Last Updated: January 2026
CtrlSec ("Company", "we", "us") provides structured cybersecurity infrastructure, including vulnerability disclosure and security collaboration platforms. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with applicable laws including GDPR, India’s DPDP Act, CCPA, and other global regulations.
We process data under the following legal bases:
Personal data is retained only as long as necessary for service delivery, compliance obligations, or legitimate business needs. Security logs may be retained longer where required for cybersecurity auditing.
We implement industry-standard technical and organizational safeguards aligned with ISO 27001 principles, including encryption, access control, monitoring, and incident response.
Where data is transferred internationally, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent lawful mechanisms.
We use strictly necessary cookies for platform operation. Non-essential cookies (analytics, marketing, personalization) are processed only after explicit user consent.
For privacy inquiries: founders@ctrlsec.io