Privacy Policy
Dataspace Security is a cybersecurity company, not a data business: we maintain no databases of personal information. This policy explains the little we do handle, why, and your rights under India's Digital Personal Data Protection Act, 2023.
01Introduction
Dataspace Security Private Limited (“Dataspace Security”, “we”, “us”, “our”) is a cybersecurity services provider offering Vulnerability Assessment and Penetration Testing (VAPT), Security Operations Center (SOC) deployment and monitoring, Governance, Risk and Compliance (GRC) advisory, and Digital Personal Data Protection (DPDP) Act compliance, implementation, and audit services.
This Privacy Policy explains how we handle personal data collected through our website, www.dataspacesecurity.com (“Website”), in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable Indian law.
We have designed our Website to be privacy-minimal by default. We do not collect any personal or sensitive personal data of individuals or organizations through our Website, other than the limited contact information described in Section 2 below.
02Personal Data We Collect
We do not store personal data.
Dataspace does not maintain any database, CRM, marketing list or profile store of personally identifiable information (PII). What little we handle is transient and purpose-bound:
- Contact and demo requests: the name, work email, organization and message you submit are delivered to our team to answer you — they are not written to any database of ours.
- Correspondence: emails you send us live in our ordinary business mailbox like any professional correspondence, and nowhere else.
- Analytics (optional, consent-only): anonymized usage statistics via Google Analytics 4 and Microsoft Clarity — loaded only if you accept them, held by those processors, never joined by us to any identity. See the Cookie Policy.
- Recruitment:CVs you send are reviewed and then deleted if we don't proceed.
We do not buy contact lists, build visitor profiles, or collect any personal data from browsing this site with analytics declined.
03How We Use Your Data
The name and email address you provide are used solely to:
- Respond to your inquiry or request;
- Communicate with you regarding our services (VAPT, SOC monitoring, GRC, and DPDP compliance, and related offerings);
- Maintain a record of business correspondence.
We do not use this information for automated decision-making, profiling, or targeted advertising.
04Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We do not share your name or email address with any third party, except:
- Where required by applicable law, regulation, or a valid order of a court or government authority; or
- With your explicit consent.
05Data Storage and Retention
5.1 Website Contact Data
The name and email address you submit through our Website are stored within our corporate email mailbox, which is protected using industry-standard technical and organizational security controls consistent with our own cybersecurity practice.
We retain this information only for as long as necessary to respond to your inquiry or to maintain business correspondence, unless a longer retention period is required for legal, regulatory, or legitimate business record-keeping purposes.
5.2 Client Engagement Data
This section applies to data generated during the course of a client engagement (VAPT, SOC monitoring, GRC, or DPDP compliance services), as distinct from the limited contact data described above:
- VAPT reports are retained in accordance with CERT-In empanelment norms and the retention timelines prescribed thereunder.
- Compliance and audit-related details (including working papers, gap assessment data, and other artefacts generated during a DPDP or GRC engagement) are deleted upon completion of the audit, except where retention of specific records is required by applicable law or contractual obligation.
06Your Rights
As a Data Principal under the DPDP Act, 2023, you have the right to:
- Access the data we hold about you;
- Request correction or updating of inaccurate or incomplete data;
- Request erasure of your personal data, where retention is no longer necessary;
- Withdraw consent at any time, where processing is based on consent;
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity;
- Raise a grievance regarding the handling of your personal data.
To exercise any of these rights, please contact us using the details in Section 9 below.
07Children's Data
Our Website and services are intended for business use and are not directed at children. We do not knowingly collect personal data from individuals under the age of 18.
08Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last Updated” date at the top of this page will indicate when changes were made. We encourage you to review this page periodically.
09Contact Us / Grievance Redressal
If you have any questions about this Privacy Policy, or wish to exercise your rights as a Data Principal, please contact:
Information Security Officer
Email: puja@dataspacesecurity.com
Phone: 8170845579
Dataspace Security Private Limited
Unit-701A, 7th Floor, Tower-II,
PS Srijan Corporate Park,
Salt Lake Sector-V, Kolkata-700091
This Privacy Policy is published in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules made thereunder.
