Contents
1.Introduction
SQ1 Security ("SQ1", "we", "us", "our") provides AI-driven cybersecurity and compliance products and services, including our Scani5, Stakflo and Udaxo platforms, and services such as Security Operations Centre as a Service (SOC-as-a-Service), penetration testing, vulnerability management, application security, cloud security, AI security, compliance and privacy services, and virtual CISO advisory.
Privacy and security are fundamental to our business, not an afterthought. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we retain it, and the rights available to you.
This Policy is designed to meet our obligations under:
- The EU General Data Protection Regulation (GDPR) and the UK GDPR and Data Protection Act 2018.
- The California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), and comparable US state privacy laws.
- India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.
Region-specific disclosures are set out in the Annexes, which prevail over the main body of this Policy for individuals in those regions.
2.Scope of this Policy
This Policy applies to personal data we process as a controller (a "Data Fiduciary" under the DPDP Act; a "business" under the CCPA), including personal data collected through:
- Our website at https://sq1.security and its subdomains.
- Enquiry, demo request and contact forms.
- Marketing activities, events, webinars, blog, and news resources.
- Our recruitment and careers process.
- Administration of customer, partner and supplier relationships.
- Account administration and support for our products and services.
This Policy does not apply to personal data contained within customer environments that we process on our customers' instructions when delivering our products and services. Please see Section 3.
3.When we act as a processor, not a controller
A significant part of what we do involves handling data belonging to our customers. When you use Scani5, Stakflo or Udaxo, or engage us for SOC-as-a-Service, vulnerability management, penetration testing, incident response or similar services, we process security telemetry, logs, alerts, scan output, configuration data, identity records and incident artefacts from your environment. This information may contain personal data, including usernames, email addresses, IP addresses, device identifiers, and endpoint activity.
In relation to that data:
- Our customer acts as the controller, Data Fiduciary, or business, as applicable.
- SQ1 acts as the processor, Data Processor, or service provider, as applicable.
- Our processing activities are governed by the applicable customer agreement and the Data Processing Addendum (DPA), rather than by this Privacy Policy.
- We process such data only in accordance with the customer's documented instructions, except where processing is required by applicable law.
If you are an employee, contractor or end user of one of our customers and you want to exercise privacy rights over data held in that customer's environment, please contact that organisation directly. We will assist our customer in responding, as required by our contract with them.
4.Who we are and who is responsible for your data
SQ1 operates through the following entities:
| Entity | Registered/principal offices | Typically the controller for |
|---|---|---|
| SQ1 Security Infotech, Inc. | 84 W Santa Clara St, 7th Floor, San Jose, CA 95113, USA | Individuals and customers located in the United States and the Americas |
| SQ1 Security UK Private Limited | Office Gold, Building 7, Floor 5, 566 Chiswick High Road, Chiswick Business Park, London W4 5YG, United Kingdom | Individuals and customers located in the United Kingdom and, where applicable, the European Economic Area (EEA) |
| SQ1 Security Technology Pvt Ltd | Futura Tech Park, 2nd Floor, Block B, 334 Rajiv Gandhi Salai, Sholinganallur, OMR, Chennai 600119, India | Individuals and customers located in India and the rest of the world |
| SQ1 Security Technology Pvt Ltd | Zed Pinnacle No. 77/A, Suite #004, Koramangala Industrial Layout, Koramangala, Bengaluru 560095, India | Individuals and customers located in India and the rest of the world |
Where you have entered into a contract with a specific SQ1 entity, that entity acts as the controller of your personal data.
Where you interact solely with our website, marketing activities, or other pre-contractual services, the controller will generally be the SQ1 entity responsible for your region, as described above.
The SQ1 entities may share personal data with one another for the purposes described in this Privacy Policy, including service delivery, customer support, sales, administration, security, and compliance, as further described in Section 9.
