Last updated: 1 October 2026
This Privacy Policy explains how Srutio Media And Software, a sole proprietorship registered in Kolkata, West Bengal, India, handles personal data that it collects through swaranlabs.com, the Site, and through the software Products sold on the Site. The Site is run under the name Swaran Labs, which is the software and technical wing of Srutio Media And Software. In this Policy, the Company, we, us and our mean Srutio Media And Software.
The Company decides why and how your personal data is processed. It is therefore the Data Fiduciary for that data under the Digital Personal Data Protection Act, 2023, the DPDP Act, and you are the Data Principal. This Policy is written to be the notice that section 5 of the DPDP Act and Rule 3 of the Digital Personal Data Protection Rules, 2025, the DPDP Rules, require. It is also the privacy policy that Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the SPDI Rules, requires.
Two sets of rules apply on different dates. Section 43A of the Information Technology Act, 2000 and the SPDI Rules apply to us today, because the Explanation to section 43A defines a body corporate to include a sole proprietorship engaged in commercial or professional activities. The DPDP Rules were notified on 13 November 2025, and their provisions on notice, consent, security, breach reporting, retention and your rights take effect on 13 May 2027. The DPDP Act omits section 43A when the provision that says so comes into force. We follow the DPDP standard from now on, so nothing in this Policy waits for those dates.
1. What We Collect
- 1.1 Account and order data. Your name, email address, billing address and order history, and your invoices. We collect these when you order a Product, including a free Product. If you create an account, we also hold your username and your password, which we store only in hashed form. If you buy for a business and give a GSTIN so that it appears on the invoice, we keep the GSTIN with the order.
- 1.2 Payment data. The payment provider named at checkout collects and processes your card, UPI or bank details. We never see or store them. We receive from the provider a transaction reference, the amount, the status of the payment, and the name and email address that the provider supplies for the payer.
- 1.3 Licence and device data. When you activate, check or deactivate a licence key in a software Product, the Product sends the licence key and a device identifier to our licence server on swaranlabs.com. The device identifier is a one-way hash that the Product computes on your device from hardware identifiers. The hardware identifiers themselves are not sent. We use the identifier to count activations against the limit stated on the Product page, which is currently two devices. The Product repeats the check from time to time.
- 1.4 Technical data. Your IP address, browser type and version, device and operating system, the page that referred you, the pages you request, and the date and time. Our server records this automatically for every request, including a request from a Product to the licence server. Cookies and similar technologies collect further data only as the Cookie Policy describes.
- 1.5 Communications. What you send us by email or through a form on the Site, if the Site offers one, including your name, your email address, your message and any attachment, and our replies.
- 1.6 Consent records. When you make a choice in the cookie tool, we record the choice, the time, your country and a masked form of your IP address, so that we can show what you chose.
- 1.7 Updates you ask for. If you subscribe to updates about new Products or releases, your email address and the time you subscribed.
- 1.8 What we do not receive from a Product. A Product processes your files, documents, audio and other content on your device, and we do not receive that content. Apart from the licence check in clause 1.3, a Product sends data to us only where its End User License Agreement or an in-app notice says so before it does.
- 1.9 Sensitive data. We do not ask for health data, biometric data or a government identity number, and we ask you not to send them to us. Your account password is the only item of sensitive personal data that we hold, because the SPDI Rules treat a password as such. Payment instrument details are also sensitive under those Rules, and only the payment provider holds them.
2. Notice and Purpose of Processing
We process your personal data only for the purposes listed below. Where the list says that we rely on your consent, we ask for it before we start, and you can withdraw it as clause 3.3 explains.
To take your order, deliver the Product, issue your licence key and send your invoice
- Data used: Account and order data, payment reference
- Basis: You gave the data for this purpose, which is a legitimate use under clause a of section 7 of the DPDP Act
To run the licence check, enforce the activation limit and stop a key being shared or resold
- Data used: Licence key, device identifier, IP address
- Basis: You give the key to the Product to activate it, for this purpose, which is the same legitimate use
To answer support requests and complaints and to keep a record of them
- Data used: Communications, order data
- Basis: You gave the data for this purpose, which is the same legitimate use
To meet tax, accounting and other record-keeping duties, including GST
- Data used: Order and invoice data
- Basis: The law requires us to keep these records, and the DPDP Act allows retention that is needed to comply with law
To keep the Site secure, detect abuse and keep the logs that the law requires
- Data used: Technical data, licence data
- Basis: The security safeguards and logs that the DPDP Act, the SPDI Rules and the CERT-In Directions of 28 April 2022 require. Your browser sends this data when it asks for a page
To understand how the Site is used, using aggregated data
- Data used: Analytics identifiers, pages viewed, approximate location, device
- Basis: Your consent, given in the cookie tool
To send you updates about new Products or releases
- Data used: Email address
- Basis: Your consent, given by a clear action and never by a pre-ticked box
To show what you chose in the cookie tool
- Data used: Consent records
- Basis: Our duty to prove your consent, which the DPDP Act places on us
- 2.1 We do not use your personal data for a purpose that is not in this list. If we need to, we tell you first and ask for your consent where the law requires it.
