Trust & Compliance
We're a young, partner-led firm building enterprise- and bank-grade practices from day one. This page is a direct account of where we stand right now, not a marketing claim — use it as a starting point for your own due diligence, not a substitute for it.
Data protection & GDPR
We agree a Data Processing Agreement, and Standard Contractual Clauses where personal data moves from the EU to India, as part of contracting — not as an afterthought once an engagement is underway.
Where a client needs EU-only data at rest, restricted local access, or infrastructure hosted entirely on their own environment, we scope that as part of the engagement design rather than defaulting to our own infrastructure.
Every engagement has a named lead accountable for data-handling practices on that account, not a shared support inbox.
For financial institutions & regulated buyers
DORA requires EU financial entities to run due diligence and maintain specific contractual terms before onboarding any ICT third party. Here's how we approach that.
For clients that are EU financial entities, we structure engagement contracts to cover service levels, audit and access rights, and exit provisions — the terms a DORA-scope vendor risk review will look for.
We support audit and inspection rights for the client and, where required, their competent authority — agreed upfront, not negotiated under pressure later.
We disclose our subcontracting chain before contracting, including partners who handle legal, compliance, operations or facilities, and don't introduce new subcontractors into a critical engagement without the client's prior knowledge.
For dedicated teams and captive centres, wind-down and transfer terms are scoped at the start of the engagement, not improvised at the end — see our build-operate-transfer model for the mechanics.
We also work with non-financial enterprise clients on NIS2-aligned incident cooperation and reporting terms where relevant, and with clients buying AI and automation work on responsible-use terms consistent with the EU AI Act's risk-based approach.
Contracting entity
Engagements are contracted with Bhuvi Venture Labs LLP, incorporated in India, under Indian law.
Send it over and we'll work through it directly rather than asking you to take our word for it.