Skip to content

Every engagement lists its scope, timeline and fixed fee before checkout

Techluminate
§Legal

Privacy Policy

What personal data Techluminate collects when you use this site or buy an engagement, why each item is needed, who else handles it, and what you can ask us to do with it.

Last updated · 17 September 2026

01Who this policy covers

This policy applies to everyone who visits Techluminate, creates an account, contacts us, submits a project brief or buys an engagement. It is written with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the reasonable security practices rules made under the Information Technology Act, 2000.

Two terms from the DPDP Act are used throughout. You are the Data Principal — the person the data relates to. We are the Data Fiduciary — the organisation that decides why and how your data is processed, and that is responsible for protecting it.

This policy does not cover websites we link to, third-party platforms you sign in to separately, or systems that belong to you and that we work inside during an engagement. Section 6 explains that last case.

02Who is responsible for your data

The Data Fiduciary is TECHLUMINATE SOLUTIONS PRIVATE LIMITED, PLOT NO 8- 3-323/1-12, Ameerpet X Road, Yellareddy Guda, Hyderabad, Hyderabad, Telangana, 500073., operating Techluminate.

Formal requests and complaints are handled by the Grievance Officer described in section 16. Each request is assigned to a named person from the moment it arrives.

03What we collect

We collect five categories of data, and nothing beyond what a technology services business needs.

  • Account data — name, email address, mobile number, company name where provided, and a one-way hash of your password. We never store your password in readable form, so neither we nor anyone who obtained the database could read it.
  • Billing data — billing name, address, city, state, PIN code and, where you supply it, your GSTIN. We need this to issue a compliant tax invoice.
  • Order data — the engagements bought, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
  • Project brief content — what you tell us so the work can be done: product and repository URLs, goals, the people involved, access notes and any other details you add. This is mainly commercial information, although it can include names and work email addresses.
  • Site and device data — IP address, browser and device type, pages viewed, referring source and approximate location, collected through analytics and server logs.

We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials. We do not ask for identifiers such as Aadhaar or PAN unless a specific legal requirement makes it necessary, and we would tell you why at the time.

04Why we collect it

Each purpose below is specific. We do not reuse data collected for one purpose for an unrelated one.

PurposeData used
Create, confirm and deliver your orderAccount, billing, order, brief
Issue a GST invoice and keep tax recordsBilling, order
Contact you about an order: confirmation, questions, handover, supportAccount, order
Plan and staff the workBrief, order
Handle a refund, dispute or grievanceOrder, billing, correspondence
Keep the site running, prevent fraud and diagnose faultsSite and device data
Understand, in aggregate, which pages are usefulSite and device data
Send occasional updates about our servicesName and email, only where you opted in

We do not build advertising profiles, run behavioural retargeting, or sell, rent or trade personal data.

05Consent and lawful basis

We rely on two grounds under the DPDP Act.

  • Consent — free, specific, informed and unambiguous, given when you submit a form, create an account, submit a brief or opt in to updates. Each request explains what the data is for before you provide it.
  • Legitimate uses — processing needed to perform the engagement you paid for, and processing required by law, such as tax record-keeping.

You may withdraw consent at any time, as easily as you gave it, by writing to the Grievance Officer. Withdrawal does not affect processing already carried out lawfully, and it does not remove records the law requires us to keep, but it stops further processing based on consent. If withdrawal would prevent us from completing an engagement you have paid for, we will tell you before acting.

Marketing consent is always separate. Declining it never affects an order, and every marketing email includes an unsubscribe link that we honour promptly.

06Your brief, and data inside your own systems

We can act in two different roles, and the distinction matters.

  • Your data, held by us. Account, billing, order and brief data is held in our systems, and we are the Data Fiduciary for it. The rest of this policy describes that processing.
  • Data about your users, held in your systems. Where an engagement requires us to work inside your repositories, databases or cloud accounts, you remain the Data Fiduciary and we act only on your documented instructions. Where such processing involves personal data, we agree a data processing agreement with you before that work starts, covering purpose limitation, security, sub-processing, breach notification and deletion.

By default we ask for anonymised, masked or synthetic data. Where access to live personal data cannot be avoided, it should be named, limited to what the work needs, time-bound and revoked at handover.

07Who processes it alongside us

We share personal data only with processors who help us run the business, only for the stated purpose, and only under contracts that require them to protect it. We list them by category because a supplier may change while the category and safeguards remain the same.

CategoryWhat it receivesWhy
Payment gatewayName, contact details, amount, order referenceTo take a UPI payment and to confirm or refund it
Email deliveryName, email address, message contentTo send order confirmations, handover notes and replies
Hosting and infrastructureEverything the site stores, at restTo run the website, database and backups
Website analyticsSite and device data, pseudonymousTo understand which pages are used and which are broken

Beyond these categories, data is shared with the people assigned to your engagement (limited to the brief and the access the work needs); with our accountants and auditors for statutory filings; and with a government authority, court or law enforcement agency where a valid legal process requires it. In that last case we ask for the demand in writing, disclose only what is legally required, and inform you unless we are prohibited from doing so.

No processor may use your data for its own purposes.

08Cross-border transfer

Some of our processors — for example email delivery, hosting and analytics providers — may operate infrastructure outside India, so some personal data may be processed abroad.

Where that happens, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, limit the transfer to what the purpose needs, and require the processor to protect the data to the standard this policy sets. If a restriction is notified, we will move the affected processing.

09How long we keep it

We keep data for as long as the purpose requires or the law demands, and then delete it or irreversibly anonymise it.

DataRetentionReason
Invoices, order and payment records8 financial yearsIncome-tax and GST record-keeping
Account profileWhile the account is open, then 90 daysSo an accidental deletion can be reversed
Project brief and delivery material12 months after handoverSo handover material can be re-sent on request
Support and grievance correspondence3 years from closureComplaint records under the e-commerce rules
Marketing consent and unsubscribesUntil you unsubscribe, plus 12 monthsProof that the unsubscribe was honoured
Server and access logs180 daysSecurity investigation and fault diagnosis
Analytics, in aggregate26 monthsYear-on-year comparison; no longer identifying

If you request erasure, we delete everything not covered by a statutory retention period above, and tell you what had to be kept and why.

10How we protect it

We apply reasonable security practices appropriate to the data we hold, including:

  • serving the site over HTTPS, so data in transit is encrypted;
  • storing passwords only as salted one-way hashes, which cannot be recovered — including by us;
  • protecting account forms against cross-site request forgery;
  • keeping payment credentials off our servers entirely — the payment gateway handles them;
  • limiting access to customer data to people who need it for their role;
  • asking clients not to send passwords or keys through the brief form, email or chat, and requesting sensitive credentials through a secure channel instead;
  • binding everyone who handles client data to confidentiality obligations.

No system is perfectly secure. If you believe you have found a security weakness in this site, please tell us through the contact details in section 16 and we will investigate promptly.

11Cookies and analytics

We use a small number of cookies and similar browser storage, in two groups.

  • Strictly necessary — session and security cookies that keep you signed in, keep your selection together between pages, and protect forms against cross-site request forgery. The site cannot work without them, so they do not require consent.
  • Analytics — used where analytics is enabled, to count page views and find broken journeys. They are pseudonymous and, where consent is required, run only after you give it.

The engagements you select before checkout are held in your own browser storage rather than on our servers, so clearing site data removes them. You can block or clear cookies in your browser settings at any time.

12Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access — a summary of the personal data we hold about you, how we use it, and the categories of processor it has been shared with;
  • Correction and completion — have inaccurate data corrected, incomplete data completed and outdated data updated;
  • Erasure — have data deleted once it is no longer needed for its purpose, subject to the statutory retention periods in section 9;
  • Withdraw consent — for any processing based on consent, as easily as it was given;
  • Nominate — appoint another person to exercise these rights on your behalf in the event of death or incapacity;
  • Grievance redressal — a readily available way to complain to us, answered within a published timeline, before approaching the Data Protection Board.

The Act also places duties on Data Principals: provide authentic information, do not impersonate anyone, and do not file false or frivolous complaints.

How to exercise a right. Write to our Grievance Officer at grievance@techluminate.com from the email address on your account, stating which right you wish to exercise. We may ask a few questions to verify your identity before acting. We respond within 30 days; if a request needs longer, we will tell you within those 30 days, with the reason and an expected date.

There is no charge for exercising these rights.

13Children and guardianship

Our engagements are sold to businesses and this site is not directed at children. We do not knowingly collect personal data from anyone under 18, and we do not track, profile or target advertising at children.

If you believe a child has given us personal data, tell us and we will delete it promptly. Where an account must be operated on behalf of a child, or of a person with a disability who has a lawful guardian, verifiable consent from the parent or guardian is required first, as the DPDP Act provides.

14Personal data breaches

If a personal data breach occurs, we will investigate and contain it, and notify the Data Protection Board of India and each affected Data Principal in the form and within the time the DPDP Act and its rules require.

Our notice to you will explain, in plain language, what happened, which data was involved, the likely consequences, the steps we have taken and what we recommend you do.

15Changes to this policy

We update this policy when our processing or the law changes. The date at the top always shows the current version. Material changes are highlighted on this page, and where a change requires fresh consent we will ask for it. Earlier versions are available on request.

16Contact and complaints

For any privacy question, data request or complaint:

Complaints are acknowledged within 48 hours and answered substantively within 15 days. The full escalation route, including external bodies you can approach, is on the Grievance Redressal page.

If you are not satisfied with our response, you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer. This policy is governed by the laws of India.

Next step

Bring the problem. Leave with a defined plan.

Pick the engagement that matches what you need, or tell us about the system you are working on and we will point you to the right starting place.