Privacy Policy
What personal data Techluminate collects when you use this site or buy an engagement, why each item is needed, who else handles it, and what you can ask us to do with it.
01Who this policy covers
This policy applies to everyone who visits Techluminate, creates an account, contacts us, submits a project brief or buys an engagement. It is written with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the reasonable security practices rules made under the Information Technology Act, 2000.
Two terms from the DPDP Act are used throughout. You are the Data Principal — the person the data relates to. We are the Data Fiduciary — the organisation that decides why and how your data is processed, and that is responsible for protecting it.
This policy does not cover websites we link to, third-party platforms you sign in to separately, or systems that belong to you and that we work inside during an engagement. Section 6 explains that last case.
02Who is responsible for your data
The Data Fiduciary is TECHLUMINATE SOLUTIONS PRIVATE LIMITED, PLOT NO 8- 3-323/1-12, Ameerpet X Road, Yellareddy Guda, Hyderabad, Hyderabad, Telangana, 500073., operating Techluminate.
Formal requests and complaints are handled by the Grievance Officer described in section 16. Each request is assigned to a named person from the moment it arrives.
03What we collect
We collect five categories of data, and nothing beyond what a technology services business needs.
- Account data — name, email address, mobile number, company name where provided, and a one-way hash of your password. We never store your password in readable form, so neither we nor anyone who obtained the database could read it.
- Billing data — billing name, address, city, state, PIN code and, where you supply it, your GSTIN. We need this to issue a compliant tax invoice.
- Order data — the engagements bought, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
- Project brief content — what you tell us so the work can be done: product and repository URLs, goals, the people involved, access notes and any other details you add. This is mainly commercial information, although it can include names and work email addresses.
- Site and device data — IP address, browser and device type, pages viewed, referring source and approximate location, collected through analytics and server logs.
We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials. We do not ask for identifiers such as Aadhaar or PAN unless a specific legal requirement makes it necessary, and we would tell you why at the time.
04Why we collect it
Each purpose below is specific. We do not reuse data collected for one purpose for an unrelated one.
| Purpose | Data used |
|---|---|
| Create, confirm and deliver your order | Account, billing, order, brief |
| Issue a GST invoice and keep tax records | Billing, order |
| Contact you about an order: confirmation, questions, handover, support | Account, order |
| Plan and staff the work | Brief, order |
| Handle a refund, dispute or grievance | Order, billing, correspondence |
| Keep the site running, prevent fraud and diagnose faults | Site and device data |
| Understand, in aggregate, which pages are useful | Site and device data |
| Send occasional updates about our services | Name and email, only where you opted in |
We do not build advertising profiles, run behavioural retargeting, or sell, rent or trade personal data.
05Consent and lawful basis
We rely on two grounds under the DPDP Act.
- Consent — free, specific, informed and unambiguous, given when you submit a form, create an account, submit a brief or opt in to updates. Each request explains what the data is for before you provide it.
- Legitimate uses — processing needed to perform the engagement you paid for, and processing required by law, such as tax record-keeping.
You may withdraw consent at any time, as easily as you gave it, by writing to the Grievance Officer. Withdrawal does not affect processing already carried out lawfully, and it does not remove records the law requires us to keep, but it stops further processing based on consent. If withdrawal would prevent us from completing an engagement you have paid for, we will tell you before acting.
Marketing consent is always separate. Declining it never affects an order, and every marketing email includes an unsubscribe link that we honour promptly.
06Your brief, and data inside your own systems
We can act in two different roles, and the distinction matters.
- Your data, held by us. Account, billing, order and brief data is held in our systems, and we are the Data Fiduciary for it. The rest of this policy describes that processing.
- Data about your users, held in your systems. Where an engagement requires us to work inside your repositories, databases or cloud accounts, you remain the Data Fiduciary and we act only on your documented instructions. Where such processing involves personal data, we agree a data processing agreement with you before that work starts, covering purpose limitation, security, sub-processing, breach notification and deletion.
By default we ask for anonymised, masked or synthetic data. Where access to live personal data cannot be avoided, it should be named, limited to what the work needs, time-bound and revoked at handover.
08Cross-border transfer
Some of our processors — for example email delivery, hosting and analytics providers — may operate infrastructure outside India, so some personal data may be processed abroad.
Where that happens, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, limit the transfer to what the purpose needs, and require the processor to protect the data to the standard this policy sets. If a restriction is notified, we will move the affected processing.
09How long we keep it
We keep data for as long as the purpose requires or the law demands, and then delete it or irreversibly anonymise it.
| Data | Retention | Reason |
|---|---|---|
| Invoices, order and payment records | 8 financial years | Income-tax and GST record-keeping |
| Account profile | While the account is open, then 90 days | So an accidental deletion can be reversed |
| Project brief and delivery material | 12 months after handover | So handover material can be re-sent on request |
| Support and grievance correspondence | 3 years from closure | Complaint records under the e-commerce rules |
| Marketing consent and unsubscribes | Until you unsubscribe, plus 12 months | Proof that the unsubscribe was honoured |
| Server and access logs | 180 days | Security investigation and fault diagnosis |
| Analytics, in aggregate | 26 months | Year-on-year comparison; no longer identifying |
If you request erasure, we delete everything not covered by a statutory retention period above, and tell you what had to be kept and why.
10How we protect it
We apply reasonable security practices appropriate to the data we hold, including:
- serving the site over HTTPS, so data in transit is encrypted;
- storing passwords only as salted one-way hashes, which cannot be recovered — including by us;
- protecting account forms against cross-site request forgery;
- keeping payment credentials off our servers entirely — the payment gateway handles them;
- limiting access to customer data to people who need it for their role;
- asking clients not to send passwords or keys through the brief form, email or chat, and requesting sensitive credentials through a secure channel instead;
- binding everyone who handles client data to confidentiality obligations.
No system is perfectly secure. If you believe you have found a security weakness in this site, please tell us through the contact details in section 16 and we will investigate promptly.
12Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Access — a summary of the personal data we hold about you, how we use it, and the categories of processor it has been shared with;
- Correction and completion — have inaccurate data corrected, incomplete data completed and outdated data updated;
- Erasure — have data deleted once it is no longer needed for its purpose, subject to the statutory retention periods in section 9;
- Withdraw consent — for any processing based on consent, as easily as it was given;
- Nominate — appoint another person to exercise these rights on your behalf in the event of death or incapacity;
- Grievance redressal — a readily available way to complain to us, answered within a published timeline, before approaching the Data Protection Board.
The Act also places duties on Data Principals: provide authentic information, do not impersonate anyone, and do not file false or frivolous complaints.
How to exercise a right. Write to our Grievance Officer at grievance@techluminate.com from the email address on your account, stating which right you wish to exercise. We may ask a few questions to verify your identity before acting. We respond within 30 days; if a request needs longer, we will tell you within those 30 days, with the reason and an expected date.
There is no charge for exercising these rights.
13Children and guardianship
Our engagements are sold to businesses and this site is not directed at children. We do not knowingly collect personal data from anyone under 18, and we do not track, profile or target advertising at children.
If you believe a child has given us personal data, tell us and we will delete it promptly. Where an account must be operated on behalf of a child, or of a person with a disability who has a lawful guardian, verifiable consent from the parent or guardian is required first, as the DPDP Act provides.
14Personal data breaches
If a personal data breach occurs, we will investigate and contain it, and notify the Data Protection Board of India and each affected Data Principal in the form and within the time the DPDP Act and its rules require.
Our notice to you will explain, in plain language, what happened, which data was involved, the likely consequences, the steps we have taken and what we recommend you do.
15Changes to this policy
We update this policy when our processing or the law changes. The date at the top always shows the current version. Material changes are highlighted on this page, and where a change requires fresh consent we will ask for it. Earlier versions are available on request.
16Contact and complaints
For any privacy question, data request or complaint:
- Grievance Officer: grievance@techluminate.com · 8121708636
- General support: care@techluminate.com
- By post: PLOT NO 8- 3-323/1-12, Ameerpet X Road, Yellareddy Guda, Hyderabad, Hyderabad, Telangana, 500073.
Complaints are acknowledged within 48 hours and answered substantively within 15 days. The full escalation route, including external bodies you can approach, is on the Grievance Redressal page.
If you are not satisfied with our response, you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer. This policy is governed by the laws of India.