Devlex Infotech ("Devlex", "we", "us", or "our") respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what choices you have. It applies to visitors of devlexinfotech.com and related pages, prospective clients, active clients, job applicants, and anyone who communicates with us.
1. Who We Are
Devlex Infotech is a software development and IT services company founded in 2020, headquartered in Ahmedabad, India. We design, build, and maintain web applications, mobile apps, cloud infrastructure, enterprise software, and AI solutions for clients worldwide.
For the purposes of applicable data protection laws, Devlex Infotech acts as the data controller for personal information collected through this website and for pre-contract communications. When we process personal data on behalf of a client during a project, we act as a data processor and the client's agreement governs that processing.
- Headquarters: B-704, Titanium Business Park, S.G. Highway, Ahmedabad, Gujarat 380015, India
- Privacy contact: devlexinfotech@gmail.com
- Phone: +91 94282 18678
2. Scope of This Policy
This policy covers personal information we collect through our website, contact forms, email, phone, video calls, proposals, contracts, careers applications, and other business communications. It does not cover third-party websites, apps, or services that we do not control, even if linked from our site.
If you are an employee or contractor of one of our clients and your data is processed inside software we built for that client, please contact that client directly. We process such data only under our client's instructions.
3. Information We Collect
We collect only the information needed to respond to inquiries, deliver services, improve our website, comply with law, and manage recruitment. The categories below are the most common.
- Identity and contact details — name, email address, phone number, company name, job title, and country.
- Project and business information — requirements, budgets, timelines, technical specifications, and files you voluntarily share during discovery or delivery.
- Careers information — résumé/CV, portfolio links, employment history, skills, and interview notes when you apply for a role.
- Communications — messages, meeting notes, support tickets, and call recordings where you have been informed and consented.
- Billing and contractual data — billing address, tax identifiers, purchase order numbers, and payment status. We do not store full payment card numbers on our servers.
- Technical and usage data — IP address, browser type, device type, operating system, referring URLs, pages viewed, and approximate location derived from IP.
- Cookies and similar technologies — as described in the Cookies section below.
We do not intentionally collect sensitive categories of data such as health records, biometric identifiers, government ID numbers, or financial account credentials through our public website forms. If a project requires processing special-category data, that is handled under a separate written agreement with appropriate safeguards.
4. How We Collect Information
- Directly from you when you fill out a form, email us, call us, schedule a meeting, sign a contract, or apply for a job.
- Automatically when you browse our website, through server logs and analytics tools.
- From referral partners or marketplaces only when you have asked to be introduced to us or have consented to that referral.
- From publicly available professional sources such as LinkedIn when recruiting, limited to business contact context.
We do not purchase bulk contact lists, scrape personal data from unrelated sources, or use deceptive data-collection practices.
5. How We Use Your Information
We use personal information for legitimate business purposes, including:
- Responding to inquiries and preparing proposals or statements of work.
- Delivering software development, consulting, support, and related professional services.
- Managing accounts, invoicing, collections, and contractual obligations.
- Providing customer support, incident response, and post-launch maintenance.
- Evaluating job applications and conducting interviews.
- Sending service-related notices, security alerts, and — where permitted — occasional company updates you can opt out of.
- Improving our website, services, security posture, and internal processes.
- Complying with legal, tax, regulatory, and law-enforcement requirements.
- Establishing, exercising, or defending legal claims.
We do not sell your personal information. We do not rent or trade contact details to data brokers or unrelated marketers.
6. Legal Bases for Processing
Where the EU/UK General Data Protection Regulation (GDPR) or similar laws apply, we rely on one or more of the following legal bases:
- Contract — processing necessary to evaluate, negotiate, or perform a contract with you or your organization.
- Legitimate interests — operating and securing our business, communicating with prospects, and improving services, balanced against your rights.
- Consent — for optional marketing emails, non-essential cookies, or other processing where consent is required. You may withdraw consent at any time.
- Legal obligation — retaining records for tax, accounting, or regulatory compliance.
For individuals in India, we process personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules, including honouring your rights to access, correction, erasure, and grievance redressal.
7. How We Share Information
We share personal information only when necessary and with appropriate safeguards:
- Service providers — cloud hosting (e.g., AWS, Azure, Google Cloud), email, CRM, analytics, accounting, and collaboration tools bound by confidentiality and data-processing terms.
