- Home
- Privacy policy
Legal
Privacy policy.
How DevOps TechLab collects, uses and protects personal data, including the client data and admin credentials we handle when managing your systems.
1. Introduction
2. Definitions
“Client” means an organisation that obtains managed services, AMC, licensing, cloud billing or other services from us.
“Client Data” means data, including personal data, stored in Client Systems or made available to us by a Client in the course of our services.
“Client Systems” means a Client’s cloud accounts, servers, networks, devices, applications and productivity environments such as Microsoft 365, Google Workspace and Zoho.
“Credentials” means usernames, passwords, access keys, tokens, recovery codes, multi-factor factors and delegated administrative privileges for Client Systems.
“Data Fiduciary / controller” means the person who decides the purpose and means of processing personal data.
“Data Processor / processor” means a person who processes personal data on behalf of a Data Fiduciary or controller.
“Data Principal / data subject” means the individual to whom personal data relates.
“Personal data” means any data about an individual who is identifiable by or in relation to that data.
3. Scope and our role
4. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, work email, phone number, company, job title | You, via forms, email, calls, meetings or events |
| Enquiry | Services of interest, primary cloud, number of users, licences or devices, your message | You |
| Commercial and billing | Billing contact and address, GSTIN, purchase orders, licence and subscription records, payment status | You or your organisation |
| Service and support | Tickets, emails, call notes, change approvals, authorised-contact lists, information needed to raise Vendor cases | You, your organisation and our systems |
| Recruitment | CV (PDF file), employment and education history, certifications, profile links, notice period, interview notes, references | You, and referees you nominate |
| Technical | IP address, browser, operating system and device type, pages visited, referring site, approximate location (country), cookie and browser-storage identifiers | Your browser, through cookies and similar technologies |
| Visit record | The page you first arrived on, the referring site, campaign tags in the link you followed (UTM parameters), the pages you view during your visit, and when you start filling in a form | Our website form script, held in your browser (see clause 4.3) |
| Enquiry context | The title, address (URL) and section of the page from which you sent a form, together with your visit record, device type and approximate country | Attached automatically when you submit a form (see clause 4.4) |
| WhatsApp opt-in | Your mobile number; whether you ticked the WhatsApp updates box; the date and time, page, form and exact wording of the consent you gave; and any later opt-out | You, when you tick the optional WhatsApp box on a form (see clause 6.4) |
| Events | Registration details, attendance, badge scans | You, and event organisers with your agreement |
| Testimonials and case studies | Name, job title, photograph, quote or video of a Client’s staff member | You or your organisation, only with approval |
5. Purposes and legal bases
| Purpose | Activities | GDPR lawful basis |
|---|---|---|
| Responding to enquiries | Replying to forms, emails and calls; scheduling reviews | Steps prior to a contract; legitimate interests |
| Quoting and supply | Preparing quotes; ordering licences, cloud services and devices through Vendors and distributors; deal registration | Contract; steps prior to a contract |
| Service delivery | Migration, managed services, AMC, support and Vendor case management | Contract |
| Billing and records | Invoicing with GST, collections, tax, accounting and audit records | Legal obligation; contract |
| Security and fraud prevention | Access logging, monitoring, incident response, protecting our and Client systems | Legitimate interests; legal obligation |
| Recruitment | Assessing applications, interviews, offers | Steps prior to a contract; legitimate interests |
| Website operation and analytics | Running the website; measuring page use | Legitimate interests; consent for analytics |
| Enquiry attribution and spam protection | Recording the page and visit that led to a form submission; filtering automated and abusive submissions | Legitimate interests |
| Marketing | Newsletters, event invitations, service updates | Consent |
| WhatsApp updates | Sending news about our services, offers, events and resources on WhatsApp to people who opted in | Consent |
| Case studies and testimonials | Publishing approved case studies, quotes and client logos (logos are covered by our Terms, Section 21) | Consent |
| Legal compliance | Responding to lawful requests; establishing, exercising or defending legal claims | Legal obligation; legitimate interests |
6. Consent and its withdrawal
- opting in is voluntary and is not a condition of any quote, service or job application;
- we keep a record of your consent (your number, the date and time, the page and form, and the wording you agreed to) so that we can show you gave it;
- you can opt out at any time by replying “STOP” to any of our WhatsApp messages, using the opt-out option in the message, or writing to janak@devopstechlab.com; we will stop sending marketing messages promptly and record your opt-out;
- opting out of WhatsApp updates does not affect replies about an enquiry you have made or messages needed to deliver services you have bought;
- we do not sell or share your number for others’ marketing, and we follow WhatsApp’s Business and Commerce policies.
