Your privacy matters
to us

We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data. This policy explains what information we gather, why we collect it, and how we keep it secure when you interact with our website and services.

Effective 01 January 2026 Governing law Bangalore, India Version 3.0
Effective date · 01 January 2026 · Version 2.1
Summary

Sitefiy ("Sitefiy," "we," "us," or "our") respects your privacy. This policy explains what personal data we collect, why we collect it, how it is used, and your rights over it. We will never sell your data to third parties.

01 - Overview

Who we are

Sitefiy is a digital product studio incorporated in India, with its registered office at Ardente Office One, Hoodi,Bangalore - 560048. We design and build websites, web applications, mobile apps, and digital experiences for clients worldwide.

This Privacy Policy applies to information collected via our website at Sitefiy, through our client onboarding processes, via email and communication channels, and during the delivery of our professional services. By accessing our website or engaging our services, you agree to the terms described herein.

02 - Data We Collect

Information collected

We collect information in two ways: data you provide directly to us, and data collected automatically when you visit our website.

CategoryExamplesSource
Identity DataName, job title, company nameContact forms, calls
Contact DataEmail address, phone number, WhatsApp IDContact forms, email
Project DataBrief descriptions, budgets, requirements, files sharedIntake forms, meetings
Financial DataInvoice details, payment references (no card data stored)Agreements, invoices
Technical DataIP address, browser type, OS, referrer URLAnalytics, server logs
Usage DataPages visited, session duration, click pathsAnalytics tools
Communication DataEmail/chat history, meeting notes, feedbackCorrespondence
What we do not collect

We do not collect sensitive personal data (health, biometric, political, or religious data). We do not store payment card numbers - all payments are processed via third-party gateways (Razorpay / Stripe) subject to their own privacy policies.

03 - How We Use It

Purpose of processing

  • To respond to enquiries and provide pre-sales consultation
  • To onboard clients and deliver contracted services
  • To send project updates, invoices, and legal documents
  • To improve our website experience and identify technical issues
  • To comply with applicable Indian laws, tax regulations, and legal obligations
  • To send marketing communications where you have given consent (opt-out any time)
  • To protect against fraud, abuse, and unauthorised access

We rely on the following legal bases: Contract performance (fulfilling our service agreement), Legitimate interest (improving our services, fraud prevention), Legal obligation (tax, regulatory compliance), and Consent (marketing emails).

04 - Sharing & Disclosure

Who sees your data

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

RecipientReason
Sub-contractorsVetted freelancers/partners bound by NDA who assist on your project
Payment processorsRazorpay / Stripe - for secure payment processing only
Cloud infrastructureAWS / GCP / Vercel - for hosting client deliverables and our own systems
Analytics providersGoogle Analytics (anonymised) - website performance insights
Legal / regulatorsWhen required by law, court order, or government authority
05 - Cookies

Cookies & tracking

Our website uses cookies - small text files placed on your device. Here is what we use and why:

Cookie TypePurposeDuration
Strictly NecessaryCore website functionality, securitySession
PerformanceGoogle Analytics - anonymised traffic dataUp to 2 years
PreferenceRemembering your settings (e.g. reduced motion)1 year
MarketingOnly if you opt in; remarketing via Google / Meta90 days

You can manage cookie preferences via your browser settings. Blocking strictly necessary cookies may impair website functionality. For Google Analytics opt-out, visit Google's opt-out page.

06 - Retention

How long we keep it

We retain personal data only as long as necessary for the purpose it was collected, or as required by law:

Data TypeRetention Period
Project & contract records7 years (Indian Companies Act requirement)
Financial / invoice records8 years (GST and tax compliance)
Enquiry / contact form data2 years from last interaction
Marketing consent recordsUntil consent is withdrawn + 1 year
Website analytics (anonymised)26 months
Server access logs90 days
07 - Security

How we protect your data

  • All data transmitted over TLS 1.3 encryption
  • Data at rest encrypted using AES-256
  • Access to client data restricted to named team members on a need-to-know basis
  • Multi-factor authentication enforced on all internal systems
  • Annual third-party security audits of our infrastructure
  • All sub-contractors and staff sign confidentiality agreements
  • Incident response plan in place; we will notify you within 72 hours of any confirmed breach affecting your data
08 - Your Rights

Control over your data

Under the Digital Personal Data Protection Act 2023 (India) and, where applicable, the GDPR (UK/EU clients), you have the following rights:

Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data (subject to legal retention obligations).
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Withdraw marketing consent at any time with no penalty.

To exercise any right, email privacy@Sitefiy. We will respond within 30 days. Identity verification may be required before we can act on a request.

09 - International Transfers

Cross-border data flows

As a studio serving global clients, some of your data may be processed outside India - for example, on cloud servers located in the EU or USA. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required by GDPR, and data processing agreements with all third-party processors.

UK and EU clients: Sitefiy's London partner office serves as a point of contact for EU/UK data protection matters. Transfers from the EEA to India are conducted under Article 46 GDPR mechanisms.

10 - Children's Privacy

Under 18s

Our website and services are directed at business professionals and are not intended for children under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently received data from a minor, please contact us immediately at privacy@Sitefiy and we will delete it promptly.

11 - Policy Changes

Keeping you informed

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will notify existing clients directly via email at least 14 days before the change takes effect. Continued use of our website or services after any update constitutes acceptance of the revised policy.

12 - Contact & DPO

Privacy enquiries

For any questions, requests, or concerns regarding this policy or our data practices, please reach out to our Privacy team:

Data Protection Contact
info@sitefiy.com
Registered Address
Sitefiy, Ardente Office One, Hoodi,Bangalore - 560048

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India (for Indian residents) or your relevant supervisory authority (for EU/UK residents).