L/01Legal

Privacy Policy

This policy explains what personal data we receive through this website, why we use it, who processes it for us and what rights you have. The website is designed to collect as little personal data as possible.

Document
Privacy Policy
Last updated
22 September 2026
Applies to
www.onioninfosec.com
On this page
  1. 1. Who we are
  2. 2. Scope of this policy
  3. 3. Personal data we collect
  4. 4. Why we use personal data and our legal bases
  5. 5. Who we share personal data with
  6. 6. International transfers
  7. 7. How long we keep personal data
  8. 8. How we protect personal data
  9. 9. Your rights by region
  10. 10. How to make a request
  11. 11. Children
  12. 12. Changes to this policy
  13. 13. Contact

1. Who we are

This website is operated by Onion Information Security Solutions Private Limited ("Onion Infosec", "we", "us"), a company incorporated in India with its registered office in Mumbai, Maharashtra.

For the personal data described in this policy, we decide why and how it is used. Under the EU General Data Protection Regulation (GDPR) and the UK GDPR, that makes us the controller. Under India’s Digital Personal Data Protection Act, 2023 (the DPDP Act), it makes us the data fiduciary.

In India, our handling of personal data is governed today by the Information Technology Act, 2000 (the IT Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the SPDI Rules). The DPDP Act will replace section 43A of the IT Act and the SPDI Rules as its provisions come into force. This policy is written to meet both.

Legal name
Onion Information Security Solutions Private Limited
Registered office
1st Floor, 1B-102, Parinee Crescenzo, G Block, Bandra Kurla Complex, Bandra East, Mumbai, Maharashtra 400051, India
Corporate Identity Number
U62099MH2025PTC443498
Grievance officer (India)
Vivek P, grievance@onioninfosec.com
EU or UK representative
Not appointed. Our processing of personal data of people in the EU and the UK is occasional and unlikely to result in a risk to them, so a representative is not required (Article 27(2) of the GDPR and of the UK GDPR). We will review this as our work in those regions grows.

2. Scope of this policy

This policy covers personal data we receive through this website: through the contact form and the partner program application form, in email sent to the addresses published on this website, in job applications, and in the business correspondence that follows.

It does not cover personal data we handle while delivering services to a client. That data is governed by the agreement with the client. Our roles in that situation are described on the Data Protection page.

3. Personal data we collect

We collect personal data in two ways: information you choose to send us, and limited technical information recorded by our hosting provider when any page is requested.

Information you give us

The contact form asks for the following fields. We ask you not to include sensitive personal data, passwords or confidential security details in the message field.

  • Name
  • Work email address
  • Company
  • Country or region
  • Area of interest
  • Message

Partner program applications

The partner program application form asks for the following. We use it to assess your application, to reply to you and to keep a record of our correspondence.

  • Name
  • Work email address
  • Company and your role
  • Country or region
  • Company website
  • The type of partnership and the areas you are interested in
  • The opportunity you describe and any message

Email to the addresses on this website

If you write to one of the addresses published on this website (contact@onioninfosec.com, sales@onioninfosec.com, partner@onioninfosec.com, careers@onioninfosec.com, privacy@onioninfosec.com, security@onioninfosec.com, legal@onioninfosec.com or grievance@onioninfosec.com), we receive your email address, your name as it appears in the message, what you write and any attachments.

Job applications

If you apply for a role, by writing to careers@onioninfosec.com or by choosing Careers on the contact form, we receive what you choose to send: usually your name, contact details, CV, work history, qualifications and links to your work. Please do not send identity documents, financial details or other sensitive personal data with an application.

Information recorded automatically

The website is hosted on Microsoft Azure Static Web Apps. The hosting platform and the function that receives form submissions may record standard log data for each request, such as IP address, date and time, the page or function requested, the referring address and the browser user agent. We do not combine this data with form submissions to build profiles.

Where these logs are available to us, we keep them for one year. We use them to detect, investigate and fix misuse and security incidents, and we keep them because Indian law requires organizations to keep logs of their systems.

Spam checks on the contact form

The contact form uses a hidden field and a timing check to filter automated submissions, and limits how many submissions one IP address can send in a short period. The IP address is held in memory only for that check and is not stored. These checks run in our own server function on this domain. The form does not use a CAPTCHA, does not load a third-party script and does not set a cookie.

What this website does not collect

The website is built without the following technologies.

  • Cookies of any kind
  • Analytics or usage measurement tools
  • Advertising trackers, pixels or retargeting tags
  • Third-party fonts, embedded media or social widgets. Fonts are hosted on this domain, and the links to our LinkedIn and Instagram pages are plain links: nothing loads from those platforms until you follow a link, and their own privacy policies then apply.
  • Browser local storage or session storage
  • Device fingerprinting

We use personal data only for the purposes below. We do not use it for automated decisions that produce legal or similarly significant effects, and we do not use it for profiling.

  • To read and respond to your enquiry and to discuss the services or products you asked about.
  • To take steps, at your request, before entering into a contract with you or your organization.
  • To assess an application to our partner program.
  • To consider your application for a role and, only if you agree, for future roles.
  • To keep a record of business correspondence.
  • To protect the website and the contact form against spam, abuse and security incidents.
  • To meet legal and regulatory obligations and to establish, exercise or defend legal claims.

Legal bases under the GDPR and UK GDPR

Where the GDPR or UK GDPR applies, we rely on the legal bases listed here.

  • Legitimate interests: responding to business enquiries, keeping records of correspondence and protecting the website. You can object to this processing at any time.
  • Steps before a contract: where you ask us for a proposal or to begin an engagement.
  • Legal obligation: where a law that applies to us requires us to keep or disclose information.
  • Consent: where we ask for it for a specific purpose, such as keeping your job application for future roles. You can withdraw consent at any time.

Grounds under the DPDP Act

Where the DPDP Act applies, we process personal data on the basis of your consent, or for a legitimate use recognized by the Act, such as where you voluntarily provide personal data for a specified purpose. The notice shown with each form on this website says what we use your details for and links to this policy, which describes the data, the purposes and how to exercise your rights.

Marketing

We do not use personal data from enquiries, partner program applications or job applications for marketing. Contacting us does not add you to a mailing list.

5. Who we share personal data with

We do not sell personal data. We do not share it for advertising. We use a small number of service providers that process personal data on our behalf and under our instructions.

  • Microsoft Azure: hosting of the website and of the server function that receives form submissions.
  • Google (Google Workspace): our business email system. Form submissions are delivered to our mailboxes through it, and enquiries, applications and correspondence are received and stored in it.

Other disclosures

We may also disclose personal data in the following limited situations.

  • To professional advisers, such as lawyers and auditors, who are bound by duties of confidentiality.
  • To courts, regulators or law enforcement bodies where the law requires it.
  • To a successor entity in a merger, acquisition or reorganization, subject to the commitments in this policy.

6. International transfers

Onion Infosec is based in India. When you submit a form or write to us, your information is sent to and processed in India and in the locations where our service providers operate. Microsoft and Google operate data centres in many countries, including outside India.

These locations may have data protection laws that differ from the laws where you live. Microsoft and Google provide contractual safeguards for international transfers in their data processing terms, including the European Commission’s standard contractual clauses. Where the law that applies to you requires a transfer mechanism, we rely on those terms.

You can ask us for more information about the safeguards that apply to your personal data through the Privacy Requests page.

7. How long we keep personal data

We keep personal data only for as long as it is needed for the purposes in section 4, and then delete it or remove the details that identify you.

  • Enquiries and partner program applications that do not lead to an engagement: 24 months after our last contact with you.
  • Job applications: 12 months from receipt. We keep an application for future roles only if you agree to it.
  • Correspondence connected to an engagement: for the period required by the engagement agreement and the law that applies.
  • Server and form-function logs: one year.

8. How we protect personal data

The website is a static site with no database behind it. Traffic is encrypted in transit. The contact form posts to a function on this domain, and submissions are delivered to our team by email. Access to hosting and to the mailboxes that receive enquiries is limited to the people who need it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. More detail is on the Security page.

9. Your rights by region

Your rights depend on the law that applies to you. We describe the main regimes below. Whichever law applies, we will consider any reasonable request about your personal data. We do not treat you differently for exercising a right.

European Economic Area and United Kingdom (GDPR and UK GDPR)

Where the GDPR or UK GDPR applies, you have the right to:

  • be told how your personal data is used, which is the purpose of this policy
  • access your personal data and receive a copy
  • have inaccurate or incomplete personal data corrected
  • have personal data erased in certain circumstances
  • restrict processing in certain circumstances
  • object to processing that is based on legitimate interests
  • receive personal data you provided in a portable format, where this right applies
  • withdraw consent at any time, without affecting processing that took place before withdrawal
  • complain to the data protection supervisory authority where you live or work, or to the UK Information Commissioner’s Office

India (IT Act, SPDI Rules and DPDP Act)

Under the IT Act and the SPDI Rules, which apply today, you can review the personal data you have given us and ask us to correct it, withdraw consent you have given, and raise a grievance with our Grievance Officer, Vivek P, grievance@onioninfosec.com. We resolve grievances within one month of receipt.

As the provisions of the DPDP Act come into force, you will also have the right to:

  • obtain a summary of the personal data we process about you and of the processing activities
  • have personal data corrected, completed, updated or erased
  • withdraw consent as easily as it was given
  • have a grievance addressed by our Grievance Officer, Vivek P, grievance@onioninfosec.com
  • nominate another person to exercise your rights in the event of death or incapacity
  • complain to the Data Protection Board of India after first using our grievance process

California (CCPA and CPRA)

Onion Infosec does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act. We do not use sensitive personal information to infer characteristics about you.

That law applies only to businesses that meet certain thresholds. Where it applies to us, California residents have the right to:

  • know what personal information we collect, use and disclose, and receive the specific pieces we hold
  • have personal information deleted, subject to legal exceptions
  • have inaccurate personal information corrected
  • opt out of sale or sharing, which we do not carry out
  • not be retaliated against for exercising these rights
  • use an authorized agent to submit a request

Other regions

If you live elsewhere, the law where you live may give you similar rights. You can send us a request from any country and we will respond under the law that applies to you.

10. How to make a request

The Privacy Requests page explains what you can ask for, how to send a request, how we confirm your identity and how to complain if you are not satisfied with our response.

11. Children

This website is written for business readers. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, tell us through the contact page and we will delete it.

12. Changes to this policy

We will update this policy when the website or our use of personal data changes. The date it was last updated appears at the top of the page. If a change materially affects how we use personal data already collected, we will take reasonable steps to tell the people affected.

13. Contact

Questions about this policy can be sent to privacy@onioninfosec.com or through the contact page.

Grievance Officer (India): Vivek P, grievance@onioninfosec.com.

Onion Information Security Solutions Private Limited, 1st Floor, 1B-102, Parinee Crescenzo, G Block, Bandra Kurla Complex, Bandra East, Mumbai, Maharashtra 400051, India. Corporate Identity Number U62099MH2025PTC443498.