Privacy contact: [email protected]
5.Personal data we collect
- Device and browser information (browser type and version, operating system, screen settings, language)
- IP address and approximate location derived from it (typically city/country level)
- Pages viewed, time on page, referring URL, exit pages, and clickstream
- Cookie and similar identifiers, and your cookie preferences
- Security and abuse-prevention signals (such as request patterns, bot detection signals, and web application firewall (WAF) logs)
When you contact us through our contact forms or related channels, we may collect:
- First name and last name
- Work email address
- Company name
- Enquiry type (Security Services, Compliance Services, Schedule a Demo, Careers/HR, General Enquiry)
- The content of your message and any subsequent correspondence
- Job title, phone number and other business contact details where you provide them
- Records of meetings, demos and calls, and notes made by our team
- Account and user profile details: name, business email, phone number, job title, organisation, role and permissions
- Authentication data: credentials, single sign-on identifiers, multi-factor authentication data, session and device information
- Product usage and audit logs: sign-in records, actions taken in the platform, configuration changes, feature usage
- Support and service data: tickets, chat transcripts, correspondence, screen recordings where you provide them
- Billing and contract administration data: purchase orders, invoicing contacts, payment status
When delivering managed security, vulnerability management, penetration testing and incident response services, we process logs, alerts, scan results, asset inventories, vulnerability findings, identity and access records and incident artefacts. These may contain personal data. As explained in Section 3, we generally handle this as a processor on our customer's behalf.
Where we process such data as a controller — for example to secure our own infrastructure, to maintain our own service records, or to generate threat intelligence and improve our detection capabilities — we do so as described in Section 7 and only to the extent permitted by our customer agreements.
We continuously improve the detection, prioritisation and response capabilities in Scani5, Stakflo and Udaxo.
To do this, we may derive aggregated and de-identified datasets from security telemetry, detections, vulnerability findings and incident outcomes across our customer base — for example attack patterns, indicators of compromise, false-positive rates, remediation timelines and model performance metrics.
Before any such data is used for this purpose:
- Direct and indirect identifiers are removed or irreversibly transformed, including names, email addresses, usernames, IP addresses, hostnames, device identifiers, account identifiers and customer-identifying metadata.
- Data is aggregated so that it does not relate to, and cannot reasonably be used to identify, any individual, household or customer.
- We apply technical and organisational measures to prevent re-identification, and we do not attempt to re-identify the data.
- We contractually prohibit our personnel and service providers from attempting re-identification.
- We do not use identifiable customer content, identifiable personal data, or an individual customer's data in isolation to train models deployed for other customers.
Once data has been aggregated and de-identified to this standard it is no longer personal data, and this Policy does not apply to it. Our handling of customer data for this purpose is also subject to the terms of the applicable Data Processing Addendum (DPA).
- Name, contact details, location
- CV/résumé, cover letter, work history, education, qualifications, certifications
- Right-to-work and immigration status information
- Interview notes, assessment and test results
- References
- Background verification and screening results, where permitted by law and separately notified to you
- Diversity information, where you choose to provide it and where permitted by local law (provided voluntarily and used only in aggregate)
We may collect:
- Business contact details, role and organisation
- Contract, procurement, due diligence and payment records
- Security and compliance assessment responses
We may collect:
- Registration information
- Attendance records
- Questions submitted during events
- Feedback
We do not intentionally collect special category data under Article 9 of the GDPR or sensitive personal information in the ordinary course of our business.
Limited exceptions may arise in recruitment and employment contexts, such as health information required for interview accommodations or government-issued identifiers used for right-to-work verification and background checks.
Account credentials and precise geolocation, where collected, are treated as sensitive personal information under the CCPA. Please refer to Annex B for further details.
We do not use or disclose sensitive personal information for purposes other than those permitted under Section 7027(m) of the CCPA regulations.
6.How we collect personal data
- Directly from you — forms, email, calls, meetings, contracts, product sign-up, job applications.
- Automatically — cookies, tags, server logs, product telemetry, security monitoring. See Section 8.
- From third parties — our customers (where you are their personnel), channel and technology partners, referrers, publicly available sources, professional networks such as LinkedIn, business data enrichment providers, background screening vendors, and fraud and security intelligence providers.
