1. Home
  2. Privacy policy

Legal

Privacy policy.

How DevOps TechLab collects, uses and protects personal data, including the client data and admin credentials we handle when managing your systems.

  • Effective date1 October 2026
  • Last updated9 October 2026
  • Applies toIndia and worldwide

1. Introduction

1.1
This Privacy Policy explains how Devops Techlab Private Limited (“DevOps TechLab”, “we”, “us” or “our”), a company incorporated in India with Corporate Identification Number U74999GJ2018PTC101332 and its registered office at 634, Iscon Emporio, Near Star Bazar, Satellite, Ahmedabad, Gujarat 380015, India, collects, uses, discloses, stores and protects personal data.
1.2
This policy is published in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the “DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and, where they apply, the EU and UK General Data Protection Regulation (“GDPR”) and US state privacy laws.
1.3
This policy should be read together with our Terms of Use and Service. Capitalised terms not defined here have the meaning given in those Terms.

2. Definitions

“Client” means an organisation that obtains managed services, AMC, licensing, cloud billing or other services from us.

“Client Data” means data, including personal data, stored in Client Systems or made available to us by a Client in the course of our services.

“Client Systems” means a Client’s cloud accounts, servers, networks, devices, applications and productivity environments such as Microsoft 365, Google Workspace and Zoho.

“Credentials” means usernames, passwords, access keys, tokens, recovery codes, multi-factor factors and delegated administrative privileges for Client Systems.

“Data Fiduciary / controller” means the person who decides the purpose and means of processing personal data.

“Data Processor / processor” means a person who processes personal data on behalf of a Data Fiduciary or controller.

“Data Principal / data subject” means the individual to whom personal data relates.

“Personal data” means any data about an individual who is identifiable by or in relation to that data.

3. Scope and our role

3.1
Where we are the Data Fiduciary or controller. We decide how personal data is used when you visit our website, submit a form, correspond with us, attend our events, act as a contact for a Client, supplier or partner, or apply for a job with us.
3.2
Where we are the Data Processor or processor. When we migrate, manage, monitor, maintain or support Client Systems, we may have access to Client Data, including personal data of the Client’s employees and customers. For that data the Client is the Data Fiduciary or controller. We process it only to provide our services and on the Client’s documented instructions, under our contract with the Client and any Data Processing Agreement. Individuals whose data is in a Client System should direct requests to that Client in the first instance; we will assist the Client in responding.
3.3
Sections 7, 8 and 9 describe the safeguards we apply to Client Data and Credentials in either role.

4. Personal data we collect

4.1
We collect the following categories of personal data:
CategoryExamplesSource
Identity and contactName, work email, phone number, company, job titleYou, via forms, email, calls, meetings or events
EnquiryServices of interest, primary cloud, number of users, licences or devices, your messageYou
Commercial and billingBilling contact and address, GSTIN, purchase orders, licence and subscription records, payment statusYou or your organisation
Service and supportTickets, emails, call notes, change approvals, authorised-contact lists, information needed to raise Vendor casesYou, your organisation and our systems
RecruitmentCV (PDF file), employment and education history, certifications, profile links, notice period, interview notes, referencesYou, and referees you nominate
TechnicalIP address, browser, operating system and device type, pages visited, referring site, approximate location (country), cookie and browser-storage identifiersYour browser, through cookies and similar technologies
Visit recordThe page you first arrived on, the referring site, campaign tags in the link you followed (UTM parameters), the pages you view during your visit, and when you start filling in a formOur website form script, held in your browser (see clause 4.3)
Enquiry contextThe title, address (URL) and section of the page from which you sent a form, together with your visit record, device type and approximate countryAttached automatically when you submit a form (see clause 4.4)
WhatsApp opt-inYour mobile number; whether you ticked the WhatsApp updates box; the date and time, page, form and exact wording of the consent you gave; and any later opt-outYou, when you tick the optional WhatsApp box on a form (see clause 6.4)
EventsRegistration details, attendance, badge scansYou, and event organisers with your agreement
Testimonials and case studiesName, job title, photograph, quote or video of a Client’s staff memberYou or your organisation, only with approval
4.2
We do not seek to collect financial account numbers, government identifiers, health data or other sensitive information through the website. Please do not include it in forms, messages or CVs. Credentials are not collected through the website and must never be sent through a website form.
4.3
Visit record. To understand which pages lead to enquiries and to filter automated spam, the script that runs our website forms keeps a small visit record in your browser’s storage for our website. It contains the items listed under “Visit record” in clause 4.1. It does not contain your name or contact details, it is not used to follow you on other websites, and it reaches us only if you submit a form. It is kept in your browser for 90 days and you can clear it at any time through your browser settings.
4.4
Technical details sent with each enquiry. When you submit any form on our website (including enquiry, quote, event registration, calculator and job application forms), we attach to your submission: the title, address (URL) and section of the page you sent it from; your visit record; your browser and device type; and your approximate country. Your IP address is used to work out your approximate country and to limit repeated submissions. We use these details to route your enquiry to the right person, to learn which pages are useful, and to protect our forms from spam and abuse.
4.5
Where website submissions are stored. Submissions from our website forms, including job applications and the CV files attached to them, are stored in a database in our own enquiry management system (the “DTL Console”), which is hosted by Hostinger on servers in India. CVs are accepted as PDF files of up to 2 MB, are stored inside that database rather than in a publicly reachable folder, and can be opened only by authorised DevOps TechLab personnel who sign in to the DTL Console. Alert and acknowledgement emails about a submission are sent through our Microsoft 365 service.

5. Purposes and legal bases

5.1
We process personal data only for the purposes below. Under the DPDP Act we rely on your consent or on a legitimate use permitted by Section 7, such as data you have voluntarily provided for a specified purpose, or compliance with law. Under the GDPR we rely on the lawful bases shown.
PurposeActivitiesGDPR lawful basis
Responding to enquiriesReplying to forms, emails and calls; scheduling reviewsSteps prior to a contract; legitimate interests
Quoting and supplyPreparing quotes; ordering licences, cloud services and devices through Vendors and distributors; deal registrationContract; steps prior to a contract
Service deliveryMigration, managed services, AMC, support and Vendor case managementContract
Billing and recordsInvoicing with GST, collections, tax, accounting and audit recordsLegal obligation; contract
Security and fraud preventionAccess logging, monitoring, incident response, protecting our and Client systemsLegitimate interests; legal obligation
RecruitmentAssessing applications, interviews, offersSteps prior to a contract; legitimate interests
Website operation and analyticsRunning the website; measuring page useLegitimate interests; consent for analytics
Enquiry attribution and spam protectionRecording the page and visit that led to a form submission; filtering automated and abusive submissionsLegitimate interests
MarketingNewsletters, event invitations, service updatesConsent
WhatsApp updatesSending news about our services, offers, events and resources on WhatsApp to people who opted inConsent
Case studies and testimonialsPublishing approved case studies, quotes and client logos (logos are covered by our Terms, Section 21)Consent
Legal complianceResponding to lawful requests; establishing, exercising or defending legal claimsLegal obligation; legitimate interests
5.2
We do not sell personal data, and we do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.

7. Client data and administrative credentials

7.1
Our managed services, AMC and licensing administration require privileged access to Client Systems. We treat Client Data and Credentials as strictly confidential and apply the following commitments.
7.2
Access method. We prefer named, role-based or delegated administration (such as delegated admin roles in Microsoft 365, IAM roles or federated access in AWS, and admin roles in Google Workspace) over shared passwords, and request only the privileges needed for the agreed work.
7.3
Storage. Credentials are stored only in an encrypted, access-controlled password vault. They are never stored in plain text or sent by email, chat or ticket, and the vault is protected by multi-factor authentication.
7.4
People. Access is limited to named personnel with a need to know, who are bound by written confidentiality obligations and receive security training. Access is revoked promptly when no longer required or when a person leaves us.
7.5
Purpose limitation. We use Credentials and access Client Data only to perform the services on the Client’s documented instructions. We do not access, copy, analyse or disclose Client Data for any other purpose, and we do not use it to train artificial-intelligence models.
7.6
Accountability. We log administrative activity where the platform allows, follow the Client’s change-approval process for high-risk changes, and make relevant records available to the Client on reasonable request.
7.7
Location. Client Data remains in the regions the Client selects for its Client Systems. Our engineers may access it remotely from India.
7.8
End of service. When services end we hand back Credentials and administrative roles, remove our access, confirm this in writing, and return or delete any Client Data in our possession, except where the law requires us to retain it. We recommend that Clients rotate all Credentials we had access to.
7.9
Detailed contractual commitments, including incident notice times and audit rights, are set out in our Terms of Use and Service and, where signed, the Client’s Data Processing Agreement.

8. Security safeguards

8.1
We implement reasonable security practices and procedures appropriate to the nature of the data and the risks of processing, including:
  1. role-based access control and multi-factor authentication for our personnel and systems;
  2. encryption of data in transit and, where supported, at rest;
  3. an encrypted credential vault for Client Credentials;
  4. endpoint protection and device management on our laptops and devices;
  5. logging and monitoring of our systems, with logs retained for at least 180 days, and for at least one year where required by the DPDP Rules;
  6. backups of our own business systems;
  7. sign-in, account lockout and a login record for the DTL Console, with access to website submissions and CVs limited to authorised personnel;
  8. confidentiality undertakings, background checks and regular security training for our personnel;
  9. written security and confidentiality obligations for our sub-processors.
8.2
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect personal data against unauthorised access, alteration, disclosure and destruction.

9. Personal data breaches

9.1
If we become aware of a personal data breach affecting data for which we are the Data Fiduciary, we will notify affected Data Principals and the Data Protection Board of India in the manner and within the time required by the DPDP Act, including a detailed report within 72 hours, and notify the competent supervisory authority within 72 hours where the GDPR applies.
9.2
We will report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within six hours of noticing them where the CERT-In Directions of 28 April 2022 require it.
9.3
If a breach affects Client Data we process as a Data Processor, we will notify the Client without undue delay and within the time set in our contract, and provide the information and assistance it needs to meet its own obligations.

10. Cookies and similar technologies

10.1
We use the following cookies and similar technologies. Analytics and marketing tools are loaded through Google Tag Manager only after you accept them in our cookie banner:
CategoryTools and cookiesPurposeDuration and your choice
Strictly necessaryCookie consent (CookieYes: cookieyes-consent); theme choice; form operation and security; staff sign-in to the DTL ConsoleRemembering your cookie and theme choices; keeping forms and our staff console working and secureUp to 1 year (consent) or session; always active, required for the website
Visit record (form script)First-party browser storage set by our form scriptRemembering your landing page, referring site, campaign tags and pages viewed so they can be sent with a form you submit (clause 4.3)Held only in your browser for 90 days and sent only if you submit a form; you can clear it in your browser settings
AnalyticsGoogle Analytics 4 (_ga, _ga_<ID>); Microsoft Clarity (_clck, _clsk, CLID, MUID)Counting visits and sessions, measuring page use and enquiries, and heatmaps and session recordings that show how pages are usedUp to 2 years (Google Analytics) and 1 day to 1 year (Clarity); off until you consent
MarketingGoogle Ads (_gcl_au); LinkedIn Insight Tag (bcookie, li_sugr, lidc, UserMatchHistory); Meta Pixel (_fbp), only while we run Meta adsMeasuring the results of our advertising and showing our ads to people who have visited the website90 days (Google Ads, Meta) and up to 1 year (LinkedIn); off until you consent
10.2
You can accept, reject or customise analytics and marketing cookies in the banner when you first visit, and change your choice at any time through the “Cookie settings” link in the website footer. Our cookie consent provider, CookieYes, records your choice with a timestamp and an anonymised IP address so that we can show what you agreed to. You can also block or delete cookies in your browser settings.
10.3
Microsoft Clarity masks what you type into forms, so session recordings do not show the personal details you enter.
10.4
Cookie names and durations are set by the providers and may change. The cookie settings panel lists the cookies currently in use on the website.

11. Disclosure of personal data

11.1
We disclose personal data only as follows:
  1. Vendors and distributors such as Amazon Web Services, Microsoft, Google, Zoho, Adobe and Apple and their authorised distributors, to provision licences, cloud services and devices, register deals, manage billing and raise support cases. They process data under their own privacy policies.
  2. Sub-processors and service providers who support our business, such as email and collaboration, CRM, ticketing, monitoring, hosting, accounting and recruitment providers, under written contracts requiring confidentiality and security. Our main providers for the website are Hostinger, which hosts our website and the DTL Console and stores website submissions and CVs in India, and Microsoft, whose Microsoft 365 service we use for email, including the alert and acknowledgement emails sent when you submit a form. Our cookie banner is provided by CookieYes. With your consent, we use Google (Google Tag Manager, Google Analytics 4 and Google Ads), Microsoft Clarity, the LinkedIn Insight Tag and, only while we run Meta ads, the Meta Pixel to measure website use and our advertising (Section 10). We use Zoho (Zoho CRM, Zoho Campaigns and Zoho Social) to manage enquiries and client relationships and to send newsletters to people who have agreed to receive them. If you opt in to WhatsApp updates, your mobile number and the messages we send you are processed through the WhatsApp Business Platform operated by Meta and our WhatsApp service provider, Voixt, which we also use for client updates and support messages on WhatsApp.
  3. Professional advisers such as auditors, lawyers and insurers, under duties of confidentiality.
  4. Event organisers, where you register through them or agree to share.
  5. Government authorities, regulators and courts where required by law, including requests from CERT-In or law-enforcement agencies under applicable law.
  6. A successor or acquirer in a merger, acquisition or reorganisation, subject to confidentiality and to this policy.
11.2
We do not disclose Client Data to any third party except to perform the services, on the Client’s instructions, or where required by law. Where lawful, we will inform the Client before responding to a legal demand for its data.

