Privacy Policy
Version 1.0 · Effective 20 September 2026
SiliBlue India (“we”, “us”) is a Data Fiduciary under the Digital Personal Data Protection Act, 2023. This notice explains what personal data we collect through siliblue.in, why we collect it, how long we keep it and how you can exercise your rights. We collect personal data only when you share it with us through our forms; we run no advertising trackers on this site.
Data Protection & DPDP Compliance
We are actively aligning our systems with India’s Digital Personal Data Protection (DPDP) Act, 2023, and the DPDP Rules, 2025. While full statutory enforcement for operational compliance is mandated by 13 May 2027, we have already implemented core security safeguards and Data Principal rights to protect your personal data.
1. Personal data we collect
We collect only what you type into our forms:
- Let's Talk form: your name, email address, what you tell us you're working on, and the service you pick. This is used for one purpose: to reply to your enquiry.
- SiliBlue forms (pages at /form/…): whatever the specific form asks for (for example contact details, a message, or files you attach). Each form states its own purpose at the top.
- Email address: if you email us directly, we use it to respond and keep a record of the conversation.
- IP address (transient): used for a few seconds to rate-limit form spam and abuse. It is not written to our database or shared.
You are not required to provide any of the above, but if you choose not to, we may not be able to respond to your enquiry.
2. Notice and consent
Every form on this site asks for your consent, with a clear and specific description of what will happen, before anything is sent to us. On the Let's Talk form the consent box is on the first step, so you cannot move forward without it; on every other form it sits just above the submit button. Consent is always a free, informed, unambiguous action: ticking the consent box. We record the exact time you consented with your submission as proof.
You may withdraw consent at any time (see section 5). Withdrawal is as easy as giving it, and we will stop processing for the purpose you withdraw, without affecting anything lawfully done before.
3. Cookies: strictly necessary only
This site sets no advertising, analytics or third-party tracking cookies. The only cookies we use are strictly necessary:
- One session cookie used only for signed-in site administration (an internal team tool). It is never set for ordinary visitors, contains no personal data about you, and expires when the administration session ends.
- Local browser storage (
siliblue:route, the privacy-notice acknowledgement): remembers which page you were on and that you have seen this notice. Stays on your device; we never read it back on our servers.
4. How long we keep data (retention)
- Enquiries and form responses: kept up to 24 months after our last contact, then deleted.
- Uploaded files: deleted with the form response they belong to.
- Email correspondence: kept up to 36 months for legal and audit purposes.
- Transient rate-limit data (IP addresses): discarded within the hour.
We erase data sooner on request when it is no longer needed for the purpose collected (see your rights below).
5. Your rights (Data Principal rights)
Under the DPDP Act you can ask us to:
- Access: get a summary of the personal data we hold about you and how we process it.
- Correct & complete: fix inaccurate or incomplete personal data.
- Erase: have your personal data deleted once the purpose is served or you withdraw consent.
- Withdraw consent: stop future processing for any purpose you earlier consented to.
- Nominate: name another person who can exercise these rights on your behalf if you are unable to.
- Grieve: complain to our Grievance Officer, and to the Data Protection Board of India if unresolved.
To exercise any right, email the Grievance Officer below from the address you used with us. There is no fee and no form-filling; a plain description of what you want is enough. We acknowledge within 48 hours and act within 30 days.
6. Grievance Officer
Our Grievance Officer is your single contact for privacy questions, rights requests and complaints:
Grievance Officer, SiliBlue India
We respond to every grievance within 48 hours and aim to resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.
7. How we protect your data
- All traffic is encrypted in transit (HTTPS/TLS, HSTS enforced).
- Personal data is stored in an access-controlled database on our secured infrastructure.
- Admin access is password-protected (salted-hash credentials), session-expiring and limited to authorised staff.
- Form spam protections (rate limiting, file-type checks) reduce abuse exposure.
- We follow least-privilege and review access whenever team responsibilities change.
8. If a breach ever happens
We maintain an incident-response process to contain and assess any personal data breach. Where a breach is likely to cause harm, we will notify affected Data Principals and the Data Protection Board of India without delay, in the manner prescribed under the DPDP Act.
9. Processors and third parties
We keep the circle small. Personal data you submit is stored on our own infrastructure and, for delivery of form alerts, processed on our behalf by our email provider under instruction from us. We do not sell personal data, and we never share it with advertisers. Where we engage a processor, we do so under a written agreement with DPDP-equivalent obligations.
10. Children
Our services are directed at businesses. We do not knowingly collect the personal data of children (under 18, or persons under legal guardianship). If you believe a child has submitted data to us, tell the Grievance Officer and we will erase it promptly.
11. Updates to this notice
We may update this notice as our services or the DPDP rules evolve. The version and effective date at the top always reflect the current notice; material changes will be highlighted on this page.
Questions about this notice? Email [email protected], or use the Let's Talk form.
