Empyreal Infotech Limited is a UK private limited company, with Companies House registration available on request, registered in London. Founder and CTO: Mohit Ramani. ICO data controller registration: held. Registered office: London, UK.
Privacy & terms. Twelve direct answers on data, cookies, DPA, DSAR, ICO, terms.
Direct answers on how Empyreal Infotech Limited handles your data on this website and under client engagement. ICO-registered data controller. UK GDPR-aware. SCCs for cross-border. DSAR and erasure runbook in writing. Terms of engagement under a separate signed letter.
Empyreal Infotech Limited is a UK company. Registered in London. We treat your data as a build problem, not a paperwork one.
This notice covers two things in plain English: how we handle your data on this website, and how we handle it once you become a client under engagement. We don’t run ad-network trackers, and we don’t use marketing or advertising cookies. What we collect, we tell you below.
Terms of engagement for clients live under a separate signed letter, agreed before any work begins. Below you’ll find twelve direct answers on data, cookies, lawful basis, retention, residency, transfers, your rights, complaints, and the website and engagement terms. This page is for the founder who wants the answer before they have to ask.
What we collect, why, and how long we keep it
Open any clause. The privacy notice in plain English: identity of the controller, what we collect on this website, cookies, lawful basis, retention, where data lives, and cross-border transfers.
Empyreal Infotech Limited is a UK private limited company (Companies House registration available on request) registered in London. Founder + CTO: Mohit Ramani. ICO data controller registration: held. Registered office: London, UK.
We collect: (a) what you send when you email mohit@empyrealinfotech.com (email address, message); (b) basic server-side analytics (anonymised IP, page path, referrer, device class) via privacy-respecting analytics; (c) cookies only where strictly necessary for site function. We do not run ad-network trackers.
We use only strictly necessary cookies for site function. We do not use marketing or advertising cookies. No third-party trackers.
Legitimate interest (responding to your enquiry; site analytics in anonymised form). Contract (where you become a client). Legal obligation (HMRC, AML, tax retention).
Email enquiries: 24 months from last contact unless a contract follows. Client data under DPA: per the engagement DPA, typically project life + 24 months retention then deletion. Anonymised analytics: 14 months.
AWS London (eu-west-2). EU clients can opt for Dublin (eu-west-1) under the DPA. US clients can opt for US East / West. Data residency listed in DPA + sub-processor list.
Only where the engagement requires it (e.g., US sub-processor) and only under signed Standard Contractual Clauses. Sub-processor list versioned.
Your request. The runbook that answers it.
Three rights founders and customers exercise most under UK GDPR, and exactly how to use each one with us. Right of access, rectification, erasure, restriction, portability, and objection are all honoured. Each request below gets a written answer inside 30 days.
- 01
“I want to know exactly what data you hold on me.”
How to request your data (DSAR). Email mohit@empyrealinfotech.com with subject “DSAR”. We respond inside 30 days. Right of access, rectification, erasure, restriction, portability, and objection all honoured under UK GDPR.
- 02
“I want you to delete what you hold on me.”
Right to erasure. Email mohit@empyrealinfotech.com with subject “Erasure”. Confirmed inside 30 days. Note: tax + AML + legal obligation may require retention of specific records for statutory periods.
- 03
“I’m not happy with how my request was handled.”
How to complain. First, email mohit@empyrealinfotech.com. If unresolved, you have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk. EU residents may also complain to their local supervisory authority.
The terms, website and engagement, in plain English
Two clauses. How you may use this website, and the shape of the engagement terms once you become a client. Engagement terms are confirmed under a separate signed letter before any work begins.
Use this website for lawful information purposes only. We do not warrant uninterrupted availability. No advice given on this website constitutes legal, financial, or regulatory advice. We are not liable for any reliance on website content. Site governed by English law.
Separate engagement letter signed before any work begins. Terms include: fixed scope, fixed price, 30-day walk-away both ways, IP assigns on every commit, mutual NDA, signed DPA + SCCs, 12-month no-poach with referrer agencies on request.
Receipts that survive Series B diligence. Numbers, not adjectives.
A privacy notice means more when the studio behind it has shipped at scale without a breach. Here’s the production record behind the controller you’re reading about.
£540M+
0M+
0
Procurement, security + trust. What your CFO, CTO, and DPO see
The privacy notice above isn’t the whole story. When you become a client, this is the evidence pack your procurement, security, and data-protection teams walk through before they sign.
SOC 2 Type II achieved
Empyreal-internal SOC 2 Type II achieved Dec 2025. Vanta evidence pipeline wired Day 1 for clients.
Signed DPA + SCCs
UK + EU GDPR-aware. SCCs for cross-border. Sub-processor list versioned.
DSAR runbook + erasure
30-day DSAR response defendable. Right-to-erasure at the schema.
30-day walk-away
You keep everything. IP assigns on commit. No lock-in.
No-poach for agencies
12-month no-poach with referrer agencies on request.
Procurement pack
SIG-Lite + CAIQ pre-filled. Pen test report. DR plan.

What it looks like shipped.
privacy terms, in context — the dashboards, flows and components your team actually ships, reviews and maintains.
Email Mohit direct.
mohit@empyrealinfotech.com · 24-hour reply. For a DSAR or erasure request, put “DSAR” or “Erasure” in the subject. ICO complaint: ico.org.uk.
- < 24h
A personal reply.
Mohit reads every first email and replies straight to your inbox, not a team thread.
- ≤ 30 days
DSAR or erasure honoured.
Access, rectification, erasure, restriction, portability, objection, all under UK GDPR.
- Unresolved
ICO escalation.
You can complain to the ICO at ico.org.uk. EU residents may use their local authority.