PRIVACY POLICY

Effective Date: August 9, 2026

Last Updated: August 8, 2026

 

1. Introduction

SiliconStream Technology ("SiliconStream", "Company", "we", "us", "our") provides IT services, custom software development, web and mobile application development, UI/UX design, cloud and DevOps services, AI/ML development and integration, SaaS products, and related technology consulting (collectively, the "Services"). We also publish and operate our own software products and applications, including SilicoSchool and SilicoCare (each, a "Product").

This Privacy Policy explains how we collect, use, disclose and safeguard personal information when you visit our website at siliconstreamtechnology.com (the "Website"), use one of our Products, engage us for Services, or otherwise interact with us.

We are based in Varanasi, Uttar Pradesh, India, and we serve clients and users worldwide. Because of this, more than one data protection law may apply to you depending on where you are located. This Policy is written to address our obligations under the Digital Personal Data Protection Act, 2023 of India (the "DPDP Act"), the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and comparable United States state privacy laws, and other applicable data protection legislation. Where a specific law gives you rights beyond those described generally in this Policy, the relevant additional rights are set out in Sections 20 to 22.

Please read this Policy together with our Terms and Conditions, which govern your use of the Website, Services and Products.

2. Scope of This Policy

This Policy applies to:

       visitors to the Website;

       prospective, current and former clients who engage us for Services;

       individuals who use a Product that we publish and operate, including registered account holders;

       individuals who communicate with us through contact forms, email, telephone, messaging apps or scheduling tools; and

       individuals whose personal information is provided to us by a client in connection with a project (see Section 19).

This Policy does not apply to:

       software, applications or platforms that we build for a client, where the client operates the resulting product under its own privacy policy and determines how personal data is used — in those cases the client is the controller or Data Fiduciary and you should refer to the client's privacy policy; or

       third-party websites, platforms and services linked from the Website or integrated into a Product (see Section 26).

3. Our Role: When We Decide, and When We Follow Instructions

As a controller / Data Fiduciary. We determine the purposes and means of processing for: information collected through the Website; information about our clients and business contacts; information collected from users of our own Products; and our internal business operations. This Policy describes that processing.

As a processor / Data Processor. When we deliver Services, we frequently process personal data on behalf of a client and on that client's documented instructions. In those cases the client determines the purposes of processing and is responsible for the lawfulness of the data and for providing notice to the affected individuals. Our processing is governed by the applicable Statement of Work and, where required, a separate Data Processing Agreement. If you are an individual whose data was given to us by one of our clients, please direct your requests to that client in the first instance; we will assist them in responding.

4. Information We Collect

4.1 Information you provide directly

Name, email address, telephone number, company name, job title, postal address, billing and invoicing details, project requirements, and the content of any message, enquiry or document you send us.

4.2 Information collected automatically

IP address, browser type, device identifiers, device and operating system information, language and time zone, pages viewed, time spent, click behaviour, referring URL, and crash and diagnostic data.

4.3 Information collected through our Products

Where you use a Product, we may additionally collect: account registration details and hashed passwords; in-product activity and feature usage; content you create, upload or share within the Product; device permissions you grant (such as camera, microphone, photo library, contacts or location) — each only where you enable it and only for the stated feature; push notification tokens; mobile advertising identifiers where applicable; and purchase or subscription status received from an app store. You can withdraw any device permission at any time through your device settings, although some features may then stop working.

4.4 Project and communication records

Shared documents, requirement specifications, emails, chat messages, support tickets, meeting notes and call records, retained so our team can understand and deliver against your requirements.

4.5 Information provided by clients

Business data, sample or test data sets, end-user records and credentials to third-party systems, shared with us so we can perform the Services.

4.6 Information from third parties

We may receive information from scheduling tools, payment processors, cloud and hosting providers, analytics providers, app stores, CRM and accounting software, and publicly available business sources.

4.7 Sensitive personal information

We collect financial, biometric, health, government identifier or similar sensitive information only where a specific engagement or feature genuinely requires it, only with the explicit consent of the relevant individual or on the documented instruction of the client responsible for that data, and only for the stated purpose. We do not use sensitive personal information for advertising, profiling or any purpose beyond that for which it was provided.

Health data and regulated data. We do not accept protected health information subject to the United States Health Insurance Portability and Accountability Act ("HIPAA"), cardholder data subject to PCI DSS, or comparable regulated data unless the parties have first executed the appropriate agreement (such as a Business Associate Agreement) and the required technical and organisational safeguards are in place. Clients must not transmit such data to us outside those arrangements.

