Privacy Policy — Your Privacy Matters to Us

    Last updated: August 15, 2025

    This Privacy Policy explains how Bug&Build (operated by copyright © Bugandbuild Technologies LLP, referred to as “we”, “us”, “our”, or the “company”) handles your personal information when you visit our website, contact us, or use our services. It applies to website visitors, prospective and current clients, vendor contacts, and others who interact with us globally. Please read it to understand what we collect, why we collect it, how we use and share it, and the choices you have.

    1) Who We Are & Our Role

    We may act as:

    • Controller — for data we collect through our Website and our own business operations.
    • Processor — when a client asks us to handle personal information on their instructions to deliver Services.

    Key terms: "Personal Data" means information that identifies or can reasonably identify you. "Processing" means any operation on Personal Data (collecting, using, storing, sharing, etc.).

    2) Information We Collect

    We collect information you provide directly to us, information collected automatically through your use of the Website, and information from third-party sources we work with to run our business. Examples include:

    Information you provide (for example):

    • Contact details (name, email, phone, organization, role)
    • Project or inquiry details, files you share with us
    • Account or portal details (if enabled)
    • Billing/contact details (note: payments are processed by third-party providers; we don't store full card data)

    Information collected automatically (for example):

    • Device and usage data (IP address, browser/OS type, pages viewed, time on page, referrer, approximate location)
    • Cookies and similar technologies

    Information from third parties (for example):

    • Analytics, support, error monitoring, identity/sign-in tools
    • Leads or referrals from partners or publicly available sources

    Please avoid sending sensitive personal data unless we specifically request it for a defined purpose.

    3) How We Use Information

    We use your information to operate our Website and business, respond to you, deliver and improve our Services, meet legal requirements, and protect users and systems. Common uses include:

    • Respond to inquiries, provide quotes, and deliver Services
    • Operate, secure, and improve the Website and our internal systems
    • Send service and administrative messages; marketing where permitted (you can opt out anytime)
    • Meet contractual, tax, and legal obligations
    • Prevent, detect, and investigate fraud, abuse, or security incidents

    Where required (e.g., EU/UK), our legal bases include consent, contract performance, legal obligation, and legitimate interests. We do not make decisions based solely on automated processing that have legal or similarly significant effects.

    If you receive marketing from us, you can unsubscribe at any time by contacting us.

    4) Cookies & Your Choices

    We use cookies to run the site, remember preferences, analyze usage, and (if enabled) support marketing. Non-essential cookies run only with your consent.

    • Manage your preferences through your browser controls.
    • We honor Global Privacy Control (GPC) where required. We currently do not respond to browser "Do Not Track" signals.

    5) Sharing Information

    We do not sell or share your personal information as defined by CPRA.

    We may share information with:

    • Service providers that support our work such as secure project management tools, source control platforms, cloud infrastructure partners, or analytics providers — all bound by confidentiality and data-protection obligations.
    • Professional advisors (legal, accounting, insurance) under confidentiality
    • Authorities or third parties when required by law, to protect rights or safety, or in response to lawful requests
    • Business transfers (e.g., merger/acquisition), subject to applicable law

    6) International Transfers

    Because we serve clients globally and use technology partners, your information may be processed in countries other than your own. Where required:

    • For EEA data, we use the EU Standard Contractual Clauses (2021).
    • For UK data, we use the UK IDTA/Addendum.

    We perform transfer impact assessments and apply additional safeguards where appropriate.

    7) Security

    We take security seriously across our development and delivery practices. We maintain safeguards such as:

    • Use of secure development environments and version control systems
    • Access controls and role-based permissions for code repositories and project data
    • Encryption of communications and secure transfer of client files
    • Regular reviews of third-party tools and vendor security
    • Internal guidelines for responsible handling of client data and project materials

    Where we provide login access, please use a strong, unique password and keep it confidential.

    No method is 100% secure. If you suspect unauthorized use or a breach, please contact us immediately.

    8) Retention

    We keep personal data only as long as needed for the purposes above. We consider the type of data, why it was collected, our legal and contractual duties, and potential risks from keeping or deleting it. Examples:

    • Leads & general inquiries: up to 24 months of inactivity
    • Contracts & invoices: up to 8 years
    • Support tickets: up to 24 months after closure
    • Project artifacts (client work): up to 12 months after the end of the engagement

    9) Your Rights

    Your rights depend on where you live. Subject to law, you may have the right to access, correct, delete, restrict or object to processing, obtain a copy (portability), and withdraw consent.

    We may ask you to verify your identity before we act on your request. If you use an authorized agent (where permitted), we may require proof of authorization.

    To exercise rights, contact us. We'll respond within timelines required by applicable law.

    10) When We Act as a Processor (Clients)

    When we process personal information on a client's instructions, we follow the client's documented directions, impose equivalent obligations on our service providers, assist with data-subject requests and security incidents, and delete or return personal information at the end of the engagement.

    11) Use of AI-Enabled Tools (If Applicable)

    We may use vetted AI-enabled tools to assist with drafting, quality checks, or code suggestions. We do not ingest client-confidential data into such tools without client approval and we enforce contractual data-use restrictions with relevant providers.

    12) Children

    Our Website and Services are not intended for individuals under 18. We do not knowingly collect data from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

    13) Third-Party Links

    Our Website may link to third-party sites. Their privacy practices are governed by their own policies. Please review those before providing any information.

    14) Breach Notification

    Where required by law, we will notify regulators without undue delay (and within 72 hours under GDPR, where applicable) and affected individuals when a breach is likely to result in a high risk to their rights and freedoms. When acting as a processor, we notify the client controller without undue delay.

    15) Changes to This Policy

    We may update this Policy from time to time. The "Effective date" and Version above show the latest revision. If we make material changes, we will post a prominent notice on this page and update the Effective date. For significant updates, we may also notify you if we have your contact details.