BitsToBug Studios LLP
Privacy Policy
1. Introduction
BitsToBug Studios LLP (“BitsToBug”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data we handle. This Privacy Policy explains how we collect, use, disclose, transfer, retain and safeguard personal data when you visit our website, contact us, apply for a role, or engage us for professional services.
This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made thereunder, and, where applicable, the European Union and United Kingdom General Data Protection Regulation.
2. Who we are
BitsToBug Studios LLP, a limited liability partnership incorporated under the Limited Liability Partnership Act, 2008, bearing LLPIN ACL-6665 and GSTIN 09ABEFB3028Q1Z4, having its registered office at 1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India, and operating from its principal place of business at Noida, Uttar Pradesh, India.
| Field | Detail |
|---|---|
| Legal entity | BitsToBug Studios LLP |
| LLPIN | ACL-6665 |
| GSTIN | 09ABEFB3028Q1Z4 |
| Registered office | 1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India |
| Principal place of business | Noida, Uttar Pradesh, India |
| Website | https://www.bitstobug.com |
| General contact | support@bitstobug.com |
| Grievance Officer | Shreyansh Tiwari, shreyansh@bitstobug.com, +91 98894 33665 |
For personal data collected through our website and business operations, BitsToBug acts as the data fiduciary, also described as the data controller. Where we process personal data on behalf of a client under a services agreement, we act as a data processor and process such data only on that client's documented instructions.
3. Personal data we collect
3.1 Data you provide to us
- Identity and contact data, including your name, business email address, telephone number, employer and job title, submitted through our contact forms, proposals or correspondence.
- Recruitment data, including your curriculum vitae, education and employment history, portfolio links and any information contained in an application.
- Engagement data, including project requirements, technical documentation and commercial correspondence exchanged during an engagement.
3.2 Data collected automatically
- Technical data, including internet protocol address, browser type and version, device type, operating system, language settings and time zone.
- Usage data, including pages viewed, referring website addresses, time spent on pages and interactions with our content.
- Cookie data, as described in our Cookie Policy.
3.3 Data we do not seek
We do not intentionally collect special category or sensitive personal data through our website. Please do not submit health information, financial account credentials, government identifiers or similar sensitive data through our public forms.
3.4 Client data processed on instruction
In delivering services we may be granted access to systems or datasets controlled by our clients, which may contain personal data relating to their customers, patients, employees or citizens. We process such data strictly as a processor, under the applicable services agreement and data processing agreement, and never for our own purposes.
4. How we use personal data
| Purpose | Examples |
|---|---|
| Responding to enquiries | Replying to contact form submissions, scoping requirements, issuing proposals |
| Delivering services | Performing our contractual obligations, project communication, support and maintenance |
| Recruitment | Assessing applications, conducting interviews, maintaining a talent pipeline where you consent |
| Website operation and improvement | Ensuring availability, diagnosing faults, analysing aggregate usage patterns |
| Security and fraud prevention | Detecting, investigating and preventing misuse or unauthorised access |
| Marketing communications | Sending service updates where you have opted in, with an unsubscribe option in every message |
| Legal and regulatory compliance | Meeting statutory obligations, responding to lawful requests, establishing or defending legal claims |
5. Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
- Contract: processing necessary to enter into or perform a contract with you or your organisation.
- Legitimate interests: operating and securing our website, business development with corporate contacts, and improving our services, balanced against your rights and freedoms.
- Consent: non-essential cookies and marketing communications. You may withdraw consent at any time.
- Legal obligation: compliance with applicable law, regulation or lawful request.
Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent or for legitimate uses permitted under the Act. Consent notices are provided in clear and plain language, and consent may be withdrawn as easily as it was given.
6. Cookies
We use cookies and similar technologies to operate our website and understand how it is used. Full detail, including categories and durations, is set out in our Cookie Policy at https://www.bitstobug.com/cookie-policy. On your first visit you may accept or reject non-essential categories, and you may change your choice at any time through the cookie settings link in our footer.
7. How we share personal data
We do not sell personal data. We share it only as set out below, and only to the extent necessary.
- Service providers and sub-processors: cloud hosting, email delivery, analytics, customer relationship management and similar vendors, engaged under written contracts imposing confidentiality and security obligations.
