Data protection

Privacy policy

How we collect, use, and protect personal data. Compliance is our own discipline — we hold ourselves to the standard we build for clients.

Privacy policy

Controller & Data Protection Officer

The controller responsible for personal data processed through this website is:

ControllerBitbase India Private Limited
Prestige Tech Park, Outer Ring Road
Bengaluru 560103, India
General contactmail@bitbasegroup.in
Data Protection OfficerSameer Iyer, Head of Compliance
DPO contactmail@bitbasegroup.in

Where processing is carried out jointly with our parent, bbg bitbase group GmbH, the responsibilities of each party are set out in an intra-group arrangement. You may exercise your rights with either entity.

Our principles

Data minimisation

We ask for what a request actually requires, and nothing more.

No sale of data

We never sell, rent, or trade personal data to third parties.

No ad tracking

This site runs no advertising pixels or cross-site trackers.

Deletion on request

Ask us to erase your data and we will, subject to legal retention duties.

What we collect

Server log data

When you visit this website, our hosting provider automatically records technical data: IP address, date and time of the request, the page requested, referrer URL, browser type and version, and operating system. This is necessary to deliver the site and to detect and defend against attacks.

Project enquiries

If you use the start a project form, we collect your name, job title, company, industry, work email, optional phone number, country, how you found us, and the details you give us about the project — scope, budget range, timeline, engagement model, and any free text.

Appointment bookings

If you book an appointment, we collect your name, work email, company, optional phone number, any additional attendee addresses you supply, your selected meeting type, host, date, time, time zone, and your agenda notes. This data is written to the relevant Bitbase staff calendar in Microsoft 365 in order to create the meeting.

Job applications

If you apply for a role, we collect your name, contact details, years of experience, notice period, portfolio or profile links, your CV, and your covering message. Special category data is never requested; please do not include it.

Email correspondence

If you email us, we process the content of your message and your contact details in order to reply and to keep a record of the exchange.
 

Processors & recipients

We use a small number of vetted providers, each bound by a data processing agreement:

Microsoft 365Email, Outlook Calendar, Teams meetings, and Bookings — used to schedule and hold appointments and to correspond with you.
Hosting providerServes this website and retains server logs on our behalf.
Applicant trackingStores and manages job applications for the duration of a hiring process.
bbg bitbase groupGroup entities may receive enquiry data where the relevant expertise sits outside India.
We also disclose data where we are legally required to do so, or where it is necessary to establish, exercise, or defend legal claims.

International transfers

Bitbase operates in India and the European Union, so personal data may be transferred between the two. Microsoft 365 data for our tenant is held in EU and Indian regions.

Transfers out of the EEA are covered by the European Commission's Standard Contractual Clauses, together with supplementary technical measures including encryption in transit and at rest, and access controls scoped to named staff.

Retention

Server logs30 days
Project enquiries24 months from last contact
Appointment records12 months after the meeting
Unsuccessful applications6 months, or 24 with consent
Contractual & tax recordsAs required by statute
We delete or anonymise data once the purpose has been met and no statutory retention period applies.

Your rights

Subject to the applicable law, you have the right to:

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where no legal ground for keeping it remains.
  • Restriction — require us to limit processing while a matter is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — at any time, without affecting processing already carried out.
  • Complain — lodge a complaint with a supervisory authority, or with the Data Protection Board of India.

To exercise any of these, write to mail@bitbasegroup.in. We respond within one month, and will tell you if we need longer.

Cookies

This website sets only cookies that are strictly necessary for it to function — for example, remembering your consent choice and maintaining state while you complete a form. No consent is required for these.

We set no advertising, profiling, or cross-site tracking cookies. If we later introduce optional analytics, it will be behind an explicit opt-in and documented here first.

Security

We run an information security management system aligned to ISO 27001. Measures include TLS encryption in transit, encryption at rest, role-based access under least privilege, multi-factor authentication on all staff accounts, logging and monitoring, and regular review of processors.

Suspected vulnerabilities can be reported in confidence to mail@bitbasegroup.in. We acknowledge reports within two business days.

Changes to this policy

We update this policy when our processing changes or the law requires it. The version in force is always the one published here.

Version 2.1 · Last updated 1 September 2026