Skip to main content

PRIVACY NOTICE
Last Updated: 13-03-2026
Compliance: Digital Personal Data Protection Act, 2023 (DPDP Act) | DPDP Rules, 2025


1. WHO WE ARE (Data Fiduciary)

  • Organisation: Codesecure Solutions
  • GSTIN: 33BKWPN0209F1Z8
  • Registered Address: Ground Floor, 159, K.P.Tower, Arcot Road, Vadapalani, Chennai, Tamil Nadu 600026
  • Grievance Officer: Naveenkumar TG
  • Email: contact@codesecure.in
  • Phone: +91-7358463582

2. WHAT PERSONAL DATA WE COLLECT (Rule 3(b)(i))

2.1 Client Contact Data (B2B):

  • Name of contact person
  • Business email address
  • Business phone number
  • Company name and designation
  • GST number (for invoicing purposes)

2.2 Employee Data:

  • Full name, date of birth
  • Email, phone, residential address
  • Aadhaar (statutory compliance), PAN (tax), bank details (salary processing)

2.3 Website Visitor Data:

  • IP address (anonymised)
  • Browser type and version
  • Pages visited and session duration
  • Cookies (Google Analytics) ONLY with your explicit consent

2.4 Client Engagement Data (Temporary):

  • Target system IP addresses or URLs provided by the client
  • Vulnerability scan outputs
  • Security assessment reports

Note: This data is deleted immediately after report delivery.

3. WHY WE PROCESS YOUR DATA (Rule 3(b)(ii))

  • Client data: Delivering cybersecurity audit services including VAPT, network security, cloud security, source code review and compliance audits
  • Employee data: Employment management and salary processing
  • Website analytics: Understanding website traffic patterns (with your consent only)
  • Client engagement data: Executing contracted security assessments

4. LEGAL BASIS FOR PROCESSING

  • Consent (Section 6): Website analytics cookies and marketing communications
  • Legitimate Use (Section 7): Employment purposes, contractual obligations and legal or statutory requirements

5. HOW WE PROTECT YOUR DATA (Section 8(4), Rule 6)

  • Disk encryption (BitLocker) on all workstations
  • Multi-factor authentication enabled on all cloud accounts
  • TLS encryption for all data communications
  • Access restricted to authorised personnel only
  • Client VAPT data deleted after report delivery

6. WHO WE SHARE YOUR DATA WITH (Data Processors)

We share data with the following categories of service providers for business operations:

  • Business communication platform (cloud-based)
  • Financial operations platform (cloud-based)
  • Service delivery platform (cloud-based)
  • Digital performance platform (cloud-based)
  • Infrastructure and delivery platform (cloud-based)
  • Workforce collaboration platform (cloud-based)

Note: Specific processor identities are disclosed upon a Data Subject Access Request per Section 11 of the DPDP Act.

7. DATA RETENTION (Section 8(7), Rule 8)

  • Client contact data: Contract period plus 3 years
  • Employee data: Employment period plus 7 years (statutory requirement)
  • Website analytics: 26 months
  • Client VAPT scan and report data: Deleted immediately after delivery
  • Invoice and tax records: 7 years (GST Act and IT Act requirement)

8. YOUR RIGHTS AS A DATA PRINCIPAL (Sections 11-14)

Under the DPDP Act, you have the right to:

  • Access (Section 11): Request a summary of your personal data we process
  • Correction and Erasure (Section 12): Request correction of inaccurate data or deletion of your data
  • Grievance Redressal (Section 13): File a complaint with us, resolved within 90 days
  • Nomination (Section 14): Nominate someone to exercise your rights on your behalf

9. HOW TO EXERCISE YOUR RIGHTS (Rule 14)

  • Email: contact@codesecure.in (Subject: "DPDP Rights Request")
  • Phone: +91-7358463582
  • Address: Privacy Lead, Codesecure Solutions, Ground Floor, 159, K.P.Tower, Arcot Road, Vadapalani, Chennai 600026

Please provide your name and email address as registered with us. Response time: within 90 days (Rule 14(3)).

10. CONSENT WITHDRAWAL (Rule 3(c)(i))

You may withdraw your consent at any time:

  • Email contact@codesecure.in with subject "Consent Withdrawal"
  • Call +91-7358463582
  • For analytics cookies: Click "Cookie Settings" in the website footer

Withdrawal of consent is as easy as giving consent (Section 6(4) of the DPDP Act).

11. COMPLAINT TO DATA PROTECTION BOARD (Rule 3(c)(iii))

If you are not satisfied with our response to your grievance, you may file a complaint with the Data Protection Board of India after exhausting our internal grievance mechanism (Section 13 of the DPDP Act).

12. CHILDREN'S DATA (Section 9)

Our services are B2B only and not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If discovered, it will be deleted immediately.

13. CROSS-BORDER DATA TRANSFER (Section 16)

We do not intentionally transfer personal data outside India. Some cloud service providers we use may have servers located outside India.

14. CHANGES TO THIS NOTICE

Updates to this Privacy Notice will be communicated via email to registered contacts. The latest version is always available at https://codesecure.in/privacy-policy.html.

15. THIRD-PARTY WIDGETS ON THIS WEBSITE

This website uses the following third-party services:

  • Google Analytics: Analytics cookies loaded only with your explicit consent
  • Collect.chat: Chat widget that may collect name and email you voluntarily provide
  • WhatsApp Widget: Redirects to WhatsApp and does not store data on our servers

16. NEWSLETTER SUBSCRIPTION

If you subscribe to our newsletter, your email address is collected with your explicit consent and used solely to send cybersecurity updates. You may unsubscribe at any time by emailing contact@codesecure.in.


Is your organization secure? We work 24x7 to secure

We work around the clock to ensure your digital safety with proactive, cutting-edge solutions and expert support