PrivacyPolicy
Last Updated: July 28, 2026 | Version 2.4
1. Overview & Data Controller Identification
This Comprehensive Privacy Policy ("Policy", "Data Governance Charter") defines the rigorous protocols, architectural data collection mechanics, transmission frameworks, storage infrastructure, and statutory user rights administered by GLAD Studio ("Company", "We", "Us", or "Our") in connection with your browsing, access, and interactive engagement with gladstudio.net (the "Site"), our custom software engineering services, proprietary client portals, staging preview deployments, API proxies, and associated digital systems (collectively, the "Services").
GLAD Studio functions in dual regulatory capacities under international data protection jurisprudence:
- As a Data Controller: With respect to direct website visitors, prospective client leads, billing and administrative contacts, and communication telemetry gathered via discovery forms, contact endpoints, and scheduling integrations.
- As a Data Processor / Sub-processor: With respect to staging data, mock datasets, or test user records provided or hosted on behalf of enterprise clients during active software development, QA testing, and systems integration sprints.
We adhere strictly to global data protection regimes, including the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the United Kingdom Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Indian Digital Personal Data Protection Act 2023 ("DPDP"), and all other applicable regional privacy statutes.
2. Categories of Information Collected
We collect information through direct user submission, automated system and network telemetry, server middleware logs, and integrated third-party analytical pipelines. The explicit categories of data processed include:
- Identity & Contact Telemetry: Full personal names, corporate email addresses, direct telephone numbers, company or startup legal names, operational roles, job titles, geographical location (country and city), LinkedIn or GitHub profiles, and preferred communication channels submitted via proposal discovery forms, calendar scheduling widgets, or direct email inquiries.
- Project, Architecture & Technical Artifacts: Product requirements documents (PRDs), database entity relationship diagrams (ERDs), API endpoint schemas, repository access tokens, Figma design files, brand identity guidelines, staging environment SSH keys, test database seed dumps, and proprietary software architecture logic provided during scoping and development sprints.
- Artificial Intelligence & Model Interaction Logs: Prompts, contextual embeddings, retrieval queries, system prompt parameters, model evaluation logs, and structured JSON output payloads submitted to or generated within client-commissioned AI workflow features, agentic pipelines, or custom RAG vector architectures.
- Automated System, Network & Diagnostic Data: Internet Protocol (IPv4/IPv6) addresses, browser user-agent signatures, device hardware specifications, operating system versions, HTTP request headers, referrer URLs, session durations, screen resolutions, clickstream event paths, edge latency measurements, and runtime JavaScript error stack traces captured by edge middleware.
- Billing & Transactional Metadata: Corporate tax identification numbers (GSTIN/VAT/EIN), billing entity addresses, transaction identifiers, payment gateway invoice reference tokens, and milestone settlement records. All payment card information is tokenized and processed securely via PCI-DSS Level 1 certified payment gateways (Stripe, Razorpay); zero raw credit card or banking credentials touch or reside on our application servers.
3. Legal Basis for Processing
In compliance with Article 6 of the GDPR and comparable global standards, GLAD Studio processes personal and client telemetry exclusively where an established legal foundation exists:
- Contractual Necessity (Art. 6(1)(b) GDPR): Processing essential to draft project proposals, execute bilateral Non-Disclosure Agreements (NDAs), establish staging development environments, provision private code repositories, fulfill sprint milestones, and complete deliverable handovers under signed Statements of Work (SOWs).
- Legitimate Business Interests (Art. 6(1)(f) GDPR): Processing necessary to maintain edge infrastructure availability, optimize web platform latency, prevent malicious DDoS vectors, investigate runtime exceptions, prevent fraudulent inquiries, enforce intellectual property protections, and ensure high-integrity communications.
- Statutory Legal Compliance (Art. 6(1)(c) GDPR): Processing mandated by corporate tax accounting regulations, statutory financial audit obligations, international commercial trade laws, anti-fraud compliance, or formal court subpoenas.
- Explicit & Unambiguous Consent (Art. 6(1)(a) GDPR): Where you have granted affirmative, opt-in consent for non-essential analytical cookies, studio newsletters, marketing case study features, or voluntary research feedback questionnaires. Consent may be revoked at any time.
4. How We Use Collected Information
We enforce strict data minimization principles across our engineering practices. Information collected is used strictly for legitimate technical, operational, and contractual purposes, including:
- Architecting, prototyping, engineering, testing, and deploying custom MVP platforms, web applications, mobile apps, and business automations.
- Provisioning isolated staging servers, configuring automated CI/CD deployment pipelines, and managing team access to private git repositories.
- Monitoring runtime system health, analyzing edge server exceptions, conducting load tests, and patching cybersecurity vulnerabilities.
- Facilitating direct founder-to-client sprint reviews, milestone sign-offs, technical advisory sessions, and code handoff walkthroughs.
- Generating milestone tax invoices, processing milestone payments, and maintaining compliance with corporate financial audit standards.
Zero Third-Party Training: GLAD Studio explicitly guarantees that we DO NOT sell, lease, license, or utilize client proprietary source code, internal data models, database dumps, confidential project briefs, or private vector embeddings to train public foundational AI models, third-party Large Language Models (LLMs), or public commercial datasets.
5. Third-Party Sub-processors & Service Providers
To provide high-availability edge hosting, secure database management, automated build pipelines, and reliable communication channels, GLAD Studio engages vetted third-party cloud infrastructure vendors. All sub-processors are bound by executed Data Processing Agreements (DPAs) with strict security, confidentiality, and data handling standards:
Cloud Infrastructure & Hosting
Amazon Web Services (AWS), Vercel Inc. (Edge serverless runtime and SSR caching), Cloudflare Inc. (WAF, DDoS mitigation, and SSL termination), Supabase Inc. (PostgreSQL and Auth).
AI & Machine Learning APIs
OpenAI LLC (Enterprise API with Zero-Data Retention policy compliance), Anthropic PBC (Claude API enterprise privacy tier), HuggingFace Inc. (Dedicated inference endpoints).
Communication & Scheduling
Cal.com Inc. (SOC2 compliant calendar scheduling), Resend Inc. (Transactional email delivery), Slack Technologies / Salesforce (Private sprint channels).
Payment Gateways
Stripe Inc. (PCI-DSS Level 1 global card & ACH processing), Razorpay Software Pvt. Ltd. (Domestic INR payment rails & GST invoicing).
We conduct periodic technical reviews of all sub-processors to verify ongoing compliance with SOC 2 Type II, ISO/IEC 27001, and GDPR Article 28 data protection requirements.
6. Cross-Border Data Transfers
As a global product engineering studio serving startups and enterprises across the United States, European Union, United Kingdom, and Asia-Pacific, telemetry and project artifacts may be processed, transferred, and stored on encrypted servers located in the United States, European Union, and India.
Standard Contractual Clauses (SCCs): For all cross-border data transfers originating from the European Economic Area (EEA) or the United Kingdom, GLAD Studio executes European Commission-approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with all relevant data partners and sub-processors.
Supplemental Technical Safeguards: Transfers are reinforced by end-to-end encryption in transit (TLS 1.3), AES-256 bit encryption at rest, strict credential tokenization, and strict Role-Based Access Controls (RBAC) to ensure that personal and proprietary information receives an equivalent level of protection regardless of geographic processing location.
7. Data Retention & Automatic Destruction Schedules
GLAD Studio maintains disciplined data retention schedules designed to ensure personal and project data is preserved only for the duration strictly necessary to fulfill contractual obligations, provide post-launch support, and satisfy statutory tax requirements:
- Active Project Repositories, Staging Environments & Sandbox Keys: Retained during the active software development lifecycle and for a mandatory ninety (90) calendar-day post-handover warranty window. Upon expiration of the warranty period, staging database instances are destroyed, temporary server credentials are revoked, and local developer build caches are securely erased.
- Financial, Invoicing & Transactional Records: Retained for seven (7) statutory fiscal years following transaction completion in immutable encrypted cloud storage to fulfill Indian Income Tax Act requirements, GST audit obligations, and international accounting standards.
- Inquiry Telemetry, Discovery Decks & Diagnostic Logs: Retained for a rolling period of twenty-four (24) months from the last documented communication or interaction, after which records are automatically purged via scheduled cron jobs unless an explicit erasure request is received sooner.
8. Security Architecture & Encryption Standards
GLAD Studio implements defense-in-depth cybersecurity protocols, modern cryptographic standards, and infrastructure controls across all operational layers:
- Cryptographic Encryption in Transit: Mandatory TLS 1.3 protocol enforcement with modern cipher suites and HTTP Strict Transport Security (HSTS) headers (1-year preload directive) across all public web endpoints, API proxies, and staging environments.
- Military-Grade Encryption at Rest: AES-256 bit symmetric key encryption applied across all persistent database clusters, cloud object storage buckets, backup archives, and environment secret managers (AWS KMS / Doppler).
- Access Governance & Multi-Factor Authentication (MFA): Strict enforcement of the Principle of Least Privilege (PoLP), hardware security key or time-based one-time password (TOTP) MFA on all code repositories, cloud consoles, and administrative dashboards, with automated session expiration.
- Automated Code Security & SAST Audits: Continuous Static Application Security Testing (SAST), automated container dependency vulnerability scanning (Dependabot/Snyk), and pre-commit secret-scanning hooks integrated into our CI/CD pipelines to prevent credential leakage.
9. Cookie & Tracking Policy
Our website utilizes privacy-respecting cookies, local browser storage tokens, and lightweight edge telemetry to maintain active user sessions, remember UI theme preferences, and analyze aggregate traffic patterns without compromising personal anonymity:
- Strictly Necessary Cookies: Essential for core site navigation, CSRF token validation, and secure form submissions. These cannot be disabled.
