Skip to main content
Global Privacy & Data Governance

Privacy Policy

Fine-tuned compliance with Indian IT Rules (DPDPA 2023, IT Act 2000), UK GDPR (Data Protection Act 2018), and US Federal & State Privacy Laws (CCPA/CPRA, COPPA).

Effective Date: September 2, 2026 Version: 3.2 (US / UK / IN Multi-Jurisdiction)
🇮🇳

India IT Rules & DPDPA

Compliant with Digital Personal Data Protection Act 2023, IT Act 2000 & SPDI Rules 2011.

🇬🇧

UK GDPR & DPA 2018

ICO-aligned data subject rights, lawful processing bases, and international transfer safeguards.

🇺🇸

US CCPA / CPRA & COPPA

Zero sale of personal data, GPC signal support, transparent collection categories, and 45-day SLAs.

1

Overview & Data Fiduciary Details

This Privacy Policy applies to Binary Froster (“we”, “us”, “our”, or the “Company”), operating via binaryfroster.com, managed by Founder & AI Engineer Shivam Dube. We provide bespoke software engineering, enterprise web applications, Artificial Intelligence integrations, workflow automations, and digital consulting to enterprise clients across India, the United States, the United Kingdom, and globally.

Depending on your jurisdiction:

  • In India: Binary Froster acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000.
  • In the United Kingdom: Binary Froster acts as a Data Controller under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 (DPA 2018).
  • In the United States: Binary Froster acts as a Business under the California Consumer Privacy Act (CCPA/CPRA) and applicable state privacy frameworks.
2

Global Regulatory Definitions

Personal Data / Personal InformationAny data about an identifiable individual (natural person), including identifiers like names, emails, IP addresses, phone numbers, and professional attributes.
Data Principal / Data Subject / ConsumerThe individual whose personal data is processed by Binary Froster through website visits, quote submissions, client onboarding, or contract execution.
Data Fiduciary / Data ControllerBinary Froster, who determines the purpose and means of personal data processing.
Data Processor / Service ProviderVetted third parties (e.g., cloud hosts, email routers, payment gateways) that process personal data on behalf of Binary Froster.
3

Information We Collect

We collect information across three primary channels with strict adherence to data minimization principles:

A. Information You Directly Provide to Us

  • Inquiry & Contact Details: Full name, professional email address, telephone/WhatsApp number, company name, job title, and geographic location submitted via our contact forms, discovery scheduler, or interactive quote slider.
  • Project Specifications: Technical scope, software architectural requirements, budget brackets (USD $, GBP £, INR ₹), wireframes, design briefs, and project timeline goals.
  • Commercial & Invoicing Records: Billing address, tax identification numbers (e.g., GSTIN in India, VAT in UK/EU, EIN in US), purchase order details, and payment transaction metadata (processed via secure PCI-DSS level-1 payment partners like Stripe and Razorpay; we never store raw credit card numbers on our servers).
  • Interactive Chat & Live Inquiries: Messages, prompts, and inquiries submitted through our on-site live chat assistant (`botBrain`).

B. Information Collected Automatically

  • Device & Network Telemetry: IP address, browser type and version, language preference, operating system, screen resolution, referring URLs, and time zone.
  • Site Interaction & Performance Metrics: Pages viewed, dwell time, navigation clicks, scroll depth, and client-side error telemetry for performance monitoring.

C. Sensitive Personal Data Notice

We do NOT knowingly solicit or collect Sensitive Personal Data or Information (SPDI) as defined under India SPDI Rules 2011, Special Category Data under UK GDPR Article 9 (such as biometric identifiers, genetic data, religious beliefs, sexual orientation, political opinions), or Sensitive Personal Information under California CPRA on public contact forms.