7.Why we use personal data, and our legal bases
| S.no | Purpose | Data used | GDPR / UK GDPR legal basis | DPDP basis |
|---|---|---|---|---|
| 1 | Respond to enquiries, demo requests and sales conversations | 5.2 | Steps at your request prior to entering a contract (Art. 6(1)(b)); legitimate interests in responding to business enquiries (Art. 6(1)(f)) | Consent, or legitimate use where you have voluntarily provided data for this purpose |
| 2 | Provide, administer, and support our products and services | 5.3, 5.4 | Performance of a contract (Art. 6(1)(b)); legitimate interests where you are a contact of a corporate customer (Art. 6(1)(f)) | Performance of a contract with your employer/consent |
| 3 | Service, security, and administrative communications | 5.2, 5.3 | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | Legitimate use |
| 4 | Marketing communications, events, and content | 5.2, 5.7 | Consent (Art. 6(1)(a)) where required; otherwise, legitimate interests in B2B marketing (Art. 6(1)(f)) | Consent |
| 5 | Website analytics, product improvement, and personalisation | 5.1, 5.3 | Consent for non-essential cookies; legitimate interests for aggregate analysis (Art. 6(1)(f)) | Consent |
| 6 | Securing our own systems, preventing fraud and abuse, and investigating incidents | 5.1, 5.3, 5.4 | Legitimate interests in network and information security (Art. 6(1)(f), Recital 49); legal obligation (Art. 6(1)(c)) | Legitimate use — for security, prevention and detection of unlawful activity |
| 7 | Developing, testing and improving our products, including our AI/ML detection and prioritisation models | Aggregated and de-identified datasets derived from 5.1, 5.3 and 5.4 (see 5.4.1) | Legitimate interests (Art. 6(1)(f)) for the act of aggregating and de-identifying; once anonymised, the GDPR no longer applies to the resulting dataset | Legitimate use for the act of de-identification; the DPDP Act does not apply to the resulting non-personal dataset |
| 8 | Recruitment and hiring | 5.5 | Steps prior to entering a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)); consent for talent pool retention; Art. 9(2)(b) where special category data is processed for employment law purposes | Legitimate use — employment purposes |
| 9 | Managing partner and supplier relationships | 5.6 | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | Contract / legitimate use |
| 10 | Legal and regulatory compliance, audits, certifications, and responding to lawful requests | All | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) | Compliance with law |
| 11 | Establishing, exercising, or defending legal claims | All | Legitimate interests (Art. 6(1)(f)); legal claims exemption (Art. 9(2)(f)) | Compliance with law/enforcement of legal rights |
| 12 | Corporate transactions (merger, acquisition, financing, restructuring) | All | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
Where we rely on legitimate interests, we have carried out a balancing assessment. You may request a summary of the relevant assessment using the contacts in Section 19.
We do not use your personal data for purposes materially different from those described here without first providing notice and, where required, obtaining your consent.
10.International transfers of personal data
We operate globally. As a result, personal data may be transferred to, stored in, or accessed from the United States, the United Kingdom, India, and other countries in which our group companies or service providers operate.
Where we transfer personal data outside the EEA or the United Kingdom to a country that is not subject to an adequacy decision, we rely on appropriate safeguards, including:
- The European Commission's Standard Contractual Clauses (SCCs) (Decision 2021/914) for EEA transfers
- The UK International Data Transfer Addendum (UK Addendum) or the UK International Data Transfer Agreement (IDTA), as applicable, for transfers from the United Kingdom; and
- Transfer impact assessments and, where appropriate, supplementary technical, organisational, and contractual measures such as encryption, access controls and government-request transparency commitments.
Transfers of personal data outside India are made in accordance with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025, subject to any restrictions notified by the Central Government and to any sector-specific requirements applicable to our customers.
You may request information about the safeguards we rely upon by contacting us using the details provided in Section 19. Where appropriate, copies of the Standard Contractual Clauses may be redacted to protect confidential commercial information.
11.How long we keep personal data
We retain personal data only for as long as necessary to fulfil the purposes described in Section 7, after which it is securely deleted or irreversibly anonymised.
Our indicative retention periods are as follows:
| Data | Retention |
|---|---|
| Website enquiry and contact form submissions | 24 Months from last interaction |
| Marketing contacts and subscriptions | Until you unsubscribe or withdraw your consent, after which we retain a suppression record indefinitely to honour your opt-out request |
| Customer contract and account records | The duration of the contract plus seven (7) years for tax, audit, and limitation period requirements |
| Product usage and audit logs | 12 months, or as specified in the applicable customer agreement. Certain logs may be retained for one year in accordance with Rule 6 of the DPDP Rules, 2025 |
| Security monitoring and incident records | 24 months, or longer where required for an ongoing investigation, legal claim, or regulatory matter |
| Unsuccessful job applicants | 12 months, or longer where you have consented to inclusion in our talent pool |
| Supplier and partner records | The duration of the relationship plus seven (7) years |
| Cookie data | As described in our Cookie Policy |
Where we are legally required to retain personal data for a longer period, or where it is relevant to an actual or anticipated legal claim, regulatory investigation, or audit, we will retain it for that extended period.
Customer data processed under a Data Processing Addendum (DPA) is retained and deleted in accordance with the terms of that DPA.
12.How we protect personal data
As a cybersecurity organisation, we apply the same high standards to protecting personal data that we recommend to our customers. Our security controls include:
- An information security management system aligned to ISO/IEC 27001, SOC 2 Type II.
- Encryption of personal data in transit (TLS) and at rest.
- Role-based access control, least-privilege access, and multi-factor authentication.
- Network segmentation, endpoint protection, logging and continuous monitoring.
- Secure development practices, code review and dependency management.
- Regular vulnerability scanning and independent penetration testing.
- Vendor security due diligence and contractual security obligations.
- Documented incident response and business continuity procedures.
- Personnel background screening (where lawful), confidentiality obligations and mandatory security and privacy training.
Although we implement robust security measures, no system can be guaranteed to be completely secure.
If we experience a personal data breach, we will notify the relevant supervisory authorities and affected individuals where required by applicable law. This includes:
- Notifying the competent supervisory authority within 72 hours where required under the GDPR and UK GDPR;
- Notifying the Data Protection Board of India without undue delay and affected Data Principals within the timeframes prescribed under the DPDP Rules, 2025; and
- Complying with applicable U.S. federal and state data breach notification requirements.
13.Your privacy rights
Depending on where you are located, you may have some or all of the following rights:
- Access — obtain confirmation of whether we process your personal data and a copy of it, together with information about the processing
- Rectification / correction — have inaccurate or incomplete data corrected or completed
- Erasure / deletion — have your personal data deleted in certain circumstances
- Restriction — restrict our processing in certain circumstances
- Portability — receive certain data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible
- Objection — object to processing based on legitimate interests, and object at any time to direct marketing
- Withdraw consent — withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Automated decision-making — not be subject to a decision based solely on automated processing that produces legal or similarly significant effects
- Opt out of sale, sharing and targeted advertising, and limit the use of sensitive personal information (U.S. states)
- Non-discrimination for exercising your rights
- Nominate another individual to exercise your rights in the event of death or incapacity (India)
- Grievance redressal (India)
- Complain to a supervisory authority or regulator
These rights are not absolute and are subject to the conditions, limitations, and exemptions set out in applicable law. Please refer to the relevant Annexes for region-specific information.
14.How to exercise your rights
You may submit a privacy rights request using any of the following methods:
- Email: [email protected]
- Web form: https://stakflo.io/data-subject-access-request
- Post: to the relevant entity address in Section 4
To protect your data, we will take reasonable steps to verify your identity before responding to a request. We may ask for information that allows us to match you with our records. Any information collected for verification purposes will be used solely for that purpose.
You may appoint an authorised agent to submit a request on your behalf. We may require written authorisation from you and may separately verify your identity before processing the request.
- EEA/UK: within one month of receipt, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month.
- California and other US states: we will acknowledge within 10 business days and respond within 45 calendar days, extendable by a further 45 days with notice.
- India: we will respond to rights requests within the periods prescribed under the DPDP Rules and will resolve grievances within a reasonable period not exceeding 90 days from receipt.
Requests are free of charge. However, where permitted by applicable law, we may charge a reasonable fee or decline to act on a request that is manifestly unfounded, excessive, or repetitive. Where this occurs, we will explain the reasons for our decision.
15.Children
Our website, products and services are directed at businesses and are not intended for children.
We do not knowingly collect personal data from individuals under the age of 16 in the EEA/UK (or the lower age set by an EEA member state, no lower than 13), or under 18 in India.
Under the DPDP Act, where we process the personal data of a child (an individual under 18 in India) or a person with a disability who has a lawful guardian, we obtain verifiable consent from the parent or lawful guardian. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Under the CCPA, we do not knowingly sell or share the personal information of consumers whom we know to be under the age of 16.
If you believe that a child has provided us with personal data, please contact us at [email protected], and we will take appropriate steps to delete the information.
16.Automated decision-making, profiling and AI
Our products use machine learning and automated analysis to detect anomalies, prioritise vulnerabilities, correlate security telemetry, assess risk, and orchestrate response activities. These systems operate on our customers' security data and are designed to analyse assets, events, and security risks rather than evaluate individuals.
We do not make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects concerning them.
We do use limited profiling for legitimate business purposes, such as segmenting business contacts by industry or engagement with our content. You have the right to object to such profiling at any time, where permitted by applicable law.
17.Third-party links and services
Our website may contain links to third-party websites and platforms, including LinkedIn, X, Instagram, and YouTube. We are not responsible for the privacy practices, content, or policies of those third parties. We encourage you to review their privacy policies before providing them with any personal data.
18.Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or regulatory requirements. The latest version will always be published on this page, and the "Last updated" date will be revised accordingly.
Where changes are material, we will provide appropriate notice and, where required by applicable law, obtain your consent before the changes take effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
19.How to contact us
If you have any questions about this Privacy Policy or our privacy practices, please contact us using the details below.
| Contact | Details |
|---|---|
| General privacy enquiries | [email protected] |
| Data Protection Officer | [email protected] |
| UK contact | SQ1 Security UK Private Limited, Office Gold, Building 7, Floor 5, 566 Chiswick High Road, Chiswick Business Park, London W4 5YG |
| Security vulnerability reports | [email protected] |
Additional information for individuals in the EEA and the United Kingdom
The controller is the relevant SQ1 entity identified in Section 4. For individuals in the United Kingdom, this will ordinarily be SQ1 Security UK Private Limited.
You have the rights listed in Section 13. In addition:
- Right to object to direct marketing is absolute. If you object, we will stop.
- Right to object to processing based on legitimate interests — we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims.
- Right to lodge a complaintyou may complain to your local supervisory authority. In the UK this is the Information Commissioner's Office (ICO), www.ico.org.uk, helpline 0303 123 1113. Within the EEA, a list of supervisory authorities is maintained by the European Data Protection Board. We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority.
Where we require your personal data to enter into or perform a contract with you, or to comply with a legal obligation, providing that data is mandatory. Failure to provide it may prevent us from delivering the relevant products or services.
Where we rely on your consent or our legitimate interests, providing your personal data is voluntary. We will inform you of the applicable legal basis at the point of collection.
Please refer to Section 10 for information about international transfers of personal data.
Additional information for residents of California and other US states
This Annex supplements the main Policy for residents of California under the CCPA, and — where applicable — residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Lowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws in force. It also serves as our Notice at Collection.
| CCPA category | Collected | Examples | Sources | Business purpose | Disclosed to |
|---|---|---|---|---|---|
| A. Identifiers | Yes | Name, work email, postal address, phone, IP address, account identifiers, cookie IDs | You automatically third parties | Sales, service delivery, support, marketing, security | Group companies service providers advisers |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes | Name, contact details, employment information, financial account information for billing | You customers | Contract administration, billing | Group companies; service providers payment providers |
| C. Protected classifications | Limited | Only where voluntarily provided in recruitment, and where lawful | You | Equal opportunity monitoring | Retained internally aggregated only |
| D. Commercial information | Yes | Products and services purchased or considered, contract history | You customers | Contract administration, account management | Group companies service providers |
| E. Biometric information | No | — | — | — | — |
| F. Internet or network activity | Yes | Browsing on our Site, interactions with content and emails, product usage logs | Automatically | Analytics, product improvement, security | Group companies analytics providers (as service providers) |
| G. Geolocation data | Yes (approximate) | City/country inferred from IP | Automatically | Localisation, security, analytics | Group companies service providers |
| H. Sensory data | Limited | Call and meeting recordings where notified and consented | You | Training, quality, record-keeping | Group companies service providers |
| I. Professional or employment information | Yes | Job title, employer, work history, CV, references, screening results | You third parties | Sales, recruitment | Group companies recruitment vendors |
| J. Education information | Yes (applicants) | Degrees, certifications | You verification vendors | Recruitment | Group companies screening vendors |
| K. Inferences | Yes | Preferences, likely interest in products, segmentation | Derived | Marketing, product improvement | Group companies marketing providers |
| L. Sensitive personal information | Yes (limited) | Account log-in credentials government identifiers and immigration status in recruitment | You | Account security legal compliance | Group companies service providers |
Retention: see Section 11.
We do not sell personal information, and we have not sold personal information in the preceding 12 months. We do not sell personal information in exchange for monetary or other valuable consideration.
We do not share personal information for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not place third-party advertising pixels or tags on our Site, and we do not disclose personal information to advertising networks, data brokers or ad-tech intermediaries.
