01 Intent & Organizational Scope
OzoStack ("OzoStack Solutions," "we," "our," or "us") operates as a global enterprise custom software engineering firm, digital transformation agency, and artificial intelligence automation partner. We respect the confidentiality of our clients, software users, job applicants, and digital visitors.
This Privacy Policy applies to all data collected via our website (ozostack.io), Statement of Work (SOW) client portals, customer management systems, and software engineering engagement desks. By accessing our services or submitting project briefs, you consent to the data handling practices outlined herein.
02 Categories of Information We Collect
Depending on your interaction with OzoStack, we collect and process the following categories of data:
- Client & Contact Data: Full name, corporate email address, phone number, WhatsApp contact details, company name, job title, and geographic location provided via contact forms or direct engineering consultations.
- Technical & Project Specifications: Software architecture blueprints, source code repositories, API endpoints, database credentials, wireframes, and Statement of Work specifications shared under executed Non-Disclosure Agreements (NDAs).
- Career Applicant Data: Resumes/CVs, employment history, portfolios, code samples, and interview evaluation records submitted via our Careers desk.
- Automated Telemetry & Analytics: IP address, browser user-agent, operating system, pages visited, session duration, and referral sources collected via privacy-preserving security logs.
03 Legal Basis & Purpose of Data Processing
We process personal and technical data strictly under legitimate business interests, contractual necessity (Master Services Agreements MSA), and explicit consent:
- Contractual Execution: Evaluating project requirements, issuing technical proposals, executing MSAs and SOWs, and delivering web, mobile, SaaS, and AI software builds.
- System Operation & SLA Compliance: Hosting managed cloud environments, monitoring system health, deploying security patches, and maintaining 99.99% cloud SLA uptime.
- Communication & Support: Providing 24/7 technical desk support, project status reports, invoice notifications, and critical security updates.
- Legal & Regulatory Compliance: Fulfilling tax obligations, preventing cybersecurity incidents, and enforcing contractual agreements.
04 Enterprise Confidentiality & NDA Guarantees
đ Absolute Non-Disclosure Guarantee
OzoStack guarantees that all client codebases, trade secrets, business logic, customer records, and proprietary algorithms are protected under binding bilateral Non-Disclosure Agreements (NDAs).
We NEVER sell, rent, lease, or monetize client data, code, or personal contact details to advertising networks, third-party data brokers, or external entities under any circumstances.
Client project assets are accessible strictly on a need-to-know basis by vetted OzoStack software engineers, system architects, and project leads bound by signed confidentiality clauses.
05 Data Security & Infrastructure Controls
We maintain rigorous physical, technical, and administrative safeguards designed to protect enterprise data against unauthorized access, loss, or disclosure:
- Encryption Standards: AES-256 encryption at rest for database clusters and TLS 1.3 encryption in transit across all API communications.
- Cloud Architecture: Hosting on multi-region AWS and GCP enterprise infrastructure featuring isolated VPC networks, automated failovers, and Cloudflare WAF protection.
- Access Governance: Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and zero-trust identity verification across all internal engineering systems.
06 International Data Rights (GDPR, CCPA & Global)
Under global data privacy laws including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA/CPRA), you possess specific rights regarding your personal data:
- Right to Access & Portability: Request a complete copy of your personal data processed by OzoStack in a machine-readable format.
- Right to Rectification: Request correction of inaccurate or incomplete corporate or contact records.
- Right to Erasure ("Right to be Forgotten"): Request the complete deletion of your contact records or job application files, subject to legal retention obligations.
- Right to Object & Restrict: Withdraw consent or restrict specific processing operations at any time.
07 Data Retention & Minimization Policy
OzoStack retains personal and project data only as long as necessary to fulfill the purposes outlined in this policy or required by contractual MSA terms:
- Active Client Project Records: Retained for the duration of the active engineering contract plus 3 years for ongoing support and audit reference.
- Career Applicant Files: Retained for 12 months following application submission, after which files are securely purged unless candidate consent is renewed.
- Financial & Billing Records: Retained for 7 years to comply with statutory accounting and tax regulations.
08 Data Protection Officer (DPO) & Legal Contact Desk
If you have questions regarding this Privacy Policy, wish to submit a Data Subject Access Request (DSAR), or require a custom NDA prior to consultation, reach out directly to our DPO desk:
đĸ OzoStack Data Protection & Legal Desk
âī¸ Direct Email: Ozostack@gmail.com
đ Phone & WhatsApp: +91 9040455757
đ Website Desk: ozostack.io