4

Lawful Bases for Processing (UK GDPR & India DPDPA)

Under UK GDPR (Article 6) and the Indian DPDPA (Section 4 & 6), we only process your personal data where a recognized lawful basis exists:

1. Contractual PerformanceProcessing necessary to prepare proposals, execute Master Services Agreements (MSAs), deliver custom software, manage source code repositories, and process invoices.
2. Explicit ConsentWhen you opt-in to receive technical whitepapers, case studies, newsletters, or submit quote requests. You may withdraw consent at any time.
3. Legitimate InterestsSecuring our web applications, mitigating DDoS attacks, preventing bot spam, optimizing application loading speed, and defending against legal claims.
4. Legal & Regulatory ComplianceComplying with statutory accounting rules, tax filings, court summons, law enforcement directives under India IT Act Section 69 / UK Investigatory Powers Act / US lawful orders.
5

How We Use Your Information

  • Service Delivery & Engineering: Designing, prototyping, architecting, coding, testing, and deploying custom software deliverables, client portals, and AI pipelines.
  • Commercial Communication: Responding to discovery inquiries within 24 business hours, delivering milestone updates, conducting sprint demos, and sending invoices.
  • Security & Threat Mitigation: Enforcing rate-limiting on API endpoints, verifying reCAPTCHA tokens, auditing system logs, and thwarting malicious penetration attempts.
  • Continuous Platform Optimization: Analyzing aggregate user telemetry to optimize mobile responsiveness, enhance accessibility (WCAG 2.1 AA), and refine our portfolio demos.
6

AI & Machine Learning Data Processing

Enterprise AI Confidentiality Commitment

As an AI Engineering studio, Binary Froster enforces strict privacy boundaries when implementing Large Language Models (LLMs), RAG pipelines, voice assistants, and algorithmic workflows:

  • Zero Public AI Model Training: Client proprietary codebases, confidential business datasets, and personal data processed through our AI infrastructure are NEVER used to train, retrain, or fine-tune public third-party foundation models (such as OpenAI ChatGPT, Anthropic Claude, or Google Gemini) without express written consent.
  • Commercial API Privacy: When client solutions interface with third-party AI APIs, we utilize enterprise-tier commercial endpoints that enforce zero-data-retention (ZDR) and strict SOC2/HIPAA compliance guarantees.
  • Synthetic Data in Sandboxes: All live portfolio sandboxes, interactive demo modals, and test mockups on our website utilize anonymized or synthetic test data.
7

Cookies & Tracking Technologies (PECR & CCPA/CPRA)

We employ minimal, privacy-centric cookies and browser storage in compliance with UK Privacy and Electronic Communications Regulations (PECR) and California CPRA:

Essential & Security CookiesStrictly necessary for CSRF protection, currency preferences (USD, GBP, INR), and session stability.
Always Active
Performance & Telemetry StorageAnonymous Core Web Vitals telemetry to diagnose latency and rendering performance.
Consent / GPC Honored

Global Privacy Control (GPC): We recognize and automatically honor browser Global Privacy Control (GPC) opt-out preference signals in accordance with California CPRA and Colorado CPA requirements.

8

Data Sharing, Subprocessors & Disclosures

We DO NOT sell your personal information or share it for cross-context behavioral advertising.

We disclose personal data strictly to vetted third-party service providers (subprocessors) under binding Data Processing Agreements (DPAs) with strict confidentiality obligations:

  • Cloud Infrastructure & Hosting: Vercel Inc. (Global Edge Network), Render Inc., Amazon Web Services (AWS), Supabase Inc.
  • Communication & Invoicing: Nodemailer/SMTP providers, Twilio Inc., Google Workspace (corporate communications).
  • Payment Gateways: Stripe Payments Inc. (US/UK/Global), Razorpay Software Pvt. Ltd. (India).
  • Legal & Regulatory Mandates: We may disclose data where required by valid court order, search warrant, subpoena, or statutory directive issued by competent government authorities under applicable law.
9

International & Cross-Border Data Transfers

Because Binary Froster serves clients across India, the United States, and the United Kingdom, personal data may be transferred to and stored on servers located outside your home country.

