Privacy Policy

Effective from: 31 August 2026·Last updated: 18 September 2026

This policy explains what personal information this website collects, why we hold it, who else sees it, how long we keep it and what you can ask us to do about it. Most of it is simple. Fill in the enquiry form and we keep what you typed, so that an engineer can answer you properly. Read a few pages and leave, and two things are recorded: the ordinary server log every website keeps to stay online and secure, and a count of your visit in Google Analytics, which tells us which pages people read. That count is linked to a random identifier in a cookie, never to your name. We run no advertising trackers here. We do not sell personal data, and we do not use it to build advertising profiles.

In legal terms, Fabtech Cleanrooms Limited is the Data Fiduciary for the personal data described here, and you are the Data Principal. This policy is issued under India's Digital Personal Data Protection Act 2023 (the DPDP Act) and, where they apply, the Information Technology Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (the SPDI Rules). Indian law governs it, and we will update it as the DPDP Act and the rules made under it come into force in phases.

01

Who we are, and what this policy covers

Fabtech Cleanrooms Limited designs, builds and validates cleanrooms and manufactures cleanroom equipment, from its registered office in Mumbai, Maharashtra. We are the company responsible for the personal data described here.

This policy covers www.fabtechcleanroom.com, the enquiry form on it, the email and telephone conversations that follow an enquiry, and CVs sent to us in response to our careers page. It does not cover other websites we link to, each of which publishes its own policy. Investor and shareholder data is handled through the investor relations section, not here.

02

The personal data we collect

Almost all of it is data you hand over deliberately, because you want an answer. The rest is the ordinary technical record any website keeps.

  • Enquiry details. Your name, company, role, email address, phone number, city or site location, and what you tell us about the project: industry, process, floor area, and the class or grade you are working towards.
  • Correspondence. The emails and notes that follow, and any document you send us, such as a specification or a tender pack.
  • Client project records. For a contracted project, the names, roles and contact details of the people our engineers work with through design, delivery, validation and handover.
  • Recruitment data. If you apply for a role, your CV, your covering note and the contact details in them.
  • Technical and usage data. Your IP address, the approximate location it indicates, your device and browser, the pages you viewed, the time, and the page that brought you here.
  • Cookies. Small files placed on your device, described below.

We do not ask you, through this website, for sensitive personal data or information as the SPDI Rules define it: passwords, financial account details, health information, biometric data. Please do not send any of it in an enquiry. If you do, we delete it once your message has been dealt with.

03

Why we use your data, and our lawful basis

Every piece of data here has a reason to exist. This is the whole picture on one screen: what we hold, why we hold it, what allows us to hold it under Indian law, and when it goes.

What we hold, why, on what lawful basis, and for how long
What we holdWhy we hold itLawful basis under the DPDP ActHow long we keep it
Enquiry detailsTo answer your enquiry and prepare a scoped proposalYou provide it voluntarily for that purpose, a certain legitimate use under Section 7A fixed period after the last contact
Correspondence and documentsTo keep an accurate record of what was asked, quoted and agreedVoluntary provision under Section 7, then performance of a contractWith the enquiry or project record it belongs to
Client project recordsTo design, deliver, validate and hand over a contracted cleanroomPerformance of the contract you have with usThe project, then the statutory period below
Recruitment dataTo consider you for a role and contact you about itYour consent, given when you send the applicationA fixed period after the application
Technical and usage dataTo keep the site secure, prevent abuse and diagnose faultsSecurity of our own systems, a certain legitimate use under Section 7A short rolling window in the server logs
Website usage statistics (Google Analytics)To see which pages are read and which ones lead to an enquiry, so we can improve the siteYour consent, which you can withdraw at any time by blocking cookies or using Google's opt-out add-on14 months, then deleted automatically
Marketing contact details, if you opt inTo send you what you asked to receiveYour consent, withdrawable at any timeUntil you withdraw consent or unsubscribe

Two things follow. We will not use your data for a new, unrelated purpose without asking you first. And where the basis is consent, withdrawing it is as easy as giving it: one email to the Grievance Officer, or the unsubscribe link on any message.

04

Cookies and analytics

A cookie is a small file a website puts on your device so it can remember something. This site uses very few of them, and the honest summary is short.

  • Analytics cookies. We use Google Analytics to count visits: which pages are read, how long people stay, what device they use, roughly which city they are in and which page or search brought them here. It sets cookies holding a random identifier, so it can tell a returning visitor from a new one without knowing who either of them is. Google Analytics does not store your IP address, and we never send it your name, email or anything you type into the enquiry form. Its reports are kept for 14 months.
  • No advertising, retargeting or social media pixels run on this site. We do not build advertising profiles and we do not sell personal data.
  • Essential cookies only, where a page genuinely needs one to function or to block abuse. They carry no advertising identifier.

Google is the only third party this site calls. Google Analytics runs on every page, and the contact page also embeds a Google map so you can find the office, which may set its own cookies once the map loads. Both are covered by Google's privacy policy as well as this one.

You can block or delete cookies in your browser at any time, though blocking essential ones may stop parts of the site working. To stop Google Analytics on every website, not just this one, install Google's opt-out add-on. If we add any other tool, we will name it here first, with what it stores and for how long.

05

Who we share your data with

We share personal data only where there is a reason to, and only with these.

