WORK SOLUTIONS RESOURCES ABOUT
START A CONVERSATION
TEAMONTIME PROTOCOL // PRIVACY

PRIVACY SHOULD BE
CLEAR. NOT CONFUSING.

How TeamOnTime safeguards agency intellectual property, merchant databases, and developer credentials.
Built on purpose limitation, AES-256 encrypted vaults, and zero data monetization.

Zero Data Sales Guarantee
DPDP Act 2023 & GDPR Aligned
AES-256 Vault Encryption
30-Day Credential Purge

BUILT FOR INVISIBLE
AGENCY SECURITY.

Operating as an invisible software engineering operating system requires strict adherence to privacy-first engineering standards. We treat agency repositories and merchant credentials with absolute confidentiality.

We never monetize, rent, or sell client data under any circumstances. Information collected is strictly restricted to fulfilling engineering Statements of Work (SOWs), executing Git pull requests, and maintaining real-time developer communication.

PRIVACY PROTOCOL STATUS ● VERIFIED COMPLIANT
COMMERCIAL DATA SALES 0% ZERO DATA SALES
CREDENTIAL STORAGE AES-256 VAULT ENCRYPTED
REGULATORY ALIGNMENT DPDP ACT 2023 • IT ACT 2000
STAGING RETENTION 30-DAY AUTOMATED PURGE
GRIEVANCE DESK ACTIVE DPO OFFICE

HOW INFORMATION MOVES SAFELY.

A transparent, deterministic progression from initial agency intake to post-delivery credential erasure.

01 // INTAKE

Encrypted Vault Ingestion

Agency shares staging API keys and access tokens via 1Password or HashiCorp Vault. Restricted solely to assigned lead engineers.

AES-256 VAULT ACCESS
02 // PURPOSE

Strict Purpose Limitation

Data is utilized exclusively to fulfill approved Statement of Work (SOW) sprint tickets, build custom sections, and deploy features.

PERMITTED SOW PURPOSE
03 // PROCESS

Masked Git Execution

Commits and PRs are executed inside your agency Git repositories under agency domain aliases with zero public metadata trace.

MASKED GIT COMMITS
04 // PURGE

30-Day Automated Delete

Upon final code handoff, all temporary developer credentials, access tokens, and staging dumps are permanently wiped from internal vaults.

CERTIFICATE OF ERASURE

FOUR DATA INTEGRITY COMMITMENTS.

The explicit principles governing data collection, access control, and engineering isolation.

01 // PRINCIPLE

Purpose Limitation

Data collected is strictly restricted to fulfilling engineering Statements of Work (SOW), executing Git pull requests, and maintaining real-time developer communication inside agency Slack workspaces.

✓ SOW-SCOPED USE ONLY
02 // PRINCIPLE

Data Minimization

We request only essential developer tokens, API endpoints, and staging credentials. Production keys are stored in encrypted vaults and purged immediately post-handoff.

✓ LEAST PRIVILEGE DATA
03 // PRINCIPLE

Storage Limitation & Purge

All temporary staging credentials, developer logs, and project database dumps are automatically queued for deletion 30 days after sprint handoff verification.

✓ 30-DAY PURGE CYCLE
04 // PRINCIPLE

Brand Anonymity & Masking

Commits map strictly to your agency domain email aliases. Development preview builds are deployed on password-protected staging containers with `noindex, nofollow` headers.

✓ ZERO PUBLIC FOOTPRINT

YOUR RIGHTS & GRIEVANCE REDRESSAL.

Enforceable rights and transparent governance under the Indian DPDP Act 2023 and global GDPR principles.

Right to Summary & Access

Agency partners reserve full rights to request a clear summary of all technical credentials, personal records, and telemetry processed during active engagements.

DPDP ACT §11(1) • GDPR ART 15

Right to Correction & Update

Instant updating and correction of inaccurate billing details, developer account access lists, point-of-contact information, or server endpoints upon notice.

DPDP ACT §12(1) • GDPR ART 16

Right to Complete Erasure

Immediate deletion of non-essential project telemetry, staging instances, and developer secrets, followed by issuance of a Certificate of Data Erasure.

DPDP ACT §12(3) • GDPR ART 17

Right to Nominate Representative

Agencies may formally designate authorized technical leads or legal representatives to exercise data principal rights on behalf of the agency partnership.

DPDP ACT §14 • AUTHORIZED PROXY

Data Protection Officer & Grievance Desk

To exercise data principal rights, request data summaries, or submit privacy inquiries, reach out directly to our Data Protection Officer. We review and process requests within 72 business hours.

OFFICIAL DPO CHANNEL privacy@teamontime.com Surat, Gujarat • IT Act 2000 §10A

CLEAR INFORMATION.
CLEAR BOUNDARIES.

Zero Data Sales Guarantee • AES-256 Vault Encryption • DPDP Act 2023 Aligned

FREQUENTLY ASKED QUESTIONS.

Direct answers regarding data storage, credentials, cookies, and regulatory compliance.

Does TeamOnTime sell agency or merchant data? +
Never. We operate under bilateral NDA. We do not sell, rent, monetize, or disclose your agency identity, client roster, or merchant revenue numbers under any circumstances.
TeamOnTime operates under strict purpose limitation, data minimization, and encryption standards aligned with the Digital Personal Data Protection Act 2023 and Information Technology Act 2000.
All credentials shared during onboarding are encrypted using AES-256 via enterprise password vault integrations (1Password / HashiCorp). Access is strictly restricted to assigned pod engineers.
30 days post-project handoff, all temporary developer credentials, access tokens, and staging database dumps are automatically purged from our internal systems.
We utilize strictly essential session cookies necessary for website performance and security monitoring. We do not use intrusive cross-site tracking scripts or ad retargeting networks.
Upon account termination or completion of an SOW build, all temporary staging instances and stored credentials enter a 30-day deletion queue, after which a Certificate of Data Erasure can be issued.
CLIENT HAS THE SPOTLIGHT

TEAMONTIME BUILDS THE ENGINE.