L/08Legal

Data Protection

This page is for customers and prospects who need to understand how Onion Infosec handles personal data. It covers our roles, the agreements we put in place, the providers we use and how requests and incidents are handled.

Document
Data Protection
Last updated
22 September 2026
Applies to
www.onioninfosec.com
On this page
  1. 1. Our roles
  2. 2. Data processing agreements
  3. 3. Subprocessors and service providers
  4. 4. International transfers
  5. 5. Security measures
  6. 6. Data subject requests
  7. 7. Personal data breach notification
  8. 8. Contact

1. Our roles

The role we take depends on whose data it is and who decides how it is used. Different laws use different words for the same roles.

Website and business contact data
Controller under the GDPR and UK GDPR. Data fiduciary under the DPDP Act. Business under the CCPA, if that law applies.
Data handled within client engagements
Typically processor under the GDPR and UK GDPR, data processor under the DPDP Act and service provider under the CCPA. The client remains the controller.

Website and business contact data

We decide why and how we use the contact details of people who enquire, of client and supplier staff, and of others we deal with in the course of business. The Privacy Policy describes this processing.

Data handled within client engagements

When we assess, build, monitor or operate systems for a client, we may come into contact with personal data the client controls. We handle it on the client’s instructions. This is governed by the engagement agreement and by a data processing agreement where the law requires one.

The role can differ in a particular engagement. Where it does, the engagement agreement says so.

2. Data processing agreements

For engagements in which we process personal data on a client’s behalf, we agree a data processing agreement as part of the contract, and we are glad to work from the client’s own template.

A data processing agreement typically sets out the following.

  • The subject matter, duration, nature and purpose of the processing
  • The types of personal data and the categories of people it relates to
  • Processing only on the client’s documented instructions
  • Confidentiality obligations for our staff
  • Security measures
  • Conditions for using subprocessors
  • Assistance with data subject requests, impact assessments and incidents
  • Return or deletion of data at the end of the engagement
  • Information and audit rights

3. Subprocessors and service providers

The providers we use depend on the context.

For this website

  • Microsoft Azure: website hosting and the contact form function
  • Google (Google Workspace): delivery of form submissions, and the business email system in which enquiries are received

For client engagements

Subprocessors are defined in each contract. Many engagements are delivered inside the client’s own environment and tools, with no subprocessor involved. Where we propose to use one, we identify it in the agreement and follow the approval and change process the agreement sets.

4. International transfers

Onion Infosec is based in Mumbai, India, and delivers work remotely and on site. Personal data may therefore be accessed from or transferred to India, or to the locations of agreed subprocessors.

Where a client’s data is subject to transfer restrictions, we agree the approach in the contract. Options include an appropriate transfer mechanism, such as standard contractual clauses or the UK International Data Transfer Addendum, and delivery models that keep data within the client’s environment and region.

5. Security measures

Engagement data is governed by non-disclosure agreements and handled under least-privilege access. Data is encrypted in transit. We aim to work within the client’s environment where practical, to take only the data an engagement needs and to return or delete it when the work ends.

Specific technical and organizational measures are set out in the engagement agreement. See also the Security page, which states what we do and do not claim.

6. Data subject requests

Where we are the controller, individuals can exercise their rights through the Privacy Requests page.

Where we act as a processor and receive a request about a client’s data, we do not respond to it ourselves. We pass it to the client and assist the client as the contract and the law require.

7. Personal data breach notification

If we become aware of a personal data breach affecting data we process for a client, we notify the client as the contract and the law that applies require, and we provide the information the client needs to meet its own notification duties.

Where we are the controller or data fiduciary, we notify regulators and affected individuals as the law that applies requires.

8. Contact

To ask about a data processing agreement, or about data protection during procurement, write to privacy@onioninfosec.com or use the contact page. Grievance Officer (India): Vivek P, grievance@onioninfosec.com.