Privacy Policy
Fine-tuned compliance with Indian IT Rules (DPDPA 2023, IT Act 2000), UK GDPR (Data Protection Act 2018), and US Federal & State Privacy Laws (CCPA/CPRA, COPPA).
India IT Rules & DPDPA
Compliant with Digital Personal Data Protection Act 2023, IT Act 2000 & SPDI Rules 2011.
UK GDPR & DPA 2018
ICO-aligned data subject rights, lawful processing bases, and international transfer safeguards.
US CCPA / CPRA & COPPA
Zero sale of personal data, GPC signal support, transparent collection categories, and 45-day SLAs.
Overview & Data Fiduciary Details
This Privacy Policy applies to Binary Froster (“we”, “us”, “our”, or the “Company”), operating via binaryfroster.com, managed by Founder & AI Engineer Shivam Dube. We provide bespoke software engineering, enterprise web applications, Artificial Intelligence integrations, workflow automations, and digital consulting to enterprise clients across India, the United States, the United Kingdom, and globally.
Depending on your jurisdiction:
- In India: Binary Froster acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000.
- In the United Kingdom: Binary Froster acts as a Data Controller under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 (DPA 2018).
- In the United States: Binary Froster acts as a Business under the California Consumer Privacy Act (CCPA/CPRA) and applicable state privacy frameworks.
Global Regulatory Definitions
Information We Collect
We collect information across three primary channels with strict adherence to data minimization principles:
A. Information You Directly Provide to Us
- Inquiry & Contact Details: Full name, professional email address, telephone/WhatsApp number, company name, job title, and geographic location submitted via our contact forms, discovery scheduler, or interactive quote slider.
- Project Specifications: Technical scope, software architectural requirements, budget brackets (USD $, GBP £, INR ₹), wireframes, design briefs, and project timeline goals.
- Commercial & Invoicing Records: Billing address, tax identification numbers (e.g., GSTIN in India, VAT in UK/EU, EIN in US), purchase order details, and payment transaction metadata (processed via secure PCI-DSS level-1 payment partners like Stripe and Razorpay; we never store raw credit card numbers on our servers).
- Interactive Chat & Live Inquiries: Messages, prompts, and inquiries submitted through our on-site live chat assistant (`botBrain`).
B. Information Collected Automatically
- Device & Network Telemetry: IP address, browser type and version, language preference, operating system, screen resolution, referring URLs, and time zone.
- Site Interaction & Performance Metrics: Pages viewed, dwell time, navigation clicks, scroll depth, and client-side error telemetry for performance monitoring.
C. Sensitive Personal Data Notice
We do NOT knowingly solicit or collect Sensitive Personal Data or Information (SPDI) as defined under India SPDI Rules 2011, Special Category Data under UK GDPR Article 9 (such as biometric identifiers, genetic data, religious beliefs, sexual orientation, political opinions), or Sensitive Personal Information under California CPRA on public contact forms.
Lawful Bases for Processing (UK GDPR & India DPDPA)
Under UK GDPR (Article 6) and the Indian DPDPA (Section 4 & 6), we only process your personal data where a recognized lawful basis exists:
How We Use Your Information
- Service Delivery & Engineering: Designing, prototyping, architecting, coding, testing, and deploying custom software deliverables, client portals, and AI pipelines.
- Commercial Communication: Responding to discovery inquiries within 24 business hours, delivering milestone updates, conducting sprint demos, and sending invoices.
- Security & Threat Mitigation: Enforcing rate-limiting on API endpoints, verifying reCAPTCHA tokens, auditing system logs, and thwarting malicious penetration attempts.
- Continuous Platform Optimization: Analyzing aggregate user telemetry to optimize mobile responsiveness, enhance accessibility (WCAG 2.1 AA), and refine our portfolio demos.
AI & Machine Learning Data Processing
As an AI Engineering studio, Binary Froster enforces strict privacy boundaries when implementing Large Language Models (LLMs), RAG pipelines, voice assistants, and algorithmic workflows:
- Zero Public AI Model Training: Client proprietary codebases, confidential business datasets, and personal data processed through our AI infrastructure are NEVER used to train, retrain, or fine-tune public third-party foundation models (such as OpenAI ChatGPT, Anthropic Claude, or Google Gemini) without express written consent.
