L/08Legal
Data Protection
This page is for customers and prospects who need to understand how Onion Infosec handles personal data. It covers our roles, the agreements we put in place, the providers we use and how requests and incidents are handled.
- Document
- Data Protection
- Last updated
- 22 September 2026
- Applies to
- www.onioninfosec.com
On this page
1. Our roles
The role we take depends on whose data it is and who decides how it is used. Different laws use different words for the same roles.
- Website and business contact data
- Controller under the GDPR and UK GDPR. Data fiduciary under the DPDP Act. Business under the CCPA, if that law applies.
- Data handled within client engagements
- Typically processor under the GDPR and UK GDPR, data processor under the DPDP Act and service provider under the CCPA. The client remains the controller.
Website and business contact data
We decide why and how we use the contact details of people who enquire, of client and supplier staff, and of others we deal with in the course of business. The Privacy Policy describes this processing.
Data handled within client engagements
When we assess, build, monitor or operate systems for a client, we may come into contact with personal data the client controls. We handle it on the client’s instructions. This is governed by the engagement agreement and by a data processing agreement where the law requires one.
The role can differ in a particular engagement. Where it does, the engagement agreement says so.
2. Data processing agreements
For engagements in which we process personal data on a client’s behalf, we agree a data processing agreement as part of the contract, and we are glad to work from the client’s own template.
A data processing agreement typically sets out the following.
- The subject matter, duration, nature and purpose of the processing
- The types of personal data and the categories of people it relates to
- Processing only on the client’s documented instructions
- Confidentiality obligations for our staff
- Security measures
- Conditions for using subprocessors
- Assistance with data subject requests, impact assessments and incidents
- Return or deletion of data at the end of the engagement
- Information and audit rights
3. Subprocessors and service providers
The providers we use depend on the context.
For this website
- Microsoft Azure: website hosting and the contact form function
- Google (Google Workspace): delivery of form submissions, and the business email system in which enquiries are received
For client engagements
Subprocessors are defined in each contract. Many engagements are delivered inside the client’s own environment and tools, with no subprocessor involved. Where we propose to use one, we identify it in the agreement and follow the approval and change process the agreement sets.
4. International transfers
Onion Infosec is based in Mumbai, India, and delivers work remotely and on site. Personal data may therefore be accessed from or transferred to India, or to the locations of agreed subprocessors.
Where a client’s data is subject to transfer restrictions, we agree the approach in the contract. Options include an appropriate transfer mechanism, such as standard contractual clauses or the UK International Data Transfer Addendum, and delivery models that keep data within the client’s environment and region.
5. Security measures
Engagement data is governed by non-disclosure agreements and handled under least-privilege access. Data is encrypted in transit. We aim to work within the client’s environment where practical, to take only the data an engagement needs and to return or delete it when the work ends.
Specific technical and organizational measures are set out in the engagement agreement. See also the Security page, which states what we do and do not claim.
6. Data subject requests
Where we are the controller, individuals can exercise their rights through the Privacy Requests page.
Where we act as a processor and receive a request about a client’s data, we do not respond to it ourselves. We pass it to the client and assist the client as the contract and the law require.
7. Personal data breach notification
If we become aware of a personal data breach affecting data we process for a client, we notify the client as the contract and the law that applies require, and we provide the information the client needs to meet its own notification duties.
Where we are the controller or data fiduciary, we notify regulators and affected individuals as the law that applies requires.
8. Contact
To ask about a data processing agreement, or about data protection during procurement, write to privacy@onioninfosec.com or use the contact page. Grievance Officer (India): Vivek P, grievance@onioninfosec.com.
