Skip to content
LEGAL

Privacy Policy

Last updated — 20 August 2026 · v2.6

This Privacy Policy explains how Triophase Global Services Pvt. Ltd. ("Triophase", "we", "us", "our") collects, uses, discloses and protects personal information when you visit triophase.com, use the Triophase Studio client portal, use our free tools, correspond with us, or engage us to deliver software services.

Triophase Global Services Pvt. Ltd. is a company incorporated in India, with its registered office at ASO-411, 4th Floor, South Block, Astra Tower, Newtown, Kolkata – 700135, West Bengal, India.

This policy covers personal information for which Triophase acts as the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023) or as the Controller (under the EU General Data Protection Regulation and the UK GDPR).

Where we handle personal data contained inside a client's systems, datasets or applications in the course of delivering a project, we act as a Data Processor on that client's instructions. That relationship is governed by our Data Processing Addendum, not by this policy.


1. Summary

  • We collect information you give us, information generated when you use our services, and a limited amount of technical information collected automatically.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • We do not use client project data, client code or client content to train any artificial intelligence model, and we contract with our AI vendors on terms that prohibit them from doing so.
  • We use a defined set of sub-processors, published and maintained at /sub-processor.
  • You have rights over your personal information, described in section 9, and a named grievance contact in section 14.

2. Information we collect

2.1 Information you provide directly

Category Examples Where it comes from
Identity and contact data Name, job title, employer, email address, telephone number, postal address Contact forms, discovery calls, Studio registration, contracts
Account data Studio username, hashed password, authentication factors, account preferences, role and permissions Studio portal
Project data Project briefs, requirements, specifications, documents, designs, credentials you choose to share, feedback and approvals recorded against milestones Spec sprints, Studio, email, calls
Commercial data Billing contact, billing address, tax registration numbers (including GSTIN), purchase orders, invoices, payment references Contracting and billing
Communications Emails, messages, support tickets, call notes, and where you have been told in advance and consented, call recordings and transcripts All channels
Recruitment data CV, work history, portfolio, right-to-work information Applications

2.2 Information collected automatically

  • IP address, and the approximate city or region derived from it
  • Browser type and version, operating system, device type, screen dimensions
  • Pages visited, referring URL, time on page, actions taken
  • Dates and times of access, and authentication events in the Studio
  • Cookie and similar identifiers, as described in our Cookie Policy

We use Google Analytics 4 for website analytics. It is set only where you have consented, and it is described in detail in our Cookie Policy.

2.3 Information from third parties

  • Business contact information from professional networks, principally LinkedIn, used for manual outbound outreach on the legal basis described in section 4. We do not purchase prospect databases and we do not operate automated outbound email sequences.
  • Information from payment providers confirming that a payment succeeded or failed
  • Publicly available information about a prospective client's organisation
  • References supplied by candidates during recruitment

2.4 Free tools

Our free tools (including the site and server health scan and the AI-readiness checker) accept a URL or domain you submit. We record the submitted target, the results generated, and the technical metadata described in 2.2. Do not submit a domain you are not authorised to test. We may retain aggregate, non-identifying statistics about tool usage indefinitely.

2.5 Sensitive personal data

We do not seek and do not want special category or sensitive personal data. Please do not include it in project briefs, support tickets or free-form fields. If a project genuinely requires processing of such data inside a client system, that is dealt with under the DPA with appropriate additional safeguards, and not through this policy.

2.6 Children

Our services are directed at businesses and are not intended for children. We do not knowingly collect personal information of a child as defined under the DPDP Act, 2023, or of any person under 16 under the GDPR. If you believe a child has provided us information, contact us using section 14 and we will delete it.


3. How we use information

  • To respond to enquiries and prepare proposals
  • To carry out a spec sprint and produce the specification, prototype and build decomposition
  • To plan, execute, test and deliver a build, including provisioning isolated build environments and per-project staging environments
  • To operate, secure and support the Triophase Studio portal
  • To communicate about projects, milestones, approvals, change orders and support
  • To invoice, collect payment, and meet accounting and tax obligations
  • To detect, investigate and prevent fraud, abuse, unauthorised access and security incidents
  • To improve our services, our tooling and our internal delivery process, using aggregated or de-identified information wherever it will serve the purpose
  • To market our services to business contacts, subject to section 4 and section 9
  • To comply with law, respond to lawful requests, and establish, exercise or defend legal claims
  • To evaluate job applications

We do not use personal information for automated decision-making that produces legal or similarly significant effects on an individual.


4. Legal bases

For individuals in India, we process personal data on the basis of your consent, or for a legitimate use permitted under the DPDP Act, 2023, including where you have voluntarily provided data for a specified purpose. Where consent is our basis, you may withdraw it at any time, and withdrawal will be as easy as giving it.

For individuals in the EEA, the UK or Switzerland, our legal bases are:

Purpose Legal basis
Delivering a project, operating the Studio, invoicing Performance of a contract, or steps prior to entering one (Art. 6(1)(b))
Security, fraud prevention, network and service integrity Legitimate interests (Art. 6(1)(f))
Service improvement and internal analytics Legitimate interests (Art. 6(1)(f))
B2B outbound marketing to business contacts Legitimate interests (Art. 6(1)(f)), subject to an unconditional right to object
Non-essential cookies and similar technologies Consent (Art. 6(1)(a))
Tax, accounting, statutory record keeping Legal obligation (Art. 6(1)(c))
Establishing or defending legal claims Legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests we have carried out a balancing assessment, and we will provide a summary of it on request.


5. Artificial intelligence

Triophase builds software using autonomous AI agents supervised by senior engineers. Because that is central to what we do, we state our position on it plainly.

  • No training on your data. Client project data, source code, specifications, credentials and content are not used to train, fine-tune or improve any model, whether ours or a vendor's. We call model providers directly under commercial API terms that contractually exclude training on submitted content. Providers may retain content for a limited period for abuse monitoring under their own terms; they do not use it to train models.
  • Model providers are sub-processors. Content submitted to a model provider for inference is a disclosure to a sub-processor. Every such provider is listed at /sub-processor.
  • Human accountability. AI-generated output is reviewed, tested and accepted by our engineers before it reaches a client environment. Accountability for delivered work rests with Triophase, not with a tool.
  • Regional pinning. We operate across several infrastructure providers, which allows us to restrict build compute and storage to a region a customer nominates. This is available on request and assessed case by case, is agreed in the order documentation, and is not applied by default. Model inference is provided by the vendors listed at /sub-processor and is subject to their own regional availability.
  • Limits. AI systems can produce incorrect or unexpected output. Our contractual warranties in the Terms of Service describe what we do and do not guarantee about delivered work.

6. Disclosure of information

We disclose personal information to:

  • Sub-processors and service providers that host, transmit, secure or otherwise support our services, listed at /sub-processor and bound by written agreements imposing confidentiality and security obligations
  • Professional advisers, including lawyers, auditors, accountants and insurers, under duties of confidentiality
  • Payment providers, for the purpose of collecting fees
  • Public authorities, where we are legally compelled, and only to the extent required. We will notify the affected party unless we are legally prohibited from doing so or a genuine risk to life or safety exists.
  • An acquirer, in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and to this policy continuing to apply to the transferred information

We do not sell personal information. We do not disclose personal information to third parties for their own independent marketing.


7. International transfers

Triophase operates from India. Our sub-processors may be located in other countries, including the United States and the European Union. Personal information will therefore be transferred outside the country in which you are located.

Where we transfer personal data out of the EEA or the UK, we rely on:

  • The European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies
  • An adequacy decision, where one covers the destination
  • Supplementary technical measures, including encryption in transit, encryption at rest, and restriction of access on a need-to-know basis

Transfers out of India are made in accordance with section 16 of the DPDP Act, 2023, and any restrictions notified by the Central Government from time to time.

A copy of the relevant transfer mechanism is available on request from the contact in section 14.


8. Retention

We keep personal information only as long as we need it.

Category Retention
Enquiry and prospect data where no engagement follows 24 months from last contact
Client project data, specifications, repositories Duration of the engagement, then 12 months, then deletion or return under the DPA
Build and staging environments Destroyed within 30 days of project completion or termination
Studio account data Duration of the account, then 12 months
Contracts, invoices, tax and accounting records 8 years, as required under Indian company and tax law
Security, access and audit logs 12 months
Backups Up to 90 days on a rolling cycle, after which they are overwritten
Marketing contact data Until objection or withdrawal of consent, then a minimal suppression record kept indefinitely so we do not contact you again
Unsuccessful job applications 12 months, unless you ask us to keep them longer

Where deletion is not immediately possible for technical reasons, such as an encrypted backup within its retention cycle, we isolate the data and delete it at the next scheduled cycle.


9. Your rights

Subject to the law applicable to you, you may have the right to:

  • Access the personal information we hold about you and obtain a summary of processing
  • Correct inaccurate or incomplete information, and complete or update it
  • Erase personal information where there is no lawful basis to keep it
  • Restrict or object to processing, including an unconditional right to object to direct marketing
  • Portability of information you provided, in a structured, machine-readable format
  • Withdraw consent at any time, without affecting processing already carried out
  • Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act, 2023
  • Complain to a supervisory authority

To exercise any right, contact us using section 14. We will respond within 30 days, or sooner where the law requires it. We may need to verify your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive.

If you are in the EEA or UK you may complain to your local supervisory authority. If you are in India you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer.

Requests about data inside a client's system. If your personal data is held inside an application we built or operate for a client, that client is the Data Fiduciary or Controller. Please direct your request to them. If you contact us, we will forward your request to the client without undue delay and tell you we have done so.


10. Security

We maintain administrative, technical and physical safeguards appropriate to the risk, described in detail in our Security statement. These include encryption in transit and at rest, per-project environment isolation, least-privilege access control, multi-factor authentication, an encrypted secrets store, logging and monitoring, and a documented incident response process.

No system is perfectly secure. We do not guarantee that our safeguards will prevent every incident. Where an incident affecting personal data occurs, we will notify affected parties and regulators as required by applicable law, including the six-hour reporting requirement to CERT-In where it applies to us.


11. Marketing

We send commercial communications to business contacts about services relevant to their role. Every message contains a working unsubscribe mechanism, and we honour opt-outs promptly. You may also opt out at any time by contacting us. Withdrawing from marketing does not affect operational messages about a live project.


12. Third-party links

Our site links to third-party websites and services we do not control. This policy does not apply to them. Review their own privacy notices before providing information.


13. Changes to this policy

We may update this policy. The "last updated" date at the top will change. Where a change materially affects your rights or how we use your information, we will provide reasonable advance notice by email to account holders or by a prominent notice on the site. Continued use after the effective date constitutes acceptance where acceptance is a valid basis; where consent is required, we will seek it separately.

We maintain previous versions and will supply an earlier version on request.


14. Contact and grievance redressal

General data protection enquiries Email: privacy@triophase.com

Grievance Officer — Digital Personal Data Protection Act, 2023

Name Sayan Nandi
Designation Grievance Officer
Entity Triophase Global Services Pvt. Ltd.
Address ASO-411, 4th Floor, South Block, Astra Tower, Newtown, Kolkata – 700135, West Bengal, India
Email grievance@triophase.com
Acknowledgement Within 3 business days of receipt
Resolution Within 30 days of receipt

The Grievance Officer is the point of contact for any Data Principal who wishes to raise a grievance about our processing of their personal data, or who is dissatisfied with our response to a request made under section 9. If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India. We ask that you raise the matter with our Grievance Officer first, as the Act contemplates.

EEA and UK representation

We provide our services to businesses. Where we process personal data relating to individuals in the EEA or the UK in the course of delivering a project, we do so as a processor acting on our customer's instructions, and that customer is responsible for those individuals' notices and for responding to their rights requests.

We have assessed whether we are required to designate a representative under Article 27 of the GDPR or Article 27 of the UK GDPR and, on the basis of our current activities, we consider that we are not. We keep that assessment under review and will publish the details here if the position changes.

Any individual in the EEA or the UK may contact us directly at privacy@triophase.com in relation to our processing of their personal data, and we will respond in accordance with section 9 above.

Cookies

We use essential cookies to run this site, and — with your agreement — analytics cookies to understand how it is used. You can change your mind by clearing your cookies. Cookie Policy