This Privacy Policy describes how AANI BROTHERS INFOTECH collects, uses, discloses, protects and otherwise handles your personal information when you visit https://aanibrothers.in, communicate with us, or engage our software development and digital technology services.

Effective Date: 03 August 2015
Last Updated: 11 July 2026

1. Introduction

AANI BROTHERS INFOTECH ("AANI BROTHERS INFOTECH", "the Company", "we", "us" or "our") is a professional software development company that provides application development, web development, custom software engineering, cloud, design and technology consulting services to clients around the world. We respect your privacy and are committed to protecting the personal information that you share with us or that we collect in the course of operating our website and delivering our services.

This Privacy Policy explains, in clear and transparent terms, what information we collect, why we collect it, how we use and store it, the circumstances in which it may be shared, the safeguards we apply to keep it secure, and the rights you can exercise over your personal information. It applies to visitors of our website, prospective clients who submit enquiries, active clients who engage our services, job applicants who apply through our website, subscribers to our updates, and any other individual who interacts with us through the channels described below.

We encourage you to read this Privacy Policy carefully. By accessing or using our website, submitting information through our forms, or otherwise engaging with us, you acknowledge that you have read and understood the practices described in this document. If you do not agree with any part of this Privacy Policy, please refrain from using our website or providing us with your personal information.

Protecting personal information is not merely a legal obligation for us; it is a core part of how we conduct our business and build trust with the clients, partners and individuals who interact with us. We have designed this Privacy Policy to give you a comprehensive understanding of our practices so that you can make informed decisions about sharing your information. We keep our practices under review and update this Privacy Policy as our services evolve, as technology changes, and as the legal landscape develops, so that our commitment to privacy remains current and meaningful. Where this Privacy Policy refers to applicable law, it means the data protection and privacy laws that apply to the processing of your personal information in the relevant jurisdiction, and this Privacy Policy should be read in a manner consistent with those laws.

2. Definitions

For the purpose of this Privacy Policy, the following terms shall have the meanings assigned to them below:

  • "Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person, such as a name, email address, telephone number, address, identification number, online identifier, or one or more factors specific to that person's identity.
  • "Processing" means any operation performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, restriction, erasure or destruction.
  • "Data Controller" means the entity that determines the purposes and means of the processing of personal data. In relation to information collected through our website and services, AANI BROTHERS INFOTECH acts as the Data Controller.
  • "Data Processor" means a third party that processes personal data on behalf of the Data Controller, such as a hosting or analytics provider.
  • "Data Subject" or "User" means the identified or identifiable natural person to whom the personal data relates.
  • "Cookies" means small text files placed on your device by a website to store information about your browsing activity.
  • "Website" means the website located at https://aanibrothers.in and all associated subdomains and pages operated by AANI BROTHERS INFOTECH.
  • "Services" means the software development, application development, design, cloud, consulting, maintenance, support and related technology services that we provide.
  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CPRA).
  • "DPDP Act" means the Digital Personal Data Protection Act, 2023 of India.

3. Company Information

AANI BROTHERS INFOTECH is an information technology services and software development company headquartered in Surat, Gujarat, India, providing services to clients worldwide. We are the entity responsible for the personal data collected and processed through our website and services.

If you have any questions about this Privacy Policy or wish to exercise your rights, you may reach us using the contact information published on our Contact Us page or by writing to us at [email protected]. Where required by applicable law, this address also serves as the point of contact for privacy and data protection matters.

4. Scope of This Policy

This Privacy Policy applies to all personal data that we collect, receive, store, use, or otherwise process in connection with:

  • Your use of, and interaction with, our website and its features;
  • Enquiries, quotation requests and project discussions initiated through our contact forms, email, telephone or other communication channels;
  • The provision and administration of our services to clients;
  • Applications submitted through our careers or recruitment channels;
  • Subscriptions to our newsletters, updates or marketing communications; and
  • Any other engagement you have with AANI BROTHERS INFOTECH.

This Privacy Policy does not apply to third-party websites, applications or services that may be linked from our website but are operated by other organizations. Such third parties maintain their own privacy policies, and we encourage you to review them before providing any personal information.

This Privacy Policy applies regardless of the device or channel through which you interact with us, whether you access our website from a desktop computer, laptop, tablet or mobile device, or whether you communicate with us by web form, email, telephone or other means. Where a specific service, campaign or feature is subject to additional or supplementary privacy terms, those terms will be provided to you at the relevant time and should be read together with this Privacy Policy. In the event of any conflict between a service-specific privacy notice and this Privacy Policy, the service-specific notice shall prevail with respect to that particular service to the extent of the conflict.

5. Information We Collect

We collect information that is necessary to respond to your requests, deliver our services, operate and improve our website, and comply with our legal obligations. Depending on how you interact with us, the categories of information we may collect include the following:

  • Full Name — the name you provide when contacting us, requesting a quotation, applying for a role, or engaging our services.
  • Email Address — used to correspond with you and to send project-related or, where permitted, marketing communications.
  • Phone Number — used to contact you regarding your enquiry, project or application.
  • Company Name — the organization you represent, where relevant to a business enquiry or engagement.
  • Country — used to understand the jurisdiction of your enquiry and to tailor our response.
  • Address — postal or business address provided for invoicing, contractual or correspondence purposes.
  • Billing Information — details required to raise invoices and administer payments for our services.
  • Payment Information — information necessary to process payments; note that card and bank details are handled by our payment providers and are not stored by us in full.
  • Project Details — descriptions, requirements, specifications and objectives that you share with us so that we can scope and deliver a project.
  • Uploaded Files — documents, images, designs, briefs or other files you submit through our forms or by email.
  • Attachments — files accompanying your communications, such as resumes, portfolios or reference materials.
  • Communications — the content of the messages, emails, chats and other correspondence you exchange with us.
  • Browser Information — the type and version of the web browser you use to access our website.
  • Device Information — the type of device, its settings and identifiers relevant to displaying our website correctly.
  • Operating System — the operating system running on your device.
  • IP Address — the internet protocol address assigned to your device, used for security, analytics and approximate location.
  • Cookies — small files stored on your device as described in our Cookie Policy.
  • Log Files — server records of requests made to our website, including timestamps and pages accessed.
  • Usage Information — data about how you navigate and interact with our website.
  • Analytics Information — aggregated and statistical data about website performance and visitor behavior.
  • Marketing Preferences — your choices regarding the receipt of newsletters and promotional communications.

We only collect information that is relevant and necessary for the purposes described in this Privacy Policy. You are not obliged to provide personal information; however, if you choose not to provide certain information, we may be unable to respond to your enquiry or deliver the services you request.

5.1 Information Collected Automatically

When you visit our website, certain information is collected automatically through cookies, log files and similar technologies. This information typically includes your IP address, browser type and version, operating system, referring website, the pages you view, the date and time of your visit, and the duration of your session. This information is generally aggregated and used for analytics, security monitoring, and to maintain and improve the performance and reliability of our website. It does not usually identify you personally, although in some jurisdictions certain identifiers such as IP addresses may be treated as personal data.

5.2 Information Collected Through Contact Forms

When you complete a contact form, quotation request or project enquiry form on our website, we collect the information you enter, which may include your name, email address, phone number, company name, country, budget indication, selected service, subject and message. We use this information solely to respond to your enquiry, provide the information or quotation you have requested, and follow up as appropriate. Our forms include measures such as hidden anti-spam fields to reduce automated submissions.

5.3 Information Collected During Project Discussions

During project discussions, whether conducted through our website, email, telephone, video calls or in-person meetings, we may collect additional information necessary to understand your requirements and prepare a proposal. This may include detailed project specifications, technical requirements, business objectives, existing systems and credentials shared for integration purposes, sample data, design assets and other materials you choose to share. We treat this information as confidential and use it only for the purpose of scoping, quoting and delivering the relevant project.

5.4 Information Collected Through Email

When you email us, we collect your email address, name, and the content of your message together with any attachments. We retain email correspondence to maintain a record of our communications, respond to your requests, and fulfil our contractual and legal obligations. Please avoid sending sensitive personal information by email unless it is necessary for the service you have requested.

5.5 Information Collected During Recruitment

If you apply for a position with AANI BROTHERS INFOTECH, we collect the information contained in your application, which may include your name, contact details, resume or curriculum vitae, employment history, educational qualifications, skills, portfolio, references and any other information you choose to provide. We use this information to assess your suitability for the role, communicate with you about your application, and, where applicable, to comply with employment and legal requirements. Recruitment data is retained only for as long as necessary for these purposes or as permitted by applicable law.

6. How Information Is Collected

We collect personal information through a variety of channels and methods, including:

  • Contact forms — information you actively submit through enquiry, quotation, project and career forms on our website.
  • Email — information contained in email correspondence you send to us.
  • Cookies — information gathered automatically through cookies and similar technologies as described in our Cookie Policy.
  • Analytics — information gathered through analytics tools that measure website traffic and usage patterns.
  • Server logs — technical information automatically recorded by our servers when your device requests content from our website.
  • User interactions — information generated as you navigate, click, scroll and interact with the features of our website.
  • Third-party integrations — information received through integrated third-party services, such as analytics providers, hosting providers and payment gateways, in accordance with their respective terms and policies.

7. Why We Collect Information

We collect and process personal information for a range of legitimate business purposes, which include the following:

  • To respond to enquiries, quotation requests and project discussions initiated by you;
  • To prepare proposals, estimates and contracts for the services you request;
  • To deliver, administer and support the services we provide to our clients;
  • To communicate with you regarding your enquiries, projects, invoices and account;
  • To process payments and manage billing and accounting;
  • To operate, maintain, secure and improve our website and services;
  • To analyze how our website is used so that we can enhance its content, functionality and user experience;
  • To assess and manage job applications and recruitment;
  • To send newsletters, updates and marketing communications where you have consented to receive them;
  • To protect our website, systems, clients and business against fraud, security threats and misuse;
  • To comply with our legal, regulatory, tax and contractual obligations; and
  • To establish, exercise or defend legal claims where necessary.

We will not use your personal information for purposes that are incompatible with those described above unless we are required or permitted to do so by law, or unless we obtain your consent. Where we wish to use your personal information for a new purpose that is not covered by this Privacy Policy, we will provide you with a clear explanation of that new purpose and, where required, obtain your consent before proceeding. In determining whether a new purpose is compatible with the original purpose of collection, we consider factors such as the relationship between the purposes, the context in which the information was collected, the nature of the information, the possible consequences for you, and the existence of appropriate safeguards. This ensures that our use of your personal information remains fair, foreseeable and consistent with your reasonable expectations.

8. Legal Basis for Processing Data

Where the GDPR or comparable data protection laws apply, we rely on one or more of the following legal bases to process your personal data:

  • Consent — where you have given clear, informed and freely given consent to the processing of your personal data for a specific purpose, such as receiving marketing communications or the use of non-essential cookies. You may withdraw your consent at any time.
  • Performance of a contract — where processing is necessary to enter into or perform a contract with you, such as delivering the services you have engaged us to provide or responding to pre-contractual requests.
  • Legitimate interests — where processing is necessary for our legitimate interests, such as operating and securing our website, communicating with prospective clients, preventing fraud and improving our services, provided those interests are not overridden by your rights and freedoms.
  • Legal obligation — where processing is necessary to comply with a legal, regulatory, tax or accounting obligation to which we are subject.
  • Vital interests and public interest — in the rare circumstances where processing is necessary to protect the vital interests of an individual or is carried out in the public interest.

Where we rely on legitimate interests, we carry out an assessment to ensure that our interests are balanced against your rights. You may contact us for further information about this balancing exercise.

