Who we are
Bytevolve (“Bytevolve”, “we”, “us”) is a web design and software studio operating from India on a remote-first basis. For personal data collected through bytevolve.com, we act as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
Questions about this policy or your personal data: email hello@bytevolve.com or use our contact form.
Scope and the law we follow
This policy covers digital personal data we process when you visit bytevolve.com, submit an enquiry or booking, manage cookie preferences, or otherwise interact with our online services from India or while we offer goods or services to people in India.
We process personal data in line with the DPDP Act and rules notified under it. Where another country’s law also applies to you, we will honour that law to the extent it requires stricter handling.
What we collect and why
Enquiry and booking forms may collect your name, email address, company, phone number (if you share it), website URL, and the message or slot you submit. We use this to reply to you, qualify the request, and keep a record of the conversation — a purpose you initiate when you contact us.
Form submissions can trigger an internal email and a workspace notification so our team can respond quickly. That processing stays limited to handling your enquiry.
Analytics and tags: with your consent where required, we may use tools such as Google Tag Manager, OpenPanel, Google Analytics, advertising measurement tags, HubSpot, or Microsoft Clarity to understand how the site is used (pages viewed, events, and form completion). Essential cookies power hosting, security, fonts and storing your consent choice.
Hosting and delivery: the site and related infrastructure may run on providers such as Vercel or equivalent hosts. Email confirmations may be sent through a transactional email provider. Each provider processes data under a contract or terms that restrict use to providing their service.
Notice, consent and legitimate use
Before or at the time we ask for personal data, we aim to give a clear notice of what we collect, the purpose, how you can exercise rights, and how to reach our grievance channel.
Where the DPDP Act requires consent, we ask for it freely, for a specific purpose, in plain language, and without bundling it with unrelated conditions. You may withdraw consent as easily as you gave it; withdrawal does not affect processing already completed lawfully.
We may process personal data without fresh consent where the DPDP Act allows “legitimate use” — for example, responding to an enquiry you started, complying with law or court orders, employment-related processing for our team, or other uses expressly listed in the Act — and only for those purposes.
What we do not do
We do not sell personal data. We do not use enquiry details for third-party advertising without a lawful basis and, where required, your consent. We do not send marketing email to enquiry addresses without asking first. We do not knowingly profile children for targeted advertising.
Children’s data
Our services are aimed at businesses and professionals. We do not knowingly offer the site or collect personal data from children under 18 in a way that requires verifiable parental consent under the DPDP Act.
If you believe a child has shared personal data with us, contact hello@bytevolve.com. We will delete or restrict that data as required once we can verify the request.
Sharing and cross-border transfers
We share personal data with processors who help us run the site and respond to you (hosting, email, analytics, CRM), only as needed for those purposes and under arrangements that require appropriate safeguards.
Personal data may be processed on servers outside India when a provider’s infrastructure requires it. We transfer data only to countries that are not restricted by the Central Government under the DPDP Act, and we keep processing aligned with the purpose you were told about.
Retention
We keep personal data only for as long as needed for the purpose it was collected, or as required by law. Enquiry correspondence is typically kept while we work together and for up to 24 months after the last contact, then deleted or anonymised.
Analytics and cookie logs follow the retention settings of each tool and your consent state. When the purpose is complete and no legal hold applies, we erase or de-identify the data.
Security safeguards
We apply reasonable security safeguards to prevent personal data breach — including access controls, encrypted transport where appropriate, least-privilege access for staff and contractors, and vendor diligence for processors.
If a personal data breach is likely to cause harm, we will take steps required under the DPDP Act, including notifying the Data Protection Board of India and affected Data Principals where mandated.
Your rights
As a Data Principal under the DPDP Act, you may request:
- A summary of personal data we hold about you and the processing activities involved
- Correction, completion or updating of inaccurate or incomplete personal data
- Erasure of personal data that is no longer needed for the stated purpose, subject to legal exceptions
- Withdrawal of consent where processing is based on consent
- Grievance redressal through the channel below
- Nomination of another individual to exercise rights on your behalf in case of death or incapacity, where the Act provides for it
Email hello@bytevolve.com or use our contact form. We will respond within the timelines set under the DPDP Act and rules (and in any case without undue delay). You may also escalate unresolved grievances to the Data Protection Board of India as provided by law.
Grievance redressal
Grievance Officer: Kamran Akhtar, Founder, Bytevolve.
Email: hello@bytevolve.com (subject line: “DPDP grievance”). We acknowledge grievances and aim to resolve them within the period prescribed under applicable DPDP rules. If you are not satisfied, you may approach the Data Protection Board of India.
Accuracy and your duties
We take reasonable steps to keep personal data accurate for the purposes we stated. Please send corrections when your details change.
Under the DPDP Act, Data Principals must not impersonate another person, suppress material information while providing personal data for a document or benefit, or file false or frivolous grievances. We may refuse or limit requests that appear abusive or unlawful.
Changes to this policy
We may update this privacy policy when our practices, tools or the law change. The “Last updated” date at the top will change when we publish a revision. Material changes will be highlighted on this page or, where appropriate, by notice on the site.
Contact
Bytevolve — privacy and data requests: hello@bytevolve.com. Postal or video meetings can be arranged on request for active clients. Prefer the contact form if you do not wish to email directly.