- Commercial API Privacy: When client solutions interface with third-party AI APIs, we utilize enterprise-tier commercial endpoints that enforce zero-data-retention (ZDR) and strict SOC2/HIPAA compliance guarantees.
- Synthetic Data in Sandboxes: All live portfolio sandboxes, interactive demo modals, and test mockups on our website utilize anonymized or synthetic test data.
Data Sharing, Subprocessors & Disclosures
We disclose personal data strictly to vetted third-party service providers (subprocessors) under binding Data Processing Agreements (DPAs) with strict confidentiality obligations:
- Cloud Infrastructure & Hosting: Vercel Inc. (Global Edge Network), Render Inc., Amazon Web Services (AWS), Supabase Inc.
- Communication & Invoicing: Nodemailer/SMTP providers, Twilio Inc., Google Workspace (corporate communications).
- Payment Gateways: Stripe Payments Inc. (US/UK/Global), Razorpay Software Pvt. Ltd. (India).
- Legal & Regulatory Mandates: We may disclose data where required by valid court order, search warrant, subpoena, or statutory directive issued by competent government authorities under applicable law.
International & Cross-Border Data Transfers
Because Binary Froster serves clients across India, the United States, and the United Kingdom, personal data may be transferred to and stored on servers located outside your home country.
Data Retention & Security Measures
We retain personal data only as long as necessary to fulfill project deliverables, maintain active business relationships, and comply with statutory limitation periods (e.g., 7 years for financial and tax records under Indian and UK tax laws). Inactive prospective lead inquiries are purged after 24 months.
Compliant with Section 43A of India IT Act & UK GDPR Article 32: TLS 1.3 encryption in transit, AES-256 encryption at rest, strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), automated vulnerability scans, and secure containerized runtime environments.
Your Privacy Rights: US, UK & India
We provide comprehensive data subject rights to all users globally, with specific statutory alignments:
🇮🇳 India: Rights Under DPDPA 2023 & IT Act 2000
30-Day SLA- Right to Access Summary: Obtain a summary of personal data being processed and data processing activities.
- Right to Correction & Erasure: Request correction of inaccurate/misleading data and erasure of data no longer necessary for purpose.
- Right to Grievance Redressal: Dedicated redressal through our appointed Grievance Officer before escalating to the Data Protection Board of India.
- Right to Nominate: Nominate an individual to exercise rights in the event of death or incapacity.
🇬🇧 United Kingdom: Rights Under UK GDPR & DPA 2018
1-Month SLA- Subject Access Request (SAR): Request confirmation and copies of your personal data free of charge.
- Right to Rectification & Erasure (“Right to be Forgotten”): Rectify inaccurate records or demand permanent deletion.
- Right to Data Portability: Receive your data in a structured, commonly used machine-readable format (JSON/CSV).
- Right to Object & Restrict: Object to legitimate interest processing or direct marketing at any time.
- Supervisory Authority Complaint: You have the statutory right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.
🇺🇸 United States: Rights Under CCPA / CPRA & State Laws
45-Day SLA- Right to Know / Access: Request disclosure of categories and specific pieces of personal information collected over the preceding 12 months.
- Right to Delete: Request deletion of personal information collected, subject to legal recordkeeping exemptions.
- Right to Correct: Correct inaccurate personal information maintained about you.
- Right to Non-Discrimination: We will never discriminate against you in pricing, service quality, or response times for exercising CCPA rights.
- Authorized Agent: You may designate an authorized agent registered with the Secretary of State to submit requests on your behalf with verified written authorization.
Children’s Privacy (COPPA / DPDPA)
Our website, products, and commercial software services are strictly intended for business enterprises, working professionals, and individuals aged 18 years and older(or the applicable age of majority in your jurisdiction). In accordance with the US Children’s Online Privacy Protection Act (COPPA), UK Age-Appropriate Design Code, and Section 9 of the India DPDPA 2023, we do not knowingly collect, track, or profile personal data of children under 13 in the US, under 16 in the UK, or under 18 in India. If you believe a child has provided us with personal information, please contact us immediately for prompt deletion.
Grievance Officer & Statutory Contacts
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Rule 3(2)) and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer and Data Protection Officer are published below: