Effective Date: January 7, 2025
Last Updated: March 10, 2025
Jurisdiction: Agartala, Tripura, India

1. Introduction & Scope

Welcome to Brewnok ("Brewnok", "we", "us", or "our"). We are an engineering solutions and technology consulting firm based in Agartala, Tripura, India, specializing in Site Reliability Engineering (SRE), observability and monitoring, custom software and web development, automation, and resilience engineering.

This Privacy Policy explains how we collect, process, store, and protect personal and business information when you:

  • Visit our primary website located at brewnok.com;
  • Engage with us for engineering, consulting, or technical support services;
  • Submit inquiries, quote requests, or schedule discovery meetings with our team;
  • Interact with our digital products and software platforms, including Schedmate, ManagerJi, CominQR, Slot4Dine, Hupwiz, and BuildingBugs.
Our Core Privacy Commitment: We respect your privacy and handle data with engineering-grade integrity. We do not sell, rent, monetize, or trade your personal data with third-party advertisers or data brokers under any circumstances.

2. Information We Collect

Depending on how you interact with Brewnok, we collect different types of information categorized below:

A. Information You Provide to Us Directly

  • Contact & Identity Information: Your full name, professional email address, phone number, and job title when you submit a message, request a quote, or correspond with us via email (brewnok@gmail.com).
  • Discovery & Meeting Details: Meeting notes, preferred dates, and communication preferences provided when booking a consultation through Calendly.
  • Project Requirements & RFPs: Technical specifications, business objectives, architectural diagrams, infrastructure requirements, and budget details shared through our Tally forms (Get a Quote and Send a Message).
  • Product Feedback & Testimonials: Reviews, survey feedback, or testimonials you choose to share with us.

B. Information Collected Automatically

When you browse our website, certain technical and telemetry data may be logged automatically by our servers and infrastructure:

  • Device & Network Identifiers: IP address, browser type and version, operating system, device model, and language preferences.
  • Usage Data: Referral source, pages visited, dwell time per section, links clicked, and timestamps.

C. Information We Do NOT Collect

We do not knowingly collect sensitive personal data such as biometric information, genetic data, religious beliefs, political opinions, health records, or government-issued national identity numbers through our website.

3. How We Use Your Information

We use the data we collect solely for legitimate commercial, operational, and engineering purposes:

  • Delivering Services: Evaluating your project specifications, executing development sprints, building infrastructure, and fulfilling contractual deliverables.
  • Communication & Proposals: Answering inquiries, scheduling discovery calls, preparing commercial estimates, and providing technical support.
  • Product Operation: Operating, testing, maintaining, and improving our software products (Schedmate, ManagerJi, CominQR, Slot4Dine, Hupwiz, BuildingBugs).
  • Infrastructure Security & Diagnostics: Monitoring server health, detecting anomalous traffic, preventing distributed denial-of-service (DDoS) attempts, and diagnosing application performance.
  • Legal & Regulatory Compliance: Maintaining accounting records, complying with tax regulations, and honoring statutory requests from authorized legal authorities.

4. Legal Bases for Processing

In accordance with applicable data privacy legislations — including India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and international standards such as the EU General Data Protection Regulation (GDPR) — we process personal data under the following legal bases:

Processing Purpose Legal Ground Context
Answering Inquiries & Consultations Consent & Legitimate Interests Processing contact submissions initiated voluntarily by you.
Executing Client Projects Contractual Necessity Fulfilling service agreements, milestone sign-offs, and warranties.
System Reliability & Security Legitimate Interests Protecting client systems, network integrity, and uptime.
Statutory & Accounting Compliance Legal Obligation Tax records, GST compliance, and regulatory bookkeeping.

5. Client Project Data & Confidentiality

As a Site Reliability Engineering and development agency, Brewnok frequently interfaces with sensitive client systems, code repositories, cloud accounts, and application logs. We maintain strict segregation between general website visitor data and client project data:

  • Non-Disclosure Agreements (NDAs): All client engagements are governed by comprehensive NDAs and Master Services Agreements (MSAs) that safeguard your intellectual property, system architecture, and customer data.
  • Principle of Least Privilege: Access to client environments (AWS, GCP, Azure, Kubernetes, Git repositories) is granted strictly on a need-to-know basis and revoked immediately upon project or SLA conclusion.
  • No Data Harvesting: We never harvest, index, or repurpose client production data or customer databases for machine learning training or commercial resale.
  • Post-Project Purging: Staging environments, local clones, and temporary test databases are securely wiped following handover and the 30-day post-launch support window.

6. Third-Party Services & Integrations

To run our business smoothly, we utilize reputable, security-vetted third-party service providers. These third parties process data on our behalf under strict confidentiality terms:

  • Tally (Tally.so): We use Tally to power our contact and quote intake forms. Submissions are processed over encrypted channels (HTTPS/TLS) and subject to Tally's robust privacy and security safeguards.
  • Calendly (Calendly.com): Used for scheduling 30-minute discovery calls. When booking, your name, email, and meeting notes are processed through Calendly's scheduling engine.
  • Google Fonts: Typography assets are served via Google Fonts to ensure high-performance, accessible visual presentation.
  • Cloud Infrastructure & Hosting: Our web platforms and product staging environments are hosted on tier-1 cloud infrastructure providers adhering to ISO/IEC 27001, SOC 2, and GDPR standards.
  • Professional Social Networks: Links to our official LinkedIn and Instagram profiles are outbound links governed by their respective privacy policies.

7. Cookies & Tracking Technologies

We maintain a minimal cookie footprint. We do not use third-party behavioral advertising cookies or cross-site tracking pixels on brewnok.com.

  • Essential Cookies: Cookies or local storage entries strictly required for website operation, user session management, and CSRF protection.
  • Functional Embedded Cookies: Third-party embeds (such as Calendly meeting popups or Tally forms) may set temporary functional cookies to preserve form progress or remember your timezone.

You can instruct your web browser to refuse all cookies or notify you when a cookie is sent. However, disabling cookies may impact your ability to interact smoothly with embedded meeting widgets.

8. Data Security & Engineering Controls

Given our specialization in SRE, resilience testing, and cloud security, safeguarding data is foundational to our engineering methodology. Our safeguards include:

  • Transport Layer Security: Enforced HTTPS/TLS 1.3 encryption across all web endpoints, securing data in transit between your browser and our servers.
  • Cryptographic Secrets Management: Client API keys, SSH credentials, and environment variables are managed via dedicated secrets vaults; plaintext credentials are never committed to version control.
  • Defensive Engineering: Static code analysis, vulnerability scanning, automated dependency updates, and fault-injection testing.
  • Zero-Trust Architecture: Multi-factor authentication (MFA) is strictly required across all internal administration and infrastructure consoles.

9. Data Retention

We retain personal information only for as long as necessary to fulfill the objectives described in this policy, unless a longer retention period is mandated or permitted by law:

  • Inquiry & Quote Records: General inquiries and quote submissions that do not result in a commercial engagement are routinely purged within 12 to 24 months.
  • Active Client Agreements: Project documentation, contracts, and communication logs are retained for the duration of the commercial relationship plus applicable statutory retention periods (typically 5 to 7 years for financial and tax audits under Indian corporate law).
  • Server Logs: Standard web server connection and access logs are rotated and deleted automatically on a 30-to-90 day cycle.

10. Your Privacy Rights

Regardless of your geographic location, Brewnok provides you with full control over your personal data. Under applicable laws (including India's DPDP Act 2023, EU GDPR, and UK GDPR), you enjoy the following rights:

  • Right to Access: You may request a summary of the personal data we hold about you and how it has been processed.
  • Right to Correction / Rectification: You may request corrections to any inaccurate or incomplete personal information.
  • Right to Erasure ("Right to be Forgotten"): You may request the deletion or removal of your personal data where there is no legal requirement for us to keep it.
  • Right to Withdraw Consent: Where processing is predicated on your consent, you may withdraw your consent at any time without retroactive effect.
  • Right to Data Portability: You may request a machine-readable copy of the data you provided directly to us.
  • Right to File a Grievance: You have the right to register a grievance with our Grievance Officer or escalate to the competent data protection authority.

To exercise any of these rights, please email us directly at brewnok@gmail.com with the subject line "Data Subject Rights Request". We verify identity before processing requests and respond within 30 days.

11. Children's Privacy

Our website, enterprise consulting services, and software products are directed exclusively at businesses, professionals, and individuals aged 18 and above. We do not intentionally or knowingly solicit or collect data from children under the age of 18. If we discover that a child under 18 has provided us with personal information, we will delete it promptly.

12. International Data Transfers

Brewnok is headquartered in India and serves clients worldwide. If you access our website or engage our services from outside India (e.g., the European Economic Area, United Kingdom, United States, or Australia), please note that your information may be processed and stored on servers located in India or other jurisdictions where our cloud infrastructure providers operate.

We ensure that any cross-border transfer complies with legally recognized transfer mechanisms, including Standard Contractual Clauses (SCCs) and appropriate technical safeguards, ensuring your data retains equivalent protection.

13. Policy Updates

We may update this Privacy Policy periodically to reflect technological changes, new service offerings, or updated regulatory requirements. Any modifications will be posted to this page with an updated "Last Updated" timestamp at the top of the policy.

We encourage you to review this policy periodically. Continued use of our website or services after changes take effect constitutes your acknowledgment of the updated policy.

14. Grievance Redressal & Contact Information

If you have any questions, concerns, feedback, or grievances regarding this Privacy Policy or our data handling practices, please contact our designated Grievance Officer:

Brewnok Data Governance

Organization: Brewnok

Location: Agartala, Tripura, India

Direct Email: brewnok@gmail.com

Website: https://brewnok.com

Response Window: We aim to acknowledge and resolve all privacy queries within 15–30 business days.