Privacy Policy

Operator: AppStra (Zerostic — a sole proprietorship firm (Proprietor: Jayant Anand Jha)) Website: https://dashboard.appstra.zerostic.com Effective date: 15 July 2026

Zerostic — a sole proprietorship firm (Proprietor: Jayant Anand Jha) ("AppStra", "we") respects your privacy and is committed to protecting your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, and other applicable Indian law. This Policy explains what we collect, why, and your rights.

1. Who is the data fiduciary

For personal data you provide when using the Platform, the operator identified above is the Data Fiduciary (controller). Where an advisory firm (Analyst) uses the Platform to serve its own clients, the Analyst is the Data Fiduciary for its clients' data and AppStra acts as a Data Processor on the Analyst's behalf under its tenant.

2. Data we collect

  • Account & profile: name, email, phone, role, organisation, login credentials (passwords are stored only as salted hashes, never in plaintext).
  • KYC & identity (where applicable): collected via our KYC provider (Digio) using DigiLocker / Aadhaar offline e-KYC and PAN verification. We store only the last four digits of Aadhaar (masked as XXXX XXXX 1234); we do not store the full Aadhaar number. PAN is stored encrypted at rest and masked for display. Verified KYC payloads and consent artifacts are retained as required.
  • Subscription, billing & payments: plan, amounts (INR), invoices, payment status, and gateway references. Payments are processed by Cashfree Payments; we do not store your full card, bank account, or UPI credentials.
  • Content & activity: communications you create or receive through the Platform, delivery logs, and audit trails (for compliance).
  • Technical: IP address, device/browser info, cookies and similar technologies necessary to operate and secure the Platform.

3. Why we use it (purposes)

To create and manage your account; deliver the subscribed services; process payments and seat fees; perform KYC and e-sign where required; distribute communications across enabled channels (Telegram, WhatsApp, email, SMS); maintain compliance and audit records; provide support; secure the Platform and prevent fraud; and meet legal and regulatory obligations.

4. Legal basis / consent

We process personal data on the basis of your consent and/or as necessary to provide the service you requested, comply with law, or for other lawful purposes permitted under the DPDP Act. Where consent is the basis (including for KYC/e-sign via Aadhaar), we obtain it through a clear consent step, and you may withdraw it (subject to legal/contractual limits) as described in §8.

5. Aadhaar & sensitive data — special handling

  • Full Aadhaar numbers are never stored — not even encrypted. If a full number passes through the e-KYC flow it is discarded immediately; only the last four digits (masked) are retained.
  • PAN and other sensitive identifiers are encrypted at rest (AES-256-GCM) and masked in the interface.
  • Channel credentials and other secrets are encrypted at rest.
  • Data is logically isolated per tenant with row-level security so one organisation cannot access another's data.

6. Sharing & disclosure

We share personal data only with: (a) service providers/processors who help us operate the Platform (e.g. Cashfree for payments, Digio for KYC/e-sign, messaging and email delivery providers, cloud hosting), under appropriate confidentiality and data-protection obligations; (b) the Analyst whose tenant you belong to (for client data); (c) authorities, where required by law, regulation, or valid legal process. We do not sell your personal data.

7. Retention

We retain personal data for as long as your account is active and thereafter for the periods required by applicable law and regulation (including SEBI record-retention requirements, which may require retention for several years). When no longer required, data is deleted or anonymised.

8. Your rights

Subject to the DPDP Act and applicable exceptions, you may: access your personal data; request correction or completion; request erasure; withdraw consent; and nominate another person to exercise your rights in the event of death or incapacity. To exercise these rights, contact the Grievance Officer in §11. We may need to verify your identity before acting.

9. Cookies

We use cookies and similar technologies that are necessary to operate, secure, and improve the Platform (for example, to keep you signed in). You can control non-essential cookies through your browser; disabling necessary cookies may impair functionality.

10. Security

We implement technical and organisational measures including encryption at rest for sensitive fields, hashed passwords, tenant isolation via row-level security, hardened authentication, access controls, and audit logging. No system is perfectly secure; we work to protect your data and will notify affected users and authorities of a reportable personal-data breach as required by law.

11. Grievances & contact (Data Protection / Grievance Officer)

If your concern is unresolved, you may lodge a complaint with the Data Protection Board of India under the DPDP Act.

12. Changes

We may update this Policy; the current version is posted at https://dashboard.appstra.zerostic.com with a revised effective date. Material changes will be notified where appropriate.