TechFleek

Privacy Policy

Plain-English privacy: what we collect, why, your rights, retention and security.

Last updated: September 17, 2026 9-minute read Techfleek Technologies Pvt Ltd

Controller: Techfleek Technologies Pvt Ltd (“TechFleek”, “we”), O-1106, Officer City-1, Raj Nagar Extension, Ghaziabad, UP 201017, India · hello@techfleek.com · +91-88021-72570.

  • We collect only what we need to respond, deliver projects and improve the site.
  • Analytics and marketing cookies run only with your consent — change it anytime via footer Cookie Settings.
  • India DPDP Act 2023, EU/UK GDPR and California CCPA/CPRA rights are honored for everyone, everywhere.
1

Data we collect

Information you provide

  • Enquiries & contact: name, email, phone, company, project details, budget range, timeline, and any files or links you share.
  • Careers: CV/résumé, portfolio links, role preferences, availability and interview notes.
  • Projects & billing: stakeholder contacts, credentials you provision, invoices, GST/tax details and payment references.

Information collected automatically

  • Device, browser and OS type, approximate city/country derived from IP, pages viewed, referrer and UTM parameters, session duration and Core Web Vitals. IP addresses are hashed; raw IPs are retained no longer than 30 days.
  • Cookies and pixels as described in our Cookie Policy. Essential storage always runs; diagnostics and marketing storage load only after you consent.

Client end-user data

When we build or operate software for clients, we process their end-users' data strictly as a processor following the client's documented instructions and data-processing agreements — never for our own purposes.

2

How we use data & legal bases

  • Respond and deliver (contract / legitimate interest): preparing quotes, delivering design, development, cloud, AI and growth services, providing support and billing.
  • Improve and secure (legitimate interest / consent where required): aggregated analytics, performance tuning, debugging, fraud prevention and infrastructure security.
  • Marketing (consent only): newsletters, case-study outreach and campaign measurement. Every message includes an unsubscribe link and withdrawing consent is one click via the footer Cookie Settings.
  • Comply (legal obligation): tax, accounting, audit and responses to lawful authority requests.

Where India's DPDP Act requires notice and consent, we present purpose-specific notices at collection and honor withdrawal prospectively.

3

Sharing, sub-processors & international transfers

We disclose personal data only to:

  • Vetted sub-processors (cloud hosting, email delivery, analytics, payment gateways, error tracking) bound by written data-processing terms with purpose limitation and confidentiality.
  • Authorities where disclosure is legally required or to protect rights, safety and security.
  • Successors in a merger, acquisition or asset transfer, with advance notice and continued protection.

We do not sell personal data and do not share it for cross-context behavioral advertising under CCPA/CPRA. Cross-border transfers use adequacy decisions or Standard Contractual Clauses plus TLS 1.2+ in transit and AES-256 encryption at rest.

4

Retention & security

  • Enquiries: 24 months from last contact, then deleted or anonymized.
  • Contracts & invoices: 8 years (Indian tax and company law).
  • Analytics aggregates: 14 months; raw event logs 90 days.
  • Backups: 90-day rolling windows; deletion propagates within 90 days.

Controls include role-based access with MFA, least-privilege credentials, encrypted secrets management, audit logging, quarterly access reviews, secure SDLC with dependency scanning, and contracted incident response with 72-hour breach notification to authorities and affected individuals where required.

5

Your rights (DPDP · GDPR · CCPA)

India — DPDP Act 2023: right to access, correction, erasure, grievance redressal and nomination, and to withdraw consent. Grievance Officer: Techfleek Technologies Pvt Ltd, address below — acknowledgment within 24 hours, resolution within 15 days.

EU/UK — GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right to lodge a complaint with your supervisory authority.

California — CCPA/CPRA: know, delete, correct, opt out of sale/sharing, limit use of sensitive data, and non-discrimination. We honor Global Privacy Control signals as opt-out requests.

To exercise any right, email hello@techfleek.com with the subject "Privacy request". We verify identity proportionately and respond within 30 days (up to 45 days for complex CCPA requests with notice).

6

Children, signals & changes

  • Our site is not directed to children under 16 (under 18 in India without guardian consent). We delete such data promptly on discovery.
  • We honor Do-Not-Track and Global Privacy Control as opt-outs of marketing storage.
  • Material changes to this policy are posted here with a new "Last updated" date and, where appropriate, emailed 15 days in advance. Continued use after the effective date constitutes acceptance.

Data controller / contracting entity

Techfleek Technologies Pvt Ltd (TechFleek)

Frequently asked questions

Quick answers to the questions we hear most.

No. We never sell personal data and do not share it for cross-context behavioral advertising. Sub-processors act only on our documented instructions.