Security and data handling
The answers a procurement checklist asks for, in one place: where your data lives, who can reach it, how access ends, which third parties are involved, which laws apply, and what we do and do not certify. The legal version is the data processing agreement; this page is the plain one.
- Where your data lives
- In your own accounts — hosting, domain, analytics, repositories. We are an invited collaborator.
- Certifications
- None. We do not hold SOC 2 or ISO 27001 and do not claim to.
- Breach notification
- Without undue delay, and within 48 hours of becoming aware.
- Legal basis
- Processor under a written DPA; SCCs and the UK Addendum for EEA and UK data; India's DPDP Act 2023.
- NDA
- Available on request — yours or ours.
- Incident contact
- contact@thetechgenius.in
At a glance
How your data is handled on every engagement
Your data lives in your accounts
Hosting, domain, analytics, source repositories, payment gateway, Meta Business Manager — every account a project needs is created in your name, or transferred into it, before launch. We work inside them as an invited collaborator. Nothing you own routes through an account of ours.
Access is the least we need, for as long as we need it
Each person working on your project gets their own login, at the lowest permission level the work allows. Multi-factor authentication is on wherever the platform supports it. Credentials are shared through the platform's own invitation system, never pasted into a chat.
Offboarding is a checklist, confirmed in writing
At handover, or when an engagement ends, our access is removed from every account, you rotate any credential we ever held, and we confirm in writing that both are done and that any personal data we processed for you has been deleted or returned, as you choose.
Client environments are kept apart
One client's code, credentials and data never sit in the same environment as another's. Development happens against your repository and your staging environment, so there is no shared workspace to leak across.
Confidentiality, and an NDA if you want one
Everyone who touches your data is bound by a duty of confidentiality that survives the engagement. We sign a mutual NDA on request — yours if it is reasonable, ours if you prefer — and for agency partners a non-circumvention agreement before we see a client name.
Incidents are reported inside 48 hours
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 48 hours, with what you need to meet your own notification obligations. The contact is below.
Sub-processors
The third parties that may process personal data on our behalf as part of delivering your project. Which of them touch your data depends on what we build — a Shopify store involves Shopify; a WhatsApp flow involves Meta. The list is the same one in the DPA, and you get at least 30 days’ notice before anything is added or replaced, with the right to object on data-protection grounds.
- Cloudflare, Inc.
- hosting, content delivery and cookieless analytics (global edge network)
- Google LLC
- Google Sheets and Apps Script — contact-form enquiries and their email notification (US/EU)
- Google LLC
- analytics and search reporting (US/EU)
- Meta Platforms
- WhatsApp Business Platform, where your project uses it
- Shopify Inc.
- where your project is built on Shopify
- AI model providers
- where an AI feature is part of your project, named in the statement of work
Which laws apply, and how we meet them
GDPR and UK GDPR
Where we process personal data for a client in the EEA or the UK, we act as a processor under a written data processing agreement. India has no EU or UK adequacy decision, so transfers are made under the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, with a transfer risk assessment on request. We say this plainly rather than wait for your legal team to ask.
India's DPDP Act 2023
As an Indian firm we are subject to the Digital Personal Data Protection Act. Where we are the controller — our own enquiries and client records — our privacy policy sets out what we hold, for how long, and the rights you have, including the right to nominate someone to exercise them for you.
Your instructions govern
We process personal data only on your documented instructions — the statement of work and anything you put in writing afterwards. If an instruction would breach data-protection law, we tell you and may pause that processing until it is resolved.
Deletion, return and audit
On termination you choose whether the personal data we hold for you is deleted or returned, and we confirm in writing when it is done. We make available what is reasonably needed to demonstrate compliance and allow audits on reasonable written notice.
Our own handling of data as a controller is in the privacy policy; the processor terms are in the data processing agreement.
Certifications
We do not hold SOC 2 or ISO 27001
We state that in its own heading because a procurement form usually asks in its own box. We have not been audited against either standard and we do not describe our practices as “SOC 2 aligned” or “ISO-ready”, which would imply an assurance nobody has given. What you get instead is the set of practices above, written down, and the right to audit them on reasonable notice. If your procurement process requires a certified vendor, we are probably not the right choice for that engagement, and we would rather say so at the start than at the end.
What you can verify today: our legal name, THE TECH GENIUS DIGITAL MARKETING STORE, and our GST registration, 23BERPB1541P1ZD, on the Indian government portal.
Reporting a security concern
Suspected breach, exposed credential, or a question your security team needs answered before signing — email contact@thetechgenius.in and put “Security” in the subject line.