digital marketing, provide business software, and operate messaging services for other businesses.
Registered office: Shop No. 219, First Floor, Keviz Plaza, Venus Corner, Station Road, Shahupuri, Kolhapur 416001, Maharashtra, India
Pune office: details available on request, Maharashtra, India
CIN: U72900PN2014PTC150117
GSTIN: 27AAUCS1147F1Z4
In this policy, "we", "us" and "our" mean Satej Infotech Pvt Ltd. "You" means the person whose personal data we handle.
This policy explains how we handle personal data in three different situations. The rules are different in each one, so please read the part that applies to you.
Situation A. You visit our website or contact us. We decide why and how your data is used. Under the Digital Personal Data Protection Act 2023 we are the Data Fiduciary. Section 4 applies.
Situation B. You are our client. We hold your business and billing details so we can provide services to you. We are the Data Fiduciary for that information. Section 5 applies.
Situation C. You are a customer of one of our clients. For example, you messaged a clinic on WhatsApp, or you filled in an enquiry form on a shop's website that we built. Here, the business you contacted decides what happens to your data. We only handle it on their instructions. They are the Data Fiduciary. We are the Data Processor. Section 6 applies.
If you are in Situation C and you want your data corrected or deleted, the fastest route is to contact the business you dealt with. You can also contact us using the details in section 14 and we will pass your request on to them.
We do not sell personal data. We have never sold personal data and we do not intend to.
We do not use data belonging to one client to benefit another client.
We do not use messages, contact lists or customer records that we handle for a client for our own marketing, for building our own database, or for training any artificial intelligence system.
We rely on your consent, which you give by contacting us or by agreeing when you submit a form. Where we are meeting a legal obligation, such as keeping tax records, we rely on that.
You can withdraw your consent at any time. See section 8.
Where you give us access to your accounts, we use that access only to perform the work you have asked for. We keep credentials in restricted storage, limit access to the team members working on your account, and remove access when our engagement ends or when you ask us to.
This section matters most if you have dealt with a business that uses our services.
We act only on the instructions of the business you contacted. We store the data, pass it to that business, and provide the tools they use to reply to you.
We do not decide what your data is used for. That business does.
The business you contacted is responsible for your data. Please contact them first. If you cannot reach them, or you do not know who holds your data, write to us at the address in section 14 and we will help you identify them and forward your request.
This section applies where we provide WhatsApp messaging services to a business.
We provide WhatsApp Business Platform services to businesses as a technology provider.
When a business uses WhatsApp through us:
A business must have your permission before messaging you on WhatsApp through our platform. Our contract requires every client to obtain and keep records of that permission, and to comply with the WhatsApp Business Messaging Policy.
If you receive a message you did not agree to, reply STOP to that conversation, and tell us using the details in section 14. We will look into it and act.
WhatsApp and the platform behind it are operated by Meta. Meta handles data under its own terms and its own privacy policy, which are separate from this one and outside our control. You can read them at whatsapp.com/legal.
To deliver messaging services we may handle your phone number, your WhatsApp profile name, message content, delivery and read status, and the time messages were sent. This is stored in the systems described in section 9 and is available to the business you are messaging.
Under the Digital Personal Data Protection Act 2023, you have the following rights over personal data for which we are the Data Fiduciary.
Right to information. You can ask what personal data of yours we hold, what we do with it, and who we have shared it with.
Right to correction and completion. You can ask us to correct data that is wrong, complete data that is missing, or update data that is out of date.
Right to erasure. You can ask us to delete your personal data, unless we are required by law to keep it.
Right to withdraw consent. You can withdraw your consent at any time. Withdrawing it does not affect anything done before you withdrew it. After you withdraw, we stop processing unless another lawful basis applies.
Right to grievance redressal. You can complain to us about how we have handled your data. Our contact details are in section 14.
Right to nominate. You can nominate another person to exercise these rights on your behalf if you die or become unable to act.
Write to us at hello@satejinfotech.in, or use the postal address in section 14. Tell us which right you want to use and give us enough information to identify you.
We will respond within 30 days. If we need longer, we will tell you why.
If we do not resolve your complaint, you may complain to the Data Protection Board of India.
We share personal data only where it is needed to run the service. Our service providers are bound to protect it and to use it only for the purpose we give them.
| Who | What for |
|---|---|
| Meta Platforms and WhatsApp | WhatsApp Business Platform messaging, and advertising on Facebook and Instagram |
| Google Workspace, Google Ads, Google Analytics and Google Business Profile | |
| Licensed SMS gateway operators in India | Sending bulk SMS on behalf of clients |
| Email delivery providers | Sending bulk email on behalf of clients |
| Hosting and cloud providers | Running websites, BoostCRM and other systems |
| Payment gateway providers | Processing payments made to us |
| Professional advisers | Accountants, auditors and lawyers, where required |
If you want to know which specific provider handles a particular service, write to us at hello@satejinfotech.in and we will tell you.
We may also disclose personal data where the law requires it, where a court or government authority validly orders it, or to establish or defend a legal claim.
We do not sell personal data to anyone.
Some of the providers above store or process data outside India. Where that happens, we take reasonable steps to make sure the data stays protected to the standard set out in this policy and in Indian law.
Our website uses cookies. A cookie is a small text file placed on your device.
We use them for two purposes.
Essential cookies make the website work. They remember your session and your preferences. The site cannot function properly without them.
Analytics cookies help us understand how people use the site, such as which pages are visited and how long people stay. We use Google Analytics for this.
You can block or delete cookies in your browser settings. Some parts of the site may not work properly if you do.
We use reasonable security safeguards, including:
No system connected to the internet can be completely secure. We do not claim ours is. We do take the protection of your data seriously and we act quickly when something goes wrong.
If personal data we hold is compromised, we will inform every affected person without delay, in plain language, explaining what happened, what the likely effect is, what we have done about it, and who to contact. We will also notify the Data Protection Board of India as required.
Where the data belongs to one of our clients, we will inform that client immediately so they can meet their own obligations.
| Data | How long |
|---|---|
| Website enquiries that do not become clients | 24 months |
| Client business and billing records | 8 years from the end of the financial year, to meet Indian tax and company law requirements |
| Data we handle on behalf of a client | For the length of our engagement with that client, then deleted or returned as they instruct |
| WhatsApp message records | 12 months, unless the client instructs otherwise |
| Website analytics | 26 months |
When a retention period ends, we delete the data or make it anonymous.
Our services are for businesses. We do not knowingly collect personal data from anyone under 18 for our own purposes.
We do not carry out behavioural monitoring or targeted advertising directed at children.
Some of our clients are clinics and healthcare practices whose patients may include children. Where we handle such data on a client's behalf, that client is the Data Fiduciary and is responsible for obtaining verifiable consent from a parent or lawful guardian. This is set out in our written agreement with them.
If you believe we hold data about a child and it should not be held, tell us and we will act.
For any question about this policy, to exercise your rights, or to make a complaint:
Grievance Officer: Satej Parandekar, Director
Email: hello@satejinfotech.in
Phone: +91 9156044824
Post: Satej Infotech Pvt Ltd, Shop No. 219, First Floor, Keviz Plaza, Venus Corner, Station Road, Shahupuri, Kolhapur 416001, Maharashtra, India
We will acknowledge your message and tell you what we are doing about it.
We may update this policy. When we do, we will change the date at the top and publish the new version on this page.
Where a change materially affects how we use your personal data, and we rely on your consent, we will tell you and ask for your consent again.
This policy is governed by the laws of India, including the Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025. The courts at Kolhapur, Maharashtra have jurisdiction.