DPDPA & GDPR Compliant

Privacy Policy

Overview

At OneMillionWebs, owned by Creoastra, we are committed to safeguarding the privacy of our users. This policy applies to all personal data collected through our developer portal, onboarding wizard, and associated digital services.

We act as the Data Fiduciary (India) and Data Controller (EU) for the information you provide during account creation and project initiation.

Data We Collect

Personal Identifiers

Name, email address, phone number, and physical address for billing.

Purpose: Account management and compliance.

Technical & Usage Data

IP address, browser type, device information, and API interaction logs.

Purpose: System security and service optimization.

Authentication Data

Microsoft Graph ID, GitHub tokens (encrypted), and session identifiers.

Purpose: Secure access and integration management.

How We Use Your Data

We process your data based on these legal foundations:

  • Contractual Necessity: To provide the development services you subscribed to.
  • Legitimate Interest: For fraud prevention and improving platform architecture.
  • Legal Obligation: For tax reporting and compliance with Indian law enforcement requests.
  • Explicit Consent: For marketing communications (optional and revocable).

Data Sharing

We do not sell your data. We share only necessary information with:

Infrastructure Partners

Vercel (Hosting), GitHub (Code), Zoho (Identity).

Payment Processors

Razorpay (Encrypted transaction handling).

International Transfers

Data collected in India may be stored on servers located in the EU or US through our partners. We ensure all transfers comply with DPDPA Chapter 4 and GDPR Chapter 5 requirements using Standard Contractual Clauses.

Your Legal Rights

Right to Correct

The ability to update outdated or inaccurate personal data.

Right to Erasure

The right to be forgotten (subject to legal retention requirements).

Right of Portability

Obtaining your data in a structured, machine-readable format.

Right of Withdrawal

Revoking consent for data processing at any time.

Consent & Data Protection Officer

By using our services, you signify your consent to this Privacy Policy. For any grievances or data requests, please contact our DPO:

Email: dpo@creoastra.com

Attention: Data Protection Officer

Response Time: Within 72 Hours (GDPR requirement).