Privacy Policy
1. Introduction
Welcome to Podstack. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website podstack.ai and use our GPU cloud computing services (collectively, the "Services").
This Privacy Policy is designed to comply with GDPR (EU), DPDP (India), ePrivacy Directive, and the Indian Information Technology Act, 2000.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
2. Data Controller
For the purposes of the GDPR and DPDP, the data controller responsible for your personal data is:
Razordynamics Private Limited (operating as Podstack)
Address: 11th Floor, Prestige Tech Park, Platina 2, Outer Ring Rd, Kadubeesanahalli, Bengaluru, Karnataka India- 560087
Email: privacy@podstack.ai
Data Protection Officer: dpo@podstack.ai
3. Information We Collect
3.1 Information You Provide Directly
- Account Information: Name, email address, phone number, password, and organization name.
- Billing Information: Payment card details, billing address, GST/VAT identification numbers, and transaction history.
- Communications: Information you provide when contacting our support team.
- User Content: Data, files, code, models, and other content you upload, store, or process using our Services.
- Builder Credit Applications: Project descriptions and optional GitHub/Colab/LinkedIn links to verify legitimate ML use.
3.2 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device identifiers, and hardware configuration.
- Usage Data: Pages visited, features used, click patterns, session duration, and interactions.
- Log Data: Server logs, error reports, and system activity logs.
- Location Data: Approximate geographic location based on IP address.
- Cookies and Similar Technologies: Information collected through cookies and similar tracking technologies.
3.3 Information from Third Parties
- Authentication Providers: Basic profile information from Google, GitHub, or other OAuth providers.
- Payment Processors: Transaction confirmations and fraud prevention data.
- Business Partners: Information from referral partners and resellers.
4. How We Use Your Information
- Provide, maintain, and improve our GPU cloud computing services.
- Process your transactions and manage your account.
- Allocate computing resources and manage infrastructure.
- Provide technical support and respond to inquiries.
- Send service-related notifications and marketing communications (with your consent).
- Analyze usage patterns to improve our Services.
- Detect, prevent, and address technical issues, fraud, and security threats — including crypto-mining abuse.
- Enforce our Terms of Service and acceptable use policies.
- Comply with legal obligations and respond to lawful requests.
5. Legal Basis for Processing (GDPR)
| Legal Basis | Processing Activities |
|---|---|
| Contract Performance | Account creation, service delivery, billing, technical support |
| Consent | Marketing communications, non-essential cookies, analytics |
| Legitimate Interests | Fraud prevention, security monitoring, service improvement, business analytics |
| Legal Obligation | Tax compliance, responding to legal requests, data retention requirements |
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account Information | Duration of account + 3 years after deletion |
| Billing & Transaction Records | 7 years (tax/legal compliance) |
| User Content & Data | Until you delete it or account termination + 30 days |
| Usage Logs | 90 days (rolling) |
| Support Communications | 3 years from resolution |
| Marketing Consent Records | Until withdrawal + 3 years |
| Cookie Consent Records | 7 years (GDPR compliance audit trail) |
7. Your Rights Under GDPR
Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data ("Right to be Forgotten").
Right to Restriction (Art. 18)
Request restriction of processing of your personal data.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests or for direct marketing.
Rights Related to Automated Decision-Making (Art. 22)
Not be subject to decisions based solely on automated processing.
Right to Withdraw Consent (Art. 7)
Withdraw consent at any time where processing is based on consent.
8. Your Rights Under DPDP (India)
Right to Access Information
Obtain a summary of your personal data and processing activities.
Right to Correction and Erasure
Request correction of inaccurate data and erasure of data no longer necessary.
Right to Grievance Redressal
Have your grievances addressed by our designated Grievance Officer.
Right to Nominate
Nominate another person to exercise your rights in case of death or incapacity.
Grievance Officer (India)
Name: Grievance Officer, Podstack
Email: grievance@podstack.ai
Response Time: Within 30 days of receipt of complaint
9. International Data Transfers
Your personal data may be transferred to and processed in countries other than your country of residence. When we transfer personal data from the EEA or UK to countries not deemed adequate by the European Commission, we use Standard Contractual Clauses (SCCs), Binding Corporate Rules, or adequacy decisions.
Cross-border transfers of personal data from India are conducted in compliance with the DPDP Act and any rules notified by the Central Government regarding permitted jurisdictions.
10. Cookies and Tracking Technologies
10.1 Types of Cookies We Use
| Category | Purpose | Consent Required |
|---|---|---|
| Essential | Authentication, security, basic functionality | No |
| Analytics | Usage statistics, performance monitoring | Yes |
| Marketing | Advertising, retargeting, conversion tracking | Yes |
| Personalization | User preferences, customized experience | Yes |
10.2 Managing Cookies
- Our cookie consent banner (displayed on first visit).
- The "Cookie Settings" link in our website footer.
- Your browser settings (note: disabling cookies may affect functionality).
11. Third-Party Services
| Category | Purpose |
|---|---|
| Cloud Infrastructure Providers | Hosting and compute resources |
| Payment Processors (Razorpay) | Secure payment processing |
| Analytics Services (Google Analytics) | Website analytics and performance |
| Communication Tools | Email delivery, chat support |
| Authentication Providers | OAuth login (Google, GitHub) |
12. Data Security
- Encryption: TLS 1.3 for data in transit; AES-256 for data at rest.
- Access Controls: Role-based access, multi-factor authentication.
- Infrastructure Security: Firewalls, intrusion detection, regular security audits.
- Data Isolation: Logical separation of customer data.
- Monitoring: 24/7 security monitoring and incident response.
- Employee Training: Regular security and privacy awareness training.
13. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@podstack.ai, and we will take steps to delete such information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you via email or prominent notice on our website.
15. Contact Us
General Privacy Inquiries
Email: privacy@podstack.ai
Data Protection Officer (GDPR)
Email: dpo@podstack.ai
Grievance Officer (India DPDP)
Email: grievance@podstack.ai
Data Subject Requests
Email: dsr@podstack.ai
EU Representative: For users in the European Union, you may also contact our EU representative at eu-rep@podstack.ai