1. Information we collect
Service details you submit: your name, phone number, e-mail address, device type, brand and model, the problem description, preferred appointment date/time, address if you request on-site work, and any notes or attachment references you choose to add.
Account information if you register as a customer: name, e-mail, phone number and a password handled by Firebase Authentication. We never store your password in our own database or logs — authentication is handled by Firebase Auth and only a hashed credential value exists in that system.
Ownership documents for password/account assistance jobs: a photo ID reference, purchase bill, box serial or written authorisation, retained as scanned references or metadata for the duration stated below.
Technical service records: Service ID, status history, diagnosis notes, approval messages, parts fitted, invoice number and amount, handover confirmation.
Website data: standard server logs (requested path, timestamp, approximate user-agent) used to keep the site running and to detect abuse, plus any analytics you enable in Admin → Settings.
- We do not ask for, and you should not send, full credit-card numbers, banking credentials, Aadhaar numbers, or passwords for your accounts.
- For password/account assistance we need proof that you own or represent the device — not your password to a bank, e-mail or social account.
- This site has no dependency on Firebase Storage or any other cloud object store. Attachments are not uploaded to our servers unless you separately configure an integration (see section 6).
2. How we use the information
To diagnose your device, prepare a written assessment and cost estimate, and obtain your approval before work starts.
To perform the service you hired: recovery, backup, migration, Windows or hardware work, malware cleanup, network or printer setup, scheduled maintenance.
To let you track status with your Service ID, send you updates, raise and deliver the invoice, and provide after-service support.
To keep records required for a legitimate business purpose: disputes, warranty on fitted parts, and evidence that an access request was authorised.
To improve our public content, e.g. publishing an anonymised case study — only with your written permission and never with your name, contact details or file contents.
- We do not sell or rent customer data.
- We do not use your personal files, photos or documents for marketing, demonstrations, screenshots or social media without written permission.
- We do not train machine-learning models on customer data.
- We do not send marketing messages to people who did not request them; you can opt out at any time by replying to any message.
3. What we see inside your device
Recovery and repair work necessarily involves access to storage. Our technicians are instructed to open and inspect only what the job requires, to avoid browsing personal content, and never to copy anything to a personal device or account.
Where the media can be read reliably, we work from a read-only sector image so your original drive is not written to during the recovery attempt.
Recovered or migrated data is delivered to you on the media you provide, or through a transfer method you approve. We do not publish or upload it anywhere.
Working copies are removed from our temporary storage after your handover is confirmed, following a short grace period (default 14 days) kept so you can ask for an immediate re-copy. If you want it deleted sooner, tell us and we will delete it and confirm.
4. Legal basis, applicable law and grievance contact
We process the information above on the basis of your consent, the service agreement between us, and our legitimate interest in running and defending the business, consistent with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and — once notified and applicable to us — the Digital Personal Data Protection Act, 2023 with its rules.
For requests relating to access, correction, deletion, or withdrawal of consent, write to us. Identity may be verified before we act, and we may decline where retention is required by law or by a documented dispute.
Grievance officer / point of contact: Ravi Prakash Prajapati, Proprietor — Prajapati NexaTech, 13/5, Mohanpuri, Meerut (U.P.) 250003 · +91 79833 82750 · raviprajapati@raviprajapati.com
5. Where data is stored and for how long
Website submissions and records are held in Cloud Firestore (Google Cloud) as configured in this project, and served by Express/Firebase Hosting. Where Firebase is not configured (local development), records stay in a local file store on our own server.
Service records and invoices: retained for the statutory accounting period (default 8 years in India) and deleted afterwards unless a dispute requires longer.
Ownership verification documents for access jobs: retained for 3 years so we can evidence authorisation, stored access-restricted, then deleted.
Contact and quote enquiries that did not become jobs: 12 months.
Account records you create: kept while your account is open; you can request deletion and we will remove the profile and close the account, except for transaction records we must retain.
6. Attachments, cookies and third parties
The booking and quote forms include an attachment field for architectural completeness. As deployed, this project does not upload files: the field records a reference (file name, size, type) and the UI tells you to send the actual files over WhatsApp or e-mail. No Firebase Storage bucket is created, used or required.
Authentication cookies / tokens: Firebase Auth issues session tokens for the customer and admin areas. We do not set advertising or cross-site tracking cookies.
Analytics, if enabled by the site owner, is configured in Admin → Settings and may use a privacy-respecting provider; enabling it is a deliberate site-owner decision, not a default.
Google Maps embed: the map loads from Google only when you click to open it on /contact.html, so a plain page view sends no data to Google.
WhatsApp links open whatsapp.com; that interaction is governed by WhatsApp/Meta’s own privacy terms.
7. Security measures
Firestore security rules restrict each customer to their own documents and reserve administration for accounts with the admin role; private pages are marked noindex; passwords are never stored by us outside Firebase Auth.
Transport is HTTPS-only in production, with security headers, strict input validation and sanitisation on every form, and rate limits on submission and authentication endpoints.
Admin access is limited to a small number of named accounts; role changes are possible only by an existing admin through Firestore, never from the public interface.
Physical handling: devices are stored in a locked area, labelled, and access is limited to the technician on the job.
No system is perfectly secure. If a breach affecting your data were to occur, we will notify you and provide the practical steps to limit harm.
8. Children, changes and contact
Our services are for adults or are provided through a parent, guardian or business. Please do not create accounts for children; we do not knowingly collect personal data from anyone under 18.
If this policy changes in a material way, the effective date at the top of this page changes and significant changes are announced on the website.
Questions, corrections or deletion requests: raviprajapati@raviprajapati.com or +91 79833 82750. Please include your Service ID if the request relates to a job.
This page is generated from the site content module so the wording stays identical everywhere it is referenced. Contact: raviprajapati@raviprajapati.com · +91 79833 82750. Questions about Indian IT-law obligations are answered honestly, including “we cannot do that”.