1. Overview & Commitment
Arham Workspace ("we", "us", or "our") operates INBOX by Arham Workspace (accessible via inbox.arhamworkspace.tech, arhamworkspace.tech, and associated client applications). We provide secure, privacy-first business email hosting, administrative domain management, and email collaboration tools.
We are deeply committed to protecting the privacy, confidentiality, and integrity of your corporate and personal data. This Privacy Policy details the types of information we process, where and how it is stored, and the extensive controls you retain over your information.
2. Information We Collect
We only collect information strictly necessary to provision, authenticate, deliver, and maintain your business email infrastructure:
- Account & Registration Information: When an administrator registers an organization, we collect company name, administrator name, primary email address, encrypted password credentials, and contact details.
- Domain & DNS Records: To configure email routing (MX, SPF, DKIM, DMARC), we process your custom domain name and DNS status.
- Mailbox & Communication Data: As an email provider, our servers receive, transmit, and store your email messages, subject lines, headers, recipient lists, and attachments solely to deliver them to your mailboxes.
- Technical & Log Data: Standard server logs including IP addresses, browser user agent, login timestamps, protocol diagnostics (IMAP, SMTP, JMAP), and delivery status to detect unauthorized access, mitigate brute force attempts, and prevent outbound spam.
- Billing Data: For paid plan upgrades, transactions are processed securely through PCI-DSS compliant payment gateways (such as Razorpay). We do not store credit card numbers or banking passwords on our servers.
3. India Data Residency
In adherence to India's regulatory frameworks and enterprise data sovereignty requirements:
- All active customer mailboxes, databases, and message caches are hosted on sovereign cloud infrastructure located in India (AWS Asia Pacific - Mumbai,
ap-south-1). - Your data does not route through or reside in foreign jurisdictions for storage.
4. How We Use Data
We use your data solely for the following explicit purposes:
- Providing, routing, storing, and synchronizing business emails across your team.
- Authenticating users and administrators during login and session maintenance.
- Protecting mail systems from spam, phishing attacks, malware, and denial-of-service attempts.
- Sending essential transactional notifications (e.g., password reset requests, storage quota threshold alerts, security notifications, invoice receipts).
5. Zero Ads & No Content Scanning
Unlike free consumer email providers, our business model is straightforward subscription software:
- We never analyze your email contents to build demographic, behavioral, or advertising profiles.
- We never display advertisements inside the webmail interface or administrative console.
- Your communication remains strictly confidential between you and your recipients.
6. Data Retention & Deletion
You maintain full custody of your data:
- Active Subscriptions: Data is retained as long as your organization maintains an active account or trial.
- Account Cancellation: Upon terminating your account, you have a 30-day grace period to export all emails, contacts, and logs via standard IMAP/JMAP tools.
- Permanent Purge: Following the grace period, all server mailboxes, domain configurations, and associated records are permanently erased from active production clusters.
7. Security & Encryption
We employ enterprise-grade defensive measures across all layers of our stack:
- In-Transit Encryption: All web traffic and client connections are enforced via TLS 1.3 encryption (HTTPS, IMAP with STARTTLS, JMAP, and SMTP submission).
- At-Rest Encryption: Production databases and disk volumes utilize AES-256 encryption.
- Credential Hashing: User passwords are never saved in plaintext; they are securely salted and hashed using modern cryptographic algorithms.
- Isolated Tenants: Multi-tenant isolation guarantees that each organization's emails and settings remain strictly compartmentalized.
8. DPDP Act Compliance & User Rights
In compliance with India's Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000, users and data principals have the right to:
- Access & Review: Access the personal information stored in your account profile at any time.
- Correction & Updating: Correct or update incomplete or outdated information through the admin console.
- Erasure / Right to be Forgotten: Request the deletion of your account and personal data.
- Data Portability: Export email history, contacts, and configuration settings using open industry standards.
9. Third-Party Service Providers
We work with a minimal set of trusted infrastructure partners who adhere to rigorous data protection standards:
- Amazon Web Services (AWS ap-south-1, Mumbai): Core server infrastructure, database hosting, and high-deliverability outbound mail relay (Amazon SES).
- Razorpay: Payment processing for Indian and international payment methods. Razorpay processes payment credentials under strict PCI-DSS Level 1 compliance.
10. Grievance Officer & Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or wish to exercise your data rights, please contact our designated Grievance Officer:
Arham Workspace — Privacy & Grievance Office
Service: INBOX by Arham Workspace
Grievance & Support Email: support@arhamworkspace.tech
Administrative Contact: admin@arhamworkspace.tech
Response Turnaround: We acknowledge requests within 24 hours and resolve grievance submissions within the statutory period prescribed under Indian IT Rules.