9. Data Security

We take the security of your personal information seriously and implement appropriate technical and organizational measures designed to protect it against unauthorized access, accidental loss, alteration, disclosure or destruction. Our security practices include, among others:

  • Encryption — we use secure transmission protocols such as HTTPS/TLS to protect data in transit, and we apply encryption to sensitive data where appropriate.
  • Firewalls — network firewalls and protective controls help guard our systems against unauthorized access and malicious traffic.
  • Access controls — access to personal data is restricted to authorized personnel who require it to perform their duties, subject to role-based permissions and authentication.
  • Secure servers — our data is hosted on servers maintained with industry-standard security configurations and safeguards.
  • Monitoring — we monitor our systems for vulnerabilities, suspicious activity and potential breaches, and maintain logging to support investigation and response.
  • Security practices — we apply patching, secure development practices, confidentiality obligations for staff and contractors, and periodic review of our safeguards.

In addition to the technical measures described above, we apply organizational measures designed to safeguard personal information. These include limiting the number of personnel who have access to personal data, providing guidance to our staff and contractors on their confidentiality and data protection responsibilities, imposing contractual confidentiality obligations, and reviewing our data handling practices periodically. Where we engage third-party processors, we require them to implement security measures appropriate to the risks presented by the processing and to act only on our documented instructions. We also seek to design our systems and processes with privacy in mind, applying principles of data minimization and access restriction so that personal information is protected throughout its lifecycle.

Despite our efforts, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal information using commercially acceptable means, we cannot guarantee its absolute security. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant authorities and affected individuals as required by applicable law.

10. Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, contractual or reporting requirements. The criteria we use to determine retention periods include:

  • The duration of our relationship with you and any ongoing service engagement;
  • Whether we have a legal or contractual obligation to retain the data;
  • Whether retention is advisable in light of our legal position, such as applicable limitation periods; and
  • The nature and sensitivity of the information.

As a general guide, enquiry and quotation information is retained for the period necessary to respond and follow up, and for a reasonable period thereafter for record-keeping. Client and project records, including billing information, are retained for the duration of the engagement and for the period required by tax and accounting laws. Recruitment data is retained for the duration of the selection process and for a limited period afterwards unless you consent to longer retention. When personal data is no longer required, we will securely delete, anonymize or destroy it.

11. Sharing of Information

We do not sell your personal information. We may share your personal information only in the limited circumstances described below and only to the extent necessary:

  • Hosting providers — with the providers that host our website, servers and data storage, so that our website and services can operate.
  • Payment providers — with payment gateways and financial institutions that process payments and invoices on our behalf.
  • Analytics providers — with analytics service providers that help us understand website usage, subject to your cookie preferences.
  • Service providers and subcontractors — with trusted vendors, contractors and partners who assist us in delivering our services, subject to appropriate confidentiality and data protection obligations.
  • Government authorities — with courts, regulators, law enforcement or other public authorities where we are legally required to do so.
  • Legal compliance — where disclosure is necessary to comply with a legal obligation, enforce our agreements, protect our rights, property or safety, or that of our clients or others.
  • Business transfers — in connection with a merger, acquisition, reorganization or sale of assets, in which case personal data may be transferred as part of the transaction subject to appropriate protections.

When we share personal data with third parties who act as processors on our behalf, we require them to process the data only in accordance with our instructions and to implement appropriate security measures.

12. International Data Transfers

Because AANI BROTHERS INFOTECH serves clients worldwide and may use service providers located in different countries, your personal information may be transferred to, stored in, or processed in jurisdictions other than the one in which you reside, including India. The data protection laws of these countries may differ from those of your jurisdiction.

Where we transfer personal data internationally, we take appropriate steps to ensure that it receives an adequate level of protection, which may include the use of contractual safeguards such as standard contractual clauses, transfers to jurisdictions recognized as providing adequate protection, or reliance on other lawful transfer mechanisms. By using our website or engaging our services, you understand that your information may be transferred and processed in this manner. You may contact us for more information about the safeguards we apply to international transfers.

