Legal

Privacy Policy

We take the privacy of your data seriously — it's the foundation of everything we do. This policy explains what we collect, why we collect it, how we protect it, and the rights you hold over it.

Effective: January 1, 2026
Last updated: January 1, 2026
Version 2.0
🇮🇳 India — DPDP Act 2023
🇪🇺 EU — GDPR Compliant
🔒 ISO/IEC 27018 Certified
📋 RBI / SEBI Aligned
01

Overview

Stornox ("we", "us", "our") operates a geo-distributed cloud object storage platform accessible at stornox.com. This Privacy Policy governs how we collect, process, store, and protect personal data obtained through our website, platform, and associated services.

We are committed to transparency. We process personal data only for the purposes described in this policy, retain it only as long as necessary, and implement technical and organisational measures to keep it safe.

Zero-knowledge architecture: Customer data stored on the Stornox platform is encrypted client-side with AES-256 before transmission. Stornox does not have the ability to read the content of your stored files. This policy applies to the personal data we handle as a data controller (e.g. account, billing, and contact data) — not to the encrypted content you store on our platform.
02

Who We Are

Data Controller: Stornox Technology Pvt. Ltd., registered in India.

Registered Name Stornox Technology Pvt. Ltd.
Registered Address India
Data Protection Officer privacy@stornox.com
General Contact hello@stornox.com

For customers in the European Union, Stornox acts as a data processor with respect to files stored on the platform (under the data processing terms in your service agreement) and as a data controller for account and billing data.

03

Data We Collect

We collect only the personal data necessary to provide and improve our services. The categories are described below.

3.1 Account & Contact Data

  • Full name, work email address, job title, company name
  • Phone number (optional, for enterprise support tiers)
  • Password (stored as a one-way bcrypt hash — never in plain text)
  • Profile and account preferences

3.2 Billing & Payment Data

  • Billing address, GST / PAN number (for Indian customers), VAT number (for EU customers)
  • Payment method details — processed exclusively by our PCI-DSS compliant payment provider; Stornox does not store full card numbers
  • Transaction records and invoice history

3.3 Usage & Technical Data

Data Type What We Collect Purpose
Access Logs
server-side
IP address, timestamp, API endpoint, HTTP status code, latency Security, abuse prevention, SLA monitoring
Storage Metrics
platform
Bytes stored, object count, bucket names, transfer volume Billing, capacity planning, usage analytics
Device & Browser
website
Browser type, OS, screen resolution, referrer URL Website analytics, compatibility
Session Data
platform
Authentication tokens (JWT), session ID, last active timestamp Authentication, security

3.4 Communication Data

  • Emails, support tickets, and live chat transcripts you send us
  • Demo request and contact form submissions
  • Survey responses and product feedback
What we never collect: We do not collect sensitive personal data such as biometrics, health information, racial or ethnic origin, political opinions, or religious beliefs. We do not purchase or source personal data from third-party data brokers.
04

How We Use Your Data

We process personal data only where we have a lawful basis for doing so. Each purpose is described below with its corresponding legal basis.

Purpose Data Used Legal Basis
Provide and operate the platform Account, usage, session data Contract performance
Billing and payment processing Billing, payment, usage data Contract performance
Security monitoring and fraud prevention Access logs, IP address, session data Legitimate interest
Customer support Account, communication data Contract performance
Product improvement and analytics Usage metrics, anonymised data Legitimate interest
Marketing communications Email, name, company Consent (opt-in only)
Legal and compliance obligations All categories as required Legal obligation
Audit trail and access logs Account actions, timestamps Legal obligation / legitimate interest
No selling of data: Stornox does not sell, rent, or trade your personal data to any third party. Stornox products are ad-free and we do not use personal data for advertising targeting.
05

Storage & Security

The security of your data is at the core of our architecture, not an afterthought. We implement defence-in-depth across every layer of the platform.

5.1 Data Residency

By default, all personal data for Indian customers is stored exclusively within India. We do not transfer personal data outside of the jurisdiction you have selected without your explicit consent or a contractual obligation to do so.

