Summary of Our Privacy Commitments
BigBurry Hypersystems LLP ("BigBurry", "we", "us", or "our") respects your privacy. We collect minimal personal information necessary to deliver software solutions, communicate with prospective and active clients, operate our portfolio products, and maintain infrastructure security. We never sell your personal data.
1. Introduction & Scope
This Privacy Policy outlines how BigBurry Hypersystems LLP, an Indian Limited Liability Partnership incorporated under the LLP Act, 2008 with its principal place of business at Angamaly, Kerala, India, collects, uses, processes, stores, and safeguards personal information obtained through our website (bigburry.com), corporate communications, product platforms, and software engineering services.
By visiting our website or submitting technical enquiries, you acknowledge the terms set forth in this Policy. If you do not agree with this policy, please refrain from providing personal information.
2. Information We Collect
We collect information across the following categories:
- Direct Inquiries & Communications: When you submit a form or email us at hello@bigburry.com, we collect your full name, work email address, company/organization name, project timeline, area of technical interest, and project requirements.
- Client Engagement Data: For contracted engineering engagements, we collect authorized stakeholder contact information, billing coordinates, and system credentials provided under non-disclosure agreements.
- Technical & Telemetry Data: Standard server access logs, IP addresses (anonymized), browser user-agent strings, referring URLs, operating system metadata, and interaction timestamps necessary for DDoS mitigation and performance diagnostics.
3. How We Use Information
We process collected data exclusively for explicit, legitimate business purposes:
- Evaluating project requirements, technical feasibility, and preparing structured engineering proposals.
- Fulfilling contracted software design, full-stack architecture, deployment, and SLA maintenance obligations.
- Facilitating administrative billing, contract governance, and mutual NDA execution.
- Ensuring network security, detecting malicious intrusion attempts, and maintaining continuous uptime across our systems.
- Complying with statutory reporting obligations under applicable Indian and international laws.
4. Legal Basis for Processing
Under the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (GDPR, EU), we process personal data under the following legal bases:
- Consent: Freely given consent when you submit an enquiry through our contact portal.
- Contractual Necessity: Performance of pre-contractual scoping or execution of software development agreements.
- Legitimate Interests: Protecting our infrastructure, verifying enterprise clients, and preventing fraudulent activity.
- Legal Compliance: Satisfying statutory audit, taxation, and regulatory mandates.
5. Sharing & Third-Party Disclosures
We do not sell, rent, or monetize your personal information. We only share information with trusted third-party service providers bound by strict data processing and confidentiality agreements:
- Cloud Infrastructure Providers: AWS, Google Cloud Platform, and Vercel for secure application hosting and database operations.
- Enterprise Email & SMTP Gateways: Secure mail transfer protocols for delivering enquiry notifications.
- Statutory Authorities: If required by a court order, subpoena, or lawful request from government law enforcement agencies.
6. Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by statutory retention requirements (e.g., tax and financial audit records retained for up to 7 years). Technical inquiry logs are purged or anonymized within 24 months of communication closure if no contract is established.
7. Information Security
We maintain multi-layered technical and organizational safeguards designed to protect personal data against unauthorized access, destruction, alteration, or disclosure:
- All web traffic and API endpoints are encrypted in transit using TLS 1.3.
- Data at rest within our production databases is encrypted using AES-256.
- Role-based access control (RBAC) and mandatory multi-factor authentication (MFA) across all administrative engineering systems.
8. Your Privacy Rights
Depending on your jurisdiction, you possess the following statutory rights regarding your personal data:
- Right of Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data records.
- Right to Erasure: Request permanent deletion of personal data when no longer required for legal obligations.
- Right to Restriction & Objection: Object to or restrict specific processing activities.
To exercise any of these rights, email your request to hello@bigburry.com. We respond to all verified requests within 30 days.
10. Grievance Redressal & Contact Information
For questions, concerns, or grievance redressal regarding this Privacy Policy or our data handling practices, please contact our designated Privacy and Compliance Office:
Attn: Privacy & Data Protection Officer
Headquarters: Angamaly, Kerala, India
Official Email: hello@bigburry.com
Corporate Website: bigburry.com