7. Client data and administrative credentials
8. Security safeguards
- role-based access control and multi-factor authentication for our personnel and systems;
- encryption of data in transit and, where supported, at rest;
- an encrypted credential vault for Client Credentials;
- endpoint protection and device management on our laptops and devices;
- logging and monitoring of our systems, with logs retained for at least 180 days, and for at least one year where required by the DPDP Rules;
- backups of our own business systems;
- sign-in, account lockout and a login record for the DTL Console, with access to website submissions and CVs limited to authorised personnel;
- confidentiality undertakings, background checks and regular security training for our personnel;
- written security and confidentiality obligations for our sub-processors.
9. Personal data breaches
10. Cookies and similar technologies
| Category | Tools and cookies | Purpose | Duration and your choice |
|---|---|---|---|
| Strictly necessary | Cookie consent (CookieYes: cookieyes-consent); theme choice; form operation and security; staff sign-in to the DTL Console | Remembering your cookie and theme choices; keeping forms and our staff console working and secure | Up to 1 year (consent) or session; always active, required for the website |
| Visit record (form script) | First-party browser storage set by our form script | Remembering your landing page, referring site, campaign tags and pages viewed so they can be sent with a form you submit (clause 4.3) | Held only in your browser for 90 days and sent only if you submit a form; you can clear it in your browser settings |
| Analytics | Google Analytics 4 (_ga, _ga_<ID>); Microsoft Clarity (_clck, _clsk, CLID, MUID) | Counting visits and sessions, measuring page use and enquiries, and heatmaps and session recordings that show how pages are used | Up to 2 years (Google Analytics) and 1 day to 1 year (Clarity); off until you consent |
| Marketing | Google Ads (_gcl_au); LinkedIn Insight Tag (bcookie, li_sugr, lidc, UserMatchHistory); Meta Pixel (_fbp), only while we run Meta ads | Measuring the results of our advertising and showing our ads to people who have visited the website | 90 days (Google Ads, Meta) and up to 1 year (LinkedIn); off until you consent |
12. International transfers
13. Data retention
| Data | Retention period |
|---|---|
| Enquiries not leading to a contract, including the visit record and technical details sent with them | 24 months from last contact |
| Client contracts, invoices and tax records | Term of the relationship plus the period for which Indian GST law requires records to be kept, plus one further year |
| Support and change records | Term of the services plus 3 years |
| Client Data held by us | Until returned or deleted at the end of the services, as set out in Section 7.8 |
| Job applications and CVs not leading to employment | 12 months from receipt, unless you ask us to delete earlier |
| Visit record held in your browser | See clause 4.3; you can clear it at any time |
| Marketing consent | Until withdrawn, or 24 months without engagement |
| Cookie consent record | Up to 1 year, or until you change your choice |
| WhatsApp opt-in and opt-out records | While you remain opted in, and for 3 years after you opt out, to show that consent was given and withdrawn |
| Security and access logs | At least 180 days, and at least one year where required by the DPDP Rules |
14. Your rights
15. Children
16. Third-party websites
17. Changes to this policy
18. Grievance Officer and contact
Postal address: Devops Techlab Private Limited, 634, Iscon Emporio, Near Star Bazar, Satellite, Ahmedabad, Gujarat 380015, India
Email: janak@devopstechlab.com
Phone: +91 88492 50274
Questions
Questions about your data?
Write to us and we’ll reply.
Requests about your personal data.
janak@devopstechlab.com
See also our Terms of use and service.







