Privacy Policy

 

Privacy Policy

1. Introduction

TechnoPop Solutions Pvt Ltd (“TechnoPop,” “we,” “our,” “us”) values your trust. Protecting personal data is central to our mission of delivering compliance‑aligned cybersecurity and advisory services. This Privacy Policy explains how we collect, process, store, and safeguard personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), global standards such as ISO 27001/27701/42001, and sectoral mandates.


2. Scope & Applicability

This policy applies to:

  • Visitors to our website and digital platforms
  • Clients, partners, and stakeholders engaging with our services
  • Employees, contractors, and consultants handling personal data on behalf of TechnoPop

It covers all personal data processed digitally or physically, including structured and unstructured formats.


3. Categories of Data Collected

We may collect:

  • Identity Data: Name, email, phone number, organization, designation
  • Professional Data: Role, department, industry, compliance responsibilities
  • Technical Data: IP address, browser type, device identifiers, cookies
  • Service Data: Preferences, inquiries, feedback, usage logs
  • Compliance Data: Audit records, consent logs, regulatory documentation

Sensitive personal data (e.g., financial, health, biometric) is collected only when legally required or contractually mandated.


4. Purpose of Processing

We process personal data for:

  • Delivering cybersecurity, GRC, and advisory services
  • Managing client relationships and communications
  • Ensuring compliance with ISO, NIST, DPDPA, RBI, and sectoral mandates
  • Conducting audits, risk assessments, and governance reporting
  • Marketing, thought leadership, and event engagement (with explicit consent)
  • Incident response and breach notification obligations

5. Consent Management Framework

We adopt a structured Consent Management System aligned with DPDPA principles:

  • Explicit Consent: Users must provide clear, affirmative consent before data collection.
  • Granular Consent: Options to consent to specific categories (e.g., marketing vs. compliance).
  • Withdrawal of Consent: Users can withdraw consent anytime via our portal or by contacting us.
  • Audit Trails: All consent actions are logged, timestamped, and retained for regulatory audits.
  • Transparency: Consent notices are written in clear, accessible language.
  • Children’s Data: For minors, parental/guardian consent is mandatory.

6. Data Sharing & Disclosure

We may share personal data with:

  • Trusted Service Providers: Cloud hosting, compliance platforms, audit partners
  • Regulatory Authorities: When legally required under DPDPA or sectoral laws
  • Internal Teams: For advisory, SOC operations, and compliance delivery

We do not sell personal data. Sharing is strictly limited to lawful, contractual, or compliance purposes.


7. Data Retention & Lifecycle Management

  • Data is retained only as long as necessary for stated purposes or legal obligations.
  • Retention Policies: Defined per category (e.g., audit logs retained for 7 years).
  • Secure Disposal: Data is anonymized or securely deleted after expiry.
  • Lifecycle Controls: Automated systems ensure compliance with retention schedules.

8. Security Safeguards

We implement layered security aligned with ISO 27001 and SOC best practices:

  • Encryption (at rest and in transit)
  • Role‑based access controls
  • Continuous monitoring via SOC operations
  • Incident response protocols with breach notification timelines
  • LMNTRIX‑powered threat intelligence and deception capabilities

9. User Rights under DPDPA

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Rectify inaccurate or incomplete data
  • Deletion: Request erasure when data is no longer needed
  • Consent Withdrawal: Opt out of processing activities at any time
  • Grievance Redressal: File complaints with TechnoPop’s DPO or the Data Protection Board of India

10. International Data Transfers

Where data is transferred outside India, we ensure:

  • Adequacy decisions or contractual safeguards
  • Binding corporate rules for intra‑group transfers
  • Encryption and compliance with global standards (ISO, GDPR equivalence where applicable)

11. Updates to Policy

We may update this Privacy Policy to reflect changes in law, technology, or business practices. Updates will be communicated via our website and, where material, via direct notification.


12. Contact Information

For privacy concerns, consent withdrawal, or data rights requests, contact:

Data Protection Officer (DPO)
TechnoPop Solutions Pvt Ltd
Email: info@technopopsolutions.com

Subscribe Newsletter

Stay Updated with
the Latest News!