Privacy Policy
This policy explains what personal data ArmourIQ collects, why we collect it, how we use and protect it, and the rights you have over it.
Introduction
ArmourIQ respects your privacy and is committed to protecting the personal data we handle. This policy applies to personal data we collect through this website and in the course of providing our Services. We handle personal data in line with India's Digital Personal Data Protection Act, 2023 (DPDPA) and, where applicable to clients or visitors in other regions, comparable data protection laws.
Who We Are
For the purposes of this policy, the data fiduciary (controller) is Twinflare Technologies LLP, doing business as ArmourIQ, registered in New Delhi, India. Where we process personal data on behalf of a client under an engagement, we act as a data processor and handle that data strictly on the client's documented instructions.
Data We Collect
Information you provide
- Contact details submitted through our forms, name, work email, phone number, company, and role.
- The content of enquiries, consultation requests, and correspondence.
- Newsletter subscription details, where you choose to subscribe.
Information collected automatically
- Basic technical data such as IP address, browser type, device information, and pages visited.
- Analytics data about how the website is used, collected via cookies or similar technologies (see section 11).
Engagement data
During a service engagement we may receive information about your systems, environment, and personnel as necessary to deliver the Services. Such data is handled under the confidentiality and data-handling terms of the relevant engagement agreement.
OUR DATA COLLECTION STANCE
We collect only the personal data we need for the purpose at hand. We do not sell personal data, and we do not use it for advertising.
How We Use Your Data
- To respond to enquiries and consultation requests.
- To provide, manage, and improve our Services.
- To send advisory updates or threat intelligence briefings you have subscribed to.
- To maintain the security and integrity of our website.
- To meet legal, regulatory, and contractual obligations.
Legal Basis for Processing
We process personal data on the basis of your consent (for example, when you subscribe to our newsletter), to take steps at your request before entering into a contract or to perform a contract with you, to meet legal obligations, and for our legitimate interests in operating and securing our business, provided those interests are not overridden by your rights.
Data Security
As a cybersecurity practice, protecting data is core to what we do. We apply administrative, technical, and organisational measures appropriate to the sensitivity of the data, including access controls, encryption in transit, and least-privilege principles. No method of transmission or storage is completely secure, but we work to protect personal data against unauthorised access, loss, or misuse.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, to comply with legal and regulatory obligations, and to resolve disputes. When data is no longer needed, we securely delete or anonymise it. Retention of engagement data is governed by the relevant engagement agreement.
International Transfers
We are based in India and primarily process data here. Where we work with clients or service providers in other regions, any transfer of personal data across borders is carried out in accordance with applicable data protection law and appropriate safeguards. For clients with data residency requirements, we can scope engagements to keep data within a specified region.
Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data where there is no overriding legal basis to retain it.
- Withdraw consent at any time, where processing is based on consent.
- Nominate another person to exercise your rights in the event of death or incapacity, as provided under the DPDPA.
- Raise a grievance with us, and escalate to the Data Protection Board of India where applicable.
To exercise any of those rights, contact us using the details in section 14.
Children's Privacy
Our website and Services are intended for businesses and professionals. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version. Material changes will be communicated through the website or, where appropriate, directly.
Contact & Grievance Officer
For any privacy-related question, request, or grievance, contact us at:
- Email: hello@armouriq.com
- Phone: +91 8007024111
- Twinflare Technologies LLP (dba ArmourIQ), Saket Salcon, Saket District Centre, New Delhi 110017
PLACEHOLDER, DPDPA NAMED PUBLICATION
Under the DPDPA, name a Grievance Officer / Data Protection point of contact and publish their designation and contact details here.