13. Your Rights

Subject to applicable law, you have a number of rights in relation to your personal information. These include:

  • Right to Access — the right to obtain confirmation of whether we process your personal data and to receive a copy of it, together with information about how it is processed.
  • Right to Correct — the right to request the correction of inaccurate or incomplete personal data that we hold about you.
  • Right to Delete — the right to request the deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to Restrict Processing — the right to request that we limit the processing of your personal data in certain circumstances.
  • Right to Object — the right to object to the processing of your personal data where we rely on legitimate interests, and to object to processing for direct marketing purposes at any time.
  • Right to Data Portability — the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to Withdraw Consent — where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us using the details in the Contact Information section below. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with a data protection authority if you believe your rights have been infringed.

13.1 GDPR Rights

If you are located in the European Economic Area or the United Kingdom, the GDPR (and equivalent UK legislation) grants you the rights described above, including the rights of access, rectification, erasure, restriction, objection, and data portability, as well as the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. You also have the right to lodge a complaint with your local supervisory authority. We do not engage in automated decision-making that produces legal or similarly significant effects on you without appropriate safeguards.

13.2 CCPA and CPRA Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides you with specific rights regarding your personal information, including:

  • The right to know what categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collecting it, and the categories of third parties with whom it is shared;
  • The right to request deletion of personal information we have collected, subject to certain exceptions;
  • The right to correct inaccurate personal information;
  • The right to opt out of the sale or sharing of personal information; and
  • The right not to receive discriminatory treatment for exercising your privacy rights.

AANI BROTHERS INFOTECH does not sell personal information as that term is commonly understood. You may exercise your California privacy rights by contacting us using the details provided in this Privacy Policy. We will not discriminate against you for exercising any of your rights.

13.3 India DPDP Act Rights

If you are a resident of India, the Digital Personal Data Protection Act, 2023 provides you with rights in respect of your personal data, including the right to access information about the personal data being processed, the right to correction and erasure of personal data, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity. We process personal data of individuals in India in accordance with the requirements of the DPDP Act, including obtaining consent where required and honoring requests to withdraw consent. To exercise your rights or raise a grievance, please contact us using the information published on our Contact Us page.

14. Children's Privacy

Our website and services are intended for businesses and individuals who are of the age of majority in their jurisdiction and are not directed at children. We do not knowingly collect personal information from children. If you believe that we have inadvertently collected personal information from a child, please contact us so that we can take appropriate steps to delete such information. Where consent is required for the processing of a child's personal data, we require verifiable consent from a parent or lawful guardian in accordance with applicable law.

15. Third-Party Websites

Our website may contain links to third-party websites, applications or resources that are not operated or controlled by AANI BROTHERS INFOTECH. These links are provided for your convenience and reference only. We are not responsible for the privacy practices, content or security of any third-party website. When you leave our website, we encourage you to read the privacy policy of every website you visit before providing any personal information.

16. Third-Party Services

We use a number of third-party services to operate our website and deliver our services. These may include, among others:

  • Google Analytics — for measuring and analyzing website traffic and usage.
  • Google Maps — for displaying location and map information where relevant.
  • Payment gateways — for processing invoices and payments securely.
  • Cloud hosting — for hosting our website, applications and data.
  • Email providers — for sending and managing transactional and, where consented, marketing emails.

Each of these third parties processes information in accordance with its own privacy policy and terms. We select our providers with care and, where they act as processors on our behalf, we put in place appropriate agreements to protect your personal data.

17. Cookies

We use cookies and similar technologies to operate our website, remember your preferences, analyze usage and, where you consent, support marketing. For detailed information about the types of cookies we use, their purposes, and how you can manage or disable them, please refer to our dedicated Cookie Policy. Your continued use of our website, together with your cookie preferences, governs how cookies are used during your visit.

18. Marketing Communications

Where you have provided your consent, or where otherwise permitted by law, we may send you newsletters, updates, offers and other marketing communications relating to our services. You may opt out of receiving marketing communications at any time by using the unsubscribe link included in our emails or by contacting us directly. Opting out of marketing communications will not affect service-related or transactional communications that are necessary for our engagement with you.

