Privacy Policy
This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it. We collect as little as we can and we do not sell personal data.
Effective 20 August 2026
1. Who we are
Atomos Technologies (OPC) Private Limited ("Atomos Technologies", "we", "us", "our") is a company incorporated in India with its principal place of business in Kolkata, West Bengal, India. We operate the website at atomostechnologies.com and provide software engineering, artificial intelligence, cybersecurity and related professional services.
For the purposes of the EU and UK General Data Protection Regulation, we act as a data controller in respect of personal data collected through this website and in the course of our own business, and as a data processor in respect of personal data we handle on behalf of clients under a services agreement. Under India's Digital Personal Data Protection Act 2023 we act as a Data Fiduciary for website data and as a Data Processor for client data.
If you have any question about this policy, contact us at care@atomostechnologies.com.
2. Personal data we collect
Data you give us directly. When you submit our contact form, email us, or engage us for services, we may collect:
- Name and job title
- Email address and telephone number
- Company or organisation name
- The content of your message and any information you choose to include in it
- Indicative budget range and service interest
- Contractual, billing and payment information where you engage us
Data collected automatically. When you visit the website we may collect:
- IP address (used for rate limiting and abuse prevention; stored only as a salted hash)
- Browser type and version, operating system and device type
- Referring page and pages viewed on our site
- Date and time of access and approximate duration
- Aggregate, cookieless analytics that do not identify you individually
Data we do not collect. We do not knowingly collect special category or sensitive personal data through this website — including health data, biometric data, financial account credentials, or data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation. Please do not include such information in a contact form message.
We do not knowingly collect personal data from children. Our website and services are directed at businesses and organisations, not at children. If you believe a child has provided us personal data, contact us and we will delete it.
3. Why we use your data, and our lawful basis
We process personal data only where we have a lawful basis to do so. The bases we rely on are:
- Performance of a contract — to provide the services you have engaged us for, to manage the engagement, and to invoice and receive payment.
- Legitimate interests — to respond to enquiries, to secure our website against abuse and attack, to keep records of our business dealings, and to understand in aggregate how our website is used. We balance these interests against your rights and do not rely on this basis where your rights override it.
- Consent — where you have explicitly agreed, for example to receive communications that are not part of an existing engagement. You may withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation — to comply with tax, accounting, statutory and regulatory requirements applicable to us.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects concerning you, and we do not carry out profiling of website visitors.
4. Marketing communications
We do not send unsolicited marketing. If you submit an enquiry we will reply to that enquiry and may follow up regarding it. We will only add you to any wider mailing list with your explicit consent, and every such message will carry a working unsubscribe mechanism.
You can opt out of any non-essential communication at any time by replying to any message or writing to care@atomostechnologies.com.
5. Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share personal data only in the following circumstances:
- Service providers who process data on our instructions under a written agreement — for example email and hosting providers, and the bot-protection service used on our contact form. They may use the data only to provide the service to us.
- Professional advisers — lawyers, accountants and auditors, where necessary and under a duty of confidentiality.
- Legal and regulatory bodies — where we are required by law, court order or a valid governmental request, or where we need to establish, exercise or defend legal claims.
- A successor entity — in connection with a merger, acquisition or transfer of the business, in which case we will notify you and the acquirer will be bound by this policy or a materially equivalent one.
Where we act as a processor for a client, we handle personal data only on that client’s documented instructions under the terms of our services agreement and any data processing agreement.
6. International transfers
We are based in Kolkata, West Bengal, India and our clients are located in many countries. Personal data may therefore be transferred to, stored in, or accessed from countries other than the one you are in, including India.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard recognised under the GDPR — typically the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable — and we carry out a transfer risk assessment where required.
Where a client requires that data remains within a specific jurisdiction, we design and deploy for that requirement, including deployment to sovereign cloud regions or on-premise infrastructure. This is agreed in the services agreement rather than left to default.
7. How long we keep data
We keep personal data only for as long as we need it for the purpose it was collected, and then delete or anonymise it. Our default retention periods are:
- Contact form enquiries that do not lead to an engagement — 24 months from last contact
- Client and engagement records — the duration of the engagement plus 8 years, to meet Indian statutory, tax and limitation requirements
- Rate-limiting records — 1 hour, stored as a salted hash rather than a raw IP address
- Aggregate analytics — retained in aggregate form only, with no individual-level record
- Email correspondence — 36 months from last contact unless it forms part of an engagement record
Where we act as a processor for a client, retention is set by that client’s instructions and by the services agreement, not by this policy.
8. How we protect your data
We are a cybersecurity company, and we apply to ourselves the practices we recommend to clients:
- Encryption in transit (TLS) for all traffic, and at rest where the storage medium supports it
- Role-based access control on a least-privilege basis, reviewed periodically
- Data minimisation — we ask for the least data an engagement requires
- No production client data copied into development environments; anonymised or synthetic data is used instead
- Dependency and vulnerability scanning as part of our build pipeline
- Penetration testing and security review before release
- Confidentiality obligations binding on every member of our team
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority — including the Data Protection Board of India where the DPDP Act applies — within the period required by law, and will notify affected individuals without undue delay where the risk is high.
9. Your rights
Depending on where you are, you have some or all of the following rights over your personal data:
- Access — to obtain confirmation of whether we process your data and a copy of it
- Correction — to have inaccurate or incomplete data corrected or completed
- Erasure — to have your data deleted where there is no continuing lawful basis to keep it
- Restriction — to limit how we use your data in certain circumstances
- Portability — to receive your data in a structured, commonly used, machine-readable format
- Objection — to object to processing carried out on the basis of legitimate interests, and to direct marketing at any time
- Withdrawal of consent — where processing is based on consent, at any time
- Grievance redressal — under the DPDP Act 2023, to have a grievance addressed by us before escalating
- Nomination — under the DPDP Act 2023, to nominate a person to exercise your rights in the event of death or incapacity
- Non-discrimination — under the CCPA/CPRA, not to be treated differently for exercising your rights
To exercise any right, email care@atomostechnologies.com with the subject DATA REQUEST. We will respond within 30 days. We may need to verify your identity before acting, and we will explain if we cannot fully comply and why.
You also have the right to complain to a supervisory authority: the Data Protection Board of India, your EU member state supervisory authority, or the UK Information Commissioner’s Office, as applicable. We would appreciate the chance to address your concern first.
10. Grievance officer
In accordance with the Information Technology Act 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and the Digital Personal Data Protection Act 2023, complaints regarding the processing of personal data may be addressed to our Grievance Officer at care@atomostechnologies.com with the subject GRIEVANCE.
We will acknowledge a grievance within 24 hours and resolve it within 15 days of receipt, as required by the applicable rules.
11. Cookies and tracking
This website uses no advertising cookies, no third-party tracking cookies and no cross-site profiling. Our analytics are cookieless and aggregate. See our Cookie Policy for the full detail of what is set and why.
12. Third-party links
Our website links to third-party sites we do not control. This policy does not apply to them, and we are not responsible for their practices. We encourage you to read the privacy policy of any site you visit.
13. Changes to this policy
We may update this policy from time to time. The current version is always published here with its effective date. Where a change materially affects your rights we will take reasonable steps to notify you directly. Continued use of the website after a change constitutes acceptance of the updated policy.
14. Contact
Atomos Technologies (OPC) Private Limited
Kolkata, West Bengal, India
Email: care@atomostechnologies.com