PRIVACY POLICY AND GDPR
This Privacy Policy explains how Ucartz Online Pvt Ltd ("Ucartz", "we") collects, uses, shares, and protects personal data. It applies to our websites, client portal, and all services listed in our Terms of Service, including Shared and Reseller Hosting, Cloud or VPS, Kali Linux VPS, Dedicated and GPU Servers, Streaming platforms, Domains and DNS, Email services, Licences and Add ons, SSL or TLS certificates, CDN and performance services, and Professional Services such as TechOps, CloudOps, FinOps, DevOps, and SecOps.This Policy works with our GDPR & Global Data Protection Notice, which contains region specific rights and legal bases, and with our Terms of Service and Acceptable Use Policy.
Privacy Policy v1.5, updated May 2026
1) Who we are and how to contact us
- Controller: Ucartz Online Pvt Ltd is the controller for account level data such as contact and billing details.
- Processor: For content you host or transmit using our platforms, you act as the controller and we act as a processor.
- Contact: compliance@ucartz.com
- DPO (EU and UK): compliance@ucartz.com
- Grievance Office (India): compliance@ucartz.com
- Postal address: Opposite to Phase 3 Gate, Technopark,Trivandrum Kerala, India.
2) Personal data we collect
We collect personal data in the categories below. The exact data depends on your relationship with us and the services you use.2.1 Data you provide
- Account and profile: name, company, email, phone, billing address, tax IDs.
- Payment: payment instrument details processed by our payment partners, transaction identifiers, invoices, GST details.
- Support: tickets, emails, chats, call recordings where applicable, attachments and diagnostic files you upload.
- Professional Services: access credentials you provide for TechOps, CloudOps, FinOps, DevOps, SecOps and migration projects. Scope and change notes may contain personal data.
- Content you host or transmit: website files, databases, streamed media, email messages and logs that you upload or send through our platforms.
- Service usage: IP addresses, device and browser details, portal activity, control panel and API actions, server and application logs, resource usage, abuse and security signals.
- Cookies and similar technologies: session cookies, preferences, analytics, and anti fraud cookies. See section 9.
- Domain registries and registrars, certificate authorities, fraud prevention partners, analytics providers, and identity verification services.
3) How we use personal data
We use personal data to:- Create and manage your account. Provide, operate, and support the services you order.
- Process payments, billing, taxation, refunds, and account changes.
- Operate and secure our platforms. Detect, prevent, and investigate abuse and security incidents.
- Communicate with you about orders, service updates, security, policy changes, and support.
- Provide Professional Services such as TechOps, CloudOps, FinOps, DevOps, and SecOps according to the agreed scope.
- Meet legal and regulatory obligations, respond to lawful requests, and enforce our agreements.
- Send marketing communications where allowed. You can opt out at any time.
4) Sharing and disclosure
We share personal data only as needed to run our business and deliver the services.- Service providers and sub processors under contract, including data centers, cloud and network providers, email and SMS services, payment processors, fraud prevention and security vendors, backup or storage providers, and customer support tools.
- Domain registries and registrars for domain operations. Certificate authorities for SSL or TLS certificates.
- Partners who help us deliver Professional Services under a Statement of Work.
- Authorities, courts, or parties to a dispute when required by law or to protect rights, property, or safety.
- Business transfers such as a merger, acquisition, or asset sale, subject to confidentiality.
5) International transfers
We operate globally. When we transfer personal data internationally we use appropriate safeguards such as the EU Standard Contractual Clauses and UK equivalents. See our GDPR & Global Data Protection Notice for details.6) Retention
- We keep account records for as long as you have an account and for a reasonable period after closure to comply with laws and resolve disputes.
- Logs are retained for operational needs and, where applicable, to comply with lawful directions. See our GDPR or DPDP notice for retention examples.
- Backups retention follows product specific schedules in the TOS appendices. Backups are not a guaranteed archive.
7) Security
We use industry standard safeguards, including role based access, encryption in transit, encryption at rest where supported, network segmentation, MFA for staff, vulnerability management, monitoring, and incident response. You are responsible for the security of your content, end user data, and access on services you control, especially on VPS, Dedicated, and GPU Servers.8) Your rights
Your rights depend on your location and the laws that apply.- EU and UK: rights of access, rectification, erasure, restriction, portability, and objection. You may withdraw consent where we rely on consent. You can complain to your supervisory authority.
- India DPDP: rights of access, correction, erasure, grievance redressal, and nomination of an alternate contact.
- Submit requests to compliance@ucartz.com. We may ask for proof of identity. We will respond within the timelines set by law.
