L/09Legal
Privacy Requests
You can ask us about the personal data we hold about you from any country. This page explains what you can request, how to send a request, how we confirm your identity and how to complain.
- Document
- Privacy Requests
- Last updated
- 22 September 2026
- Applies to
- www.onioninfosec.com
On this page
1. What you can request
The rights available to you depend on the law that applies to you. They are described by region in the Privacy Policy. You can ask us for any of the following.
- Access: confirmation of whether we hold personal data about you, and a copy or summary of it.
- Correction: to correct, complete or update personal data that is inaccurate or out of date.
- Deletion: to erase your personal data, subject to any legal duty we have to keep it.
- Withdrawal of consent: where we rely on your consent. Withdrawal does not affect earlier processing.
- Objection or restriction: to object to processing based on legitimate interests, or to ask us to restrict processing.
- Portability: a copy of personal data you provided in a commonly used format, where this right applies.
- Grievance (India): to raise a grievance with our Grievance Officer. As the DPDP Act comes into force, you can also nominate a person to act for you.
- Appeal: to ask us to reconsider a request we have declined. Some laws give you a formal right of appeal.
2. How to submit a request
You can send a request in either of these ways.
- Use the contact page and select "Privacy request" as the area of interest.
- Write to privacy@onioninfosec.com.
What to include
- Your name and the email address you used when you contacted us
- The right you want to exercise and the data it relates to
- The country or region where you live, so that we can apply the correct law
- If you act for someone else, evidence of your authority to do so
Grievance officer
Grievances in India, under the IT Act and the SPDI Rules and under the DPDP Act as it comes into force, can be addressed to our Grievance Officer, Vivek P, grievance@onioninfosec.com. We resolve grievances within one month of receipt.
3. How we confirm your identity
We need to be reasonably sure that a request comes from the person the data relates to, or from someone authorized to act for them. In most cases we do this by replying to the email address already associated with your enquiry.
If that is not possible, we may ask for limited further information. We ask only for what is needed, use it only to verify the request and do not ask for identity documents unless there is no reasonable alternative.
4. Response timelines
We respond within the period required by the law that applies to you. Grievances raised with our Grievance Officer are resolved within one month of receipt. We aim to answer other requests within 30 days. If a request is complex and the law allows an extension, we will tell you and explain why.
5. Fees
We do not charge a fee in normal cases. Where the law allows, we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive or repetitive. We will explain our reasons if we do.
6. If we cannot act on a request
Sometimes we cannot do what you ask, for example where a law requires us to keep a record, or where the request would expose another person’s data. If so, we will tell you why, to the extent the law allows, and explain how you can ask us to reconsider.
7. Data we process for clients
If your request concerns personal data that we process on behalf of a client, the client is responsible for responding. We will pass your request to the client or tell you whom to contact. See Data Protection.
8. Your right to complain
We would like the chance to resolve your concern first, but you can complain to a regulator where the law gives you that right.
- European Economic Area: the data protection supervisory authority in the country where you live or work, or where you believe a breach occurred.
- United Kingdom: the Information Commissioner’s Office.
- India: the Data Protection Board of India, after first using our grievance process.
- California: the California Privacy Protection Agency or the California Attorney General, where the law applies.
- Elsewhere: the privacy or data protection regulator in your country.
