Legal
Privacy Policy
How Ownzap Infosec collects, uses, discloses, retains, and protects personal information when you visit or interact with our website.
Ownzap Infosec (“Ownzap Infosec”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit or interact with the Ownzap Infosec website, submit an enquiry, request information about our services, communicate with us, or otherwise use our website and related services.
We seek to process personal information in accordance with applicable data protection and privacy laws and recognized information-security practices, including, where applicable, the Digital Personal Data Protection Act, 2023 (DPDP Act), the General Data Protection Regulation (GDPR), applicable provisions of the Information Technology Act, 2000, and applicable contractual, regulatory, and information-security requirements.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal information collected through:
- Our website and web forms.
- Contact and enquiry forms.
- Requests for information about our products or services.
- Business communications with Ownzap Infosec.
- Other online interactions through which you voluntarily provide personal information to us.
This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from our website. Such third parties are responsible for their own privacy practices.
2. Personal Information We Collect
Depending on how you interact with our website, we may collect the following personal information:
- Full Name
- Email Address
- Phone Number
- Organization Name
We may also collect information that you voluntarily provide in an enquiry, communication, service request, or other interaction with us.
We follow the principle of data minimization and seek to collect only information that is reasonably necessary for the relevant purpose.
We do not intentionally request or collect sensitive personal information through our general website contact forms unless specifically required for a legitimate and lawful purpose.
3. Information Collected Automatically
When you access our website, certain technical information may be collected automatically by our website infrastructure, hosting provider, security systems, or analytics technologies.
Depending on the configuration of our website, this may include:
- IP address.
- Browser and device type.
- Operating system.
- Date and time of access.
- Pages visited.
- Referring website or source.
- Basic website usage and diagnostic information.
- Security and technical logs.
This information may be used for website security, troubleshooting, performance monitoring, analytics, fraud prevention, and improving the website.
Where required by applicable law, we will obtain appropriate consent before using non-essential cookies or similar tracking technologies.
4. Purpose of Processing
We may process personal information for the following purposes:
- To respond to enquiries and requests.
- To communicate with you regarding our products and services.
- To understand your requirements and provide appropriate information.
- To provide and manage services requested by you or your organization.
- To maintain business and professional communications.
- To improve our website, services, security, and user experience.
- To prevent, detect, investigate, and respond to security incidents, fraud, misuse, or unauthorized activity.
- To maintain appropriate business, administrative, contractual, audit, and compliance records.
- To comply with applicable legal, regulatory, or contractual obligations.
- To establish, exercise, or defend legal claims where necessary.
We will not use personal information for purposes that are incompatible with the purpose for which it was collected unless permitted or required by applicable law or appropriately notified to you.
5. Lawful Basis for Processing
Depending on the applicable law and the circumstances, we may process personal information on one or more of the following bases:
- Your consent.
- Performance of a contract or steps taken at your request before entering into a contract.
- Compliance with a legal or regulatory obligation.
- Our legitimate interests, where permitted by applicable law and where those interests are not overridden by your rights and interests.
- Other lawful grounds permitted under applicable legislation.
Where processing is based on consent, you may withdraw your consent at any time, subject to applicable legal or contractual limitations.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
For processing governed by the DPDP Act, personal data will be processed in accordance with the lawful grounds and requirements applicable to the relevant processing activity.
6. Transparency and Data Minimization
We aim to ensure that personal information is:
- Processed lawfully, fairly, and transparently.
- Collected for specified and legitimate purposes.
- Limited to information reasonably necessary for those purposes.
- Accurate and kept up to date where necessary.
- Retained only for an appropriate period.
- Protected using appropriate security measures.
These principles are intended to support our privacy and information-security obligations under applicable laws and recognized security frameworks.
7. Sharing of Personal Information
We do not sell, rent, or trade your personal information for third-party marketing purposes.
We may disclose personal information where reasonably necessary to:
- Authorized employees and personnel of Ownzap Infosec.
- Hosting, cloud, IT, security, communications, CRM, analytics, and other technology service providers that support our business.
- Professional advisers, auditors, insurers, or legal advisers.
- Business partners or service providers where necessary to provide a service requested by you.
- Government, regulatory, law-enforcement, or judicial authorities where disclosure is required or permitted by law.
- Other parties where disclosure is necessary to protect our rights, property, security, users, or the public.
Where third parties process personal information on our behalf, we seek to implement appropriate contractual, confidentiality, security, and data-protection requirements.
8. International Data Transfers
Some of our service providers, technology providers, or business partners may process or store personal information outside your country or jurisdiction.
Where personal information is transferred internationally, we will take appropriate measures required by applicable law to protect the information and ensure that the transfer is subject to appropriate safeguards.
For individuals whose personal information is subject to the GDPR, international transfers will be carried out using an applicable transfer mechanism or safeguard recognized under the GDPR, where required.
9. Data Retention
We retain personal information only for as long as reasonably necessary to:
- Fulfill the purposes for which it was collected.
- Provide requested services or communications.
- Maintain legitimate business records.
- Meet contractual requirements.
- Comply with legal, regulatory, audit, or reporting obligations.
- Establish, exercise, or defend legal claims.
- Maintain appropriate security and operational records.
Retention periods may therefore vary depending on the type of information and the purpose for which it is processed.
When personal information is no longer required, we will take reasonable steps to securely delete, destroy, anonymize, or otherwise dispose of it in accordance with applicable requirements and our retention procedures.
10. Information Security
Ownzap Infosec maintains appropriate technical, administrative, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, destruction, misuse, or other unlawful processing.
Depending on the nature and risk of the processing, security measures may include:
- Access control and least-privilege principles.
- Authentication and authorization controls.
- Encryption of information in transit and, where appropriate, at rest.
- Secure hosting and infrastructure controls.
- Network and endpoint security controls.
- Vulnerability management and security monitoring.
- Logging and monitoring.
- Backup and recovery controls.
- Security incident management procedures.
- Employee confidentiality and security awareness measures.
- Vendor and third-party security assessments.
- Periodic review and improvement of security controls.
Our information-security practices are designed to support applicable legal requirements and recognized information-security principles, including controls maintained within our information security management framework, where applicable.
11. Cookies and Similar Technologies
Our website may use cookies and similar technologies for:
- Essential website functionality.
- Session management.
- Security.
- Performance and reliability.
- Website analytics.
- Improving user experience.
Non-essential cookies or tracking technologies will be used in accordance with applicable law and, where required, subject to your consent.
You may control or disable cookies through your browser settings. Disabling certain cookies may affect some website functionality.
12. Your Privacy Rights
Depending on your location and applicable law, you may have certain rights concerning your personal information.
These may include the right to:
- Request access to personal information held about you.
- Request correction of inaccurate or incomplete information.
- Request deletion or erasure of personal information where legally applicable.
- Request restriction of processing where applicable.
- Object to certain processing activities.
- Withdraw consent where processing is based on consent.
- Request portability of personal information where applicable.
- Raise a complaint regarding our processing of your personal information.
- Request information about how your personal information is processed.
Under applicable Indian data-protection law, including the DPDP Act, individuals may have rights and grievance mechanisms as provided under the applicable legislation and rules.
For individuals subject to the GDPR, applicable GDPR rights will be provided subject to the conditions and limitations set out in the GDPR.
13. Exercising Your Rights
To submit a privacy request, correction request, deletion request, consent withdrawal, or privacy-related complaint, please contact us using the details provided below.
We may need to verify your identity before processing certain requests to prevent unauthorized access to personal information.
We will respond to valid requests within the timeframe required by applicable law.
14. Privacy and Security by Design
Where appropriate and proportionate to the nature and risks of processing, we seek to incorporate privacy and security considerations into the design and operation of our systems, services, processes, and website.
This includes applying principles such as data minimization, access control, appropriate security safeguards, retention controls, and privacy-aware system design.
15. Personal Data Breaches and Security Incidents
We maintain processes for identifying, assessing, responding to, and managing information-security incidents and personal data breaches.
Where notification is required by applicable law or regulation, we will make the required notifications to relevant authorities and/or affected individuals within the applicable statutory or regulatory timelines.
16. Children’s Privacy
Our website and services are intended primarily for business, professional, and general audiences.
We do not knowingly solicit personal information from children in circumstances where such collection is prohibited by applicable law.
Where applicable law establishes specific requirements for processing children’s personal information, we will follow those requirements.
17. Third-Party Websites and Services
Our website may contain links to third-party websites, applications, platforms, or services.
We are not responsible for the privacy practices, security, or content of third-party websites.
We encourage you to review the applicable privacy policies and terms of third-party services before providing personal information to them.
18. Complaints and Grievances
If you have a question, concern, or complaint regarding the processing of your personal information, please contact us first using the contact information below.
We will investigate and address privacy-related complaints in accordance with our internal procedures and applicable legal requirements.
Where applicable law provides a right to lodge a complaint with a regulatory or supervisory authority, you may exercise that right.
19. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our business practices, technology, services, legal requirements, regulatory requirements, or security practices.
The updated Privacy Policy will be published on this page with a revised “Last Updated” date.
We encourage you to review this Privacy Policy periodically.
20. Contact Information
For privacy-related questions, requests, or complaints, please contact:
Where required by applicable law, additional information regarding our Data Protection Officer, privacy representative, or grievance officer will be provided through the appropriate communication channel.
21. Applicable Privacy and Security Frameworks
Ownzap Infosec seeks to maintain privacy and information-security practices appropriate to the nature, scope, and risks of the information we process.
Depending on the applicable processing activity, jurisdiction, and service environment, our practices may take into consideration:
- Digital Personal Data Protection Act, 2023 (India).
- Applicable rules and regulations issued under Indian data-protection law.
- General Data Protection Regulation (EU) 2016/679, where applicable.
- Information Technology Act, 2000 and applicable rules.
- ISO/IEC 27001 information-security management principles and applicable controls.
- Other applicable contractual, regulatory, and industry requirements.
Nothing in this Privacy Policy should be interpreted as a representation that Ownzap Infosec is certified under a particular standard or regulation unless such certification is expressly stated and supported by a valid certification or assessment.
Last Updated: