Overview
Tafora Technology (Tafora, we, us) builds custom software, mobile and AI products, and provides dedicated engineering teams to clients worldwide. We operate from offices in Rajshahi, Bangladesh; Hopkins, Minnesota, United States; and Helsinki, Finland.
This Privacy Policy explains what personal information we collect through taforatechnology.com and in the course of our client work, why we collect it, who we share it with, and the choices and rights you have. It applies to visitors to our website, prospective and current clients, partners, and applicants who contact us.
It does not apply to third-party websites we link to, or to the products we build for clients once those products are operated by the client under their own privacy policy.
Information We Collect
Information you give us
When you submit our contact form, we collect your name, email address, and project message, and optionally your phone number, company name, and the service you are interested in. When you book a call through our scheduling link, or reach us by email, WhatsApp, or phone, we receive whatever information you choose to share in that conversation.
If we go on to work together, we also process business contact details and the commercial information needed to scope, deliver, and invoice the engagement.
Information collected automatically
Like most websites, our servers and analytics tooling record technical data when you visit: IP address, browser type and version, device and operating system, referring page, pages viewed, and the date and time of your visit. This data is used in aggregate to keep the site secure and understand how it is used.
Client data we handle on your behalf
Delivering a project sometimes requires access to systems that contain personal data belonging to our client and their users, for example a staging database or a support inbox. In that situation the client is the data controller and Tafora acts as a data processor, handling that data only on documented instructions under the engagement contract. See Our Role as a Processor.
Information we do not want
Please do not send us special category data (health, biometric, political or religious information), payment card numbers, or system credentials through the contact form or email. Where an engagement genuinely requires sensitive data, we agree a secure channel with you first.
How We Use Information
We use personal information to:
- Respond to your enquiry and schedule an introductory call.
- Prepare proposals, statements of work, quotes, and estimates.
- Deliver the services we have agreed, including project communication, code delivery, and support.
- Issue invoices, collect payment, and keep accounting records.
- Provide support, respond to warranty claims, and handle refund requests under our Refund Policy.
- Operate, secure, debug, and improve our website and internal systems.
- Send occasional updates about our services where you have asked to hear from us. Every such message includes an unsubscribe link.
- Comply with legal, tax, and accounting obligations, and establish or defend legal claims.
We do not sell or rent your personal information, and we do not share it with third parties for their own marketing.
Legal Bases for Processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract to deliver the services you have engaged us for, and to take steps at your request before entering a contract.
- Legitimate interests in responding to enquiries, running and securing our website, preventing fraud and abuse, and growing our business, balanced against your rights and freedoms.
- Consent for non-essential cookies and for marketing email. You may withdraw consent at any time without affecting processing already carried out.
- Legal obligation where retention or disclosure is required by tax, accounting, or other applicable law.
International Data Transfers
Because we operate across Bangladesh, the United States, and Finland, your information may be transferred to and processed in a country other than the one you live in, including countries that have not received an adequacy decision from the European Commission.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, principally the European Commission Standard Contractual Clauses together with technical and organisational measures suited to the data involved. You can request a copy of the safeguards we use by writing to info@taforatechnology.com.
Data Retention
We keep personal information only as long as we need it for the purpose it was collected, and then delete or anonymise it. In practice:
- Enquiries that do not become projects are kept for up to 24 months, so we have context if you come back to us.
- Client and project records are kept for the term of the engagement and for as long afterwards as we may need them to support the delivered work or defend a legal claim.
- Invoices and accounting records are kept for the period required by tax law in the relevant jurisdiction, typically six to ten years.
- Website analytics are retained in aggregate form and are not tied to an identifiable individual.
Client data we process on a client instruction is deleted or returned at the end of the engagement in line with the engagement contract.
How We Protect Information
We apply the security practices we build into client systems to our own: encryption in transit, least-privilege access, role-based permissions, multi-factor authentication on business-critical accounts, code review, and dependency monitoring. Access to client systems is granted per engagement and revoked when it ends.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information and applicable law requires it, we will notify you and the relevant supervisory authority without undue delay.
Your Privacy Rights
If you are in the EEA or the UK
Subject to conditions in the GDPR, you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing (including profiling and direct marketing), to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority. In Finland this is the Office of the Data Protection Ombudsman.
If you are in California
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it, to request deletion, to request correction, and to be free from discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising, so no opt-out is required.
How to exercise your rights
Email info@taforatechnology.com and tell us which right you want to exercise. We may ask for information to verify your identity, which we use only for that purpose. We respond within 30 days, or tell you why we need longer. There is no charge unless a request is manifestly unfounded or excessive.
If your request concerns data we hold as a processor on behalf of a client, we will refer you to that client and support them in responding.
Our Role as a Processor
When we build or maintain a system for a client, the client decides what personal data that system holds and why. They are the controller; we are the processor. In that role we:
- Process personal data only on the documented instructions of the client.
- Bind our engineers to confidentiality, and grant access strictly on a need-to-know basis.
- Use test or anonymised data instead of production data wherever the work allows it.
- Engage sub-processors only with the client agreement, under equivalent obligations.
- Assist the client with data subject requests, breach notification, and impact assessments.
- Delete or return the data at the end of the engagement, as the client directs.
Where required, we enter a separate Data Processing Agreement with the client. Ask us for one at any time.
Children
Our website and services are directed at businesses, not children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
Third-Party Links and Services
Our site links to third-party services, including our scheduling provider, WhatsApp, and our social media profiles. Once you follow one of those links, the third party handles your information under its own privacy policy, which we do not control. We encourage you to read it before sharing anything.
Changes to This Policy
We may update this policy as our services, tooling, or legal obligations change. The version shown here is always current, and the date at the top of the page tells you when it last changed. Where a change materially affects how we handle your information, we will take reasonable steps to tell you directly. This policy was last updated on 5 September 2026.
Contact Us
For any question about this policy, or to exercise a privacy right, contact us at info@taforatechnology.com or through our contact page.
Bangladesh
158/27, Kazla, Boalia, Rajshahi-6204, Bangladesh
United States
903 1st Street North #1061, Hopkins, MN 55343, United States
Finland
Viulutie 1 A 1, 00420 Helsinki, Uusimaa, Finland