Back to home

PrivacyPolicy.

Effective
20 July 2026
Version
1.0
Applies to
melmanlabs.com and all engagements

The short version

Not a substitute for the sections below

We collect as little as possible, use it only to answer you, and never sell it. That's the whole policy in one line.

01

Only what you send us

The contact form collects your name, email, and what you tell us. Company and budget are optional.

02

No advertising trackers

No Facebook pixel, no ad networks, no cross-site tracking, no profiling. We don't run advertising.

03

We never sell your data

Not to anyone, in any form, ever. We share it only with the processors listed in section 5.

04

Enquiries deleted in 24 months

If an enquiry doesn't become an engagement, it's removed. Ask sooner and we'll do it sooner.

05

Client data is yours

Where we handle personal data inside systems we build, we act on your instructions only.

06

Ask and we'll act

Want a copy of what we hold, or want it deleted? One email. We respond within 30 days.

Contents

1. Who we are

Melman Labs is a software engineering and consultancy practice based in India. For the purposes of data protection law we are the data controller for information collected through this website and through direct correspondence with us.

Where we process personal data inside systems we build or operate for a client, that client is the controller and we act as a processor on their instructions. Section 9 covers that arrangement.

You can reach us about anything in this policy at webinngo@gmail.com.

2. What we collect

Information you give us. When you submit the contact form we collect your name, email address, the engagement type you selected, and the message you write. Company name and budget range are optional fields — leave them blank and we will not have them.

Information from correspondence. If you email or call us, we retain that correspondence and any information contained in it.

Information collected automatically. Our hosting provider records standard server logs including IP address, browser type, referring page, and timestamp. These are generated by the infrastructure rather than by us, and are used for security and diagnostics.

What we do not collect. We do not collect payment card details through this website, we do not build behavioural profiles, and we do not purchase personal data from third parties.

3. Why we collect it

We use the information you submit to respond to your enquiry, to assess whether we are a suitable fit for the work, and to prepare a scope document if the engagement proceeds.

Where an engagement begins, we use your contact details to administer it — sending scope documents, invoices, and project correspondence.

Our lawful basis is legitimate interest in responding to enquiries directed at us, and performance of a contract once an engagement begins. Where we rely on consent — for example if you ask to receive occasional writing from us — you may withdraw it at any time.

We do not use your information for automated decision-making or profiling.

4. Cookies and analytics

This website sets no cookies of its own. We use no advertising cookies, no third-party tracking pixels, and no cross-site identifiers.

Your browser’s dark or light mode preference is read from your operating system setting and held in memory for the duration of your visit. Nothing is written to your device and nothing persists after you close the tab.

Where we use analytics, we use a privacy-respecting, cookieless provider that reports aggregate page views without identifying individual visitors. If this changes we will update this section before the change takes effect.

5. Who we share with

We do not sell, rent, or trade personal data. We share it only with service providers necessary to operate, and only to the extent necessary:

Hosting provider — serves this website and generates the server logs described in section 2. Email provider — delivers and stores correspondence with you. Form processing service — receives contact form submissions and forwards them to our email. Accounting software — holds invoicing details for clients, as required for tax records.

Each of these acts as a processor under contract and may not use your data for their own purposes.

We may also disclose information where required by law, court order, or a lawful request from a public authority, and where necessary to establish or defend legal claims.

6. How long we keep it

Enquiries that do not become engagements are deleted 24 months after the last contact. If you ask us to delete sooner, we will.

Client records are kept for the duration of the engagement and for seven years afterwards, which is the retention period required for financial and tax records in India.

Server logs are retained by our hosting provider on a rolling basis, typically 30 days.

Correspondence is retained while it remains relevant to an active or prospective engagement, subject to the periods above.

7. How we protect it

We apply the same standards to our own data that we apply to the systems we build for clients: encryption in transit on every service, access limited to those who need it, multi-factor authentication on all accounts holding personal data, and least-privilege configuration throughout.

We do not keep local unencrypted copies of client data, and we remove access credentials at the end of an engagement.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and in any case within 72 hours of becoming aware of it.

8. Your rights

You have the right to request a copy of the personal data we hold about you; to have inaccurate data corrected; to have your data deleted where we have no overriding legal obligation to retain it; to restrict or object to our processing; to receive your data in a portable format; and to withdraw consent where processing is based on it.

To exercise any of these, email webinngo@gmail.com. We respond within 30 days and do not charge for reasonable requests.

If you are unsatisfied with our response, you may complain to your local data protection authority. In India this is the Data Protection Board; in the EU or UK it is your national supervisory authority.

9. Client data we process

Where an engagement requires us to access systems containing personal data belonging to a client’s users, we act as a processor and the client remains the controller.

In that role we process personal data only on the client’s documented instructions; access only the minimum necessary to perform the work; do not export production data to local machines except where strictly required for debugging, and delete such copies immediately afterwards; and do not use client data for any purpose of our own, including testing, training, or demonstration.

On termination of an engagement we delete or return personal data in our possession as the client directs. Specific obligations are set out in the engagement’s terms and any separate data processing agreement.

10. International transfers

We are based in India and work with clients in other jurisdictions. Some of our service providers store data outside India, principally in the European Union and the United States.

Where personal data is transferred internationally, we rely on the provider’s standard contractual clauses or an equivalent recognised safeguard, and we take account of the destination jurisdiction’s protections before transferring.

If you require that your data remains within a specific jurisdiction, tell us before an engagement begins and we will confirm whether we can accommodate it.

11. Children

This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 18.

If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes and contact

We may update this policy as our practices or the law change. Material changes are published here with a revised effective date and version number. Where an engagement is active, we notify the client directly of material changes.

The version in force is the one published on this page at the time of your visit. Previous versions are available on request.

Questions, requests, or complaints about this policy go to webinngo@gmail.com.

Exercise your rights

Want a copy of what we hold, a correction, or deletion? One email is enough — no form, no account required. We respond within 30 days.

webinngo@gmail.com