Privacy Policy

Last updated: August 7, 2026

Who we are

Secalyx Technologies LLP ("Secalyx", "we", "us") is a cybersecurity and compliance advisory practice registered in India.

Registered office: 94 Sai Kripa Colony, Indore, Madhya Pradesh 452010, India
LLPIN: ACZ-7602
Privacy Contact: info@secalyx.com

Where the EU or UK General Data Protection Regulation applies, Secalyx acts as data controller. When the substantive provisions of India's Digital Personal Data Protection Act 2023 commence, Secalyx will act as a Data Fiduciary for processing to which they apply.

What this covers

Personal data collected through secalyx.com/ and through email correspondence arising from it. It does not cover personal data processed during a client engagement, which is governed by that engagement's agreement.

What we collect

Through the contact form

Your name, your work email address, your organization, and the content of your message. These are the only fields the form collects.

Generated when you submit the form

A short-lived value derived from your IP address and email address, used only to prevent repeated automated submissions. It expires within minutes and is not used for tracking.

Through email

Correspondence you send us and anything you include in it.

Through our hosting provider

Standard web server logs, including IP address, browser type, pages requested and timestamps, generated for security and operational purposes.

We do not use analytics. There is no Google Analytics, no advertising pixel, and no behavioral profiling on this website.

Please do not send sensitive material

This form is for initial contact. Please do not use it to send passwords, credentials, security keys, exploit details, production data, client information, or other confidential material. For security research, see our Responsible Disclosure Policy.

Why we use it

PurposeBasis where GDPR or UK GDPR applies
Responding to a service enquiry, including information or a proposal you have requestedSteps taken at your request before entering a contract
Preventing automated abuse of our formsOur legitimate interests in protecting our systems
Website security and operational integrityOur legitimate interests
Meeting legal obligationsLegal obligation

The checkbox on our form confirms you have read this policy. It is an acknowledgment, not consent for marketing, and it is not the legal basis for our processing. The bases are above.

We do not use your information for marketing and we do not send newsletters.

How long we keep it

WhatHow long
Enquiries received through this website or by email24 months from last contact
Security disclosure reports24 months after closure
BackupsDeleted on our hosting provider's normal overwrite cycle

A single 24-month retention policy is applied to our mailbox, so deletion is automatic rather than manual. Copies may remain in routine backups until those backups are overwritten. Where an enquiry becomes a client engagement, retention follows that engagement's agreement and any applicable record-keeping requirement.

Who else is involved

We do not sell personal data and we do not share it for advertising.

ProviderWhat they handle
HostingerWebsite hosting. Holds server logs and backups
Microsoft (Microsoft 365)Our email. Handles messages to and from us, including enquiries submitted through the website
GoDaddyDomain registration and DNS. Does not receive your form content

We may disclose personal data where required by law, court order, or lawful request from a competent authority.

International transfers

Secalyx is established in India. Our hosting and email providers operate international infrastructure, so personal data may be processed outside your country.

Where personal data originating in the European Economic Area or the United Kingdom is transferred, we rely on the transfer mechanisms our providers maintain, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum where those apply. You may ask us for information about the safeguards covering a particular transfer.

Your rights

Rights depend on where you are and which law applies, and are subject to the conditions and exceptions in that legislation.

Where the EU or UK GDPR applies, you may have the right to access your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to object to processing based on legitimate interests; and, where conditions are met, to data portability. Where we rely on consent for a specific purpose, you may withdraw it at any time without affecting earlier processing.

If you are in India, the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 follow a phased commencement schedule. The provisions concerning individual rights, grievance redressal and complaints to the Data Protection Board of India commence on the dates notified by the Central Government. We follow the schedule as notified and will update this notice if it changes.

In the meantime, as a matter of practice rather than statutory obligation, we will accept and act on requests to access, correct, update or delete the personal data we hold about you, subject to any legal requirement to retain it. We will update our processes before those provisions commence.

To make a request, email info@secalyx.com. We will respond as promptly as we can, and within any period applicable law requires. We may need to verify your identity first.

Grievances and complaints

If you are unhappy with how we have handled your personal data, contact our Privacy Contact at info@secalyx.com. We aim to acknowledge within 5 working days and resolve within 30 days.

Where the EU or UK GDPR applies, you may also complain to a supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, your national data protection authority. In India, once the relevant provisions of the Digital Personal Data Protection Act 2023 commence, unresolved grievances may be escalated to the Data Protection Board of India.

Security

We apply administrative and technical measures proportionate to the scale of our processing. These measures include encrypted transport (HTTPS) for data in transit, multi-factor authentication on administrative accounts, access limited to those who need it, and defined retention limits.

Encrypted transport protects data while it travels between your browser and our systems. It does not mean all stored information is encrypted at rest. No system is completely secure and we do not claim otherwise.

Children

This website is not directed at children and we do not knowingly collect their personal data.

Changes

We may update this policy; the date above reflects the current version. If we introduce new processing — analytics, a newsletter, resource downloads, comments, or embedded third-party content — we will update this policy and, where consent is required, obtain it first.

Contact

Privacy Contact · info@secalyx.com
Secalyx Technologies LLP, 94 Sai Kripa Colony, Indore, Madhya Pradesh 452010, India