ruchirgupta.com. Specific data governance, customer data processing, and enterprise obligations for contracted engineering pods are governed by individual client Data Processing Addenda (DPA) executed under master service contracts.1. Scope & Relationship to Client Contracts
This Global Privacy Policy governs how Proficed, conducting business through its specialized enterprise engineering division Ruchir Gupta ("Ruchir Gupta", "we", "us", or "our"), collects, utilizes, and safeguards information obtained through ruchirgupta.com, associated API subdomains, and preliminary engagement interactions.
When Ruchir Gupta delivers software engineering, pod augmentations, or architectural consulting under a countersigned Master Services Agreement (MSA) and Statement of Work (SOW), Ruchir Gupta acts strictly as a Data Processor / Service Provider under applicable privacy statutes. In such engagements, the specific client Data Processing Agreement (DPA) and Master Agreement govern all production data, source repositories, and client environments.
2. Categories of Data & Legal Basis for Processing
We process professional engagement records and technical telemetry under established legal grounds:
- Contractual Necessity & Pre-Contractual Steps: Processing corporate stakeholder identities, business emails, and technical inquiry requirements submitted for initial feasibility reviews, RFP filings, or architecture evaluations.
- Legitimate Commercial Interests: Monitoring edge infrastructure security, verifying TLS handshakes, defending against distributed denial-of-service (DDoS) attempts, and validating server performance.
- Statutory Compliance: Retaining transactional history, anti-fraud verifications, and contractual correspondence as mandated by applicable fiscal and corporate governance laws.
3. Telemetry, Analytics & Cookie Mechanics
Ruchir Gupta does not deploy intrusive consumer ad trackers, behavioral retargeting networks, or third-party identity resolution graphs across ruchirgupta.com. We categorize our automated tracking into strictly isolated functions:
- Strictly Necessary State: Ephemeral session state, CSRF mitigation tokens, and client load-balancer routing hashes required to render the application.
- Diagnostic Performance Metrics: De-identified, aggregated traffic analytics measuring cache efficiency, page latency, and CDN edge routing performance.
4. Infrastructure Subprocessors & Cross-Border Transfers
To deliver scalable global digital delivery, technical telemetry and engagement inquiries may transit vetted cloud compute and managed infrastructure providers (such as Amazon Web Services, Microsoft Azure, and enterprise communication gateways). Every third-party processor is bound by data processing agreements requiring compliance no less rigorous than this policy.
Where processing involves cross-border transfers outside the European Economic Area (EEA) or the United Kingdom, transfers rely on standard contractual mechanisms recognized by regulatory authorities, including European Commission Standard Contractual Clauses (SCCs) and UK International Data Transfer Addenda.
5. Cryptographic Security & Retention Schedules
All data in transit over public interfaces is encrypted using TLS 1.3/TLS 1.2 with hardened cipher suites. At-rest engagement archives and administrative databases leverage AES-256 encryption. We retain general commercial contact records and exploratory scope outlines for twenty-four (24) months, after which they are purged or irreversibly anonymized, unless an active signed contract mandates alternative retention windows.
6. Enterprise & Individual Privacy Rights (GDPR / CCPA / CPRA)
Subject to statutory verifications, corporate representatives and site visitors hold distinct data rights under GDPR, UK GDPR, and CCPA/CPRA:
- Right to Access & Portability: Obtain formal confirmation of data held, along with machine-readable exports of relevant contact profiles.
- Right to Rectification & Erasure: Correct incomplete records or mandate permanent cryptographic deletion of non-contractual records.
- No Sale or Sharing of Personal Information: We do not sell, rent, disclose, or share personal or professional data with third parties for cross-context behavioral advertising.
To exercise these rights, submit a verified request to privacy@ruchirgupta.com. Requests receive initial review and response within thirty (30) calendar days.
7. Architectural Inquiries, Code Reviews & Diagnostic Data
Any technical schematics, repository access snippets, or system diagnostic logs shared during exploratory technical inquiries, advisory engagements, or code audits are treated with strict professional confidentiality. Exploratory diagnostic files not under active contract are deleted from our local development environments within 30 days of initial review.