Processing...
Navigation
Home WhatsApp Cloud API TRAI SMS Gateway Enterprise Services Pricing & Plans Case Studies Blog About Us Contact
Regulatory & Compliance Policy

Privacy Policy & Data Protection Policy

Effective Date: January 01, 2026
Summary: Comprehensive privacy governance and data protection policy detailing GDPR and CCPA compliance, enterprise cryptographic safeguards, data retention schedules, individual rights, and Data Protection Officer (DPO) contact details.
<h2>1. Architectural Commitment to Data Privacy</h2>
<p>At <strong>New Age Technology</strong> ("NAT", "we", "our", or "us"), founded and led by <strong>Yash Kumar Jha</strong>, we treat data privacy and information security not merely as legal obligations, but as fundamental architectural requirements. This Privacy Policy &amp; Data Protection Policy outlines how we collect, process, store, encrypt, and safeguard information obtained through our web properties, software solutions, cloud consulting engagements, and client service portals.</p>

<h2>2. Scope and Regulatory Alignment</h2>
<p>This policy applies to all global clients, prospective partners, website visitors, and users of our digital assets. We design our systems and data processing workflows to comply with leading international data privacy frameworks, including:</p>
<ul>
<li><strong>General Data Protection Regulation (EU GDPR / UK GDPR):</strong> Regulation (EU) 2016/679 regarding the protection of natural persons with respect to the processing of personal data.</li>
<li><strong>California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):</strong> Regulating the personal information of California residents.</li>
<li><strong>Digital Personal Data Protection Act (DPDPA):</strong> Indian data protection standards for electronic personal data processing.</li>
<li><strong>Health Insurance Portability and Accountability Act (HIPAA):</strong> Safeguards for Protected Health Information (PHI) when building custom MedTech architectures.</li>
</ul>

<h2>3. Categories of Information We Collect</h2>
<p>We collect information strictly on a need-to-know basis to provide enterprise software engineering and consulting services:</p>
<ul>
<li><strong>Direct Business Disclosures:</strong> Full name, corporate email address, phone number, company name, project technical requirements, and service interests submitted via our contact or architectural discovery forms.</li>
<li><strong>Client Account &amp; Authentication Data:</strong> Cryptographically hashed credentials (bcrypt/Argon2id), session identifiers, and role-based access attributes for authorized CMS and portal users.</li>
<li><strong>Technical Telemetry &amp; Server Logs:</strong> IP addresses (anonymized where required), browser user-agent strings, HTTP request headers, diagnostic latency metrics, and error stack traces recorded for system reliability and DDoS mitigation.</li>
<li><strong>Consulting Engagement Artifacts:</strong> Architecture diagrams, database schemas, repository metadata, and infrastructure configuration files provided under signed Non-Disclosure Agreements (NDAs).</li>
</ul>

<h2>4. Legal Bases for Data Processing (GDPR Article 6)</h2>
<p>We process personal data only when substantiated by valid legal grounds:</p>
<ul>
<li><strong>Performance of a Contract:</strong> Processing necessary to execute master services agreements, deliver custom engineering sprints, and provide technical support.</li>
<li><strong>Legitimate Interests:</strong> Securing our network infrastructure, optimizing database query latency, preventing malicious intrusion, and improving user experience.</li>
<li><strong>Consent:</strong> Explicit user opt-in for marketing communications, whitepapers, or non-essential telemetry.</li>
<li><strong>Legal Compliance:</strong> Adhering to statutory tax, corporate governance, and audit reporting mandates.</li>
</ul>

<h2>5. Enterprise Data Security &amp; Cryptographic Controls</h2>
<p>Under the technical leadership of Yash Kumar Jha, New Age Technology deploys rigorous defense-in-depth security architectures:</p>
<ul>
<li><strong>Data at Rest:</strong> All database stores, backups, and disk volumes are encrypted utilizing <strong>AES-256</strong> industry-standard cryptographic algorithms.</li>
<li><strong>Data in Transit:</strong> All HTTP communications and API endpoints mandate <strong>TLS 1.3</strong> with strict HSTS (HTTP Strict Transport Security) and perfect forward secrecy.</li>
<li><strong>Access Control:</strong> Zero-trust network access, mandatory Multi-Factor Authentication (MFA), and granular Role-Based Access Control (RBAC) across all development environments.</li>
<li><strong>Code &amp; Database Integrity:</strong> Parameterized PDO queries and prepared statements preventing SQL injection, automated static analysis (SAST), and continuous dependency vulnerability scanning.</li>
</ul>

<h2>6. Data Retention &amp; Destruction Schedules</h2>
<p>We retain personal information only for as long as necessary to fulfill the operational purposes outlined in our engagement contracts or to satisfy legal, accounting, or regulatory requirements. Technical contact inquiries are retained for up to 24 months from the last engagement touchpoint, after which records are either securely purged using cryptographic erasure protocols or irreversibly anonymized for longitudinal analytics.</p>

<h2>7. Your Data Subject Rights (GDPR &amp; CCPA)</h2>
<p>Depending on your jurisdiction, you possess specific statutory rights regarding your personal information:</p>
<ul>
<li><strong>Right of Access:</strong> Request a copy of the personal data we hold about you in a structured, machine-readable format.</li>
<li><strong>Right to Rectification:</strong> Request correction of inaccurate, incomplete, or outdated information.</li>
<li><strong>Right to Erasure ("Right to be Forgotten"):</strong> Request permanent deletion of your data, subject to statutory retention exceptions.</li>
<li><strong>Right to Restrict or Object to Processing:</strong> Challenge our legitimate interest processing or opt out of specific communications.</li>
<li><strong>Right to Data Portability:</strong> Transfer your personal records directly to another service provider.</li>
<li><strong>Non-Discrimination:</strong> We will never deny services, charge differentiated rates, or degrade service quality because you exercise statutory privacy rights.</li>
</ul>

<h2>8. Third-Party Sub-Processors</h2>
<p>We do not sell, rent, monetize, or trade client personal data to third parties. We engage carefully vetted enterprise sub-processors under binding Data Processing Agreements (DPAs) for infrastructure operations, including cloud hosting providers (AWS, GCP, Azure), transactional email dispatchers, and error monitoring telemetry.</p>

<h2>9. International Data Transfers</h2>
<p>Where personal data is transferred across international boundaries (including transfers between India, the European Union, the United Kingdom, and the United States), transfers are governed by European Commission approved Standard Contractual Clauses (SCCs) and robust technical supplementary measures.</p>

<h2>10. Data Protection Officer (DPO) &amp; Contact Information</h2>
<p>For privacy inquiries, rights requests, or data protection concerns, you may reach our Data Protection Officer and senior architecture team directly:</p>
<ul>
<li><strong>Organization:</strong> New Age Technology</li>
<li><strong>Founder &amp; Chief Architect:</strong> Yash Kumar Jha</li>
<li><strong>Data Protection Officer Email:</strong> <a href="mailto:dpo@newagetechnology.co.in">dpo@newagetechnology.co.in</a></li>
<li><strong>General Inquiries:</strong> <a href="mailto:contact@newagetechnology.co.in">contact@newagetechnology.co.in</a></li>
<li><strong>Physical Address:</strong> Tech Innovators Park, Outer Ring Road, Bangalore, KA 560103, India</li>
</ul>
Sub-3s Latency • 80 MPS Throughput • Wholesale Pricing

Ready to Upgrade Your Enterprise Cloud Communications?

Join high-growth brands that rely on New Age Technology for WhatsApp Cloud API, TRAI DLT-compliant SMS, and verified customer engagement.