- Version
- ver2.3
- Effective date
- 26 September 2026
1. Scope and legal framework
This policy explains how BellGlobal collects, uses, discloses, stores and protects personal data in connection with bellglobal.in, customer accounts, VPS and dedicated-server Services and support. BellGlobal processes personal data under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and the rules and directions made under it (including the CERT-In directions of 28 April 2022), to the extent and from the dates they apply. BellGlobal is the Data Fiduciary for the data described in clause 2. For data you store inside your own Server, you are the fiduciary or controller and BellGlobal is an infrastructure provider (clause 4).
2. Information BellGlobal collects directly
| Category | What | Why |
|---|---|---|
| Account information | Full name, email, telephone, company name, city, state, country, postal code; account password (stored only as a salted, peppered hash); date joined; account status | Create and secure your account; contact you; invoicing |
| Sign-in providers | Where you sign in with Google, Microsoft, GitHub or Facebook: the provider’s account identifier, name, email and whether the provider has verified it | Authenticate you; link the sign-in to your account only when the email is verified |
| One-time codes | Emailed password-reset codes (10-minute life); authenticator-app setup secrets stored encrypted; authenticator verification and recovery events; single-use authenticator-recovery links (15-minute life); where enabled, the mobile number verified by SMS at sign-up and the code exchange | Password reset; two-factor authentication and recovery; sign-up verification |
| Subscriber information (CERT-In) | The identity and contact details above, the IP addresses allotted to you and the dates of service; and the purpose for which you use the Server, which BellGlobal asks for where the directions require it | Required of a VPS provider by the CERT-In directions of 28 April 2022 |
| Billing and payment | Billing address; business name and registration details where you supply them; invoice and transaction references; payment status | Invoicing, refunds, fraud prevention. Card details are processed by PCI-DSS-compliant payment providers; BellGlobal does not see or store full card numbers |
| Server, network and security logs | Server identifiers, provisioning events, operation logs (operator, time, reference, originating IP), firewall and login events, abuse reports | Operate and secure the Service; investigate abuse; legal obligations |
| IP addresses and session data | Your IP address, login and session metadata, browser and device information, timestamps | Security, fraud prevention, session management |
| Records of your instructions | For each policy acceptance, credential handover, OpenAlgo action and custom-domain request: time, version shown, account and available request metadata; fields vary by workflow | Evidence of what you asked for (Terms clause 21) |
| Support tickets | Ticket content, attachments, diagnostics you supply, correspondence | Provide support; quality |
| Cookies and live chat | Essential cookies (sign-in, security, theme, your consent choice). The live-chat widget and any optional analytics load only after you accept them in the consent banner, and may set their own cookies | Website function; chat support and usage analysis if consented |
3. Why BellGlobal processes it, and the legal basis
To create and manage accounts; provision, operate and support the Services; process payments and issue tax invoices; communicate with you; prevent fraud and abuse; maintain security; investigate incidents; comply with law, including the subscriber-information and incident-reporting obligations of a VPS provider; enforce contracts; resolve disputes; and establish, exercise or defend legal claims. Processing rests on the performance of your contract, BellGlobal’s legal obligations, and — for optional cookies and marketing — your consent. Aggregated or de-identified information may be used for capacity planning, service improvement and security analysis.
Where processing rests on consent, you may withdraw it through the client panel or by writing to the contact above; withdrawal does not affect processing that lawfully continues on another basis.
4. Data you store inside your Server
You decide what to store and run inside your Server and are responsible for its lawful use, permissions and day-to-day security unless your Order expressly includes management. BellGlobal resells the infrastructure and may carry out the limited Platform Operations described in Terms clause 15.
BellGlobal may process configuration, broker credentials or diagnostics to the extent needed for an authorised action, proportionate security response or legal obligation. Operational credentials and submitted broker settings may be retained encrypted for those functions. This is not ongoing management of your applications or trading activity.
Authorised administrator access may use a panel reveal or a single-use download depending on the product and action. Expiry or consumption of a download does not erase every encrypted operational copy. SSH private keys generated in the client panel remain in your browser and are not submitted to BellGlobal.
6. International processing
Some providers may process information outside India. BellGlobal uses such providers where reasonably necessary, applies contractual, technical and organisational safeguards, and complies with cross-border transfer requirements in force under the Digital Personal Data Protection Act, 2023, including any restriction notified by the Central Government.
