Legal

Privacy Notice

What personal data we collect, why we collect it, who we share it with, and the rights you have over it.

Effective Date: August 6, 2026

1 Who We Are

SecComply Technologies Private Limited ("SecComply", "we", "our", "us"), registered office [registered office address to be inserted], operates the website seccomply.net and provides cybersecurity compliance consulting, vulnerability assessment and penetration testing (VAPT), and related advisory services.

For the personal data described in this notice, SecComply is the Data Fiduciaryunder the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025. That means we decide why and how your data is processed, and we are accountable for it. If you are visiting from the EEA or the UK, Section 12 sets out the additional rights you have under the GDPR.

This document is also referred to as our Privacy Policy; the two names mean the same thing and are used interchangeably across our forms and our Cookie Policy.

2About This Notice & Languages

We publish this notice under Section 5(1) of the DPDP Act and Rule 3 of the DPDP Rules, 2025. It is written to be read on its own, in plain language, without cross-referencing other documents. Where we ask for your consent on a form, you will also see a short notice at the point of collection telling you exactly what that specific form collects and why.

Languages. This notice is published in English. Under Section 5(3) of the DPDP Act you have the option to receive it in English or in any language listed in the Eighth Schedule to the Constitution of India. Write to info@seccomply.net naming the language you would prefer and we will provide a translation free of charge.

3What We Collect & Why

We collect only what we need, for the purposes listed below, and we rely on your consent under Section 6 of the DPDP Act for each of them. Every form on this site is optional — you can browse the entire website without giving us any personal data at all.

Contact, assessment, pricing and scoping forms

What: your name, work email address, mobile number, organisation name, employee-count band, the services you are interested in, how you heard about us, and anything you choose to write in a free-text message or scoping answer. Why: to reply to your enquiry, prepare the assessment or pricing you asked for, and put you in touch with the right person on our team.

If you tick the separate, optional marketing box, we also use your email to send service offers and product updates. That consent is independent — declining it does not affect your enquiry, and you can withdraw it at any time.

Guide and resource downloads

What: your name, work email address, phone number and company name. Why: to give you the requested guide and to follow up about it.

DPDP Scanner

What: the website address you ask us to scan, and — only if you choose to enter one and tick the consent box — your email address. Why: to run the scan and, where you asked us to, to send you the results and follow up. The scan itself works without an email. We fetch and analyse the public page you name in order to produce your score; we do not store the page content or the scan result.

Website security

What: your IP address. Why: to rate-limit form submissions and block automated abuse. It is held in server memory only, for a maximum of ten minutes, and is never written to a database or attached to your enquiry. Our hosting provider also keeps standard access logs for its own security and reliability purposes.

Booking a call

What: whatever you enter on the booking page — typically name, email and a meeting time. Why: to schedule the meeting. Bookings are handled on Microsoft Bookings rather than on this website; see Section 5.

We do not sell your personal data, we do not use it to build advertising profiles, and we do not make any automated decision about you that produces a legal or similarly significant effect.

4Cookies & Analytics

This website sets one strictly necessary item of first-party storage, sc_consent, which records the cookie choice you made so we do not have to ask again. It contains your analytics preference, a timestamp and a version number — nothing that identifies you.

Analytics cookies are set only if you opt in. Nothing loads before you choose. If you accept, Google Analytics 4 sets _ga and _ga_<id> cookies to measure aggregate site usage. We run it with IP anonymisation enabled and with advertising storage, ad personalisation and ad user data permanently denied, so your visit is never used for advertising.

You can change your mind at any time using the Cookie Preferences link in the footer. Withdrawing is exactly as easy as consenting, as Section 6(4) of the DPDP Act requires, and when you withdraw we actively delete the analytics cookies rather than merely stopping new ones. We also honour the Global Privacy Control browser signal: if your browser sends it, we record a refusal automatically and never show you the banner.

One thing worth knowing: when you use the search box, your search term appears in the page address (for example /search?q=your+term). If you have enabled analytics, that address — including the search term — is part of the usage data we receive. Please avoid typing personal details into the search box.

Our Cookie Policy lists every cookie individually, with its purpose and lifetime.

5Sharing, Processors & Cross-Border Transfers

We do not sell your personal data. We share it only with the service providers below, who process it on our instructions and are contractually required to protect it. Several are based outside India, so using this website involves a transfer of your data abroad. Section 16 of the DPDP Act permits this except to countries the Central Government has specifically restricted; we do not transfer personal data to any restricted country.

RecipientWhat it doesLocation
ResendDelivers your form submission to our team as an emailUnited States
Google AnalyticsAggregate website usage measurement — only if you opt inUnited States
Google FormsHosts our self-assessment and gap-assessment questionnairesUnited States
Microsoft BookingsScheduling when you book a consultation callMicrosoft global infrastructure
UnsplashServes some article and guide images. Your browser requests these directly, so Unsplash receives your IP address and the page you are readingUnited States
Website hostingServes this website and keeps standard access logs[hosting provider and region to be confirmed]

Beyond these providers, we disclose personal data only where:

  • You ask us to — for example, sharing findings with an audit or certification body during an engagement.
  • The law requires it — under a court order, regulatory demand or other binding legal process.
  • Our business changes hands — in a merger, acquisition or sale of assets, subject to the same protections described here.

6 How Long We Keep It

Under Section 8(7) of the DPDP Act we must erase personal data once the purpose it was collected for is no longer being served. In practice:

  • Enquiry and download records: kept for 24 months from our last interaction with you, then deleted.
  • IP addresses used for rate limiting: held in server memory for at most ten minutes and never stored.
  • Client engagement and financial records: kept for the duration of the engagement and afterwards for as long as tax, accounting and contractual obligations require.

You can ask us to erase your data sooner at any time — see Section 7 — and we will do so unless we are legally required to keep it.

7 Your Rights as a Data Principal

The DPDP Act gives you the following rights over your personal data:

  • Access (Section 11): ask for a summary of the personal data we hold about you, what we do with it, and who we have shared it with.
  • Correction and erasure (Section 12): have inaccurate data corrected, incomplete data completed, outdated data updated, or your data erased.
  • Withdraw consent (Section 6(4)): withdraw any consent you gave us, as easily as you gave it. This does not undo processing that already happened lawfully.
  • Nominate (Section 14): nominate another person to exercise these rights on your behalf if you die or become incapacitated.
  • Grievance redressal (Section 13): raise a complaint with us about how we have handled your data — see Section 8.

How to exercise them. Email info@seccomply.net with the subject line "DPDP Rights Request". Tell us which right you are exercising and include the email address you originally gave us, so we can find your records. We may ask you one verifying question before we act, to be sure we are not disclosing your data to someone else. There is no fee.

For analytics consent specifically, you do not need to email anyone — the Cookie Preferences link in the footer withdraws it immediately.

A note on your own duties: Section 15 of the DPDP Act asks Data Principals not to file false or frivolous complaints and to give authentic information when exercising the right to correction.

8Grievance Redressal & Escalation

If you are unhappy with how we have handled your personal data or your rights request, you can raise a grievance with our designated Grievance Officer:

  • Grievance Officer, SecComply Technologies Private Limited
  • Email: info@seccomply.net
  • Address: [registered office address to be inserted]

We will acknowledge your grievance within 3 business days and give you a substantive response within 15 business days. Where a matter is complex and needs longer, we will tell you why and keep you updated, and we will in every case respond within the period prescribed by the DPDP Rules, 2025, which is at most 90 days.

If you are not satisfied with our response, or we do not respond in time, you may complain to the Data Protection Board of India through its digital office. You must raise the matter with us first — exhausting our grievance process is a precondition under Section 13(3) of the DPDP Act.

9 Personal Data Breaches

If a personal data breach affects your data, we will notify you without delay, in clear language, describing what happened, what data was involved, what we are doing about it and what you can do to protect yourself. We will also report the breach to the Data Protection Board of India — an initial intimation without delay, followed by a detailed report within 72 hours, as the DPDP Rules, 2025 require.

10Children's Data

This website and our services are meant for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children, and we do not carry out any tracking, behavioural monitoring or targeted advertising directed at children, which Section 9(3) of the DPDP Act prohibits. If you believe a child has given us their data, write to info@seccomply.net and we will delete it promptly.

11 How We Protect Your Data

Section 8(5) of the DPDP Act requires us to take reasonable security safeguards. Ours include:

  • Encryption of data in transit (TLS) and at rest
  • Role-based access control, so only staff who need your data can reach it
  • Collecting the minimum data each form actually needs
  • Rate limiting and bot protection on every form
  • Regular security assessments and vulnerability testing of our own systems
  • Staff training on data protection
  • Written terms with every processor listed in Section 5
  • A documented incident response procedure

No method of transmission or storage is perfectly secure, and we will not claim otherwise. What we commit to is maintaining safeguards appropriate to the data we hold and improving them as threats change.

12Additional Rights for EEA & UK Visitors

If you are in the European Economic Area or the United Kingdom, the GDPR applies to you in addition to everything above.

Our legal bases. We rely on your consent for enquiry forms, downloads, marketing and analytics; on contractual necessity where processing is needed to deliver an engagement or take pre-contractual steps you asked for; on legitimate interests for website security and abuse prevention; and on legal obligation where the law requires us to process or retain data.

Additional rights. Alongside access, rectification, erasure and consent withdrawal, you have the right to restrict processing, the right to data portability, and the right to object to processing carried out on the basis of legitimate interests.

Transfers. Where we transfer your data outside the EEA or UK, we rely on Standard Contractual Clauses or another recognised transfer mechanism.

Complaints. You may lodge a complaint with your local supervisory authority, though we would appreciate the chance to resolve it with you first.

13 Changes to This Notice

We update this notice when our practices, technology or legal obligations change. The Effective Date at the top always reflects the current version. Where a change materially affects how we handle your data, we will give you clearer notice than a silent edit — for example by re-requesting your consent where the law requires it.

14 Contact Us

Questions about this notice or about how we handle your data:

  • SecComply Technologies Private Limited
  • Email: info@seccomply.net
  • Address: [registered office address to be inserted]
  • Website: seccomply.net

To exercise a right, see Section 7. To raise a grievance, see Section 8.

Have Questions About Your Data?

We take your privacy seriously. Reach out to our team if you have any questions about how we handle your information.