Privacy Policy
At eSecurity (“we”, “our”, “us”, or “eSecurity”), we are committed to protecting your privacy and handling your personal data responsibly and lawfully. This Privacy Policy explains how we collect, use, disclose, store, protect, and dispose of personal data when you visit our website, use our services, or otherwise interact with us.
Prepared in accordance with the Digital Personal Data Protection Act, 2023 (“DPDPA”), the rules made or to be made thereunder, and other applicable laws of India.
By using our website or services, or by otherwise providing personal data to us, you acknowledge that you have read and understood this Policy. Where processing is based on consent, that consent is sought separately and is not implied merely from your use of the website.
1. About eSecurity
eSecurity is a cybersecurity consulting and technology solutions company providing cybersecurity advisory, managed security services, security assessments, governance, risk and compliance consulting, cyber awareness training, and implementation services.
For the purposes of the DPDPA, eSecurity acts as a Data Fiduciary in determining the purpose and means of processing personal data described in this Policy. Where eSecurity processes personal data solely on the documented instructions of a client in the course of delivering contracted services, eSecurity acts as a Data Processor on that client's behalf, and the client's own privacy notice and instructions shall govern that processing.
eSecurity will assess, on an ongoing basis, whether it meets the criteria for classification as a Significant Data Fiduciary under Section 10 of the DPDPA. If so notified by the Central Government, eSecurity will comply with the additional obligations applicable to Significant Data Fiduciaries, including appointment of a Data Protection Officer, periodic Data Protection Impact Assessments, and independent data audits.
2. Personal Data We Collect
We collect only the personal data necessary for the purposes described in Clause 3, across the following categories:
Identity Information
- Full name
- Company name
- Designation
- Business email address
- Business phone number
Professional Information
- Organisation and industry
- Project requirements
- Security challenges disclosed to us
- Communication preferences
Technical Information
- IP address
- Browser type and version
- Device information
- Operating system
- Referring website
- Website usage data and session information
- Cookies and similar tracking technologies
Marketing Preferences
- Newsletter subscriptions
- Webinar registrations
- Event participation records
- Whitepaper and research downloads
3. Itemised Notice: Purpose and Legal Basis for Processing
In accordance with Section 5 of the DPDPA, the table below sets out, for each category of personal data collected, the specific purpose(s) of processing and the legal basis relied upon.
| Category of Personal Data | Specific Purpose(s) | Legal Basis |
|---|---|---|
| Identity Information (name, company, designation, business email/phone) | Responding to enquiries; scheduling consultations; delivering services; contract management | Consent / Performance of contract |
| Professional Information (organisation, industry, project requirements, security challenges) | Scoping and delivering cybersecurity services; technical support; security assessments | Consent / Performance of contract |
| Technical Information (IP address, browser/device data, usage data, cookies) | Website functionality; security monitoring; fraud and threat detection; performance analytics | Consent / Legitimate use as permitted under Section 7, DPDPA |
| Marketing Preferences (newsletter, webinar, whitepaper activity) | Sending marketing communications, invitations and publications | Consent |
We process personal data only for the purposes stated above and for no purpose incompatible with them, save where required by law.
4. Consent
Where processing is based on consent under Section 6 of the DPDPA, we obtain free, specific, informed, unconditional, and unambiguous consent through a clear affirmative action (such as a checkbox or form submission) before collecting or processing personal data.
Consent, and its withdrawal, is recorded and can be managed by contacting us using the details in Clause 16, or, where applicable, through a registered Consent Manager as and when this mechanism is implemented on our website.
You may withdraw consent at any time with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where consent is withdrawn for processing necessary to deliver a specific service, that service may no longer be available to you; we will identify the affected service(s) at the time you request withdrawal.
6. Disclosure of Personal Data
We may share personal data, strictly to the extent necessary for the purposes described in Clause 3, with:
- Authorised employees and personnel, on a need-to-know basis
- Technology and cloud infrastructure vendors engaged to support our services
- Professional advisors (legal, accounting, insurance) bound by professional confidentiality obligations
- Business partners engaged to deliver services you have requested
- Government or regulatory authorities, where required by law or a valid legal process
We do not sell personal data to third parties. Every third party processing personal data on our behalf does so under a written contract that requires implementation of appropriate technical and organisational safeguards and prohibits use of the data for any purpose beyond the scope of our instructions.
7. International Transfer of Personal Data
Personal data may be processed or stored outside India using secure cloud infrastructure or trusted service providers. Any such transfer is made in accordance with Section 16 of the DPDPA.
eSecurity will not transfer personal data to any country or territory restricted by notification of the Central Government, and will maintain an internal record of such restrictions, updated as notifications are issued.
