Legal & Compliance Document

Client Privacy & Data Protection Policy

Effective Date: January 1, 2026Last Revised: July 2026 · Version 3.5

At a Glance

Core privacy commitments for all client engagements

  • Zero Telemetry & Code RetentionNo telemetry or code retention on non-disclosure projects
  • Global Standards AlignmentAligned with GDPR, CCPA, and ISO/IEC 27001 practices
  • 100% IP OwnershipClient retains 100% IP ownership of delivered source code
  • End-to-End EncryptionData encrypted in transit (TLS 1.3) and at rest (AES-256)

1. Scope & Applicability

Team Unibrains is a software engineering consultancy. This policy explains how we collect, store, process, and protect information from clients, prospective partners, and visitors to our digital channels, project portals, and engineering platforms.

This policy applies to our offices and operations in India and Germany, and to any personal data we process on behalf of clients under an active engagement.

2. Source Code & Client Data Protection

We maintain strict data segregation across engagements:

  • Client repositories, staging databases, API keys, and architectural documentation are held in isolated, zero-trust cloud workspaces, scoped per project.
  • We do not use client codebase assets to train AI models or code-completion tools without explicit written authorization.
  • Access to client environments is limited to the assigned engineering team and logged.
  • On engagement completion or termination, client data and credentials are deleted or returned per the retention schedule in Section 6, unless a legal or contractual obligation requires longer retention.

3. Information We Collect

• Professional identity data

Name, business email, company/organization, job title, and phone number, collected when you submit a project brief, request a consultation, or engage with our sales team.

• Technical logs & metrics

IP address, browser type, operating system, device information, and session timestamps, collected for site performance monitoring and security purposes.

• Client project data

Code, credentials, and technical documentation you provide us to deliver the engagement, handled per Section 2.

We do not sell personal data, and we do not collect data from anyone we know to be under 16.

4. How We Use Information & Legal Basis

We process personal data to: respond to inquiries and provide quotes, deliver contracted engineering services, maintain platform security, and meet legal/tax obligations. Where GDPR applies, our legal bases are: performance of a contract, our legitimate interests (security, service improvement), and consent where specifically requested.

5. Sharing & Cross-Border Transfers

We do not sell client or visitor data. We may share data with:

  • Subprocessors who support our operations (e.g., hosting, communication, and payment tools), bound by contractual confidentiality and data protection obligations.
  • Authorities, where required by law.

Given our operations across India and Germany (and any data transferred to/from the United States), international transfers are made under appropriate safeguards, such as Standard Contractual Clauses, where required by GDPR.

6. Data Retention

We retain personal data only as long as needed for the purposes above, or as required by law/contract. Client project data is retained per the schedule agreed in the applicable SOW, and deleted or returned within [X] days of engagement completion unless otherwise agreed.

7. Your Rights (GDPR & CCPA)

Depending on your location, you may have the right to:

  • Access, correct, or export your personal data
  • Request deletion ("right to be forgotten")
  • Object to or restrict certain processing
  • Opt out of the sale/sharing of personal information (CCPA) - note: we do not sell personal data
  • Lodge a complaint with your local data protection authority

To exercise these rights, contact us using the details in Section 9. We will respond within the timeframe required by applicable law (generally 30 days under GDPR, 45 days under CCPA).

8. Security Measures

We use TLS 1.3 for data in transit and AES-256 for data at rest, apply zero-trust access controls to client workspaces, and follow practices aligned with ISO/IEC 27001. In the event of a data breach affecting personal data, we will notify affected clients and, where legally required, relevant authorities, without undue delay.

9. Data Protection Contact

For privacy inquiries, audit requests, or data deletion requests, contact:

10. Changes to This Policy

We may update this policy periodically; material changes will be reflected in the "Last Revised" date above and, where required, communicated directly to active clients.

Have questions about our privacy framework?

Schedule a confidential consultation with our security engineering lead.