Privacy policy
Two things reach us from this website: the server's record of your request, and an email if you choose to send one. This is what happens to both.
It is longer than most website privacy pages because it states the retention periods rather than gesturing at them, and because it draws a hard line between this website and the systems we deploy for customers. Those are two different things and they are governed by two different documents.
This page applies to the westra.dev website. It does not govern Westra's products or any system we build for a client; those are covered by the contract signed for them.
Effective 20 September 2026
1Who this is from, and what it covers
- 1.1Westra publishes the website at westra.dev. This is Westra's privacy policy. For personal data collected through that website it is also the notice that section 5 of the Digital Personal Data Protection Act, 2023 requires us to give you.
- 1.2For that personal data, Westra is the Data Fiduciary and you are the Data Principal, as those terms are used in the Act and the rules made under it. In this policy, "the Act" means the Digital Personal Data Protection Act, 2023.
- 1.3This policy does not govern personal data held inside a Westra product deployed for an organisation. That distinction is set out at clause 9, and for anyone reading this as part of an evaluation it is the most important paragraph on the page.
- 1.4"We", "us" and "our" mean Westra. "You" means the person reading this.
- 1.1
2What this website collects
- 2.1The website is a set of static files. It sets no cookies, runs no analytics, no tag manager, no session recording and no advertising pixels. There are no accounts and no forms, so there is nothing on it that asks you for personal data.
- 2.2The typefaces are served from this domain rather than fetched from a third party, so opening a page here does not tell anyone other than the server that answers the request that you did.
- 2.3Server log data. Whoever serves these files records the ordinary details of a web request: the IP address it came from, the page it asked for, the time, the HTTP status and the browser's user-agent string. That is the minimum a server needs in order to answer you. We add nothing to it, we do not combine it with any other source, and we do not use it to work out who you are.
- 2.4Correspondence. If you write to hi@westra.dev, we hold what you put in the message: usually your name, your email address, your organisation, your role, and whatever you tell us about the problem you are trying to solve. A message exists only because you chose to send one; nothing on this site sends one on your behalf.
- 2.5We do not ask for financial, health or biometric data anywhere on this site, we do not buy personal data from anyone, and there is no mailing list to be added to.
- 2.1
3Why we hold it, and on what basis
- 3.1Server log data is held so that the site can be served, so that it stays available, and so that abuse or a security incident can be investigated. It is not used for anything else.
- 3.2Correspondence is held to answer you and to carry on the conversation you started. Where it leads to a proposal, a bid or a contract, it is held as part of the record of that engagement.
- 3.3The Act allows personal data to be processed for a lawful purpose for which you have given consent, or for one of the certain legitimate uses in section 7. When you write to us you provide your personal data voluntarily for a specified purpose, which is getting an answer, so we rely on the legitimate use in section 7(a) for that purpose and for purposes reasonably connected to it. Clause 7 says what happens if you would rather we did not hold it.
- 3.4Where a law requires us to keep something, section 8(7) of the Act allows us to retain it for as long as that law requires, even after the purpose we first held it for has been served. Clause 6 and the schedule below say which records that applies to.
- 3.5We do not profile you, we do not make automated decisions about you, and we do not use anything you send us to train a model.
- 3.1
4Who else can see it
- 4.1This website is served as static files by a hosting provider. That provider necessarily handles the server log data described above in order to answer requests, and does so as our Data Processor: on our instructions, under contract, and for no purpose of its own.
- 4.2Our correspondence sits in a business email service, whose provider handles it on the same footing.
- 4.3We do not name either provider on this page, because the arrangement can change and a stale name is worse than none. We will name both in writing to a Data Principal who asks, and to an evaluator as part of a tender response.
- 4.4Section 8(2) of the Act only permits a Data Fiduciary to engage a Data Processor under a valid contract. Both engagements are on that footing, and we remain answerable to you for what a processor does with your personal data.
- 4.5We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone else, except where a law, a court or another competent authority requires it, in which case we disclose only what is required.
- 4.1
5Where it is kept
- 5.1Personal data collected through this website is kept in India. Storage in India is a condition of engaging any provider described in clause 4, and we will confirm the arrangement in writing on request.
- 5.2Section 16 of the Act permits personal data to be transferred outside India except to a country the Central Government restricts. Our position is narrower than the Act requires: we do not transfer personal data collected through this website out of India at all.
- 5.3Where a Westra product is deployed for an organisation, data residency is a term of that deployment rather than of this policy. Clause 9 and the security page cover it.
- 5.1
6How long we keep it
- 6.1We keep personal data for as long as the purpose it was collected for requires, or for as long as a law requires us to retain it, whichever is longer. When neither applies, it is deleted.
- 6.2The retention schedule below states the period for each kind of data this website collects, and the position for data inside a Westra deployment. It forms part of this policy.
- 6.3Deleting a record from a live system does not remove it from backups already taken. It stays in those backups until they age out on the rotation in the schedule, and it is not restored into the live system afterwards.
- 6.4Where a court, a regulator or another competent authority requires data to be preserved, or where it is relevant to a proceeding that is live or that we reasonably anticipate, the periods in the schedule are suspended for the data in scope until that requirement is lifted.
- 6.1
7Your rights as a Data Principal
- 7.1Access, under section 11. You may ask us for a summary of the personal data we hold about you and of how it is being processed, together with the identities of any other Data Fiduciaries and Data Processors we have shared it with and a description of what was shared.
- 7.2Correction and erasure, under section 12. You may ask us to correct personal data that is inaccurate or misleading, to complete or update it, and to erase it. We will erase it unless keeping it is necessary for the purpose you gave it for or for compliance with a law, and where we cannot erase it we will tell you which obligation stops us and for how long.
- 7.3Grievance redressal, under section 13. You may raise a grievance about anything we do with your personal data, by the means set out at clause 8.
- 7.4Nomination, under section 14. You may nominate another individual to exercise these rights on your behalf in the event of your death or your incapacity.
- 7.5To exercise any of them, write to hi@westra.dev with enough detail for us to identify the correspondence in question. We will acknowledge within seven working days and answer within thirty days, and in any event within the period prescribed under the rules made under the Act. There is no charge for any of it.
- 7.6The Act places duties on you as well. Section 15 requires that you do not impersonate another person when exercising a right, and that you do not raise a grievance you know to be false or frivolous.
- 7.1
8Grievances, and the Data Protection Board
- 8.1Send a grievance to hi@westra.dev. That address reaches the person able to answer questions about Westra's processing of personal data, whose contact information section 8(9) of the Act requires us to publish, and it is the grievance mechanism section 13 requires us to maintain.
- 8.2Tell us what happened, what you would like us to do about it, and how to reach you. We will acknowledge it and tell you what we intend to do.
- 8.3If you are not satisfied with our answer, or if we do not answer, you may complain to the Data Protection Board of India. The Act requires you to exhaust our grievance mechanism before you approach the Board.
- 8.1
9Data inside Westra products
- 9.1Where an organisation deploys a Westra product, the personal data inside that deployment belongs to that organisation, and that organisation is the Data Fiduciary for it. Westra is a Data Processor, and handles that data only on the organisation's documented instructions and under the contract signed for the deployment.
- 9.2That organisation's own privacy notice governs the data, not this policy. If you are a citizen, an employee, a client or a customer of an organisation that runs a Westra product, and you want to exercise a right over data held inside it, address the organisation rather than us. If you write to us, we will tell you so, and where our contract allows we will tell you who to write to.
- 9.3Depending on how a product is deployed, Westra may hold no copy of the data at all. An on-premise or air-gapped deployment runs entirely inside the organisation's own perimeter. The deployment options are set out on the security page.
- 9.4The terms that govern data inside a deployment — where it lives, where the model runs, what it may be used for, and how it comes back out — are set out below and on the security page. They are contractual terms, not statements of intent.
- 9.1
10Children, and persons with a disability
- 10.1This website is not directed at children. Nothing on it asks anyone for personal data, and we do not knowingly hold the personal data of anyone under eighteen.
- 10.2Section 9 of the Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed, and the same for a person with a disability who has a lawful guardian. It also prohibits tracking, behavioural monitoring and advertising directed at children. We do none of those things on this site, to anyone, of any age.
- 10.3If you believe a child's personal data has reached us in correspondence, write to hi@westra.dev and we will delete it.
- 10.1
11Security, and what happens after a breach
- 11.1Section 8(5) of the Act requires reasonable security safeguards to prevent a personal data breach. The controls that apply to Westra systems are set out on the security page.
- 11.2If a personal data breach occurs, section 8(6) of the Act requires us to give intimation of it to the Data Protection Board of India and to each affected Data Principal, in the form and manner prescribed. We will.
- 11.3Where a breach affects a customer's deployment, we notify the customer, because the customer is the Data Fiduciary and the duty to notify Data Principals is theirs. The contract for the deployment sets the time within which we have to tell them.
- 11.1
12Changes to this policy
- 12.1If this website begins to collect something it does not collect today, this policy changes before that happens rather than after.