- 2.2 We do not make decisions about you by automated means that have legal or similarly significant effect. The licence check compares a key and a device identifier with a count, and a failed check leaves you able to write to us for a review.
- 2.3 We do not send reminders about a checkout that you did not finish, and we do not use retargeting or advertising tools.
3. Your Consent and How to Withdraw It
- 3.1 Where we rely on your consent, it is free, specific, informed, unconditional and unambiguous, and you give it by a clear affirmative action. We never treat a pre-ticked box, silence or a default setting as consent.
- 3.2 We do not make consent to a purpose that is not needed for your order a condition of buying a Product.
- 3.3 You may withdraw a consent at any time and as easily as you gave it. For cookies, use the cookie tool in the Site footer. For updates, use the unsubscribe link in any update email or write to the address in Section 9.
- 3.4 Withdrawing consent does not affect the lawfulness of processing done before you withdrew. If a service needs data that you have withdrawn consent for, we may stop that service, and you bear the consequences of that. We cannot stop processing that is needed to supply a Product that you have already ordered and paid for.
- 3.5 Where we process data because you gave it for a stated purpose, you may tell us at any time that you do not consent to that use. We then stop, subject to the same limit for an order that you have already placed.
4. Sharing of Data
We share personal data only with the recipients listed below, and only to the extent each one needs it for the stated purpose. Each recipient that processes data for us does so under a written contract with us. Where the recipient decides for itself how the data is used, it is a Data Fiduciary in its own right, and its own privacy policy applies as well.
PayPal, the Site’s payment gateway, named at checkout
- What it receives: The payment details you enter, the order amount, and your name and email address
- Why: To take your payment and to make a refund
Hostinger, our web hosting provider
- What it receives: All data held on the Site, including server logs
- Why: To host the Site and the licence server
Hostinger, whose mail service sends our order emails, invoices and replies
- What it receives: Your email address and the content of order and support emails
- Why: To deliver order emails, invoices and replies
Google, only if you consent to analytics
- What it receives: Analytics identifiers, pages viewed, approximate location and device
- Why: To produce aggregated statistics about use of the Site
Wordfence, the security service that runs on the Site
- What it receives: Technical data, including IP addresses
- Why: To block abuse and keep the Site secure
Government and regulatory bodies, courts and law enforcement, including the Data Protection Board of India, CERT-In and tax authorities
- What it receives: What the law requires and no more
- Why: To comply with a legal duty or an order
- 4.1 We do not sell, rent or trade your personal data to anyone for their own marketing.
- 4.2 Some recipients listed in this section store or process data outside India. The DPDP Act allows a transfer of personal data outside India except to a country that the Central Government has restricted. Where the SPDI Rules apply to sensitive personal data, we transfer it only to a recipient that ensures the same level of data protection, and only where the transfer is needed to perform our contract with you or where you have agreed to it.
- 4.3 You may ask us for the names of all the recipients that hold your personal data and for a description of the data each one holds. Section 6 explains how.
5. Data Retention
We keep each kind of data only for as long as the list below says. When that period ends, we erase the data or remove anything that identifies you, unless a law or a legal proceeding requires us to keep it longer.
Order, invoice and payment records
- How long we keep it: Until 72 months after the due date of the annual GST return for the year that the record belongs to, and for longer if an appeal or an investigation needs it
- Why: Section 36 of the Central Goods and Services Tax Act, 2017
Account data, such as your username and saved details
- How long we keep it: While your account is open. We delete it within 30 days after you ask us to close the account or to erase it, except for records in this list that we must keep
- Why: To run your account
Licence records, including the licence key, device identifiers and activation history
- How long we keep it: For the life of the licence and for one year after it ends
- Why: To support and secure the licence. The DPDP Rules require personal data and processing logs to be kept for at least one year
Server, application and security logs, which include IP addresses
- How long we keep it: One year
- Why: The CERT-In Directions require 180 days as a rolling minimum. The DPDP Rules require one year from 13 May 2027
Support emails and complaint records
- How long we keep it: Three years after the matter closes
- Why: A consumer complaint may be filed within two years, under section 69 of the Consumer Protection Act, 2019, and we keep a margin beyond that
Cookie consent records
- How long we keep it: For as long as we rely on the choice, and for one year after
- Why: To prove your consent
Analytics data
- How long we keep it: 14 months
- Why: To measure use of the Site over time
Your subscription to updates
- How long we keep it: Until you unsubscribe or withdraw consent. We then keep a record of the withdrawal, and nothing else, so that we do not write to you again
- Why: To honour your choice
- 5.1 If you ask us to erase your data, we erase what we can and we tell you what we keep and why. The law does not let us erase records that we must keep, such as a GST invoice.
