Table of Contents
Definitions
For the purposes of this Data Policy, the following terms have the meanings set out below:
Scope of This Policy
This Data Policy applies to:
- All personal data and client data processed by Tejasbyte Technologies in the course of delivering software engineering, AI development, cloud infrastructure, and related services
- Data collected through our website at www.tejasbyte.com
- Data shared with us by clients, partners, and prospective clients during pre-sales, onboarding, and active engagements
- All employees, contractors, and service providers of Tejasbyte who have access to personal or client data
Data We Process
Website visitor data:
- Contact and enquiry information submitted via forms (name, email, company, project details)
- Technical and usage data collected through cookies and analytics tools
- Newsletter subscription data
Client engagement data:
- Business contact information for client stakeholders and team members
- Project specifications, source code, database schemas, and technical documentation
- End-user data that clients entrust to Tejasbyte for development, testing, or infrastructure purposes
- Access credentials and environment configuration (handled under strict security protocols)
Operational data:
- Financial records including invoices and payment information
- Contract and legal correspondence
- Internal communications and project management records
Lawful Basis for Processing
Tejasbyte processes data under the following lawful bases as applicable:
Data Subject Rights
Tejasbyte respects the rights of individuals whose data we process. Where we act as data processor, we will assist our clients (as data controllers) in fulfilling these rights. Applicable rights may include:
- The right to be informed about how personal data is used
- The right to access personal data held about an individual
- The right to rectification of inaccurate data
- The right to erasure ('right to be forgotten') where applicable
- The right to restriction of processing
- The right to data portability in a structured, machine-readable format
- The right to object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making and profiling
To exercise any right or to make a data subject request, contact us at contact@tejasbyte.com.
Data Processor Obligations
When Tejasbyte processes personal data on behalf of a client, we commit to the following obligations:
- Process personal data only on documented instructions from the client
- Ensure that all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the client in responding to data subject rights requests
- Delete or return all personal data to the client upon termination of services
- Provide all information necessary to demonstrate compliance with data protection obligations
- Notify the client without undue delay upon becoming aware of a personal data breach
- Not engage sub-processors without prior written authorisation from the client
Data Security Standards
Tejasbyte implements security measures commensurate with the sensitivity of the data and the risks involved. Our security practices include:
- Encryption in transit using TLS 1.2 or higher for all data communications
- Encryption at rest for sensitive data stored in our systems
- Role-based access control (RBAC) limiting data access to authorised personnel only
- Multi-factor authentication (MFA) for access to production systems and client environments
- Regular security reviews and penetration testing of systems handling client data
- Secure code development practices including OWASP guidelines
- Vendor security assessments for all sub-processors handling personal data
- Incident response procedures and documented escalation paths
Incident Response & Breach Notification
In the event of a confirmed personal data breach, Tejasbyte will:
- Contain and assess the breach as promptly as possible
- Notify affected clients without undue delay and no later than 72 hours after becoming aware of a breach involving their data
- Provide clients with sufficient information to fulfil their own notification obligations to regulatory authorities and affected individuals
- Document the breach, its effects, and all remedial actions taken
- Conduct a post-incident review to prevent recurrence
Data Retention & Deletion
Tejasbyte retains data only as long as required to fulfil the purposes for which it was collected or to comply with legal obligations.
- Client project data: retained for the duration of the engagement plus up to 12 months unless instructed otherwise
- Source code and deliverables: returned or deleted upon project completion or client request
- Financial and contractual records: retained for 7 years in accordance with legal requirements
- Website enquiry data: retained for up to 3 years
- Employee and contractor data: retained as required by employment law
Upon termination of a service agreement, Tejasbyte will securely delete or return all client data within 30 days of the termination date, unless instructed otherwise in writing.
Sub-processors
Tejasbyte engages the following categories of sub-processors who may have access to personal or client data in the course of delivering services:
- Cloud infrastructure providers (e.g. AWS, Google Cloud, Azure) for hosting and compute
- Version control and project management tools (e.g. GitHub, Linear, Notion) for development workflows
- Communication platforms used in client engagements (e.g. Slack, Google Workspace)
- Transactional email providers (Resend) for service communications
- Analytics providers (e.g. Google Analytics) for website usage data
We will inform clients of any intended changes to sub-processors and provide the opportunity to object. Sub-processors are selected based on security standards and are bound by data processing agreements.
Cross-Border Data Transfers
Tejasbyte's operations span the United States and Nepal. Data may be transferred between these jurisdictions in the course of delivering services. We ensure that such transfers are governed by appropriate safeguards including:
- Standard contractual clauses where required by applicable data protection law
- Transfers to providers participating in recognised data protection frameworks
- Contractual protections between Tejasbyte entities and personnel
Client Data Responsibilities
Where clients share personal data with Tejasbyte for development, testing, or other purposes, clients acknowledge that:
- They are the data controller and are responsible for ensuring they have a lawful basis to share that data with Tejasbyte
- Production personal data should not be used for development or testing purposes without appropriate anonymisation or pseudonymisation
- Clients must inform Tejasbyte of any specific data handling requirements, applicable regulations (e.g. HIPAA, GDPR), or restrictions before engagement
- Clients are responsible for obtaining any consents required from their end users
Policy Governance
This Data Policy is reviewed at least annually and updated to reflect changes in our operations, legal obligations, or industry best practices. The most recent version is always available at www.tejasbyte.com/data-policy.
All Tejasbyte personnel and contractors are required to adhere to this policy as a condition of their engagement.
Contact
For questions or concerns about this Data Policy, data processing practices, or to submit a data subject request:
