Semaphore CloudSemaphore Cloud
Legal

Privacy Policy

Last updated: 14 September 2026

Effective 30 July 2026 · India (DPDPA)

1. Who we are

This Privacy Policy explains how Semaphore Technosoft LLP ("Semaphore Cloud", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit our websites, contact us, create an account, or use our cloud hosting and related services.

We are a limited liability partnership organised under the laws of India. Under the Digital Personal Data Protection Act, 2023 ("DPDPA"), we act as a Data Fiduciary for personal data we determine the purpose and means of processing. Where you place end-user or customer content on servers we provide, you are typically the Data Fiduciary for that content; we process it as a service provider on your instructions.

Registered address: Semaphore Technosoft LLP, Surat, Gujarat, India.
Contact: support@semaphorecloud.com · +91 9712360303

This policy applies to semaphorecloud.com cloud marketing sites, related subdomains (including pricing tools), customer portals, APIs, and support channels we operate. It does not govern third-party websites linked from our pages.

2. Scope and applicable law

We primarily process personal data in accordance with Indian law, including the DPDPA, the Information Technology Act, 2000, and rules framed thereunder. Where you are located outside India, additional local rules may also apply. If you are in the European Economic Area or United Kingdom, certain GDPR or UK GDPR rights may apply in parallel; contact us and we will honour applicable rights where they apply to our processing.

We may update this policy when our practices or the law change. Material updates will be posted on this page with a revised "Last updated" date. Where required, we will also notify primary account contacts by email.

3. Personal data we collect

3.1 Data you provide

  • Identity and contact details (name, email, phone, company, billing or shipping address)
  • Account credentials and authentication data (including multi-factor settings)
  • Business details where relevant (GSTIN / tax identifiers, company registration information)
  • Messages you send via contact forms, sales inquiries, support tickets, or email
  • Job application materials if you apply for a role with us

3.2 Data collected automatically

  • IP address, approximate location derived from IP, browser and device information
  • Pages viewed, referring URL, timestamps, and basic access or error logs
  • Service telemetry for hosting (resource use, bandwidth, API activity) tied to your account
  • Security signals used to detect abuse, fraud, or attacks

3.3 Payment data

Card and wallet payments are handled by payment partners (for example Razorpay and/or Stripe, depending on the flow). We receive confirmation of payment status, invoice metadata, and limited billing identifiers. We do not store full card numbers or CVV on Semaphore systems.

3.4 Customer content on hosted servers

Content you store or process on virtual machines, storage volumes, or related services is processed to provide the service you ordered. We do not use that content for marketing. Access is limited to what is needed for operations, security, abuse handling, or legal compliance.

4. Why we process personal data

We process personal data for the following purposes:

  • Providing, securing, and improving websites, accounts, and hosting services
  • Identity verification, authentication, and account administration
  • Order fulfilment, provisioning, billing, invoicing, and collections
  • Customer support and responding to sales or product questions
  • Fraud prevention, abuse detection, sanctions or restricted-party screening where required, and network security
  • Service notices, security alerts, and transactional email
  • Marketing communications only where you have consented or where Indian law otherwise permits, with an easy opt-out
  • Recruitment, where you apply for employment
  • Complying with Indian law, court orders, tax and accounting obligations, and responding to lawful government requests

Under the DPDPA, processing is generally based on your consent and/or other lawful grounds recognised by statute (for example, for employment, medical emergencies, or to comply with law). Where consent is the basis, you may withdraw it for future processing, subject to contractual and legal limits (for example, we may still need billing records).

We do not use automated decision-making that produces a legal or similarly significant effect on you without human review.

5. Website, logs, and security monitoring

When you visit our websites, servers automatically process technical data (IP address, request path, user-agent, status codes) so pages can load, errors can be diagnosed, and attacks (including DDoS or intrusion attempts) can be detected and mitigated. Logs are retained only as long as needed for security, operations, and legal requirements, then deleted or anonymised.

We may use content delivery, DNS, or security partners to protect availability. Those partners process technical data as our processors under written arrangements where required.

6. Accounts, orders, and payments

Registration and order data (identity, contact, company, and plan details) are used to create your account, provision services, and perform the contract. After an account ends, we retain limited records as needed for tax, accounting, dispute resolution, and statutory retention, then delete or restrict them.

Payment processors receive the billing details needed to complete a transaction. Their privacy notices also apply to data they collect directly when you pay through their checkout.