  • Service providers who work for us. Website hosting, email, form handling, customer records, website analytics (Google Analytics) and the IT support behind them. They act as Data Processors: they handle the data on our instructions, under written contract, and may not use it for their own purposes.
  • Professional advisers. Auditors, bankers and lawyers, where they need it to do work for us.
  • Statutory and regulatory recipients. As a listed company we are subject to statutory audit and to lawful requests for information from regulators, stock exchanges, tax authorities, courts and government agencies. Where the law requires disclosure we disclose, and we keep it to what is asked for.
  • A successor entity, if part of the business is transferred or reorganised. It then carries the same duties towards your data that we do.

We do not sell personal data, we do not rent it, and we do not share it with data brokers or advertising networks.

06

Where your data is stored

Your data sits on systems run by us and by our service providers . We are an Indian company, so it is processed in India, and it may also be processed by a provider hosting outside India.

Section 16 of the DPDP Act allows an Indian Data Fiduciary to transfer personal data outside India except to a country the Central Government restricts by notification, and we comply with that restriction as and when it is notified. If you write to us from the European Union or the United Kingdom, your data will reach India, because that is where the engineers who answer you sit. This section exists so that the decision to write is an informed one.

07

How long we keep your data

Only as long as there is a reason to, and then no longer. The DPDP Act requires a Data Fiduciary to erase personal data once the purpose it was collected for is no longer served, unless a law requires it to be kept.

  • An enquiry that does not become a project: a fixed period after the last contact, then deleted .
  • A contracted project: the life of the project, then the statutory period. Indian law drives this one. The Companies Act 2013 requires books of account and the vouchers behind them to be preserved for eight financial years, and tax and contract records carry their own requirements.
  • Recruitment data: a fixed period after the application closes, unless you ask us to hold it on file .
  • Server logs: a short rolling window, then overwritten .
  • Website usage statistics: 14 months in Google Analytics, then deleted automatically.

Ask us to erase your data sooner and we will, unless the law requires us to keep it, in which case we will tell you which law and stop using the data for anything else.

08

How we protect your data

We use reasonable security practices and procedures, as Section 43A of the Information Technology Act 2000 and the SPDI Rules require. In practice: the site is served over an encrypted connection, access to enquiry and project records is limited to the people whose job needs it, accounts are individually credentialled, systems are patched and backed up, and service providers are held to written confidentiality and security obligations.

No system is perfectly secure, and a policy that claims otherwise is not worth reading. If a personal data breach occurs we will act to contain it, and we will report it to the Data Protection Board of India and to the affected Data Principals in the manner and within the timelines the DPDP Act requires.

09

Your rights as a Data Principal

The DPDP Act gives you a specific set of rights over your own data.

  • Access. Ask for a summary of the personal data we hold about you, what we are doing with it, and who it has been shared with.
  • Correction, completion and updating. If something we hold is wrong, incomplete or out of date, ask us to fix it.
  • Erasure. Ask us to delete it. We will, unless a law requires us to keep it, in which case we tell you which law.
  • Grievance redressal. Raise a complaint about how we have handled your data, and we must answer it. The route is below.
  • Nomination. Nominate someone to exercise these rights for you if you die or become unable to exercise them yourself.
  • Withdrawal of consent. Wherever consent is the basis, withdraw it at any time, as easily as you gave it.

Write to the Grievance Officer, say what you want, and give us enough detail to find your record. We may ask you to confirm your identity first, because handing your data to someone impersonating you would be the worse failure. There is no charge. The Act asks something of you in return: give accurate details, do not impersonate anyone, and do not raise a complaint you know to be false, because the Data Protection Board of India may penalise frivolous complaints.

10

If you are in the EU or the UK

We are an Indian company, we operate in India, and Indian law governs this policy. We are not saying that we are established in the European Union or the United Kingdom, or that we have appointed a representative there. We are saying that if you contact us from either place, we will handle your request the way the General Data Protection Regulation and the UK GDPR would expect.

The bases in the table above read across as follows: an enquiry rests on steps taken at your request before entering into a contract, and then on performance of that contract; security logging and record keeping rest on our legitimate interests in running the business, and on our legal obligations under Indian company and tax law. On request we will honour the equivalent rights: access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Write to the Grievance Officer and say which one you are exercising. If you think we have got it wrong, you may also complain to the supervisory authority in your own country.

11

Children

This is a business website about industrial cleanroom projects. It is not directed at children, and we do not knowingly collect the personal data of anyone under 18 through it.

Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do none of those. The same protection applies to a person with a disability who has a lawful guardian. If you believe a child has given us personal data, tell the Grievance Officer and we will erase it.

12

Contact the Grievance Officer

One person is responsible for answering questions and complaints about personal data, and this is the route to them.

Include what you are asking for, the email address or phone number you first contacted us on, and enough detail for us to find the right record. We will acknowledge your message and respond within the period the DPDP Act and the rules under it prescribe. If you are not satisfied with our response, or we do not respond, you may escalate the matter to the Data Protection Board of India.

Two things go elsewhere. Investor, shareholder and share-transfer grievances go through the investor relations section, which carries the statutory contacts for those matters. Job applications go to the careers route.

13

Changes to this policy

We will update this policy when the law changes, when we start using a new tool that touches personal data, or when we find a clearer way to say something. The date at the top always tells you which version you are reading.

If a change materially affects how we use data you have already given us, we will flag it on the page rather than rely on a quiet update, and where the change needs your consent we will ask again. Earlier versions are available on request from the Grievance Officer.