8. Information Security
We implement appropriate technical and organisational safeguards appropriate to the nature and sensitivity of the personal data processed, including:
- Encryption of data in transit and at rest, where applicable
- Role-based access control
- Secure authentication mechanisms
- Network monitoring and intrusion detection
- Periodic security audits and vulnerability assessments
- Backup and disaster recovery procedures
- Employee security awareness and training programmes
While we employ industry-recognised security measures, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
9. Personal Data Breach Notification
In the event of a personal data breach, eSecurity shall, in accordance with Section 8(6) of the DPDPA:
- Notify the Data Protection Board of India in the form and manner, and within the timeline, prescribed under applicable rules
- Notify each affected Data Principal without undue delay, describing the nature of the breach, the likely consequences, the measures taken or proposed to mitigate risk, and safety measures the Data Principal may take
- Take immediate remedial steps to contain, investigate, and mitigate the effects of the breach
eSecurity maintains an internal incident response process to give effect to these obligations.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, meet contractual obligations, comply with legal or regulatory requirements, resolve disputes, or protect our legal interests. Indicative retention periods by category are set out below; these may be varied where a longer period is required by law or a specific engagement.
| Category of Personal Data | Retention Period | Basis for Period |
|---|---|---|
| Enquiry and lead data (no engagement results) | 24 months from last contact | Legitimate business follow-up window |
| Client and contract data | 7 years from termination of engagement | Contractual and statutory limitation periods |
| Security assessment records and deliverables | As specified in the applicable service agreement, or 7 years if unspecified | Contractual/regulatory audit requirements |
| Website and cookie usage data | 13 months | Analytics and security monitoring cycle |
| Marketing consent and communication records | Until consent is withdrawn, plus 12 months | Evidencing lawful basis for past processing |
Once retention is no longer necessary, personal data is securely deleted or anonymised such that it can no longer be associated with an identifiable individual.
11. Your Rights as a Data Principal
Subject to applicable law, you may exercise the following rights under the DPDPA by contacting us using the details in Clause 16:
11.1 Right to Access Information (Section 11)
You may request a summary of the personal data we process about you, the processing activities undertaken, the identities of Data Fiduciaries and Data Processors with whom your data has been shared together with a description of the data shared, and any other information prescribed by the rules made under the DPDPA.
11.2 Right to Correction and Erasure (Section 12)
You may request correction of inaccurate or misleading personal data, completion of incomplete personal data, updating of personal data, and erasure of personal data that is no longer necessary for the purpose for which it was processed, unless retention is required by law.
11.3 Right to Grievance Redressal (Section 13)
You have the right to have any grievance relating to processing of your personal data resolved by us, before approaching the Data Protection Board of India.
11.4 Right to Nominate (Section 14)
You may nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity. To register a nomination, please submit a written request with the nominee's name and contact details to the Grievance Officer identified in Clause 12.
11.5 Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time as described in Clause 4.
We will respond to requests exercising these rights within the timelines prescribed under applicable law. We may require reasonable verification of your identity before acting on a request.
12. Grievance Officer
In accordance with Section 13 of the DPDPA, eSecurity has appointed the following Grievance Officer to address privacy-related concerns and grievances:
- Name: [Insert Grievance Officer Name]
- Designation: [Insert Designation]
- Email: privacy@esecurity.com
- Address: [Insert Registered Office Address]
We will acknowledge receipt of a grievance within 7 days and endeavour to resolve it within the timelines prescribed under applicable rules, currently proposed at 90 days under the draft DPDP Rules, 2025. If you are not satisfied with our resolution, you may escalate the grievance to the Data Protection Board of India.
13. Children's Data and Data of Persons with Disabilities
Our services are intended for businesses and professionals and are not directed at children. In accordance with Section 9 of the DPDPA, we do not knowingly collect or process the personal data of any child (an individual who has not completed the age of eighteen years) without verifiable consent of the child's parent or lawful guardian, and we do not process personal data of a person with a disability who has a lawful guardian without the consent of such guardian, where required.
We do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children.
If we identify that we have inadvertently collected such personal data without the requisite consent, it will be deleted promptly upon discovery.
14. Marketing Communications
Where you have opted in, we may send security advisories, product announcements, industry reports, research papers, webinar invitations, and event information.
You may unsubscribe at any time using the unsubscribe link in our communications or by contacting us using the details in Clause 16.
15. Third-Party Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of those websites independently.
16. Contact Us
For any questions regarding this Privacy Policy or your personal data, please contact:
- eSecurity
- Email: privacy@esecurity.com
- Website: www.esecurity.com
- Registered Office: [Insert Registered Office Address]
17. Changes to this Privacy Policy
We may revise this Privacy Policy periodically to reflect changes in our services, legal obligations, or business practices. The updated version will be published on this page together with a revised Effective Date and version number. Where changes are material, we will provide additional notice, such as by email or a prominent notice on our website, before the changes take effect.
18. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and any rules, regulations, or notifications issued thereunder. Any disputes arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts at the location of eSecurity's registered office.
Questions about your data?
Reach our privacy team at privacy@esecurity.com
