Privacy Policy
Last updated: July 2026
1. Introduction & Overview
Welcome to Verdant Cyberz LLP ("we," "us," or "our"). As a premier cybersecurity and compliance consulting firm, we understand that protecting personal data is paramount. This Privacy Policy outlines how we collect, use, process, and protect your personal data in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023 of India and other applicable international data protection frameworks.
2. Role of Verdant Cyberz
Depending on the context of our engagement, Verdant Cyberz may act as either a Data Fiduciary (when determining the purpose and means of processing your personal data, such as for our own marketing or client onboarding) or a Data Processor (when processing personal data strictly on behalf of and under the instructions of our clients during security audits, VAPT, or GRC engagements).
3. The Personal Data We Collect
We practice strict data minimization, collecting only the personal data necessary for our specified purposes. This may include:
- Identity & Contact Data: Names, business email addresses, phone numbers, and organizational roles collected via our contact forms.
- Technical Data: IP addresses, browser types, and usage data collected automatically when you browse our website.
- Client Engagement Data: Information strictly necessary for the execution of cybersecurity assessments, consulting, and forensic investigations.
4. Grounds for Processing (Lawful Basis)
Under the DPDP Act, we process your personal data primarily on the basis of Consent, which you explicitly provide when engaging our services or contacting us. In certain scenarios, we may process data based on Legitimate Uses, such as for compliance with Indian regulatory frameworks (CERT-In directives, RBI guidelines) or in response to a medical emergency or legal judgment.
5. Your Rights as a Data Principal
The DPDP Act grants you specific rights regarding your personal data. You have the right to:
- Access & Information: Request a summary of the personal data we process and the identities of any Data Fiduciaries with whom we have shared it.
- Correction & Erasure: Request correction of inaccurate data or the deletion of data when it is no longer necessary for the purpose it was collected.
- Grievance Redressal: Readily register grievances regarding our data processing practices.
- Nomination: Nominate an individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, please contact our designated Data Protection Officer/Consent Practitioner at info@verdantcyber.com.
6. Security Safeguards & Frameworks
We practice what we preach. Verdant Cyberz implements comprehensive, state-of-the-art security safeguards aligned with ISO 27001, CERT-In guidelines, and industry best practices. Our defense-in-depth approach ensures your data is protected against unauthorized access, accidental loss, or breach.
7. Personal Data Breach Notification
In the unlikely event of a personal data breach, we have established rapid incident response protocols. As mandated by the DPDP Act and CERT-In guidelines, we will notify the Data Protection Board of India and every affected Data Principal as required by law, without undue delay.
8. Data Retention & Cross-Border Transfers
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, or accounting requirements. Unless strictly necessary and legally permitted under the DPDP Act, we do not transfer personal data outside the borders of India.
9. Contact & Grievance Officer
If you have any questions, concerns, or grievances regarding this Privacy Policy or our data processing practices, please contact our Grievance Officer at:
Email: info@verdantcyber.com
Address: Delhi NCR, India