PRIVACY POLICY
STRATRAN
Website: STRATRAN.com
Effective Date: 23 August 2026
Last Updated: 23 August 2026
1. Introduction
STRATRAN (“STRATRAN”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal information entrusted to us.
This Privacy Policy explains how STRATRAN collects, uses, processes, stores, discloses, and protects personal information when you:
- visit or use com;
- contact us through our website, email, telephone, or other communication channels;
- request information, quotations, consultations, or services from us;
- become or interact with us as a customer, supplier, consultant, business partner, candidate, employee, or other business contact; or
- interact with STRATRAN in connection with our consulting, technology, BPO, KPO, RPO, recruitment, outsourcing, or related services.
STRATRAN is an India-based business that intends to provide services to clients and organizations internationally. Accordingly, this Privacy Policy is intended to address applicable Indian data-protection requirements as well as, where applicable, privacy requirements in other jurisdictions, including the European Union/European Economic Area (“EU/EEA”) and the United Kingdom.
This Privacy Policy should be read together with any applicable contractual terms, Data Processing Agreement (“DPA”), service agreement, recruitment privacy notice, cookie notice, or other privacy notice that may apply to a particular STRATRAN service or engagement.
2. About STRATRAN
Legal/Business Name: STRATRAN
Business Registration:
Registered in India under the Micro, Small and Medium Enterprises Development (MSMED) Act, 2006
Udyam Registration Number:
UDYAM-DL-03-086574
Registered Address:
STRATRAN
30, Venus Apartment
Paschim Vihar
New Delhi – 110041
India
Email – Info@stratran.com
Grievance – GRP@stratran.com
Business Activities:
STRATRAN provides consulting, technology services, Business Process Outsourcing (“BPO”), Knowledge Process Outsourcing (“KPO”), Recruitment Process Outsourcing (“RPO”), and related professional services to businesses and organizations across industries.
3. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed by STRATRAN in connection with its own business activities and website.
Where STRATRAN processes personal information on behalf of a client as part of BPO, KPO, RPO, technology, consulting, outsourcing, or other services, STRATRAN may act as a data processor/service provider while the client or another organization determines the purposes of processing.
In such circumstances, the applicable client contract, DPA, instructions, and applicable law may govern the processing. Individuals whose information is processed on behalf of a client may need to direct certain privacy requests to that client, depending on the circumstances.
4. Privacy Laws That May Apply
STRATRAN is based in India and will handle personal information in accordance with applicable Indian laws and regulations.
These may include, where applicable, the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025, and other applicable Indian laws and regulations relating to privacy, information technology, cybersecurity, employment, contractual obligations, and data protection.
The DPDP framework has a phased commencement structure, and STRATRAN will implement applicable requirements as and when they become legally effective. The company may update its privacy practices and this Privacy Policy as the applicable Indian framework develops.
Where STRATRAN’s processing falls within the territorial scope of the EU General Data Protection Regulation (“GDPR”), STRATRAN will comply with the GDPR requirements applicable to that processing.
Where applicable, STRATRAN may also comply with other privacy laws applicable to its international operations, clients, personnel, or data subjects, including applicable UK data-protection requirements.
Nothing in this Privacy Policy is intended to provide individuals with fewer rights than they are entitled to under mandatory applicable law.
5. Personal Information We May Collect
Depending on the nature of your relationship with STRATRAN, we may collect different categories of information.
5.1 Information You Provide Directly
This may include:
- Full name
- Company or organization name
- Job title, designation, or professional role
- Business address
- Residential address where necessary
- Email address
- Telephone or mobile number
- Professional profile information
- Information contained in business correspondence
- Enquiry and communication details
- Information provided in forms
- Information contained in proposals, quotations, contracts, or service requests
- Payment, billing, and invoicing information where applicable
- Recruitment and candidate information
- CVs/resumes and employment history
- Qualifications and professional experience
- References and other recruitment information
- Information necessary to provide contracted services
- Information voluntarily provided to us for a specific business purpose
5.2 Technical and Usage Information
When you access STRATRAN.com, we may automatically receive certain technical information, such as:
- IP address
- Browser type
- Device type
- Operating system
- Approximate location derived from technical information
- Date and time of access
- Pages visited
- Referring website
- Website interaction information
- Security and diagnostic logs
- Other information generated through normal website operation
5.3 Information Received from Third Parties
We may receive personal information from third parties where legally permitted, including:
- Clients
- Business partners
- Recruitment partners
- Professional advisers
- Vendors and service providers
- Publicly available professional sources
- References provided during recruitment
- Individuals authorized to provide information on your behalf
6. Special Categories and Sensitive Information
STRATRAN does not intentionally request sensitive personal information through its general website unless it is necessary for a specific and legitimate business purpose.
However, because STRATRAN provides RPO, BPO, KPO, consulting, technology, and outsourcing services, certain client engagements may involve information that is considered sensitive or specially protected under applicable law.
Examples may include:
- Government identification information
- Employment information
- Financial information
- Health information
- Background-verification information
- Biographical information
- Diversity or equal-opportunity information
- Other information subject to special legal protection
Where such information is processed, STRATRAN will apply appropriate safeguards and process it only where permitted or required by applicable law and contractual instructions.
7. Purposes for Which We Use Personal Information
We may process personal information for the following purposes:
Business Operations
- Responding to enquiries
- Communicating with customers and prospects
- Providing consulting and technology services
- Providing BPO, KPO and RPO services
- Managing client relationships
- Preparing proposals and quotations
- Negotiating and performing contracts
- Managing suppliers and business partners
- Providing customer support
Recruitment and Human Resources
- Processing job applications
- Candidate screening and evaluation
- Recruitment administration
- Communicating with candidates
- Conducting lawful background checks where applicable
- Managing employment-related processes
Technology and Security
- Operating and maintaining our website
- Monitoring system performance
- Detecting and preventing fraud
- Protecting information systems
- Investigating security incidents
- Preventing unauthorized access or misuse
- Maintaining business continuity
Legal and Regulatory
- Complying with applicable laws
- Responding to lawful requests from government authorities
- Establishing, exercising, or defending legal claims
- Maintaining accounting, tax, audit, and business records
- Enforcing contracts and policies
Marketing
Where permitted by applicable law, we may use contact information to provide information about STRATRAN’s services, solutions, capabilities, events, or business offerings.
You may opt out of marketing communications at any time.
8. Legal Basis for Processing – GDPR
Where the GDPR applies, STRATRAN will process personal information on an appropriate legal basis.
Depending on the circumstances, the legal basis may include:
- Consent – where you have provided valid consent;
- Contract – where processing is necessary to enter into or perform a contract;
- Legal obligation – where processing is necessary to comply with applicable law;
- Legitimate interests – where processing is necessary for STRATRAN’s legitimate business interests and those interests are not overridden by applicable rights and interests;
- Vital interests – where applicable; or
- Other lawful grounds permitted under applicable law.
Where STRATRAN processes information on behalf of a client, the client’s instructions and applicable legal basis may determine the underlying processing.
9. Processing Under Indian Data-Protection Law
Where Indian data-protection law applies, STRATRAN will process digital personal data in accordance with applicable requirements, including applicable provisions of the DPDP Act and the DPDP Rules as they come into force.
Where consent is required, STRATRAN will seek consent in an appropriate manner and provide information about the purposes for which personal data is processed.
Where applicable, individuals may be provided with mechanisms to exercise rights, withdraw consent, and raise complaints in accordance with applicable Indian law.
10. Data Controller and Data Processor Roles
Depending on the circumstances, STRATRAN may act as:
Data Controller / Equivalent
Where STRATRAN determines the purposes and means of processing personal information for its own business activities, STRATRAN may act as the controller or equivalent entity under applicable law.
Data Processor / Service Provider
Where STRATRAN processes personal information on behalf of a client, STRATRAN may act as a processor, service provider, or equivalent entity.
For example, in an RPO engagement, a client may provide candidate information to STRATRAN so that STRATRAN can perform recruitment-related services on the client’s behalf.