12. International transfers

12.1
We are based in India and provide cloud services to clients worldwide. Our licensing, device and cloud billing services (such as AWS billing in INR on a GST invoice) are provided to clients in India.
12.2
Our website, the DTL Console and the database that stores website submissions and CVs are hosted in India. Personal data may also be processed in other countries where we, our sub-processors or Client Systems operate. In particular, Google, Microsoft, LinkedIn, Meta, CookieYes and, for WhatsApp messages, Voixt may process data outside India, mainly in the United States and the European Union.
12.3
Transfers from India are made in accordance with the DPDP Act, which permits transfers except to countries or territories restricted by notification of the Government of India.
12.4
Transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision are made under the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful safeguard. A copy is available on request.

13. Data retention

13.1
We retain personal data only for as long as necessary for the purpose for which it was collected or as required by law:
DataRetention period
Enquiries not leading to a contract, including the visit record and technical details sent with them24 months from last contact
Client contracts, invoices and tax recordsTerm of the relationship plus the period for which Indian GST law requires records to be kept, plus one further year
Support and change recordsTerm of the services plus 3 years
Client Data held by usUntil returned or deleted at the end of the services, as set out in Section 7.8
Job applications and CVs not leading to employment12 months from receipt, unless you ask us to delete earlier
Visit record held in your browserSee clause 4.3; you can clear it at any time
Marketing consentUntil withdrawn, or 24 months without engagement
Cookie consent recordUp to 1 year, or until you change your choice
WhatsApp opt-in and opt-out recordsWhile you remain opted in, and for 3 years after you opt out, to show that consent was given and withdrawn
Security and access logsAt least 180 days, and at least one year where required by the DPDP Rules
13.2
When the retention period ends, we delete or irreversibly anonymise the data. Website submissions and CVs held in the DTL Console are deleted from it when their retention period ends.

14. Your rights

14.1
India. Under the DPDP Act you may request a summary of the personal data we process and the persons we have shared it with; correction, completion, updating or erasure of your personal data; redressal of grievances; and nominate another individual to exercise your rights in the event of death or incapacity. You may complain to the Data Protection Board of India after exhausting our grievance process.
14.2
EEA, UK and Switzerland. Under the GDPR you may request access, rectification, erasure, restriction and portability; object to processing based on legitimate interests and to direct marketing at any time; withdraw consent; and lodge a complaint with your supervisory authority.
14.3
United States. Where state privacy laws apply, you may request to know, access, correct or delete personal information. We do not sell personal information or share it for cross-context behavioural advertising, and we will not discriminate against you for exercising your rights.
14.4
How to exercise your rights. Write to janak@devopstechlab.com or our Grievance Officer. We may need to verify your identity. We will respond within the time required by applicable law: within one month under the GDPR, within 45 days under US state laws, and no later than 90 days under the DPDP Rules.
14.5
For personal data in Client Systems, please contact the relevant Client. We will assist the Client in responding.

15. Children

15.1
Our website and services are directed at businesses. We do not knowingly collect personal data of anyone under 18. If you believe we have, contact janak@devopstechlab.com and we will delete it.

17. Changes to this policy

17.1
We may update this policy to reflect changes in our services or the law. We will revise the “Last updated” date and, for significant changes, notify you by email or a prominent notice on the website before they take effect.

18. Grievance Officer and contact

18.1
Privacy contact: janak@devopstechlab.com
Postal address: Devops Techlab Private Limited, 634, Iscon Emporio, Near Star Bazar, Satellite, Ahmedabad, Gujarat 380015, India
18.2
Grievance Officer (DPDP Act and Information Technology Act, 2000): Falguni Prajapati, HR
Email: janak@devopstechlab.com
Phone: +91 88492 50274
18.3
We acknowledge grievances within 48 hours and resolve them within the time required by law.

Questions

Questions about your data?

Write to us and we’ll reply.

Privacy contactjanak@devopstechlab.com

Requests about your personal data.

Grievance OfficerFalguni Prajapati, HR

janak@devopstechlab.com

Everything elseTalk to an engineerBook a 20-minute review

See also our Terms of use and service.