Privacy Policy
Governing personal and technical data under the Digital Personal Data Protection Act 2023 (India) and EU General Data Protection Regulation (GDPR).
1. Regulatory Framework & Corporate Status
BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED ("BhishmaSec", "Company", "we", "us", or "our") is a corporate cybersecurity architecture and offensive testing practice incorporated under the Indian Companies Act, 2013. This Privacy Policy sets out the principles and legal bases under which we collect, process, manage, and safeguard Personal Data in compliance with:
- The Digital Personal Data Protection Act, 2023 ("DPDP Act") of India;
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation / "GDPR") where applicable to international engagements.
2. Data Fiduciary vs. Data Processor Classification
In the execution of our corporate operations, BhishmaSec acts in dual statutory capacities:
- As a Data Fiduciary / Controller: In respect of business contact details, inquiry scoping forms, procurement correspondence, and billing records provided directly by prospective or contracted enterprise clients.
- As a Data Processor: In respect of any client application data, database records, source code, or network logs accessed strictly transiently and incidentally during the execution of contracted security architecture, DevSecOps pipelines, or offensive penetration tests.
3. Categories of Data Collected
We practice rigorous data minimization. We do not collect consumer behavioral dossiers or deploy invasive third-party ad trackers. We collect only:
- Inquiry & Scoping Records: Full name, corporate email address, employer entity name, designation, high-level technological architecture specifications, and budget ranges.
- Technical Security Telemetry: Target IP ranges, domain names, API schemas, and security vulnerability findings generated solely under contracted Statements of Work (SoWs).
- Essential Local Preferences: Consent status stored locally within browser
localStorage(e.g. cookie preference tokens).
4. Lawful Grounds for Processing
We process personal data solely on established lawful grounds:
- Consent & Voluntary Provision: Where an authorized representative submits an inquiry form seeking scoping advisory (DPDP Act Section 6; GDPR Article 6(1)(a)).
- Contractual Performance: Processing necessary for the execution of Master Services Agreements (MSAs), Statements of Work (SoWs), and bilateral NDAs (GDPR Article 6(1)(b)).
- Statutory & Legal Compliance: Compliance with mandatory tax laws, accounting standards, and statutory cybersecurity reporting obligations issued by the Indian Computer Emergency Response Team (CERT-In).
5. Technical Safeguards & Cryptographic Protocols
Pursuant to Section 8 of the DPDP Act and Article 32 of GDPR, BhishmaSec enforces institutional technical safeguards:
- In-Transit & At-Rest Encryption: All electronic communication is encrypted via TLS 1.3; all client reports and audit artifacts are encrypted using AES-256 GCM.
- Isolated Testing Enclaves: Security assessments are executed from hardened, access-restricted ephemeral VPCs with multi-factor authentication (FIDO2/WebAuthn).
- Cryptographic Data Sanitization: Upon conclusion of the contracted re-test window (30 days), all client proof-of-concept payloads and temporary test credentials are cryptographically purged (NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization).
6. Rights of Data Principals & Data Subjects
Under applicable data protection legislation, you are entitled to exercise the following statutory rights:
- Right to Confirmation & Access: Request a summary of personal data being processed by the Company.
- Right to Correction & Erasure: Request the correction of misleading or outdated data, or the deletion of data no longer required for statutory or contractual purposes.
- Right of Grievance Redressal: Submit inquiries or grievances to our nominated Data Protection Officer.
- Right to Nominate: (Under DPDP Act) Nominate an individual to exercise rights in the event of death or incapacity.
7. Data Protection Officer & Grievance Redressal
In accordance with the DPDP Act 2023, inquiries or complaints regarding the processing of your personal data should be addressed to our Data Protection Officer:
Data Protection Officer: Legal & Compliance Practice
Corporate Entity: BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED
Email: [email protected]
Jurisdiction: Tamil Nadu, India