7. Security
BellGlobal uses password hashing, encrypted operational credentials, role-based administrative access, host-key verification for supported automation and operation/acceptance records. The exact checks vary by workflow. A baseline records observed state on supported enrolled Servers, not a guarantee that every Server has identical protection.
Platform-record backups are not a backup service for customer Server contents. BellGlobal does not claim a security certification or immunity from compromise. Customers must protect their own credentials, applications and data; BellGlobal remains responsible for reasonable security measures for the information and systems under its control. See Terms Schedule A for the division of responsibilities.
8. Personal-data breaches and security incidents
BellGlobal assesses security incidents affecting its services or the information it handles, coordinates containment and provider assistance, and meets reporting and notification duties applicable to its role. Required reporting is not deferred until an upstream provider finishes investigating.
CERT-In reporting requirements apply independently of the phased commencement of the DPDP framework. DPDP notifications to the Board and affected individuals apply from the dates and in the circumstances specified by the law in force; this policy does not represent future duties as already commenced. A customer-Server compromise requires a case-specific assessment, not an automatic conclusion about who is at fault.
9. Retention
| Category | Kept for | Basis |
|---|---|---|
| Subscriber (KYC) information, IP allotments, service dates | 5 years after the Service ends | CERT-In directions, 28 April 2022 |
| Security, access and operation logs | 180 days, stored in India | CERT-In directions |
| Invoices, credit notes, payment records | 8 years from the end of the financial year | Existing BellGlobal retention commitment, subject to applicable accounting law and legal holds |
| Records of your instructions and consents | 8 years, or longer while a dispute or claim is live | Establishment and defence of legal claims |
| Support tickets | 3 years after closure | Service history; disputes |
| Encrypted platform backups (BellGlobal’s records only) | Per the backup retention schedule, currently up to 30 days / 10 packages; then deleted | Business continuity; contains no customer Server contents |
| Sign-in and one-time-code records | Password-reset codes 10 minutes; authenticator recovery links 15 minutes; authenticator credential while enabled or pending recovery; security-event records 180 days; provider link while the account is open | Authentication and account security |
| Account and contact data | While the account is open, then per the rows above | Contract; legal obligation |
| Data on an expired or terminated Server | Subject to the Order, notices, actual recovery/rebuild state and provider retention; no universal two-day deletion guarantee | Terms clause 24 |
These published record-retention commitments are not shortened by the lean reseller model. A record-retention period is not proof that every log source or deletion job is already configured. After account termination, personal data not covered by a row above is erased within 90 days. Deletion may be refused or delayed where retention is required by law or reasonably necessary to establish, exercise or defend a claim, investigate abuse, maintain security records or complete accounting obligations; you will be told which records are retained and why.
10. Your rights
Subject to verification and to the law in force, you may: access a summary of the personal data BellGlobal holds about you and the processing it carries out; have inaccurate or incomplete data corrected; have data erased where BellGlobal no longer needs it for the purpose or a legal obligation; withdraw consent where processing rests on consent; nominate a person to exercise these rights if you die or are incapacitated; and raise a grievance with the contact above. BellGlobal responds within applicable legal deadlines. DPDP-specific rights and Board remedies apply as their provisions commence; other applicable remedies remain available. Signed-in customers can download a summary of the personal data BellGlobal holds about them, the processing carried out and the parties it is shared with, submit the requests above, and give or withdraw the optional service-updates consent, all under Account → Privacy in the client panel, where each request and its outcome is recorded; anyone may write to [email protected]. BellGlobal may ask for reasonable information to verify your identity before acting, and will tell you which records it must keep and why if a request cannot be met in full.
12. Children
The Services are for persons aged 18 and over and for businesses. BellGlobal does not knowingly collect a child’s personal data and does not operate the verifiable parental-consent process the Digital Personal Data Protection Act requires; an account found to belong to a child will be closed and its data erased subject to clause 9.
13. Communications
BellGlobal sends transactional and service communications necessary to operate your account — invoices, maintenance notices, incident notices, security notices and policy changes. Promotional communications are sent only with consent and carry an unsubscribe option.
14. Changes to this policy
BellGlobal may update this policy to reflect changes in law, technology, providers or practice. Material changes are published with an effective date and notified to the email address on your account in accordance with clause 31 of the Terms.
15. Contact and grievance
Data Fiduciary: BellGlobal, Bengaluru, Karnataka, India.
Privacy and grievance contact: Grievance Officer, BellGlobal, [email protected].
General support: Support Tickets in the client panel.