Privacy Policy

How SMRKONOVA protects data, user privacy, and proprietary information across our enterprise systems and client partnerships.

LAST UPDATED: FEBRUARY 15, 2026

SMRKONOVA (“SMRKONOVA,” “we,” “us,” or “our”) respects your privacy and is dedicated to protecting your personal information. This Privacy Policy outlines how we collect, store, handle, and disclose personal data gathered across our websites, enterprise engineering portals, APIs, client consulting engagements, and related developer platforms (collectively, our “Services”).

At SMRKONOVA, our core principle is rooted in data minimality, user sovereignty, and enterprise-grade operational security. We never sell, rent, or trade your personal data. Any data collected is retained solely to deliver, secure, and optimize our digital systems and technical collaborations. If you have questions regarding this policy or our data practices, contact us at privacy@smrkonova.com.

1. SMRKONOVA as a Service Provider and Sub-Processor

SMRKONOVA provides digital infrastructure architecture, software development, cloud operations, and systems integration services to our enterprise Clients. In providing these engineering services, SMRKONOVA frequently acts as a Service Provider and “Sub-Processor” or “Processor” on behalf of our Clients, who act as the primary Data Controllers.

Where SMRKONOVA processes data strictly on behalf of our corporate Clients, we do so strictly pursuant to executed Master Services Agreements (MSAs) and Data Processing Addenda (DPAs). We do not control or own the telemetry, database payloads, or proprietary assets our Clients ingest into their cloud clusters or software environments. If you are an end-user, employee, or partner of one of our Clients and have inquiries regarding your personal information processed within their systems, please direct your inquiry directly to that respective entity.

2. Personal Information We Collect

In the table below, we outline the categories of Personal Information that SMRKONOVA has collected within the last twelve (12) months, the sources from which information is derived, and the operational purposes for which it is processed:

EXAMPLES / CATEGORIES OF PERSONAL INFORMATIONSOURCES OF PERSONAL INFORMATIONPURPOSES FOR PERSONAL INFORMATION COLLECTION
Identifiers:Name, business email address, company name, phone number, enterprise IP address.Direct Submissions & Enterprise OnboardingEstablishing client communications, account authorization, enterprise provisioning, verifying technical support tickets, and service onboarding.
Commercial Information:Scope of contracted services, signed statements of work (SOWs), billing records, payment histories.Direct Submissions & Enterprise ContractingFulfilling contractual scope, invoicing, financial reporting, corporate tax audits, and ongoing account administration.
Payment & Billing Information:Bank account wire instructions, masked credit card tokens (processed via PCI-DSS certified gateway), VAT/GST identifiers.Direct Submissions & Merchant ProcessorsExecuting wire receipts, processing project retainer payments, resolving billing inquiries, and fraud mitigation.
Professional / Employment Details:Job titles, engineering roles, department affiliations, technical credentials provided during partnership.Direct Submissions & Enterprise Client RecordsAssembling dedicated engineering pods, evaluating technical competency, team communication, and managing project milestones.
Internet & Electronic Network Activity:Browser type, operating system, device telemetry, request timestamps, pages visited, API diagnostic logs.Automated Platform Telemetry & Server LogsSystem uptime monitoring, mitigating DDoS and malicious queries, identifying application regressions, and interface performance tuning.
Geolocation Data:General coarse regional location derived from business IP address.Automated Network TelemetryEnsuring compliance with localized data sovereignty regulations, edge cache routing, and server load balancing.

In the preceding 12 months, SMRKONOVA has not collected biometric identifiers, protected health information (PHI), or sensory audio/visual surveillance data from general website visitors.

3. How We Collect Personal Information

SMRKONOVA gathers personal and technical data through three transparent methods:

  • Direct Submissions: Technical inquiries, RFPs, contact submissions, contract onboarding, credential generation, and direct support tickets initiated by authorized client personnel.

  • Automated Platform Telemetry: Server logs, telemetry collectors, and essential performance cookies deployed across our hosted web properties and customer portals.

  • Third-Party & Commercial Partners: Verified business referrals, enterprise directories, payment settlement gateways, and public repositories relevant to active technical consulting scopes.

4. Cookies and Tracking Technology

We employ cookies, HTTP state tokens, and local web storage to maintain interface continuity, enhance security, and monitor system performance.

Essential / Necessary Cookies:

These tokens are cryptographically required to safeguard sessions, prevent Cross-Site Request Forgery (CSRF), and authenticate active engineers. You cannot disable these via settings without interrupting platform utility.

Performance & Telemetry Headers:

We use minimal aggregated analytics to identify platform bottlenecks, optimize server routing, and evaluate documentation readability. These metrics do not profile users across unrelated third-party websites.

Browser Control Instructions:

Most modern web browsers allow you to disable cookies or clear stored cache via application settings. Note that disabling essential security tokens will prevent login to SMRKONOVA client dashboards and development staging environments.