- Functional & Preference Cookies: Preserve UI state, reduced-motion preferences, and temporary form field inputs across browser sessions.
- Aggregate Analytical Telemetry: Anonymized traffic metrics (pageviews, referrers, bounce rates) processed without cross-site tracking cookies, device fingerprinting, or personal profiling.
You may configure your web browser (Chrome, Safari, Firefox, Edge) to block, reject, or alert you about cookies. Please note that disabling essential cookies may impact certain interactive form functionalities on our website.
10. Client Confidentiality & Intellectual Property
GLAD Studio recognizes that during engineering engagements, clients disclose confidential business strategies, unreleased software logic, proprietary algorithms, and trade secrets. All client proprietary assets are governed under strict mutual Non-Disclosure Agreements (NDAs) and clean-room development protocols.
Absolute IP Sovereignty: Upon milestone invoice settlement, full ownership of all custom source code, design artifacts, database architectures, and digital build assets transfers 100% to the Client. GLAD Studio will never repurpose, sublicense, or expose client-specific proprietary code bases to any other client or external organization.
11. Your Data Protection Rights
Depending on your country, state, or regional jurisdiction (including the EEA, UK, California, and India), you hold statutory rights regarding the personal information we process:
- Right of Access & Data Portability (Art. 15/20 GDPR): Request a complete, structured, machine-readable (JSON/CSV) copy of all personal records and telemetry held by GLAD Studio.
- Right to Rectification (Art. 16 GDPR): Request the immediate correction, modification, or completion of inaccurate or outdated personal telemetry.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request the permanent deletion and purging of your personal records from all active databases, subject to statutory tax record retention requirements.
- Right to Restrict or Object to Processing (Art. 18/21 GDPR): Limit or object to specific processing activities, automated profiling, or marketing communications.
To exercise any of these statutory rights, please submit a formal request to our compliance team at contact@gladstudio.net. We will verify your identity and process your request within thirty (30) calendar days without fee.
12. Breach Notification Protocols (72-Hour SLA)
In the event of a confirmed cybersecurity incident, unauthorized data access, or infrastructure breach impacting personal data or client project assets, GLAD Studio adheres to strict incident response protocols aligned with GDPR Articles 33 and 34 and international standards:
- 72-Hour Controller Notification: We will formally notify affected client data controllers and relevant data protection supervisory authorities within seventy-two (72) hours of incident confirmation.
- Forensic Remediation Report: Notifications will include an actionable forensic assessment detailing the nature of the breach, categories of affected records, estimated impact, and immediate containment measures taken.
13. Children's Privacy Prohibition
GLAD Studio's digital services, engineering consultations, and SaaS products are designed strictly for enterprise clients, commercial founders, and adults aged eighteen (18) and older. We do not knowingly solicit, collect, or process personal data from children under the age of sixteen (16) pursuant to the Children's Online Privacy Protection Act (COPPA) and Article 8 of the GDPR.
If we discover that personal data of a minor has been inadvertently submitted through our discovery forms, we will immediately initiate secure data purging protocols to delete the records permanently from all servers.
14. Amendments to this Policy
GLAD Studio reserves the right to revise and update this Privacy Policy periodically to reflect technological evolutions, infrastructure migrations, emerging statutory requirements, or studio service expansions.
Any material revisions will be reflected with an updated "Last Updated" timestamp and version increment at the top of this document. We encourage clients and website visitors to review this page periodically to remain informed of our ongoing data protection standards.
15. Contact Information & Legal Inquiries
For any privacy inquiries, Data Protection Officer (DPO) requests, sub-processor audits, or formal legal notices, please contact our dedicated compliance team:
FAQ.




Clear Answers on Scope,
Timelines and Cost
Before Any Work
Begins जवाब.
Every project is custom-scoped based on your specific requirements, feature complexity, and timeline. We work on a transparent, fixed-price milestone basis — meaning after an initial discovery call, you receive a detailed proposal with a fixed quote and guaranteed delivery timeline before any code is written.
Most projects begin within 1–2 weeks of signing. For urgent work, we can sometimes start within a few days.
Yes — most of our clients are non-technical. We translate ideas into clear technical specifications, user-friendly designs, and shipped products, ensuring you always understand the trade-offs at every step.
You own 100% of all intellectual property, source code, designs, and project assets from day one. Upon final milestone completion, full repository access and credentials are handed over.
We work in structured 2-week sprints with weekly async updates, active messaging channels (Slack/Discord), and direct access to a live staging environment so you can test features as they are built.
Yes. Whether upgrading an existing application, refactoring legacy code, or integrating new AI features and third-party APIs, we can seamlessly audit and build directly within your current codebase.
We focus on modern, type-safe, and scalable web and mobile stacks — primarily React, Next.js, TanStack Start, TypeScript, Node.js, Python, Flutter, Tailwind CSS, and cloud platforms like AWS and Vercel.
We provide dedicated post-launch support for bug fixes, performance monitoring, and maintenance. Many of our clients continue working with us long-term as their dedicated development team.