LEGAL

Privacy Policy

This policy explains what personal data Bymond Private Limited handles, why we handle it, who we share it with, and the choices and rights available to you.

The short version: we record every visit to this website (IP address, pages viewed, referrer and device information) and we do not offer a way to browse without that being recorded. We do not try to identify who you are, and we hold no name or email for you unless you send one. Full detail in what we collect.

If anything here is unclear, write to [email protected] and we will explain it.

Effective
21 August 2026
Last updated
21 August 2026
Applies to
bymond.com and Bymond's technology services
On this page
  1. Who we are
  2. Scope of this policy
  3. Personal data we collect
  4. How we use personal data
  5. Grounds on which we process personal data
  6. Cookies, analytics and marketing technologies
  7. Sharing personal data and service providers
  8. Payments
  9. Customer and client data
  10. AI-related processing
  11. International data handling
  12. Security
  13. Retention and deletion
  14. Your rights and choices
  15. Consent and withdrawal
  16. Children
  17. Contact and grievance redressal
  18. Changes to this policy

Who we are

Bymond Private Limited ("Bymond", "we", "us" or "our") is a private limited company incorporated in India under the Companies Act, 2013. We build and operate technology for organisations: software engineering, cloud and infrastructure engineering, DevOps, AI development and automation, technology consulting, application hosting, and related services.

This website is an informational and marketing site. Nothing is sold through it and it has no accounts, no logins and no checkout. Its purpose is to describe what we do and to let you start a conversation with us, which shapes everything below, because the only personal data we hold about an identifiable person is what that person chose to send us.

This Privacy Policy explains how we handle personal data when you visit bymond.com, contact us, or engage us for services. For the purposes of the Digital Personal Data Protection Act, 2023, Bymond acts as a Data Fiduciary in respect of the personal data described in this policy, except where we process data on behalf of a customer. See customer and client data.

Entity Details

Legal entity
Bymond Private Limited
Incorporation
A private limited company incorporated in India under the Companies Act, 2013
CIN
U51909WB2019PTC234607
GSTIN
19AAICB7296E1ZA
Registered office
Asanboni, Gopiballavpur, Medinipur, West Bengal 721506, India
Operating location
Kolkata, West Bengal 700094, India
Project enquiries
[email protected]
General & legal
[email protected]
Support & grievance
[email protected]

Scope of this policy

This policy applies to:

  • your use of the Bymond website and any forms or contact channels on it;
  • business enquiries, proposals, quotations and pre-contract discussions;
  • the administration of engagements and the commercial relationship with our customers;
  • communications you exchange with us by email or other channels we operate.

What this policy does not cover

  • BigBlueButton Host. BigBlueButton Host is a separate service brand operated by Bymond with its own service-specific terms and policies published at bigbluebutton.host. Those policies govern that service, including its hosting, recording, storage and support arrangements. Where you use BigBlueButton Host, refer to the policies published on that service rather than this page.
  • Systems we build or operate for a customer. Where we develop, host or operate a system for a customer, the customer generally determines what personal data is collected in that system and why. The privacy policy of that customer applies to the end users of their system, not this one.
  • Third-party websites. Sites and services we link to operate under their own privacy policies. We do not control them.

Personal data we collect

Information you give us through the enquiry form

The project consultation form on our contact page collects the following. Only the first three fields are mandatory; the rest are optional and exist so we can respond usefully rather than with a generic reply.

  • full name, work email address (required) and your primary objective (required);
  • company name and company website;
  • a description of your current infrastructure or situation, target scale, indicative timeline and an optional budget range;
  • any further project details or notes you choose to write.

Technical information collected with a form submission

When a form is submitted, our edge service records limited technical information alongside it to protect against automated abuse, deduplicate repeated submissions and understand where enquiries originate:

  • the IP address the submission was made from;
  • the browser user-agent string and preferred browser language;
  • the referring page, where your browser supplies one;
  • the country associated with the connection, and a request identifier from our network provider.

Business enquiry and relationship information

  • correspondence with us, including emails, proposals, quotations, scoping notes and meeting notes;
  • the business contact details of the people who represent a customer, supplier or prospective customer;
  • billing and invoicing information, including business address, tax registration details and payment references.

Account and service information, where applicable

Where a service we provide includes an account, portal or administrative access, we handle the information needed to create and administer that access, for example account identifiers, contact details and records of administrative actions. Not every engagement involves an account.

Website usage information

We record information about every visit to this website. This applies to all visitors, from the moment a page loads, and it is not something that can be switched off while continuing to use the site. We record:

  • the IP address you connect from, and the general location it indicates;
  • each page you view, the order you view them in, and how long you stay;
  • the page, search or link that referred you;
  • your browser, device type, operating system and language preference;
  • the date and time of each request.

We use this to operate and secure the site, to see which pages are actually useful, and to be available to help while you are on it. Our live chat provider reports page views in real time for that last purpose. Where you have consented to analytics, we additionally receive aggregate usage measurement. See our Cookie Policy for what runs and when.

Recording visits is not optional

Running a website means recording who requests what from it. We make no apology for that and we would rather set it out plainly here than leave it implied. If you would prefer your visit not to be recorded in this way, the way to achieve that is not to use the website. There is no setting that turns off basic visit logging while the site continues to serve you pages.

What we do not do is try to work out who you are. We do not buy identity data, we do not attempt to match your IP address to a named individual, and we do not build a profile of you to sell. Unless you contact us and give us your details, you remain a route through the site, not a person we hold a name for.

What we do not ask for

We do not ask you to submit sensitive personal information, financial account credentials, government identifiers, or health information through this website. Please do not include confidential customer data, credentials or personal data belonging to other people in an enquiry form or an unsolicited email.

How we use personal data

We use personal data for the following purposes:

  • to respond to enquiries and to prepare proposals, quotations and scopes of work;
  • to deliver, support and operate the services we have agreed to provide;
  • to administer the commercial relationship: contracting, invoicing, payments and accounts;
  • to communicate about an engagement, including service, security, billing and administrative messages;
  • to maintain and secure our website and systems, including preventing abuse, fraud and automated attacks;
  • to understand, in aggregate, how our website is used so we can improve its structure and content;
  • to keep records and to comply with applicable legal, tax, accounting and regulatory obligations;
  • to establish, exercise or defend legal claims.

We do not sell personal data. We do not rent or trade contact details to third parties for their own marketing.

Grounds on which we process personal data

Under the Digital Personal Data Protection Act, 2023, personal data may be processed with consent or for certain legitimate uses recognised by that Act. In practice:

  • Consent. When you submit an enquiry form or write to us, you provide the information voluntarily for the purpose of us responding to you.
  • Performance of an engagement. Where we have a contract, order form or agreed scope with you or the organisation you represent, we process the personal data needed to deliver and administer it.
  • Legal and regulatory obligations. Indian tax, company and accounting law requires us to create and retain certain records.
  • Operating and securing the website. Recording who requests which page, and when, is inherent to serving and defending a website. We treat it as necessary to running the service rather than as an optional extra, and it applies to every visitor.

The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into force in stages. We are aligning our practices with those requirements as the relevant provisions come into effect.

Cookies, analytics and marketing technologies

Cookies and similar technologies are dealt with in detail in our Cookie Policy, which describes each category we use or may use, and what would change if we introduce analytics or marketing technologies in future.

In summary: strictly necessary cookies are set by our hosting and network provider for delivery and security, and your cookie choice itself is stored so it can be honoured. Analytics (provided by Google Analytics) and marketing technologies are not loaded onto the site at all unless you have agreed to them through the consent panel shown on your first visit. You can change that choice at any time using Cookie Preferences in the footer.

Sharing personal data and service providers

We share personal data only where there is a reason to, and only with:

  • Service providers we rely on to operate. This includes hosting, content delivery, network security, email, business applications and, where relevant to a project, cloud infrastructure providers. They process the data to provide services to us.
  • Payment processors. See payments below.
  • Live chat and visitor monitoring. Our chat widget is provided by Tawk.to and runs on every page of this site. It processes any messages you send, and also the pages you view, your IP address, your referring page and general browser information, so that we can see visitors in real time and offer help. Tawk.to handles that information under its own terms and privacy policy. See our Cookie Policy.
  • Professional advisers. Accountants, auditors, insurers and legal advisers, where needed.
  • Authorities. Where we are required to disclose information by law, by a court, or by a competent authority, or where disclosure is necessary to establish, exercise or defend legal claims.
  • In connection with a corporate transaction. If Bymond is involved in a merger, acquisition, reorganisation or sale of assets, information may be transferred as part of that transaction, subject to this policy continuing to apply to it.

Where a third-party provider processes personal data on our behalf, we seek to put appropriate contractual arrangements in place with that provider. Third-party providers also process information under their own policies, which we do not control.

Payments

Payments to Bymond may be made through payment processors and financial channels including Stripe, Razorpay, Wise, bank transfer and UPI. Not every method is offered for every transaction. The methods available for a given engagement are confirmed on the invoice or in the applicable agreement.

Where a payment processor is used, the payment is completed on the systems of that processor. Bymond does not receive or store complete card numbers or banking credentials from those transactions. We receive transaction confirmations, references and the billing information needed for invoicing, reconciliation and tax records. Payment processors handle payment information under their own terms and privacy policies.

Customer and client data

In the course of an engagement we may be given access to, or asked to process, data belonging to a customer, including personal data relating to that customer's own users, employees or contacts. In that situation the customer determines the purpose and means of processing, and Bymond processes the data on the customer's instructions in order to deliver the agreed services.

  • We use customer data to deliver, support, secure and operate the agreed services, and for no unrelated purpose.
  • The customer is responsible for having the right to provide the data to us and for the lawfulness of the instructions it gives.
  • Where a data processing agreement, non-disclosure agreement or other written arrangement is in place, that arrangement governs how we handle that data and prevails over this page in the event of a conflict.
  • Access to customer environments is limited to personnel who need it in order to perform the work.

