Written for the person who has to sign this off
Where your data lives, who can touch it, what we'll sign, and — the part vendors usually leave out — what we haven't done yet.
The physical controls are most of the answer
For this kind of work, a supervised room does more for your data than a certificate does. Here is what that means concretely.
Work happens on our machines
Client work runs on company laptops in our office. No personal devices, no working from home on your data, no files on a phone.
One room, supervised
The floor is a single supervised space. Anyone touching your process is a named employee we can identify on request.
No removable media
USB storage is disabled on work machines. Where your task genuinely needs export, it goes through an agreed channel only.
Access ends with employment
Accounts are provisioned per person per client, and revoked the day someone leaves the seat — not at the end of the month.
What we'll sign before you send anything
All of this is available before a pilot, not after. Ask and we'll send the drafts.
- Mutual NDA before we see any sample data
- Individual confidentiality undertakings signed by every person on your process
- A written scope naming which staff may access what
- Deletion or return of your data on request, and at contract end by default
- Named point of contact for any incident, with a same-day response commitment
DPDP Act, in plain terms
The Digital Personal Data Protection Act, 2023 governs personal data in India. If your batches contain personal data, this is the shape of the arrangement.
You are the Data Fiduciary
You decide why and how the data is processed. Consent, notice and the lawful basis sit with you, and we don't use your data for anything other than your task.
We are a Data Processor
We act only on your written instructions, under contract, with the access controls above — and we delete or return the data when you tell us to, or when the contract ends.
This is a description of how we work, not legal advice. Your counsel should review any agreement before you sign it.
The gaps, before you find them
We are not ISO 27001 or SOC 2 certified
Those are real, expensive audits and we have not done them. Anyone our size claiming otherwise is worth a second look.
We are not a data controller for you
We process what you send us, on your instructions, for your purposes. Your privacy notice and lawful basis stay yours.
We do not subcontract without telling you
Your work stays on our floor. If a task ever needed an outside specialist, you would be asked first, in writing.
If your process needs something stricter
Some clients need controls we don't have yet — a segregated room, device-level DLP, or a specific certification. Tell us at scoping.
If it's something we can put in place for your engagement, we'll quote it honestly. If it isn't, we'll say so and you can go elsewhere with two weeks intact rather than two months.