Blutrain
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

What we collect, why, how long we keep it, and what you can require of us. Written to be read rather than to be technically defensible while remaining opaque.

Last updated: 8 September 2026

Who this applies to

This policy explains how Blutrain Private Limited ("Blutrain Private Limited", "we", "us") handles personal data. It covers three groups of people, and the treatment differs between them:

  • Website visitors — anyone browsing theblutrain.com.
  • Enquirers — people who contact us by form, email or phone.
  • Client personnel — named contacts at organisations we work with.

It does not cover personal data belonging to our clients' own customers, employees or users, which we may process while delivering an engagement. In that situation the client is the Data Fiduciary and we act as a Data Processor on their documented instructions under a separate agreement. Section "When we process data on a client's behalf" explains how that works.

What we collect

We collect as little as we can reasonably operate with.

When you use the website

Our web server records standard request logs: IP address, timestamp, page requested, referrer and user-agent string. These are used for security and to understand which pages are read, and they are deleted or aggregated within 90 days.

The site sets no advertising or cross-site tracking cookies. Your theme preference (light or dark) is stored in your browser's local storage; it never reaches our servers and you can clear it at any time through your browser settings.

When you contact us

Your name, email address, and — if you provide them — organisation, phone number and the content of your message. The message content is the part that matters to us, and we would ask you not to include confidential technical details or personal data about third parties in a first message.

When you become a client

Business contact details for the people we work with, correspondence, and the commercial and billing records required to run and account for the engagement.

Why we use it, and on what basis

Under the Digital Personal Data Protection Act, 2023, we process personal data for the following purposes:

PurposeBasisRetention
Responding to your enquiryYour consent, given by contacting us24 months from last contact
Delivering a contracted engagementPerformance of the contractDuration of engagement, then as below
Invoicing, tax and statutory recordsLegal obligation8 years, per Indian accounting and tax law
Website security and abuse preventionLegitimate use90 days

We do not sell personal data. We do not share it with advertisers. We do not use it to build profiles for marketing, and we do not run behavioural advertising of any kind.

When we process data on a client's behalf

Delivering an engagement often means handling personal data that belongs to our client's customers, patients, employees or users. When that happens:

  • The client remains the Data Fiduciary. We act only as a Data Processor.
  • A written data processing agreement is in place before any data moves.
  • We process that data only for that client's engagement, on their documented instructions.
  • We never use one client's data to train, tune or evaluate anything for another client, and we never use it to improve a general-purpose model of our own.
  • We work with anonymised, pseudonymised or synthetic data wherever the engagement permits it, and we will propose that route by default.
  • Access is limited to the engineers assigned to that engagement, and it is logged.
  • On completion, data is returned or destroyed per the agreement, and we confirm in writing when it has been.

Where an engagement would involve a third-party model provider processing client data, we identify that provider, the data involved and the applicable terms during scoping — and where the requirement is that data must not leave the client's environment, we design for self-hosted models instead.

Who else sees it

We keep the number of third parties deliberately small. The categories are:

  • Infrastructure and hosting providers — for the website and our internal systems.
  • Business tools — email, document storage and accounting software.
  • Professional advisers — accountants and legal counsel, under duties of confidentiality.
  • Authorities — where we are legally required to disclose. If we receive such a request affecting a client's data, we will notify that client unless we are legally prohibited from doing so.

These are service providers, not data recipients in their own right. None of them is permitted to use your data for their own purposes.

Where your data is held

Our primary infrastructure is located in India. Some business tools we use may process data outside India; where that is the case we rely on the provider's contractual data-protection commitments and, for client engagements, we agree the position explicitly in the data processing agreement.

Where a client's requirements or sector regulation demand that data must remain within India or within their own environment, we architect the engagement to meet that from the outset. This is a common requirement in financial services and healthcare work and it is not an obstacle.

Your rights

Under the DPDP Act you may:

  • Access — ask what personal data of yours we hold and how it is used.
  • Correct — have inaccurate or incomplete data corrected or completed.
  • Erase — ask us to delete data we no longer need for the purpose it was collected for, or where you withdraw consent.
  • Withdraw consent — at any time, as easily as it was given. This does not affect processing already carried out.
  • Nominate — appoint someone to exercise these rights on your behalf in the event of death or incapacity.
  • Complain — raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied with our response.

Write to sales@theblutrain.com. We respond within 30 days. If your request concerns data we hold as a processor for a client, we will direct you to that client, who is the Data Fiduciary, and assist them in responding.

How we protect it

Concretely, rather than as a general assurance:

  • Encryption in transit (TLS) and at rest for stored data.
  • Role-based access, granted per engagement and reviewed when an engagement ends.
  • Multi-factor authentication on all internal systems.
  • Separate environments per client engagement — no shared data stores between clients.
  • Access logging, retained and reviewable.
  • Confidentiality obligations binding on every member of staff and any subcontractor.

No system is perfectly secure, and we will not claim otherwise. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required, with what we know, what we are doing, and what you should do.

Children

Our services are provided to organisations, and this website is not directed at children. We do not knowingly collect personal data from anyone under 18 through this site. Where an engagement involves data about minors — in education or healthcare work, for example — the additional protections required by the DPDP Act are agreed with the client before any data is processed, including the restriction on behavioural monitoring and targeted advertising directed at children.

Changes to this policy

If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle data belonging to enquirers or clients, we will notify the people affected directly rather than relying on them to notice a revised page.

Contacting us

For any question about this policy, or to exercise your rights, contact:

Blutrain Private Limited
SCF 08, 2nd Floor, The Eminence Plaza
Ambala–Chandigarh Expressway
Zirakpur, Punjab 140603
India
Email: sales@theblutrain.com
Telephone: +91 95010 19942

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Next step

Questions about any of this?

Write to sales@theblutrain.com or call +91 95010 19942. We would rather clarify a term before an engagement than argue about it during one.