5. How We Collect Information

We collect information through Website forms including contact and consultation requests; direct communication such as calls, emails and messaging apps; client onboarding, proposals, statements of work and kickoff meetings; your use of a Product or a client portal we operate; cookies and analytics technologies (see Sections 12 and 13); and third-party services we use to run our business.

6. How We Use Personal Information

We use personal information to:

       provide, deliver, operate and manage the Services and the Products;

       create and administer accounts and authenticate users;

       manage client relationships, including proposals, contracts and account administration;

       process payments, invoices and subscriptions;

       respond to enquiries and provide customer and technical support;

       communicate about projects, including status updates, change requests and deliverables;

       send service, security and transactional notifications;

       maintain the security of our Website, systems, Products and Services, and detect and prevent fraud, abuse and misuse;

       debug, fix errors and improve our Services, Products and internal processes;

       analyse Website and product usage;

       send marketing and promotional communications where legally permitted and, where required, with your consent (see Section 25); and

       comply with legal, tax, accounting and regulatory obligations, and establish, exercise or defend legal claims.

We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising as those terms are defined under United States state privacy laws. We have not done so in the preceding twelve months.

7. Artificial Intelligence and Machine Learning

We build AI and machine learning features for clients and may use AI-assisted tools internally. We want to be clear about what this means for your data:

       We do not use client project data, Confidential Information or personal data received from clients to train general-purpose or foundation models, and we do not permit our subprocessors to do so, unless the client has expressly agreed in writing.

       Where a client engages us to train or fine-tune a model on the client's own data, that model and its outputs are handled under the applicable Statement of Work, and the client remains responsible for the lawfulness of the training data.

       Where a Product uses AI features, we will describe in the Product what data is processed, whether any third-party AI provider is involved, and what choices you have.

       Where we use third-party AI services, we select providers that contractually commit not to train on our submitted data.

8. Legal Bases for Processing (EEA and United Kingdom)

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases:

 

Purpose

Legal basis

Delivering Services and Products you or your organisation requested

Performance of a contract, or steps taken at your request before entering a contract

Account creation, support and service communications

Performance of a contract

Security, fraud prevention and system integrity

Legitimate interests in protecting our business and users

Product improvement and analytics

Legitimate interests, or consent where required for non-essential cookies

Direct marketing to business contacts

Legitimate interests, or consent where required by local law

Non-essential cookies and optional marketing emails

Consent

Sensitive personal data

Explicit consent, or another condition under Article 9 GDPR

Tax, accounting and regulatory record-keeping

Compliance with a legal obligation

 

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you may object to that processing as described in Section 20.

9. Consent and Withdrawal of Consent

Where we rely on your consent, we will request it clearly and separately from other terms, and we will tell you what you are consenting to. You may withdraw consent at any time by contacting us using the details in Section 29, by using the unsubscribe link in a marketing email, or through the preference controls in a Product. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and we may continue processing where another lawful basis applies. If you are in India, you may withdraw consent with the same ease with which it was given, and you may exercise your rights through a Consent Manager registered with the Data Protection Board of India once that mechanism is operational.

10. Data Sharing and Disclosure

We may disclose personal information to:

       service providers and subprocessors who perform functions on our behalf (see Section 11);

       our clients, where we process data on their behalf as part of an engagement;

       professional advisors such as accountants, auditors, insurers and lawyers, where necessary;

       government, regulatory or law enforcement authorities, where required by law or legal process, or where necessary to protect our rights, property or safety or that of others. Where lawfully permitted, we will notify affected clients before responding to such a request;

       a successor entity, in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to confidentiality protections and continued application of this Policy; and

       other parties with your consent or at your direction.

11. Service Providers and Subprocessors

We engage third-party vendors to support our operations, which may include cloud hosting and infrastructure providers, communication and scheduling tools, project management and collaboration software, analytics providers, payment processors, customer support platforms, email delivery services and IT security tools. These providers process personal information only as necessary to perform their functions for us, under written contracts imposing confidentiality and data protection obligations, and are not permitted to use it for their own purposes. A current list of subprocessors used for a specific engagement is available to that client on request.

12. Cookies and Tracking Technologies

The Website uses cookies and similar technologies such as tags, SDKs and local storage to enable core functionality, remember preferences, understand how visitors use the Website, and support analytics and, where applicable, advertising. The categories we may use are strictly necessary, functional, performance and analytics, and advertising cookies.

Where required by law, we request your consent before placing non-essential cookies and provide a mechanism to review and change your preferences at any time. You can also control cookies through your browser settings, though disabling them may affect functionality.

Global Privacy Control. Where your browser or extension transmits a Global Privacy Control or similar opt-out preference signal, we treat it as a valid request to opt out of any sale or sharing of personal information for that browser.

13. Analytics and Third-Party Tools

We use third-party analytics and product measurement providers to understand how the Website and Products are used. These providers may collect information about your device and usage patterns under their own privacy policies. Where required, we deploy them only after obtaining consent, and we configure them to limit data collection where such controls are available.

14. Payments

Payments are handled by third-party payment processors. We do not collect or store complete payment card numbers on our own systems. Payment processors handle payment data under their own privacy and security practices and applicable card scheme rules. Where a Product is purchased through an app store, the app store processes the transaction and we receive only confirmation of purchase and subscription status.

15. International Data Transfers

We are based in India and use service providers located in other countries. As a result, personal information may be transferred to, stored in and processed in countries other than the one in which it was collected, including countries whose data protection laws differ from those of your home jurisdiction.

Where we transfer personal data out of the EEA or the United Kingdom, we rely on an appropriate safeguard recognised under applicable law, which will ordinarily be the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supplemented by additional technical and organisational measures where our transfer risk assessment indicates they are needed. Transfers from India are made in accordance with the DPDP Act and any restrictions notified by the Government of India. You may request a copy of the relevant safeguards by contacting us using the details in Section 29.

16. Data Security

We implement administrative, technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration and destruction. These include role-based access controls, encryption of data in transit, encryption at rest for systems that support it, hashed storage of passwords, network and endpoint protection, logging and monitoring, secure development practices, vendor due diligence, and confidentiality obligations and security training for personnel.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim certification to any specific security standard such as ISO/IEC 27001 or SOC 2 unless we have actually obtained that certification and can produce the report on request.

17. Data Retention

We retain personal information only for as long as necessary for the purposes described in this Policy, and then delete or irreversibly anonymise it. Indicative retention periods are:

 

Category of information

Indicative retention period

Website enquiry and contact form submissions

24 months from last contact, unless a client relationship begins

Client project records, contracts and deliverables

Duration of the engagement plus 3 years

Invoices, tax and accounting records

8 years, or as required by applicable tax law

Product account data

Duration of the account plus 90 days after closure

User content within a Product

Deleted within 30 days of account closure, subject to backups

Backups and disaster recovery copies

Overwritten on a rolling cycle, not exceeding 90 days

Marketing contact data

Until you unsubscribe, plus a suppression record retained to honour your opt-out

Security, access and audit logs

12 months

Data processed on behalf of a client

As directed by the client in the applicable agreement; returned or deleted on termination

 

We may retain information for longer where required to comply with a legal obligation, or to establish, exercise or defend legal claims, in which case we restrict processing to those purposes.

18. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling for that purpose. If this changes, we will update this Policy, tell you the logic involved and the consequences for you, and provide the safeguards required by applicable law, including the right to obtain human review.

19. Client Responsibilities

Where a client provides us with personal information about the client's own employees, customers or other individuals, the client represents and warrants that it has the legal right and any necessary consents to share that information with us, that it has provided appropriate notices to the affected individuals, and that its instructions to us comply with applicable law. Clients must not send us more personal data than an engagement requires, and should use anonymised or synthetic data for testing wherever practicable.

We process such data only as reasonably necessary to perform the Services, in accordance with the applicable Statement of Work and, where executed, a Data Processing Agreement. On termination of an engagement we will return or delete that data at the client's election, except where retention is required by law.

20. Your Privacy Rights

Depending on your location and applicable law, you may have some or all of the following rights in relation to your personal information:

       Access — confirmation of whether we process your data and a copy of it, together with information about the processing;

       Correction — rectification of inaccurate or incomplete information;

       Deletion — erasure of your personal information, subject to legal exceptions;

       Portability — a copy of certain information in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible;

       Restriction and objection — restriction of processing, or objection to processing based on legitimate interests, including objection to direct marketing at any time;

       Withdrawal of consent — at any time where processing is based on consent;

       Non-discrimination — we will not deny you services, charge you a different price or provide a lower quality of service because you exercised a privacy right; and

       Complaint — to lodge a complaint with a supervisory or data protection authority in your jurisdiction.

How to exercise your rights. Contact us using the details in Section 29. We will acknowledge your request promptly and respond within the period required by applicable law, which is generally one month under the GDPR and forty-five days under United States state privacy laws, each extendable where permitted if we tell you why. We may need to verify your identity before acting, and we will only use the information you provide for verification for that purpose. An authorised agent may submit a request on your behalf with proof of authorisation. There is no fee unless your request is manifestly unfounded or excessive.

21. Additional Rights — EEA and United Kingdom

If you are in the European Economic Area or the United Kingdom, the rights in Section 20 arise under Articles 15 to 22 of the GDPR. The controller is SiliconStream Technology, at the address in Section 29.

You may contact our representative on any matter relating to our processing of your personal data.