- Professional advisers — lawyers, accountants, auditors, and insurers under duty of confidentiality.
- Payment processors — to process invoices. Card data is handled directly by the processor, not stored by us.
- Client-authorised integrations — when you ask us to connect your systems with third-party APIs during a project.
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to notice where required by law.
- Legal and safety — when required by court order, subpoena, or to protect rights, safety, and security.
We require processors to use data only for the services they provide to us and to maintain appropriate security measures.
8. International Data Transfers
Devlex is based in India and serves clients globally. Your information may be transferred to, stored in, or accessed from India, the United States, the European Economic Area, or other countries where we or our service providers operate.
When we transfer personal data across borders, we implement appropriate safeguards such as Standard Contractual Clauses, data-processing agreements, encryption in transit, and access controls. You may request more information about the safeguards applicable to your data by contacting us.
9. Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, unless a longer period is required by law.
- Sales inquiries — typically up to 24 months after last contact, unless an engagement begins.
- Active client records — for the contract term plus up to 7 years for accounting, tax, and dispute records.
- Project artefacts and communications — according to the signed agreement; confidential client data is deleted or returned on request after offboarding.
- Careers applications — up to 18 months unless you ask us to delete sooner or you become an employee.
- Website logs and analytics — generally 12–26 months in aggregated or pseudonymised form.
When data is no longer needed, we securely delete or anonymise it.
10. Security Measures
We apply administrative, technical, and organisational measures aligned with ISO 9001:2015 certified processes and industry good practice, including:
- Encryption in transit (TLS/HTTPS) for website and API traffic.
- Role-based access controls and least-privilege accounts for internal systems.
- Secure development practices — code review, environment separation, and secrets management.
- Regular backups, monitoring, and incident-response procedures.
- NDA and confidentiality obligations for all team members.
No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.
11. Cookies and Similar Technologies
Our website uses cookies and similar technologies to keep the site functional, remember preferences, and understand aggregate traffic patterns.
- Essential cookies — required for navigation, security, and form submission.
- Analytics cookies — help us measure page views and improve content. We use privacy-conscious, aggregate analytics where possible.
- Preference cookies — remember choices such as dismissed banners, where implemented.
We do not use invasive advertising trackers or sell browsing behaviour to ad networks. You can block or delete cookies through your browser settings; essential site features may still work, but some preferences may not be saved.
12. Third-Party Links
Our website may link to third-party sites such as LinkedIn, GitHub, Clutch, or client demos. We are not responsible for the privacy practices of those sites. We encourage you to read their policies before providing personal information.
13. Children's Privacy
Our website and services are directed at businesses and professionals. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact devlexinfotech@gmail.com and we will delete it promptly.
14. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the data we hold about you.
- Correction — ask us to fix inaccurate or incomplete data.
- Deletion — request erasure where we have no lawful reason to retain data.
- Restriction — ask us to limit processing in certain circumstances.
- Portability — receive data you provided in a structured, machine-readable format where applicable.
- Objection — object to processing based on legitimate interests or direct marketing.
- Withdraw consent — where processing is based on consent.
- Complaint — lodge a complaint with your local supervisory authority.
California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of sale or sharing. Devlex does not sell personal information as defined by California law.
To exercise your rights, email devlexinfotech@gmail.com with enough detail for us to verify your identity. We respond within 30 days, or the timeframe required by applicable law. There is no fee unless a request is manifestly unfounded or excessive.
15. Marketing Communications
We may send occasional emails about our services, case studies, or events if you have opted in or have an existing business relationship and applicable law permits. Every marketing email includes an unsubscribe link. Service-related messages — such as contract updates or security notices — are not marketing and may still be sent.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or business changes. The "Last updated" date at the top will change, and material updates may be highlighted on our website. Continued use of the site after changes constitutes acceptance of the revised policy.
17. Contact Us
For privacy questions, requests, or complaints, contact:
- Email: devlexinfotech@gmail.com
- Mail: Devlex Infotech, B-704, Titanium Business Park, S.G. Highway, Ahmedabad, Gujarat 380015, India
- Phone: +91 94282 18678
If you are not satisfied with our response, you may contact the relevant data protection authority in your country. In India, grievances may be raised under the DPDP Act through the Data Protection Board of India once fully operational.