Software development for London companies

We build software for London companies

Building the thing is usually the easy conversation. The one that decides it happens with people who were not in the first meeting, and one of their three questions is a no.

  • When we are actually working

    10:00 to 19:00 IST, 04:30 to 13:30 UTC, year roundAgainst a 09:00 to 17:30 London day: 4.5 hours of overlap under GMT, 5.5 under BST. A project coordinator can host a standup in the uncovered hours, or an overlap shift can be arranged. No continuous cover.

  • Where your code and deployments sit

    Your Git hosting and your cloud accountsCode lives in your Git hosting and deployments run in your cloud accounts, so what crosses a border is access rather than a copy of your estate.

  • Who is in London

    NobodyEvery one of our developers currently works from India. There is no London office, no UK entity and nobody on your side of the water.

Tell us what you are building.

You get a reply within one business day, with a technical person on the call.

Start with a paragraph

What it does, who uses it, and what has to be true before you can sign. One business day, technical person on the call.

How we handle what you send is set out in our privacy notice.

Whether we can build the thing is usually settled in an hour

What stalls a London engagement with an India-based supplier is three other questions. They come from three different people on your side, and they arrive in this order.

They also land on one desk, and it is probably yours. You put the supplier forward. Legal, the data protection officer and procurement come back to you, not to us. Usually separately. Usually after you have told your board it is handled. If the third question stops this in month two, you are the one explaining the choice to people who were happy to leave it to you.

The three questions, in the order they arrive

  1. 1

    Legal asks first: who owns the code?

    The cheapest question to get wrong and the most expensive to fix later. The default under English law surprises most people, and paying for the work does not settle it.

  2. Why 2 waits for 1Ownership is settled in the agreement before anyone writes a line, so it is answered first.
  3. 2

    Your data protection officer asks second: how does data reach India?

    India has no UK adequacy finding, so anything carrying personal data is a restricted transfer needing an instrument and an assessment behind it. We have a real answer. The answer is not that the problem disappears.

  4. Why 3 waits for 2The transfer question has an instrument behind it, so it is answerable. The last one is where we are short.
  5. 3

    Procurement asks last: what do you hold?

    Where we are short. We hold no framework certification of our own. For some procurement policies that ends the conversation, and it should end here rather than after six weeks of assessment.

Who owns the code?

Under the Copyright, Designs and Patents Act 1988 the author of a work is first owner of the copyright. Source code is a literary work under that Act, and so is the design material behind it. One general exception exists and it turns on employment. Where a work is made by an employee in the course of his employment, the employer is first owner. A supplier is not your employee. So the firm that writes your software owns it and you own nothing, whatever you paid.

Two sections reverse that, and both belong in the agreement before anyone writes a line. Section 90(3): an assignment of copyright is not effective unless it is in writing signed by or on behalf of the assignor. A verbal agreement, an invoice or a purchase order moves nothing. Section 91(1) handles the awkward part. The code does not exist on the day you sign, so what is assigned is future copyright. That signed agreement vests it in you automatically as each file comes into existence. Watch for a licence offered instead. Even an exclusive licence under section 92(1), in writing and signed, is permission to use and never moves the copyright.

Our position is that from Day 1 every line of code is your IP. For that to be true under English law the agreement has to carry that assignment of future copyright, in writing and signed, before the code exists. Ask for the clause and check it is there.

That is English law in general rather than advice on your own contracts, and your solicitor should read the sections.

Four things you can open and check

  1. The repository

    Commits land in your Git hosting, in your account, from the first one. Check: whose organisation owns the repository today.

  2. The cloud accounts

    Deployments run in your cloud accounts and your storage, and where you do not have them we provision, set up and hand the keys over. Check: whose billing account the environment sits in.

  3. The operational runbook

    Every project starts with documentation: architecture, deployment, CI/CD pipelines, BRD, SRS and change notes. Owning copyright in code you cannot deploy is ownership on paper. Check: hand the pipeline documentation to another firm and ask whether they could run a release from it.

  4. The TRS

    Architecture decisions go into the technical requirements specification, and every change goes through code review by a senior software engineer with GitFlow, unit tests, integration tests and CI/CD gating each merge. Check: pick a decision that looks odd and ask where it is recorded.

We work 10:00 to 19:00 India time

India does not observe daylight saving, so that is 04:30 to 13:30 UTC every day of the year. London moves twice a year. Against a London working day of 09:00 to 17:30, this is what our window covers.

Show data table
Hours of a 09:00 to 17:30 London working day during which Atyantik is at a keyboard. Our 04:30 to 13:30 UTC day reads as 04:30 to 13:30 in London under GMT, and 05:30 to 14:30 under BST.
Measure Value Target Range
London on GMT 4.5 hours 8.5 hours 0 hours to 8.5 hours
London on BST 5.5 hours 8.5 hours 0 hours to 8.5 hours

Four hours of your working day are uncovered in winter, three in summer. Where a live session has to sit inside them, a project coordinator can host it, or an overlap shift can be arranged on request. What we do not offer is continuous cover.

Figure Hours of a 09:00 to 17:30 London working day during which Atyantik is at a keyboard. Our 04:30 to 13:30 UTC day reads as 04:30 to 13:30 in London under GMT, and 05:30 to 14:30 under BST. Atyantik published working hours, 10:00 to 19:00 IST.

Uncovered hours do not evaporate

Somebody absorbs them, usually by answering a message at an hour they had not planned to work. Jasmina Chauvin, Prithwiraj Choudhury and Tommy Pan Fang published a study in Organization Science in 2024 covering 12,038 employees across 48 countries inside a single multinational employer. They measured the share of synchronous communication falling outside local business hours, and it moves sharply with overlap.

Show data table
Share of synchronous communication falling outside local business hours, by overlap with a direct superior and with the immediate team. Chauvin, Choudhury and Fang, Organization Science, 2024. Population: 12,038 employees across 48 countries within one multinational employer.
Item Value
Overlap with superior, 2 hours or less 24.6 percent
Overlap with superior, complete 11.9 percent
Overlap with immediate team, 2 hours or less 32.4 percent
Overlap with immediate team, complete 12.9 percent

That is an outside study of an outside workforce, not a measurement of an Atyantik engagement. It is the shape of the problem when someone counts it properly, and the reason our answer is a published window plus a named arrangement for the hours outside it.

Figure Share of synchronous communication falling outside local business hours, by overlap with a direct superior and with the immediate team. Chauvin, Choudhury and Fang, Organization Science, 2024. Population: 12,038 employees across 48 countries within one multinational employer. Chauvin, Choudhury and Fang, Organization Science, 2024.

How does data reach India?

India has no UK adequacy finding. That is a fact about a published list, not a judgement about Indian data protection standards. So if personal data reaches us, that is a restricted transfer under the UK GDPR. For an ongoing supplier relationship the route is Article 46 appropriate safeguards. The Article 49 derogations are built for occasional transfers, not a standing engagement, so they will not carry this. In practice that is the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Both were issued under section 119A of the Data Protection Act 2018 and have been in force since 21 March 2022. The instrument alone is not sufficient: the regulator's published expectation is that a transfer risk assessment accompanies it. Separately, as controller, you impose an Article 28 processor contract. It stipulates eight terms. They include processing only on your documented instructions, and deletion or return of the data when the work ends. This is a general statement of UK data protection law, not advice on your own processing.

What this changes

  • What genuinely reduces the assessment

    What that means

    Your systems stay yours. Code lives in your Git hosting and deployments run in your cloud accounts, so what crosses a border is access rather than a copy of your estate. That changes the volume, the retention and the blast radius your assessment has to reason about.

  • What it does not do

    What that means

    It does not remove the transfer, and we will not tell you it does. Access is processing. If a software engineer in India can read a production record, personal data has been made available outside the UK and your safeguards have to cover it. Keeping the database in London does not make the paperwork go away.

  • Where we can cut the exposure instead

    What that means

    The transfer exists. The question worth the time is how little personal data has to sit inside it: how much production data any non-production environment actually needs, whether production access can be scoped and time-bounded, and who holds what in writing. Worth settling on the first call rather than the fifth.

How we design data access

Here is the no

They took ownership like our in-house team would, maybe better. We didn't waste time explaining everything. They scoped, planned, and shipped. That's it.

Bob Miller, President, FoxDealer, 2022

One client, on one thing: how the work ran. He is describing delivery. Copyright, data transfers and audits all sit outside what he saw. Take it for what it is, a named person you can look up saying the scoping held and the thing shipped without needing managing from his side.

Here is the version to paste

At some point you have to explain this to someone who will never read a supplier's website, and who was not in any of these meetings.

Forward this part

Atyantik Technologies, software delivery supplier summary

  • Supplier. Atyantik Technologies. All developers currently based in India. No UK entity, no London office.
  • Hours. 10:00 to 19:00 IST, which is 04:30 to 13:30 UTC year round and does not shift. Against a 09:00 to 17:30 London day: 4.5 hours of overlap under GMT, 5.5 under BST. A project coordinator can host a standup in the uncovered hours, or an overlap shift can be arranged. No continuous cover.
  • Code ownership. Their position is that from Day 1 the code is our IP. For that to hold, our agreement has to assign future copyright in writing and signed, so it vests in us as each file is created. Code in our own repositories and cloud accounts, not theirs. This is a general statement of English law, not advice on our own contracts.
  • Data. No UK adequacy finding for India, so this is a restricted transfer: IDTA or UK Addendum under section 119A DPA 2018, plus a transfer risk assessment, plus an Article 28 processor contract. Systems stay in our tenancy, not the supplier's, which narrows the assessment without removing the transfer. This is a general statement of UK data protection law, not advice on our own processing.
  • Certification. None of their own. Their position is that they engineer systems to pass our auditors' requirements. If our policy requires a supplier certificate, this stops here.
  • Change control and first response. Every change request becomes a change note with time, effort and cost laid out before approval, and nothing in the build moves on a re-scope we have not explicitly accepted. That holds during the build and post-launch on AMC or lean-mode arrangements. First response is one business day, technical person on the call. The first conversation returns a scope, and the number follows the scope.