You have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the EEA, a list of authorities is available from the European Data Protection Board (edpb.europa.eu). We would appreciate the chance to address your concern before you approach a regulator.

22. Additional Rights — United States

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas or another state with a comprehensive privacy law, you have the rights described in Section 20 as provided by your state's law, including the right to know the categories of personal information we have collected, the sources, the business purposes, and the categories of third parties to whom we disclose it, as set out in this Policy.

We have not sold personal information, and have not shared personal information for cross-context behavioural advertising, in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under sixteen years of age.

We collect the categories of personal information identified in Section 4, which correspond to the statutory categories of identifiers, customer records, commercial information, internet and network activity, geolocation data, professional and employment information, audio and visual information from recorded calls and meetings, sensitive personal information where expressly provided, and inferences drawn from the foregoing. We use sensitive personal information only for the purposes permitted under the CCPA/CPRA, and you may direct us to limit its use as described in Section 20.

California residents may also request information under California's "Shine the Light" law regarding disclosure of personal information to third parties for their direct marketing purposes. If you wish to appeal a decision we make about your request, you may do so by writing to us at the address in Section 29; if we deny your appeal, you may contact your state Attorney General.

23. Additional Rights — India

If you are located in India, we process your personal data as a Data Fiduciary under the DPDP Act in respect of the Website, our Products and our own business operations, and as a Data Processor where we act on a client's instructions.

As a Data Principal you have the right to access a summary of your personal data and our processing of it, the right to correction, completion, updating and erasure, the right to withdraw consent, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of your death or incapacity. To exercise the right of nomination, or any other right, contact our Grievance Officer using the details in Section 29.

You are responsible for providing authentic information and for not impersonating another person or suppressing material information when exercising your rights. If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India.

24. Children's Privacy

Our Website, Services and Products are intended for individuals aged eighteen (18) or over. We do not knowingly collect personal information from children.

Where a Product is made available to a person under 18, we will do so only with the verifiable consent of a parent or legal guardian obtained as required by applicable law, and we will not undertake tracking, behavioural monitoring or targeted advertising directed at that person. We comply with the Children's Online Privacy Protection Act in the United States, the applicable age of digital consent under the GDPR, and the requirements of the DPDP Act, which treats every individual under 18 as a child.

If we become aware that we have collected personal information from a child without the required consent, we will delete it promptly. Parents or guardians who believe a child has provided us with personal information should contact us using the details in Section 29.

25. Marketing Communications

We may send marketing communications about our Services and Products where permitted by law, based on your consent or our legitimate interest in marketing to existing business contacts. You may opt out at any time using the unsubscribe link in any marketing email or by contacting us directly. Opting out does not affect transactional or service-related communications necessary to deliver the Services or operate your account.

26. Third-Party Websites and Links

The Website and our Products may contain links to third-party websites, social media pages and services, including portfolio case studies referencing client websites. We are not responsible for the privacy practices or content of those third parties, and we encourage you to review their privacy policies.

27. Security Incidents and Breach Notification

If a security incident compromises the confidentiality, integrity or availability of personal information we hold, we will investigate, contain and remediate it, and will notify affected individuals, our clients and the relevant regulators where and within the timeframes required by applicable law.

In particular, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act; report qualifying cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within twenty-four hours of becoming aware of them, in accordance with its directions; notify the competent supervisory authority within seventy-two hours where the GDPR applies and the incident is likely to result in a risk to individuals; and notify our clients without undue delay where the incident affects data we process on their behalf, so that they can meet their own obligations.

28. Changes to This Policy

We may update this Policy to reflect changes in our practices, Services, Products or legal requirements. We will post the updated Policy on the Website with a revised "Last Updated" date. Where changes are material, we will provide additional notice by email or a prominent Website or in-product notice before they take effect and, where required by law, obtain your consent. Continued use of the Website, Services or Products after the changes take effect constitutes acceptance of the updated Policy to the extent permitted by law.

29. Contact Us

If you have questions about this Policy or wish to exercise your rights, please contact us:

SiliconStream Technology

Rameshwar, Varanasi, Uttar Pradesh, India – 221405

Email: info@siliconstreamtechnology.com

Telephone: +91 94525 11318

 

Grievance Officer (India)

Name: Anil Maurya

Designation: Administrator, SiliconStream Technology

Email: people@siliconstreamtechnology.com

Address: Rameshwar, Varanasi, Uttar Pradesh, India – 221405

We will acknowledge a grievance within twenty-four (24) hours of receipt and endeavour to resolve it within fifteen (15) days, or sooner where required by law.

 

This Privacy Policy is effective as of August 9, 2026 and was last updated on August 8, 2026.