TRANSPARENCY
AND DATA INTEGRITY.
EthosCore is built on principles of architectural rigor and confidentiality. We treat client information, source code, and user telemetry with zero-trust security standards.
Core Privacy Principles
At EthosCore (“EthosCore”, “we”, “us”, or “our”), we recognize that trust is the foundation of high-consequence software engineering. We believe privacy is an architectural requirement, not a legal afterthought.
This Privacy Policy defines how we collect, process, isolate, and safeguard data when you visit our website (ethoscore.in), communicate with our engineering teams, or engage us to design, architect, and deploy software systems.
We do not sell, rent, broker, or trade client inquiries, contact details, or technical specifications to third-party ad networks.
Client repositories, proprietary logic, schemas, and staging instances remain air-gapped between customer engagements.
Information We Collect
We restrict data collection to the minimum required to fulfill technical consultations and maintain reliable infrastructure:
- Inquiry & Consultation Intake:When you submit our contact or architecture consultation form, we collect your name, corporate email, phone number, company name, approximate budget bracket, and project brief.
- Technical Telemetry & Server Logs:Standard HTTP request metadata such as IP address (anonymized where possible), browser user-agent, operating system, referring URL, and timestamp to monitor DDoS attempts and maintain network security.
- No Invasive Third-Party Trackers:We avoid invasive tracking pixels, social media remarketing beacons, or fingerprinting scripts. We prioritize privacy-respecting analytics for operational performance.
Client Project Data & Intellectual Property
In our capacity as a bespoke software engineering agency, we frequently interact with sensitive client specifications, trade secrets, database schemas, and proprietary business logic.
Under all contractual agreements:
- Client data and codebases are processed solely for the delivery of agreed software development milestones.
- Client code is never ingested into public AI model training sets or external unvetted third-party services.
- Access to client production databases is governed strictly by the Principle of Least Privilege (PoLP) and multi-factor authentication.
- All proprietary IP, business rules, and customer end-user records remain the exclusive property of the client.
How We Use Collected Information
We process collected information under legitimate business interests and contract fulfillment:
- Direct technical evaluation, scoping calls, and sending proposals or engineering estimates.
- Executing Statements of Work (SOWs), master services agreements, and milestone deliverables.
- Security monitoring, spam prevention, and safeguarding our web applications against malicious attacks.
- Fulfilling legal, tax, and regulatory compliance obligations under applicable law.
Infrastructure & Sub-Processors
We host our marketing website and deploy engineering systems using enterprise-grade infrastructure providers that adhere to ISO 27001, SOC 2 Type II, and GDPR compliance standards:
| Provider | Purpose | Data Location | Security Level |
|---|---|---|---|
| Vercel Inc. | Edge Web Application Hosting & CDN | Global Edge Network | SOC 2 / ISO 27001 |
| Cloudflare / AWS | DNS, TLS & DDoS Mitigation | Global Anycast | SOC 2 / PCI-DSS |
| Transactional Email (Resend) | Inquiry dispatch & notification delivery | US / EU | TLS 1.3 / Encrypted |
Data Retention & Deletion
We retain communication records only for as long as required to maintain project history, satisfy statutory tax and accounting regulations, or resolve contractual queries.
Upon completion or termination of an active engineering retainer, non-essential temporary development artifacts, staging database snapshots, and test API credentials are decommissioned according to our structured offboarding procedure.
Your Rights & Grievance Redressal
Regardless of your geographic location, EthosCore provides rights in accordance with the Digital Personal Data Protection Act (DPDP India) and GDPR principles:
- Right to Access: You can request a summary of the personal information we hold about you.
- Right to Rectification: You may correct inaccurate or incomplete contact records.
- Right to Erasure: You can request the removal of your contact details from our active outreach systems.
Privacy Office Contact
For privacy inquiries, data deletion requests, or data processing agreements (DPA), please reach our privacy and governance team directly: