Data protection · reviewed 11 September 2026

Working with us from the EU and the UK

We are an Indian company. Data you send through this website is processed in India, and India has no adequacy decision from the EU or the UK. Rather than bury that, this page says exactly where your data goes, who else sees it, what protects it, and what we sign so that working with us is defensible to your own data protection officer.

Where it lives

This website: DigitalOcean, India. Your project: on infrastructure you own, with us added as developers. Your data does not touch ours unless you ask for a demo.

What protects it

TLS with HSTS, a database with no public port, daily backups kept thirty days with failure alerts. No certification, and we say so.

What we sign

Mutual NDA before scoping. Your DPA and your transfer clauses, on your paper. The repository is yours from the first commit.

Who else receives your data

Every third party that gets personal data from this website, what each one gets, and when. This list is generated from the code that calls them, not written from memory.

ProviderPurposeWhat they receiveRegionWhen
DigitalOceanHosting, database, file storage and backupsEverything the site stores: enquiry form submissions, chat transcripts and any details given to the chat, uploaded media, the content database and its nightly backups.India (object storage in the Bangalore region)Always — this is where the site runs.
Zoho CorporationEmailThe contents of enquiry notifications and replies — your name, email address, company and message.IndiaWhen you submit a form, or when we email you.
OpenRouter, routing to AnthropicThe assistant on this siteThe messages you type into the chat, and the name and email address if you provide them to continue a conversation. Used only to generate the reply. We do not train anything on them.United StatesOnly if you use the chat. The rest of the site makes no call to any model provider.
GoogleAnalytics and form protectionPage views, clicks on booking and contact links, and a spam-check on form submissions. Analytics runs with IP anonymisation and no user-level identifiers we set.United StatesOn every page (analytics); on form submission (reCAPTCHA).
Microsoft ClaritySession analyticsHow pages are used — scrolls, clicks, and masked session replays. Text you type into forms is masked.United StatesOn every page.
Cal.comBooking a callYour name, email address and the meeting time you choose.United StatesOnly if you book a call. The booking page is theirs, opened in a new tab.

What protects it

Only what is actually in place. We hold no security certification — no ISO 27001, no SOC 2 — and we have not commissioned a penetration test. What follows is the set of controls we run, each with a way for you to check it.

Encrypted in transit, everywhere

TLS on every request, with HSTS set for one year and applied to all subdomains, so a browser will not fall back to plain HTTP.

verify · Any HTTP security-header checker against boffincoders.com.

The database is not reachable from the internet

It accepts connections only from the application itself. There is no public database port.

Daily backups, retained thirty days, with failure alerts

A full backup runs every day and is kept for thirty days. A failed backup alerts us the same day rather than being discovered when it is needed.

Encrypted at rest in object storage

DigitalOcean Spaces encrypts stored objects at rest. That covers uploaded media and every backup.

verify · DigitalOcean Spaces documentation.

Enquiries are readable only by signed-in team members

Anything you submit through this site is stored behind authentication. Nothing submitted is publicly readable.

How we work, and what we sign

The paperwork your procurement team will ask for. Ask for any of it before the first call; none of it needs a signed contract to be sent.

Your infrastructure, not ours
By default your project runs on accounts you provision and own — hosting, database, source repositories, every third-party service. We are added as developers to your accounts rather than holding anything of yours in ours. Your data never touches our infrastructure unless you ask us to stand up a demo environment, and then only for that purpose.You do not need to be technical to do this. We walk you through creating each account, what access to grant, and how to hand credentials over safely — usually one call. The steps are written up so you can follow them at your own pace.The accounts your development team needs, and who should own them
You own the repository from the first commit
Code lives in a repository under your organisation, with us as contributors. There is no handover of ownership at the end, because ownership was never anywhere else. The same applies to designs and any accounts created for the project.
Non-disclosure
We sign a mutual NDA before scoping, and have on nearly every engagement to date — which is why most of our long-running client work does not appear on this site.
Data processing agreement
Where an engagement involves personal data, we sign your DPA. Send it with the NDA and both come back together.
Transfers outside the EEA and the UK
We are in India, and India has no adequacy decision from the EU or the UK, so a transfer mechanism is required rather than optional: standard contractual clauses for EU clients, the International Data Transfer Addendum for UK clients. We sign whichever applies, on your paper. Because your data stays on infrastructure you own, in practice the transfer is usually limited to what our developers see while working in your systems.

Questions to ask any vendor outside your jurisdiction

Including us. If a vendor cannot answer these in writing, that is the answer.

  1. Where, precisely, is my data stored — which country and which region?
  2. Which third parties receive it, and what does each one get?
  3. What is the legal mechanism for the transfer, and will you sign it?
  4. Who on your side can access production, and how is that access protected?
  5. How often are backups taken, where do they go, and when did you last restore one?
  6. What happens to my data when the engagement ends?
  7. If a breach happens, how quickly do I hear about it?

We reply to every enquiry within one working day.

Ask for the DPA, the transfer clauses or the NDA and they come back within one working day. Anything on this page you want in writing, we will put in writing.

This page describes what we do. It is not legal advice for your organisation. Reviewed 11 September 2026. See also our privacy policy for the mobile applications we publish.