Skip to content
IshanX Studio
Services How it runs Founder FAQ
Start a project
Services How it runs Founder FAQ Contact

Legal IshanX Studio

Privacy Policy

Last updated: 1 August 2026 · Governing law: India · Jurisdiction: Bhubaneswar, Odisha

On this page 1. Information we collect 2. Why we use it, and our legal basis 3. Who we share it with 4. How long we keep it 5. How we protect it 6. Your rights 7. Children 8. Cookies and tracking 9. Where your data is stored 10. Grievance officer 11. Changes to this policy

Who we are. “IshanX Studio”, “the Studio”, “we”, “us” and “our” refer to the software studio operating at ishanxstudio.in from Bhubaneswar, Odisha, India, founded and run by Ishan Nayak. The business is a registered Indian proprietorship; the registered owner of record is Mamata Tarai, Udyam Registration No. UDYAM-OD-19-0044440. “You”, “your” and “Client” refer to the person or organisation using this website or engaging our services.

This policy explains what personal information IshanX Studio collects, why we collect it, how long we keep it, and what rights you have. It applies to this website and to information you share with us during an engagement. We follow the Information Technology Act, 2000 and its rules, and the Digital Personal Data Protection Act, 2023 (DPDP Act).

The short version: we collect the minimum needed to reply to you and to run the services you have asked for. We do not sell your data, we do not run advertising trackers, and we delete what we no longer need.

1. Information we collect

Information you give us

  • Contact form and email — your name, email address, the service you selected and the message you wrote.
  • During an engagement — business details, billing details, and any credentials or access you choose to share with us so we can do the work.

Information collected automatically

  • Standard server logs kept by our hosting provider: IP address, browser and device type, referring page, pages visited and timestamps. These are used for security and troubleshooting.
  • Basic, privacy-respecting usage statistics, where enabled, to understand which pages are useful.

Client end-user data

When we build or operate a system for a client, that client's customer data may pass through infrastructure we manage. For that data the client is the Data Fiduciary and we act as a Data Processor on their instructions. We do not use it for our own purposes.

What we do not collect

We do not ask for and do not want your passwords for personal accounts, card numbers, CVV, OTPs, government ID numbers, biometric data or health information. Never send these to us. If you need to share a credential for project work, use a password manager share link or a temporary account with limited access.

2. Why we use it, and our legal basis

PurposeData usedBasis
Replying to your enquiryName, email, messageYour consent / steps towards a contract
Delivering the services you orderedBusiness, project and billing detailsPerformance of contract
Invoicing, accounting and tax recordsBilling detailsLegal obligation
Security, abuse prevention, backupsServer logsLegitimate use
Service updates about your projectEmailPerformance of contract

We do not use your information for profiling, automated decision-making, or advertising.

3. Who we share it with

We do not sell, rent or trade personal information. We share it only with:

  • Infrastructure and email providers that host this website and our mailboxes, so a message can reach us at all.
  • Payment and accounting providers, where you make a payment — they receive only what is needed to process it, and their own policies apply.
  • Government or law-enforcement authorities, where we are legally required to disclose.

Every provider we use is bound by its own confidentiality and data-protection obligations, and receives the minimum information necessary.

4. How long we keep it

  • Enquiries that do not become projects — up to 12 months, then deleted.
  • Client project records and correspondence — for the duration of the engagement plus 3 years, for support and warranty reasons.
  • Invoices and financial records — 8 years, as required by Indian tax law.
  • Server logs — typically 30 to 90 days, depending on the provider.
  • Backups — rotated on a schedule; deleted records disappear from backups as the rotation completes.

5. How we protect it

We apply reasonable security practices proportionate to the size of the Studio: HTTPS/TLS on all sites we run, access limited to the people who need it, credentials stored in a password manager rather than in chat or spreadsheets, multi-factor authentication on critical accounts, regular patching, and scheduled encrypted backups.

No system is perfectly secure. If a personal data breach affects you, we will notify you and the relevant authority as required under the DPDP Act, and tell you plainly what happened and what to do next.

6. Your rights

Under the DPDP Act you may:

  • Ask what personal data of yours we hold and how it is being used.
  • Ask us to correct data that is wrong, incomplete or out of date.
  • Ask us to erase data we no longer need for the purpose it was collected.
  • Withdraw consent you previously gave, at any time.
  • Nominate someone to exercise these rights on your behalf if you cannot.
  • Raise a grievance with us and, if unresolved, with the Data Protection Board of India.

To exercise any of these, email ishanits31@gmail.com from the address you contacted us with. We respond within 30 days. Some records — invoices, for example — must be retained by law even after a deletion request; we will tell you if that applies.

7. Children

This website and our services are intended for businesses and adults. We do not knowingly collect personal data from children under 18 through this site. If you believe a child has sent us personal data, write to ishanits31@gmail.com and we will delete it.

8. Cookies and tracking

This site is built to run without advertising or cross-site tracking cookies. Fonts and the 3D library are loaded from public content delivery networks, which necessarily see your IP address to serve the file. Full detail is in our Cookie Policy.

9. Where your data is stored

Our primary hosting is in India. Some providers we rely on — email, CDN, cloud storage — may process data on servers outside India. Where that happens, we use providers that offer contractual data-protection commitments, and transfers are made only to countries not restricted under Indian law.

10. Grievance officer

In line with Indian law, the person responsible for privacy grievances at IshanX Studio is:

Ishan Nayak — Founder, IshanX Studio
Email: ishanits31@gmail.com
WhatsApp: +91 84800 49428
Address: Bhubaneswar, Odisha, India
Response time: acknowledgement within 48 hours, resolution within 30 days.

11. Changes to this policy

We update this policy when our practices or the law change. The date at the top of this page always reflects the current version. Material changes affecting existing clients are communicated by email.

Questions about this page? Write to ishanits31@gmail.com, message +91 84800 49428 on WhatsApp, or reach @ISHANX_OFFICIAL on Telegram. We answer legal and privacy requests within 30 days, and usually much sooner.

IshanX Studio

We build the systems your business runs on — apps, websites, bots, payments, hosting and data, built and automated from Bhubaneswar, India.

Open for work

Services

Full-stack development Bots & automation Data management Hosting & infrastructure Payment integration Customer management

Studio

How it runs Founder Studio brief FAQ Contact

Legal

Terms & Conditions Privacy Policy Refund & Cancellation Service Delivery Cookie Policy Acceptable Use Disclaimer

© 2026 IshanX Studio. All rights reserved. · Registered owner: Mamata Tarai · Udyam Reg. No. UDYAM-OD-19-0044440 · Bhubaneswar, Odisha, India.

Built in-house · ishanits31@gmail.com