Data Processing Terms
Last updated 25 Sep 2026
These terms form part of the Terms of Service between you, the business using OnePageCard Staging, and Tilefin IT Solutions (OPC) Private Limited. They cover the information your site collects from your visitors and customers. For that information you decide what is collected and why, so you are the controller (under India's law, the data fiduciary), and we process it on your behalf. Where these terms and the Terms of Service differ on visitor information, these terms apply.
What we process, and why
| Purpose | Publishing your site, receiving what visitors send through it, delivering it to you by email and in your dashboard, and keeping it until you delete it |
| Whose information | People who visit your site, send you an enquiry, book an appointment or event, or leave a review you publish |
| What information | Name, email address, phone number, messages, booking details (including an address, if you offer home visits), the IP address an enquiry came from, and country and city counted per day for your statistics |
| How long | For as long as your account holds it: you can delete any item from your dashboard, and everything goes when your account is deleted. The IP address on an enquiry is removed after one year. |
What we commit to
- Only on your instructions. We process visitor information only to run your site as you have set it up, and as these terms describe. If we think an instruction breaks data protection law, we will tell you.
- Confidentiality. Anyone at Tilefin IT Solutions (OPC) Private Limited who can reach it is bound to keep it confidential, and reaches it only to run or support the service.
- Security. The measures described under How it is protected in our Privacy Policy, including isolation between businesses that is covered by automated tests.
- Sub-processors. You authorise the services listed under "Who else sees it" in our Privacy Policy, which says what each one receives and where it is. We hold each of them to data protection terms at least as protective as these. We will email you at least 14 days before adding one that receives visitor information, and if you object you can close your account before it starts.
- Helping you answer your visitors. You can see and delete enquiries and appointment bookings yourself in your dashboard, cancel event bookings, and download everything in one file from your profile. If a visitor writes to us about their information, we pass the request to you rather than answer it ourselves, unless the law requires otherwise. We will help with anything the dashboard cannot do.
- Breaches. If we become aware of a breach affecting your visitors' information, we will tell you without undue delay, with what we know about what happened, what was affected and what we are doing, so that you can meet your own obligations.
- Assessments. We will give you the information you reasonably need for a data protection impact assessment or a question from a regulator about our part.
- At the end. Export what you need before closing your account. When it is deleted, the visitor information goes with it; copies in backups are overwritten in the ordinary course of the backup cycle and are not used in the meantime. We keep nothing unless the law requires us to.
- Showing our compliance. We will answer reasonable written questions and give you the information needed to show that we meet these terms. An inspection can be agreed where a regulator requires one.
Information from the EU, the EEA, the UK or Switzerland
Our servers are in the Netherlands and our team is in India. Where visitor information you control is transferred from the EU or EEA to us, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, Module Two (controller to processor), form part of these terms, with you as data exporter and us as data importer. For those clauses: the optional docking clause and clause 11's option do not apply; under clause 9 the general written authorisation above applies, with the 14-day notice above; clauses 17 and 18 are governed by the law and courts of the Netherlands; the annexes are completed by this page (the parties, the table above, the security measures and sub-processors linked above) and the competent supervisory authority is the one where you are established. For the UK, the Information Commissioner's International Data Transfer Addendum applies alongside them, and for Switzerland they apply as adapted for the Swiss Federal Act on Data Protection.
Everything else
These terms last as long as we hold visitor information for you. The limits of liability in the Terms of Service apply to them, except where the law does not allow it.
Questions: privacy@onepagecard.com.