Privacy Policy
Version 1.0 · Effective 25 August 2026
This policy explains how Dream Blend Solutions Private Limited collects, uses, stores and protects personal data in connection with MailDoc.
It is written to meet the Digital Personal Data Protection Act, 2023 (India), the Information Technology (Reasonable Security Practices) Rules, 2011, and, where applicable, the EU and UK General Data Protection Regulation.
1. The two roles we play
This distinction determines who is accountable for what, so it matters.
| Role | Applies to | Meaning |
|---|---|---|
| Data Fiduciary (Controller) |
Your account data: name, email, billing details, usage and security logs | We decide why and how this is processed, and we are accountable for it. |
| Data Processor | The contents of the mailboxes you connect, including your own customers' personal data | That data remains yours. We process it only on your documented instructions and make no independent use of it. |
Where we act as Processor, our Data Processing Addendum governs the relationship and forms part of your contract with us.
2. What we collect
Account information
- Name, email address and, if you enable SMS codes, phone number
- Organisation name, registered address and GSTIN
- An Argon2id hash of your password — the password itself is never stored
- Two-factor secrets, held encrypted, and hashes of backup codes
Mail data
- Message subjects, bodies, attachments and participant addresses from mailboxes you connect
- Mailbox credentials, encrypted with AES-256-GCM
Technical and security data
- IP address, browser and device characteristics
- Sign-in attempts, both successful and failed
- Audit records of which user performed which action and when
Billing data
- Plan, invoice history and payment status
- We never collect card details. Payment happens entirely on the gateway's own secure page. We receive only a transaction reference and a status.
Enquiry data
- Anything you submit through the contact form, plus the IP address it was sent from
3. What we do not do
This list matters as much as the one above.
- We do not sell, rent or licence personal data to anyone.
- We do not scan message content for advertising or profiling.
- We do not use message content to train artificial intelligence models.
- We run no third-party analytics, advertising or tracking scripts on our website.
- We do not share data with data brokers.
- We do not use automated decision-making that produces legal effects.
4. Why we process, and on what basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Operating your account | Account information | Performance of contract |
| Synchronising and storing mail | Mail data | Performance of contract |
| Preventing fraud and abuse | Technical and security data | Legitimate interests |
| Billing, tax and accounting | Billing data | Legal obligation |
| Responding to enquiries | Enquiry data | Consent |
| Service and security notices | Name and email | Legitimate interests |
5. How we protect it
- In transit: TLS 1.2 or above is mandatory, with HTTP Strict Transport Security enabled.
- At rest: AES-256-GCM authenticated encryption for message bodies, subjects, addresses and mailbox credentials, under a key separate from the application key.
- Passwords: Argon2id, a memory-hard algorithm chosen to make offline cracking expensive.
- Access control: role-based, default-deny, with permissions grantable at any level of your hierarchy.
- Audit: a hash-chained log that cannot be altered retrospectively, including by our own staff.
- Authentication: multiple two-factor methods, brute-force protection and optional network restrictions.
Full technical detail is on our Security page.
6. How long we keep it
| Category | Retention | Reason |
|---|---|---|
| Mail content | While your account is active, then 30 days | Recovery window before permanent deletion |
| Audit logs | 2 years | Security investigation and compliance |
| Sign-in attempts | 90 days | Abuse detection |
| Invoices and tax records | 8 years | Indian tax law |
| Contact enquiries | 2 years | Relationship history |
| Backups | 90 days on a rolling basis | Disaster recovery |
7. Your rights
Under the DPDP Act 2023 and, where it applies, the GDPR, you have the right to:
- Access — obtain a copy of the personal data we hold about you
- Correction — have inaccurate data corrected
- Erasure — request deletion where we have no overriding obligation to retain
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent — where processing relies on consent
- Nominate — appoint someone to exercise your rights if you are incapacitated or deceased (DPDP Act)
- Object or restrict — where processing relies on legitimate interests (GDPR)
- Complain — to us, or to the Data Protection Board of India or your local supervisory authority
Send requests to info@dreambspl.com. We verify identity before acting and respond within 30 days. There is no charge unless a request is manifestly unfounded or repetitive.
8. Sub-processors
We rely on the following third parties to deliver the Service. No others receive your data.
| Provider | Purpose | Location |
|---|---|---|
| Hosting provider | Server and database infrastructure | India |
| Razorpay | Payment processing | India |
| PayU | Payment processing | India |
| CCAvenue | Payment processing | India |
| PayPal | International payment processing | United States and European Union |
We give 30 days' notice before adding a sub-processor that handles personal data, and you may object.
9. International transfers
Data is stored in India. The single exception is PayPal, used only where a customer chooses to pay internationally; those transfers rely on Standard Contractual Clauses and PayPal's own safeguards. No mail content is ever transferred outside India.
10. Cookies
We use strictly necessary cookies only. There are no advertising, analytics or third-party cookies. Details are in our Cookie Policy.
11. Children
The Service is business software and is not directed at anyone under 18. We do not knowingly collect children's data. If you believe a child's data has reached us, contact us and we will delete it.
12. Breach notification
In the event of a personal data breach likely to cause harm, we will notify affected customers and the Data Protection Board of India within 72 hours of becoming aware, and provide what is known about the nature of the breach, its likely consequences and the steps being taken.
13. Changes
We update this page when our practices change, and increment the version number shown at the top. Material changes are notified by email at least 30 days in advance.
14. Contact
Dream Blend Solutions Private LimitedSamastipur
Samastipur, Bihar 848101
India
Email: info@dreambspl.com
Phone: +91 7280008555
Data Protection Officer
Data Protection Officer
info@dreambspl.com
+91 7280008555
Grievance Officer
Grievance Officer
info@dreambspl.com
+91 7280008555