Skip to content

Trust Center

Privacy

How WebCastle handles personal data — where it acts as a controller for its own business, where it acts as a processor for customers, and which document governs which.

DomainOperatingReviewed 12 August 2026

At a glance

  • The published WebCastle privacy policy is the authoritative legal document.
  • WebCastle is a controller for its own visitors, enquiries and staff.
  • On customer projects WebCastle acts as a processor on customer instruction.
  • Privacy enquiries reach the WebCastle team at security@webcastle.in.

How WebCastle approaches privacy

WebCastle designs, builds and operates web applications. Personal data reaches WebCastle in two very different ways, and almost every privacy question is easier to answer once it is clear which one applies.

In the first, WebCastle decides for itself what personal data to collect and why: visitors to its websites, people who submit an enquiry, prospects and commercial contacts, applicants, and its own staff. Here WebCastle is the controller. The published WebCastle privacy policy is the document that describes this handling, and it is the authoritative one.

In the second, personal data belongs to a customer and reaches WebCastle because WebCastle is building or running something on that customer's behalf. The customer decides what is collected, why, and for how long; WebCastle acts on the customer instruction. Here the customer is the controller and WebCastle is the processor. What WebCastle may and may not do with that data is set by the customer agreement, not by this page and not by the published privacy policy.

This page exists to make that split legible and to point you at the right document. It is a summary, written for people doing security and procurement review. It does not create obligations, define lawful bases, or set response deadlines. Where a practice is still being formalised, this page says so rather than implying it is settled.

Two roles, two governing documents

Identifying which role applies to your situation tells you which document to read and who to raise a request with.

  • WebCastle as controller

    Covers people who visit webcastletech.com or this Trust Center, submit an enquiry or a proposal request, correspond with WebCastle commercially, apply for a role, or work at WebCastle. WebCastle decides the purpose and means of this handling. The published privacy policy describes it.

  • WebCastle as processor

    Covers personal data inside applications and environments WebCastle builds or operates for a customer — the customer's own users, employees and records. WebCastle acts on the customer instruction and does not use that data for its own purposes. The customer agreement and any data processing terms in it govern this handling.

  • Which one applies to you

    If you are a user of a website or application WebCastle built for another organisation, that organisation is your controller and your first point of contact. WebCastle will support them in responding, and will pass on a request that reaches it by mistake rather than acting on it directly.

  • What WebCastle does not do

    WebCastle does not sell personal data, and it does not repurpose customer data for its own marketing, product development or model training. Access to a customer environment is granted to the people delivering that engagement rather than across the company.

The essentials

Privacy contact
Email security@webcastle.in for any privacy or data-protection enquiry. It is currently the same monitored mailbox used for security correspondence; a dedicated privacy address may be provisioned as the program develops.
What this page is
An orientation summary for security reviewers, customers and prospective customers. It is not a privacy notice, not a contract, and not a substitute for either the published policy or your agreement with WebCastle.
The governing document
For WebCastle as controller, the published privacy policy at https://webcastletech.com/privacy-policy. For personal data WebCastle processes on your behalf as a customer, your customer agreement and the data processing terms within it.
Making a request about your data
Write to security@webcastle.in describing what you are asking for and your relationship with WebCastle. If the data sits inside a customer environment, WebCastle will tell you which organisation to approach and notify that customer of the request.
Verification
WebCastle will take reasonable steps to confirm who you are before acting on a request about personal data, so that a request cannot be used to obtain someone else's information.

Personal data, cookies and retention

What WebCastle handles for its own business, how this site and the main site are measured, and how long information is kept.

As a controller, the personal data WebCastle handles is mostly ordinary business contact information: name, employer, role, email address, telephone number, and the content of the correspondence itself. Enquiry and proposal forms on the main site collect what the sender chooses to provide. Recruitment brings in application material. Employment brings in the records an employer necessarily holds. WebCastle does not seek special-category data in any of these routes and asks that it is not submitted through them.

This Trust Center is a static site. It has no accounts, no login, no forms and no user-submitted content, and it is not the place where personal data reaches WebCastle. The main site at https://webcastletech.com is where enquiry forms live, and where any cookies or analytics associated with WebCastle marketing operate.

Cookies and analytics on the main WebCastle site are described in the published privacy policy, which is the accurate reference for what is set and why. Where an application WebCastle built for a customer sets cookies or runs analytics, those choices belong to the customer as controller and are described in that organisation's own privacy notice rather than here.

WebCastle has not published fixed retention periods and this page will not invent them. In practice, business correspondence and commercial records are kept while the relationship is live and for as long as there is a legitimate business or legal reason afterwards; data inside a customer environment is retained and deleted according to the customer instruction and the agreement. Defining documented retention schedules is part of the ongoing development of the WebCastle data-protection program, and the data protection page tracks that work.

Rights individuals may have

Depending on the applicable law and on your relationship with WebCastle, you may have some or all of the rights below. Which of them apply, and on what terms, is determined by the law that governs your situation — not by this page. Where WebCastle acts as a processor, these rights are exercised against the customer who is your controller, and WebCastle supports them in responding.

  • Access

    To ask whether personal data about you is held and to obtain a copy of it, together with information about how it is used.

  • Correction

    To have inaccurate personal data corrected and incomplete data completed.

  • Deletion

    To ask for personal data to be erased, subject to the exceptions the applicable law allows and to any record WebCastle must retain for legal or business reasons.

  • Objection and restriction

    To object to certain uses of personal data, or to ask that its use be limited while a question about it is resolved.

  • Portability

    Where the applicable law provides it, to receive personal data you supplied in a structured, commonly used format, or to have it transmitted to another organisation.

  • Complaint to a supervisory authority

    To raise a complaint with the data protection or privacy regulator competent for you. WebCastle would prefer to hear from you first so it can put something right, but nothing here affects that route.

  • How to raise one

    Email security@webcastle.in and say what you are asking for. WebCastle will respond and, where it is a processor, route the request to the right controller. WebCastle does not publish its own statutory response deadline here; where a legal deadline applies to a request, that deadline is set by the applicable law.

Third parties and international transfers

WebCastle uses third-party services to run its business and to host and operate the applications it builds — cloud infrastructure, email, collaboration tooling, source control and similar. Some of these may process personal data. The subprocessors page lists the providers relevant to customer engagements, together with what each one is used for and where it operates.

Contractual arrangements with these providers vary. WebCastle relies on the data-protection terms that each major cloud and SaaS provider publishes for its customers, and is working through its supplier arrangements to make the position consistent and documented across the estate. WebCastle does not claim to have negotiated bespoke terms or transfer mechanisms with every provider, and vendor security review is being formalised alongside this.

WebCastle operates from India. Where a customer or its users are located elsewhere, personal data may be accessed from India or stored in a cloud region chosen for the engagement. Hosting region is an architectural decision made with the customer, and a customer with a data residency requirement should raise it early so it can be designed in rather than retrofitted. The specific transfer arrangements that apply to an engagement are a matter for the customer agreement and for legal advice on both sides.

A documented set of internal data-protection procedures — records of what is processed, a defined assessment step for higher-risk work, and standard contractual terms applied consistently to suppliers and customers — is being built as part of the ongoing development of the WebCastle security and privacy program. This page will be updated as each piece is approved rather than in advance of it.