This policy explains how personal data is handled when Sancharak, our email delivery platform, is used to send transactional and campaign email on behalf of 4Brains or one of a limited number of clients. It covers the website and infrastructure at sancharak.com specifically; the corporate website 4brains.in has its own policy.
1.Who this applies to
#Two groups of people interact with this infrastructure:
- Recipients — people who receive email sent through Sancharak, whether a transactional message (receipt, alert, confirmation) or a campaign message they opted into.
- Senders — 4Brains itself, and clients who use the Sancharak API to send mail through this infrastructure. Senders are responsible for having a lawful basis to email their own recipients; this policy covers what the infrastructure does with the data once a send is submitted.
2.What data we process
#To deliver, track and honour opt-outs for a message, the platform processes:
- Envelope and header data — recipient email address, sender address, subject line, message-ID and timestamps.
- Delivery and bounce status — whether a message was accepted, deferred, bounced or rejected by the receiving server, and any diagnostic code returned.
- Engagement events — open and click events captured via
track.sancharak.com, including the requesting IP address, user agent string and timestamp of the event. - Suppression and unsubscribe records — via
u.sancharak.com, the address, list, timestamp and method (one-click link or header) of any opt-out. - Content — the message body and attachments a sender submits through the API, held only as long as needed to deliver and, if applicable, retry the message.
3.Why we process it
#All processing exists to provide the sending service itself: accepting a message from a sender’s integration, delivering it, recording whether delivery succeeded, measuring engagement when a sender has enabled tracking, and making sure an unsubscribed address is never emailed again for that list. We do not process this data for any purpose unrelated to operating the platform.
4.Retention
#- Message content is retained only for the operational window needed to deliver and retry a send, then deleted.
- Delivery, bounce and engagement logs are retained for a limited operational period to support deliverability troubleshooting and sender reporting, after which they are aggregated or deleted.
- Suppression and unsubscribe records are kept indefinitely. This is intentional: it is the only way we can guarantee an opted-out address is never re-added to a list.
5.Who we share data with
#We do not sell, rent or trade recipient data. The infrastructure is self-hosted and self-operated by 4Brains — we do not route mail or tracking data through third-party sending, analytics or advertising platforms. Data submitted by a client sender is made available back to that sender (for example, delivery and engagement statistics for their own campaigns) and is not shared with other senders on the platform.
6.Security
#Mail is transmitted over TLS wherever the receiving server supports it, DKIM-signs every outgoing message, and access to delivery logs and the sending API is restricted to authenticated senders and the operations team. Infrastructure runs on systems managed directly by 4Brains, not on shared third-party sending platforms.
7.Your choices as a recipient
#Every campaign message includes a one-click unsubscribe link and, where supported by your mail client, a List-Unsubscribe header. Using either immediately and permanently removes your address from that sender’s list — see the abuse and unsubscribe page for details. Transactional mail (receipts, security alerts, account notices) is not subject to marketing unsubscribe, since it relates to an account or transaction you are already party to; contact the sender directly to stop those.
8.Your rights and how to reach us
#If you want to know what data we hold about an email address, request deletion of engagement history, or ask a question about this policy, write to contact@4brains.in. Where a request conflicts with our need to keep a permanent suppression record (see section 4), we will honour the suppression and delete everything else.
9.Changes to this policy
#We will update this page if how the infrastructure handles data changes, and update the effective date above. We do not notify recipients individually of changes to this page.