5. How We Use the Personal Information We Collect

We process collected data strictly under verified legal and operational grounds:

  • Provisioning, executing, and maintaining enterprise software, digital architectures, and cloud services.
  • Verifying client authorizations, executing signed statements of work, and issuing statutory tax invoices.
  • Mitigating security vulnerabilities, monitoring infrastructure uptime, and defending against unauthorized API queries.
  • Communicating critical system advisories, security patches, scheduled maintenance windows, and technical releases.
  • Complying with regulatory obligations, financial audits, corporate tax governance, and lawful government requests.
  • Continuously tuning web performance, documentation clarity, and developer interface latency.

6. How We Share Personal Information

SMRKONOVA does not disclose personal data to third parties for monetary consideration. We only share information with vetted sub-processors and entities bound by rigorous data confidentiality agreements:

  • Cloud Infrastructure & Hosting Sub-Processors: Enterprise cloud providers (e.g., AWS, GCP, Vercel) operating under certified SOC2 Type II and ISO 27001 data processing agreements.

  • Operational Service Providers: Secure payment processors, billing automation systems, enterprise ticketing desks, and cryptographic key management vaults.

  • Business Reorganizations: In the event of an acquisition, corporate restructuring, merger, or asset transfer, where data transfer is conducted under executed non-disclosure agreements.

  • Legal & Regulatory Authorities: When strictly mandated by valid legal process, judicial subpoena, or statutory enforcement orders under applicable law.

7. European Data Privacy Rights

If you are located within the European Economic Area (EEA), the United Kingdom, or Switzerland, you are entitled to statutory protections under the General Data Protection Regulation (GDPR) and UK GDPR:

Lawful Basis for Processing: We process personal data solely when necessary for performance of our contracts, compliance with legal obligations, or pursuant to our legitimate business interests in operating secure engineering services.

Your Statutory Prerogatives: You have the right to request access, correction, erasure (“right to be forgotten”), restriction of processing, data portability, and to object to processing. Where processing is based on consent, you may withdraw it at any time.

International Transfers: Where data is transferred outside the EEA/UK, SMRKONOVA implements European Commission-approved Standard Contractual Clauses (SCCs) and robust technical safeguards to ensure adequate data protection.

8. U.S. Privacy Rights

This section supplements our policy to address specific disclosures required by U.S. state privacy legislation, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), as well as privacy statutes in Virginia, Colorado, Utah, and Connecticut.

Notice at Collection:

The categories of personal information gathered over the preceding 12 months, the commercial purposes for use, and retention standards are set forth in Section 2 above.

Do Not Sell or Share My Personal Info:

SMRKONOVA does not sell personal information to third parties, nor do we “share” personal information for cross-context behavioral advertising.

Exercising Consumer Rights:

Eligible U.S. residents may submit access, correction, or deletion requests via email at privacy@smrkonova.com. We will verify your identity before processing and will never discriminate against you for exercising your privacy prerogatives.

9. Control Over Your Information

You have practical tools to inspect, modify, and limit the collection of your information:

Email Communications:

You may opt out of non-transactional marketing announcements at any time by clicking the “unsubscribe” link embedded in emails. You will continue to receive critical operational, billing, and security advisories.

Account Updates:

Authorized client administrators can review and revise user profile details by logging into the SMRKONOVA administrative console.

10. Data Retention and Data Security

Retention Schedules:

We retain personal data strictly for as long as necessary to fulfill active contractual engagements, resolve customer support inquiries, and comply with legal, tax, or accounting requirements. Upon contract expiration or verified erasure requests, client data is securely purged or cryptographically pseudonymized according to established retention cycles.

Security Controls:

SMRKONOVA maintains enterprise technical and organizational protections designed to prevent unauthorized access, alteration, or disclosure. All data at rest is encrypted using AES-256 standards, and data in transit is protected via TLS 1.3 protocol. Access to production systems is restricted via mandatory multi-factor authentication (MFA) and least-privilege role-based access control (RBAC).

11. Children's Privacy

Our websites and enterprise engineering offerings are strictly intended for commercial entities and individuals aged 18 and older. SMRKONOVA does not knowingly solicit or collect personal information from individuals under the age of 16. If we become aware that personal information of a minor has been collected without parental consent, we will promptly delete the data from our repositories.

12. Changes to Privacy Policy

We periodically review and update this Privacy Policy to reflect advancements in our engineering systems, legal requirements, and industry standards. Material changes will be highlighted via an updated “Last Updated” date at the top of this document or communicated via direct email notification to enterprise account holders. We encourage you to review this policy periodically.

13. European Representative and Data Protection Officer Details

For individuals residing within the European Economic Area (EEA), United Kingdom, or Switzerland, inquiries regarding cross-border telemetry, standard contractual clauses, or supervisory authority escalations may be directed to our dedicated compliance desk at privacy@smrkonova.com.

14. Contact Us

If you have questions, comments, or formal data access requests regarding this Privacy Policy, please reach out to our privacy desk:

MAILING ADDRESS

SMRKONOVA Engineering Systems
Outer Ring Road, Bellandur
Bangalore, Karnataka 560103
India

INQUIRIES & LEGAL DESK

privacy@smrkonova.com

Formal privacy inquiries are acknowledged within 48 business hours.