CodeCurious Logo
  • Home
  • Services
  • Solutions
  • Work
  • About
  • Blog
  • Contact
Book Consultation →
LEGAL & DATA PRIVACY COMPLIANCE

Privacy Policy

At CodeCurious Technologies, we engineer high-scale software with zero-trust confidentiality. Here is exactly how we collect, handle, and secure your personal and commercial data.

📅 Effective Date: January 1, 2026
🔒 SOC-2 Type II & GDPR Aligned
🏢 CodeCurious Technologies Pvt. Ltd.
Table of Contents
  • 1. Information We Collect
  • 2. How We Use Information
  • 3. Client IP & Code Privacy
  • 4. AI & LLM Zero-Retention
  • 5. Data Protection & AES-256
  • 6. Cookies & Tracking
  • 7. GDPR & CCPA Rights
  • 8. Data Retention & Deletion
  • 9. Contact DPO & Legal
01

Information We Collect

CodeCurious Technologies Pvt. Ltd. ("CodeCurious", "we", "us", or "our") collects information necessary to deliver bespoke engineering services, cloud platform development, mobile applications, and technical consulting.

  • Direct Consultation Data: Your name, work email address, phone/WhatsApp number, company name, and project scope details provided via contact forms or Calendly integrations.
  • Technical Telemetry: Anonymized browser metadata, IP address, device viewport, and navigation logs used strictly to diagnose site performance and prevent DDoS attacks.
  • Project Artifacts: Architectural specifications, wireframes, repository access credentials, and API tokens provided under mutual Non-Disclosure Agreements (NDAs).
02

How We Use Your Information

We use collected information solely for genuine commercial and engineering purposes:

  • To formulate engineering estimates, sprint roadmaps, and technical architecture proposals.
  • To execute custom software development, DevOps CI/CD pipelines, and cloud deployments on your designated infrastructure.
  • To transmit critical system alerts, project deliverables, and monthly engineering dispatches (which you may opt out of at any time).
Zero Monetization Guarantee: We never sell, rent, monetize, or trade client contact details or proprietary business logic to third-party advertisers or data brokers under any circumstances.
03

Client Intellectual Property (IP) & Code Privacy

We operate under a strict 100% Client IP Ownership Model. All source code, schema designs, database scripts, deployment configurations, and trade secrets authored for your project belong exclusively to you upon payment of agreed invoices.

Our engineers work within ephemeral, containerized development sandboxes with strict RBAC access controls, ensuring client codebase isolation and zero cross-tenant contamination.

04

AI & LLM Zero-Data Retention Policy

When building autonomous AI systems, LangGraph agent workflows, or RAG platforms for our clients:

  • We mandate enterprise zero-data-retention (ZDR) APIs (e.g. OpenAI Enterprise, Anthropic Bedrock, AWS Private LLMs).
  • Your proprietary data, prompts, embeddings, and database contents are never used to train public AI foundation models.
  • Private vector databases (pgvector, Qdrant, Pinecone) are deployed inside your dedicated VPCs with end-to-end encryption.
05

Data Protection & AES-256 Encryption

We implement comprehensive defense-in-depth measures:

  • In Transit: TLS 1.3 with Perfect Forward Secrecy across all web endpoints and API gateways.
  • At Rest: AES-256 GCM encryption on all storage volumes, databases, and backup snapshots.
  • Access Control: Mandatory Hardware 2FA / WebAuthn for all engineering workstations, SSO authentication, and least-privilege IAM policies.
06

Cookies & Local Storage

Our website uses strictly minimal, privacy-friendly storage keys:

  • cc_theme: Saves your preferred UI color mode (Sapphire Dark or Light).
  • cc_session_token: Authenticates secure project estimator and contact sessions.

We do not utilize invasive cross-site tracking pixels, third-party canvas fingerprinting, or commercial spyware.

07

Your Rights (GDPR, CCPA & Global Privacy)

Regardless of your geographic location, you retain full sovereignty over your personal data:

  • Right to Access & Portability: Request an export of all personal data held in our systems.
  • Right to Rectification: Update or correct any inaccurate personal details.
  • Right to Erasure ("Right to Be Forgotten"): Request immediate permanent purging of your records from our active databases.
  • Right to Restrict Processing: Limit how your information is utilized during active commercial disputes.
08

Data Retention & Deletion Schedules

We retain contact intake records for a maximum of 24 months following the conclusion of commercial discussions, unless statutory tax or legal regulations require extended preservation. Inactive staging repositories and ephemeral test environments are cryptographically destroyed 30 days after project handoff.

09

Contact Our Data Protection Officer (DPO)

For privacy inquiries, GDPR subject access requests, or NDA execution requests, contact our legal counsel directly:

CodeCurious Technologies Pvt. Ltd. — Legal & Compliance Office
📍 TDI City, Sector 118, Mohali, Punjab 140307, India
📧 Email: contact@codecurious.in
⏱ Response SLA: Within 48 business hours.
CodeCurious Logo

High-performance software engineering partner building scalable mobile apps, web platforms, custom ERPs, and autonomous AI systems.

📍 TDI City, Sector 118, Mohali, Punjab 140307, India

Services

  • Mobile App Development
  • Next.js Web Platforms
  • Custom Software & ERP
  • Autonomous AI Workflows
  • WebRTC Live Streaming

Solutions

  • Healthcare & MedTech
  • Fintech & Payments
  • Live Streaming Platforms
  • E-Commerce Marketplaces
  • Logistics & Supply Chain

Ecosystem

  • Developer Free Tools
  • Technology Radar
  • Security & SOC2
  • System Status
  • Engineering Blogs

Company

  • About CodeCurious
  • Why CodeCurious
  • Project Estimator & Contact
  • contact@codecurious.in
  • Book Consultation →
© 2026 CodeCurious Technologies Pvt. Ltd. Engineered for market-dominating scale.
Privacy Policy • Terms of Service • Security & SOC2 • Status Page (99.99%)