What personal data we collect, why we collect it, who we share it with, and the rights you have over it.
For the personal data described in this notice, SecComply is the Data Fiduciaryunder the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025. That means we decide why and how your data is processed, and we are accountable for it. If you are visiting from the EEA or the UK, Section 12 sets out the additional rights you have under the GDPR.
This document is also referred to as our Privacy Policy; the two names mean the same thing and are used interchangeably across our forms and our Cookie Policy.
We publish this notice under Section 5(1) of the DPDP Act and Rule 3 of the DPDP Rules, 2025. It is written to be read on its own, in plain language, without cross-referencing other documents. Where we ask for your consent on a form, you will also see a short notice at the point of collection telling you exactly what that specific form collects and why.
Languages. This notice is published in English. Under Section 5(3) of the DPDP Act you have the option to receive it in English or in any language listed in the Eighth Schedule to the Constitution of India. Write to info@seccomply.net naming the language you would prefer and we will provide a translation free of charge.
We collect only what we need, for the purposes listed below, and we rely on your consent under Section 6 of the DPDP Act for each of them. Every form on this site is optional — you can browse the entire website without giving us any personal data at all.
What: your name, work email address, mobile number, organisation name, employee-count band, the services you are interested in, how you heard about us, and anything you choose to write in a free-text message or scoping answer. Why: to reply to your enquiry, prepare the assessment or pricing you asked for, and put you in touch with the right person on our team.
If you tick the separate, optional marketing box, we also use your email to send service offers and product updates. That consent is independent — declining it does not affect your enquiry, and you can withdraw it at any time.
What: your name, work email address, phone number and company name. Why: to give you the requested guide and to follow up about it.
What: the website address you ask us to scan, and — only if you choose to enter one and tick the consent box — your email address. Why: to run the scan and, where you asked us to, to send you the results and follow up. The scan itself works without an email. We fetch and analyse the public page you name in order to produce your score; we do not store the page content or the scan result.
What: your IP address. Why: to rate-limit form submissions and block automated abuse. It is held in server memory only, for a maximum of ten minutes, and is never written to a database or attached to your enquiry. Our hosting provider also keeps standard access logs for its own security and reliability purposes.
What: whatever you enter on the booking page — typically name, email and a meeting time. Why: to schedule the meeting. Bookings are handled on Microsoft Bookings rather than on this website; see Section 5.
This website sets one strictly necessary item of first-party storage, sc_consent, which records the cookie choice you made so we do not have to ask again. It contains your analytics preference, a timestamp and a version number — nothing that identifies you.
Analytics cookies are set only if you opt in. Nothing loads before you choose. If you accept, Google Analytics 4 sets _ga and _ga_<id> cookies to measure aggregate site usage. We run it with IP anonymisation enabled and with advertising storage, ad personalisation and ad user data permanently denied, so your visit is never used for advertising.
You can change your mind at any time using the Cookie Preferences link in the footer. Withdrawing is exactly as easy as consenting, as Section 6(4) of the DPDP Act requires, and when you withdraw we actively delete the analytics cookies rather than merely stopping new ones. We also honour the Global Privacy Control browser signal: if your browser sends it, we record a refusal automatically and never show you the banner.
One thing worth knowing: when you use the search box, your search term appears in the page address (for example /search?q=your+term). If you have enabled analytics, that address — including the search term — is part of the usage data we receive. Please avoid typing personal details into the search box.
Our Cookie Policy lists every cookie individually, with its purpose and lifetime.
We do not sell your personal data. We share it only with the service providers below, who process it on our instructions and are contractually required to protect it. Several are based outside India, so using this website involves a transfer of your data abroad. Section 16 of the DPDP Act permits this except to countries the Central Government has specifically restricted; we do not transfer personal data to any restricted country.
| Recipient | What it does | Location |
|---|---|---|
| Resend | Delivers your form submission to our team as an email | United States |
| Google Analytics | Aggregate website usage measurement — only if you opt in | United States |
| Google Forms | Hosts our self-assessment and gap-assessment questionnaires | United States |
| Microsoft Bookings | Scheduling when you book a consultation call | Microsoft global infrastructure |
| Unsplash | Serves some article and guide images. Your browser requests these directly, so Unsplash receives your IP address and the page you are reading | United States |
| Website hosting | Serves this website and keeps standard access logs | [hosting provider and region to be confirmed] |
Beyond these providers, we disclose personal data only where:
Under Section 8(7) of the DPDP Act we must erase personal data once the purpose it was collected for is no longer being served. In practice:
You can ask us to erase your data sooner at any time — see Section 7 — and we will do so unless we are legally required to keep it.
The DPDP Act gives you the following rights over your personal data:
How to exercise them. Email info@seccomply.net with the subject line "DPDP Rights Request". Tell us which right you are exercising and include the email address you originally gave us, so we can find your records. We may ask you one verifying question before we act, to be sure we are not disclosing your data to someone else. There is no fee.
For analytics consent specifically, you do not need to email anyone — the Cookie Preferences link in the footer withdraws it immediately.
A note on your own duties: Section 15 of the DPDP Act asks Data Principals not to file false or frivolous complaints and to give authentic information when exercising the right to correction.
If you are unhappy with how we have handled your personal data or your rights request, you can raise a grievance with our designated Grievance Officer:
We will acknowledge your grievance within 3 business days and give you a substantive response within 15 business days. Where a matter is complex and needs longer, we will tell you why and keep you updated, and we will in every case respond within the period prescribed by the DPDP Rules, 2025, which is at most 90 days.
If a personal data breach affects your data, we will notify you without delay, in clear language, describing what happened, what data was involved, what we are doing about it and what you can do to protect yourself. We will also report the breach to the Data Protection Board of India — an initial intimation without delay, followed by a detailed report within 72 hours, as the DPDP Rules, 2025 require.
This website and our services are meant for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children, and we do not carry out any tracking, behavioural monitoring or targeted advertising directed at children, which Section 9(3) of the DPDP Act prohibits. If you believe a child has given us their data, write to info@seccomply.net and we will delete it promptly.
Section 8(5) of the DPDP Act requires us to take reasonable security safeguards. Ours include:
No method of transmission or storage is perfectly secure, and we will not claim otherwise. What we commit to is maintaining safeguards appropriate to the data we hold and improving them as threats change.
If you are in the European Economic Area or the United Kingdom, the GDPR applies to you in addition to everything above.
Our legal bases. We rely on your consent for enquiry forms, downloads, marketing and analytics; on contractual necessity where processing is needed to deliver an engagement or take pre-contractual steps you asked for; on legitimate interests for website security and abuse prevention; and on legal obligation where the law requires us to process or retain data.
Additional rights. Alongside access, rectification, erasure and consent withdrawal, you have the right to restrict processing, the right to data portability, and the right to object to processing carried out on the basis of legitimate interests.
Transfers. Where we transfer your data outside the EEA or UK, we rely on Standard Contractual Clauses or another recognised transfer mechanism.
Complaints. You may lodge a complaint with your local supervisory authority, though we would appreciate the chance to resolve it with you first.
We update this notice when our practices, technology or legal obligations change. The Effective Date at the top always reflects the current version. Where a change materially affects how we handle your data, we will give you clearer notice than a silent edit — for example by re-requesting your consent where the law requires it.
Questions about this notice or about how we handle your data:
To exercise a right, see Section 7. To raise a grievance, see Section 8.
We take your privacy seriously. Reach out to our team if you have any questions about how we handle your information.