Corporate Privacy Policy
Effective Date: January 1, 2026 • Last Revised: September 24, 2026 • Document Ref: IT-POL-PRIV-2026-V2
Executive Data Protection Summary
Infi Technology (“Company,” “we,” “our,” or “us”) operates an enterprise technology consulting practice and software engineering firm. We adhere strictly to international data privacy frameworks including the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the California Consumer Privacy Act / CPRA, and the Digital Personal Data Protection Act (DPDPA 2023 of India). We never sell, rent, or trade your personal data to third-party marketing companies.
1. Scope & Legal Controller Information
This Privacy Policy applies to all personal information collected, processed, and stored when you visit or interact with our primary web domain (https://www.infitechnology.com), submit project consultation inquiries, initiate support tickets, or communicate with our technical engineering desks.
2. Categories of Personal Data We Collect
We collect personal information through two main channels: direct submission by users and automated technical data logging.
A. Information Provided Directly by You
- Identity & Professional Contact Details: Full Name, Business Email Address, Corporate Company Name, Telephone Number.
- Project Requirements & Communications: Selected service interest, project description, target timeline, technical specifications, and files uploaded via consultation forms.
- Billing & Commercial Records: Tax registration numbers, billing address, and invoice transaction details generated during active client SOW engagements.
B. Automated Technical & Telemetry Data
- Network & Device Identifiers: Anonymized Internet Protocol (IP) address, browser family and version, operating system, device class, time zone setting, and language preferences.
- Interaction Telemetry: Uniform Resource Locators (URLs) visited, clickstream data, page response latency, download errors, and duration of page visits collected via Google Analytics 4 (Measurement ID:
G-HX4GVWR539).
3. Legal Bases for Data Processing (GDPR Art. 6)
Under applicable data privacy laws, we rely on the following lawful grounds to process your personal data:
Processing necessary to evaluate consultation inquiries, draft proposals, and execute Master Services Agreements (MSAs).
Optimizing website performance, securing our network against DDoS attacks, and analyzing visitor engagement patterns.
Optional analytical cookies, opt-in newsletter communications, or explicit permission given for technical audits.
Compliance with statutory financial record-keeping, tax audits, or law enforcement disclosure demands.
4. Cookies & Web Analytics Governance
Our website uses first-party and third-party cookies to ensure essential site navigation and measure aggregated visitor telemetry. We utilize Google Analytics 4 (G-HX4GVWR539) configured with IP anonymization enabled.
You can configure your browser settings to refuse all non-essential cookies or notify you when a cookie is sent. Disabling essential cookies may impair website navigation.
5. Third-Party Sub-Processors & Data Sharing
We do not sell, rent, or trade your personal data. We disclose information to vetted third-party sub-processors only to the extent necessary to maintain cloud hosting, deliver emails, process payments, or maintain cybersecurity:
| Sub-Processor | Purpose / Category | Data Location |
|---|---|---|
| Vercel / AWS Cloud Infrastructure | Edge CDN Hosting & Server Administration | United States / Global Edge |
| Google Analytics (GA4) | Aggregated Web Telemetry Analytics | United States |
| Infi Technology Contact API Gateway | Public Form Ingestion & Consultation Routing | India / Dedicated Datacenter |
6. International Data Transfers
Your personal data may be transferred to and processed on servers located outside of your state or country. When transferring data internationally from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on EU Standard Contractual Clauses (SCCs) and robust cryptographic encryption safeguards to ensure an equivalent level of protection.
7. Data Security & Technical Safeguards
Infi Technology maintains rigorous administrative, technical, and physical security measures aligned with ISO 27001 standards:
- In-Transit Encryption: All web traffic and form submissions are transmitted using TLS 1.3 cryptographic protocols with modern cipher suites.
- At-Rest Encryption: Database records and backups are encrypted using AES-256 standard encryption keys.
- Access Control: Granular Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) enforce strict data isolation.
- Vulnerability Audits: Regular automated security scanning and annual third-party penetration testing.
8. Data Retention & Archival Schedule
We retain personal data only for the period necessary to fulfill the original collection purpose or comply with legal obligations:
- General Consultation Inquiries: Retained for 24 months from the date of last communication.
- Client Commercial & SOW Records: Retained for the active duration of the contract plus 7 years to satisfy statutory tax and financial audit rules.
- Web Analytics Telemetry: GA4 event data is automatically purged after 14 months.
9. Your Privacy Rights & Data Subject Requests
Depending on your jurisdiction (e.g., GDPR, CCPA, DPDPA), you possess specific legal rights regarding your personal data:
To exercise any of these rights, please submit a Verifiable Data Subject Request (VDSR) to our DPO at [email protected]. We will acknowledge receipt within 48 hours and provide a full response within 30 days.
10. Policy Updates & Governing Law
We reserve the right to update this Privacy Policy periodically to reflect technological changes, new service offerings, or evolving privacy legislation. Revisions will be posted on this page with an updated “Last Revised” timestamp.
This Privacy Policy is governed by and construed under the laws of India, with primary jurisdiction vested in the courts of Udaipur, Rajasthan, India.