How a build actually runs

Or put us in front of them instead

Send the paragraph and we bring these six answers to the first call, within one business day.

How we handle what you send is set out in our privacy notice.

Whether to call us

  • You are building or rebuilding a product and want one team on it rather than a rotating bench. You get a core team assigned only to your project, and a lead software engineer you talk to directly. No handoffs you did not agree to.

  • Your auditors set the bar and you want a supplier who builds to it. That is the arrangement we are built for.

  • Your legal team is willing to put an assignment of future copyright into the agreement, in writing and signed before work starts. That clause is what makes the ownership real.

Where we are the wrong call

  • Your procurement policy requires the supplier itself to hold a certificate. We hold none, and we will not argue you out of your own policy. Stop here.

    Security and compliance work

  • You need somebody reachable across a full London working day. Our window covers 4.5 hours of it under GMT and 5.5 under BST, and we do not offer continuous cover. An overlap shift extends the window on request; it does not cover the day.

    Where we actually are

  • Your data protection officer will not approve any processing outside the UK as a matter of policy. Nothing on our side changes that, and the transfer is real.

    How we design data access

  • You want to see delivered work before you talk to anyone. There is a better starting point than a contact form.

    Delivered work

Questions your own process will generate

Do you have an office in London?
No. Atyantik Technologies has no UK entity and no London office, and all our developers are currently based in India. We work with London companies from India, on a published window of 10:00 to 19:00 India time, which is 04:30 to 13:30 UTC and does not shift when the clocks change. Against a London working day of 09:00 to 17:30 that is 4.5 hours of overlap under GMT and 5.5 under BST.
Who owns the code we pay for?
You do, and the mechanism matters because the default runs the other way. Under the Copyright, Designs and Patents Act 1988 the author is first owner. The only general exception is for an employee acting in the course of employment. So a supplier keeps the copyright unless the agreement assigns it in writing and signed. Our position is that from Day 1 every line of code is your IP. For that to be true the agreement has to assign future copyright in writing and signed, so that section 91(1) vests it in you as each file is created rather than at handover. Ask for that clause and check it is there. This is a general statement of English law, not legal advice on your own contracts.
India has no UK adequacy finding. How can we transfer personal data to you?
Through Article 46 appropriate safeguards. In the UK that means the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Both were issued under section 119A of the Data Protection Act 2018 and have been in force since 21 March 2022. A transfer risk assessment goes alongside, which the regulator expects, and an Article 28 processor contract on top. Because code lives in your Git hosting and deployments run in your cloud accounts, what crosses a border is access rather than a copy of your estate, which narrows what your assessment must cover. It does not remove the transfer. Access is processing. This is a general statement of UK data protection law, not advice on your own processing.
Do you hold a security certification?
No. We do not certify against specific compliance frameworks ourselves, we engineer systems that pass your auditors' requirements. Our enterprise engagements include regulated finance and supply-chain platforms where security audits are quarterly and downtime is measured in minutes, and we implement OAuth and SSO at the standard those domains expect. If your procurement policy requires the supplier itself to hold a certificate, we are not a fit.
What happens during the hours we do not overlap?
Our day is 10:00 to 19:00 India time, 04:30 to 13:30 UTC year round. Against a London working day of 09:00 to 17:30 that leaves four hours uncovered under GMT and three under BST. Where a live session has to sit inside those hours, a project coordinator can host it, or an overlap shift can be arranged on request. We do not offer continuous cover. When timelines move you hear about it in the week the risk emerges, not the week before delivery.
How are changes to scope handled?
Every change request becomes a change note. Time, effort, and cost are laid out before approval, and the change only enters the plan once you sign off, confirmed in a meeting and in writing. Nothing in the build moves on a re-scope you have not explicitly accepted. That applies during the build and post-launch on AMC or lean-mode arrangements.
What if we want to move the work in-house or to another firm?
Every project starts with documentation: architecture, deployment, CI/CD pipelines, BRD, SRS and change notes, with architecture decisions recorded in the technical requirements specification. If you choose to move the work, the handoff is a process, not a hostage situation, and the freedom is yours from Day 1. So far, no client has needed to use it.
How long before work starts, and what happens after launch?
Planning is bounded, not open-ended. The average MVP from intake to first production deploy is around 3.5 weeks. Complex requirements take longer to plan, never longer to start. After launch, most engagements continue as an Annual Maintenance Contract or a lean-mode arrangement; our longest active partnership has run more than a decade.

Tell us what you are building

A paragraph is enough. What it does, who uses it, and what has to be true before you can sign.

If the ownership question or the transfer question is what is blocking you, say so in the message. We bring those answers to the first call instead of the third.

Tirth BodawalaCTO, Atyantik Technologies
  • You get a reply within one business day with a technical person on the call, not a salesperson with a software engineer copied in.
  • The first conversation returns a scope, and the number follows the scope.

How we handle what you send is set out in our privacy notice.