Privacy Policy
Dataspace Security is a cybersecurity company: we maintain privacy-minimal systems. This policy describes how 9147009931 and its affiliates collect, use, share, protect and process your personal data through https://www.dataspacesecurity.com and under India's DPDP Act, 2023.
01Introduction & Scope
This Privacy Policy describes how 9147009931 (Dataspace Security Private Limited, “Dataspace Security”, “we”, “our”, “us”) and its corporate affiliates collect, use, share, protect or otherwise process your information and personal data through our website https://www.dataspacesecurity.com (“Platform”).
Dataspace Security is a cybersecurity services provider offering Vulnerability Assessment and Penetration Testing (VAPT), Security Operations Center (SOC) deployment and monitoring, Governance, Risk and Compliance (GRC) advisory, and Digital Personal Data Protection (DPDP) Act compliance, implementation, and audit services.
Please note that you may browse certain sections of the Platform without registering. We do not offer any product/service under this Platform outside India, and your personal data will primarily be stored and processed in India.
By visiting this Platform, providing your information or availing any product/service offered on the Platform, you expressly agree to be bound by the terms and conditions of this Privacy Policy, the Terms of Use and applicable service terms, and agree to be governed by the laws of India including the Digital Personal Data Protection Act, 2023 (“DPDP Act”). If you do not agree, please do not use or access our Platform.
02Personal & Sensitive Data Collected
We collect your personal data when you use our Platform, services or otherwise interact with us during the course of our relationship:
- Registration & Contact Data: Name, date of birth, address, telephone/mobile number, work email ID, organization, and proof of identity or address provided during sign-up or contact requests.
- Sensitive Personal Data (Consent-Based): Bank account, credit/debit card, or payment instrument details, or biometric information (such as facial features or physiological information where specific features are opted for), collected in accordance with applicable law(s).
- Transient & Recruitment Data: CVs submitted for recruitment are reviewed and deleted if not proceeded with; business correspondence remains solely in our secure corporate mailbox.
- Aggregated & Transaction Data: Behavioural tracking, preferences, and transaction details on our Platform and third-party partner platforms.
03Usage of Personal Data
We use personal data to provide the services you request. To the extent we use your personal data to market to you, we provide the ability to opt-out.
We use your personal data to:
- Fulfill service requests (VAPT, SOC monitoring, GRC, DPDP compliance, and product orders);
- Assist sellers and business partners in handling and fulfilling orders;
- Enhance customer experience, troubleshoot technical issues, and resolve grievances;
- Inform you about online/offline offers, security updates, and service enhancements;
- Detect, prevent, and protect against error, fraud, cybersecurity incidents, and criminal activity;
- Enforce our Terms of Use and conduct analytical market research.
04Data Storage & Client Engagement Retention
4.1 Website & Platform Data Retention
We retain your personal data for no longer than is required for the purpose for which it was collected or as required under applicable Indian laws. Data may be retained to prevent fraud, resolve pending grievances, or in anonymized form for analytical research.
4.2 Client Engagement & Security Audit Data
Data generated during commercial client engagements (VAPT, SOC monitoring, GRC advisory, DPDP audits) is governed by specialized retention protocols:
- VAPT Reports: Retained strictly in accordance with CERT-In empanelment guidelines and mandatory regulatory retention timelines.
- Compliance & Audit Artefacts: Working papers, gap assessment findings, and technical evidence generated during DPDP or GRC audits are securely destroyed upon completion of the engagement, except where specific records must be retained by law or contract.
05Data Sharing & Disclosure
We do not sell or rent your personal data. We disclose personal data only to:
- Internal group entities, corporate affiliates, and business partners to provide unified services (with marketing opt-out);
- Third-party service providers, logistics partners, payment gateways, and prepaid payment instrument issuers necessary for transaction processing;
- Government agencies, law enforcement authorities, or courts when required by law, subpoena, or court order in good faith belief.
06Security Precautions & Infrastructure
To protect your personal data from unauthorized access, loss, or misuse, we adopt reasonable security practices and ISO/IEC 27001:2022 aligned technical controls. Account information is hosted on secure servers with encrypted transit.
However, transmission over the internet cannot be guaranteed as 100% secure. Users accept the inherent risks of online data transmission and remain responsible for protecting their account login credentials.
07Data Deletion & Account Closure
You have the option to delete your account through your profile settings or by writing to our team. Deletion results in loss of access to account data. We may delay or refuse deletion in events of pending grievances, active shipments, or legal retention mandates.
08Your Rights as a Data Principal (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, you hold the following statutory rights:
- Right to Access: Summary of personal data being processed and processing activities.
- Right to Correction & Erasure: Rectification of inaccurate or incomplete data and erasure of data no longer necessary.
- Right to Withdraw Consent: Withdraw consent at any time without retrospective effect.
- Right of Grievance Redressal: Access to a dedicated Grievance Officer for privacy concerns.
- Right to Nominate: Nominate another individual to exercise your rights in the event of death or incapacity.
09Consent & Opt-Out Procedure
By using our Platform, you consent to the collection, storage, and processing of your data as outlined. Providing third-party data represents that you possess explicit authority to do so.
You consent to receive communications via SMS, instant messaging apps, phone calls, and email from us and our technology/marketing partners.
To withdraw consent, write to our Grievance Officer with the exact subject line: “Withdrawal of consent for processing personal data”. Upon consent withdrawal, we reserve the right to limit or deny services requiring such data.
10Children's Privacy
Our Platform and cybersecurity offerings are intended exclusively for business and adult users. We do not knowingly collect personal data from individuals under 18 years of age.
11Changes to Policy
We periodically update this Privacy Policy to reflect evolving legal and operational practices. Significant changes will be notified as required by law.
12Grievance Redressal & Information Security Officer
For grievances, DPDP Data Principal rights requests, or privacy inquiries, please contact our Information Security & Grievance Officer:
Information Security Officer / Grievance Officer: Puja / Legal Officer
Company: Dataspace Security Private Limited (9147009931)
Registered Address: Unit-701A, 7th Floor, Tower-II, PS Srijan Corporate Park, Salt Lake Sector-V, Kolkata-700091
Email: puja@dataspacesecurity.com / grievance@dataspacesecurity.com
Phone: +91 8170845579 / +91 9147009931
Working Hours: Monday – Friday (9:00 – 18:00 IST)
