Privacy Policy
How inderkochar.in collects, uses, stores and protects personal information – for visitors, clients, people who book appointments and staff using the employee portal.
Effective date: 5 October 2026
This policy explains how Inder Pal Singh Kochar (“I”, “me”), operating the website inderkochar.in, collects, uses, stores and protects personal information. It covers visitors to the site, people who use the free tools, prospective and existing clients, people who book appointments, and staff who use the employee portal.
I collect only what is needed to answer you, deliver the services you ask for, run the business and keep the site secure. I do not sell personal information and do not use it for advertising or profiling.
Contents
- Who is responsible
- What I collect and why
- Free tools
- Cookies and similar technologies
- Service providers
- Where data is stored and international transfers
- How long I keep it
- Security
- Your rights
- Children
- Contact and grievances
- Changes to this policy
1. Who is responsible
The data controller (in India, the “Data Fiduciary”) is Inder Pal Singh Kochar, an independent IT consultant working in India and Australia. Contact: hello@inderkochar.in.
2. What I collect and why
Contact form and email
Your name, email address and message, plus optional company and phone number; the page you wrote from; and a one-way hash of your IP address for spam protection. Purpose: to reply to your enquiry and prepare a proposal. Basis: your consent and steps you ask me to take before a contract.
Newsletter
Your email address, the date and the page where you signed up. You confirm by email before anything is sent (double opt-in), and every email has a one-click unsubscribe link. Basis: your consent, which you can withdraw at any time.
Client accounts, support tickets and support plans
When you create a support account: your name, email address, company, password (stored only as a secure hash) and preferences. In tickets: the details, messages and files you send, and the time spent on them. For support plans: the plan, invoices and payment status. Card and PayPal details are entered on Stripe or PayPal and are never stored on this website. If you allow browser notifications, your browser’s push subscription is stored so you can receive ticket updates. Basis: performing our contract, and keeping accounting records required by law.
Appointments
The service, date and time you choose, your name, email address, phone number and any notes. Used to confirm the booking and send reminders by email. Basis: performing the service you request.
Subscription and payment reminders
For clients with recurring services: contact details, the service, renewal dates and payment status, used to send renewal reminders. Basis: performing our contract.
Comments
Your name, email address and comment. Your email is never published. Comments are moderated and checked for spam on this server.
Employee portal (staff only)
For people employed or engaged by me, the payroll system holds employment and payroll information: name, contact details, role, attendance and leave, salary, advances and reimbursements, payslips, payment details, statutory information, and identity documents provided for employment and legal purposes (for example Aadhaar). Basis: the employment relationship and legal obligations (tax, provident fund and similar). Identity documents are stored outside the public website and can only be opened by signed-in administrators; staff see only their own records.
Security and technical data
Like any web server, this site records technical information such as IP address, date and time, the page requested, browser type and referring page in server logs. A security plugin records sign-in attempts, form submissions and blocked requests (with IP address and approximate country) to stop abuse and attacks. Basis: legitimate interest in keeping the site and its users safe.
3. Free tools
Most tools (subnet calculators, config generators, password and hash generators and others) run entirely in your browser – what you type is not sent to the server. Files you check with the hash generator never leave your device.
The DNS Lookup and SPF, DKIM & DMARC Checker send the domain or IP address you enter to this server so it can query public DNS. Results are cached for a few minutes. To prevent abuse, lookups per connection are counted for a short time using a one-way hash of your IP address; lookups are not linked to your identity.
4. Cookies and similar technologies
This site uses no advertising or analytics cookies and no third-party tracking scripts on its public pages. Fonts and scripts are served from this server.
- Sign-in cookies – set by WordPress and the client and staff portals only when you sign in, to keep you signed in. Essential.
- Comment cookies – remember your name and email for future comments, only if you tick the box. Optional.
- Display preference – your light/dark choice is kept in your browser’s local storage and never sent to the server.
- Spam protection – forms on this site (contact, newsletter, comments, sign-in, registration, tickets and bookings) use a self-hosted check: your browser solves a small calculation before the form is sent. It sets no cookie and no third party is involved; a one-way hash of your network address is kept for up to an hour to limit abuse.
- Payment pages – Stripe and PayPal set their own cookies during checkout for fraud prevention.
You can block or delete cookies in your browser settings; essential sign-in cookies are needed to use the client and staff portals.
5. Service providers
I share personal information only with providers that help me run the services, under their own privacy and security commitments, and only as far as needed:
- Hosting – the website, database and backups run on a server I manage in Australia.
- Email – messages are sent through my own mail server (mail.inderkochar.in).
- Stripe and PayPal – processing online payments for support plans.
- Gravatar (Automattic) – profile pictures next to comments; a one-way hash of the commenter’s email address is used to look up the picture.
I may disclose information if required by law, a court order or a government authority, or to protect the rights and safety of clients, staff or the public.
6. Where data is stored and international transfers
Data is stored on a server in Australia. Clients and staff are mainly in India and Australia, and some providers (Stripe, PayPal) process data in other countries, including the United States. Where data leaves your country, I rely on the providers’ contractual and security safeguards and transfer only what is needed for the service.
7. How long I keep it
- Enquiries: up to 24 months after the last contact, unless we start working together.
- Newsletter: until you unsubscribe.
- Client accounts, tickets, invoices and appointment records: for the duration of the relationship and afterwards as long as needed for legal, tax and accounting obligations (usually up to 8 years).
- Employee and payroll records, including identity documents: for the employment and the period required by employment and tax law, then securely deleted.
- Security logs: rotated automatically, normally within 14–90 days.
- Backups: overwritten on a rolling basis.
8. Security
The site is served only over HTTPS. Access to personal data is limited to me and, for their own records, the people concerned. Measures include hashed passwords, rate-limited and monitored sign-in, sensitive documents stored outside the public web folder, server hardening, regular updates and backups. No system is completely secure; if a breach affecting your personal data occurs, I will notify you and the relevant authority as the law requires.
9. Your rights
Depending on where you live, you can:
- ask for a copy or a summary of the personal data I hold about you;
- ask me to correct, complete or update it;
- ask me to delete it, where I don’t have to keep it by law;
- withdraw consent (for example to the newsletter) at any time – this doesn’t affect anything done before;
- object to or ask me to restrict certain processing, and ask for your data in a portable format (EU/UK visitors);
- nominate another person to exercise your rights in case of death or incapacity (India).
Email hello@inderkochar.in. I may need to verify your identity and will respond within 30 days.
If you are not satisfied, you can complain to the authority where you live: in India, the Data Protection Board of India under the Digital Personal Data Protection Act 2023; in Australia, the Office of the Australian Information Commissioner (oaic.gov.au) under the Privacy Act 1988; in the EU or UK, your local data-protection authority.
10. Children
This site and its services are intended for adults and businesses. I do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data, please contact me and I will delete it.
11. Contact and grievances
For any privacy question, request or complaint, contact the person responsible for data protection (Grievance Officer):
Inder Pal Singh Kochar
Email: hello@inderkochar.in
I aim to acknowledge every request within 7 days.
12. Changes to this policy
I may update this policy when the services or the law change. The updated version will be published on this page with a new effective date; significant changes will be highlighted on the site or sent to clients by email.