Privacy Policy & Data Protection Charter
This Privacy Policy explains how CombineGrowth Technologies Private Limited collects, protects, isolates, and processes information across our websites, custom software engineering services, cloud architectures, and digital growth engines.
Zero Data Monetization
We strictly never sell, rent, monetize, or trade your personal or business data under any circumstances.
Zero-Trust Cryptography
End-to-end TLS 1.3 in-transit and military-grade AES-256 encryption at-rest across all infrastructure.
100% Client Code Isolation
Client repositories, proprietary logic, and database schemas remain strictly isolated under signed NDAs.
Global Privacy Alignment
Full statutory compliance with EU/UK GDPR, California CCPA/CPRA, and India's DPDP Act 2023.
1. Introduction & Corporate Identity
This Privacy Policy is entered into by and between you and CombineGrowth Technologies Private Limited ("CombineGrowth", "Company", "we", "us", or "our"), a private limited company duly incorporated under the laws of the Republic of India, with its principal office located at Narasaraopet, Andhra Pradesh, India.
CombineGrowth operates as an enterprise software engineering company providing custom website development, iOS & Android mobile application development, enterprise CRM and ERP platform architectures, cloud-native microservices, GraphQL/REST API gateways, and specialized search engine optimization (SEO) and generative engine optimization (GEO) solutions worldwide.
This Privacy Policy establishes our binding data governance standards across all interactions with our corporate website (https://combinegrowth.com), client dashboards, project discovery portals, communication channels, and contractual engagements.
2. Regulatory & Jurisdictional Compliance Framework
Because CombineGrowth serves international enterprises across North America, the European Economic Area, the United Kingdom, India, the Middle East, and the Asia-Pacific region, this policy has been drafted to strictly align with the highest global statutory standards:
Regulation (EU) 2016/679 and UK Data Protection Act 2018.
California Consumer Privacy Act and California Privacy Rights Act.
Digital Personal Data Protection Act, 2023 statutory mandates.
3. Categories of Information We Collect
We adhere strictly to the principle of Data Minimization under Article 5(1)(c) of the GDPR. We collect only the information necessary to evaluate project inquiries, deliver custom software products, and administer client relationships.
A. Directly Provided Business & Contact Data
When you complete our contact forms, request technical proposals, schedule architectural consultations, or engage our engineering teams, you may provide: Full Name, Professional/Corporate Email Address, Phone Number, Corporate Name, Job Title, Project Specifications, Budgetary Estimates, and Functional Requirements.
B. Technical Infrastructure & Telemetry Data
When accessing our web applications, our edge servers automatically capture diagnostic telemetry: Internet Protocol (IP) addresses, browser type, operating system version, referring URLs, HTTP request headers, time-stamp logs, device screen resolution, and error telemetry necessary for security firewalls and DDoS protection.
C. Commercial & Billing Transaction Metadata
For enterprise client engagements: Corporate Billing Address, Tax Identification Numbers (GSTIN, VAT, EIN), purchase orders, and wire remittance records. Please note that credit card processing is handled via PCI-DSS Level 1 compliant financial gateways; CombineGrowth never stores raw credit card CVV or unencrypted cardholder numbers.
4. Lawful Bases for Data Processing
Under global privacy statutes including Article 6 of the GDPR, we only process personal information where a valid legal justification exists:
- Contractual Performance (Article 6(1)(b)): Processing necessary to fulfill Master Services Agreements (MSA), Statements of Work (SOW), execute milestone deliverables, deploy software systems, and provide technical maintenance.
- Legitimate Business Interests (Article 6(1)(f)): Processing essential to defend against malicious traffic, prevent cybersecurity breaches, conduct vulnerability assessments, optimize website load times, and manage enterprise client communications.
- Explicit Consent (Article 6(1)(a)): Where you explicitly consent to receive technical whitepapers, architectural case studies, marketing newsletters, or non-essential cookies.
- Statutory & Legal Compliance (Article 6(1)(c)): Compliance with mandatory taxation audits, corporate filings, statutory anti-fraud regulations, and lawful judicial subpoenas.
5. Enterprise Client Code Confidentiality & Data Isolation
A core pillar of CombineGrowth's engineering charter is strict client proprietary code and data isolation.
