LEGAL · PRIVACY POLICY

Effective 1 January 2025 · Last updated 9 August 2026Privacy Policy

How Staffinc collects, uses, stores and protects personal information when you visit this website or engage our services. Written in plain language so you can see exactly what happens to your data and what your rights are.

THE SHORT VERSION
Five things worth knowing
Client platforms run on your infrastructureWe do not host your operational data. It stays on your servers.
We never sell personal dataNot to anyone, for any purpose, ever.
No automated decisions about youWe do not profile website visitors or enquirers.
You can ask us to delete itThirty days to respond, no questions about why.
One follow-up, then silenceNo nurture sequences and no re-adding you later.
The full policy below is the operative version.

01Who we are

Staffinc is a software development company that designs and builds technology platforms for healthcare staffing agencies. We operate under the trading name Staffinc as part of Maverick Mount Technologies Pvt Ltd.

For personal data collected through this website and direct business communications, Staffinc acts as the data controller. For the platforms we build for clients, the client is the data controller and Staffinc acts as a data processor under a written data processing agreement.

Company Maverick Mount Technologies Pvt Ltd, trading as Staffinc
Registered office T 93/1 GF, Press Enclave Road, Malviya Nagar, New Delhi, Delhi 110017, India
Website staffinc.io

02Where client data lives

This is the section most prospective clients want first, so it comes early.

Platforms we build run on infrastructure you control. The source code, the database and the operational data all sit on your servers or your cloud account, in the region you choose. We do not host your platform, we do not hold your operational data, and we do not have a copy of it.

That means shift records, credential documents, client lists, timesheets and any personal data belonging to your workers or clients remain under your control at all times. If you end the relationship with us tomorrow, nothing of yours has to be retrieved from us, because we do not have it.

During a build and during any support engagement, named members of our team require access to your environment in order to do the work. That access is granted by you, scoped to what is needed, logged, and revoked when the engagement ends.

03International access and transfers

Our engineering and delivery team is based in New Delhi, India. Where a client is in the European Economic Area, the United Kingdom or another region with data transfer restrictions, access to personal data by our team constitutes an international transfer even though the data itself remains hosted in your chosen region.

We address this in the data processing agreement that accompanies every project contract, which includes standard contractual clauses where required, defined access controls, and a record of who has access and when. A copy is available on request before you sign anything.

For personal data collected through this website, such as enquiry and contact details, that data is processed by our team in India and by service providers described in section 06.

04Information we collect

We collect information you give us directly, and information collected automatically when you use this website.

Contact information Name, work email, agency name. Collected through forms on this website and direct email.
Business information Market, vertical, current systems and operational challenges. Collected through forms and discovery conversations.
Usage data Pages visited, time on site, referral source, browser type and IP address. Collected automatically through cookies and analytics.
Communications Emails, messages and notes from calls or meetings.
Billing information Details required to raise and settle project invoices, processed through third-party payment providers.
If you use a platform we built: for example a nurse using a shift app, or a family member using a homecare portal, your data is controlled by the agency operating that platform and hosted on their infrastructure, not ours. Please refer to their privacy policy.

05How we use it and on what basis

  • To respond to enquiries and arrange discovery calls

  • To assess requirements and prepare proposals

  • To deliver development and support services under contract

  • To raise and manage invoices

  • To understand how this website is used and improve it

  • To send relevant content where you have opted in

  • To meet legal and contractual obligations Where data protection law applies, including the GDPR, we rely on contractual necessity to deliver services you have engaged us for, legitimate interests to respond to business enquiries and improve our services, legal obligation where the law requires it, and consent for marketing communications. You can withdraw consent at any time by emailing [email protected].

    We do not sell personal data. We do not carry out automated decision-making or profiling in relation to website visitors or enquirers.

06Sharing your data

We do not sell or rent personal data. We share it only in these circumstances:

  • Service providers used to run our business, such as email, scheduling, analytics and cloud services. All are contractually required to handle data securely and only as instructed.

  • Professional advisors such as accountants, lawyers and auditors, where necessary for compliance.

  • Legal requirements, where required by law or court order, or to protect the rights and safety of Staffinc, our clients or the public.

  • Business transfers, in the event of a merger, acquisition or sale of part of our business.

07How long we keep it

Enquiry and contact data 2 years from last contact, or until deletion is requested
Client project records 7 years from completion, for legal and financial compliance
Invoice and billing records 7 years, for tax and accounting requirements
Website analytics 26 months, aggregated and anonymised
Marketing contact data Until consent is withdrawn or you unsubscribe

08Your rights

Depending on where you are and which law applies, you may have the right to access a copy of your data, correct it, have it deleted, restrict how it is used, receive it in a portable format, object to processing, or withdraw consent.

If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR and UK GDPR, and you may lodge a complaint with your local supervisory authority. In Ireland that is the Data Protection Commission.

If you are in the United States, several states including California, Colorado, Connecticut, Virginia and others provide rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined in state privacy laws. You may still exercise the rights above.

If you are in Canada, PIPEDA and applicable provincial legislation give you rights of access and correction, and the right to complain to the Office of the Privacy Commissioner.

To exercise any right, email [email protected]. We respond within 30 days and may need to verify your identity first. Exercising a right never costs you anything and never affects the service you receive.

09Cookies

This website uses cookies. Essential cookies are required for the site to function and cannot be disabled. Analytics and marketing cookies are optional and are only set where you have given consent through our cookie banner.

You can change or withdraw your cookie choices at any time through the cookie preferences link in the footer, or through your browser settings. Disabling optional cookies does not affect access to any part of this site.

10Security

  • Encrypted transmission (HTTPS and TLS) across all web properties

  • Role-based access, so personal data is reachable only by people who need it

  • Named, time-limited and revocable access to client environments

  • Regular security reviews of our systems and third-party providers No method of transmission over the internet is completely secure. If you believe your data has been compromised, email [email protected] immediately and we will treat it as urgent.

11Children

This website and our services are directed at business professionals and are not intended for anyone under 16. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it promptly.

12Changes and contact

We may update this policy to reflect changes in our practices or the law. Material changes will be reflected in the "last updated" date above. Continued use of this website after changes are posted constitutes acceptance.

Company Staffinc, a Maverick Mount Technologies Pvt Ltd company
Response time Within 30 days of receiving your request