Please have this reviewed by a qualified lawyer before you rely on it. It was drafted as a well-researched starting point for a software and hosting business serving clients internationally, but it is not legal advice, and no one who wrote it is your lawyer. Your obligations differ depending on where your clients are — India's DPDP Act, the EU and UK GDPR, and US state laws such as the CCPA all apply differently.
You must also replace the placeholders marked [ ] with your real registered address, entity type and grievance officer details before publishing.
01Des ingénieurs full-stack sur le web, le mobile, l'e-commerce et l'IA, travaillant par cycles courts avec un code documenté et maintenable.
Intense Iconic Webs ("we", "us", "our") is a custom software development and managed hosting company based in Hyderabad, Telangana, India, operating the website intenseiconicwebs.com and the client area at iiwebs.com/myaccount.
For the purposes of data protection law we act as a data controller for information about our own visitors, enquirers and clients, and as a data processor for personal data held inside systems we build, host or operate on behalf of a client.
| Legal entity | [Full registered name and entity type] |
| Registered address | [Street, area, Hyderabad, Telangana, PIN], India |
| Privacy contact | Développement de sites web |
| Grievance Officer (India) | [Name], Développement de sites web |
02What this policy covers
This policy explains what we do with personal information when you:
- browse our marketing website;
- send us an enquiry or request a quote by email, WhatsApp or our forms;
- become a client and use our client area, billing and support systems;
- use hosting, servers or applications we operate for you;
- install and use our Android client portal app.
It does not cover the practices of third-party websites we link to, or of a client's own website that happens to be hosted by us — those are governed by that client's own policy.
03Information we collect
Information you give us
- Enquiry and quote details — name, company, email address, phone or WhatsApp number, budget range, timeline and the description of your requirement.
- Client account details — billing name and address, tax identifiers, contacts authorised to act on the account, and domain or service records.
- Payment information — processed by our payment providers. We receive confirmation of payment and the last digits of the instrument; we do not store full card numbers on our systems.
- Support content — tickets, chat and email threads, and any files, screenshots, logs or credentials you choose to send us.
Information collected automatically
- Server logs — IP address, user agent, requested URL, referrer, response code and timestamp, kept for security and troubleshooting.
- Client area session data — a session cookie so you stay logged in, and a record of logins for account security.
- Local preferences — our marketing website stores your chosen language in your browser's local storage. It is not sent to us and is not used to identify you.
What we do not do
- We do not sell personal information, and we never have.
- We do not run advertising or behavioural tracking on our marketing website.
- We do not buy contact lists or send unsolicited bulk email.
04Our quote form
The quote form on our website does not send anything to a server. It opens your own email application with the details you entered already written into a message addressed to us. Nothing is stored on the page, and nothing reaches us until you press send in your own email client. Once you send it, the message is handled like any other email enquiry described in this policy.
05How we use information, and on what basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Replying to enquiries and preparing quotes | Enquiry details | Steps at your request before a contract |
| Delivering the services you have engaged us for | Account, project and support data | Performance of a contract |
| Billing, invoicing and collecting payment | Billing and payment records | Contract and legal obligation |
| Keeping systems secure and available | Logs, IP addresses, session records | Legitimate interests in security |
| Tax, accounting and statutory records | Invoices and account records | Legal obligation |
| Service notices about your account | Contact details | Contract and legitimate interests |
| Occasional marketing to existing clients | Business contact details | Legitimate interests, with opt-out in every message |
Where we rely on consent — for example marketing to someone who is not already a client — you may withdraw it at any time without affecting anything done beforehand.
06AI and automated processing
We build and operate AI systems for clients, and we use AI tooling in our own work. You should know the following:
- We do not make decisions with legal or similarly significant effects about you by automated means alone. AI agents we deploy escalate to a human where they are not confident, and a person remains accountable for the outcome.
- Where an AI agent handles a conversation on our behalf or on a client's behalf, the conversation is logged so it can be reviewed for quality and corrected.
- Where we pass content to a third-party AI provider as part of a service, we do so under terms that prohibit that provider from training its general models on the content, and we will name the provider in the applicable service agreement.
- We do not upload client data to consumer AI tools.
07Data we hold on behalf of clients
When we build, host or operate a system for you, that system may contain personal data about your customers, staff or suppliers. For that data:
- you are the controller and we are the processor;
- we act only on your documented instructions;
- we do not use it for our own purposes, and never for training or marketing;
- we keep it confidential under an NDA and restrict access to staff who need it;
- we will help you respond to requests from individuals and to security incidents;
- on termination we return or delete it as you instruct, subject to any legal retention requirement.
If you require a formal data processing agreement, including standard contractual clauses for transfers out of the EEA or UK, email Développement de sites web and we will put one in place.
08Who we share information with
We share personal information only where it is necessary, and only with:
- Infrastructure and hosting providers operating the data centres and servers your services run on.
- Payment processors who handle card and bank transactions.
- Communication providers for email delivery and WhatsApp messaging.
- Domain registrars and certificate authorities where you have asked us to register a domain or issue a certificate on your behalf.
- Professional advisers such as accountants and lawyers, under duties of confidentiality.
- Authorities, where we are legally required to, and only to the extent required.
A current list of the sub-processors used for your specific services is available on request. If we ever transfer the business, personal data may move with it, and you will be told before that happens.
09International transfers
We are based in India and serve clients worldwide, so personal data may be processed outside your own country, including in India, the European Union and the United States.
Where we transfer personal data out of the EEA or the UK, we do so on the basis of an adequacy decision where one exists, or otherwise under standard contractual clauses together with any additional safeguards the transfer requires. You may request a copy of the mechanism that applies to you.
10Applicable dans le monde entier
| Category | Retention |
|---|---|
| Enquiries that do not become projects | Up to 24 months, then deleted |
| Client account and project records | Duration of the relationship, then up to 7 years |
| Invoices and tax records | As required by Indian tax law, currently 8 years |
| Support tickets | 3 years from closure |
| Server and security logs | Typically 30 to 180 days |
| Backups | Rolling, overwritten on the cycle agreed for your service |
Data inside a system we host for a client is retained according to that client's own instructions, not this schedule.
11Planification des mises à jour
We take security seriously because it is part of what we sell. Our measures include encryption in transit using current TLS, hardened server configuration, firewalling and malware scanning, role-based access control, separate credentials per environment, patching of operating systems and packages, monitoring with alerting, and backups whose restores are tested rather than assumed.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to you, we will notify you and the relevant supervisory authority within the timescales the law requires, and tell you what happened and what we are doing about it.
If you believe you have found a vulnerability in something we run, please report it to Développement de sites web rather than disclosing it publicly. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter data beyond what is needed to demonstrate it.
12La version anglaise fait foi
Depending on where you are, you may have the right to:
- ask what personal information we hold about you and receive a copy;
- have inaccurate information corrected;
- have information deleted where we no longer have grounds to keep it;
- restrict or object to certain processing, including direct marketing;
- receive your data in a portable, machine-readable format;
- withdraw consent where consent is the basis we relied on;
- nominate another person to exercise your rights in the event of death or incapacity (India, under the DPDP Act);
- complain to a supervisory authority.
To exercise any of these, email Développement de sites web. We will respond within 30 days and will not charge you for a reasonable request. We may need to verify your identity first.
If we hold your data on behalf of one of our clients, we will pass your request to that client, who is responsible for answering it.
Des questions avant de signer ?
13Children
Nous préférons y répondre maintenant plutôt que vous laisser découvrir une surprise plus tard. Écrivez-nous et nous vous expliquerons n'importe quelle clause en langage clair.
14The Android app
Les conditions qui régissent nos devis, projets, hébergements, assistance et tout ce que nous faisons pour vous.
15Changes to this policy
We may update this policy as our services or the law change. The date at the top shows when it was last revised. Where a change materially affects how we handle your information, we will tell existing clients by email rather than relying on you noticing the page.
16Contact us
Questions, requests or complaints about privacy should go to Développement de sites web, or by post to our registered address above, marked for the attention of the Grievance Officer.
We would rather hear from you directly than have you go to a regulator first, and we will always try to resolve a concern properly.