If you are an end user of a system Bymond built or operates for another organisation, that organisation is the appropriate first point of contact for questions about your data.

AI-related processing

Bymond provides AI development and automation services, and may use AI-assisted tooling internally. Where an AI capability forms part of an engagement, it may involve third-party AI infrastructure or model providers, in which case data submitted for processing is transmitted to that provider in order to produce a result.

Where Bymond controls the applicable arrangement, we do not knowingly permit customer confidential information to be used by AI providers for training their models. Provider terms and capabilities differ and can change; where this matters to an engagement it should be addressed in the applicable agreement. Our AI Services & Usage Policy sets out our approach in full.

International data handling

Bymond is established in India and serves customers in India and internationally. The service providers we rely on, including hosting, content delivery, email and cloud infrastructure providers, operate globally, so personal data may be processed or stored outside the country in which it was collected, including outside India.

Where we transfer personal data across borders, we do so in accordance with applicable law, including any restrictions notified by the Central Government of India under the Digital Personal Data Protection Act, 2023. Where an engagement has specific data location or residency requirements, those requirements need to be agreed in writing as part of the engagement; we do not make general data residency promises on this page.

If you are located outside India, you may have rights under the privacy law of your own jurisdiction. Where such a law applies to our processing, we will handle requests in accordance with it. Nothing in this policy should be read as a statement that every foreign privacy law applies to Bymond, or that Bymond is certified or accredited under any particular privacy framework.

Security

We take reasonable technical and organisational measures appropriate to the nature of our services to protect personal data against unauthorised access, disclosure, alteration and loss. These include limiting access to systems on a need-to-know basis, using authenticated server-to-server communication between our own components, transport encryption for data in transit, and hardening and monitoring of the infrastructure we operate.

No method of transmission or storage over the internet can be guaranteed to be completely secure, and we do not claim otherwise. Our Security & Responsible Disclosure page explains how to report a suspected vulnerability.

Retention and deletion

We keep personal data only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it.

  • Enquiries that do not proceed. Retained for a reasonable period so we can pick up the conversation if you return, then deleted or reduced to a minimal record.
  • Customer and project records. Retained for the duration of the engagement and for a long period afterwards, potentially twenty years or more. Technology we build is often still in production, and still being extended or supported, many years after delivery; the scoping decisions, architecture notes and correspondence behind it stay relevant for as long as the system does.
  • Financial and tax records. Retained for the periods required by Indian tax, company and accounting law.
  • Customer data we process on a customer's behalf. Handled in line with the applicable agreement, including any agreed return or deletion at the end of the engagement.

Long retention of project records does not mean we hold everything indefinitely. Where personal data within those records is no longer needed for the purpose it was collected for, we delete it or reduce it so that it no longer identifies you, unless retention is required by law.

You may ask us to erase personal data using the contact details below. We will act on the request except where we are required or permitted by law to retain the data, or where the data is embedded in records we need to keep in order to support or defend work already delivered, in which case we will tell you what we are keeping and why.

Your rights and choices

Subject to applicable law and to verification of your identity, you may ask us to:

  • confirm whether we process personal data about you, and provide a summary of that processing;
  • correct, complete or update personal data that is inaccurate or out of date;
  • erase personal data that is no longer needed for the purpose for which it was collected;
  • stop sending you non-essential communications; you can also unsubscribe from any marketing email we send;
  • in the case of Indian residents, nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the Digital Personal Data Protection Act, 2023.

We will respond to a request within a reasonable period. There are limits: we may need to keep certain records for legal or accounting reasons, and where we hold data on behalf of a customer we will usually refer the request to that customer, who is the appropriate party to decide on it.

You are responsible for the accuracy of the information you provide to us, and for not submitting personal data about other people unless you are entitled to do so.

Children

Our website and services are directed at businesses and professional users, not at children. Under Indian law a child is an individual who has not completed eighteen years of age. We do not knowingly collect personal data of children through this website. If you believe a child has provided personal data to us, contact [email protected] and we will take steps to delete it.

Contact and grievance redressal

If you have a question, a request about your personal data, or a complaint about how we have handled it, contact us using the details below. Please describe the issue clearly so we can identify the relevant records and respond. We will acknowledge your communication and work to resolve it within a reasonable period.

Bymond has designated a Data Protection Officer as the point of contact for questions, requests and grievances relating to personal data.

Privacy Contact

Data Protection Officer
Pritam Nanda
Privacy & grievances
[email protected]
General & legal
[email protected]
Postal address
Asanboni, Gopiballavpur, Medinipur, West Bengal 721506, India
Entity
Bymond Private Limited · CIN U51909WB2019PTC234607

If you are not satisfied with our response and you are covered by the Digital Personal Data Protection Act, 2023, you may escalate the matter to the Data Protection Board of India in accordance with that Act and the rules made under it.

Changes to this policy

We may update this Privacy Policy to reflect changes in our services, our providers, or the law. The current version is always published on this page with its effective date and last-updated date. Where a change is significant, we will take reasonable steps to bring it to the attention of affected customers. Continued use of the website or our services after an update takes effect indicates that you have reviewed the updated policy.