- 12.2The effective date at the top of this page is the date this version took effect. We keep the versions that came before it and will send you one on request.
- 12.1
Retention schedule
Data this website collects
- Web server access logs
The server's record of each request to this site: IP address, page requested, time, status and user-agent. The period matches the rolling 180 days the CERT-In directions require ICT system logs to be maintained for, and they are maintained in India.
Kept for: 180 days
Then: Rotated out and overwritten. No archive copy is taken.
- Security investigation records
Where log entries form part of an investigation into an attack, abuse or a suspected breach, the entries that matter are copied out of the rotation and held with the investigation.
Kept for: 12 months from the close of the investigation
Then: Deleted with the investigation file, unless a legal hold applies.
- Correspondence that does not become an engagement
Email to hi@westra.dev and our replies, where the conversation ends without a proposal or a contract.
Kept for: 24 months from the last message
Then: Deleted from the mailbox and from the mail system's deleted items.
- Correspondence that becomes an engagement
Email that forms part of the record of a proposal, a bid or a contract, including the names and contact details of the people on both sides of it.
Kept for: The term of the engagement, then 8 years
Then: Deleted with the engagement record.
- Tender and procurement documents
Documents we receive or submit in a procurement, including pre-bid clarifications and technical compliance sheets. These usually carry the names and contact details of officials.
Kept for: 8 years from the award or the close of the tender, or the period the tender conditions require, whichever is longer
Then: Deleted, unless the contract awarded requires otherwise.
- Records a law requires us to keep
Invoices, accounting records and the rest of the statutory record, which may carry your name, your organisation and your contact details.
Kept for: The period the law requires — not less than eight financial years for books of account under the Companies Act, 2013, and 72 months for records under the goods and services tax law
Then: Deleted at the first annual review after the period ends.
Data inside a Westra deployment
Here the customer sets the period and Westra carries it out. These are the defaults that apply where a contract is silent; a contract that says otherwise governs.
- Records inside a deployment
Everything your users create in a Westra product, and the metadata around it. It is yours. Westra is a Data Processor for it and sets no retention period of its own.
Kept for: As your own retention policy and the law that applies to you require
Then: Disposed of by the method your policy specifies.
- Audit trail
The tamper-evident record described on the security page. It has to outlive the records it describes, or it cannot evidence what happened to them.
Kept for: The life of the records it describes, then the further period your policy sets. Where your policy is silent, 7 years
Then: Exported to you, then deleted.
- Operational logs
Application and infrastructure logs kept in order to run and support the deployment: errors, performance and access events. They can carry usernames and IP addresses.
Kept for: 180 days, or longer where your contract sets a longer support or forensic window
Then: Rotated and overwritten.
- Backups
Point-in-time copies taken so that a deployment can be restored. A record deleted from the live system stays inside backups already taken until those backups age out.
Kept for: Daily for 30 days, weekly for 13 weeks, monthly for 12 months, unless your contract sets a different rotation
Then: Overwritten in place by the rotation. Backups are encrypted at rest.
- Hand-back at the end of a contract
When a contract ends, your data is exported to you in open formats and the copies Westra holds are then deleted.
Kept for: Available for export for 30 days after the contract ends
Then: Deleted from live systems within 30 days of the end of that window, and from backups as the rotation completes, within 12 months at the outside. A certificate of deletion on request.
- Data under legal hold
Data a court, a regulator or another competent authority requires to be preserved, or that is relevant to a proceeding that is live or reasonably anticipated.
Kept for: Until the hold is lifted
Then: The ordinary period resumes and disposal happens at the next cycle. We tell you when a hold is placed on your data and when it is lifted, unless we are prohibited from telling you.
What deletion means
A deleted record is removed from the live system and cannot be reached through the application or restored by us through it. It persists inside backups already taken until those age out on the rotation above.
Storage media that leaves our control is sanitised or destroyed before it is disposed of, and the disposal is recorded.
Where a different period applies
If a law, a tender condition or your own contract requires a longer period than this schedule, the longer period applies. If it requires a shorter one, the shorter one applies and we will tell you what changed.
Where your organisation is a government department, your own record retention rules govern the records inside your deployment and this schedule yields to them.
Review
The schedule is reviewed once a year, and whenever the law behind one of these periods changes. A change to the schedule is a change to this policy.
Your data stays yours, in India
- Deploy on-premise, on MeghRaj government cloud, on a private cloud or air-gapped.
- Data residency in India by default, with no replication outside the country.
- Models can run entirely inside your perimeter. Nothing you enter is used for training.
- Full export of your data in open formats at any time. No lock-in.