Who else receives your data
Every third party that gets personal data from this website, what each one gets, and when. This list is generated from the code that calls them, not written from memory.
Data protection · reviewed 11 September 2026
We are an Indian company. Data you send through this website is processed in India, and India has no adequacy decision from the EU or the UK. Rather than bury that, this page says exactly where your data goes, who else sees it, what protects it, and what we sign so that working with us is defensible to your own data protection officer.
This website: DigitalOcean, India. Your project: on infrastructure you own, with us added as developers. Your data does not touch ours unless you ask for a demo.
TLS with HSTS, a database with no public port, daily backups kept thirty days with failure alerts. No certification, and we say so.
Mutual NDA before scoping. Your DPA and your transfer clauses, on your paper. The repository is yours from the first commit.
Every third party that gets personal data from this website, what each one gets, and when. This list is generated from the code that calls them, not written from memory.
| Provider | Purpose | What they receive | Region | When |
|---|---|---|---|---|
| DigitalOcean | Hosting, database, file storage and backups | Everything the site stores: enquiry form submissions, chat transcripts and any details given to the chat, uploaded media, the content database and its nightly backups. | India (object storage in the Bangalore region) | Always — this is where the site runs. |
| Zoho Corporation | The contents of enquiry notifications and replies — your name, email address, company and message. | India | When you submit a form, or when we email you. | |
| OpenRouter, routing to Anthropic | The assistant on this site | The messages you type into the chat, and the name and email address if you provide them to continue a conversation. Used only to generate the reply. We do not train anything on them. | United States | Only if you use the chat. The rest of the site makes no call to any model provider. |
| Analytics and form protection | Page views, clicks on booking and contact links, and a spam-check on form submissions. Analytics runs with IP anonymisation and no user-level identifiers we set. | United States | On every page (analytics); on form submission (reCAPTCHA). | |
| Microsoft Clarity | Session analytics | How pages are used — scrolls, clicks, and masked session replays. Text you type into forms is masked. | United States | On every page. |
| Cal.com | Booking a call | Your name, email address and the meeting time you choose. | United States | Only if you book a call. The booking page is theirs, opened in a new tab. |
Only what is actually in place. We hold no security certification — no ISO 27001, no SOC 2 — and we have not commissioned a penetration test. What follows is the set of controls we run, each with a way for you to check it.
TLS on every request, with HSTS set for one year and applied to all subdomains, so a browser will not fall back to plain HTTP.
verify · Any HTTP security-header checker against boffincoders.com.
It accepts connections only from the application itself. There is no public database port.
A full backup runs every day and is kept for thirty days. A failed backup alerts us the same day rather than being discovered when it is needed.
DigitalOcean Spaces encrypts stored objects at rest. That covers uploaded media and every backup.
verify · DigitalOcean Spaces documentation.
Anything you submit through this site is stored behind authentication. Nothing submitted is publicly readable.
The paperwork your procurement team will ask for. Ask for any of it before the first call; none of it needs a signed contract to be sent.
Including us. If a vendor cannot answer these in writing, that is the answer.
We reply to every enquiry within one working day.
Ask for the DPA, the transfer clauses or the NDA and they come back within one working day. Anything on this page you want in writing, we will put in writing.
This page describes what we do. It is not legal advice for your organisation. Reviewed 11 September 2026. See also our privacy policy for the mobile applications we publish.