7. Contact forms, sales, and support

If you submit a website contact form, pricing-calculator lead, or support request, we process your name, email, phone, company (if provided), product interest, and message content to respond and keep an internal record of the conversation. Sales and support records are kept for the time needed to complete the inquiry and for reasonable follow-up, then archived or deleted subject to legal retention.

8. Cookies and similar technologies

Essential cookies are required for security, session management, and core site functions. They cannot be disabled if you want the site to work.

Analytics cookies come from Google Analytics 4, operated by Google LLC, when you opt in. They help us understand aggregate usage (pages, device, referrer, and similar). We send an opaque user identifier for signed-in portal sessions — not your email or name. Marketing cookies are reserved for a later campaign tool and stay off unless you opt in. You can change your choice anytime using Cookie settings in the footer. You can also control cookies through your browser; blocking some cookies may limit features.

Full details are in our Cookie Policy. We do not operate third-party advertising cookie networks on our marketing site as of the date of this policy.

9. Who we share data with

We do not sell personal data. We share personal data only as needed with:

  • Payment processors (for example Razorpay, Stripe) to collect and reconcile payments
  • Analytics providers — Google LLC (Google Analytics 4) when you consent to analytics cookies, to measure site and product usage. We do not send names, emails, or phone numbers in analytics events
  • Infrastructure and operations partners who help us deliver hosting, networking, email delivery, monitoring, and support tooling, under confidentiality and processing terms
  • Upstream cloud capacity providers that provision or operate virtual servers and related resources you purchase from us. Those providers may process account identifiers, configuration metadata, and hosted content as needed to run the underlying infrastructure in the region you select
  • Professional advisers (legal, accounting) under confidentiality duties
  • Authorities when Indian law, a court order, or a lawful request requires disclosure

Processors may only use personal data on our instructions for the agreed services, except where they must comply with their own legal obligations.

10. International transfers

Our commercial relationship with you is governed from India. Account, billing, and support records are primarily processed in India. Because we offer multiple regions and resell capacity from global infrastructure partners, some personal data and customer content may be processed outside India — including in the European Union (for example Germany), and other regions you select at order time.

Where personal data leaves India, we take reasonable steps consistent with the DPDPA and applicable contracts so that recipients provide an appropriate level of protection (for example contractual clauses, security commitments, and limiting access to what is necessary).

11. Retention

We keep personal data only as long as needed for the purposes above, including:

  • Active account and service data for the life of the customer relationship
  • Billing and tax records for periods required under Indian tax and company law (often several years after the relevant transaction)
  • Security and access logs for a limited operational window unless an incident requires longer retention
  • Marketing consents until you unsubscribe or we delete inactive contacts
  • Recruitment data for a limited period after a hiring decision unless you agree to a longer talent pool

When retention ends, we delete or irreversibly anonymise personal data, unless a legal hold applies.

12. Security

We use administrative, technical, and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest where applicable, access controls, logging, and vulnerability management. No method of transmission or storage is perfectly secure; please use strong unique passwords and enable multi-factor authentication where offered.

If we become aware of a personal data breach that requires notice under Indian law, we will notify affected individuals and/or the Data Protection Board of India as required.

13. Your rights (Data Principals)

Subject to the DPDPA and other applicable law, you may request to:

  • Access a summary of personal data we hold about you and the processing activities
  • Correct inaccurate or incomplete personal data
  • Erase personal data that is no longer necessary (subject to legal retention)
  • Withdraw consent where processing is consent-based
  • Nominate another person to exercise rights on your behalf in case of death or incapacity, where the DPDPA provides for this
  • Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved

To exercise rights, email support@semaphorecloud.com with the subject line "Privacy Request". We may need to verify your identity before acting. We aim to respond within the timelines required by law (generally within a reasonable period and not later than the statutory limit).

Grievance Officer: For privacy grievances under Indian law, contact the Grievance Officer at support@semaphorecloud.com (Attention: Grievance Officer, Semaphore Technosoft LLP, Surat, Gujarat, India).

14. Children

Our services are directed to businesses and adults. We do not knowingly offer accounts to children under 18. If you believe we have collected personal data from a minor without appropriate consent, contact us and we will take steps to delete it.

15. Third-party links

Our sites may link to external sites (documentation, payment checkouts, status pages). Those sites have their own privacy practices. We are not responsible for content or processing on sites we do not control.

16. Contact

For privacy questions, rights requests, or complaints:

Semaphore Technosoft LLP
Surat, Gujarat, India
Email: support@semaphorecloud.com
Phone: +91 9712360303

Questions about your privacy?

Reach our team for access, correction, or grievance requests.

Contact us