Smart Tech Innovation — Software Development & Technology Solutions
Legal & Compliance

Privacy Policy

Last updated August 2026. This privacy policy explains how Smart Tech Innovation collects, processes, protects and retains your personal data, and details your legal rights under global data protection laws.

1. Data Controller & General Information

**Smart Tech Innovation** ('we', 'us', 'our') operates the website [smarttechinnovation.com](https://smarttechinnovation.com/) and is the data controller responsible for your personal information under the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the UK Data Protection Act 2018 / UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and applicable international privacy frameworks.

We are a software engineering company providing custom software development, web and mobile application engineering, SaaS platform architecture, AI solutions and business automation for businesses worldwide.

If you have any questions regarding this policy, your personal data, or wish to exercise your legal rights, you may contact our Data Protection team directly at: [[email protected]](mailto:[email protected]).

2. Information We Collect

We collect only the minimum personal information necessary to deliver our services, respond to project inquiries, secure our digital infrastructure, and maintain transparent commercial relationships.

**A. Information you provide directly to us:**

• **Contact Form & Project Briefs:** When you request a consultation or contact us, we collect your full name, work email address, company or organisation name, phone number, project scope, requirements, estimated budget, and the contents of your message.

• **Commercial Correspondence:** Communication history across emails, project scoping calls, technical briefs, and non-disclosure agreement (NDA) negotiations.

• **Client Onboarding Records:** Billing information, tax identification numbers, authorized contact persons, and infrastructure credentials shared securely during contracted software engagements.

**B. Information collected automatically (Technical & Log Data):**

When you access and browse our website, our servers automatically record standard technical log data to ensure network resilience and protect against cyberattacks. This may include your IP address, browser type and version, operating system, referring URL, pages viewed, time spent on pages, and server access timestamps.

3. Lawful Bases for Processing (GDPR & International Standards)

We process your personal information only when a valid legal basis exists under Article 6 of the GDPR:

• **Consent (Art. 6(1)(a)):** When you voluntarily submit an inquiry form or consent to specific communications.

• **Contractual & Pre-Contractual Necessity (Art. 6(1)(b)):** Processing required to evaluate your software requirements, provide estimates, negotiate agreements, and execute deliverables.

• **Legal Obligation (Art. 6(1)(c)):** Retaining statutory financial records, tax accounting, and complying with lawful government or regulatory requests.

• **Legitimate Interests (Art. 6(1)(f)):** Operating, analyzing, debugging, and securing our website against unauthorized access, malicious bots, and DDoS attacks, as well as managing business inquiries in an organized manner.

4. Cookies, Tracking Technologies & Advertising Disclosures (Google AdSense Compliant)

Our website is engineered for speed, privacy, and minimal footprint. We use cookies and similar web technologies only where strictly necessary for site functionality, performance, and compliance.

**Google AdSense & Third-Party Advertising Disclosures:**

• Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to our website or other websites on the Internet.

• Google's use of advertising cookies (such as the DoubleClick cookie / DART cookie) enables it and its partners to serve ads to our users based on their visits to our site and/or other sites across the Internet.

• Users may opt out of personalized advertising at any time by visiting [Google Ads Settings](https://adssettings.google.com/).

• Alternatively, you may opt out of a third-party vendor's use of cookies for personalized advertising by visiting the [Network Advertising Initiative Opt-Out Page](https://optout.networkadvertising.org/) or [AboutAds Consumer Choices](https://www.aboutads.info/choices/).

**Managing Cookies:** Most web browsers allow you to control cookies through browser settings (blocking third-party cookies, deleting stored cookies, or disabling cookies entirely). Disabling cookies will not affect your ability to browse our content or submit contact forms.

5. Third-Party Processors & Sub-processors

We do not sell, rent, monetize, or trade your personal data to data brokers or marketing lists. We share data only with vetted service providers (processors) who assist in hosting, communication, and infrastructure under strict data processing agreements:

• **Cloud Hosting & CDN Providers:** Secure cloud infrastructure (such as Google Cloud / Firebase Storage, AWS, Hostinger) for delivering web assets and media.

• **Communication & Form Delivery Providers:** Encrypted email routing and transactional form submission handlers used exclusively to deliver your messages to our engineering team.

• **Legal & Accounting Authorities:** Professional legal counsel and certified accounting auditors strictly to meet statutory compliance obligations.

6. International Data Transfers & Security Safeguards

Because our clients and technology partners operate globally, data may be transferred to and stored in servers located outside your country of residence. Where cross-border transfers occur, we implement robust contractual safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTA).

All data transmission across our website is protected by modern Transport Layer Security (TLS 1.3 / HTTPS). Internal access to inquiry data is strictly restricted to engineers and authorized personnel under least-privilege access controls.

7. Data Retention & Erasure Schedule

We retain personal data only for as long as necessary to fulfill the purposes for which it was gathered:

• **General Inquiries:** Inquiries that do not lead to a formal contract are securely deleted within 24 months.

• **Contracted Engagements:** Correspondence, project specifications, and financial documentation for contracted clients are retained for the duration of the engagement and up to 7 years thereafter to satisfy statutory tax, accounting, and legal liability requirements.

• **Right to Earlier Deletion:** You may request the immediate deletion of your personal data at any time, subject to overriding statutory retention obligations.

8. Your Legal Rights (GDPR, UK GDPR, CCPA / CPRA)

Depending on your location and applicable law, you have enforceable privacy rights regarding your personal data:

• **Right of Access (DSAR):** You have the right to request a copy of the personal data we hold about you.

• **Right to Rectification:** You have the right to have incomplete or inaccurate data corrected without undue delay.

• **Right to Erasure ('Right to be Forgotten'):** You may request that we delete your personal data where no overriding legal requirement exists to retain it.

• **Right to Restriction of Processing:** You can request that we temporarily suspend the processing of your data while an accuracy check or objection is resolved.

• **Right to Data Portability:** You have the right to receive your personal data in a structured, commonly used, machine-readable format.

• **Right to Object:** You have the right to object to processing based on legitimate interests or direct marketing.

• **Right to Withdraw Consent:** Where processing is based on consent, you may withdraw it at any time with immediate effect.

• **California Privacy Rights (CCPA / CPRA):** California residents have the right to know what personal categories are collected, request deletion, and not receive discriminatory treatment for exercising their privacy rights. We do not sell or share personal information.

• **Right to Complain:** You have the right to lodge a complaint with your local Data Protection Authority (such as the ICO in the UK, CNIL in France, or your national supervisory authority).

9. Protection of Minors (COPPA)

Our website and software services are exclusively intended for commercial enterprises, professionals, and adults aged 18 and older. We do not knowingly collect, solicit, or store personal data from children under 16 years of age. If we learn that a minor has submitted personal information, we will delete that data immediately.

10. Updates to This Policy & How to Contact Us

We may update this Privacy Policy periodically to reflect changes in our technology, operational practices, or international legal requirements. Any modifications will be posted here with an updated revision date.

To exercise your rights, request data deletion, or ask privacy questions, please contact our team at: [[email protected]](mailto:[email protected]). We will respond to verified requests within thirty (30) days.