# Privacy Policy
**Last updated: 08-23-2026**
Aaryanova (“Aaryanova”, “we”, “us”, “our”) provides cybersecurity consulting services. This policy explains what personal data we collect through aaryanova.com (the “Site”), why we collect it, how we protect it, and the rights you have over it.
We treat privacy as a security discipline, not a compliance formality. The commitments below reflect how we actually operate.
—
# 1. Who We Are
Aaryanova is a cybersecurity consultancy specialising in threat modelling, secure-by-design architecture, cloud security, and AI security.
**Data controller:** Aaryanova
**Registered address:** Bangalore, India
**Contact for privacy matters:** support@aaryanova.com
**Website:** https://aaryanova.com
If you are contacting us about data protection specifically, please put “Privacy Request” in the subject line so it is routed correctly.
—
## 2. What We Collect
### 2.1 Information you give us directly
When you submit our contact form or email us, we collect:
– Your name
– Your email address
– Your organisation name and role, where provided
– Your telephone number, where provided
– The content of your enquiry and any subsequent correspondence
We ask you not to include confidential technical details, credentials, vulnerability specifics, or client-sensitive information in an initial enquiry. Web forms and email are not appropriate channels for that material. If your enquiry requires it, we will arrange a secure channel first.
### 2.2 Information collected automatically
When you visit the Site, our hosting infrastructure and security tooling record:
– IP address
– Browser type, version, and user agent string
– Operating system and device type
– Pages visited, referring URL, and timestamps
– Approximate geographic region derived from IP address
This data is generated as a normal function of serving and protecting a website. We use it to keep the Site available, diagnose faults, and detect abuse such as automated scanning, credential stuffing, or denial-of-service attempts.
### 2.3 Information from third-party sources
If you interact with us on LinkedIn, we may see the profile information you have made available on that platform. Your use of LinkedIn is governed by LinkedIn’s own privacy policy, not this one.
—
## 3. Why We Process Your Data
| Purpose | Data used | Lawful basis |
|—|—|—|
| Responding to your enquiry | Contact form and email data | Legitimate interests; steps prior to entering a contract |
| Delivering consulting services | Contact and correspondence data | Performance of a contract |
| Protecting the Site from attack and abuse | Technical and log data | Legitimate interests in network and information security |
| Meeting legal, tax, and regulatory duties | Correspondence and contract records | Legal obligation |
| Sending service or business updates you asked for | Email address | Consent |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, functioning business does not override your rights and freedoms. You may object to this processing (see Section 8).
—
## 4. What We Do Not Do
We consider these commitments part of the service:
– **We do not sell your personal data.** Not to data brokers, not to advertisers, not to anyone.
– **We do not run advertising or cross-site tracking pixels** on this Site.
– **We do not build marketing profiles** from your browsing behaviour.
– **We do not send unsolicited marketing.** You will only receive email from us in response to your enquiry or where you have expressly opted in.
– **We do not use your enquiry content to train AI models,** our own or any third party’s.
—
## 5. Cookies and Similar Technologies
This Site uses a deliberately minimal set of cookies.
**Strictly necessary cookies.** Our content management platform sets session and security cookies required for the Site to function, including form submission integrity and protection against cross-site request forgery. These cannot be disabled without breaking the Site.
**Anti-spam and bot protection.** Our contact form is protected by a CAPTCHA service, which sets a cookie or token to distinguish humans from automated submissions. This is a security control, not an analytics tool.
**Administrator cookies.** If you log in to the Site as an authenticated administrator, additional cookies store your session and interface preferences. These apply only to Aaryanova personnel.
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent the contact form from working.
—
## 6. Third Parties Who Process Data on Our Behalf
We use a small number of vetted service providers. Each is bound by contract to process data only on our instructions and to maintain appropriate security controls.
– **Hosting and infrastructure provider** — hosts the Site and retains server logs
– **Form and anti-spam services** — process contact form submissions and filter automated abuse
– **Email provider** — delivers and stores our business correspondence
We may also disclose personal data where we are legally required to do so, where necessary to establish or defend legal claims, or to protect the rights and safety of Aaryanova, our clients, or others.
We do not permit any of these providers to use your data for their own purposes.
—
## 7. International Transfers
Our service providers may process data in countries outside your own, including outside the UK and European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as UK International Data Transfer Agreements, European Commission Standard Contractual Clauses, or an adequacy decision covering the destination country.
You may request details of the safeguards applied to a specific transfer by contacting us.
—
## 8. Your Rights
Depending on your jurisdiction, you have the right to:
– **Access** the personal data we hold about you
– **Rectify** data that is inaccurate or incomplete
– **Erase** your data where we have no continuing lawful basis to retain it
– **Restrict** processing while a dispute about accuracy or lawfulness is resolved
– **Object** to processing carried out on the basis of legitimate interests
– **Portability** — receive your data in a structured, commonly used, machine-readable format
– **Withdraw consent** at any time, where consent is the basis for processing
– **Complain** to your national data protection authority
To exercise any of these rights, email support@aaryanova.com. We will respond within one month. We may ask you to verify your identity before we act, precisely because we do not want to disclose your data to someone impersonating you.
Exercising these rights is free of charge, and we will not treat you differently for doing so.
—
## 9. How Long We Keep Data
| Record type | Retention period |
|—|—|
| Enquiries that do not become engagements | 12 months from last contact |
| Client correspondence and project records | Duration of engagement plus 3 years |
| Contracts and financial records | 3 years, or as tax law requires |
| Web server and security logs | 90 days, unless retained for an active investigation |
| Marketing consent records | Until consent is withdrawn, plus 2 years as proof of consent |
Where a longer period is required by law or by an unresolved legal claim, we retain the minimum necessary for that purpose and delete the remainder.
—
## 10. How We Protect Your Data
We apply the controls we recommend to clients:
– Encryption in transit via TLS across the entire Site
– Multi-factor authentication on all administrative and email accounts
– Least-privilege access, with access to enquiry data limited to personnel who need it
– Timely patching of the Site platform, themes, and plugins
– Logging and monitoring for anomalous access
– Regular review of third-party processors and their security posture
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it and inform affected individuals without undue delay where the risk is high.
—
## 11. Children
The Site is directed at businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
—
## 12. External Links
The Site links to external services, including LinkedIn. Once you follow a link off aaryanova.com, this policy no longer applies. We are not responsible for the privacy practices of other operators, and we encourage you to read their policies.
—
## 13. Changes to This Policy
We may update this policy to reflect changes in our practices, our service providers, or the law. The “Last updated” date at the top records the current version. Material changes will be flagged prominently on this page. We encourage you to review it periodically.
—
## 14. Contact
Questions, requests, or complaints about this policy:
**Email:** support@aaryanova.com
If you are not satisfied with our response, you may complain to your data protection supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). In the EU it is the authority in your country of residence.
—
© 2025 Aaryanova. All rights reserved.
