Skip to content
Keystone Technologies

Legal · Privacy Policy

Keystone Technologies Privacy Policy

Effective date: 3 October 2026

This Policy describes how Keystone Technologies collects and uses personal data for its own business website, enquiries, hiring and services that Keystone itself operates. It also explains Keystone’s limited role when it processes data for a business client. A client that decides why and how its app or service uses personal data is responsible for its own privacy notice; this Policy does not replace that notice.

1. Who we are and how to contact us

“Keystone”, “we”, “us” and “our” mean Keystone Technologies, the business name used by Proprietor Praveena Mehta, with registered/business address at Veera Desai Rd, Andheri West, Mumbai, India, 400053.

Privacy contact: Keystone Technologies, info@keystonetech.si; relations@keystonetech.si; +91 98199 99221; +91 98193 76763. Postal address: Veera Desai Rd, Andheri West, Mumbai, India, 400053. Privacy/grievance contact person: Praveena Mehta, Proprietor. Keystone will identify any statutory officer where applicable law requires one.

For Keystone’s own website, business enquiries and directly operated services, Keystone decides the purposes and means of the processing described here. For a client project, the client will normally decide those purposes and means and Keystone will process data on the client’s documented instructions under the relevant contract and DPA.

2. Personal data we may handle

Contact and identity details, such as name, business email, telephone number, organisation, job title and postal address.

Enquiry and relationship information, such as proposals requested, communications, support tickets, meeting notes and contract administration records.

Account and service data, such as account identifiers, authentication events, preferences and service configuration, where Keystone directly operates an account-based service.

Technical and usage data, such as IP address, device and browser information, timestamps, diagnostic logs, security events and feature usage, subject to configuration and applicable law.

Business-client project data that a client supplies or directs Keystone to process. This may include information about the client’s staff, customers or end users and, only where the project and contract require it, health or other sensitive information. The client must provide the required notices, authority and instructions.

3. How data is collected

We collect information directly when a person contacts us, requests a proposal, enters a contract, applies for work or uses a service that Keystone operates.

We may receive business contact details from the person’s organisation, an authorised client, a referral, a public business source or a service provider used for business operations.

Technical information may be generated automatically by a website or service. Cookies and similar tools are described in the Cookie Policy and are enabled according to the choices and controls available on the relevant site.

When Keystone acts as a processor, the client or its users provide the project data through the client’s service. The client controls the collection notice, permissions and the data subject relationship.

4. Why we use data

We use business contact and enquiry details to answer requests, assess opportunities, prepare proposals, negotiate and perform contracts, provide support and maintain business records.

We use account, technical and service data to operate, maintain, secure, troubleshoot and improve a Keystone-operated service; prevent misuse; and administer access.

We use information to comply with applicable law, respond to valid legal requests, establish or defend legal claims and protect people, systems and property.

We send promotional communications only where permitted. Each marketing message will include a way to opt out. An opt-out does not stop essential service or contract communications.

For client project data, Keystone uses information only to provide the contracted service, follow documented client instructions, maintain security, and meet legal obligations that apply to Keystone.

6. Health and other sensitive information

Keystone does not ask people to send medical records, health details, passwords or financial account credentials through a general business enquiry channel. Please use the designated client service if one has been provided.

Where a client instructs Keystone to process health or other sensitive data for a project, the client remains responsible for the service purpose, legal authority, notices, consent, professional decisions and user requests. Keystone follows its contract and documented instructions, applies agreed safeguards, and does not use that data for Keystone’s own advertising or unrelated purposes.

Keystone does not provide medical care or make clinical decisions merely because it hosts, builds or supports software that handles health information.

7. When we share personal data

We may share data with service providers that host, secure, support or operate Keystone’s own business systems, subject to appropriate contractual and access controls.

For a client project, we may make data available to the client and to sub-processors authorised under the project contract. The client should provide or link the current sub-processor information for its service.

We may disclose data to professional advisers, auditors, insurers, courts, regulators or law-enforcement authorities where necessary or legally required.

If Keystone undergoes a restructuring or transfer of a business, relevant records may be shared with the proposed successor under appropriate confidentiality and legal safeguards.

We do not sell personal data for money. We do not permit service providers to use client personal data for their independent advertising purposes.

8. Storage, locations and international transfers

Data is stored with the providers and in the locations selected for the relevant Keystone or client service. Actual providers and data locations must be identified in the applicable service notice or contract; Keystone does not promise that all data remains in India unless the service contract expressly says so.

Before a transfer or remote access from outside India, Keystone and the relevant client will identify applicable restrictions and implement an available lawful transfer mechanism or contractual safeguard where required. The client’s DPA and service schedule should identify the processing locations and transfer arrangement.

Keystone will not make a public claim about a specific hosting region, encryption standard or certification unless it has verified that claim for the relevant service.

9. Retention and deletion

We keep Keystone business records for the period needed for the purpose for which they were collected, applicable legal and accounting requirements, dispute handling and security. Actual retention periods depend on the record type and will be set in Keystone’s retention schedule.

For client project data, the client’s instructions and contract govern return, deletion, export and retention. Some copies may remain in protected backups until normal overwrite, or where retention is legally required; those copies remain protected and are not used for another purpose.

We will complete and publish a category-specific retention schedule before launch of any account-based product that stores personal data.

10. Choices and rights

A person may contact us to ask about data Keystone controls, correct inaccurate information, withdraw consent where processing relies on it, request deletion where available, opt out of marketing or raise a complaint. We may need information to verify identity and may retain records where law or a legitimate recordkeeping need requires it.

For data processed by Keystone for a client, direct requests to the organisation operating that product. Keystone will assist the client as required by contract and applicable law; Keystone may not be able to identify or respond to a request without the client’s direction.

Rights under the DPDP Act will be administered when the relevant provisions commence. We will update the contact process and user notices as required. A person may also use rights and remedies available under other applicable law.

11. Security and incidents

Keystone uses technical and organisational safeguards proportionate to the data and service, such as access controls, confidentiality commitments, secure configuration, backups or logging where configured, and incident handling. The specific controls for a client service are set out in its security schedule or DPA.

No online service or transmission can be guaranteed completely secure. If an incident affects data Keystone processes for a client, Keystone will notify the client under the contract and applicable law so the client can assess its own notice duties.

If a person believes their account or information has been misused, contact us promptly at the addresses in Section 1 and include the relevant service name and account identifier, but do not send passwords or unnecessary health information.

12. Cookies and similar technologies

Keystone websites may use strictly necessary storage for core functions and may use optional preference, analytics or advertising technologies only if the relevant site actually deploys them. The live consent interface and Cookie Policy describe the controls available. We do not assume every category is used on every website.

Changing browser settings may block some storage, but a site’s own preference tool should be used to withdraw or change optional choices where provided.

13. Children

Keystone’s general business website and business-to-business services are not designed to collect information directly from children. If a client project is intended for children or processes children’s data, the client and Keystone must agree specific age, consent, design and security controls before that processing begins.

If you believe a child has provided personal data directly to a Keystone-operated service inappropriately, contact us so we can review and take appropriate steps.

14. Complaints and changes

Contact Keystone first using the details in Section 1. We will review and respond within the period required by the law applicable to the request. Where a regulator or statutory grievance process applies, a person may use that process after completing any required first step.

We may revise this Policy when services, data practices or law change. The revised version will show a new effective date. If a change materially affects a person’s choices, Keystone or the responsible client will provide an additional notice where required.