Privacy Policy
Effective Date: January 1, 2026 • GDPR, UK GDPR & India DPDP Act (2023) Aligned
1. Information We Collect
We strictly collect corporate and professional information necessary to deliver high-performance software interventions:
- Inquiry & Consultation Data: Professional business contact details (name, corporate email, phone number, company name, domain, and stated technical bottlenecks).
- Diagnostic System Information: Architecture schemas, error logs, anonymized database query telemetry, API endpoint specifications, and platform configuration metadata shared voluntarily during Technical Audits.
- Engineering Retainer Administrative Data: Project management identities (Slack handles, GitHub/GitLab usernames) necessary for sprint coordination and code commits.
2. Processing of Diagnostic Audit Data & Zero-Retention Policy
During preliminary and forensic technical audits (AIM Framework):
- We request read-only access to repositories and monitoring dashboards. We never require or store end-user Personal Identifiable Information (PII) or production customer credit card details.
- All diagnostic samples and architecture diagrams are analyzed in secure, air-gapped environments and are permanently expunged within 30 days of audit ledger delivery.
- We never sell, broker, or monetize client system telemetry under any circumstances.
3. Artificial Intelligence (Claude AI) & LLM Data Boundaries
When engineering automated AI workflows, RAG knowledge retrieval hubs, or Anthropic Claude agent tools:
- No Model Training: Involve Technologies only utilizes enterprise-tier commercial API endpoints (Anthropic Commercial API, OpenAI Enterprise, Azure OpenAI) with zero-data-retention (ZDR) guarantees. Your corporate data, prompts, and completions are never utilized to train foundation models.
- Encrypted Vector Embeddings: Vector embeddings generated for customer knowledge retrieval are encrypted with AES-256 at rest and stored exclusively in private customer tenants.
4. WhatsApp Cloud API & Messaging Compliance
For WhatsApp Cloud API integrations, all messaging payloads, phone numbers, and webhook events pass directly between the client's Meta Business Manager tenant and the client's core CRM or database via TLS 1.3 encrypted pipelines. Involve Technologies does not store intermediate conversational transcripts on third-party servers.
5. Staff Augmentation & Workstation Security
Our dedicated platform engineers operate under individual bilateral NDAs, SOC 2 Type II workstation compliance, full-disk BitLocker/FileVault encryption, password manager vault enforcement, and biometric multi-factor authentication. Developers access client code repositories directly without local repository replication to unauthorized devices.
6. Cloud Sub-Processors & Infrastructure Partners
We work exclusively with ISO 27001, SOC 2 Type II, and PCI-DSS compliant cloud providers for hosting our website and staging environments, including Amazon Web Services (AWS), Microsoft Azure, DigitalOcean, and Cloudflare.
7. Cross-Border International Data Transfers
As an engineering firm operating across India, the United Kingdom, the United Arab Emirates, and the United States, all cross-border data transfers are protected under Standard Contractual Clauses (SCCs) and rigorous data processing agreements conforming to GDPR Article 46 and the Digital Personal Data Protection (DPDP) Act 2023.
8. Your Data Protection Rights
Depending on your jurisdiction, you possess the right to access, update, rectify, port, or request permanent deletion of your business contact information from our CRM. Requests are fulfilled within 14 business days.
Contact Our Data Protection Officer
To exercise your data privacy rights or review enterprise security certifications, email our compliance team at privacy@involvetechnologies.com.