Overview
Hygravity Solutions processes client data as part of delivering software development, digital marketing, and design services to clients worldwide. We take data security extremely seriously and maintain enterprise-grade security controls across all our systems and workflows.
This policy describes the technical and organizational measures we implement to protect client data from unauthorized access, disclosure, alteration, or destruction.
Encryption
Data in Transit
- • TLS 1.3 for all website communications
- • HTTPS enforced across all services
- • Encrypted API communications (REST/GraphQL)
- • VPN for team member remote access
- • End-to-end encrypted file sharing (Signal, Proton)
Data at Rest
- • AES-256 encryption for all stored data
- • Encrypted cloud storage (AWS S3 with SSE)
- • Encrypted database volumes
- • Encrypted password manager (1Password/Bitwarden)
- • Full-disk encryption on all team devices
Access Control
We implement strict access control measures using the principle of least privilege:
Role-Based Access Control (RBAC)
Each team member has access only to the systems and data required for their specific role.
Multi-Factor Authentication (MFA)
MFA is mandatory for all internal systems, cloud accounts, and client-facing tools.
Zero Trust Architecture
No implicit trust within the network. Every access request is verified regardless of location.
Access Reviews
Regular access reviews conducted quarterly to remove stale permissions and accounts.
Client Credential Isolation
Client credentials are stored in isolated vaults, accessible only to assigned team members.
Backup & Recovery
We maintain comprehensive backup procedures to ensure data availability:
Data Retention
Client data is retained only as long as necessary:
Upon client request, all data is securely deleted (overwritten) within 30 days of a deletion request.
Incident Response
In the event of a data breach or security incident:
Detection & Containment
Within 1 hourImmediate isolation of affected systems to prevent further exposure.
Assessment
Within 4 hoursDetermine scope, nature, and impact of the breach.
Client Notification
Within 24 hoursAffected clients notified via email with details of the incident.
Regulatory Notification
Within 72 hoursNotify relevant data protection authorities as required by GDPR/DPDPA.
Remediation
OngoingRoot cause analysis, patch deployment, and enhanced controls.
Post-Incident Report
Within 30 daysFull incident report shared with affected clients.
Legal Compliance
Our data practices comply with regulations and standards applicable in jurisdictions where our clients operate:
GDPR
General Data Protection Regulation (EU/UK)
Europe & UKDPDPA 2023
Digital Personal Data Protection Act (India)
IndiaIT Act 2000
Information Technology Act (India)
IndiaQuestions about this policy?
Contact our team at hello@hygravity.com or reach us at our India or UK office.
