Advanced Technology Engineering
HOW WE HANDLE INFORMATION — THE SHORT VERSION IS "WE DON'T, UNLESS YOU ASK US TO"

Privacy policy
in plain language.

This is the whole policy, not a summary of a longer one. Two facts explain most of it: this website collects almost nothing, and when we operate your systems, your data is yours under contract — we touch what the job needs and nothing else. Where law gives you rights, this page tells you how to use them.

updated — October 2026
grievance — via the contact page
law — India's DPDP Act 2023

What the website collects

This website is static. It sets no cookies, places no advertising or social trackers, loads no third-party analytics, and fingerprints nothing. Your visit does not create a profile, is not logged into an advertising graph, and is not shared with anyone.

The only records that exist are operational: web-server access logs (IP address, requested page, timestamp — what every working server needs to be debugged and defended) and anything you deliberately give us — an email sent via the contact page, a conversation, a project document you attach. That correspondence lives in our mailbox systems for as long as the conversation is live, and afterward for legal and business-record purposes we consider reasonable. If a future version of this site adds anything that tracks, this page changes before it ships — not after.

For individuals — your rights, and how to use them

Under India's Digital Personal Data Protection Act 2023 (and any other regime that applies to us by operation), you may ask us to confirm what personal data we hold about you, correct anything wrong, and erase what we have no lawful reason to keep. You may nominate someone to exercise these rights on your behalf, and you may withdraw consent for any processing that rested on consent. Requests go to the person your engagement already has a line to, through the contact page; we respond without undue delay and within the statutory timelines. Grievances are handled by the same door — we would rather you reached us first than an authority.

Children: we do not knowingly collect personal data from anyone under 18. If we discover we have, it is deleted on learning of it.

When we run your systems — the operational distinction

In managed and consulting engagements you are the data fiduciary (controller); we act as a processor strictly on your documented instructions. Practically, this means: we access personal data only as the service description requires; we keep it within the geography your contract names; we do not train models on it, sell it, broker it, or fold it into products. A device inventory you hand us stays a device inventory. If we need to touch a dataset in a new way, that is a change to the service description and it reaches you before it reaches production.

Email, telemetry, and the systems we watch

Because we operate mail and monitoring for others, we describe our own handling plainly: mail we host is stored to serve delivery; it is not scanned to build advertising profiles, ever. Monitoring telemetry we generate (metrics, logs, incident records) describes machines, not people — and where it can describe a person (a login, a mailbox event), it exists to run the contract and ages out on the retention schedule stated in that contract.

Third parties we work with

We use a small list of processors where a service cannot be self-hosted — payment providers, mail transit, cloud infrastructure where named in your contract. Each is bound contractually to handle data only as we both agree it should be handled. Beyond that list, personal data is not sold, rented, or handed over; where law compels disclosure, we give the minimum the order demands and — unless gagged — tell you first.

Retention and deletion

We keep what an engagement requires and delete what no longer does. Correspondence: conversation-life plus reasonable legal retention. Project deliverables: held by you; ours in working copies expire per contract. Backups age out on their schedule — no data is promised to vanish from a backup in less time than the rotation takes, and we will show you that rotation if you ask.

Incidents

If personal data is compromised in anything we operate, you will hear from us without undue delay — never later than applicable law requires — with the honest scope of what happened and what we are doing about it. Where the breach touches your users and law assigns notification to you as fiduciary, we hand you everything needed to make your notification accurate and complete. We do not use delay to shape the story.

Changes to this policy

Material changes are posted here with a new date, and for anyone with a live engagement, by email before they take effect. Non-material clarifications may go up as they are written. This page is the policy of record; nothing else you've been sent competes with it unless your engagement contract says so.

Questions, corrections, grievances

the contact page, one door, human on the other end — no queue number. The related page — terms, acceptable use, liability, the rest of it — is here.

Printed honestly: written by engineers. Before binding real data flows, counsel should read it against the actual processing footprint and entities of each engagement — and once contracts name us as processor, this page becomes the public face of what those contracts promise.