We build software for London companies
Building the thing is usually the easy conversation. The one that decides it happens with people who were not in the first meeting, and one of their three questions is a no.
- When we are actually working
10:00 to 19:00 IST, 04:30 to 13:30 UTC, year roundAgainst a 09:00 to 17:30 London day: 4.5 hours of overlap under GMT, 5.5 under BST. A project coordinator can host a standup in the uncovered hours, or an overlap shift can be arranged. No continuous cover.
- Where your code and deployments sit
Your Git hosting and your cloud accountsCode lives in your Git hosting and deployments run in your cloud accounts, so what crosses a border is access rather than a copy of your estate.
- Who is in London
NobodyEvery one of our developers currently works from India. There is no London office, no UK entity and nobody on your side of the water.
Tell us what you are building.
You get a reply within one business day, with a technical person on the call.
Start with a paragraph
What it does, who uses it, and what has to be true before you can sign. One business day, technical person on the call.
Whether we can build the thing is usually settled in an hour
What stalls a London engagement with an India-based supplier is three other questions. They come from three different people on your side, and they arrive in this order.
They also land on one desk, and it is probably yours. You put the supplier forward. Legal, the data protection officer and procurement come back to you, not to us. Usually separately. Usually after you have told your board it is handled. If the third question stops this in month two, you are the one explaining the choice to people who were happy to leave it to you.
The three questions, in the order they arrive
1
Legal asks first: who owns the code?
The cheapest question to get wrong and the most expensive to fix later. The default under English law surprises most people, and paying for the work does not settle it.
- Why 2 waits for 1Ownership is settled in the agreement before anyone writes a line, so it is answered first.
2
Your data protection officer asks second: how does data reach India?
India has no UK adequacy finding, so anything carrying personal data is a restricted transfer needing an instrument and an assessment behind it. We have a real answer. The answer is not that the problem disappears.
- Why 3 waits for 2The transfer question has an instrument behind it, so it is answerable. The last one is where we are short.
3
Procurement asks last: what do you hold?
Where we are short. We hold no framework certification of our own. For some procurement policies that ends the conversation, and it should end here rather than after six weeks of assessment.
Who owns the code?
Under the Copyright, Designs and Patents Act 1988 the author of a work is first owner of the copyright. Source code is a literary work under that Act, and so is the design material behind it. One general exception exists and it turns on employment. Where a work is made by an employee in the course of his employment, the employer is first owner. A supplier is not your employee. So the firm that writes your software owns it and you own nothing, whatever you paid.
Two sections reverse that, and both belong in the agreement before anyone writes a line. Section 90(3): an assignment of copyright is not effective unless it is in writing signed by or on behalf of the assignor. A verbal agreement, an invoice or a purchase order moves nothing. Section 91(1) handles the awkward part. The code does not exist on the day you sign, so what is assigned is future copyright. That signed agreement vests it in you automatically as each file comes into existence. Watch for a licence offered instead. Even an exclusive licence under section 92(1), in writing and signed, is permission to use and never moves the copyright.
Our position is that from Day 1 every line of code is your IP. For that to be true under English law the agreement has to carry that assignment of future copyright, in writing and signed, before the code exists. Ask for the clause and check it is there.
That is English law in general rather than advice on your own contracts, and your solicitor should read the sections.
Four things you can open and check
The repository
Commits land in your Git hosting, in your account, from the first one. Check: whose organisation owns the repository today.
The cloud accounts
Deployments run in your cloud accounts and your storage, and where you do not have them we provision, set up and hand the keys over. Check: whose billing account the environment sits in.
The operational runbook
Every project starts with documentation: architecture, deployment, CI/CD pipelines, BRD, SRS and change notes. Owning copyright in code you cannot deploy is ownership on paper. Check: hand the pipeline documentation to another firm and ask whether they could run a release from it.
The TRS
Architecture decisions go into the technical requirements specification, and every change goes through code review by a senior software engineer with GitFlow, unit tests, integration tests and CI/CD gating each merge. Check: pick a decision that looks odd and ask where it is recorded.
We work 10:00 to 19:00 India time
India does not observe daylight saving, so that is 04:30 to 13:30 UTC every day of the year. London moves twice a year. Against a London working day of 09:00 to 17:30, this is what our window covers.
Show data table
| Measure | Value | Target | Range |
|---|---|---|---|
| London on GMT | 4.5 hours | 8.5 hours | 0 hours to 8.5 hours |
| London on BST | 5.5 hours | 8.5 hours | 0 hours to 8.5 hours |
Four hours of your working day are uncovered in winter, three in summer. Where a live session has to sit inside them, a project coordinator can host it, or an overlap shift can be arranged on request. What we do not offer is continuous cover.
Uncovered hours do not evaporate
Somebody absorbs them, usually by answering a message at an hour they had not planned to work. Jasmina Chauvin, Prithwiraj Choudhury and Tommy Pan Fang published a study in Organization Science in 2024 covering 12,038 employees across 48 countries inside a single multinational employer. They measured the share of synchronous communication falling outside local business hours, and it moves sharply with overlap.
Show data table
| Item | Value |
|---|---|
| Overlap with superior, 2 hours or less | 24.6 percent |
| Overlap with superior, complete | 11.9 percent |
| Overlap with immediate team, 2 hours or less | 32.4 percent |
| Overlap with immediate team, complete | 12.9 percent |
That is an outside study of an outside workforce, not a measurement of an Atyantik engagement. It is the shape of the problem when someone counts it properly, and the reason our answer is a published window plus a named arrangement for the hours outside it.
