Legal

Privacy Policy

Last updated: 25 July 2026

This Privacy Policy explains how Togo Tech Ventures Private Limited(“Togo Tech”, “we”, “us”), operating BackStage OS under its Backstage Advisors brand, collects, uses, shares, and protects personal data. It is written to align with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). By using the Service you acknowledge this Policy. It forms part of our Terms of Service.

1. Our role

For account and security data, we act as the Data Fiduciary. For the content you enter into your workspace (“Customer Data”), we act as a processor on behalf of your organisation, which determines what personal data (if any) it puts into the Service; that organisation is responsible for having a lawful basis to do so.

2. What we collect

  • Account data: your name, work email, role, and a securely hashed password. We never store passwords in plain text.
  • Workspace content: the records you create — pain points, capabilities, initiatives, vendors, KPIs, outcomes, comments, and notes. This may contain personal data only to the extent your organisation chooses to enter it.
  • Document links: URLs you add that point to your own document storage. We store the link only — never the file, and we do not fetch or open your documents.
  • Usage and audit data: a log of actions taken in your workspace (who changed what, and when), used for security and accountability.
  • Technical data: limited request metadata such as IP address, used for authentication, rate-limiting, and abuse prevention.

3. What we do not collect

  • We do not upload, host, or scan your documents — only the links you provide.
  • We do not use third-party advertising, analytics, or cross-site tracking technologies.
  • We do not sell or rent personal data to anyone, ever.

4. Cookies

We use only strictly necessary cookies to run the Service — there are no advertising or analytics cookies, so no consent banner is required for non-essential tracking (there is none). Specifically:

CookiePurpose
Session tokenKeeps you signed in. HTTP-only, same-site, secure in production.
Active workspaceRemembers which client workspace a Backstage consultant is viewing.

5. How we use personal data

  • to provide, secure, and support the Service and your account;
  • to authenticate you and prevent abuse (rate-limiting, brute-force protection);
  • to send transactional emails only — email verification, password reset codes, teammate invitations, and account notifications you have enabled. We do not send marketing email through this system;
  • to maintain the audit log and to comply with legal obligations.

6. Sharing and sub-processors

We do not sell personal data. We share it only with service providers who help us run the Service, under contractual confidentiality and data-protection obligations:

ProviderPurpose
SupabaseManaged PostgreSQL database hosting (where your data is stored)
VercelApplication hosting and delivery (compute; stores no customer data)
Zoho ZeptoMailDelivery of transactional emails

Within a consulting engagement, a client’s workspace data is made visible to our consulting team only after the client expressly approves that engagement inside the Service, and access is revoked when the engagement ends. We may also disclose data where required by law or to protect our rights, users, or the public.

7. Data retention

We retain Customer Data for as long as your workspace is active. On termination you may request an export before deletion; we then delete or irreversibly anonymise Customer Data within a reasonable period, except where retention is required by law. Audit and security logs may be retained for a limited additional period for accountability and fraud prevention.

8. Security

We apply measures appropriate to the risk, including: passwords hashed with bcrypt; encryption in transit (TLS); role-based access control enforced on every request; strict tenant isolation so one organisation cannot access another’s data; one-time email codes stored only as hashes; session revocation on password change; a content-security policy and standard security headers; and an audit trail of workspace actions. No system is perfectly secure, but we work to protect your data and to notify affected parties of a reportable breach as required by law.

9. Your rights

Subject to applicable law, including the DPDP Act, you may:

  • access a summary of the personal data we process about you;
  • request correction, completion, or updating of inaccurate data;
  • request erasure of your personal data where it is no longer needed;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • raise a grievance with our Grievance Officer (below) and, if unresolved, with the Data Protection Board of India.

Where we process Customer Data on behalf of your organisation, please direct these requests to your workspace owner; we will support them in fulfilling your request.

10. International transfers

Our providers may process data in locations outside your country. Where personal data is transferred across borders, we do so in accordance with applicable law and under appropriate safeguards with our sub-processors.

11. Children

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data of children; if you believe a child has provided data, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, communicated to workspace owners.

13. Grievance Officer and contact

In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer for any privacy concern or to exercise your rights:

Shashvat Jaiswal, Grievance Officer
Togo Tech Ventures Private Limited
Registered office: D 703, Himachali CGHS, Sector 3, Dwarka, Delhi – 110078, India
Email: privacy@backstageadvisors.com