During development, QA validation, and staging deployments, CombineGrowth strictly enforces synthetic mock data and sanitized datasets. Real production databases containing sensitive end-user PII are never duplicated onto local engineering workstations.
All client source code, database architectures, proprietary business algorithms, and intellectual property remain 100% exclusive to the client as governed under executed bilateral Non-Disclosure Agreements (NDAs) and Master Services Agreements. We never cross-contaminate proprietary logic across client repositories.
6. Detailed Purposes for Processing Personal Data
We process collected data exclusively for the following stated operational purposes:
Executing CI/CD workflows, orchestrating cloud microservices, and maintaining our 99.99% uptime commitments.
Real-time threat monitoring, rate limiting, SQL injection defense, and blocking automated botnets.
Conducting weekly sprint reviews, technical demonstrations, scope adjustments, and invoicing.
Aggregating anonymized Core Web Vitals to deliver sub-100ms response latencies and 100/100 performance scores.
7. Third-Party Sub-Processors & Data Sharing Restrictions
We do not sell, lease, trade, or monetize personal data under any circumstances. Data is shared only with strictly vetted enterprise sub-processors under signed Data Processing Agreements (DPAs):
We may also disclose information where mandatory by law, such as to comply with a valid court order, regulatory investigation, or statutory legal proceeding.
8. International Cross-Border Data Transfers
When personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside these territories, CombineGrowth enforces appropriate transfer mechanisms recognized under Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs): Execution of the European Commission-approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
- UK International Data Transfer Addendum:Compliance with the UK Information Commissioner's Office (ICO) statutory transfer requirements.
- Technical Safeguards: Supplementary technical and organizational measures including mandatory cryptographic encryption in transit and at rest.
9. Data Retention & Cryptographic Disposal Schedules
We retain personal information only for as long as strictly necessary to fulfill the operational purposes set forth in this policy, unless a longer statutory retention period is required by tax, corporate, or financial audit laws:
| Data Category | Retention Schedule | Disposal Mechanism |
|---|---|---|
| General Website Inquiries & Form Leads | 12 Months from last active communication | Automated database purge |
| Master Services Agreements & Invoices | 7 Years (Mandated by Statutory Tax Laws) | Secure cryptographic archiving |
| Ephemeral Server Logs & Telemetry | 30 to 90 Days maximum rolling window | Cyclical overwrite rotation |
10. Zero-Trust Security & Technical Safeguards
CombineGrowth deploys industry-leading defense-in-depth security architectures to protect your data against unauthorized access, exfiltration, alteration, or destruction:
All network communications require TLS 1.3 encryption. Data stored at rest is protected with AES-256 cipher specifications.
Strict least-privilege access model enforced. Hardware security keys and Multi-Factor Authentication (MFA) required for all internal engineering staff.
Continuous SAST (Static Application Security Testing) and automated dependency vulnerability scanning integrated into CI/CD pipelines.
Virtual Private Clouds (VPC) with strict subnet network access control lists (NACLs) preventing unauthorized lateral movement.
12. Your Global Statutory Privacy Rights
Depending on your geographic residency (e.g., European Economic Area, UK, California, India), you possess specific non-waivable statutory rights under applicable privacy legislation:
13. Children's Online Privacy Protection
CombineGrowth provides specialized enterprise B2B software engineering and digital technology consulting. Our services and digital interfaces are strictly intended for corporate entities and adults aged eighteen (18) and older.
We do not knowingly solicit or collect personal information from individuals under the age of 18 in accordance with COPPA (Children's Online Privacy Protection Act) and global equivalents. If you suspect that a minor has provided us with personal data, please notify us immediately at hello@combinegrowth.com, and we will delete the data without delay.
14. Policy Modifications & Governance Updates
As our enterprise engineering capabilities evolve and global privacy statutes update, CombineGrowth reserves the right to modify this Privacy Policy. Any material revisions will be reflected by updating the "Last Updated" date at the top of this document.
For material changes that substantively impact how we handle existing personal data, we will provide conspicuous advance notice through our website banner or direct electronic communication to registered corporate client representatives.
15. Data Protection Officer (DPO) & Legal Inquiries
For statutory inquiries, Data Protection Officer communications, NDA executions, or legal escalations:
