Effective Date: April 2026
1. Introduction CyberPulse Data Security (“we,” “us,” or “our”) is committed to protecting the privacy and security of our clients’ data. This Privacy Policy outlines how we collect, use, safeguard, and disclose information when you visit our website, engage our Managed IT Services, access our Security Awareness Training (SAT) platforms , or when we manage your data within vendor-provided multi-tenant management portals. For personal information collected directly through our website, marketing activities, and business operations, CyberPulse Data Security acts as the Data Fiduciary. When providing managed security, IT, monitoring, or advisory services involving Client Data, CyberPulse Data Security acts as a Data Processor on behalf of the Client, who remains the Data Fiduciary.
2. Information We Collect Given the nature of our business-focused cybersecurity and IT management services, we collect specific categories of information to ensure optimal service delivery:
• Account & Business Information: Company name, GSTIN, primary contact details, billing addresses, and payment processing information necessary for service agreements.
• Service & Infrastructure Data: Network topology, IP addresses, system logs, and endpoint device metrics required for our managed threat monitoring and IT support services.
• Vendor Platform Data (Multi-Tenant): End-user (employee) names, corporate email addresses, and performance metrics generated within vendor-provided multi-tenant management portals.
• Security Awareness Training (SAT) Platform Data: End-user names, corporate email addresses, platform account identifiers, training progress, quiz scores, phishing simulation interactions, completion records, and compliance tracking metrics generated when utilizing our Security Awareness Training platforms.
• Website Data: Information submitted via our consultation forms, as well as standard analytical data (cookies, browser type, and usage metrics) to improve our website experience. We use cookies and similar technologies to enhance website functionality, analyse traffic, improve user experience, and maintain website security. Users may control cookie preferences through their browser settings.
3. How We Use Your Information We utilize the collected information strictly for business and operational purposes, including:
• Provisioning, managing, and securing your dedicated tenant environment within vendor-provided multi-tenant management portals.
• Executing managed IT support, software licensing deployments, and real-time network monitoring.
• Hosting interactive educational modules, tracking user compliance, and generating organizational risk reports through our proprietary Security Awareness Training platforms.
• Processing billing and fulfilling contractual obligations.
• We process some data to comply with legal obligations (tax, regulatory, security). Any marketing communication relies on consent and can be opted out
• Communicating critical security alerts, system updates, and service announcements.
• We collect only the information reasonably necessary to deliver our services, respond to enquiries, comply with legal obligations, and improve our customer experience.
4. Data Sharing and Third-Party Sub-Processors We do not sell, rent, or trade client data. We only share information with trusted third parties under strict confidentiality agreements, including:
• Authorized Vendor Partners: Industry-leading, globally recognized cybersecurity and infrastructure vendor partners, strictly for the purpose of provisioning requested software licenses and partner integrations. A current list of specific third-party sub-processors utilized for your environment can be provided upon request or as detailed in your Master Service Agreement (MSA). CyberPulse Data Security remains responsible for managing its relationships with third-party service providers and requires such providers to maintain appropriate security and confidentiality protections.
• Infrastructure Providers: Secure cloud hosting and payment gateways required to operate our platform and process transactions. CyberPulse Data Security endeavours to engage reputable service providers that implement industry-standard security controls to protect information processed on their platforms.
• Legal & Regulatory Requirements: When mandated by Indian law enforcement or regulatory bodies to comply with legal obligations.
• Certain third-party vendors, cloud service providers, and software platforms used in delivering our services may process or store information in jurisdictions outside India. Where such transfers occur, CyberPulse Data Security will take reasonable steps to ensure that appropriate contractual, organizational, and security safeguards are implemented in accordance with applicable laws and regulations.
5. Data Security & Multi-Tenant Isolation Security is our core business. We implement robust, business-focused technical and organizational measures to protect your data. We utilize strict multi-tenant architecture protocols within vendor portals to ensure that each client’s data is completely isolated, encrypted at rest and in transit, and protected by zero-trust access controls. In the event of a confirmed data breach affecting personal information under our control, CyberPulse Data Security will take appropriate containment, investigation, and remediation measures and will provide notifications to affected parties and regulatory authorities where required under applicable law.
6. Data Retention and Offboarding We retain personal and corporate data only for as long as necessary to fulfil the purposes outlined in this policy, comply with our legal and tax obligations under Indian law, resolve disputes, and enforce our agreements. Furthermore, aligning with our Master Service Agreement (MSA) offboarding protocols, upon termination, we will hold the Client’s backups for up to 30 days, before securely wiping the data.
7. Your Rights Subject to applicable Indian data protection laws, including the Digital Personal Data Protection (DPDP) Act, you have the right to request access to, correction of, or deletion of your personal data. Requests relating to access, correction, deletion, or other privacy rights may be submitted via email to privacy@cyberpulse.in. We may require reasonable verification of identity before processing such requests and will respond within the timelines prescribed under applicable law. in accordance with applicable law. Clients managing their SaaS tenants also have administrative controls to manage their respective end-user data directly through our portal.
8. Children’s Privacy: Our website, products, and services are intended primarily for business and professional use and are not directed toward individuals under the age of 18. We do not knowingly collect personal information from minors.
9. Changes to This Policy We may update this Privacy Policy periodically to reflect changes in our technology stack, services, or legal requirements. We will notify active clients of any material changes via email or through an alert within the client portal.
10. Contact Us For any questions regarding this Privacy Policy, your personal data, or to raise a concern, you can contact CyberPulse Data Security at:
Email: privacy@cyberpulse.in
Address: CyberPulse Data Security, Sector 16, Faridabad, Haryana 121002, India.
