BTB Dots
BitsToBug
Contact

BitsToBug Studios LLP

Privacy Policy

Effective date: 15 July 2026Last updated: 15 July 2026

1. Introduction

BitsToBug Studios LLP (“BitsToBug”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data we handle. This Privacy Policy explains how we collect, use, disclose, transfer, retain and safeguard personal data when you visit our website, contact us, apply for a role, or engage us for professional services.

This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made thereunder, and, where applicable, the European Union and United Kingdom General Data Protection Regulation.

2. Who we are

BitsToBug Studios LLP, a limited liability partnership incorporated under the Limited Liability Partnership Act, 2008, bearing LLPIN ACL-6665 and GSTIN 09ABEFB3028Q1Z4, having its registered office at 1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India, and operating from its principal place of business at Noida, Uttar Pradesh, India.

FieldDetail
Legal entityBitsToBug Studios LLP
LLPINACL-6665
GSTIN09ABEFB3028Q1Z4
Registered office1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India
Principal place of businessNoida, Uttar Pradesh, India
Websitehttps://www.bitstobug.com
General contactsupport@bitstobug.com
Grievance OfficerShreyansh Tiwari, shreyansh@bitstobug.com, +91 98894 33665

For personal data collected through our website and business operations, BitsToBug acts as the data fiduciary, also described as the data controller. Where we process personal data on behalf of a client under a services agreement, we act as a data processor and process such data only on that client's documented instructions.

3. Personal data we collect

3.1 Data you provide to us

  • Identity and contact data, including your name, business email address, telephone number, employer and job title, submitted through our contact forms, proposals or correspondence.
  • Recruitment data, including your curriculum vitae, education and employment history, portfolio links and any information contained in an application.
  • Engagement data, including project requirements, technical documentation and commercial correspondence exchanged during an engagement.

3.2 Data collected automatically

  • Technical data, including internet protocol address, browser type and version, device type, operating system, language settings and time zone.
  • Usage data, including pages viewed, referring website addresses, time spent on pages and interactions with our content.
  • Cookie data, as described in our Cookie Policy.

3.3 Data we do not seek

We do not intentionally collect special category or sensitive personal data through our website. Please do not submit health information, financial account credentials, government identifiers or similar sensitive data through our public forms.

3.4 Client data processed on instruction

In delivering services we may be granted access to systems or datasets controlled by our clients, which may contain personal data relating to their customers, patients, employees or citizens. We process such data strictly as a processor, under the applicable services agreement and data processing agreement, and never for our own purposes.

4. How we use personal data

PurposeExamples
Responding to enquiriesReplying to contact form submissions, scoping requirements, issuing proposals
Delivering servicesPerforming our contractual obligations, project communication, support and maintenance
RecruitmentAssessing applications, conducting interviews, maintaining a talent pipeline where you consent
Website operation and improvementEnsuring availability, diagnosing faults, analysing aggregate usage patterns
Security and fraud preventionDetecting, investigating and preventing misuse or unauthorised access
Marketing communicationsSending service updates where you have opted in, with an unsubscribe option in every message
Legal and regulatory complianceMeeting statutory obligations, responding to lawful requests, establishing or defending legal claims

5. Legal bases for processing

Where the GDPR applies, we rely on the following legal bases:

  • Contract: processing necessary to enter into or perform a contract with you or your organisation.
  • Legitimate interests: operating and securing our website, business development with corporate contacts, and improving our services, balanced against your rights and freedoms.
  • Consent: non-essential cookies and marketing communications. You may withdraw consent at any time.
  • Legal obligation: compliance with applicable law, regulation or lawful request.

Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent or for legitimate uses permitted under the Act. Consent notices are provided in clear and plain language, and consent may be withdrawn as easily as it was given.

6. Cookies

We use cookies and similar technologies to operate our website and understand how it is used. Full detail, including categories and durations, is set out in our Cookie Policy at https://www.bitstobug.com/cookie-policy. On your first visit you may accept or reject non-essential categories, and you may change your choice at any time through the cookie settings link in our footer.

7. How we share personal data

We do not sell personal data. We share it only as set out below, and only to the extent necessary.

