Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Effective Date: September 9, 2026
Last Updated: September 9, 2026
Website: https://infracodez.com
Entity: InfraCodez (“we,” “our,” or “us”)

1. Introduction

At InfraCodez, we engineer digital infrastructure, custom web applications, eCommerce solutions, cloud architectures, ERP/CRM integrations, and managed technical services. We are committed to transparency regarding how we collect, handle, protect, and process data when you visit our website, submit service requests, or contract our technical services.

This Privacy Policy outlines the categories of data we collect, how we manage client server credentials and technical assets, how data is stored, and your statutory privacy rights.

2. Roles: Data Controller vs. Data Processor

  • InfraCodez as Data Controller: When you visit our website, submit inquiries via our Service Request or Contact forms, or execute commercial agreements, we act as the Data Controller of your contact and business information.
  • InfraCodez as Data Processor: When providing development, cloud migration, database maintenance, or troubleshooting services, we may access or migrate databases, staging environments, or user data residing on your servers. In these scenarios, you remain the Data Controller of your end-user data, and InfraCodez acts strictly as a Data Processor pursuant to our confidentiality and service agreements.

3. Information We Collect

A. Information You Provide Directly

  • Contact & Business Details: Name, company/business name, work email address, phone number, and billing address.
  • Project & Technical Scoping Data: Website URLs, business domain details, current tech stack, project scope descriptions, timeline preferences, and budget ranges submitted through our Service Request forms.
  • Technical Credentials & Environment Access: When contracted for development or maintenance, you may provide access to repositories (e.g., GitHub, GitLab), hosting environments (e.g., cPanel, AWS, GCP, VPS), domain DNS panels, CMS administrative accounts, and third-party API keys.
  • Billing & Transaction Records: Transaction receipts, invoice history, and tax identifiers. (Note: Payment processing is handled via secure, PCI-DSS-compliant third-party gateways; we never store raw credit card numbers).

B. Information Collected Automatically

  • Log & Technical Data: IP addresses, browser types, operating systems, referring URLs, access times, pages viewed, and diagnostic server logs.
  • Essential Cookies: Standard session cookies required for core website security, load balancing, and anti-bot/CSRF protection. We do not engage in third-party advertising retargeting networks.

4. How We Use Your Information

We process data solely for legitimate technical and operational purposes:

  1. Scoping & Technical Evaluation: Analyzing your architecture requirements to prepare accurate milestones, proposals, and estimates.
  2. Service Delivery & Execution: Developing custom code, provisioning cloud environments, configuring eCommerce checkout pipelines, and executing CRM/ERP integrations.
  3. Project Management & Support: Communicating milestone reviews, staging previews, security alerts, and support resolutions.
  4. Zero-Spam Commitment: We will never sell, rent, or trade your email address or business information to third-party data brokers or marketing lists. Communications are strictly confined to your service inquiries, active projects, and operational notices.

5. Infrastructure Security & Credential Handling Protocols

Given the technical nature of our work, InfraCodez enforces strict security standards:

  • Least-Privilege Access: Access to client repositories, server infrastructure, and staging databases is granted strictly to assigned engineers on a need-to-know basis.
  • Encrypted Credential Vaults: Client credentials, SSH keys, and API tokens are stored in encrypted vaults utilizing AES-256 encryption. Plain-text transmission over insecure channels is prohibited.
  • Credential Rotation & Data Purging: Upon project launch or agreement conclusion, we advise clients to rotate master passwords and API keys. We securely purge temporary credentials and local staging database dumps.
  • Encrypted Transport: All communication to and from our site and environments is secured via modern Transport Layer Security (TLS 1.3).

6. Disclosure of Information

We disclose your information only under the following limited conditions:

  • Cloud Infrastructure & Subprocessors: Trusted enterprise cloud providers that assist in hosting, database backups, and transactional email delivery (e.g., Amazon Web Services, Google Cloud).
  • Professional Advisors: Legal counsel, accountants, and auditors bound by legal duties of confidentiality.
  • Legal Obligations: If strictly required by law, subpoena, or government authority to protect public safety or enforce our legal agreements.

7. Data Retention

  • Inquiries & Service Requests: Retained for up to twenty-four (24) months to facilitate ongoing technical correspondence and scoping history, unless deletion is requested earlier.
  • Financial Records: Retained for seven (7) years in compliance with statutory tax and bookkeeping regulations.
  • Client Database Copies & Local Repositories: Purged within thirty (30) days following final deployment, client acceptance, and invoice settlement, unless covered by an ongoing active maintenance agreement.

8. Your Data Rights

Under applicable data protection legislation (such as GDPR and CCPA/CPRA), you may request access to, correction of, or deletion of your personal data, or object to specific processing activities.

To submit a data rights request, contact us at  .