Privacy Policy
Digital Mega Factory ("DMF") operates this website on its own infrastructure in Bangalore, India. This policy describes what information we collect when you use this site and how we handle it.
What we collect
We collect only the information you choose to send us through our contact form: your name, email address, and the message you write. We do not run analytics scripts, advertising trackers, or third-party cookies on this site. The only cookie we set is for your display theme preference (light or dark mode), and it contains no personal data.
How we store it
Contact form submissions are stored on DMF's own servers in Bangalore. We do not use third-party cloud processors, form services, or email marketing platforms to store or relay your information. Your message goes directly to our team and is not shared with any external party.
How we use it
We use your contact information solely to respond to your inquiry about our services. We do not send marketing emails, newsletters, or unsolicited communications. If you become a client, the terms of that engagement govern how we handle any data involved in your project.
Healthcare projects & sensitive data
DMF designs and operates systems for healthcare and medical-research clients, including platforms that process clinical and patient data. Any such data belongs to the client and their patients — never to DMF. It is processed only within the scope of the engagement that covers it, on infrastructure dedicated to that engagement, and is never used for training, analytics, marketing, or any purpose beyond the contracted work. Access is restricted to the DMF team members working on that engagement.
HIPAA
All DMF team members have completed formal HIPAA compliance training and certification (May 2026, conducted with Validus Institute Inc.), covering the Privacy Rule, the Security Rule, and the handling of protected health information (PHI). Our healthcare engineering follows HIPAA-aligned safeguards: minimum-necessary access, role-based access control, encryption of data in transit, audit logging, and signed confidentiality agreements for everyone who touches clinical data. For engagements with U.S. healthcare organizations, DMF operates under Business Associate Agreements where applicable.
Security
This site and our platforms run on infrastructure DMF owns and operates — not rented multi-tenant cloud services. Our network is segmented, services are firewalled to the minimum necessary exposure, and production systems are monitored continuously by our own tooling. No third party processes your data on our behalf.
Retention
Contact form submissions are kept only as long as needed to handle your inquiry and any engagement that follows from it. Data covered by a client engagement is retained or destroyed according to that engagement's terms.
Your rights
You may request a copy of any information we hold about you, ask us to correct it, or ask us to delete it. Send your request to dmf.careteam@gmail.com. We will respond within 30 days.
Contact
For questions about this policy or your data, contact us at dmf.careteam@gmail.com.
Last updated: July 2026