Last updated 15 August 2026
Privacy policy
What we collect, why we have it, where it goes, and how to make us delete it. Written to be read rather than to be survived.
01Who we are
Maera Tech is a web development studio based at Plot No. 341, Vardhman Nagar, Karni Vihar, Ajmer Road, Jaipur, Rajasthan 302019, India. For the purposes of UK and EU data protection law we act as a data controller for the information described in this policy, and as a data processor for any personal data you ask us to handle on your behalf while delivering a project.
You can reach us about anything in this policy at contact@maeratech.com.
02What we collect
We only collect what we need to answer you and to run a project. That falls into three groups.
- Information you send us: your name, email address, company, country, budget range, and whatever you write in the contact form or in an email.
- Project information: credentials and access you grant us to your systems, plus any files, content, or data you share so we can do the work.
- Technical information: your IP address, browser type, pages visited, and referring page, collected automatically when you use this website.
We do not collect special category data, and we ask that you do not send it to us. We do not knowingly collect information from anyone under 16.
03Why we use it, and our legal basis
Under UK and EU GDPR we must have a lawful basis for each use. Ours are:
- To reply to your enquiry and prepare a proposal — our legitimate interest in responding to people who contact us.
- To deliver a project you have engaged us for — performance of a contract.
- To send invoices and keep accounting records — compliance with a legal obligation.
- To keep this website secure and working — our legitimate interest in preventing abuse.
- To send occasional updates about our services — your consent, which you can withdraw at any time.
We do not sell personal data, we do not share it with data brokers, and we do not use it to train machine learning models.
05International transfers
We are based in India. India has not received an adequacy decision from the UK government or the European Commission, which means personal data reaching us from the UK or the EEA is being transferred to a country without an adequacy finding.
Where we handle personal data originating in the UK or EEA, we do so under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment. We will sign these with you as part of a data processing agreement before any project begins, and we will provide a copy on request.
In practice we also reduce exposure directly: we ask for the minimum access needed, we prefer anonymised or test data during development, and we return or delete production data as soon as the work that needed it is finished.
06How long we keep it
- Enquiries that do not become projects: 24 months, then deleted.
- Project records and correspondence: for the length of the engagement and 6 years afterwards, which is the period in which a contract claim can be brought.
- Invoices and financial records: 8 years, to meet Indian tax record-keeping requirements.
- Client system credentials: deleted within 30 days of a project ending, or immediately on request.
- Website analytics: 14 months.
07Your rights
If you are in the UK or EEA you have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where consent is the basis we rely on.
If you are a California resident, you have the right to know what personal information we collect and why, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
To exercise any of these, email contact@maeratech.com. We will respond within 30 days and will not charge you for it. If you are unhappy with our answer you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
09How we protect it
- Encryption in transit on this website and on every system we operate.
- Access to client systems limited to the people working on that project, removed when they stop.
- Multi-factor authentication and a password manager on every account that supports them.
- Credentials shared through a secrets manager, never over email or chat.
No system is perfectly secure. If a breach ever affects your personal data and is likely to present a risk to you, we will tell you and the relevant regulator within 72 hours of becoming aware of it.
10Changes to this policy
When this policy changes we will update the date at the top of the page. If a change materially affects how we handle your personal data, we will contact clients directly rather than relying on you to notice.