Legal

Privacy Policy

At eSecurity (“we”, “our”, “us”, or “eSecurity”), we are committed to protecting your privacy and handling your personal data responsibly and lawfully. This Privacy Policy explains how we collect, use, disclose, store, protect, and dispose of personal data when you visit our website, use our services, or otherwise interact with us.

Prepared in accordance with the Digital Personal Data Protection Act, 2023 (“DPDPA”), the rules made or to be made thereunder, and other applicable laws of India.

By using our website or services, or by otherwise providing personal data to us, you acknowledge that you have read and understood this Policy. Where processing is based on consent, that consent is sought separately and is not implied merely from your use of the website.

1. About eSecurity

eSecurity is a cybersecurity consulting and technology solutions company providing cybersecurity advisory, managed security services, security assessments, governance, risk and compliance consulting, cyber awareness training, and implementation services.

For the purposes of the DPDPA, eSecurity acts as a Data Fiduciary in determining the purpose and means of processing personal data described in this Policy. Where eSecurity processes personal data solely on the documented instructions of a client in the course of delivering contracted services, eSecurity acts as a Data Processor on that client's behalf, and the client's own privacy notice and instructions shall govern that processing.

eSecurity will assess, on an ongoing basis, whether it meets the criteria for classification as a Significant Data Fiduciary under Section 10 of the DPDPA. If so notified by the Central Government, eSecurity will comply with the additional obligations applicable to Significant Data Fiduciaries, including appointment of a Data Protection Officer, periodic Data Protection Impact Assessments, and independent data audits.

2. Personal Data We Collect

We collect only the personal data necessary for the purposes described in Clause 3, across the following categories:

Identity Information

  • Full name
  • Company name
  • Designation
  • Business email address
  • Business phone number

Professional Information

  • Organisation and industry
  • Project requirements
  • Security challenges disclosed to us
  • Communication preferences

Technical Information

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Referring website
  • Website usage data and session information
  • Cookies and similar tracking technologies

Marketing Preferences

  • Newsletter subscriptions
  • Webinar registrations
  • Event participation records
  • Whitepaper and research downloads

5. Cookies

Our website uses cookies and similar technologies to improve user experience, analyse website traffic, remember user preferences, enhance website security, and measure website performance. Details of the specific cookies used, their duration, and their purpose are set out in our Cookie Notice, available on request or via the cookie banner on our website.

You may manage or withdraw cookie consent at any time through your browser settings or the cookie preference tool on our website.

6. Disclosure of Personal Data

We may share personal data, strictly to the extent necessary for the purposes described in Clause 3, with:

  • Authorised employees and personnel, on a need-to-know basis
  • Technology and cloud infrastructure vendors engaged to support our services
  • Professional advisors (legal, accounting, insurance) bound by professional confidentiality obligations
  • Business partners engaged to deliver services you have requested
  • Government or regulatory authorities, where required by law or a valid legal process

We do not sell personal data to third parties. Every third party processing personal data on our behalf does so under a written contract that requires implementation of appropriate technical and organisational safeguards and prohibits use of the data for any purpose beyond the scope of our instructions.

7. International Transfer of Personal Data

Personal data may be processed or stored outside India using secure cloud infrastructure or trusted service providers. Any such transfer is made in accordance with Section 16 of the DPDPA.

eSecurity will not transfer personal data to any country or territory restricted by notification of the Central Government, and will maintain an internal record of such restrictions, updated as notifications are issued.

8. Information Security

We implement appropriate technical and organisational safeguards appropriate to the nature and sensitivity of the personal data processed, including:

  • Encryption of data in transit and at rest, where applicable
  • Role-based access control
  • Secure authentication mechanisms
  • Network monitoring and intrusion detection
  • Periodic security audits and vulnerability assessments
  • Backup and disaster recovery procedures
  • Employee security awareness and training programmes

While we employ industry-recognised security measures, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

9. Personal Data Breach Notification

In the event of a personal data breach, eSecurity shall, in accordance with Section 8(6) of the DPDPA:

  • Notify the Data Protection Board of India in the form and manner, and within the timeline, prescribed under applicable rules
  • Notify each affected Data Principal without undue delay, describing the nature of the breach, the likely consequences, the measures taken or proposed to mitigate risk, and safety measures the Data Principal may take
  • Take immediate remedial steps to contain, investigate, and mitigate the effects of the breach

eSecurity maintains an internal incident response process to give effect to these obligations.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, meet contractual obligations, comply with legal or regulatory requirements, resolve disputes, or protect our legal interests. Indicative retention periods by category are set out below; these may be varied where a longer period is required by law or a specific engagement.

Category of Personal DataRetention PeriodBasis for Period
Enquiry and lead data (no engagement results)24 months from last contactLegitimate business follow-up window
Client and contract data7 years from termination of engagementContractual and statutory limitation periods
Security assessment records and deliverablesAs specified in the applicable service agreement, or 7 years if unspecifiedContractual/regulatory audit requirements
Website and cookie usage data13 monthsAnalytics and security monitoring cycle
Marketing consent and communication recordsUntil consent is withdrawn, plus 12 monthsEvidencing lawful basis for past processing

Once retention is no longer necessary, personal data is securely deleted or anonymised such that it can no longer be associated with an identifiable individual.

11. Your Rights as a Data Principal

Subject to applicable law, you may exercise the following rights under the DPDPA by contacting us using the details in Clause 16:

11.1 Right to Access Information (Section 11)

You may request a summary of the personal data we process about you, the processing activities undertaken, the identities of Data Fiduciaries and Data Processors with whom your data has been shared together with a description of the data shared, and any other information prescribed by the rules made under the DPDPA.

11.2 Right to Correction and Erasure (Section 12)

You may request correction of inaccurate or misleading personal data, completion of incomplete personal data, updating of personal data, and erasure of personal data that is no longer necessary for the purpose for which it was processed, unless retention is required by law.

11.3 Right to Grievance Redressal (Section 13)

You have the right to have any grievance relating to processing of your personal data resolved by us, before approaching the Data Protection Board of India.

11.4 Right to Nominate (Section 14)

You may nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity. To register a nomination, please submit a written request with the nominee's name and contact details to the Grievance Officer identified in Clause 12.

11.5 Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time as described in Clause 4.

We will respond to requests exercising these rights within the timelines prescribed under applicable law. We may require reasonable verification of your identity before acting on a request.

12. Grievance Officer

In accordance with Section 13 of the DPDPA, eSecurity has appointed the following Grievance Officer to address privacy-related concerns and grievances:

  • Name: [Insert Grievance Officer Name]
  • Designation: [Insert Designation]
  • Email: privacy@esecurity.com
  • Address: [Insert Registered Office Address]

We will acknowledge receipt of a grievance within 7 days and endeavour to resolve it within the timelines prescribed under applicable rules, currently proposed at 90 days under the draft DPDP Rules, 2025. If you are not satisfied with our resolution, you may escalate the grievance to the Data Protection Board of India.

13. Children's Data and Data of Persons with Disabilities

Our services are intended for businesses and professionals and are not directed at children. In accordance with Section 9 of the DPDPA, we do not knowingly collect or process the personal data of any child (an individual who has not completed the age of eighteen years) without verifiable consent of the child's parent or lawful guardian, and we do not process personal data of a person with a disability who has a lawful guardian without the consent of such guardian, where required.

We do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children.

If we identify that we have inadvertently collected such personal data without the requisite consent, it will be deleted promptly upon discovery.

14. Marketing Communications

Where you have opted in, we may send security advisories, product announcements, industry reports, research papers, webinar invitations, and event information.

You may unsubscribe at any time using the unsubscribe link in our communications or by contacting us using the details in Clause 16.

15. Third-Party Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of those websites independently.

16. Contact Us

For any questions regarding this Privacy Policy or your personal data, please contact:

  • eSecurity
  • Email: privacy@esecurity.com
  • Website: www.esecurity.com
  • Registered Office: [Insert Registered Office Address]

17. Changes to this Privacy Policy

We may revise this Privacy Policy periodically to reflect changes in our services, legal obligations, or business practices. The updated version will be published on this page together with a revised Effective Date and version number. Where changes are material, we will provide additional notice, such as by email or a prominent notice on our website, before the changes take effect.

18. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and any rules, regulations, or notifications issued thereunder. Any disputes arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts at the location of eSecurity's registered office.

Questions about your data?

Reach our privacy team at privacy@esecurity.com

Contact Us