Legal

Data Protection Policy

The technical safeguards and operational protocols we apply when managing data across our products and client engagements.

This page is maintained by NewClear Labs LLC (USA) and NewClear Labs Pvt. Ltd (INDIA). (collectively, 'NewClear Labs') for informational and operational transparency. It does not constitute legal advice.

1. Purpose

This policy describes the practices NewClear Labs applies when handling data on our own systems and within client engagements. It is a statement of our current practices, not a certification or an audit result.

2. Shared responsibility

Responsibility for data security is shared. Cloud and hosting providers secure the underlying infrastructure; NewClear Labs is responsible for how we design, configure and operate the software we build; clients are responsible for the data they choose to place in a system, for their own user accounts, and for the policies that govern their organisation.

3. Access control

Access to client systems and data is granted on a least-privilege basis and only to team members working on the relevant engagement. Accounts are individually attributed, protected with multi-factor authentication where the provider supports it, and revoked when a project ends or a team member's role changes.

4. Encryption in transit and at rest

Our websites and the applications we build are served over HTTPS. Where the platforms and managed services we use provide encryption at rest, we enable it. Specific encryption arrangements for a given project are documented in that engagement.

5. Development and change management

Code changes are version-controlled and reviewed before release. Secrets and credentials are held in dedicated secret storage rather than in source code. Dependencies are kept current, and we act on known vulnerabilities in the libraries we use.

6. Data minimisation and retention

We collect only the data required for the purpose at hand, avoid copying production data into development environments where it can be avoided, and delete or return client data at the end of an engagement in line with the agreed terms.

7. Subprocessors and integrations

We use third-party providers for hosting, email, source control and, where a project requires it, AI and analytics services. Providers relevant to a specific engagement are identified in that engagement so clients can assess them.

8. Incident response

If we become aware of a security incident affecting data we hold or process, we investigate promptly, take steps to contain it, and notify affected clients without undue delay so they can meet their own notification obligations.

9. Reporting a vulnerability

If you believe you have found a security issue in one of our systems or products, email connect@newclearlabs.com with the details. Please do not publicly disclose it before we have had a reasonable opportunity to respond.