Skip to content

Legal

DPDP notice

This notice is given under Section 5 of the Digital Personal Data Protection Act, 2023, and sets out how KalkiShield handles personal data as a Data Fiduciary.

Who the Data Fiduciary is

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Contact: privacy@kalkishield.com.

Personal data processed, and for what purpose

Through this website:

  • Name — to address you correctly in our reply.
  • Work email address — to reply to your enquiry.
  • Company name, if you provide it — to scope the work accurately.
  • The content of your message — to understand what you need.

The purpose is limited to responding to your enquiry and, if you proceed, delivering the engagement. We process no personal data for any other purpose without asking you first.

Consent, and withdrawing it

Processing is based on the consent you give at the point of collection. The notice text shown to you and the time of your agreement are recorded with your enquiry, so both of us have a record of what was actually agreed.

To withdraw consent, email privacy@kalkishield.com. We will stop processing and delete your data unless we are required by law to retain it. Withdrawal does not affect processing that already lawfully took place.

Your rights as a Data Principal

  1. Right to access — a summary of the personal data we hold about you and how it is being processed.
  2. Right to correction and erasure — to have inaccurate data corrected, incomplete data completed, and data erased where it is no longer needed.
  3. Right to grievance redressal — to complain to us and receive a response, before approaching the Board.
  4. Right of nomination — to nominate another person to exercise these rights on your behalf in the event of your death or incapacity.

You also have duties under Section 15 of the Act, including not impersonating another person and not filing false or frivolous complaints.

Personal data encountered during security testing

This section matters more than the rest, because of what we do. Security testing can expose us to personal data held in a client system — user records, logs, uploaded documents. Our standing rules are:

  • We access personal data only to the minimum extent needed to demonstrate a finding, and never at scale.
  • Evidence in reports is redacted or synthesised. We do not reproduce real personal data in a deliverable.
  • Anything encountered is stored encrypted, is never removed from controlled systems, and is destroyed on the schedule agreed in the engagement contract.
  • Where testing reveals a personal data breach, we tell the client immediately so that they can meet their own obligation to notify the Data Protection Board and affected Data Principals. That notification is the client’s to make, as the Data Fiduciary for that data.

Retention

Enquiry data is erased 24 months after collection. Engagement records are retained for the period set out in the relevant contract, and erased at the end of it.

Grievance redressal

If you are unhappy with how we have handled your personal data, contact our Grievance Officer, [GRIEVANCE OFFICER NAME], at privacy@kalkishield.com. We will acknowledge within 7 days and respond substantively within 30 days.

If you remain dissatisfied, you may complain to the Data Protection Board of India in accordance with the Act.