Privacy Policy & Technical Safeguards
How Sutra Tech Labs protects proprietary client architecture, technical scoping briefs, and commercial operational data with zero compromise and enterprise-grade confidentiality.
Purpose & Scope of This Policy
Sutra Tech Labs ("Sutra", "we", "our", or "us") operates as a premier bespoke software engineering lab based in Kathmandu, Nepal. We architect, design, and engineer custom web platforms, multi-branch enterprise ERPs, payment mesh integrations, and high-concurrency cloud systems.
This Privacy Policy governs the processing, retention, and isolation of information provided by prospective clients, active engineering partners, enterprise stakeholders, and visitors through our web application at sutratechlabs.com and our direct engineering intake channels.
Information We Collect & Process
We adhere to strict data minimization principles—collecting solely what is technically necessary to evaluate domain requirements, draft architectural blueprints, and execute software development contracts.
- •Primary stakeholder name, work email, and phone number.
- •Company or organization identity and operating geography.
- •System specifications, domain models, and workflow briefs.
- •Target launch timeline, scalability parameters, and budget tier.
- •Anonymized edge request routing and latency diagnostics.
- •Browser user-agent, operating system, and viewport category.
- •Rate-limiting counters and anti-DDoS challenge verification.
- •Zero cross-site trackers or invasive behavioral recording.
How We Utilize Technical Data
Information provided to Sutra Tech Labs is utilized exclusively for engineering evaluation and project execution:
Data Security & Infrastructure Standards
Security is engineered into our foundation. We maintain rigorous physical, electronic, and procedural controls to isolate sensitive client systems:
All data in transit is encrypted using modern cipher suites with strict forward secrecy.
Stored intake records and architecture diagrams are encrypted with hardware security modules.
Zero shared credentials; mandatory biometric MFA and least-privilege repository permissions.
Subprocessors & Infrastructure Partners
To deliver global sub-50ms latency and high availability, we partner with industry-standard, SOC-2 and ISO 27001 certified infrastructure vendors:
| Subprocessor | Purpose | Location | Compliance |
|---|---|---|---|
| Vercel Inc. | Edge Web Hosting & Serverless Compute | Global Edge | SOC-2 Type II |
| Amazon Web Services (AWS) | Encrypted Cloud Storage & Database Backups | ap-south-1 | ISO 27001 / SOC-2 |
| Cloudflare, Inc. | Edge DNS, TLS Termination & Anti-DDoS | Global Anycast | ISO 27001 / SOC-2 |
| Resend Inc. | Transactional Notification Infrastructure | US / Global | GDPR / SOC-2 |
Your Data Rights & Deletion Guarantee
Regardless of your operating jurisdiction, we extend full sovereign rights over your organizational and technical data:
You may request immediate, permanent cryptographic deletion of your scoping submissions, intake forms, and contact records at any time.
You may request a standardized structured export (JSON / PDF) of all architectural notes and technical blueprints generated during intake.
Contact & Data Protection Desk
For privacy inquiries, audit verification, NDA signing, or immediate data deletion requests, contact our dedicated engineering privacy desk: