Working with us from anywhere
We are an Indian company. Data you send through this website is processed in India, so working with us is a cross-border transfer whichever country you are in, and each one answers that differently. Rather than bury it, this page says exactly where your data goes, who else sees it, what protects it, and what we sign in your jurisdiction, so the arrangement is defensible to whoever asks inside your organisation.
Where it lives
This website: DigitalOcean, India. Your project: on infrastructure you own, with us added as developers. Your data does not touch ours unless you ask for a demo.
What protects it
TLS with HSTS, a database with no public port, daily backups kept thirty days with failure alerts. No certification, and we say so.
What we sign
Mutual NDA before scoping. Your DPA and your transfer clauses, on your paper. The repository is yours from the first commit.
Who else receives your data
Every third party that gets personal data from this website, what each one gets, and when. This list is generated from the code that calls them, not written from memory.
| Provider | Purpose | What they receive | Region | When |
|---|---|---|---|---|
| DigitalOcean | Hosting, database, file storage and backups | Everything the site stores: enquiry form submissions, chat transcripts and any details given to the chat, uploaded media, the content database and its nightly backups. | India (object storage in the Bangalore region) | Always - this is where the site runs. |
| Zoho Corporation | The contents of enquiry notifications and replies - your name, email address, company and message. | India | When you submit a form, or when we email you. | |
| OpenRouter, routing to Anthropic | The assistant on this site | The messages you type into the chat, and the name and email address if you provide them to continue a conversation. Used only to generate the reply. We do not train anything on them. | United States | Only if you use the chat. The rest of the site makes no call to any model provider. |
| Analytics and form protection | Page views, clicks on booking and contact links, and a spam-check on form submissions. Analytics runs with IP anonymisation and no user-level identifiers we set. | United States | On every page (analytics). On form submission (reCAPTCHA). | |
| Microsoft Clarity | Session analytics | How pages are used - scrolls, clicks, and masked session replays. Text you type into forms is masked. | United States | On every page. |
| Cal.com | Booking a call | Your name, email address and the meeting time you choose. | United States | Only if you book a call. The booking page is theirs, opened in a new tab. |
What protects it
Only what is actually in place: the set of controls we run, each with a way for you to check it. Where your procurement asks for ISO 27001, SOC 2 or a penetration test, we work inside your own programme and your auditor checks our access.
Encrypted in transit, everywhere
TLS on every request, with HSTS set for one year and applied to all subdomains, so a browser will not fall back to plain HTTP.
verify · Any HTTP security-header checker against boffincoders.com.
The database is not reachable from the internet
It accepts connections only from the application itself. There is no public database port.
Daily backups, retained thirty days, with failure alerts
A full backup runs every day and is kept for thirty days. A failed backup alerts us the same day rather than being discovered when it is needed.
Encrypted at rest in object storage. DigitalOcean Spaces encrypts stored objects at rest. That covers uploaded media and every backup.
verify · DigitalOcean Spaces documentation.
Enquiries are readable only by signed-in team members
Anything you submit through this site is stored behind authentication. Nothing submitted is publicly readable.
How we work, and what we sign
The paperwork your procurement team will ask for. Ask for any of it before the first call; none of it needs a signed contract to be sent.
- Your infrastructure, not ours
- By default your project runs on accounts you provision and own - hosting, database, source repositories, every third-party service. We are added as developers to your accounts rather than holding anything of yours in ours. Your data never touches our infrastructure unless you ask us to stand up a demo environment, and then only for that purpose.You do not need to be technical to do this. We walk you through creating each account, what access to grant, and how to hand credentials over safely - usually one call. The steps are written up so you can follow them at your own pace.The accounts your development team needs, and who should own them →
- You own the repository from the first commit
- Code lives in a repository under your organisation, with us as contributors. There is no handover of ownership at the end, because ownership was never anywhere else. The same applies to designs and any accounts created for the project.
- Non-disclosure
- We sign a mutual NDA before scoping, and have on nearly every engagement to date - which is why most of our long-running client work does not appear on this site.
- Data processing agreement
- Where an engagement involves personal data, we sign your DPA. Send it with the NDA and both come back together.
- The cross-border transfer, wherever you are
- We are in India, so every engagement is a cross-border transfer and every jurisdiction has its own answer. We sign whichever applies, on your paper. Because your data stays on infrastructure you own, the transfer is in practice limited to what our developers see while working inside your systems.European Union: India has no adequacy decision, so standard contractual clauses apply. United Kingdom: the International Data Transfer Agreement, or the Addendum to the EU clauses. Australia: APP 8 makes you accountable for an overseas recipient, so the contract carries the equivalent obligations. Canada: PIPEDA requires comparable protection by contract. United States: your state law.
Questions to ask any vendor outside your jurisdiction
Including us. If a vendor cannot answer these in writing, that is the answer.
- Where, precisely, is my data stored - which country and which region?
- Which third parties receive it, and what does each one get?
- What is the legal mechanism for the transfer, and will you sign it?
- Who on your side can access production, and how is that access protected?
- How often are backups taken, where do they go, and when did you last restore one?
- What happens to my data when the engagement ends?
- If a breach happens, how quickly do I hear about it?
We reply to every enquiry within one working day.
Ask for the DPA, the transfer clauses or the NDA and they come back within one working day. Anything on this page you want in writing, we will put in writing.
Questions procurement asks
The six that come up in every vendor review. Each answer is a summary of something stated above, so nothing here is a new promise.
- Where does our data live if we work with you?
- In your own accounts. By default the project runs on infrastructure you provision and own - hosting, database, repositories, every third-party service - and we are added as developers. Your data only touches ours if you ask us to stand up a demo environment, and then only for that purpose.
- We are outside India. What covers the transfer?
- A transfer mechanism signed before work starts, and which one depends on where you are. European Union: standard contractual clauses, because India has no adequacy decision. United Kingdom: the International Data Transfer Agreement or the Addendum. Australia: contract terms carrying the APP 8 obligations. Canada: comparable protection under PIPEDA. United States: your state law. We sign whichever applies, on your paper.
- Will you sign our DPA?
- Yes, and a mutual NDA before scoping. Send both with the enquiry and they come back within one working day. We do not require you to use our template.
- Who else receives our data?
- The sub-processors listed on this page, each with what it receives and when. That list is generated from the code that calls them rather than written from memory, so it does not drift from what the site actually does.
- Do you hold any certification?
- Not as a company certificate. We run the controls published on this page, each with a way for you to check it yourself, and where your procurement asks for ISO 27001, SOC 2 or a penetration test, we work inside your own programme and your auditor or testing provider checks our access and our code under your agreement.
- What happens to our data when the engagement ends?
- Nothing moves, because nothing was ours. Our accounts are removed from your systems, the shared vault stops being shared, and you rotate the keys. Three steps, and the page above lists them in order.
Not answered here?
This page describes what we do. It is not legal advice for your organisation. Reviewed 11 September 2026. See also our privacy policy for the mobile applications we publish.