Privacy Policy

Last updated: July 2026

1. Introduction & Overview

Welcome to Verdant Cyberz LLP ("we," "us," or "our"). As a premier cybersecurity and compliance consulting firm, we understand that protecting personal data is paramount. This Privacy Policy outlines how we collect, use, process, and protect your personal data in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023 of India and other applicable international data protection frameworks.

2. Role of Verdant Cyberz

Depending on the context of our engagement, Verdant Cyberz may act as either a Data Fiduciary (when determining the purpose and means of processing your personal data, such as for our own marketing or client onboarding) or a Data Processor (when processing personal data strictly on behalf of and under the instructions of our clients during security audits, VAPT, or GRC engagements).

3. The Personal Data We Collect

We practice strict data minimization, collecting only the personal data necessary for our specified purposes. This may include:

4. Grounds for Processing (Lawful Basis)

Under the DPDP Act, we process your personal data primarily on the basis of Consent, which you explicitly provide when engaging our services or contacting us. In certain scenarios, we may process data based on Legitimate Uses, such as for compliance with Indian regulatory frameworks (CERT-In directives, RBI guidelines) or in response to a medical emergency or legal judgment.

5. Your Rights as a Data Principal

The DPDP Act grants you specific rights regarding your personal data. You have the right to:

To exercise any of these rights, please contact our designated Data Protection Officer/Consent Practitioner at info@verdantcyber.com.

6. Security Safeguards & Frameworks

We practice what we preach. Verdant Cyberz implements comprehensive, state-of-the-art security safeguards aligned with ISO 27001, CERT-In guidelines, and industry best practices. Our defense-in-depth approach ensures your data is protected against unauthorized access, accidental loss, or breach.

7. Personal Data Breach Notification

In the unlikely event of a personal data breach, we have established rapid incident response protocols. As mandated by the DPDP Act and CERT-In guidelines, we will notify the Data Protection Board of India and every affected Data Principal as required by law, without undue delay.

8. Data Retention & Cross-Border Transfers

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, or accounting requirements. Unless strictly necessary and legally permitted under the DPDP Act, we do not transfer personal data outside the borders of India.

9. Contact & Grievance Officer

If you have any questions, concerns, or grievances regarding this Privacy Policy or our data processing practices, please contact our Grievance Officer at:
Email: info@verdantcyber.com
Address: Delhi NCR, India