UK & EU International TransfersFor transfers from the UK/EEA to non-adequate jurisdictions, we execute the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs) with robust supplementary technical safeguards (encryption in transit and at rest).
India DPDPA Cross-Border ComplianceData transfers originating from India comply with Section 16 of the Digital Personal Data Protection Act, 2023 and government-notified jurisdiction allowances.
10

Data Retention & Security Measures

Data Retention Periods

We retain personal data only as long as necessary to fulfill project deliverables, maintain active business relationships, and comply with statutory limitation periods (e.g., 7 years for financial and tax records under Indian and UK tax laws). Inactive prospective lead inquiries are purged after 24 months.

Technical Security Standards

Compliant with Section 43A of India IT Act & UK GDPR Article 32: TLS 1.3 encryption in transit, AES-256 encryption at rest, strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), automated vulnerability scans, and secure containerized runtime environments.

11

Your Privacy Rights: US, UK & India

We provide comprehensive data subject rights to all users globally, with specific statutory alignments:

🇮🇳 India: Rights Under DPDPA 2023 & IT Act 2000

30-Day SLA
  • Right to Access Summary: Obtain a summary of personal data being processed and data processing activities.
  • Right to Correction & Erasure: Request correction of inaccurate/misleading data and erasure of data no longer necessary for purpose.
  • Right to Grievance Redressal: Dedicated redressal through our appointed Grievance Officer before escalating to the Data Protection Board of India.
  • Right to Nominate: Nominate an individual to exercise rights in the event of death or incapacity.

🇬🇧 United Kingdom: Rights Under UK GDPR & DPA 2018

1-Month SLA
  • Subject Access Request (SAR): Request confirmation and copies of your personal data free of charge.
  • Right to Rectification & Erasure (“Right to be Forgotten”): Rectify inaccurate records or demand permanent deletion.
  • Right to Data Portability: Receive your data in a structured, commonly used machine-readable format (JSON/CSV).
  • Right to Object & Restrict: Object to legitimate interest processing or direct marketing at any time.
  • Supervisory Authority Complaint: You have the statutory right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

🇺🇸 United States: Rights Under CCPA / CPRA & State Laws

45-Day SLA
  • Right to Know / Access: Request disclosure of categories and specific pieces of personal information collected over the preceding 12 months.
  • Right to Delete: Request deletion of personal information collected, subject to legal recordkeeping exemptions.
  • Right to Correct: Correct inaccurate personal information maintained about you.
  • Right to Non-Discrimination: We will never discriminate against you in pricing, service quality, or response times for exercising CCPA rights.
  • Authorized Agent: You may designate an authorized agent registered with the Secretary of State to submit requests on your behalf with verified written authorization.
How to Exercise Your Rights: Submit your request with proof of identity to binaryfroster@gmail.com. We acknowledge receipt within 48 hours and resolve verified requests within statutory deadlines (30 days for India/UK, 45 days for US).
12

Children’s Privacy (COPPA / DPDPA)

Our website, products, and commercial software services are strictly intended for business enterprises, working professionals, and individuals aged 18 years and older(or the applicable age of majority in your jurisdiction). In accordance with the US Children’s Online Privacy Protection Act (COPPA), UK Age-Appropriate Design Code, and Section 9 of the India DPDPA 2023, we do not knowingly collect, track, or profile personal data of children under 13 in the US, under 16 in the UK, or under 18 in India. If you believe a child has provided us with personal information, please contact us immediately for prompt deletion.

13

Grievance Officer & Statutory Contacts

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Rule 3(2)) and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer and Data Protection Officer are published below:

Designated OfficerShivam DubeFounder & AI Engineer / Grievance Officer
OrganizationBinary FrosterAI Engineering & Custom Software Studio
Grievance Acknowledgment SLAWithin 24–48 Hours
Grievance Escalation Process: All privacy grievances, data principal rights requests, and security disclosures received by the Grievance Officer will be acknowledged within 48 hours and substantively resolved within 15 to 30 calendar days.
Have questions about our Terms? Review our Terms of Service.