Legal
Privacy Policy
Effective date: 1 July 2025 — Last updated: 1 July 2025
1. Who We Are
Bluvara Solutions Limited (“Bluvara”, “we”, “us”, or “our”) is a software development and digital solutions company incorporated in Trinidad and Tobago. We operate exclusively online and can be contacted at:
- Email: info@bluvarasolutions.com
- Phone: +1 (868) 253-2019
- Website: https://www.bluvarasolutions.com
2. Legal Framework
This Privacy Policy is prepared in accordance with the Data Protection Act, Chapter 22:03 of the Laws of Trinidad and Tobago (as amended), which governs the collection, processing, storage, and transfer of personal data in Trinidad and Tobago. We are committed to processing personal data lawfully, fairly, and transparently.
Where we process the personal data of individuals located in the European Economic Area, we additionally comply with the General Data Protection Regulation (GDPR) to the extent applicable.
3. Personal Data We Collect
We may collect the following categories of personal data:
- Identity data: name, job title, company name.
- Contact data: email address, telephone number.
- Communication data: messages you send via our contact form or email.
- Technical data: IP address, browser type and version, time zone, pages visited, and other analytics data collected through cookies and similar technologies.
- Project data: information you provide during the course of an engagement (business requirements, workflow documentation, etc.) only to the extent necessary to deliver our services.
We do not collect special categories of personal data (e.g. health, biometric, racial or ethnic origin data) in the normal course of our business.
4. How We Collect Personal Data
- Directly from you — when you fill in our contact form, email us, or call us.
- Automatically — when you visit our website, we may collect technical data through cookies and analytics tools (see Section 9).
- From third parties — such as referral partners, only where that third party has confirmed they have your consent or another lawful basis to share your data.
5. Lawful Bases for Processing
Under the Data Protection Act (Cap. 22:03) and, where applicable, the GDPR, we process your personal data on the following lawful bases:
- Consent — where you have given us clear, specific, and freely given consent (e.g. opting in to receive marketing communications).
- Contractual necessity — where processing is necessary to fulfil a contract with you or to take pre-contractual steps at your request.
- Legal obligation — where we are required to process data to comply with a legal obligation under the laws of Trinidad and Tobago.
- Legitimate interests — where the processing is necessary for our legitimate business interests (e.g. improving our services, securing our systems) and those interests are not overridden by your rights and interests.
6. How We Use Your Personal Data
We use personal data to:
- Respond to your enquiries and provide quotations.
- Deliver, manage, and improve the software and digital services you engage us for.
- Send you service-related communications (project updates, invoices, support messages).
- Send you marketing communications where you have consented to receive them (you may withdraw consent at any time).
- Comply with applicable laws and regulatory obligations in Trinidad and Tobago.
- Detect, prevent, and investigate security incidents or fraudulent activity.
- Analyse website usage to improve our site and user experience.
7. Data Sharing and Disclosure
We do not sell, rent, or trade personal data. We may share your data only in the following circumstances:
- Service providers — trusted third-party processors (cloud hosting, analytics, payment processors) who process data on our behalf under binding data processing agreements and are contractually obligated to keep it confidential and secure.
- Legal requirements — where disclosure is required by applicable law, court order, or governmental authority in Trinidad and Tobago.
- Business transfers — in the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity subject to equivalent privacy protections.
8. International Data Transfers
Some of our service providers (e.g. cloud infrastructure) may be located outside Trinidad and Tobago. Where personal data is transferred internationally we ensure appropriate safeguards are in place, including:
- Contractual clauses that require the recipient to protect your data to a standard at least equivalent to the Data Protection Act.
- Where the recipient is located in a jurisdiction that the Information Commissioner has determined provides an adequate level of protection.
9. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to improve your browsing experience and to understand how visitors interact with our site. You can control cookies through your browser settings. Blocking cookies may affect some functionality.
We use analytics tools (such as Google Analytics) solely for aggregated, anonymised traffic analysis. We do not use cookies for targeted advertising.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:
- Enquiry / contact data: up to 2 years from last contact, unless converted to a client engagement.
- Client project data:7 years from project completion, in line with our legal and tax obligations under T&T law.
- Website analytics: up to 14 months in aggregated form.
When data is no longer required we securely delete or anonymise it.
11. Security and Compliance Certifications
Bluvara Solutions Limited applies industry-leading technical and organisational security measures. Our security programme is aligned with:
- SOC 2 Type II — our processes and controls are designed and operated to meet the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. We work towards and maintain SOC 2 Type II compliance to provide independent assurance to our clients.
- ISO/IEC 27001 principles — our Information Security Management System is structured around the ISO 27001 framework, covering risk assessment, access control, asset management, and incident response.
- OWASP Top 10 — all software we develop is reviewed against the OWASP Top 10 web application security risks, ensuring protection against injection attacks, broken authentication, insecure design, and related vulnerabilities.
- Encryption in transit and at rest — we use TLS 1.2+ for all data in transit and AES-256 encryption for sensitive data at rest.
- Access control & least privilege — access to client data is limited to personnel who require it to deliver the agreed services. Multi-factor authentication is enforced on all internal systems.
- Vulnerability management — we perform regular dependency audits, static analysis, and penetration testing to identify and remediate security vulnerabilities before they can be exploited.
Copies of our security attestations or compliance documentation are available to enterprise clients upon request and under a non-disclosure agreement.
12. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority (the Office of the Information Commissioner of Trinidad and Tobago) as soon as reasonably practicable and, where required, notify affected individuals without undue delay in accordance with the Data Protection Act.
13. Your Rights
Under the Data Protection Act (Cap. 22:03) and applicable law, you have the following rights:
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to request that inaccurate or incomplete data be corrected.
- Right to erasure — to request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to restriction — to request that we restrict processing of your data in certain circumstances.
- Right to object — to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at info@bluvarasolutions.com. We will respond within 30 days. You may also lodge a complaint with the Office of the Information Commissioner of Trinidad and Tobago.
14. Children’s Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. We will post the revised policy on this page with an updated effective date. We encourage you to review this policy periodically.
16. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact:
Bluvara Solutions LimitedData Privacy Enquiries
Email: info@bluvarasolutions.com
Phone: +1 (868) 253-2019