Firefinch Studios
Effective Date: January 1, 2025
verified Revision 3.4 • India IT Act 2000 & GDPR Compliant

Privacy Policy & Data Governance

At Firefinch Studios (operating as Firefinch Studios India), computational elegance meets zero-surveillance architecture. We engineer client digital properties, bespoke web applications, and high-performance server edge setups with strict confidentiality, isolated data silos, and transparent operational ethics.

no_encryption_gmailerrorred
Zero Log
No Data Monetization
We never sell, broker, or trade client telemetry or visitor habits to third parties.
lock
256-Bit TLS
Strict Transport Security
End-to-end encrypted in-flight data via modern TLS 1.3 cryptographic suites.
shield
Legal Parity
GDPR & DPDP Ready
Full alignment with India Digital Personal Data Protection Act & EU GDPR standard clauses.
history_toggle_off
30-Day Cycle
Rolling Backups
Hardened point-in-time snapshots with zero lingering unencrypted redundant storage.
01

Information Collection & Client Data

When entering an engagement with Firefinch Studios, we collect minimum required professional data to execute web engineering contracts. This includes:

  • Design & Brand Assets: Vector source files, proprietary copy, and prototype credentials transmitted to our sandboxed repositories.
  • Contact & Administrative Identifiers: Authorized corporate contact persons, invoicing postal address, corporate tax ID (GST/PAN), and administrative billing email.
  • Domain Registration & DNS Handling: Domain WHOIS privacy proxy settings applied systematically to shield customer identities from public lookup scrapers where supported by registrar registries.

All production secrets, staging tokens, and environment parameters shared during active build sprints are stored exclusively in zero-knowledge encrypted credential vaults.

02

Website Hosting, Logs & Analytics

For our direct properties and managed client cloud workloads, we practice edge-first performance without invasive telemetry footprints.

Server Access Records

Edge gateways log IP addresses in anonymized hash format strictly for rate-limiting, DDoS mitigation, and traffic anomaly inspection. Uncompressed raw request logs auto-purge within 7 days.

Telemetry Without Fingerprinting

Our internal performance monitors track purely aggregated page weight, core web vitals, and HTTP response codes without harvesting canvas fingerprints, cross-site IDs, or hardware identifiers.

03

Third-Party Services & Integrations

To maintain global reliability and uninterrupted deployment pipelines, Firefinch Studios selectively partners with top-tier infrastructure providers bound by rigorous data-handling terms:

  • DNS & Content Delivery: Cloudflare Edge & AWS Route 53
    Anycast Global Routing
  • Certificate Authorities: Let's Encrypt & DigiCert Root CAs
    Automated ACME Rotations
  • Transactional Gateways: Postmark & Amazon SES
    Strict DKIM / SPF / DMARC
04

Cookies & Tracking Technologies

Firefinch Studios enforces a strict zero-tracker policy across its public showcase platform.

check_circle What We Set: Essential Session Tokens Only

We deploy only strictly essential ephemeral cookies required for theme resolution (dark/light preference persistence) and CSRF protection against cross-site form forgery.

cancel What We Never Set: Advertising Pixels & Third-Party Ad Trackers

Zero Meta/Facebook pixels, zero Google Ads cross-network beacons, zero commercial retargeting scripts. You browse in peace.

05

Data Security, Backup & Retention

Enterprise infrastructure demands multi-layered hardware boundaries and verified persistence mechanics:

Encrypted NVMe
Physical drives operate with AES-XTS-256 baseline hardware encryption at rest.
Isolated Sandbox
Client runtime environments are segmented via container virtualization and RBAC rules.
30-Day Rotation
Automated rolling snapshots cycle every 24 hours and permanently decommission on day 31.
06

User Rights & Data Subject Access

Regardless of your geography, we guarantee fundamental digital sovereignty. You possess the following rights regarding any data associated with your interaction:

Right to Access: Request a human-readable digest of all client records held in our systems.
Right to Rectification: Immediately correct out-of-date billing, contact, or operational information.
Right to Erasure: Execute complete project purge and repo scrub post contract completion.
Right to Portability: Direct export of raw source codes, assets, and SQL schemas with zero lock-in.
07

Inquiries & Data Protection Officer Contact

For inquiries regarding this privacy charter, formal rights exercise requests, or data vulnerability disclosures, please coordinate directly with our designated Data Protection Officer:

Legal Governance & Compliance Team
Firefinch Studios India
Official Response SLA: Within 48 Business Hours
mail [email protected]