Privacy Policy

Learn how Vinca Cyber collects, protects, processes, and respects your personal data in alignment with the Digital Personal Data Protection Act (DPDP Act 2023) and global security best practices.

Data Protection & PrivacyLast Updated: September 30, 2026

At Vinca Cyber, cyber resilience and data protection are fundamental to who we are. This Privacy Policy details our transparent practices regarding the collection, processing, safeguarding, and retention of personal information across our website and communication channels, in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and international data protection norms.

01.Introduction & Scope

Vinca Cyber (“Vinca Cyber”, “we”, “us”, or “our”) was founded by cybersecurity and IT infrastructure practitioners who spent their careers protecting enterprise environments. We provide comprehensive cyber resilience solutions, including 24/7 Managed SOC, Cloud and Endpoint Security, Firewall Security Management, Vulnerability Management, Application Resilience, and Digital Personal Data Protection (DPDP Act) compliance advisory.

This Privacy Policy applies to personal information gathered through our website located at https://vincacyber.com (the “Website”), as well as related inquiries, consultation requests, career applications, partner inquiries, interactive chat sessions, and direct communications with our offices.

By accessing or using our Website and digital touchpoints, you acknowledge that you understand the terms described in this Privacy Policy. If you do not agree with these practices, please refrain from providing personal information through this Website.

02.Information We Collect

We limit our collection of personal information strictly to what is necessary to deliver our services, respond to enterprise inquiries, manage professional applications, and ensure the security of our digital infrastructure.

A. Personal Information You Voluntarily Provide

  • Consultation & Contact Inquiries: When you request a cyber risk review, consultation, or contact us via our website forms (such as on our Contact Us, Services, or Solutions pages), we collect your full name, business email address, telephone number, organization name, job title, and the details of your cybersecurity needs.
  • Career Applications: When you submit an application or express interest in open roles at Vinca Cyber, we collect your name, email address, phone number, curriculum vitae (CV) or resume, LinkedIn profile URL, work history, educational credentials, and any accompanying cover note.
  • Partner Inquiries: When organizations reach out regarding reseller, Managed Service Provider (MSP), or System Integrator (SI) partnerships, we collect company details, representative contact information, and partnership preferences.
  • Virtual Assistant & Chat Interactions: When you interact with our automated website chatbot or lead capture assistant, we collect conversation prompts and contact details voluntarily submitted during the session.
  • Direct Communications: Any correspondence you direct to us via email (e.g. marketing@vincacyber.com) or telephone (+91 86570 12904), including message history and attachments.

B. Information Collected Automatically

  • Server & Network Logs: For cybersecurity defense, load balancing, and diagnostic purposes, our web servers automatically log standard network transmission data, including your Internet Protocol (IP) address, browser type and version, operating system, HTTP referrer headers, and access timestamps.
  • Website Usage Analytics: We collect aggregated, non-identifying telemetry regarding how visitors navigate our site, such as pages viewed, bounce rates, session duration, and scroll interactions.

C. Information We Do Not Collect

We do not process consumer payments, store payment card details, or request national government identification numbers, biometrics, or sensitive personal data on our public Website. Our web presence is designed exclusively for business information and professional engagement.

03.How We Use Information

Vinca Cyber uses collected information only for legitimate, lawful business purposes and with your consent where applicable:

  • Service Delivery & Quotes: To evaluate your organizational requirements, schedule security assessments, deliver service proposals, and answer technical questions.
  • Recruitment & Hiring: To review employment applications, assess qualifications for open positions, schedule candidate interviews, and communicate application outcomes.
  • Partner Channel Evaluation: To evaluate and establish commercial channel and technology partnerships.
  • Infrastructure Defense & Security: To detect unauthorized intrusion attempts, mitigate bot attacks and denial-of-service attempts, investigate suspicious access, and maintain the integrity of our network.
  • Platform Optimization & Usability: To analyze performance, troubleshoot layout or server anomalies, and ensure responsiveness across various client devices.
  • Legal & Compliance: To comply with mandatory statutory, regulatory, and audit requirements under applicable Indian laws.

04.No Sale of Personal Data

Vinca Cyber does NOT sell, rent, lease, trade, or commercially monetize your personal data, business contact information, or application materials to third parties, data aggregators, or advertisers under any circumstances.

Any information shared with our authorized technical service processors is conducted strictly under written agreements requiring equivalent standards of confidentiality and data protection.

