Engineering for UK companies.
UK procurement asks the right questions early: who is the data controller, where is the transfer agreement, which sub-processors, what is your certification number. We hold the answers as documents rather than assurances — ISO 27001, a DPA with named sub-processors, and an IDTA for the transfer, all available before the first technical call.
- Daily overlap
- 09:00–12:30 GMT
- Contract currency
- GBP
- Data regime
- UK GDPR and the Data Protection Act 2018
- Regulator
- Information Commissioner's Office (ICO)
- Working language
- English
Hours, money,
and paperwork.
The three things that decide whether a cross-border engagement works, answered before you ask. Everything here is specific to the UK rather than a global average.
Time overlap
09:00–12:30 GMT
IST is five and a half hours ahead of GMT, so your morning is the back half of our day. Our 18:00 IST is your 12:30 GMT, which gives three and a half hours of genuine overlap through the winter. Under British Summer Time the gap narrows by an hour and the overlap grows to four and a half. Standups, reviews and stakeholder demos sit inside it. Your afternoon is outside our working day and is covered by written reporting rather than by someone pretending to be online.
Currency and tax
GBP
Quoted and invoiced in pounds sterling, so your budget line and our invoice carry the same number with no exchange exposure on your side. There is no Indian tax component to reclaim or query. As a non-UK supplier of services to a UK business, VAT is accounted for by you under the reverse charge — a treatment your accountant will recognise immediately.
Data protection
- Governing law
- UK GDPR and the Data Protection Act 2018
- Authority
- Information Commissioner's Office (ICO)
- Our role
- Processor, on your instructions
Named sub-processors, written consent before any addition.
You are controller, we are processor, under a DPA that names every sub-processor and requires your written consent before another is added. Transfers out of the UK are covered by the ICO's International Data Transfer Agreement or the UK Addendum to the EU SCCs, with a transfer risk assessment provided. UK or EU data residency can be fixed at contract rather than left to the provider's default region.
Answered
before you ask.
The questions we are asked most often from the UK, answered straight. Where we do not hold something, it says so.
Cyber Essentials certification
We hold ISO 27001:2022 rather than Cyber Essentials, which is a UK-specific scheme for UK-registered organisations. ISO 27001 is the broader standard and covers the same control ground with an external audit behind it. We will map our controls to the Cyber Essentials five if you need the comparison.
DPA, sub-processor list and TRA
All three exist as documents, not promises. The sub-processor list is specific to your engagement, and adding to it needs written consent. The transfer risk assessment is provided with the DPA rather than on request.
Financial standing and company checks
We are a registered Indian LLP, LLPIN ACS-5305, verifiable on the MCA portal — the equivalent of a Companies House check. GSTIN, DPIIT recognition and Udyam registration are all published with their numbers.
Accessibility conformance
Accessibility criteria are set during design rather than retrofitted, and WCAG 2.2 AA is the working target on public-facing interfaces. Full conformance claims require manual testing with assistive technology and expert review, which we scope explicitly rather than assert.
Certificate numbers, accreditation status and the verification route are published on our trust page. Check them without asking us.
The problems
that arrive.
The work that comes to us from the UK most often. If one of these is yours, send us the brief.
Legacy estate that cannot be replaced wholesale
A system that runs the business, was written a decade ago, and has to keep running while it changes. Integration boundaries and incremental extraction, not a rewrite pitch.
Regulated-adjacent product work
Financial services, insurance and healthcare products where the audit trail matters as much as the feature. Decision records and change control are deliverables, not overhead.
Design and brand systems
Design and brand are commissioned on their own here more often than in most markets. Identity, design systems and front-end build without an engineering programme attached.
Why the UK works with us
- The four documents UK procurement asks for — ISO 27001 certificate, DPA, sub-processor list, transfer risk assessment — exist before you ask, with a certificate number you can verify independently.
- Your whole morning overlaps our working day, which is the difference between collaboration and handover — and we quote the window in your time zone rather than ours.
- Weekly written reporting covering what shipped, what slipped, decisions taken and risks opened or closed — an audit trail a board pack can quote.
We are not a UK-registered company and hold neither Cyber Essentials nor a G-Cloud listing. For central government work that mandates either, we are not eligible. For private sector and most local authority work, the ISO certifications and a mapped control summary have been sufficient — but check your own framework before you invest time.
Asked from
the UK.
Answers open with the answer. The general set — pricing, process, IP, security — is on the FAQ.
- Are you UK GDPR compliant as a data processor?
- Yes. Engagements run under a data processing agreement where you are controller and we are processor, naming every sub-processor, with your written consent required before another is added. Transfers to India are covered by the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and a transfer risk assessment is supplied with the DPA. The ISO 27001:2022 information security management system provides the audited control framework beneath those commitments.
- Do you have Cyber Essentials, and what if our framework requires it?
- We do not hold it and cannot: the scheme certifies UK-registered organisations, and we are an Indian LLP. Where your framework treats it as preferred rather than mandatory, our ISO 27001:2022 certificate plus a mapping to the five Cyber Essentials controls has been accepted. Where it is genuinely mandatory — most central government routes, and some framework agreements — the workable structure is us as a subcontracted engineering capability behind a UK prime who holds it, with our ISO scope statement supporting their submission. If neither route fits, we will tell you on the first call rather than let you run a procurement that cannot conclude.
- Can our data stay in the UK or EU?
- Yes, where the architecture allows it. Data residency is agreed at contract and written into the DPA rather than left to a provider default. Hosting in UK or EU regions is standard for engagements with that requirement, and the sub-processor list is adjusted accordingly before work starts.
- How much overlap will we actually get with your team?
- Three and a half hours in winter and four and a half through British Summer Time, running from your 09:00. India is five and a half hours ahead of GMT, so our working day ends at 12:30 GMT — your morning is our afternoon, and your afternoon is outside our day. We publish the window in your time zone and treat it as a commitment: standups, reviews and demos happen inside it, and the rest of your day runs on written reporting rather than on someone appearing to be available.
Where else
we work.
Working hours, currency and data protection, covered for every market we serve.
Working with the UK.
Contracted in GBP, governed by UK GDPR and the Data Protection Act 2018, delivered inside the 09:00–12:30 GMT overlap window.
Cognimit Technologies LLP · Monday to Friday, 10:00–18:00 IST · IST (UTC+5:30)