🇮🇳
India Data Residency: In compliance with MEITY cloud guidelines and RBI data localisation requirements, personal data of Indian customers is stored in Indian data centres. Cross-border transfers are conducted only under the conditions permitted by the DPDP Act 2023 and subject to Standard Contractual Clauses or equivalent safeguards.

5.2 Technical Safeguards

  • Encryption at rest: AES-256 encryption for all stored data
  • Encryption in transit: TLS 1.2+ enforced on all API and web connections
  • Zero-knowledge storage: Customer file content encrypted client-side — Stornox cannot access plaintext
  • Geo-distribution: Data fragmented and distributed across multiple nodes; no single node holds a complete file
  • Access control: Role-based IAM policies, S3 Object Lock, multi-factor authentication
  • Audit logging: Immutable logs of all access and administrative actions
  • Penetration testing: Independent security assessments conducted annually

5.3 Certifications

  • ISO/IEC 27001:2013 — Information Security Management
  • ISO/IEC 27017:2015 — Cloud Security Controls
  • ISO/IEC 27018:2019 — Cloud Privacy and Personal Data Protection
  • ISO 9001:2015 — Quality Management Systems
  • ISO 22301:2019 — Business Continuity Management
06

Data Sharing

We do not share your personal data except in the limited circumstances described below. All third-party processors are bound by Data Processing Agreements (DPAs) and are required to maintain appropriate security standards.

6.1 Sub-processors

Provider Purpose Data Transferred Location
Payment Gateway Payment processing Billing address, payment method India / EU
Email Service Provider Transactional emails, support Name, email address India
Error Monitoring Platform reliability Anonymised error data India
Analytics (self-hosted) Website analytics Anonymised usage data India

6.2 Legal Disclosures

We may disclose personal data when required to do so by applicable law, court order, or lawful request from government or regulatory authorities in India. We will notify you of such requests to the extent permitted by law.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity. We will provide notice before your data becomes subject to a materially different privacy policy.

07

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.

Data Category Retention Period Basis
Account data Duration of account + 30 days post-deletion Contract, legal obligation
Billing records 7 years from transaction date Indian tax law (Income Tax Act, GST)
Access logs 90 days (extended to 1 year for security incidents) Legitimate interest, legal
Support communications 3 years from last interaction Legitimate interest
Marketing consent records Until consent is withdrawn + 3 years Legal obligation (consent record)
Stored customer files Deleted immediately on account termination Contract, DPDP Act 2023

Upon account deletion, your personal data will be purged from our live systems within 30 days and from encrypted backups within 90 days. Data retained for legal compliance will be isolated and not used for any other purpose.

08

Your Rights

Depending on your jurisdiction, you hold the following rights over your personal data. We honour all valid requests within the timeframes required by applicable law.

Right to Access
Request a copy of the personal data we hold about you and information on how it is processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data. You can update most data directly in your account settings.
Right to Erasure
Request deletion of your personal data, subject to retention obligations required by law.
Right to Portability
Receive your personal data in a structured, machine-readable format (JSON / CSV) for transfer to another provider.
Right to Object
Object to processing based on legitimate interests, including direct marketing communications.
Right to Restrict Processing
Request that we restrict the processing of your data in certain circumstances while a dispute is resolved.
Withdraw Consent
Withdraw any consent you have given at any time. Withdrawal does not affect lawfulness of processing prior to withdrawal.
Lodge a Complaint
Lodge a complaint with the relevant supervisory authority — in India, the Data Protection Board; in the EU, your national DPA.

To exercise any right, contact privacy@stornox.com. We will respond within 30 days for GDPR requests and within the timelines specified under the DPDP Act 2023 for Indian data principals. We may request identity verification before processing your request.

09

India — DPDP Act 2023

🇮🇳
This section applies specifically to Indian data principals under the Digital Personal Data Protection Act, 2023 (DPDP Act). These provisions are in addition to — and do not limit — the rights described in Section 08.

9.1 Our Role as Data Fiduciary

Under the DPDP Act, Stornox acts as a Data Fiduciary when processing personal data of Indian residents. We determine the purpose and means of processing account, billing, and contact data. For encrypted customer file content, we act as a Data Processor on behalf of our enterprise customers.

