Legal

Privacy Policy

How we collect, use and protect personal data — and what you can ask us to do with yours.

Note for the site owner: this is a working template covering the common obligations under UK/EU GDPR and India's DPDP Act 2023. Have it reviewed by a qualified lawyer against your actual data practices before you publish. Last updated 12 September 2026.

Who we are

Tech & Crafts Technologies Pvt. Ltd. (“TnC”, “we”, “us”) is a software development company registered in India, with its principal place of business at 4th Floor, Athulya Building, Infopark Phase I, Kakkanad, Kochi, Kerala 682042. For questions about this policy, write to hello@techandcrafts.com.

What we collect

Through this website we collect only what you give us and what is needed to run the site:

  • Enquiry details — name, email address, phone number, company, country, budget range and the message you write, when you submit the contact form.
  • Application details — your CV and covering note, if you email us about a role.
  • Technical data — IP address, browser type, referring page and pages viewed, recorded in server logs and analytics.
  • Cookies — a session cookie required for form security, plus analytics cookies if you consent. See our cookie policy.

We do not knowingly collect data from children, and we do not buy contact lists.

Why we use it, and the lawful basis

  • To reply to your enquiry — on the basis of steps taken at your request prior to entering a contract.
  • To provide services under a contract — where you become a client.
  • To keep the site secure and working — on the basis of our legitimate interest in preventing abuse.
  • To understand how the site is used — on the basis of your consent to analytics cookies.
  • To meet legal and accounting obligations — where the law requires us to keep records.

Client data we process on your behalf

When we build or support software for a client, we may process personal data belonging to that client's users. In that arrangement the client is the data controller and we act as a data processor under a written data processing agreement. We do not use client data for any purpose other than delivering the agreed services, we do not sell it, and we do not use it to train machine learning models unless the client has specifically instructed us to.

Who we share it with

We never sell personal data. We share it only with:

  • Service providers who help us operate — email delivery, cloud hosting, analytics — each under contract and processing only on our instructions.
  • Professional advisers such as accountants and lawyers, where required.
  • Authorities, where we are legally obliged to disclose.

International transfers

We are based in India and our infrastructure may be located in India, the EU, the UK, the US or other regions depending on the service. Where personal data originating in the UK or EEA is transferred to India, we rely on Standard Contractual Clauses together with appropriate technical and organisational safeguards. For client engagements we deploy into the region your own compliance position requires.

How long we keep it

  • Enquiries that do not become projects — 24 months, then deleted.
  • Client records — for the duration of the relationship plus the period required by Indian tax and company law, currently eight years for financial records.
  • Job applications — 12 months, unless you ask us to keep them longer.
  • Server logs — 90 days.

How we protect it

Encryption in transit and at rest, role-based access limited to staff who need it, multi-factor authentication on administrative systems, signed confidentiality undertakings from every employee, logged access to production systems, and a documented incident response process. No system is perfectly secure, but these are the controls we maintain and can evidence.

Your rights

Depending on where you are, you may have the right to:

  • Ask what personal data we hold about you and receive a copy.
  • Have inaccurate data corrected.
  • Have your data deleted where we have no continuing lawful basis to keep it.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, where consent was the basis.
  • Complain to a supervisory authority — the ICO in the UK, your national authority in the EEA, or the Data Protection Board in India.

To exercise any of these, email hello@techandcrafts.com. We respond within 30 days and will not charge you for a reasonable request.

Changes to this policy

If we change this policy materially we will update the date at the top and, where the change affects you directly, tell you by email. This version is effective from 12 September 2026.