Privacy Policy
Effective date: 16 September 2026 | Last updated: 16 September 2026
AmcoderZ Infotech (“AmcoderZ”, “we”, “us”) is a software development company based in Ahmedabad, India. This policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have over it.
It covers visitors to amcoderz.com, people who contact us about a project, and clients whose systems we build or maintain. Where we handle personal data belonging to a client’s own customers or patients, different rules apply — those are set out in Section 6.
1. Who we are
AmcoderZ Infotech
704, City Center 1, Science City Road, Opp. Sukan Mall, Science City, Sola, Ahmedabad, Gujarat 380060, India
Email: info@amcoderz.com | Phone: +91 9277709780
You can read more about our company and the services we provide.
2. Our role in handling personal data
We handle personal data in two different capacities, and the rules differ between them:
- As a controller: For data we decide the purpose of ourselves — website analytics, enquiries, client business contacts, invoicing and our own security logs — we are the data controller, or data fiduciary under Indian law.
- As a processor: For personal data belonging to a client’s customers, patients or users, which we encounter while building or maintaining their systems, the client is the controller and we act as processor, or service provider. We process that data only on their documented instructions. This is covered in Section 6.
3. Information we collect
- Server and security logs: IP address, request timestamps and error data, recorded by our hosting infrastructure for security and troubleshooting.
- Website analytics: Device type, browser, pages viewed, time on page, approximate location and referral source. Our analytics provider does not record raw IP addresses.
- When you contact us: Name, email address, phone number, company name, and whatever you include in your message or project brief.
- When you book a call: The time slot you select, your time zone, and the contact details you provide to the scheduling tool.
- When you become a client: Billing details, contract information, the names and contact details of people at your organisation we work with, and any credentials or system access you provide for the project.
Third-party tools
| Provider | Purpose | Data involved |
|---|---|---|
| Google Analytics | Website analytics | Usage and device data |
| Google Tag Manager | Tag deployment | Depends on the tags deployed |
| Calendly | Meeting scheduling | Contact and booking details |
| hosting provider | Website hosting | Server and log data |
| live chat provider | Website chat | Chat transcripts, contact details |
| email provider | Communications | Email and contact details |
| CRM, or delete this row | Lead management | Contact and project details |
We do not buy personal data from third parties, and we do not sell it.
4. How we use your information
- To respond to enquiries and provide project estimates
- To deliver, support and maintain the software we build for you
- To issue invoices and manage contracts
- To improve our website and understand how it is used
- To secure our systems and investigate misuse
- To meet legal, tax and accounting obligations
We do not sell or rent your contact details, and we do not add you to marketing lists without your consent. If we send you anything beyond a direct reply, it is because you opted in, and you can unsubscribe at any time.
5. Legal basis for processing
The bases below apply where GDPR or UK GDPR governs the relevant processing. These laws can apply to organisations outside the EU and UK where services are offered to, or the behaviour of, individuals in those regions is involved.
| What we process | Legal basis |
|---|---|
| Enquiry and contact details | Legitimate interest — responding to a request you made |
| Client and billing data | Performance of a contract |
| Analytics and non-essential cookies | Consent, where required |
| Server and security logs | Legitimate interest — securing our systems |
| Accounting and tax records | Legal obligation |
Client end-user data: Where we act as a processor, the client as controller determines the lawful basis. We process that data only on documented instructions and under the applicable data processing agreement.
Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect processing that has already taken place.
6. Client project data
This section covers personal data belonging to our clients’ own customers, patients or users. It applies across our work, including custom software development, healthcare software development and mobile app development.
How we handle it:
- Development and testing use de-identified or synthetic data wherever the work allows it
- Access to client production systems is restricted to named team members
- Access is revoked when a project or support agreement ends
- Client production data is returned or deleted in accordance with the applicable agreement and our documented retention and backup schedules
- Every project is covered by a non-disclosure agreement
Healthcare projects: Where HIPAA applies to an engagement, we enter into an appropriate Business Associate Agreement where required. HIPAA compliance is not a certification a development vendor can hold — no such certification exists. HIPAA places obligations on covered entities, and vendors handling protected health information take on part of those obligations contractually through a BAA.
Subprocessors: Where a project requires a third-party service — cloud hosting, error monitoring, a notification provider — this is handled in accordance with the data processing terms agreed with the client.
7. Who we share data with
We share personal data only where necessary:
- Cloud and hosting providers — for the infrastructure our services run on
- Analytics providers — for website usage data in aggregate
- Payment and accounting providers — for invoicing
- Professional advisers — accountants and lawyers, where required
- Authorities — only where legally compelled
We do not sell personal data, and we do not share it for third-party advertising.
8. How long we keep data
| Data | Retention |
|---|---|
| Server and security logs | [FILL: retention period — confirm with hosting provider] |
| Website analytics | Retained for the period configured in our analytics property |
| Enquiries that do not become projects | [FILL: 12 or 24 months after last contact] |
| Client contracts and billing records | As required by Indian tax law, then deleted |
| Client project data | Returned or deleted at the end of the engagement, as set out in the contract |
Where a retention period is set by law, we keep the data for that period and no longer.
9. How we protect data
- Data exchanged with our systems is encrypted in transit
- Access to client systems is restricted to named team members
- Development and production environments are kept separate
- Non-disclosure agreements cover all staff and all projects
No system is completely secure. If a breach occurs that affects your personal data, we will notify you and the relevant authority within the timeframes the applicable law requires.
10. Your rights
Depending on where you are based, you may have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data, where we have no legal reason to keep it
- Restrict or object to how we process it
- Receive a copy in a portable format
- Withdraw consent where consent is the basis we rely on
- Complain to a supervisory authority
If you are in the UK, that authority is the Information Commissioner’s Office. In the EU it is your national data protection authority. In India it is the Data Protection Board of India.
California residents: Where the CCPA applies to us, California residents also have the right to know what personal information is collected and how it is used, to delete it, to correct it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of these rights, email info@amcoderz.com. We respond within the timeframe required by the law that applies to you — one month under GDPR and UK GDPR, and 45 days under the CCPA. If a request is complex we will tell you and explain why more time is needed.
11. Cookies
Our website uses cookies and similar technologies for:
- Essential: making the site work and remembering your preferences
- Analytics: understanding how visitors use the site
- Functional: the live chat widget and scheduling tool
You can block or delete cookies through your browser settings. Blocking essential cookies may affect how the site works.
12. International data transfers
We are based in India. If you contact us from outside India, your data is transferred to and processed in India.
Where clients require regional data residency, we can configure hosting arrangements accordingly. However, authorised support or development access from other locations may itself constitute an international transfer, and is governed by the applicable contractual and legal safeguards.
13. Children
Our services are intended for businesses. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete it.
14. Changes to this policy
We may update this policy as our services or the law changes. The dates at the top show when it took effect and when it was last revised. Material changes affecting clients will be communicated directly.
15. Contact
Questions about this policy or about how we handle your data:
AmcoderZ Infotech
704, City Center 1, Science City Road, Opp. Sukan Mall, Science City, Sola, Ahmedabad, Gujarat 380060, India
Email: info@amcoderz.com | Phone: +91 9277709780
Hours: Monday to Saturday, 10:00 AM – 8:00 PM IST
You can also reach us through our contact page, or read our terms and conditions.

