Privacy Policy
We take the privacy of your data seriously — it's the foundation of everything we do. This policy explains what we collect, why we collect it, how we protect it, and the rights you hold over it.
Overview
Stornox ("we", "us", "our") operates a geo-distributed cloud object storage platform accessible at stornox.com. This Privacy Policy governs how we collect, process, store, and protect personal data obtained through our website, platform, and associated services.
We are committed to transparency. We process personal data only for the purposes described in this policy, retain it only as long as necessary, and implement technical and organisational measures to keep it safe.
Who We Are
Data Controller: Stornox Technology Pvt. Ltd., registered in India.
For customers in the European Union, Stornox acts as a data processor with respect to files stored on the platform (under the data processing terms in your service agreement) and as a data controller for account and billing data.
Data We Collect
We collect only the personal data necessary to provide and improve our services. The categories are described below.
3.1 Account & Contact Data
- Full name, work email address, job title, company name
- Phone number (optional, for enterprise support tiers)
- Password (stored as a one-way bcrypt hash — never in plain text)
- Profile and account preferences
3.2 Billing & Payment Data
- Billing address, GST / PAN number (for Indian customers), VAT number (for EU customers)
- Payment method details — processed exclusively by our PCI-DSS compliant payment provider; Stornox does not store full card numbers
- Transaction records and invoice history
3.3 Usage & Technical Data
| Data Type | What We Collect | Purpose |
|---|---|---|
| Access Logs server-side |
IP address, timestamp, API endpoint, HTTP status code, latency | Security, abuse prevention, SLA monitoring |
| Storage Metrics platform |
Bytes stored, object count, bucket names, transfer volume | Billing, capacity planning, usage analytics |
| Device & Browser website |
Browser type, OS, screen resolution, referrer URL | Website analytics, compatibility |
| Session Data platform |
Authentication tokens (JWT), session ID, last active timestamp | Authentication, security |
3.4 Communication Data
- Emails, support tickets, and live chat transcripts you send us
- Demo request and contact form submissions
- Survey responses and product feedback
How We Use Your Data
We process personal data only where we have a lawful basis for doing so. Each purpose is described below with its corresponding legal basis.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and operate the platform | Account, usage, session data | Contract performance |
| Billing and payment processing | Billing, payment, usage data | Contract performance |
| Security monitoring and fraud prevention | Access logs, IP address, session data | Legitimate interest |
| Customer support | Account, communication data | Contract performance |
| Product improvement and analytics | Usage metrics, anonymised data | Legitimate interest |
| Marketing communications | Email, name, company | Consent (opt-in only) |
| Legal and compliance obligations | All categories as required | Legal obligation |
| Audit trail and access logs | Account actions, timestamps | Legal obligation / legitimate interest |
Storage & Security
The security of your data is at the core of our architecture, not an afterthought. We implement defence-in-depth across every layer of the platform.
5.1 Data Residency
By default, all personal data for Indian customers is stored exclusively within India. We do not transfer personal data outside of the jurisdiction you have selected without your explicit consent or a contractual obligation to do so.
5.2 Technical Safeguards
- Encryption at rest: AES-256 encryption for all stored data
- Encryption in transit: TLS 1.2+ enforced on all API and web connections
- Zero-knowledge storage: Customer file content encrypted client-side — Stornox cannot access plaintext
- Geo-distribution: Data fragmented and distributed across multiple nodes; no single node holds a complete file
- Access control: Role-based IAM policies, S3 Object Lock, multi-factor authentication
- Audit logging: Immutable logs of all access and administrative actions
- Penetration testing: Independent security assessments conducted annually
5.3 Certifications
- ISO/IEC 27001:2013 — Information Security Management
- ISO/IEC 27017:2015 — Cloud Security Controls
- ISO/IEC 27018:2019 — Cloud Privacy and Personal Data Protection
- ISO 9001:2015 — Quality Management Systems
- ISO 22301:2019 — Business Continuity Management
Data Sharing
We do not share your personal data except in the limited circumstances described below. All third-party processors are bound by Data Processing Agreements (DPAs) and are required to maintain appropriate security standards.
6.1 Sub-processors
| Provider | Purpose | Data Transferred | Location |
|---|---|---|---|
| Payment Gateway | Payment processing | Billing address, payment method | India / EU |
| Email Service Provider | Transactional emails, support | Name, email address | India |
| Error Monitoring | Platform reliability | Anonymised error data | India |
| Analytics (self-hosted) | Website analytics | Anonymised usage data | India |
6.2 Legal Disclosures
We may disclose personal data when required to do so by applicable law, court order, or lawful request from government or regulatory authorities in India. We will notify you of such requests to the extent permitted by law.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity. We will provide notice before your data becomes subject to a materially different privacy policy.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Duration of account + 30 days post-deletion | Contract, legal obligation |
| Billing records | 7 years from transaction date | Indian tax law (Income Tax Act, GST) |
| Access logs | 90 days (extended to 1 year for security incidents) | Legitimate interest, legal |
| Support communications | 3 years from last interaction | Legitimate interest |
| Marketing consent records | Until consent is withdrawn + 3 years | Legal obligation (consent record) |
| Stored customer files | Deleted immediately on account termination | Contract, DPDP Act 2023 |
Upon account deletion, your personal data will be purged from our live systems within 30 days and from encrypted backups within 90 days. Data retained for legal compliance will be isolated and not used for any other purpose.
