Legal & Policies
Grey Shield cybersecurity firm. Effective date: 1 January 2025.
On this page
Privacy Policy
Last updated: January 2025This Privacy Policy explains how Grey Shield ("we", "us") collects, uses, discloses, and protects personal data when you visit greyshield.in (the "Site"), submit a contact or engagement enquiry, or otherwise interact with us. It does not cover data processed on behalf of clients during a security Engagement — that is governed by the relevant Statement of Work and Master Services Agreement.
1. Who We Are
Grey Shield is a cybersecurity firm based in Haryana, India, offering penetration testing, vulnerability assessment, and security advisory services. For the purposes of applicable data protection law, Grey Shield is the data fiduciary/controller for personal data collected through this Site.
2. Data We Collect
- Contact & enquiry data — name, email address, company, and message content when you email us or submit a form (e.g. a vulnerability report or engagement enquiry);
- Technical data — IP address, browser type, device information, and pages visited, collected automatically via server logs and analytics;
- Cookie data — as described in Section 4 below.
We do not knowingly collect sensitive personal data (such as financial, health, or biometric information) through the Site.
3. How We Use It
- To respond to enquiries, quote requests, and vulnerability reports;
- To operate, secure, and improve the Site;
- To understand aggregate traffic and usage patterns;
- To comply with legal obligations, and to establish, exercise, or defend legal claims.
We do not sell personal data, and we do not use data collected through the Site for unrelated marketing without your consent.
4. Cookies & Analytics
The Site may use strictly necessary cookies (to keep the Site functioning) and analytics cookies (to understand how visitors use the Site). Where analytics or non-essential cookies are used, you'll be asked for consent via a cookie banner where required by law, and you can withdraw that consent at any time through your browser settings or the banner controls.
5. Sharing & Disclosure
We may share personal data with:
- Service providers who help us run the Site (e.g. hosting, email, analytics), under confidentiality obligations;
- Professional advisers (legal, accounting) where necessary;
- Law enforcement or regulators, where required by law or a valid legal process.
We do not share personal data with third parties for their own independent marketing purposes.
6. Retention
We retain personal data only as long as necessary for the purposes described in this policy, or as required by applicable law (for example, contract and tax record-keeping requirements). Enquiry and correspondence data is typically retained for as long as needed to resolve the matter and for a reasonable period afterward, then deleted or anonymised.
7. Security
As a security company, we take the protection of personal data seriously. We apply technical and organisational measures — including access controls, encryption in transit, and regular review of our own infrastructure — appropriate to the sensitivity of the data involved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Subject to applicable law — including India's Digital Personal Data Protection Act, 2023 where it applies to you — you may have the right to:
- Request access to, and a copy of, the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data, where applicable;
- Withdraw previously given consent (e.g. for cookies), without affecting processing carried out before withdrawal;
- Nominate another individual to exercise your rights in the event of death or incapacity, where applicable;
- Lodge a grievance with us, and where unresolved, with the applicable data protection authority.
To exercise any of these rights, contact our Grievance Officer using the details in Section 12.
9. International Transfers
Some of our service providers (such as hosting or analytics platforms) may process data outside India. Where this happens, we take reasonable steps to ensure an adequate level of protection, consistent with applicable law.
10. Children's Privacy
The Site is intended for business and professional use and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be reflected in the "Last updated" date above, and where required by law, we will provide additional notice.
12. Grievance Officer & Contact
Grievance Officer
For requests relating to your personal data, or complaints under applicable data protection law: