Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.

Legal

Privacy Notice

What happens to the personal data you share with SecureRoot through this website, the basis we hold it on, exactly how long we keep it, and what you can make us do about it.

Last Updated
1 September 2026 (version 2026-09-01)
Published By
SecureRoot Risk Advisory LLP, Kanpur, India
  • Your message is deleted after 6 months, the rest of your enquiry after 12
  • We rely on legitimate use and legitimate interests, not consent, so there is nothing to tick
  • No analytics, no advertising trackers, no profiling, no selling of personal data
  • Access, correction, erasure and objection, answered within 30 days

1.Who We Are and What This Notice Covers

SecureRoot Risk Advisory LLP is a cybersecurity consultancy registered in India. Our registered office is at Plot No. 110-A Gandhi Gram, Kanpur Nagar, Uttar Pradesh 208007, India. We also work from a branch office at 1027, Tower 3, Golden-I, Plot No. 11, Sector Tech Zone IV, Amrapali Leisure Valley, Greater Noida West, Uttar Pradesh 201318, India.

This notice explains what happens to personal data you share with us through this website, secureroot.co, and how you can exercise your rights over it. For that data we are the data fiduciary, or data controller, which means we decide why and how it is used.

If you are a client, the personal data we handle inside a paid engagement is governed by the agreement and confidentiality terms we sign with you, and by our role there as a processor acting on your instructions. This notice does not replace those terms.

Questions about anything below go to info@secureroot.co, with “Privacy” in the subject line.

2.Which Law Applies

We are an Indian firm, so the Digital Personal Data Protection Act, 2023 applies to what we do. That is the starting point and it shapes everything below.

This site is published in thirty languages, including every official language of the European Union, and it describes work that only European and British organisations need. We therefore treat the EU General Data Protection Regulation and the UK GDPR as applying to personal data we collect from readers in those places, and this notice is written to meet what they ask for. That is a decision to be careful rather than a legal finding, and we would rather state it plainly than argue about it.

Readers elsewhere: Switzerland’s revised Federal Act on Data Protection and Brazil’s LGPD reach us on similar reasoning, and Canada’s PIPEDA treats most of what this form collects as business contact information. The single set of practices described here is what we apply to everyone. We do not run a different standard per country, and we are not going to publish a section per statute to look thorough.

We do not say that we are “compliant” with any of these laws. Compliance is something a regulator decides, not something a firm declares about itself. What we can do is tell you exactly what we collect, why, for how long and what you can make us do about it, and let you check the answer against the site.

3.What We Collect

We collect what you give us, two values we work out from it, and the records our systems keep to stay online and secure. Nothing else.

The Consultation Form

The same form appears on the contact page, on the assessment request page, and in the dialog that opens from the header. It stores:

  • What you type. Your name, job title, work email address, phone number and its country dialling code, company name, location, the service and sub-service you select, and whatever you write in the message box. Your name, work email, phone number, service and message are required, and we cannot reply without them. Job title, company and location are optional, and the form works without them.
  • Two values we work out, and never ask for. Your company’s internet domain, taken from your email address, and your country, taken from the dialling code you chose. We say so on the form as well, because a field you cannot see is the one you have no way of finding out about.
  • The language of the page you submitted from, so we reply in it, and the version identifier of the privacy notice that was on screen at the time, so we can show later exactly what you were told.

Before your message is stored it is scanned for anything shaped like a password, an API key, a private key or a token, and any match is removed. We keep a count of how many were removed, so we can tell you to rotate them, and we never keep the matched text. That is a safety net rather than a licence. Please do not put credentials, client-confidential material or another person’s contact details in that box.

Correspondence

The emails, call notes and scoping documents that follow from your enquiry, kept so we can pick up where the conversation left off.

The Assistant on This Site

What you type into the assistant panel, and the recent turns of that conversation, are sent to our model provider so it can produce a reply. We store none of it. Section 6 sets out the whole of it, because it is the one place on this site where your words leave India.

Technical Records

Our hosting provider records standard server logs, which include the IP address making a request, the page requested, the time, and the browser and device type your software reports. These keep the site available and let us investigate abuse. We do not store the IP address of anyone who submits the consultation form against their enquiry record; the anti-abuse counter that limits repeated submissions keeps a one-way hash and nothing else.

Separately, our staff administration panel records sign-in attempts, including failed ones, with the IP address and browser string that made them. If you have never tried to sign in to it, there is nothing about you in there.

We do not ask for sensitive personal data through this website. Please do not send us identity documents, passwords, access credentials or client data by email or through the form. If an engagement needs that material, we will agree a secure channel for it first.

4.Cookies and Browser Storage

This website runs no advertising networks, no cross-site tracking, no profiling cookies and no analytics of any kind. There is no analytics script, no tag manager, no advertising pixel and no session recording. Our fonts are served from this site rather than fetched from another company, so reading a page here tells nobody but our own host that you did.

The complete list of what this site can put in your browser:

  • A language cookie named NEXT_LOCALE, holding nothing but a language code, so your choice of language survives. The switcher writes it when you pick a language, and the routing layer also refreshes it as you move between pages. Which of the two wrote it last decides how long it lasts: the switcher asks for a year, the routing layer for the length of your browser session.
  • Staff sign-in cookies for our administration panel, set only if you sign in to it. They expire after eight hours.

That is all of it. Nothing is written to your browser’s local storage. Because neither cookie is used for measurement, advertising or profiling, we do not put a consent banner in front of you to ask about them. If we ever add something that needs consent, we will ask before it runs, and we will update this section and the date at the top of the page first.

5.Why We Use It, and Our Legal Basis

Each use below is limited to the purpose you gave us the information for.

  • To reply to your enquiry, understand what you are trying to solve, and prepare a scope, timeline and quote.
  • To keep a record of the exchange, so a later question about what was asked and what we said has an answer.
  • To deliver and administer an engagement you have signed, including reporting, retesting and invoicing.
  • To keep this website available, diagnose faults and investigate misuse.
  • To meet legal, tax and record-keeping obligations that apply to us in India.

We do not use the details you send through this website to build marketing profiles, and we do not add you to a mailing list because you asked us a question. The consultation form records no marketing permission of any kind, because it asks for none. If we ever want to use your information for a different purpose, we will tell you what that purpose is and establish a proper basis for it before we start.

The Basis We Rely On

Under the DPDP Act we rely on the legitimate use in section 7(a). You gave us these details yourself, for the specified purpose of getting a reply, and you have not told us to stop.

For a reader in the European Union or the United Kingdom our basis is legitimate interests, Article 6(1)(f). The interest is a specific one and naming it is part of the obligation: answering enquiries about our services, working out whether we can help, and keeping a record of that exchange. We have weighed it against your interests. The balance is straightforward here, because you approached us, the information is ordinary business contact data, we do no profiling and make no automated decisions about you, the period we keep it for is short and published, and one email stops the whole thing.

This is not consent, and we do not ask you for any. There is no tick box on our form and there will not be one for the enquiry itself. That matters practically as well as legally. Because we are not relying on consent, there is no consent for you to withdraw, and the right that takes its place is the right to object. For a reader in the European Union or the United Kingdom that right is Article 21 of the GDPR and of the UK GDPR. The DPDP Act does not name a right to object at all; what does the same work there is the right to erasure in section 12, together with the fact that we hold nothing of yours on consent to begin with. Either way we treat it as a request we grant rather than one we weigh up, and section 10 says how to make it.

6.The Assistant on This Site

Some pages carry a chat assistant that answers questions about our services. It deserves its own section, because it is the one place on this site where what you write leaves India.

  • Where your question goes. Your message, and up to a dozen recent turns of the same conversation, are sent by our server to Google’s Gemini interface so a reply can be generated. Your browser never contacts Google directly, so Google receives no IP address, no cookie and no identifier from you. It receives the text.
  • What we keep. Nothing. No transcript, no message text and no question of yours reaches a log line, a database or a file belonging to us, and nothing is kept in your browser either, so closing the panel ends the conversation for good.
  • What Google does with it is governed by Google’s own terms for that interface, not by ours. We cannot make a promise on Google’s behalf and we are not going to pretend to. Treat anything you type there as having left our control.

Which is why the panel asks you to keep confidential detail out of it, and why we mean it. The assistant is for questions about what a piece of work covers. Anything about your own environment, an incident or a finding belongs in a call, and the scoping call costs nothing.

7.Who Else Sees It

We do not sell personal data and we do not trade it for services. Access inside SecureRoot is limited to the people who need it for your enquiry or engagement, and every read of an enquiry message is recorded against the person who read it.

These are the companies that handle it on our behalf. We name them rather than write “trusted partners”, because a category is not an answer:

  • Our website and database host. Runs this site and stores the enquiry records.
  • Microsoft. Business email through Microsoft 365, and document storage. When you submit the form, a notification carrying your contact details and a link to the record reaches our consultants this way. It does not carry the text of your message. Our mail settings have an option to attach the first line or two of it, and we keep that option switched off, so the message itself stays in the database behind the access controls in section 12.
  • Google. The assistant only, as described in section 6. Google receives nothing from the consultation form.

They act on our instructions and are bound by contract. We will disclose information to a court, regulator or law enforcement body only where a valid legal obligation requires it, and only to the extent required.

One thing we would rather tell you than have you find out. That notification email is a second copy of your contact details, sitting in a mailbox, and deleting the record in our database does not by itself delete the copy in the mailbox. Closing that gap properly is work we have identified and not yet finished. Until it is, if you ask us to erase your enquiry we clear the mailbox copy by hand as part of answering you.

8.Where Your Data Is Held and Sent

SecureRoot works from India, so we read and act on your enquiry in India. The website, the database and the mailbox are operated for us by the providers named in section 7, on infrastructure that may sit outside India and outside your own country.

If you are in the European Union, the United Kingdom or Switzerland, the plain position is this. India has no adequacy decision from the European Commission, no adequacy regulations from the United Kingdom, and no equivalent recognition from Switzerland. We do not claim otherwise, and anyone in our line of work who does is worth a second look. Where those laws apply, our disclosures to the providers above rest on the standard contractual clauses in their data processing terms, with the UK addendum where the UK GDPR applies.

Write to info@secureroot.co and ask which countries your enquiry record is held in, or for a copy of the safeguards we rely on, and we will answer with the actual list rather than a category.

9.How Long We Keep It

These are periods our systems enforce, not intentions. Every enquiry carries its own two deletion deadlines, written onto the record the moment you submit it, and a scheduled job deletes what has passed them.

  • What you wrote in the message box: 6 months from the day you send it. It is then permanently removed, while the rest of the enquiry stays for a while longer. That box is the field most likely to hold something we have no purpose for, which is why it has the shorter clock.
  • The rest of your enquiry: 12 months from the day you send it. The whole record is then deleted outright. Not flagged as deleted, not archived. Deleted.
  • Enquiries that become engagements leave this schedule, because the record then sits under a signed contract and under the tax and record-keeping obligations that come with it. Those periods are set by the engagement agreement and by Indian law, not by this page.

Both clocks run from the day you submit the form, not from our last exchange with you. That is a deliberate choice and it is what the code does, so it is what this page says.

Server logs are kept for a short operational period by our host and then rotated out. For the sign-in records from our staff administration panel we have not yet set a fixed deletion period, and we would rather say that here than publish a number we do not enforce. The same is true of the anti-abuse counter described in section 3: it holds one-way hashes rather than addresses, and nothing deletes those rows on a schedule yet.

Backups are the honest caveat on all of it. Deleting a record removes it from the live system straight away, and a copy can survive in our host’s routine backups until those rotate. Backups are used to restore a failure, never to bring a deleted record back into use.

You can ask us to delete your data sooner, and section 10 says how. Where nothing obliges us to keep it, we will.

10.Your Rights, and How to Use Them

One address does all of this: info@secureroot.co, with “Privacy” in the subject line.

Quote the email address you used on the form. That is the detail we look your record up by, it has to match exactly, and telling you now saves a round trip. We will not demand identity documents for a request about a form submission. A reply from the address that submitted it is normally enough.

What You Can Ask For

  • A copy. Everything we hold about you from this website, what we are doing with it, and who it has reached.
  • A correction. Anything inaccurate put right, and anything incomplete or out of date completed or updated.
  • Erasure. Deletion of your enquiry. Where no law requires us to keep it, this is a request we grant rather than one we weigh up.
  • That we stop. Tell us to stop using your details and we will, and we will delete the enquiry unless something obliges us to keep it. This is the right to object, and because we rely on legitimate use and legitimate interests rather than consent, it is the right that matters most here.
  • To complain. Section 11.
  • To nominate someone. The DPDP Act lets you nominate another person to exercise these rights on your behalf if you die or lose capacity. Write to us and we will record it. We handle this by hand and there is no form for it.

Restriction, and What We Can Actually Do

If you are in the European Union or the United Kingdom, Article 18 gives you the right to have us hold a record still rather than delete it while a dispute about it is resolved. We will do that, and we will do it by hand: there is no control in our systems that marks a record as held, and the scheduled deletion job described in section 9 does not know about holds either. So if you ask for one, say so plainly, and we will confirm in writing what we have done and take the record out of the ordinary schedule ourselves. Building the control is on our list and it is not built.

Two Things We Will Not Pretend to Offer

Data portability does not apply here. Under the GDPR that right attaches to processing based on consent or on a contract, and ours is based on legitimate interests, so it is not engaged. We would rather tell you that than list a right we do not owe you and quietly not build it. If you simply want your data in a file, ask for a copy above and we will send you one.

There is no automated decision-making and no profiling. Nothing on this site scores you, ranks you, or decides anything about you without a person involved. If that ever changes, this sentence changes with it.

How Long We Take

We will acknowledge your request and answer it within 30 days. If one is unusually complicated and we need longer, we will tell you inside those 30 days, say why, and give you a date. There is no charge. Where we cannot do what you have asked, we will tell you why and where you can take it next.

11.Complaints

If something we have done with your personal data is wrong, tell us first. Write to info@secureroot.co with “Privacy” in the subject line. We will acknowledge it within 30 days, look into it properly, and write back with what we found and what we have changed. This route is open to everyone, wherever you are.

If our answer does not satisfy you, you can take it further, and you do not need our agreement to do so.

  • In India, to the Data Protection Board of India.
  • In the European Union, to the data protection supervisory authority in the country where you live or work.
  • In the United Kingdom, to the Information Commissioner's Office.
  • Elsewhere, to the data protection regulator in your own country.

12.How We Protect Information

Security is the work we do for clients, so we hold ourselves to the practices we recommend. Data in transit to this website is encrypted. Enquiry records sit behind role-based access control, so most of our own people cannot open the message you wrote at all. Reaching one needs multi-factor authentication. Deleting one is refused unless the person signed in within the last ten minutes, so a session left open on a desk cannot destroy a record. Every read of a message, every correction, every export and every deletion is written to an audit trail against the person who did it.

We are not going to describe any of that as bank-grade or enterprise-grade, and we hold no certification for the systems behind this website. What is written above is what is actually built, and it is checkable.

No system is beyond risk and we will not claim otherwise. If a breach affects your personal data we will assess it, act on it, and notify you and the Data Protection Board of India as the DPDP Act requires, along with any other regulator entitled to hear about it.

13.Children

This website and our services are directed at organisations and the people who work in them, not at children. We do not knowingly collect personal data of anyone under 18. If you believe a child has sent us personal data, write to info@secureroot.co and we will delete it.

14.The Language of This Notice

This page is published in English. The shorter notice on the consultation form itself, which tells you who receives your details, why, on what basis, for how long, and how to stop us, is the one in front of you at the moment you decide whether to submit. It is published in English, German, French, Spanish, Italian, Dutch, Portuguese, Polish, Arabic, Chinese, Russian, and Hindi.

This site routes 30 languages. In the other 18, most of which are official languages of the European Union, that form notice is shown to you in English, because we have not yet translated it into them. So is the rest of the page you are reading it on. We would rather tell you that here than let you meet it on the form, and a translation of the notice is the work this paragraph exists to make visible until it is done.

Write to us in any language this site is published in. We will answer a rights request or a complaint in the language you sent it in, and the 30 days in section 10 include the time that takes.

15.Changes to This Notice

We update this notice when our practices or the law change. The date and version at the top of the page identify the current text. Where a change materially affects how we use data you have already given us, we will contact you rather than rely on you noticing the update.

The shorter notice on the form carries its own version identifier, and the one in use today is 2026-09-01.3. Every enquiry we store records which version was on screen when it was sent, and we keep the exact wording of each version, in each language, so that a question about what you were told has a precise answer rather than a reconstruction. Enquiries submitted before 1 September 2026 were made when no such notice existed, and they record that honestly instead of being backdated to one.

16.Contact and Grievances

Write to info@secureroot.co for any question, request or complaint about this notice or about how we have handled your personal data. Please put “Privacy” in the subject line. That mailbox is our privacy contact and it is monitored.

SecureRoot Risk Advisory LLP
Plot No. 110-A Gandhi Gram,
Kanpur Nagar, Uttar Pradesh 208007,
India

You can also reach us through the contact page. Our terms of use are set out here.