Tejasbyte Technologies
Start Project
HomeServicesPortfolioBlogAboutContactStart Project
Legal

Data Policy

This policy governs how Tejasbyte Technologies Pvt. Ltd. collects, processes, stores, protects, and manages data — including client data entrusted to us during software development engagements.

Last updated: August 11, 2026

Table of Contents

  1. Definitions
  2. Scope of This Policy
  3. Data We Process
  4. Lawful Basis for Processing
  5. Data Subject Rights
  6. Data Processor Obligations
  7. Data Security Standards
  8. Incident Response & Breach Notification
  9. Data Retention & Deletion
  10. Sub-processors
  11. Cross-Border Data Transfers
  12. Client Data Responsibilities
  13. Policy Governance
  14. Contact
01

Definitions

For the purposes of this Data Policy, the following terms have the meanings set out below:

Personal Data: Any information relating to an identified or identifiable natural person ('data subject'), including name, email address, IP address, or any combination of data that could identify an individual.
Client Data: All data, including personal data, that a client provides to Tejasbyte or that Tejasbyte processes on behalf of a client in the course of delivering services.
Data Controller: The entity that determines the purposes and means of processing personal data. Clients are typically the data controller for their end-user data.
Data Processor: The entity that processes personal data on behalf of the data controller. Tejasbyte acts as a data processor when handling client data.
Processing: Any operation or set of operations performed on personal data, whether by automated means or otherwise — including collection, storage, use, transmission, and deletion.
Sub-processor: A third-party service provider engaged by Tejasbyte to assist in the processing of personal data on behalf of a client.
02

Scope of This Policy

This Data Policy applies to:

  • All personal data and client data processed by Tejasbyte Technologies in the course of delivering software engineering, AI development, cloud infrastructure, and related services
  • Data collected through our website at www.tejasbyte.com
  • Data shared with us by clients, partners, and prospective clients during pre-sales, onboarding, and active engagements
  • All employees, contractors, and service providers of Tejasbyte who have access to personal or client data
This policy is read alongside our Privacy Policy, which governs personal data collected directly from website visitors.
03

Data We Process

Website visitor data:

  • Contact and enquiry information submitted via forms (name, email, company, project details)
  • Technical and usage data collected through cookies and analytics tools
  • Newsletter subscription data

Client engagement data:

  • Business contact information for client stakeholders and team members
  • Project specifications, source code, database schemas, and technical documentation
  • End-user data that clients entrust to Tejasbyte for development, testing, or infrastructure purposes
  • Access credentials and environment configuration (handled under strict security protocols)

Operational data:

  • Financial records including invoices and payment information
  • Contract and legal correspondence
  • Internal communications and project management records
04

Lawful Basis for Processing

Tejasbyte processes data under the following lawful bases as applicable:

Contractual performance: Processing necessary to deliver services under a signed agreement or statement of work.
Legitimate interests: Processing necessary to operate our business, improve our services, and maintain client relationships, where these interests are not overridden by data subject rights.
Legal obligation: Processing required to comply with applicable laws and regulations in the jurisdictions where we operate, including the United States and Nepal.
Consent: Processing of website visitor data for analytics and marketing where we have obtained clear, specific consent.
05

Data Subject Rights

Tejasbyte respects the rights of individuals whose data we process. Where we act as data processor, we will assist our clients (as data controllers) in fulfilling these rights. Applicable rights may include:

  • The right to be informed about how personal data is used
  • The right to access personal data held about an individual
  • The right to rectification of inaccurate data
  • The right to erasure ('right to be forgotten') where applicable
  • The right to restriction of processing
  • The right to data portability in a structured, machine-readable format
  • The right to object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making and profiling

To exercise any right or to make a data subject request, contact us at contact@tejasbyte.com.

