This policy covers the Idea2Code mobile app for Android and iOS, and this website, idea2code.org. Both are operated by Atomos Technologies OPC Private Limited.
Effective 31 August 2026.
Idea2Code is a business tool. You use it to describe software you want built, agree terms, follow the work, and pay for it. Everything below follows from that: we hold what an engagement needs, for as long as Indian tax and contract law requires us to, and nothing is sold or used for advertising.
Atomos Technologies OPC Private Limited is a One Person Company incorporated in India, with its principal place of business in Atomos Technologies HQ, Kolkata, West Bengal, India. We are the Data Fiduciary under India's Digital Personal Data Protection Act 2023 for personal data collected through the Idea2Code app and this website, and the data controller for the purposes of the UK and EU GDPR in respect of the same. Where we handle data belonging to a client's own users in the course of building software for them, we act as a Data Processor on that client's documented instructions under the services agreement.
GSTIN 19AAXCA0822C1ZQ · D-U-N-S 738695694.
The table below is the complete list, taken from the application's own database schema rather than written from memory.
| Category | What exactly | Why |
|---|---|---|
| Account | Your name, email address, phone number, a hashed password, an optional profile photo, and your language preference | To create and secure your account and to contact you about your project |
| Sign-in with Google or Apple | The identifier that provider returns to us, and the email address on it | So you can sign in without a separate password. We never receive your Google or Apple password |
| Business details | Organisation name, contact person, contact number, email, address, state, postcode and GSTIN where you are billing as a business | To raise a legally valid tax invoice |
| Your project | The brief you write, the stage and priority you pick, the categories you choose, your preferred way of meeting, and the appointment slot you book | To quote for and carry out the work |
| Files you upload | The file itself, its original filename, type and size | Because you attached it to a request as part of the brief |
| Signature evidence | When you sign an agreement in the app: your name, title, entity, email, phone, the IP address and device you signed from, the exact time, and a cryptographic hash of the precise document text you were shown | This is what makes an electronic signature evidential under the Information Technology Act 2000. Without it a signed agreement could not be relied on by either of us |
| Payments | Which instalments were raised, what you paid, when, in what currency, and the reference the payment gateway returned. We never see or store your card or bank details — those go directly to the gateway | To take payment and to issue the tax invoice we are required to issue |
| Support | The subject and body of any support ticket you raise | To answer it |
| Device | A push notification token, the platform, a device name, and when it was last seen | To send you notifications about your project. Turn notifications off and this stops |
| Security and audit log | For actions taken in the app and the panel: IP address, user agent, device type, platform and the route used | To detect abuse, and so that a change to your project can be traced to whoever made it |
Idea2Code is for businesses and professional clients and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, write to us and we will delete it.
We do not use your data for automated decision-making that has a legal or similarly significant effect on you.
We do not sell personal data and we do not share it for advertising. It reaches only these processors, each for one purpose:
| Who | What they get | What for |
|---|---|---|
| Google Firebase (Authentication, Cloud Messaging, App Check) | Account identifier, device push token, an app integrity signal | Sign-in, push notifications, and blocking forged clients |
| Google Sign-In · Apple Sign-In | Whatever you authorise at the provider's own prompt | Signing in without a separate password |
| Razorpay, Stripe, PayPal, NOWPayments | Amount, currency, and the details you enter on their own checkout | Taking payment. Each is its own controller for what you give them |
| Hostinger | Everything, at rest, as our hosting provider | Running the service |
| Our own email sending | Your email address and the message | Verification codes, receipts and notices |
Beyond that we disclose personal data only to professional advisers under a duty of confidentiality, where the law or a valid order requires it, or to a successor entity in a merger or acquisition — in which case you will be told, and the acquirer is bound by this policy or one materially equivalent.
Our servers are in India. If you are in the EEA or the UK, personal data is transferred to India, and we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, with a transfer risk assessment where one is required.
| What | How long |
|---|---|
| Account and project records for an engagement that went ahead | The engagement, plus 8 years, to meet Indian tax, statutory and limitation requirements |
| Invoices, payments and signed agreements | 8 years. These we are required to keep and cannot delete on request |
| A request that never became an engagement | 24 months from your last contact |
| Files attached to a request that was abandoned | Pruned automatically |
| Push notification tokens | Until the app is uninstalled or the token stops working |
| Security and audit logs | 18 months |
No system is perfectly secure. If a breach occurs that is likely to affect your rights, we will notify the Data Protection Board of India and, where the risk is high, you directly, within the periods the law requires.
You have the right to access your data, to have it corrected, to have it erased, to withdraw consent, to nominate someone to exercise your rights if you die or become incapacitated (DPDP Act 2023), and to have a grievance addressed. In the EEA and UK you also have rights to restriction, portability and objection.
Most of this you can do yourself, in the app.
Otherwise write to care@idea2code.org with the subject DATA REQUEST. We reply within 30 days, and we may need to verify who you are first.
Under the Information Technology Act 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and the Digital Personal Data Protection Act 2023, complaints about how your personal data is handled may be addressed to:
We acknowledge a grievance within 24 hours and resolve it within 15 days, as those rules require. These are the same details shown inside the app under compliance, because both are read from one record.
You may also complain to the Data Protection Board of India, or to your own supervisory authority in the EEA or the UK. We would rather you gave us the chance to put it right first.
Our Terms & Conditions and Shipping & Refunds Policy govern the commercial relationship and are published by Atomos Technologies OPC Private Limited. Where a signed services agreement exists, that agreement takes precedence.
The current version always lives at this address with its effective date. Where a change materially affects your rights we will tell you in the app before it takes effect.
Atomos Technologies OPC Private Limited
Atomos Technologies HQ, Kolkata, West Bengal, India
Email: care@idea2code.org