In such cases, STRATRAN will generally process information according to the client’s documented instructions, the applicable service agreement, DPA, and applicable law.
11. Sharing of Personal Information
STRATRAN does not sell personal information as a business activity.
We may disclose personal information where reasonably necessary to:
- Authorized STRATRAN employees and personnel
- Contractors and consultants
- Clients and customers
- Recruitment partners
- Technology and IT service providers
- Website hosting providers
- Email and communication providers
- Cybersecurity and infrastructure providers
- Professional advisers
- Lawyers and auditors
- Financial institutions and payment service providers
- Government authorities and regulators
- Courts and law-enforcement authorities where legally required
- Potential purchasers, investors, successors, or transaction parties in connection with a merger, acquisition, restructuring, investment, or sale of business assets
Third parties will receive information only where there is a legitimate business, contractual, operational, or legal reason for doing so and subject to applicable safeguards.
12. Hosting and Email Infrastructure
STRATRAN’s website is hosted through Xozz.
The hosting/server location identified by STRATRAN is:
Pune, Maharashtra, India
STRATRAN uses Roundcube as its email interface/environment.
Email and related information may also be processed by the underlying email hosting, mail-server, security, infrastructure, and communications providers used by STRATRAN.
Such information may include:
- Email addresses
- Email content
- Email attachments
- Communication metadata
- IP addresses
- Login information
- Technical logs
- Security information
STRATRAN will take reasonable measures to ensure that service providers handling personal information are appropriately selected and managed.
13. International Data Transfers
Because STRATRAN intends to serve international customers, personal information may be processed in India and, where necessary, in other jurisdictions.
Where personal information protected by the GDPR or another applicable international privacy law is transferred outside the relevant jurisdiction, STRATRAN will use an appropriate lawful transfer mechanism where required.
Depending on the circumstances, such mechanisms may include:
- An adequacy decision;
- Standard Contractual Clauses (“SCCs”);
- Appropriate contractual safeguards;
- Other legally recognized transfer mechanisms; or
- Another lawful mechanism permitted under applicable law.
Where STRATRAN acts as a processor for an international client, applicable international-transfer requirements may also be addressed through the client’s DPA and contractual arrangements.
14. European Economic Area – GDPR
Where the GDPR applies to STRATRAN’s processing, individuals in the EU/EEA may have rights including:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restriction of processing;
- Right to data portability;
- Right to object;
- Rights relating to automated decision-making and profiling, where applicable;
- Right to withdraw consent where processing is based on consent; and
- Right to lodge a complaint with a competent data-protection supervisory authority.
These rights are subject to the conditions and exceptions established by applicable law.
STRATRAN will generally respond to valid GDPR requests within the time period required by applicable law.
We may request reasonable information to verify the identity of the requester before responding to a request.
15. European Representative
Where Article 27 of the GDPR requires STRATRAN to appoint an EU representative, STRATRAN will assess the requirement and, where legally applicable, appoint an appropriate representative.
The details of such representative will be added to this Privacy Policy when applicable.
EU Representative:
[To be inserted if legally required]
STRATRAN will not represent that an EU representative has been appointed unless such appointment has actually been made.
16. Data Protection Officer
STRATRAN will determine whether it is legally required to appoint a Data Protection Officer (“DPO”) under applicable law.
Where a DPO is appointed, the relevant contact details will be published in this Privacy Policy.
Data Protection Officer / Privacy Contact:
[Insert applicable name/title]
17. Your Rights and Privacy Requests
If you believe that STRATRAN holds personal information about you, you may contact us to:
- Request access to information;
- Request correction of inaccurate information;
- Request deletion where legally available;
- Withdraw consent where applicable;
- Request restriction of processing where applicable;
- Object to certain processing;
- Request data portability where applicable;
- Ask questions about our processing activities;
- Raise a privacy complaint; or
- Exercise other rights available under applicable law.
Requests will be assessed according to the law applicable to the relevant processing activity.
Where STRATRAN processes information solely on behalf of a client, we may direct your request to the relevant client where appropriate.
18. Marketing Communications
STRATRAN may send business or marketing communications where permitted by law.
You may opt out of marketing communications at any time by:
- Using an unsubscribe mechanism included in the communication, where available; or
- Contacting STRATRAN using the privacy contact details provided below.
Opting out of marketing communications will not prevent us from sending essential transactional, contractual, security, legal, or service-related communications.
19. Cookies and Similar Technologies
STRATRAN.com may use cookies and similar technologies.
Cookies may be used for:
- Essential website functionality;
- Security;
- User preferences;
- Website performance;
- Analytics;
- Understanding website usage; and
- Improving our services.
Where required by applicable law, STRATRAN will obtain consent before placing non-essential cookies or similar tracking technologies.
You may also manage cookies through your browser settings.
A separate Cookie Policy may be published by STRATRAN where appropriate.
20. Automated Decision-Making and Profiling
STRATRAN does not intend to make decisions producing legal or similarly significant effects based solely on automated processing unless such processing is lawful and appropriate safeguards are implemented.
If automated decision-making or profiling is introduced in circumstances where applicable law requires specific disclosures, consent, human intervention, or other safeguards, STRATRAN will provide the information and rights required by applicable law.
21. Data Retention
STRATRAN will retain personal information only for as long as reasonably necessary for the purposes for which it was collected or as required by:
- Contractual obligations;
- Applicable law;
- Tax and accounting requirements;
- Regulatory obligations;
- Dispute resolution;
- Legal claims;
- Security requirements; or
- Legitimate business requirements.
Retention periods may vary depending on the type of information and the purpose of processing.
When personal information is no longer required, STRATRAN may securely delete, destroy, anonymize, or otherwise dispose of it, subject to applicable legal and contractual requirements.
22. Data Security
STRATRAN takes reasonable technical, organizational, administrative, and physical measures designed to protect personal information.
Depending on the nature and risk of processing, these measures may include:
- Access controls;
- Password and authentication controls;
- Role-based access;
- System monitoring;
- Security logging;
- Backup procedures;
- Data minimization;
- Confidentiality obligations;
- Vendor and service-provider controls;
- Security awareness measures;
- Incident-response procedures; and
- Appropriate technical safeguards.
However, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure.
Accordingly, STRATRAN cannot guarantee absolute security of personal information.
23. Personal Data Breaches and Security Incidents
STRATRAN maintains procedures intended to identify, assess, investigate, contain, and respond to personal-data and information-security incidents.
Where required by applicable law or contractual obligations, STRATRAN will notify relevant authorities, clients, or affected individuals within the applicable legally required timeframe.
Where STRATRAN processes information on behalf of a client, applicable breach notification responsibilities may be governed by the relevant DPA and service agreement.
24. Data Minimization
STRATRAN seeks to collect and process only personal information reasonably necessary for the relevant business, contractual, legal, operational, security, or service purpose.
We encourage individuals not to provide unnecessary personal or sensitive information through general website forms or ordinary business communications.
25. Children’s Privacy
STRATRAN’s website and professional services are primarily intended for businesses, professionals, organizations, job applicants, and other legitimate business users.
STRATRAN does not knowingly seek to collect children’s personal information for general commercial website activities.
If you believe that a child has provided personal information to STRATRAN in circumstances where such collection is not permitted, please contact us so that appropriate steps can be taken.
26. Third-Party Websites and Services
STRATRAN.com may contain links to websites, applications, platforms, or services operated by third parties.
STRATRAN is not responsible for the privacy, security, content, or practices of third-party websites.
We recommend reviewing the privacy policies of third parties before submitting personal information to them.
27. Confidentiality of Business and Client Information
STRATRAN recognizes that its consulting, technology, BPO, KPO, and RPO engagements may involve confidential business information.
Confidential information received from clients, candidates, suppliers, employees, or business partners will be handled according to applicable contractual obligations, confidentiality commitments, and applicable law.
Where required, separate confidentiality agreements, non-disclosure agreements, DPAs, or contractual security requirements may apply.
28. Client Data and Sub-Processors
Where STRATRAN processes personal information on behalf of a client, STRATRAN may use authorized third-party service providers or sub-processors where necessary to provide the contracted services.
Depending on the applicable contract and law, STRATRAN may:
- Maintain a list of relevant sub-processors;
- Require contractual confidentiality obligations;
- Require appropriate security measures;
- Restrict processing to authorized purposes;
- Require appropriate data-protection obligations; and
- Remain responsible for sub-processor activities to the extent required by applicable contract and law.
For enterprise clients, specific sub-processor requirements may be addressed in the applicable DPA.
29. International Clients and Data Processing Agreements
For international clients, STRATRAN may enter into a Data Processing Agreement or equivalent data-protection provisions.
Depending on the services and applicable law, such agreements may address:
- Processing instructions;
- Categories of personal information;
- Categories of data subjects;
- Processing purposes;
- Confidentiality;
- Security measures;
- Sub-processors;
- International transfers;
- Data-subject requests;
- Personal-data breaches;
- Data retention and deletion;
- Audits and compliance information; and
- Assistance with regulatory obligations.
Where required, applicable Standard Contractual Clauses or other lawful international-transfer mechanisms may be incorporated into the contractual arrangements.
30. Complaints
If you have concerns about how STRATRAN handles your personal information, we encourage you to contact us first so that we can investigate and attempt to resolve the issue.
You may also have the right to lodge a complaint with the relevant data-protection authority or regulator applicable to your circumstances.
For individuals in the EU/EEA, this may include the data-protection supervisory authority in the country where you live, work, or where you believe an infringement occurred.
For individuals in India, complaints and rights will be handled in accordance with applicable Indian data-protection law and the mechanisms available under that law.
31. Privacy Contact
For privacy questions, requests, complaints, or data-protection matters, please contact:
STRATRAN
30, Venus Apartment
Paschim Vihar
New Delhi – 110041
India
Privacy Email:
GRP@stratran.com
Website:
STRATRAN.com
When making a privacy request, please provide sufficient information for us to understand and verify your request. Please do not send unnecessary sensitive personal information.
32. Changes to This Privacy Policy
STRATRAN may update this Privacy Policy from time to time to reflect:
- Changes in our business;
- New services or technologies;
- Changes to our data-processing practices;
- Changes in applicable laws or regulations;
- Changes in international operations; or
- Changes in contractual or security requirements.
The latest version will be published on STRATRAN.com and will include the applicable “Last Updated” date.
Where required by law, we will provide additional notice or obtain consent before making material changes.
33. Governing Law
This Privacy Policy is intended to operate in conjunction with applicable laws and does not exclude mandatory rights or protections available to individuals under the law applicable to their personal information.
For STRATRAN’s activities in India, applicable Indian law will apply subject to any mandatory legal rights applicable to the relevant individual or processing activity.
Where GDPR or another mandatory privacy regime applies to particular processing activities, the relevant mandatory provisions of that regime will apply to that processing notwithstanding any general provision of this Privacy Policy.
34. Important Notice Regarding GDPR and International Operations
STRATRAN’s inclusion of GDPR-related provisions in this Privacy Policy does not by itself constitute a representation or certification that STRATRAN is “GDPR certified” or universally subject to every GDPR requirement.
The applicability of GDPR depends on the nature, location, purpose, and circumstances of the relevant processing activity.
STRATRAN will assess the applicability of GDPR and other international privacy laws to its relevant services, clients, personnel, and processing activities and will implement appropriate contractual, technical, organizational, and legal measures where required.
35. Contact Information Summary
STRATRAN
30, Venus Apartment
Paschim Vihar
New Delhi – 110041
India
Udyam Registration No.: UDYAM-DL-03-086574
Website: STRATRAN.com
Hosting Provider: Xozz
Primary Hosting/Server Location: Pune, India
Email Interface/Provider: Roundcube
Privacy Contact: info@stratran.com
Grievance – GRP@stratran.com