How does data reach India?
India has no UK adequacy finding. That is a fact about a published list, not a judgement about Indian data protection standards. So if personal data reaches us, that is a restricted transfer under the UK GDPR. For an ongoing supplier relationship the route is Article 46 appropriate safeguards. The Article 49 derogations are built for occasional transfers, not a standing engagement, so they will not carry this. In practice that is the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Both were issued under section 119A of the Data Protection Act 2018 and have been in force since 21 March 2022. The instrument alone is not sufficient: the regulator's published expectation is that a transfer risk assessment accompanies it. Separately, as controller, you impose an Article 28 processor contract. It stipulates eight terms. They include processing only on your documented instructions, and deletion or return of the data when the work ends. This is a general statement of UK data protection law, not advice on your own processing.
What this changes
What genuinely reduces the assessment
What that means
Your systems stay yours. Code lives in your Git hosting and deployments run in your cloud accounts, so what crosses a border is access rather than a copy of your estate. That changes the volume, the retention and the blast radius your assessment has to reason about.
What it does not do
What that means
It does not remove the transfer, and we will not tell you it does. Access is processing. If a software engineer in India can read a production record, personal data has been made available outside the UK and your safeguards have to cover it. Keeping the database in London does not make the paperwork go away.
Where we can cut the exposure instead
What that means
The transfer exists. The question worth the time is how little personal data has to sit inside it: how much production data any non-production environment actually needs, whether production access can be scoped and time-bounded, and who holds what in writing. Worth settling on the first call rather than the fifth.
Here is the no
They took ownership like our in-house team would, maybe better. We didn't waste time explaining everything. They scoped, planned, and shipped. That's it.
One client, on one thing: how the work ran. He is describing delivery. Copyright, data transfers and audits all sit outside what he saw. Take it for what it is, a named person you can look up saying the scoping held and the thing shipped without needing managing from his side.
Here is the version to paste
At some point you have to explain this to someone who will never read a supplier's website, and who was not in any of these meetings.
Forward this part
Atyantik Technologies, software delivery supplier summary
- Supplier. Atyantik Technologies. All developers currently based in India. No UK entity, no London office.
- Hours. 10:00 to 19:00 IST, which is 04:30 to 13:30 UTC year round and does not shift. Against a 09:00 to 17:30 London day: 4.5 hours of overlap under GMT, 5.5 under BST. A project coordinator can host a standup in the uncovered hours, or an overlap shift can be arranged. No continuous cover.
- Code ownership. Their position is that from Day 1 the code is our IP. For that to hold, our agreement has to assign future copyright in writing and signed, so it vests in us as each file is created. Code in our own repositories and cloud accounts, not theirs. This is a general statement of English law, not advice on our own contracts.
- Data. No UK adequacy finding for India, so this is a restricted transfer: IDTA or UK Addendum under section 119A DPA 2018, plus a transfer risk assessment, plus an Article 28 processor contract. Systems stay in our tenancy, not the supplier's, which narrows the assessment without removing the transfer. This is a general statement of UK data protection law, not advice on our own processing.
- Certification. None of their own. Their position is that they engineer systems to pass our auditors' requirements. If our policy requires a supplier certificate, this stops here.
- Change control and first response. Every change request becomes a change note with time, effort and cost laid out before approval, and nothing in the build moves on a re-scope we have not explicitly accepted. That holds during the build and post-launch on AMC or lean-mode arrangements. First response is one business day, technical person on the call. The first conversation returns a scope, and the number follows the scope.
Or put us in front of them instead
Send the paragraph and we bring these six answers to the first call, within one business day.
Whether to call us
Where we fit
You are building or rebuilding a product and want one team on it rather than a rotating bench. You get a core team assigned only to your project, and a lead software engineer you talk to directly. No handoffs you did not agree to.
Your auditors set the bar and you want a supplier who builds to it. That is the arrangement we are built for.
Your legal team is willing to put an assignment of future copyright into the agreement, in writing and signed before work starts. That clause is what makes the ownership real.
Where we are the wrong call
Your procurement policy requires the supplier itself to hold a certificate. We hold none, and we will not argue you out of your own policy. Stop here.
You need somebody reachable across a full London working day. Our window covers 4.5 hours of it under GMT and 5.5 under BST, and we do not offer continuous cover. An overlap shift extends the window on request; it does not cover the day.
Your data protection officer will not approve any processing outside the UK as a matter of policy. Nothing on our side changes that, and the transfer is real.
You want to see delivered work before you talk to anyone. There is a better starting point than a contact form.
Questions your own process will generate
Do you have an office in London?
Who owns the code we pay for?
India has no UK adequacy finding. How can we transfer personal data to you?
Do you hold a security certification?
What happens during the hours we do not overlap?
How are changes to scope handled?
What if we want to move the work in-house or to another firm?
How long before work starts, and what happens after launch?
Tell us what you are building
A paragraph is enough. What it does, who uses it, and what has to be true before you can sign.
If the ownership question or the transfer question is what is blocking you, say so in the message. We bring those answers to the first call instead of the third.
- You get a reply within one business day with a technical person on the call, not a salesperson with a software engineer copied in.
- The first conversation returns a scope, and the number follows the scope.