Privacy Policy & Client Data Safeguards
At Bugbattlers Technologies Pvt. Ltd., we treat client confidential information, trade secrets, user data, and code repositories with uncompromising security. This Privacy Policy details how we handle, process, and protect your data across our entire service portfolio.
Overview & Scope
This Privacy Policy governs the operations of Bugbattlers Technologies Pvt. Ltd. (“Bugbattlers”, “we”, “us”, or “our”), a private limited software engineering corporation headquartered in Pune, Maharashtra, India. This policy describes our principles regarding the collection, storage, processing, transfer, and protection of personal data and confidential client artifacts.
This policy applies to all visitors of our official website (https://bugbattlers.com), prospective clients requesting software engineering proposals, existing clients under active Master Services Agreements (MSAs) or Statements of Work (SOWs), and users of software systems, applications, and platforms engineered by Bugbattlers.
Key Privacy Promise
We operate strictly under a Privacy-by-Design paradigm. We never sell, rent, monetize, or trade client source code, database dumps, user data, or proprietary algorithms to third parties under any circumstances.
Information We Collect
Depending on how you interact with Bugbattlers, we collect information across three primary categories:
A. Client & Contact Data
Full names, professional email addresses, phone numbers, job titles, organization names, billing addresses, and tax identifiers (GST/VAT) provided during consultation forms, sales inquiries, and billing setup.
B. Engineering & Project Artifacts
System architecture diagrams, API specs, database schemas, source code repositories, staging server credentials, and test datasets supplied under signed Non-Disclosure Agreements (NDAs).
C. Technical & Usage Metadata
IP addresses, browser type, operating system metadata, referral URLs, pages visited, session duration, and device diagnostic logs collected via automated web server logs when browsing our digital portals.
Service-Specific Data Practices
Because Bugbattlers delivers specialized technology solutions across multiple domains, specific privacy protocols apply per service line:
Zero Data-Leakage Guarantee: Client proprietary data, private LLM prompts, embeddings, vector databases (Pinecone, Qdrant, pgvector), and training data are processed in isolated client-dedicated VPCs or on-premises nodes. Client data is NEVER used to train or fine-tune public baseline AI models (e.g. OpenAI, Anthropic, Google Gemini public models).
When submitting iOS and Android apps to the Apple App Store and Google Play, we generate compliant Apple Privacy Nutrition Labels and Google Play Data Safety forms reflecting exact app runtime behaviors (e.g., location permissions, camera access, push notifications, telemetry).
Infrastructure deployments on AWS, Microsoft Azure, and Google Cloud Platform (GCP) are configured directly within the client’s own cloud tenant accounts. Access keys and secrets are stored in hardware security modules (AWS KMS, HashiCorp Vault) with least-privilege RBAC controls.
All customer checkout and payment processing flows adhere to PCI-DSS Level 1 compliance. We configure cookie consent banners and customer data deletion request workflows (Right to be Forgotten) in accordance with global e-commerce privacy standards.
Hardware device IDs, sensor data streams, and location telemetry are encrypted end-to-end using TLS 1.3 / MQTT-SN over TLS. Pseudonymization is applied to all field telemetry prior to persistence in time-series databases.
IP & NDA Safeguards
We enforce stringent confidentiality protocols to ensure 100% intellectual property protection:
- Mutual Non-Disclosure Agreement (NDA): Before analyzing your code, API docs, or business workflow, we execute a legally binding mutual NDA.
- Senior Engineer Access Controls: Project repositories are restricted solely to assigned senior engineers using 2FA/MFA enforced Git permissions.
- 100% IP Assignment: All custom source code, documentation, UI assets, and backend architectures created for your project become your exclusive intellectual property upon contract milestone fulfillment.
How We Use & Process Data
We process collected data exclusively for legitimate engineering and business purposes:
- Designing, engineering, testing, and deploying custom software applications.
- Executing software architecture audits, security vulnerability assessments, and performance optimization.
- Communicating project status, code reviews, sprint deliverables, and billing invoices.
- Providing post-launch maintenance, emergency bug resolution, and SLA server uptime monitoring.
- Complying with legal, tax, and regulatory compliance mandates.
Security & Encryption Standards
Bugbattlers enforces enterprise security benchmarks across internal workstations, cloud servers, and code repositories:
Data in Transit
TLS 1.3 / HTTPS encryption for all web, API, and git communications.
Data at Rest
AES-256 bit encryption applied across database volumes and cloud storage buckets.
Authentication
Mandatory Multi-Factor Authentication (MFA/SSO) for developer tools.
Vulnerability Audits
Automated static code analysis (SAST) and weekly dependency scanning.
Third-Party Sub-processors
To deliver reliable cloud deployment, continuous integration, and communication, we utilize trusted enterprise cloud infrastructure providers under strict Data Processing Agreements (DPAs):
| Sub-processor | Category | Purpose / Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure | Hosting, VPC, Database & Serverless (US / EU / APAC) |
| Google Cloud Platform (GCP) | AI & Analytics Hosting | AI GPU workloads & BigQuery analytics |
| GitHub / GitLab | Code Version Control | Encrypted git repositories & CI/CD workflows |
| Stripe / Razorpay | Payment Processor | PCI-DSS compliant invoice payments & transactions |
Global Regulatory Compliance
Bugbattlers serves clients across 18 countries. Our software architecture and corporate policies align with international data privacy frameworks:
EU General Data Protection Regulation (GDPR)
Provides Standard Contractual Clauses (SCCs), data minimization, right to erasure, and Data Protection Impact Assessments (DPIA) for European clients.
California Consumer Privacy Act (CCPA/CPRA)
Honors "Do Not Sell or Share My Personal Information" rights for California residents and commercial partners.
India DPDP Act 2023 & IT Act 2000
Full compliance with Indian Digital Personal Data Protection mandates, data fiduciary obligations, and CERT-In incident notification standards.
HIPAA & FERPA Compatibility
Custom healthcare and e-learning platforms engineered by Bugbattlers incorporate BAA readiness, HIPAA audit logging, and student data segregation.
Retention & Secure Destruction
We retain client data only for the duration specified in your active contract or required by tax law. Upon written contract completion, offboarding, or explicit request:
- Staging environment databases and temporary data dumps are permanently sanitized within 30 days.
- Access tokens, API keys, and cloud server SSH keys are revoked immediately upon offboarding sign-off.
- Client git repositories are archived or transferred exclusively to the client’s designated organization account.
Your Rights & Data Choices
Depending on your jurisdiction, you hold legal rights regarding your personal information:
Contact Our Data Protection Team
For privacy inquiries, Data Processing Agreement (DPA) execution, or exercising data rights, contact our Data Protection & Legal Officer:
Office No: 12, 2nd Floor, C Wing, Anant Manohar Apartment, Bhusari Colony, Kothrud, Pune - 411038, Maharashtra, India.
Ready to Start a Confidential Project?
We sign mutual NDAs before any code review or technical scoping session. Connect with our engineering team today.