Because we neither sell nor share personal information, no "Do Not Sell or Share My Personal Information" link is required on our Site. We nonetheless honour Global Privacy Control (GPC) signals in respect of non-essential cookies.
We do not sell or share the personal information of consumers we know to be under 16 years of age.
Disclosures we make to our service providers and contractors — such as cloud hosting, analytics, CRM and support providers, as listed in Section 9 — are made for the business purposes described in Section 7 under written contracts that prohibit those providers from retaining, using or disclosing the personal information for any other purpose. Under the CCPA, these disclosures are not sales or shares.
- Right to know the categories and specific pieces of personal information we collected, the sources, purposes, and the categories of third parties to whom we disclosed it (covering the preceding 12 months, and beyond 12 months on request unless it would be impossible or involve disproportionate effort)
- Right to delete personal information, subject to statutory exceptions
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use and disclosure of sensitive personal information
- Right to non-discrimination — we will not deny goods or services, charge different prices, or provide a different level of quality because you exercised your rights
- Right to use an authorised agent
Residents of certain other states additionally have the right to opt out of targeted advertising and of profiling in furtherance of decisions producing legal or similarly significant effects. As explained in B.2 and Section 16, we do not engage in targeted advertising, and we do not carry out profiling that produces legal or similarly significant effects concerning you, so there is currently nothing to opt out of. We will update this Annex if that changes.
Residents of those states also have the right to appeal a refusal of a rights request. To appeal, reply to our decision or contact [email protected] with "Privacy Appeal" in the subject line. We will respond within 45 days (60 days in some states). If your appeal is denied, you may contact your state Attorney General.
Where a state law requires a data protection assessment for certain processing activities, we conduct and document those assessments as required.
See Section 14. We provide at least two designated methods: email and web form.
California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
Additional information for Data Principals in India
This Annex applies to individuals whose personal data is processed under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
SQ1 Security Technology Pvt Ltd acts as a Data Fiduciary for the personal data described in Section 5 that it determines the purpose and means of processing for. Where we process personal data on the instructions of a customer, we act as a Data Processor — see Section 3.
Where we rely on your consent, we provide a clear, standalone notice in plain language, available in English and in the languages specified in the Eighth Schedule to the Constitution of India on request, setting out:
- the personal data being collected and the specific purpose of processing;
- the goods, services or uses enabled by that processing;
- how you may withdraw consent, with the same ease as giving it;
- how you may exercise your rights;
- how you may make a complaint to the Data Protection Board of India.
Your consent is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the personal data necessary for the stated purpose.
Withdrawing consent is as easy as giving it and can be done at [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal. Following withdrawal, we will cease processing and cause our Data Processors to do the same, unless retention is required by law.
Where applicable, we process personal data for "legitimate uses" under Section 7 of the DPDP Act without consent, including where you have voluntarily provided data for a specified purpose, for employment purposes, for compliance with law, and to respond to a medical emergency or threat to public health or safety.
- Right to access information about the personal data we process, a summary of processing activities, and the identities of other Data Fiduciaries and Data Processors with whom it has been shared
- Right to correction, completion, updating and erasure of your personal data
- Right to grievance redressal — you must first raise a grievance with us before approaching the Data Protection Board
- Right to nominate one or more individuals to exercise your rights in the event of your death or incapacity
- Right to withdraw consent at any time
| Contact | Details |
|---|---|
| Grievance Officer Email | [email protected] |
| Address | SQ1 Security Technology Pvt Ltd, Futura Tech Park, 2nd Floor, Block B, 334 Rajiv Gandhi Salai, Sholinganallur, OMR, Chennai 600119, India |
We will acknowledge your grievance, issue a tracking reference, and respond within a reasonable period not exceeding 90 days from receipt. If you are not satisfied with our response, or do not receive a response within that period, you may make a complaint to the Data Protection Board of India.
The DPDP Act places duties on Data Principals, including to comply with applicable law when exercising rights, not to impersonate another person, not to suppress material information when providing personal data for a document or identifier, not to register a false or frivolous grievance or complaint, and to furnish only authentic information when seeking correction or erasure. Breach of these duties may attract a penalty of up to ₹10,000.
We do not process the personal data of children (individuals under 18 in India) without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring of children, or targeted advertising directed at children.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with Rule 7 of the DPDP Rules, 2025, including notification to affected Data Principals within 72 hours.
Please refer to Section 10 for information about cross-border transfers of personal data.

