How we collect, use, and protect personal data. Compliance is our own discipline — we hold ourselves to the standard we build for clients.
The controller responsible for personal data processed through this website is:
| Controller | Bitbase India Private Limited Prestige Tech Park, Outer Ring Road Bengaluru 560103, India |
| General contact | mail@bitbasegroup.in |
| Data Protection Officer | Sameer Iyer, Head of Compliance |
| DPO contact | mail@bitbasegroup.in |
Where processing is carried out jointly with our parent, bbg bitbase group GmbH, the responsibilities of each party are set out in an intra-group arrangement. You may exercise your rights with either entity.
We ask for what a request actually requires, and nothing more.
We never sell, rent, or trade personal data to third parties.
This site runs no advertising pixels or cross-site trackers.
Ask us to erase your data and we will, subject to legal retention duties.
When you visit this website, our hosting provider automatically records technical data: IP address, date and time of the request, the page requested, referrer URL, browser type and version, and operating system. This is necessary to deliver the site and to detect and defend against attacks.
If you use the start a project form, we collect your name, job title, company, industry, work email, optional phone number, country, how you found us, and the details you give us about the project — scope, budget range, timeline, engagement model, and any free text.
If you book an appointment, we collect your name, work email, company, optional phone number, any additional attendee addresses you supply, your selected meeting type, host, date, time, time zone, and your agenda notes. This data is written to the relevant Bitbase staff calendar in Microsoft 365 in order to create the meeting.
If you apply for a role, we collect your name, contact details, years of experience, notice period, portfolio or profile links, your CV, and your covering message. Special category data is never requested; please do not include it.
If you email us, we process the content of your message and your contact details in order to reply and to keep a record of the exchange.
Where the GDPR applies, we rely on the following legal bases:
| Puropse | Legal basis |
|---|---|
| Delivering and securing this website | Legitimate interests |
| Scheduling and holding an appointment | Pre-contractual steps |
| Scheduling and holding an appointment | Pre-contractual steps |
| Assessing a job application | Pre-employment |
| Keeping a talent pool after a rejection | Consent |
| Meeting statutory record-keeping duties | Legal obligation |
For users in India, the equivalent processing is carried out in accordance with the Digital Personal Data Protection Act, 2023, on the basis of your consent or a legitimate use as defined in that Act.
We use a small number of vetted providers, each bound by a data processing agreement:
| Microsoft 365 | Email, Outlook Calendar, Teams meetings, and Bookings — used to schedule and hold appointments and to correspond with you. |
| Hosting provider | Serves this website and retains server logs on our behalf. |
| Applicant tracking | Stores and manages job applications for the duration of a hiring process. |
| bbg bitbase group | Group entities may receive enquiry data where the relevant expertise sits outside India. |
Bitbase operates in India and the European Union, so personal data may be transferred between the two. Microsoft 365 data for our tenant is held in EU and Indian regions.
Transfers out of the EEA are covered by the European Commission's Standard Contractual Clauses, together with supplementary technical measures including encryption in transit and at rest, and access controls scoped to named staff.
| Server logs | 30 days |
| Project enquiries | 24 months from last contact |
| Appointment records | 12 months after the meeting |
| Unsuccessful applications | 6 months, or 24 with consent |
| Contractual & tax records | As required by statute |
Subject to the applicable law, you have the right to:
To exercise any of these, write to mail@bitbasegroup.in. We respond within one month, and will tell you if we need longer.
This website sets only cookies that are strictly necessary for it to function — for example, remembering your consent choice and maintaining state while you complete a form. No consent is required for these.
We set no advertising, profiling, or cross-site tracking cookies. If we later introduce optional analytics, it will be behind an explicit opt-in and documented here first.
We run an information security management system aligned to ISO 27001. Measures include TLS encryption in transit, encryption at rest, role-based access under least privilege, multi-factor authentication on all staff accounts, logging and monitoring, and regular review of processors.
Suspected vulnerabilities can be reported in confidence to mail@bitbasegroup.in. We acknowledge reports within two business days.
We update this policy when our processing changes or the law requires it. The version in force is always the one published here.