19. Business Communications

Regardless of your marketing preferences, we may send you communications that are necessary for the administration of our relationship with you. These include responses to your enquiries, project updates, quotations, invoices, service notices, security alerts and other communications that form part of the services you have requested or the contract between us. Such communications are not marketing in nature and cannot be opted out of while our engagement is active.

20. Intellectual Property Notice

All content on our website, including text, graphics, logos, images, layouts, source code samples and design elements, is the property of AANI BROTHERS INFOTECH or its licensors and is protected by applicable intellectual property laws. This Privacy Policy itself, and the manner in which it is expressed, is the original work of AANI BROTHERS INFOTECH. Nothing in this Privacy Policy grants you any right, title or interest in our intellectual property. The handling of intellectual property arising from client engagements is governed by our Terms & Conditions and any applicable project agreement.

21. Disclaimer

This Privacy Policy is provided for general informational purposes and describes our current data practices. It does not constitute legal advice and should not be relied upon as such. While we make every effort to keep this Privacy Policy accurate and up to date, we do not warrant that it is complete or error-free. To the fullest extent permitted by law, AANI BROTHERS INFOTECH disclaims liability for any loss or damage arising from reliance on this Privacy Policy, save for our obligations under applicable data protection law.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements or for other operational reasons. When we make material changes, we will revise the "Last Updated" date at the top of this policy and, where appropriate, provide additional notice. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our website following the posting of changes constitutes your acceptance of the revised policy.

23. Aggregated and De-identified Information

We may aggregate, anonymize or de-identify personal information so that it no longer identifies you, either directly or indirectly. Aggregated and de-identified information—such as statistical reports about website traffic, service usage trends and demographic summaries—does not constitute personal data and may be used and retained by us for any lawful business purpose, including analytics, research, service improvement, benchmarking and marketing. Where we hold de-identified information, we maintain it in de-identified form and do not attempt to re-identify it except as permitted by law, for example to test the effectiveness of our de-identification measures.

24. Security of Payment Information

When you make a payment for our services, your payment card and bank details are processed by our payment providers and financial institutions, which maintain their own security standards and, where applicable, comply with the Payment Card Industry Data Security Standard (PCI DSS). We do not store your full payment card details on our own systems. We retain only the transactional and billing information necessary to administer invoices, maintain accounting records and comply with our legal obligations. We encourage you to review the privacy and security practices of the payment providers before completing a transaction. Please never send full card numbers or sensitive financial credentials to us by email or through our contact forms.

25. Automated Decision-Making and Profiling

We do not use your personal data to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or that similarly significantly affect you, without a lawful basis and appropriate safeguards. Where we use analytics tools to understand website usage, this is done at an aggregate level and is not used to make automated decisions about individuals. If we were to introduce any automated decision-making that produces legal or similarly significant effects, we would inform you and implement the safeguards required by applicable law, including the right to obtain human intervention, to express your point of view, and to contest the decision.

26. Data Protection Principles

In handling your personal information, we are guided by internationally recognized data protection principles. We process personal data lawfully, fairly and in a transparent manner. We collect it for specified, explicit and legitimate purposes and do not further process it in a manner incompatible with those purposes. We limit the personal data we collect to what is adequate, relevant and necessary. We take reasonable steps to keep personal data accurate and up to date. We retain personal data no longer than is necessary for the purposes for which it is processed. We process personal data in a manner that ensures appropriate security. And we take accountability for our processing activities, maintaining records and controls designed to demonstrate our compliance with applicable data protection law.

27. Your Choices and Preferences

You have choices about how your personal information is collected and used. You may choose not to provide certain information, although this may limit our ability to respond to you or provide services. You may opt out of marketing communications at any time. You may manage cookies and similar technologies through your browser settings and our cookie preferences, as described in our Cookie Policy. You may update or correct the information you have provided by contacting us. And you may exercise the data protection rights described in this Privacy Policy. We are committed to honoring your choices and making it straightforward for you to communicate your preferences to us.

