Cookie & Data Retention Policy

Cookie & Security Policy

Detailed technical disclosures regarding cookie categorization, session tokens, analytical trackers, and data retention schedules under the DPDP Act 2023.

Effective Date: October 01, 2025 • Last Revised: August 25, 2026 • Ahmedabad, Gujarat, India

1 What are Cookies & Local Storage Tokens?

Cookies are small alphanumeric files placed on your browser or device when accessing B A C services. We utilize strictly necessary cookies and local storage tokens to ensure secure user authentication, CSRF token verification, and server load balancing.

2 Categories of Cookies Deployed

Strictly Necessary

Essential for session management, JWT authentication cookies (client_token, status_admin_token), and security firewalls.

Functional & UI

Preserves user interface state, active filter selections, and cookie consent preferences.

Aggregated Analytics

Anonymous traffic measurements, network performance latency probes, and crash telemetry.

3 Data Retention Schedules (DPDP Compliance)

Under Section 8(7) of the DPDP Act 2023, personal data is retained only for the duration necessary to satisfy the purpose for which it was collected:

Data Category Retention Period Statutory Justification
Client Account & Git Profiles Duration of active account + 30 days after deletion request Service fulfillment & account recovery grace period
Invoices & Financial Records 8 years from transaction date Statutory requirement under Indian GST & Income Tax Act
Status Alert Subscriptions Until unsubscribed or consent withdrawn Explicit opt-in consent
Server Diagnostic Logs 90 rolling days Security monitoring & incident RCA investigations

Questions or Cookie Preferences?

You can configure cookie preferences directly in your browser or submit a data management inquiry to our Data Protection Officer at [email protected].