Legal

Privacy Notice

Version 2.0 · Effective 22 September 2026

This notice explains how ZeroRisk Labs handles personal data across the jurisdictions in which our clients operate, the legal basis on which we do so, the mechanisms that make our international transfers lawful, and how to exercise your rights.

It is written to be read by a data protection officer or in-house counsel as well as by an individual. Where a commitment carries a deadline or a defined period, that period is stated rather than described as “reasonable”.

1. Who we are and what this notice covers

ZeroRisk Labs is a cybersecurity services firm established in India. We deliver security testing, incident response, digital forensics, cloud and application security, compliance readiness, and training engagements to organisations in the United Kingdom, the European Union, the United States, South Africa, India, and elsewhere.

This notice explains how we handle personal data in two distinct situations: when you interact with this website or contact us, and when we process personal data belonging to a client in the course of delivering an engagement. The distinction matters because our legal role, and therefore your route to exercising rights, differs between the two.

2. Our role: when we are a controller and when we are a processor

We act as a controller for the personal data we decide the purposes and means of processing. That covers enquiries submitted through this website, correspondence you send us, our commercial relationship with client contacts, and recruitment.

We act as a processor, an operator in South African terminology, or a service provider under US state privacy law, for personal data we handle on a client's documented instructions during an engagement. In that role the client is the controller, or the business. They determine what is processed and why; we act only within the instructions recorded in the engagement agreement and the accompanying Data Processing Agreement.

If you are a data subject whose personal data we encountered during an engagement for one of our clients, your rights are exercised against that client as controller. If you contact us directly we will acknowledge your request, tell you promptly whether we hold data as processor rather than controller, and refer you to the responsible controller instead of leaving the request unanswered.

Our processor obligations, including the mandatory terms required by Article 28(3) of the UK and EU GDPR and by section 21 of POPIA, are published in full in our Data Processing Agreement.

3. The laws we apply

We apply the data protection regime of the jurisdiction in which the affected individuals are located, rather than applying Indian law alone and asking international clients to accept it. Where more than one regime applies, we apply the more protective standard.

  • United Kingdom — UK General Data Protection Regulation (UK GDPR); Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
  • European Union and European Economic Area — Regulation (EU) 2016/679 (EU GDPR); The national data protection legislation implementing and supplementing the GDPR in the Member State in which the data subject is located.
  • United States — California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.) and the CCPA Regulations; The comprehensive consumer privacy statutes in effect in twenty states as at the effective date of this notice, and those enacted and not yet in force; Sectoral federal law where applicable to an engagement, including HIPAA for protected health information and the GLBA Safeguards Rule for financial institutions; State data breach notification statutes in all fifty states.
  • South Africa — Protection of Personal Information Act 4 of 2013 (POPIA).
  • India — Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 and commencing in phases, with most substantive obligations operative from 13 May 2027.

Our compliance with these regimes is a matter of how we operate, not only of what we publish. Where a specific obligation depends on an engagement's circumstances, it is recorded in the engagement agreement.

4. Personal data we process as a controller

a) Information you provide to us

  • Identity and contact details — first name, last name, and business email address submitted through our enquiry or service request forms.
  • Enquiry content — the description of your requirement, project, or question that you choose to include.
  • Service interest — the service category you select on a service request.
  • Correspondence — the content of email exchanges you initiate or continue with us.

b) Information collected automatically

  • IP address — used to enforce a limit on the rate of form submissions so that our forms cannot be used for automated abuse. It is not used to track, profile, or identify you, and it is not combined with any advertising or analytics dataset.
  • Request metadata — the browser user agent string and the originating page, used for the same abuse-prevention purpose.

c) Information we do not collect

  • We set no analytics, advertising, or tracking cookies, and we embed no third-party analytics or advertising scripts. There is no cross-site tracking of any kind on this website.
  • We do not ask for, and do not want, special category data in an enquiry. Please do not include health, biometric, racial or ethnic, political, religious, trade union, or sexual orientation data in a web form.
  • We do not require a telephone number and we do not collect one.

5. Why we process it, and our lawful basis

Every processing operation we carry out as a controller rests on one of the following bases. We identify the basis before processing begins, not retrospectively.

  • Performance of a contract, or steps taken at your request before entering one — to answer your enquiry, scope an engagement, prepare a proposal, and deliver services you have commissioned. Article 6(1)(b) UK and EU GDPR; section 11(1)(b) POPIA.
  • Legitimate interests — to protect this website and our infrastructure from abuse, to maintain records of our commercial dealings, and to respond to business correspondence. Article 6(1)(f) UK and EU GDPR; section 11(1)(f) POPIA. We have assessed in each case that these interests are not overridden by your interests, rights, and freedoms, and we will provide the substance of that assessment on request.
  • Compliance with a legal obligation — to meet statutory retention, tax, accounting, and lawful disclosure requirements. Article 6(1)(c) UK and EU GDPR; section 11(1)(c) POPIA.
  • Consent — where we rely on consent, we ask for it separately and unambiguously, and you may withdraw it at any time without detriment. Article 6(1)(a) UK and EU GDPR; section 11(1)(a) POPIA.

We do not process personal data for advertising, for sale or rental to third parties, for profiling, or for automated decision-making that produces legal effects.

6. Personal data we handle during engagements

Security testing, incident response, and forensic work can expose us to personal data held in a client's systems. This is the highest-risk category of data we touch, and it is governed by a deliberately restrictive set of rules.

  • We process engagement data only on the client's documented instructions, within a defined scope and an authorisation that the client confirms in writing before work begins.
  • We apply data minimisation as an operational rule: we do not extract, copy, or retain live personal data beyond what is strictly necessary to evidence a finding. Where a finding can be demonstrated with a redacted or synthetic example, that is what appears in the deliverable.
  • Where an engagement may expose special category data — for example in forensic or data loss prevention work — that exposure is identified during scoping, recorded in the engagement agreement, and subjected to additional handling restrictions.
  • Evidence is handled under documented chain of custody and returned or destroyed on the client's instruction.
  • Working material containing client personal data is deleted on a short fixed clock after the final deliverable is accepted, rather than retained for convenience. The period is stated in the retention schedule below.
  • We will refuse or pause an instruction that would require us to process personal data unlawfully, and we will say so in writing rather than proceeding and documenting an objection afterwards.

7. Who we share personal data with

We do not sell, rent, or trade personal data. We disclose it only in the circumstances below.

  • Sub-processors that support our operations under a written contract imposing data protection obligations equivalent to our own. Each is named, with its role and the safeguard relied upon, in our published sub-processor register.
  • Changes to that register are notified at least 30 days before a new sub-processor begins processing, so that a controller has a genuine opportunity to object.
  • Professional advisers — legal and accounting advisers bound by professional duties of confidentiality, where necessary to obtain advice or defend a claim.
  • Competent authorities — where disclosure is required by a binding legal obligation. We assess every request for validity, disclose only the minimum necessary, and notify the affected controller unless we are legally prohibited from doing so.
  • An acquirer — if our business or any part of it is reorganised or transferred, subject to equivalent protections continuing to apply.

We do not disclose client identities, engagement findings, or the existence of an engagement to anyone without the client's written authorisation. Confidentiality of that kind is the basis on which security work is possible at all.

8. International transfers

We are established in India. Personal data originating in the United Kingdom, the European Economic Area, or South Africa is therefore transferred internationally when we process it. We do not obscure this, and we do not rely on a transfer mechanism that would not withstand review.

India is not the subject of an adequacy decision under Article 45 of the EU GDPR, and is not covered by UK adequacy regulations. Transfers therefore rely on the safeguards set out below rather than on adequacy.

A copy of the transfer mechanism applicable to your data, and of the transfer impact or transfer risk assessment supporting it, is available on request.

European Economic Area to India

Standard Contractual Clauses, Module Two (controller to processor)

We enter into the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. India is not the subject of an adequacy decision under Article 45 of the EU GDPR, so transfers rely on Article 46 safeguards supported by a transfer impact assessment and, where that assessment requires them, supplementary technical and organisational measures.

United Kingdom to India

International Data Transfer Agreement, or the EU SCCs with the UK International Data Transfer Addendum

The EU Standard Contractual Clauses are not a valid transfer mechanism on their own under the UK GDPR. We therefore enter into either the ICO's International Data Transfer Agreement or the EU SCCs together with the ICO's International Data Transfer Addendum, at the controller's election, supported by a transfer risk assessment.

United States to India

Contractual protection — no statutory transfer mechanism is imposed by US law

Neither federal law nor the state privacy statutes impose a GDPR-style restriction on transferring personal information outside the United States, so there is no equivalent of the Standard Contractual Clauses to execute. We do not treat that as a reason to offer less protection. Our service provider commitments under the CCPA Regulations apply in full wherever the processing occurs, and we extend the same technical and organisational measures, breach notification timescales, sub-processor controls, and government access commitments to US client data as we do to data originating in the United Kingdom or the European Economic Area. Where an engagement involves protected health information, a Business Associate Agreement is executed before processing begins.

South Africa to India

Operator agreement satisfying section 72 of POPIA

Transfers are made under a written agreement that subjects the personal information to a level of protection substantially similar to the conditions for lawful processing under POPIA, including the further-processing and security-safeguard provisions, as contemplated by section 72(1)(a).

9. Where personal data is processed, and government access

Our own operations are conducted from India. Our sub-processors are global providers that may process data in more than one jurisdiction in the course of delivering platform-level functions such as content delivery and mail routing. The specific processing regions applicable to an engagement are recorded in the engagement agreement and are available to clients on request.

Because we are established outside the United Kingdom, the European Economic Area, and South Africa, anyone assessing us has to consider whether a public authority in our jurisdiction could compel access to personal data we hold. We address that directly rather than leaving it to be assumed:

  • We have received no government or law enforcement request for client personal data to date, and no order requiring us to build or maintain any facility for bulk access to it.
  • We assess every request we receive for legal validity, jurisdiction, and proportionality before responding, and we reject any request that is overbroad or defective on its face.
  • We disclose only the minimum data strictly necessary to comply with a valid and binding order, never the whole of a dataset where a subset will satisfy it.
  • We notify the affected controller before disclosing, or as soon afterwards as we lawfully can, and we provide whatever detail about the request the law permits us to share.
  • We challenge a request through available legal channels, including seeking interim relief, where there are reasonable grounds to consider it unlawful under the applicable law or inconsistent with our obligations to the controller.
  • We will tell a controller if we ever become subject to a law or measure that would prevent us from honouring these commitments, so that the controller can suspend transfers and exercise its termination rights.
  • We maintain a record of any request received and the response given, and make it available to controllers and, where required, to supervisory authorities.

We state processing locations at country level on this page and confirm specific regions contractually. Publishing a detailed map of our infrastructure would offer no benefit to you and some benefit to an attacker. The commitments above mirror Clauses 14 and 15 of the EU Standard Contractual Clauses and are repeated as binding terms in clause 15 of our Data Processing Agreement.

10. How long we keep personal data

We hold personal data for defined periods rather than indefinitely. The schedule below applies unless a longer period is required by law, or a controller has instructed a different period — longer or shorter — under an engagement agreement.

When a retention period ends, data is deleted securely. Where deletion from backup media cannot be completed immediately, the data is placed beyond use and removed on the next scheduled destruction cycle.

Website enquiries and service requests that do not become engagements

24 months from your last contact with us

Allows us to pick up a delayed procurement cycle without holding commercial correspondence indefinitely.

Abuse-prevention records

Short-lived

These records exist only to stop our public forms being used for automated abuse. They carry an expiry timestamp and are eligible for automated deletion once the period they relate to has closed. They are never used for any other purpose.

Engagement working material containing client personal data

Deleted within 30 days of final deliverable acceptance, unless the client instructs otherwise in writing

Testing artefacts, captured credentials, and forensic working copies are the highest-risk data we hold. They are destroyed on a short clock rather than retained for convenience.

Engagement deliverables and the records evidencing the engagement

Deleted or returned on termination, unless the engagement agreement provides for a defined retention period — commonly the term plus 24 months

Deliverables are Engagement Data, so the default position in clause 12 of our Data Processing Agreement governs: on termination we delete or return them at the client's choice. Where a client wants the deliverable set kept to support retesting, audit evidence, or the defence of legal claims, that period is agreed in the engagement agreement and the agreement constitutes the client's documented instruction to retain. We do not retain deliverables on our own initiative.

Recruitment applications

12 months from the conclusion of the recruitment process

Allows us to consider a candidate for a comparable role that opens shortly afterwards.

Records we are required by law to keep

The period required by the applicable statutory obligation

Tax, accounting, and corporate records are retained for their statutory minimum and no longer.

11. How we protect personal data

We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the UK and EU GDPR and section 19 of POPIA. In summary, and at the level of detail appropriate to a public document:

  • Encryption in transit for all connections to this website, with transport security enforced rather than merely offered, and encryption at rest for stored submissions.
  • No public access path to stored data. Our datastore denies client-side access by default; all reads and writes occur server-side through a credentialled service identity.
  • Access on a need-to-know basis, restricted to personnel who require it for a defined task, under individual confidentiality undertakings.
  • Input validation and abuse prevention on every submission path, including automated-submission controls and rate limiting.
  • A hardened browser security posture, including a content security policy, framing and content-type protections, and a restrictive permissions policy.
  • Logging designed to avoid leaking detail, with error output sanitised and public responses carrying no internal record identifiers.
  • Secure deletion at the end of a retention period or on controller instruction.

We do not publish control parameters, configuration values, tooling inventories, or architectural detail. That information would materially assist an attacker and is of no practical use to a reader assessing our posture. It is provided to clients and prospective clients under a non-disclosure agreement as part of due diligence.

12. Your rights

Subject to the conditions in the applicable regime, you have the following rights. We do not charge a fee for exercising them, and we do not treat you less favourably for having done so.

  • Access — Obtain confirmation of whether we process personal data about you and receive a copy of it, together with information about the purposes, recipients, and retention period.
  • Rectification — Have inaccurate personal data corrected and incomplete personal data completed.
  • Erasure — Have personal data deleted where it is no longer necessary for the purpose it was collected for, where you withdraw consent that was the sole basis for processing, or where the processing is unlawful.
  • Restriction — Require that we limit processing to storage only while an accuracy dispute or an objection is being resolved.
  • Objection — Object to processing carried out on the basis of our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Portability — Receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Withdrawal of consent — Withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before it.
  • Complaint to a supervisory authority — Lodge a complaint with the data protection authority in your jurisdiction. Exercising a right with us never removes that option.
  • No decisions made solely by automated means — We do not carry out automated decision-making producing legal effects, and we do not profile you. This right requires no action on your part because the processing does not occur.

If you are a US resident, the comparable rights under your state's privacy statute apply, which in most states means the rights to know, access, correct, delete, obtain a portable copy, opt out of sale or targeted advertising, limit the use of sensitive personal information, and not be discriminated against for exercising them. Two of those need no action from you: we do not sell or share personal information, and we do not use it for targeted or cross-context behavioural advertising, so there is nothing to opt out of. Where we hold your data as a service provider for one of our clients, your request goes to that client as the business, and we will tell you so rather than leaving it unanswered.

13. How to exercise your rights

Send your request to privacy@zerorisklabs.com using the subject line "Data Protection Request". Describe what you are asking for and, if you are able to, the context in which you contacted us. You do not need to cite a legal provision or use any particular form of words.

  • We acknowledge every request within 72 hours.
  • We respond substantively within 30 days. If the request is complex and the applicable regime permits an extension, we will tell you within that period, explain why, and give a revised date.
  • We will ask for identity verification only where we have a genuine doubt about who you are, and we will request the minimum necessary to resolve that doubt.
  • If we cannot comply, in whole or in part, we will tell you which exemption or condition we rely on and explain your right to challenge that outcome.
  • If we hold your data as a processor rather than a controller, we will tell you so and identify the controller responsible, or forward your request to them where we are contractually required to.

14. Complaints to a supervisory authority

We would prefer the opportunity to resolve a concern directly, but you are never required to come to us first. You may complain to the data protection authority for your jurisdiction at any time.

If you are in the European Economic Area you may also complain to the authority in the Member State of your habitual residence or place of work, whichever you prefer.

15. Representatives and points of contact

All data protection correspondence, from data subjects and from supervisory authorities alike, should be addressed to privacy@zerorisklabs.com. This is a dedicated mailbox, monitored separately from our general enquiry address, so correspondence from an authority is never queued behind a sales enquiry.

Suspected vulnerabilities and security incidents should go to security@zerorisklabs.com, which is likewise monitored separately so that an active incident is not delayed behind routine correspondence.

Where Article 27 of the EU GDPR or Article 27 of the UK GDPR requires us to designate a representative in the Union or the United Kingdom for a particular processing activity, we will designate one in writing and publish the designated representative's identity and contact details on this page. We will not assert that a representative has been appointed before that appointment is in place.

Under an engagement, the client remains free to address any data protection matter to the contact named in the engagement agreement, which takes precedence over this page for that engagement.

16. Personal data breaches

Where we act as a processor and become aware of a personal data breach affecting a client's personal data, we notify that client without undue delay and in any event within 24 hours of becoming aware. This is set deliberately tighter than the regulatory deadline so that a controller retains the majority of its own notification window under Article 33 of the UK and EU GDPR. Where POPIA applies, section 21(2) requires us to notify the responsible party immediately, and we do; the 24-hour figure is an outer limit for other jurisdictions, not a permission to wait.

Where we act as a controller and a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware. Where the risk is high, we also notify affected individuals directly and without undue delay.

In either case we provide the information needed to assess the incident: what happened, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. We do not delay an initial notification in order to complete an investigation first, and we supply further detail in phases as it is established.

If you believe you have identified a vulnerability in this website or a security issue affecting our services, please see the responsible disclosure provisions in our Terms and Conditions.

17. Cookies and tracking

This website sets no cookies for analytics, advertising, profiling, or tracking, and loads no third-party analytics or advertising scripts. There is consequently no consent banner, because there is nothing to consent to.

Because we operate no cross-site behavioural advertising and no profiling, a browser "Do Not Track" signal has no processing for us to suppress. We do not implement a separate response to it, as no uniform technical standard for doing so exists.

18. Children

Our website and services are directed to organisations and their professional staff, not to children. We do not knowingly process the personal data of children through this website.

If you believe a child has provided personal data to us, contact us and we will review and delete it where we are required or able to do so.

19. Recruitment and candidate data

If you apply for a role with us, we process your personal data as a controller for the purpose of assessing your application and managing the recruitment process.

  • What we process — your name, contact details, curriculum vitae, work history, and the content of your application and interview correspondence.
  • Lawful basis — steps taken at your request before entering into a contract, and our legitimate interest in assessing candidates for advertised roles.
  • Retention — 12 months from the conclusion of the recruitment process, so that we can consider you for a comparable role that opens shortly afterwards. You may ask us to delete your application sooner and we will.
  • Sub-processor — applications submitted through our advertised vacancies are handled by the recruitment platform named in our sub-processor register. That platform processes candidate data only; no client engagement data passes through it.
  • No automated assessment — we do not screen, rank, score, or filter candidates by automated means. Every application is read by a person.
  • Your rights — the rights in section 12 apply in full. For anything concerning a job application, write to hr@zerorisklabs.com, which reaches our recruitment team directly. You may use the general address in section 21 instead if you prefer.

We do not ask candidates for special category data and ask that you do not include any in an application. Please also do not send us confidential material belonging to a current or former employer; we will not accept it, and offering it will count against an application for a security role.

20. Changes to this notice

We revise this notice when our practices or the applicable law change. The effective date and version are shown at the top of the page, and the substance of any material change is described rather than merely announced.

Where a change materially affects how we process personal data under an active engagement, we notify the affected controller directly instead of relying on publication alone.

21. Contact us

For any question about this notice, about how we process personal data, or to exercise a right:

ZeroRisk Labs

Ambari, Guwahati, Assam 781001, India

Email: privacy@zerorisklabs.com

Please use the subject line Data Protection Request so your message is routed correctly on arrival.