Legal & Governance

Privacy Policy

Effective Date: September 15, 2026 · Version 3.4 · Bitneka Technologies Pvt. Ltd.

Zero Data Retention

Client code never used in public AI training

GDPR & CCPA Ready

Full data subject rights and deletion protocols

Mutual NDA Guard

Strict confidentiality before technical discovery

1 Corporate Identity & Scope

This Privacy Policy applies to all digital properties, software engineering services, consulting deliverables, and client portals operated by Bitneka Technologies ("Bitneka", "we", "us", or "our"), having its registered corporate engineering operations in Islamabad, Pakistan, and serving clients across the United States, United Kingdom, European Union, Australia, and Middle East.

This document governs how we handle personally identifiable information (PII), corporate confidential data, repository credentials, and architectural specifications collected through www.bitneka.com, technical discovery briefs, project management portals, and executed Statements of Work (SOW).

2 Categories of Data We Collect

Depending on the nature of your interaction with Bitneka, we process the following categories of information:

A. Commercial & Discovery Inquiries Full name, business email address, phone/WhatsApp number, organization name, approximate project budget, technical requirements, and project briefs submitted via our contact and consultation forms.
B. Technical & Repository Access Data For contracted clients, access credentials, API keys, staging environment URLs, database schemas, and GitHub/GitLab repository permissions shared for the purpose of executing agreed software engineering milestones.
C. Talent & Candidate Information Curriculum vitae (CV), portfolio links, GitHub profiles, employment history, and contact details submitted through our Careers application portal.
D. Automated Telemetry & Server Logs IP addresses, browser client user-agents, operating system types, referral sources, and page interaction timestamps recorded to prevent malicious traffic and monitor platform availability.

3 AI Governance & Zero-Retention Commitment

Strict Isolation of Client Code & Proprietary Models

As an enterprise engineering firm specializing in Generative AI and intelligent systems, Bitneka enforces the strictest AI safety and intellectual property safeguards in the industry.

  • Zero Foundation Model Training: Your proprietary source code, vector embeddings, customer records, and system prompts are NEVER used to train, fine-tune, or reinforce any public foundation models.
  • Enterprise Zero-Retention Endpoints: All commercial LLM integrations (Azure OpenAI, AWS Bedrock, Anthropic Claude Enterprise) are deployed under enterprise contractual tiers guaranteeing that API payloads are not logged, inspected, or retained by model providers.
  • Private VPC Isolation: Where required by financial or healthcare regulatory mandates, model weights and inference pipelines are deployed strictly within your dedicated cloud tenant (Private AWS VPC / Azure Virtual Network).

4 Lawful Basis & Purposes of Processing

Under the EU General Data Protection Regulation (GDPR Article 6), UK Data Protection Act, and international standards, we process your information strictly under the following lawful bases:

  • Performance of a Contract: To deliver custom software, conduct code reviews, manage sprint releases, and provide 30-day warranty support outlined in your contract.
  • Legitimate Commercial Interests: To protect our network perimeter against unauthorized intrusions, maintain audit logs, and improve our engineering workflows.
  • Legal & Regulatory Obligations: To comply with international taxation, export compliance, accounting audits, and statutory disclosure mandates.
  • Explicit Consent: Where you have opted in to receive direct technical briefings or company communications.

5 Technical Data Security & Encryption Standards

Bitneka adheres to rigorous technical and organizational security controls designed to safeguard client information:

TLS 1.3 & AES-256 All data in transit is encrypted using modern TLS 1.3, with data at rest secured via AES-256 encryption.
Hardware MFA & Zero Trust Mandatory hardware-backed MFA across all developer accounts, cloud consoles, and repository access.
Automated SAST Scanning Continuous automated vulnerability scanning across all CI/CD deployment pipelines before production releases.

6 Your Statutory Rights (GDPR & Global Access)

Regardless of your geographical location, Bitneka extends universal data rights to all users and enterprise partners:

  • Right of Access & Portability: Obtain a complete machine-readable copy of any personal data or commercial records held in our systems.
  • Right to Rectification: Request immediate correction of outdated or inaccurate personal and organizational records.
  • Right to Erasure ("Right to be Forgotten"): Request full permanent cryptographic deletion of personal data upon completion of contractual obligations.
  • Right to Object / Restrict: Restrict processing of your data for specific analytical or direct communication workflows.

To exercise any statutory right, submit a verified request directly to our Data Protection team at privacy@bitneka.com. Requests are fulfilled within 30 calendar days at zero cost.