9) Cookies and similar technologies
We use cookies and similar technologies for session management, preferences, analytics, and fraud prevention.- You can control cookies in your browser. Blocking some cookies may affect how our site or portal works.
- Where required by law we will show a consent banner with choices.
10) Domains, certificates, and WHOIS data
- Domain registrations require us to submit data to registries under ICANN rules.
- WHOIS data may be publicly accessible depending on TLDs and registry policies.
- We may need to disclose data to certificate authorities and registrars for operations
11) Children’s data
Our services are for business use. Do not host or collect children’s data without proper consent and safeguards.- We keep account records for as long as you have an account and for a reasonable period after closure to comply with laws and resolve disputes.
- Logs are retained for operational needs and, where applicable, to comply with lawful directions. See our GDPR or DPDP notice for retention examples.
- Backups retention follows product specific schedules in the TOS appendices. Backups are not a guaranteed archive.
12) Professional Services and access you provide
We operate globally. When we transfer personal data internationally we use appropriate safeguards such as the EU Standard Contractual Clauses and UK equivalents. See our GDPR & Global Data Protection Notice for details.13) How to contact us and grievances
- Privacy inquiries and rights requests: compliance@ucartz.com
- DPO (EU and UK): compliance@ucartz.com
- Grievance Officer (India): compliance@ucartz.com. We acknowledge within 24 hours and aim to resolve within 15 days where applicable.
- Postal address: Near LP school, Agasthiyacodu, Anchal, Kollam, Kerala - 691306, India.
14) GDPR & Global Data Protection Notice
Ucartz Online Pvt Ltd ("Ucartz", "we") processes personal data across regions, including the EU or EEA (GDPR), the United Kingdom (UK GDPR), and India (Digital Personal Data Protection Act, 2023 — DPDP). It complements our Terms of Service and AUP.14.1) Roles and Scope
- Controller: We act as controller for customer account data such as contact, billing, and service usage.
- Processor: We act as processor for content you host or transmit via our platforms when you control the purposes and means of processing.
- Service contexts: We process personal data when delivering TechOps, CloudOps, FinOps, DevOps, and SecOps managed and consulting services.
- Sub processors: We use reputable infrastructure, email, billing, and anti abuse providers under appropriate contracts. A current list is available on request.
14.2) Data We Process
- Account and Billing: name, email, phone, addresses, payment identifiers that are tokenized, invoices.
- Service Operations: IP addresses, device and session data, control panel activity, server and application logs, resource usage, abuse signals.
- Content You Provide: files, databases, emails, and streamed media you upload or transmit through our services.
- Support: tickets, chats, and call recordings where applicable.
14.3) Purposes and Legal Bases
- Provide services and support under contract performance.
- Secure and maintain platforms under legitimate interests and legal obligation where applicable.
- Billing, taxation, fraud prevention, and compliance under legal obligation or legitimate interests.
- Communications about service updates, security, and changes to policies under legitimate interests or contract.
- Marketing with consent where required. You may withdraw consent at any time.
14.4) Your Choices and Rights
- GDPR and UK GDPR: access, rectification, erasure, restriction, portability, and objection. Right to withdraw consent. Right to lodge a complaint with your supervisory authority.
- India DPDP: right to access, correction, erasure, grievance redressal, and nomination of an alternate contact.
- Submit requests to compliance@ucartz.com. We may require identity verification. We respond within applicable statutory timelines.
14.5) Security Measures
We use layered security that includes role based access controls, encryption in transit, encryption at rest where supported, network segmentation, MFA for staff, vulnerability management and patching, continuous monitoring, and incident response runbooks.14.6) International Data Transfers
When transferring personal data internationally, we use appropriate safeguards such as the EU Standard Contractual Clauses (SCCs, 2021 or 914) and equivalent UK mechanisms, plus supplementary measures where needed. Copies are available on request subject to confidentiality.14.7) Breach Notification
We assess security incidents promptly. Where required by law, we will notify the appropriate supervisory authority and affected customers without undue delay after becoming aware of a personal data breach.14.8) Grievances and Appeals in India
We publish a Grievance Officer name and contact details and acknowledge complaints within 24 hours, resolving them within 15 days where applicable. Users may appeal to the Grievance Appellate Committee as per current law.14.9) Data Processing Addendum (DPA)
- Account records are retained for the life of your account and a reasonable period thereafter for compliance and dispute resolution.
- Security and access logs are retained for operational needs and, where applicable, to comply with lawful directions, including minimum 180 day retention for certain system logs under Indian CERT In directions.
- Backups observe rolling retention windows. See product appendices for details.