🚀 Introducing the CloudSEK MCP Server!
Read more
At CloudSEK along with its affiliates and subsidiaries (“CloudSEK”, “We” or “Us”), the privacy and confidentiality of Personally Identifiable Information (PII) shared with Us is handled with utmost care and respect. This privacy policy (“Policy”) describes how your information is collected, used and disclosed by CloudSEK and its subsidiaries, and applies to information we collect when you use the Website, Content, App, Platform, or otherwise interact with Us (collectively, the “Services”).
The CloudSEK entity responsible for your personal data (the data controller / Data Fiduciary) is the CloudSEK group company that provides the Services to you, as identified in your agreement with us or otherwise applicable to your region. A current list of CloudSEK entities and their registered addresses is available at cloudsek.com/contact. For data principals in India, the responsible Data Fiduciary is CloudSEK Information Security Private Limited. If you are a corporate entity, references to “you” and “your” include your employees, representatives and agents. If you do not agree with our practices, your choice is not to use the Services.
Where our processing relies on your consent, we obtain that consent as described in the “Your Consent” section below, and you may withdraw it at any time. Where we rely on another lawful basis, that basis is described in “How We Use Your Information”.
We may update this Policy from time to time to reflect changes in our practices, our Services, or applicable law. The date it was last revised is indicated at the top. Where a change introduces a new purpose for processing your personal data or otherwise changes the lawful basis on which we rely, we will notify you of that change and, where our processing depends on your consent, obtain your fresh consent before relying on the new purpose or basis. For other updates, we encourage you to review this Policy periodically.
You may provide personal information to Us by completing web forms, by email, by creating an account to access the App or Platform, and by communicating with Us. Contact information such as name, email address and/or phone number is typically provided by you. By providing this information, you represent that you are the owner or are authorized to provide it.
We use cookies and similar technologies to monitor use of the Website. Non-essential cookies are set only with your consent where required by law. Neither We nor third parties acting on our behalf use cookies to automatically retrieve personal data from your computer. For more detail on the cookies we use and how to manage your preferences, please see our Cookies Policy.
We use the information collected only for specified purposes and only where we have a lawful basis to do so. Depending on the interaction and your location, that basis may be your consent, the performance of a contract with you, compliance with a legal obligation, or another basis permitted by the data protection laws applicable to you. Where we rely on your consent, you may withdraw it at any time as described in the “Your Consent” section. The purposes for which we use your information are:
We will not use your personal data for a new purpose that is incompatible with those specified above without first providing notice and, where required, obtaining your consent.
Where we rely on your consent, we request it through a clear affirmative action, separately for each distinct purpose, in plain language, at or before the time of collection. We do not use pre-ticked boxes and we do not bundle unrelated purposes into a single consent.
You may withdraw your consent at any time, and doing so is as easy as giving it through your account settings, the unsubscribe link in our emails, our cookie controls, or by contacting our Data Protection Officer. Withdrawal does not affect processing carried out before withdrawal, and certain Services may become unavailable.
The information collected by Us may be sent to and stored on servers located in the United States and/or other countries. We make appropriate arrangements to ensure your data is processed securely and in compliance with applicable data protection laws. For transfers originating in the EEA or the UK, we rely on adequacy decisions or Standard Contractual Clauses (with the UK Addendum where relevant) and apply appropriate safeguards. For data principals in India, transfers are permitted except to any country restricted by the Central Government; we monitor the restricted-country list and adjust our transfers accordingly.
CloudSEK is ISO/IEC 27001 and ISO 22301 certified and GDPR compliant, and maintains its programme in alignment with SOC 2 and India’s DPDP Act. The security of your PII is of utmost importance to Us. We have implemented reasonable and appropriate physical, administrative and technical safeguards - including encryption, access controls, logging and monitoring, and secure backups - designed to protect your personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. When the purpose has been served, or where you withdraw consent and no other lawful basis applies, we erase or anonymize your personal data, unless retention is required by law. Upon termination of your account, your personal data is destroyed or anonymized from our records and systems, subject to any legally required retention period. Where data cannot be immediately deleted (for example, in secure backups), we isolate it from further use until deletion is possible.
Depending on where you are located and the applicable laws, you may have the following rights. To exercise them, please contact Us using the details in “Contact Us”; we may verify your identity and will respond within the timeline required by law.
a. Right to access: to request access to, and a copy of, the personal data we hold about you.
b. Right to correction: to have inaccurate or incomplete data corrected or completed.
c. Right to erasure: to request deletion of your personal data, subject to legal-retention exceptions.
d. Right to withdraw consent: where processing is based on consent, to withdraw it at any time, as easily as it was given.
e. Right to grievance redressal: to a readily available means of raising a grievance with Us, to which we will respond within the prescribed period.
f. Right to nominate (India): to nominate another individual to exercise your rights in the event of your incapacity or demise.
g. Right to complain to a data protection authority: if your grievance is not satisfactorily resolved, you may complain to the data protection authority responsible for your region - such as the Data Protection Board of India, or, in the EEA or UK, your local supervisory authority (or the UK Information Commissioner’s Office).
h. Additional rights (EEA/UK): data portability, and restriction of or objection to processing (including direct marketing and profiling).
We recognize the importance of children’s safety and privacy. Our Services are directed to businesses and are not intended for children. We do not knowingly process the personal data of any individual under the age of 18 without the verifiable consent of a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that we have collected personal data from a person under 18 without such consent, we will take steps to delete it. If you believe a child has provided Us with personal data, please contact our Data Protection Officer, whose contact details are provided below.
In the event of a personal data breach, We will respond in line with our incident-response procedures. We will take prompt steps to contain and assess the breach and, where notification is required by the laws applicable to you, notify the relevant data protection authority and affected individuals without undue delay after becoming aware of the breach - and, for notification to the relevant authority, within 72 hours where that timeframe applies. Our notification will include the information required by law, such as the nature of the breach, its likely consequences, the measures taken, and how to contact us.
To reach Us regarding a breach, please contact our Data Protection Officer, whose contact details are provided below.
We gather certain information automatically and store it in log files, including IP addresses, browser type, ISP, referring/exit pages, operating system and clickstream data. We use tools such as Google Analytics - with your consent where required - to evaluate usage of our Site and improve our Services. This may link automatically collected data to personally identifiable information.
The Website may contain links to other websites. We are not responsible for the privacy practices of any websites other than our own. We encourage you to review the privacy statements of any such websites.
If you have questions or concerns regarding this Policy, please contact our Legal Department at [email protected].
‍
Data Protection Officer: Rahul Sasi · [email protected]
Our office addresses and CloudSEK entities are available at cloudsek.com/contact.