- 5.2 Closing your account does not end our duty to keep your order records and the logs of your processing for the periods in the list.
6. Your Rights as a Data Principal
- 6.1 You have the right to obtain a summary of the personal data we process about you and the processing we carry out on it, and the identities of every other Data Fiduciary and Data Processor with whom we have shared it, with a description of what we shared.
- 6.2 You have the right to have inaccurate or misleading data corrected, incomplete data completed and out-of-date data updated.
- 6.3 You have the right to ask us to erase your personal data, unless keeping it is necessary for the purpose it was collected for or to comply with law.
- 6.4 You have the right to withdraw consent, as clause 3.3 explains, and to review the information that you have given us, under Rule 5 of the SPDI Rules.
- 6.5 You have the right to nominate another individual to exercise these rights for you if you die or become unable to do so.
- 6.6 You have the right to a readily available way to raise a grievance, and to a response within the period in Section 9.
- 6.7 To exercise a right, write to the Grievance Officer at the address in Section 9. We may ask you to prove who you are, so that we do not give your data to someone else. We do not charge a fee for a request under this Section.
- 6.8 This notice is available in English on this page. You may ask us for it in any language listed in the Eighth Schedule to the Constitution of India, and we will give it to you in that language.
7. Data Security and Personal Data Breaches
- 7.1 We protect the data we hold with reasonable security safeguards that match the volume and sensitivity of the data. They include encryption of data in transit, hashed storage of passwords, access controls that limit access to the proprietor, a web application firewall and login protection, software updates, backups, and logs that we monitor and review.
- 7.2 We keep a written information security programme that is proportionate to the data we hold, as Rule 8 of the SPDI Rules requires.
- 7.3 If a personal data breach affects you, we tell you without delay. Our message describes the breach, its likely consequences for you, what we have done to reduce the harm, what you can do to protect yourself, and how to reach us. We also report the breach to the Data Protection Board of India without delay and give it more detail within 72 hours.
- 7.4 We report the cyber incidents that the CERT-In Directions of 28 April 2022 list, including unauthorised access to systems or data and data breaches, to CERT-In within six hours of noticing them.
- 7.5 No system can be made completely secure. That fact does not reduce our duty to keep reasonable safeguards, and it does not limit any right you have to compensation.
8. Children’s Data
- 8.1 The Site and the Products are for adults. A child is a person under 18. We do not sell to a child and we do not knowingly process a child’s personal data.
- 8.2 We do not track or monitor the behaviour of children, and we do not direct advertising at them.
- 8.3 If you think that a child has given us personal data, write to the Grievance Officer. Unless we hold the verifiable consent of the child’s parent or lawful guardian, we will erase the data.
9. Contact and Grievance Redressal
- 9.1 For a question about this Policy, to exercise a right, or to raise a grievance, contact the Grievance Officer. Name: Eeshin. Designation: Chief Architect and Proprietor, Srutio Media And Software. Email: eeshin@swaranlabs.com. Srutio Media And Software operates entirely online from Kolkata, West Bengal, India, and it gives its registered address to the Data Protection Board, a court or an authority that asks for it.
- 9.2 These are the business contact details that sub-section 9 of section 8 of the DPDP Act and Rule 9 of the DPDP Rules require us to publish, and the name and contact details of the Grievance Officer that sub-rule 9 of Rule 5 of the SPDI Rules requires. We repeat them in every reply that we send to a request under this Policy.
- 9.3 Support and general questions go to support@swaranlabs.com. We pass any message from that address that concerns your personal data to the Grievance Officer.
- 9.4 We acknowledge a grievance within 48 hours. The acknowledgement carries a reference number and a copy of the grievance as we recorded it. We redress the grievance within one month of receiving it. Rule 14 of the DPDP Rules lets a Data Fiduciary set a period of up to 90 days, and ours is shorter.
- 9.5 Please raise a grievance with us first. If you remain dissatisfied, you may complain to the Data Protection Board of India in the way that the DPDP Act and the DPDP Rules provide. While section 43A of the Information Technology Act, 2000 remains in force, you may claim compensation before the adjudicating officer under that Act if you believe that our failure to keep reasonable security safeguards has caused you a loss. Nothing in this Policy limits your right to approach a Consumer Commission.
10. Changes to This Policy
- 10.1 We may update this Policy, including as the DPDP Rules take effect. We post the updated version on this page with a new last updated date. A material change carries a dated note at the top of the page for 30 days, and where the change affects how we use data that you gave us, we also email the address on your order.
- 10.2 If a change needs your consent, we ask for it. We do not treat your continued use of the Site as that consent.