06

Data Processor Obligations

When Tejasbyte processes personal data on behalf of a client, we commit to the following obligations:

  • Process personal data only on documented instructions from the client
  • Ensure that all personnel with access to personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist the client in responding to data subject rights requests
  • Delete or return all personal data to the client upon termination of services
  • Provide all information necessary to demonstrate compliance with data protection obligations
  • Notify the client without undue delay upon becoming aware of a personal data breach
  • Not engage sub-processors without prior written authorisation from the client
07

Data Security Standards

Tejasbyte implements security measures commensurate with the sensitivity of the data and the risks involved. Our security practices include:

  • Encryption in transit using TLS 1.2 or higher for all data communications
  • Encryption at rest for sensitive data stored in our systems
  • Role-based access control (RBAC) limiting data access to authorised personnel only
  • Multi-factor authentication (MFA) for access to production systems and client environments
  • Regular security reviews and penetration testing of systems handling client data
  • Secure code development practices including OWASP guidelines
  • Vendor security assessments for all sub-processors handling personal data
  • Incident response procedures and documented escalation paths
08

Incident Response & Breach Notification

In the event of a confirmed personal data breach, Tejasbyte will:

  • Contain and assess the breach as promptly as possible
  • Notify affected clients without undue delay and no later than 72 hours after becoming aware of a breach involving their data
  • Provide clients with sufficient information to fulfil their own notification obligations to regulatory authorities and affected individuals
  • Document the breach, its effects, and all remedial actions taken
  • Conduct a post-incident review to prevent recurrence
Clients must provide an emergency contact and notification procedure in their service agreement. Breach notifications will be directed to the designated contact.
09

Data Retention & Deletion

Tejasbyte retains data only as long as required to fulfil the purposes for which it was collected or to comply with legal obligations.

  • Client project data: retained for the duration of the engagement plus up to 12 months unless instructed otherwise
  • Source code and deliverables: returned or deleted upon project completion or client request
  • Financial and contractual records: retained for 7 years in accordance with legal requirements
  • Website enquiry data: retained for up to 3 years
  • Employee and contractor data: retained as required by employment law

Upon termination of a service agreement, Tejasbyte will securely delete or return all client data within 30 days of the termination date, unless instructed otherwise in writing.

10

Sub-processors

Tejasbyte engages the following categories of sub-processors who may have access to personal or client data in the course of delivering services:

  • Cloud infrastructure providers (e.g. AWS, Google Cloud, Azure) for hosting and compute
  • Version control and project management tools (e.g. GitHub, Linear, Notion) for development workflows
  • Communication platforms used in client engagements (e.g. Slack, Google Workspace)
  • Transactional email providers (Resend) for service communications
  • Analytics providers (e.g. Google Analytics) for website usage data

We will inform clients of any intended changes to sub-processors and provide the opportunity to object. Sub-processors are selected based on security standards and are bound by data processing agreements.

11

Cross-Border Data Transfers

Tejasbyte's operations span the United States and Nepal. Data may be transferred between these jurisdictions in the course of delivering services. We ensure that such transfers are governed by appropriate safeguards including:

  • Standard contractual clauses where required by applicable data protection law
  • Transfers to providers participating in recognised data protection frameworks
  • Contractual protections between Tejasbyte entities and personnel
12

Client Data Responsibilities

Where clients share personal data with Tejasbyte for development, testing, or other purposes, clients acknowledge that:

  • They are the data controller and are responsible for ensuring they have a lawful basis to share that data with Tejasbyte
  • Production personal data should not be used for development or testing purposes without appropriate anonymisation or pseudonymisation
  • Clients must inform Tejasbyte of any specific data handling requirements, applicable regulations (e.g. HIPAA, GDPR), or restrictions before engagement
  • Clients are responsible for obtaining any consents required from their end users
We strongly recommend that clients use anonymised or synthetic data for development and testing environments wherever possible.
13

Policy Governance

This Data Policy is reviewed at least annually and updated to reflect changes in our operations, legal obligations, or industry best practices. The most recent version is always available at www.tejasbyte.com/data-policy.

All Tejasbyte personnel and contractors are required to adhere to this policy as a condition of their engagement.

14

Contact

For questions or concerns about this Data Policy, data processing practices, or to submit a data subject request:

🏢
Company
Tejasbyte Technologies Pvt. Ltd.
🇺🇸
US Office
2420 Rheem Ave, Richmond, California, CA 94804
🇳🇵
Nepal Office
Kathmandu, Nepal
✉️
Data enquiries
contact@tejasbyte.com
Also read our Privacy Policy →← Back to Home