9.2 Consent and Notice

We process personal data of Indian data principals on the basis of free, specific, informed, unconditional, and unambiguous consent obtained through clear affirmative action. We provide a notice — in clear and plain language — at the time of or before collection, specifying:

  • The personal data being collected and the purpose of processing
  • The manner in which you may exercise your rights as a data principal
  • The manner in which you may make a complaint to the Data Protection Board of India

9.3 Rights of Indian Data Principals

Under the DPDP Act 2023, Indian data principals have the following additional rights:

  • Right to Information: Know what personal data is being processed and the identities of all Data Fiduciaries and significant Data Fiduciaries with whom data has been shared
  • Right of Correction and Erasure: Correct, complete, update, or erase personal data where such data is no longer necessary for the purpose for which it was collected
  • Right to Grievance Redressal: Have grievances addressed by Stornox within 7 days of submission at privacy@stornox.com
  • Right to Nominate: Nominate another individual to exercise rights on your behalf in the event of death or incapacity

9.4 Obligations Under DPDP Act

Stornox, as a Data Fiduciary, undertakes the following obligations:

  • Process personal data only for lawful purposes and only to the extent necessary
  • Maintain reasonable security safeguards to prevent personal data breach
  • Notify the Data Protection Board of India and affected data principals of a personal data breach in the prescribed form and manner
  • Erase personal data and cause Data Processors to erase personal data upon withdrawal of consent or upon the purpose of collection being no longer served
  • Publish the contact details of a Data Protection Officer or another responsible person to enable data principals to exercise their rights

9.5 Cross-Border Data Transfers (India)

Cross-border transfers of personal data of Indian residents are conducted in accordance with the provisions of the DPDP Act 2023 and any rules notified thereunder by the Central Government. We transfer data outside India only to jurisdictions approved by the Government of India or subject to Standard Contractual Clauses or equivalent safeguards.

9.6 Regulatory Compliance

  • RBI Data Localisation: Personal and financial data of Indian customers processed in connection with payment services is stored and processed in India in compliance with RBI guidelines
  • SEBI Cybersecurity Framework: Data processed in connection with securities-related clients is handled in accordance with SEBI's cybersecurity and cyber resilience framework
  • MEITY Cloud Guidelines: Our cloud infrastructure complies with MEITY's guidelines for government and regulated-sector cloud services
10

Cookies & Tracking

We use a minimal set of cookies and similar technologies. We do not use advertising cookies or allow third-party ad networks to track you on our site.

Cookie Type Purpose Duration Can be disabled?
Strictly necessary Authentication, session management, CSRF protection Session / 30 days No — required for platform to function
Analytics (self-hosted) Page views, user flows — no cross-site tracking, no personal identifiers sent to third parties 13 months Yes — via cookie preferences
Functional preferences Language, theme, dashboard layout preferences 12 months Yes — settings will reset

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking cookies. Our analytics are self-hosted in India.

11

Children's Privacy

The Stornox platform is intended for use by enterprises and business professionals only. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided personal data to us, please contact privacy@stornox.com and we will promptly delete it.

Under the DPDP Act 2023, we treat processing of personal data of children (individuals under 18) with heightened care and obtain verifiable parental consent where applicable.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Send an email notification to registered account holders at least 30 days before changes take effect
  • Display a prominent notice on our platform and website
  • Maintain an accessible version history for the previous 24 months

Your continued use of our services after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the changes, you may close your account and request deletion of your data before the effective date.

13

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or want to raise a concern about our data practices, please reach out through any of the following channels.

Data Protection Officer privacy@stornox.com
General Enquiries hello@stornox.com
Response Time Within 7 days (DPDP) · 30 days (GDPR)
Registered Address Stornox Technology Pvt. Ltd., India

Regulatory Authorities

If you are not satisfied with our response to a privacy concern, you have the right to escalate to the relevant supervisory authority:

  • India: Data Protection Board of India (once constituted under DPDP Act 2023)
  • European Union: Your national Data Protection Authority (DPA)
We respond to all privacy requests. We will acknowledge receipt of your request within 48 hours and provide a substantive response within the statutory deadline. We will never charge a fee for exercising your rights, except in cases of manifestly unfounded or excessive requests.