- Professional advisers: auditors, accountants, insurers and legal counsel, bound by professional duties of confidentiality.
- Corporate transactions: in connection with a merger, acquisition, restructuring or sale of assets, subject to equivalent protections.
- Legal and regulatory: where required by applicable law, court order or a lawful request from a public authority.
A current list of material sub-processors is available on request from support@bitstobug.com.
8. International transfers
We serve clients in multiple jurisdictions. Personal data may therefore be transferred to, stored in, or accessed from countries other than your own, including India, where our engineering operations are based.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission or the United Kingdom International Data Transfer Agreement, together with supplementary technical and organisational measures where required. Where the Digital Personal Data Protection Act, 2023 applies, transfers are made in accordance with the Act and any restrictions notified by the Central Government.
For engagements requiring data residency within a specific jurisdiction, including on-premise or India-resident deployments, such requirements are addressed in the applicable services agreement.
9. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, contractual or reporting requirements.
| Category | Retention period |
|---|---|
| Website enquiries not converted | 24 months from last contact |
| Client engagement records | Duration of the engagement plus 3 years |
| Recruitment applications | 12 months, or longer where you consent |
| Financial and statutory records | 8 years, as required under Indian law |
| Cookie and analytics data | Up to 26 months, as stated in the Cookie Policy |
| Server and security logs | 12 months |
When personal data is no longer required, we securely delete it or irreversibly anonymise it.
10. Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and, where appropriate, at rest; role based access control applying the principle of least privilege; secure software development practices including peer code review; logging, monitoring and audit trails; vendor due diligence; and employee confidentiality obligations and security training. Further detail is published at https://www.bitstobug.com/security.
No method of transmission or storage is completely secure. In the event of a personal data breach, we will notify the Data Protection Board of India, any other competent supervisory authority, and affected individuals where required by applicable law, without undue delay.
11. Your rights
Subject to applicable law and verification of your identity, you may exercise the following rights:
- Access: obtain confirmation of whether we process your personal data and a copy of it.
- Correction: have inaccurate or incomplete data corrected or completed.
- Erasure: request deletion where the data is no longer necessary or consent is withdrawn.
- Restriction and objection: restrict or object to certain processing, including direct marketing.
- Portability: receive your data in a structured, commonly used and machine readable format.
- Withdraw consent: withdraw consent at any time, without affecting processing carried out before withdrawal.
- Nominate: under the Digital Personal Data Protection Act, 2023, nominate an individual to exercise your rights in the event of death or incapacity.
- Complain: lodge a complaint with the Data Protection Board of India or your local supervisory authority.
To exercise any right, contact Shreyansh Tiwari at shreyansh@bitstobug.com. We will acknowledge your request within 24 hours and respond within 15 days, or such shorter period as applicable law requires. Where we process personal data as a processor on behalf of a client, we will refer your request to that client and support them in responding.
12. Children's data
Our website and services are directed at businesses and institutions and are not intended for children. We do not knowingly collect personal data of children as defined under applicable law, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, contact us and we will delete it promptly.
13. Third party links
Our website may link to third party websites, including those of our affiliated products such as Kallix. We are not responsible for the privacy practices or content of those websites. We encourage you to review their privacy notices.
14. Changes to this Policy
We may update this Policy from time to time. The current version is always published on this page with the last updated date shown above. Where changes are material, we will provide prominent notice on our website and, where required by law, seek your consent.
15. Grievance Officer and contact
In accordance with the Information Technology Act, 2000 and the rules made thereunder, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:
| Field | Detail |
|---|---|
| Name | Shreyansh Tiwari |
| Designation | Grievance Officer and Data Protection Contact |
| Entity | BitsToBug Studios LLP |
| shreyansh@bitstobug.com | |
| Telephone | +91 98894 33665 |
| Address | 1st Floor, E-137, Panki Road, Near Rotomac Factory, Kanpur Nagar, Uttar Pradesh 208020, India |
| Acknowledgement | Within 24 hours of receipt |
| Resolution | Within 15 days of receipt |
General enquiries may be sent to support@bitstobug.com.