  • Service providers and sub-processors: cloud hosting, email delivery, analytics, customer relationship management and similar vendors, engaged under written contracts imposing confidentiality and security obligations.
  • Professional advisers: auditors, accountants, insurers and legal counsel, bound by professional duties of confidentiality.
  • Corporate transactions: in connection with a merger, acquisition, restructuring or sale of assets, subject to equivalent protections.
  • Legal and regulatory: where required by applicable law, court order or a lawful request from a public authority.

A current list of material sub-processors is available on request from support@bitstobug.com.

8. International transfers

We serve clients in multiple jurisdictions. Personal data may therefore be transferred to, stored in, or accessed from countries other than your own, including India, where our engineering operations are based.

Where personal data is transferred out of the European Economic Area or the United Kingdom, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission or the United Kingdom International Data Transfer Agreement, together with supplementary technical and organisational measures where required. Where the Digital Personal Data Protection Act, 2023 applies, transfers are made in accordance with the Act and any restrictions notified by the Central Government.

For engagements requiring data residency within a specific jurisdiction, including on-premise or India-resident deployments, such requirements are addressed in the applicable services agreement.

9. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, contractual or reporting requirements.

CategoryRetention period
Website enquiries not converted24 months from last contact
Client engagement recordsDuration of the engagement plus 3 years
Recruitment applications12 months, or longer where you consent
Financial and statutory records8 years, as required under Indian law
Cookie and analytics dataUp to 26 months, as stated in the Cookie Policy
Server and security logs12 months

When personal data is no longer required, we securely delete it or irreversibly anonymise it.

10. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and, where appropriate, at rest; role based access control applying the principle of least privilege; secure software development practices including peer code review; logging, monitoring and audit trails; vendor due diligence; and employee confidentiality obligations and security training. Further detail is published at https://www.bitstobug.com/security.

No method of transmission or storage is completely secure. In the event of a personal data breach, we will notify the Data Protection Board of India, any other competent supervisory authority, and affected individuals where required by applicable law, without undue delay.

11. Your rights

Subject to applicable law and verification of your identity, you may exercise the following rights:

  • Access: obtain confirmation of whether we process your personal data and a copy of it.
  • Correction: have inaccurate or incomplete data corrected or completed.
  • Erasure: request deletion where the data is no longer necessary or consent is withdrawn.
  • Restriction and objection: restrict or object to certain processing, including direct marketing.
  • Portability: receive your data in a structured, commonly used and machine readable format.
  • Withdraw consent: withdraw consent at any time, without affecting processing carried out before withdrawal.
  • Nominate: under the Digital Personal Data Protection Act, 2023, nominate an individual to exercise your rights in the event of death or incapacity.
  • Complain: lodge a complaint with the Data Protection Board of India or your local supervisory authority.

To exercise any right, contact Shreyansh Tiwari at shreyansh@bitstobug.com. We will acknowledge your request within 24 hours and respond within 15 days, or such shorter period as applicable law requires. Where we process personal data as a processor on behalf of a client, we will refer your request to that client and support them in responding.

12. Children's data

Our website and services are directed at businesses and institutions and are not intended for children. We do not knowingly collect personal data of children as defined under applicable law, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, contact us and we will delete it promptly.

13. Third party links

Our website may link to third party websites, including those of our affiliated products such as Kallix. We are not responsible for the privacy practices or content of those websites. We encourage you to review their privacy notices.

14. Changes to this Policy

We may update this Policy from time to time. The current version is always published on this page with the last updated date shown above. Where changes are material, we will provide prominent notice on our website and, where required by law, seek your consent.

15. Grievance Officer and contact

In accordance with the Information Technology Act, 2000 and the rules made thereunder, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:

FieldDetail
NameShreyansh Tiwari
DesignationGrievance Officer and Data Protection Contact
EntityBitsToBug Studios LLP
Emailshreyansh@bitstobug.com
Telephone+91 98894 33665
Address1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India
AcknowledgementWithin 24 hours of receipt
ResolutionWithin 15 days of receipt

General enquiries may be sent to support@bitstobug.com.