Legal

Project Data Handling

Last updated 6 October 2026

This note describes the standard approach used by Adyan Rehaman, trading as Eastonix, for client project data. The accepted proposal or data-processing schedule records the controls for a specific engagement.

Purpose and instructions

Client data is used only to scope, build, test, secure, operate and hand over the agreed system. Eastonix follows documented client instructions and does not sell project data or use it for unrelated work.

Data minimisation

Eastonix requests only the sample and production data reasonably needed for the project. Redacted, synthetic or least-privilege access is preferred where it can support the agreed work.

Providers

AI, hosting, database, logging and communication providers are selected for the agreed architecture and disclosed before production use. Available enterprise or no-training controls are used where the scope requires them.

Access and safeguards

Access is limited to people and providers who need it for the project. Reasonable account security, credential handling, access control and deletion practices are applied. A relevant confirmed incident is communicated to the client without undue delay.

Retention and deletion

Unless the client instructs otherwise or law requires retention, working copies of client data are deleted within 30 days after final handover or termination. Encrypted backups may remain until they are overwritten in the provider’s normal cycle, normally no longer than 60 additional days.

Requests and status

Eastonix will reasonably assist with access, correction, deletion and grievance requests involving systems it operates. This note is a statement of operating practices, not a claim of certification, formal compliance audit, ISO accreditation or SOC status. Contact Adyan Rehaman at adyan@eastonix.com or +91 63978 81966.