28. Cross-Border Service Delivery

As a software development company serving clients worldwide, we routinely deliver services and communicate with clients and prospective clients across multiple countries. In doing so, personal information may be collected in one country and processed in another, including India where we are based. We recognise our responsibility to protect personal information consistently regardless of where it is processed, and we apply the safeguards described in this Privacy Policy and the International Data Transfers section to all such processing. By engaging with us across borders, you acknowledge and consent to this cross-border handling of your information, subject to the protections we maintain.

29. Grievance Redressal and Complaints

We are committed to resolving any concerns or grievances you may have about the way we handle your personal information. If you have a complaint, please contact us using the details in the Contact Information section, describing your concern and how you would like it to be addressed. We will acknowledge your complaint and work to resolve it promptly and fairly. Where applicable law provides for a designated grievance officer or point of contact for data protection matters, that role is fulfilled through the contact details published on our Contact Us page. If you remain dissatisfied, you have the right to escalate your complaint to the relevant data protection or supervisory authority in your jurisdiction.

30. Do Not Track and Global Privacy Signals

Some browsers and devices allow you to send "Do Not Track" signals or global privacy control signals that communicate your preference regarding tracking. Because there is no consistent industry standard for interpreting these signals, our website may not respond to all of them uniformly. Regardless, you can exercise control over cookies and tracking technologies through your browser settings and our cookie preferences, and you can exercise your privacy rights and choices as described in this Privacy Policy and our Cookie Policy. We monitor developments in privacy signaling standards and will adapt our practices as those standards evolve and as required by applicable law.

31. Sensitive Personal Information

In the ordinary course of our business, we do not seek to collect sensitive or special categories of personal information, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, or data concerning a person's sex life or sexual orientation. We ask that you do not provide such sensitive information to us unless it is strictly necessary for a specific, agreed purpose. Where we are required to process sensitive personal information—for example, to comply with a legal obligation or with your explicit consent—we apply additional safeguards appropriate to the heightened sensitivity of the data and process it only to the extent necessary and permitted by applicable law.

32. Consent and Withdrawal of Consent

Where we rely on your consent to process your personal information, we seek that consent in a clear and specific manner, and we keep a record of the consent you provide. You have the right to withdraw your consent at any time, and we make the process of withdrawal as straightforward as the process of giving consent. To withdraw consent, you may use the unsubscribe options in our communications, adjust your cookie preferences, or contact us directly using the details in this Privacy Policy. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal, and it does not affect processing that is based on a legal ground other than consent, such as the performance of a contract or compliance with a legal obligation.

33. Information From Third-Party Sources

In most cases, we collect personal information directly from you. Occasionally, we may receive information about you from third-party sources, such as business partners, referral sources, publicly available directories, professional networking platforms, or service providers who assist us in operating our business. Where we receive personal information from third parties, we take reasonable steps to ensure that the information has been obtained lawfully and that the third party is entitled to share it with us. We process such information in accordance with this Privacy Policy and inform you of its receipt where required by applicable law.

34. Retention Schedule and Deletion

Beyond the general retention approach described earlier, we apply practical retention schedules to the different categories of personal information we hold. Enquiry and quotation records are generally retained while a prospective relationship remains active and for a limited period afterwards. Contractual, project and billing records are retained for the duration of the engagement and for the period required by tax, accounting and limitation laws. Communications are retained for as long as necessary to maintain a proper record of our dealings. When a retention period expires, or when personal information is no longer required for the purpose for which it was collected, we securely delete, destroy or irreversibly anonymize it, unless a longer retention period is required or permitted by law.

35. Notification of Data Breaches

We maintain procedures to detect, investigate and respond to personal data breaches. In the event of a breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the competent supervisory or data protection authority within the timeframe required by applicable law, and we will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms. Our breach response includes containment, assessment of the scope and impact, remediation, and steps to prevent recurrence. We keep records of data breaches and the measures taken in response, in accordance with our accountability obligations.

36. Contact Information

If you have any questions, concerns, requests or complaints regarding this Privacy Policy or the way we handle your personal information, please contact us:

We are committed to resolving any concerns you may have about our use of your personal information and will respond to your enquiry as promptly as possible.