Your Rights
Depending on your jurisdiction, you hold the following rights over your personal data. We honour all valid requests within the timeframes required by applicable law.
To exercise any right, contact privacy@stornox.com. We will respond within 30 days for GDPR requests and within the timelines specified under the DPDP Act 2023 for Indian data principals. We may request identity verification before processing your request.
India — DPDP Act 2023
9.1 Our Role as Data Fiduciary
Under the DPDP Act, Stornox acts as a Data Fiduciary when processing personal data of Indian residents. We determine the purpose and means of processing account, billing, and contact data. For encrypted customer file content, we act as a Data Processor on behalf of our enterprise customers.
9.2 Consent and Notice
We process personal data of Indian data principals on the basis of free, specific, informed, unconditional, and unambiguous consent obtained through clear affirmative action. We provide a notice — in clear and plain language — at the time of or before collection, specifying:
- The personal data being collected and the purpose of processing
- The manner in which you may exercise your rights as a data principal
- The manner in which you may make a complaint to the Data Protection Board of India
9.3 Rights of Indian Data Principals
Under the DPDP Act 2023, Indian data principals have the following additional rights:
- Right to Information: Know what personal data is being processed and the identities of all Data Fiduciaries and significant Data Fiduciaries with whom data has been shared
- Right of Correction and Erasure: Correct, complete, update, or erase personal data where such data is no longer necessary for the purpose for which it was collected
- Right to Grievance Redressal: Have grievances addressed by Stornox within 7 days of submission at privacy@stornox.com
- Right to Nominate: Nominate another individual to exercise rights on your behalf in the event of death or incapacity
9.4 Obligations Under DPDP Act
Stornox, as a Data Fiduciary, undertakes the following obligations:
- Process personal data only for lawful purposes and only to the extent necessary
- Maintain reasonable security safeguards to prevent personal data breach
- Notify the Data Protection Board of India and affected data principals of a personal data breach in the prescribed form and manner
- Erase personal data and cause Data Processors to erase personal data upon withdrawal of consent or upon the purpose of collection being no longer served
- Publish the contact details of a Data Protection Officer or another responsible person to enable data principals to exercise their rights
9.5 Cross-Border Data Transfers (India)
Cross-border transfers of personal data of Indian residents are conducted in accordance with the provisions of the DPDP Act 2023 and any rules notified thereunder by the Central Government. We transfer data outside India only to jurisdictions approved by the Government of India or subject to Standard Contractual Clauses or equivalent safeguards.
9.6 Regulatory Compliance
- RBI Data Localisation: Personal and financial data of Indian customers processed in connection with payment services is stored and processed in India in compliance with RBI guidelines
- SEBI Cybersecurity Framework: Data processed in connection with securities-related clients is handled in accordance with SEBI's cybersecurity and cyber resilience framework
- MEITY Cloud Guidelines: Our cloud infrastructure complies with MEITY's guidelines for government and regulated-sector cloud services
Cookies & Tracking
We use a minimal set of cookies and similar technologies. We do not use advertising cookies or allow third-party ad networks to track you on our site.
| Cookie Type | Purpose | Duration | Can be disabled? |
|---|---|---|---|
| Strictly necessary | Authentication, session management, CSRF protection | Session / 30 days | No — required for platform to function |
| Analytics (self-hosted) | Page views, user flows — no cross-site tracking, no personal identifiers sent to third parties | 13 months | Yes — via cookie preferences |
| Functional preferences | Language, theme, dashboard layout preferences | 12 months | Yes — settings will reset |
We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking cookies. Our analytics are self-hosted in India.
Children's Privacy
The Stornox platform is intended for use by enterprises and business professionals only. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided personal data to us, please contact privacy@stornox.com and we will promptly delete it.
Under the DPDP Act 2023, we treat processing of personal data of children (individuals under 18) with heightened care and obtain verifiable parental consent where applicable.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Send an email notification to registered account holders at least 30 days before changes take effect
- Display a prominent notice on our platform and website
- Maintain an accessible version history for the previous 24 months
Your continued use of our services after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the changes, you may close your account and request deletion of your data before the effective date.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to raise a concern about our data practices, please reach out through any of the following channels.
Regulatory Authorities
If you are not satisfied with our response to a privacy concern, you have the right to escalate to the relevant supervisory authority:
- India: Data Protection Board of India (once constituted under DPDP Act 2023)
- European Union: Your national Data Protection Authority (DPA)