Checkable facts
What your IT reviewer will ask.
Every line below is a fact about how this actually runs, not a posture. Where we
have not done something, it says so.
Who holds the data
TALPRO INDIA PRIVATE LIMITED, CIN U74999KA2020PTC135946, Bengaluru, India.
We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023.
Where it is hosted
A dedicated virtual server operated by Hostinger International Ltd, hosted in the
European Union. Not a shared platform, not a third-party document service.
Encryption in transit
TLS 1.2 and TLS 1.3 only. Older protocols are refused at the edge.
HSTS is enforced with a one-year max-age. Your upload travels over this, not as an email attachment.
How the file reaches us
After you enquire, you receive a single-use link signed with HMAC-SHA256, valid for
fourteen days and bound to your reference. It accepts four files. The file type is verified by
reading the file's own leading bytes, not by trusting its name.
Storage and access
Written to a directory the operating system permits only the service account to open
(0700 directory, 0600 file), under a random filename. There is no public
database port, no object-storage bucket and no shared drive. Server access is by SSH key only —
password logins are disabled.
What software reads it
Nothing automated. No parser, no scorer, no summariser and no language model runs against
your file on our servers. It is opened by the reviewer assigned to your case. If we ever add a
step where a model reads your material, we will name the provider on this page and ask you for a
separate consent before it applies to you.
Who else touches it
Four sub-processors, and only these:
Hostinger (hosting, EU),
Google Workspace
(the email we reply from),
Cloudflare (name resolution only — it never receives your
documents),
HubSpot (the customer record system Talpro India Private Limited uses to
track your enquiry — it holds the details you typed, never your uploaded documents). We add none without updating the
Privacy Policy first.
How long we keep it
Uploaded documents are deleted automatically 30 days after you send them — measured
from the moment the file arrives, not from delivery or handover, so the window cannot quietly
stretch. Enquiry records are deleted automatically 90 days after the last message
between us. If a first report never becomes a larger engagement, both clocks run anyway. A scheduled
process performs all of it — you do not have to ask, and nobody has to remember. Ask sooner
and we do it the same working day.
What we measure
One first-party beacon, on this site's own server.
No cookie, no third-party script,
no advertising pixel, no cross-site identifier — ten named events, ten named fields, and any
value containing an
@ discarded twice over. A random per-tab identifier in
sessionStorage is erased when you close the tab. Records are deleted after
180 days.
Section 11 of the
Privacy Policy lists the lot.
If something goes wrong
We will tell you within 72 hours of becoming aware of any breach affecting your data, and
notify the Data Protection Board of India as the Act requires. You will hear it from us, in
writing, naming what was affected.
For organisations
A mutual NDA and a data-processing agreement are available on request before any cohort work
begins. Email
[email protected].
What we do not claim. The disks are not encrypted at rest. We could say
"enterprise-grade security" and most sites would; instead here is the actual position: the
protection on your file is operating-system access control on a server only we can reach, plus
deletion on a short clock. If at-rest encryption is a requirement for you, tell us before you
upload and we will handle your case differently.
We hold no ISO 27001, no SOC 2 and no certification of any kind, and we will not imply
otherwise. When we earn one, it will appear here with its certificate number.