Global Privacy Policy
Effective Date: January 1, 2026 • Last Updated: July 20, 2026
Our Commitment to Privacy & Data Sovereignty
Viraat Systems ("we", "us", or "our") operates as a global software development and artificial intelligence engineering agency. We adhere strictly to global data protection laws, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and international ISO/IEC 27001 security standards. We do not sell, rent, or monetize your personal data under any circumstances.
1. Scope of This Policy
This Privacy Policy applies to all information collected through our official website (www.viraatsystems.com and subdomains), interactive tools, customer portals, discovery sessions, email communications, and job application processes. It outlines what personal data we collect, why we collect it, how we safeguard it, and your statutory rights regarding your information.
2. Information We Collect
We collect personal information through two main mechanisms: data you explicitly provide to us, and technical data automatically recorded when you navigate our site.
A. Information Provided Voluntarily
- Contact & Sales Inquiries: Full name, professional work email address, telephone number, job title, company name, project requirements, and budget specifications submitted via our contact forms or strategy call bookings.
- Interactive Tools & Calculators: Inputs provided into interactive tools (e.g. project estimators, WHO growth calculators) are processed client-side or temporarily in-memory to generate calculations and are not retained long-term for identity profiling.
- Career Applications: Resume/CV, work history, educational credentials, GitHub/LinkedIn profile URLs, and contact details submitted through our careers portal.
- Client Project Assets: Source code, technical documentation, API keys, and business logic shared under mutual Non-Disclosure Agreements (NDAs) for custom engineering projects.
B. Information Collected Automatically
- Device & Network Identifiers: IP address, operating system, browser type and version, language preferences, and referral URLs.
- Telemetry & Usage Patterns: Time spent per page, click-stream paths, error logs, and performance metrics collected to optimize site speed and Core Web Vitals.
3. Legal Bases for Processing (GDPR Article 6)
We process your personal data under the following recognized legal grounds:
- Contractual Necessity (Art. 6(1)(b)): To execute Master Services Agreements (MSAs), Statements of Work (SOWs), or preliminary technical consultations requested by prospective clients.
- Legitimate Interests (Art. 6(1)(f)): To maintain web security, prevent cyber threats, analyze infrastructure load, and communicate enterprise updates to B2B contacts.
- Consent (Art. 6(1)(a)): Where you explicitly subscribe to technical whitepapers, newsletters, or accept non-essential performance cookies.
- Legal Obligation (Art. 6(1)(c)): Compliance with tax, accounting, anti-fraud, and corporate regulatory obligations.
4. Cookies & Tracking Technologies
We use cookies and similar browser storage mechanisms to enhance user experience, remember theme preferences (dark/light mode), and analyze web performance.
Cookie Categories Used:
- Essential Cookies: Required for site navigation, theme state, and security routing.
- Preference Cookies: Store dark mode settings and regional unit preferences.
- Performance Cookies: Anonymous telemetry to measure page load speeds and server performance.
You can manage or disable cookies at any time through your web browser settings. Disabling essential cookies may affect site styling or interactive functionality.
5. Third-Party Data Sharing & Sub-Processors
We do not sell, trade, or lease personal information to advertising brokers. We share data only with verified sub-processors who provide critical infrastructure services under strict Data Processing Agreements (DPAs):
- Cloud Infrastructure Providers: Hostinger, Amazon Web Services (AWS), Vercel (for secure web hosting and CDN content delivery).
- Customer Relationship & Communications: Enterprise email servers and transactional API gateways (TLS-encrypted).
- Analytics Services: Privacy-focused web analytics operating on anonymized IP hashes.
6. International Data Transfers & Security Controls
As a global technology company with engineering hubs in India, the USA, and Europe, data may be transferred across international borders. All transfers adhere to EU Standard Contractual Clauses (SCCs) and robust technical safeguards:
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public web endpoints and API calls.
- Encryption at Rest: AES-256 bit encryption for databases and backup storage vaults.
- Access Control: Strict Zero-Trust, role-based access control (RBAC) and Multi-Factor Authentication (MFA) across internal engineering environments.
7. Data Retention Guidelines
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or satisfy legal compliance mandates:
- Sales & Technical Inquiries: Retained for up to 3 years from the date of last contact if no contract is signed.
- Client Contractual Records: Retained for 7 years post-project completion for accounting, tax, and MSA compliance auditing.
- Job Applications: Retained for up to 2 years with applicant consent for future engineering roles.
8. Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your geographic jurisdiction, you hold the following statutory rights regarding your personal information:
9. Contact & Data Protection Officer (DPO)
To exercise any of your privacy rights or submit questions regarding data protection practices, contact our Privacy Officer:
Knowledge Park V, Greater Noida West, Uttar Pradesh 201306, India
Email: connect@viraatsystems.com
Phone: +91 9355-789-001