Legal
What we collect, why, how long we keep it, and how to have it removed.
Last updated 23 August 2026
Turagh Technologies provides cyber security, digital forensics, software engineering, cloud and network services from Kolkata, West Bengal and Delhi / Noida, Uttar Pradesh, India. We decide how and why the information described below is processed.
Questions, corrections and deletion requests all go to contact@turagh.com.
The contact form asks for your name, email address, and optionally a phone number and WhatsApp number, along with the message you write and the topic you pick. We also record the IP address and browser user-agent the submission arrived from, because the form is open to anyone and those two values are what let us tell a real enquiry from an automated flood.
Your name, email address, phone number, country, and optionally a WhatsApp number. Your password is never stored — only a bcrypt hash of it, which cannot be reversed into the password you chose. Verification codes are likewise stored only as hashes.
Everything on the brief form: the description of the work, the services selected, and where given, your current stack, budget range, timeline, preferred contact method and how you heard about us. You may also name your organisation, its type, size and website. Any file you attach is stored along with its filename, size and type.
One session record per device, holding the IP address, the browser user-agent and when it was last used, so that you can see where your account is signed in and end sessions you do not recognise. We also keep a record of security-relevant actions — sign-ins, password changes, code requests — with the acting account and the originating IP address.
One cookie, holding a session identifier and nothing else. It is set only once there is something to remember: signing in, or starting a form that needs protecting against forgery. There is no advertising cookie, no analytics cookie and no third-party tracker on this site.
Only as long as the reason we collected it lasts. Deletion is not something we get round to — it runs automatically, on a schedule, and removes what is past its period without anyone deciding to.
The short-lived things go first. Verification codes stop being useful the moment they are used or expire. Sessions end when you stop using them. Registrations nobody confirmed are removed rather than left sitting as details we were never asked to keep. The technical details recorded alongside a message — the address and browser it came from — are erased well before the message itself, because they exist to catch abuse and stop being needed long before the enquiry does.
Enquiries are kept for a period measured in months. Accounts, briefs and attachments last while your account does, because they are the record of work you asked us to do; when the work is a commercial record, we keep it for as long as we are required to.
If you want to know the exact period for something in particular, ask us and we will tell you.
We do not sell personal information, and we do not share it for advertising. Three parties are involved in running the site:
Beyond those, information is disclosed only where the law requires it.
An attachment on a brief is treated as confidential. It is never included in an outgoing email and is never served from a public address — it stays behind an authenticated download, and each time a member of staff opens one that access is recorded against their account.
No system is beyond compromise. If yours is affected by a breach of ours, we will tell you.
You can ask us to:
Write to contact@turagh.com. We will respond within 30 days. If you are not satisfied with how we handled it, you may complain to the relevant data protection authority.
This service is for businesses and is not directed at children. We do not knowingly collect information from anyone under 18.
If this notice changes materially we will update the date at the top and, where the change affects information we already hold about you, tell you directly.