05.Cookies and Analytics

Cookies are small text files placed on your device to enhance browsing convenience, secure sessions, and collect anonymous usage metrics.

  • Essential Cookies: These are technically necessary for our Website to operate correctly, enabling basic functions such as page navigation, theme rendering, and security controls.
  • Website Analytics: When configured, our website utilizes Google Tag Manager to load analytics and measurement tags that evaluate aggregate visitor traffic and interaction patterns. These tools record anonymous metrics such as browser type, time spent on pages, and referral URLs, and do not identify you personally.

Managing Cookies: You can review or change your cookie preferences at any time using the Cookie Preferences control in the website footer. Analytics and other optional tags load only after you grant consent for those categories. Most browsers also let you refuse cookies or alert you when a cookie is sent—refer to your browser's help documentation (such as Google Chrome, Mozilla Firefox, Microsoft Edge, or Apple Safari). Note that disabling certain cookies may affect interactive site elements.

06.Information Sharing & Disclosure

We share personal information only under strictly delineated, legitimate conditions:

  • Technical Processors: We partner with vetted service providers who assist us with cloud hosting, secure email relay (SMTP), customer relationship management, and infrastructure monitoring. These providers are bound by rigorous confidentiality agreements and may only process data in accordance with our instructions.
  • Legal & Law Enforcement Mandates: We may disclose personal information when required to do so by applicable Indian law, court order, regulatory direction (such as CERT-In or judicial directives), or to defend Vinca Cyber's legal rights.
  • Corporate Reorganization: In the event of a merger, acquisition, corporate restructuring, or asset sale, personal data held by us may be transferred to the successor entity, subject to equivalent privacy obligations.

07.Data Security Safeguards

As a dedicated cyber resilience operating partner, securing data is central to our mission. We implement multi-layered physical, administrative, and technical controls to protect personal data against accidental loss, unauthorized access, disclosure, or destruction:

  • Encryption in Transit: All traffic between your browser and our servers is encrypted using modern Transport Layer Security (TLS 1.2 and TLS 1.3).
  • Access Governance: Access to form submissions and candidate materials is restricted to authorized staff on a strict need-to-know basis via role-based access control (RBAC).
  • Continuous Monitoring: We conduct periodic vulnerability assessments, firewall policy audits, and ongoing endpoint security monitoring across our infrastructure.

While no Internet transmission or digital storage system can be guaranteed to be 100% impenetrable, we continually enhance our defensive posture in line with current cybersecurity standards.

08.Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Client & Contact Inquiries: Retained for the duration of the active business conversation and subsequent engagement, or until you request deletion.
  • Candidate Records: Retained during the recruitment cycle and for a reasonable period thereafter for potential future opportunities, unless you request expedited removal.
  • Technical Logs: Retained for routine security auditing and incident investigation periods, after which they are automatically rotated and purged.

09.Your Rights (DPDP Act 2023)

In alignment with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable privacy laws, you possess specific rights as a Data Principal regarding your personal information:

  • Right to Access & Summary: You have the right to request confirmation of whether we process your personal data and to receive a summary of that data.
  • Right to Correction & Updating: You have the right to request correction of inaccurate, misleading, or incomplete personal data.
  • Right to Erasure & Withdrawal of Consent: You may withdraw previously given consent and request the deletion of your personal data, subject to legal or statutory retention exceptions.
  • Right to Grievance Redressal: You have the right to access readily available mechanisms for grievance redressal regarding our data processing.

To exercise any of these rights, please email us at marketing@vincacyber.com with the subject line “Data Principal Rights Request”. We will verify your identity and respond within statutory timeframes.

10.Children's Privacy

Our Website and enterprise cybersecurity offerings are designed strictly for organizations, business professionals, and individuals aged 18 and older. We do not knowingly collect, solicit, or maintain personal information from individuals under 18 years of age.

If you have reason to believe that a minor has provided us with personal information, please contact us at marketing@vincacyber.com, and we will promptly delete the data from our records.

12.Changes to this Policy

We may revise this Privacy Policy periodically to reflect changes in applicable legislation, technological updates, or our service offerings. Any modifications will be published on this page with an updated “Last Updated” date at the top.

We encourage you to review this Privacy Policy periodically to remain informed about how Vinca Cyber protects your information.

Privacy & Grievance Redressal

For questions about our data practices, to exercise your Data Principal rights, or to submit a privacy grievance, reach out to our team.

Corporate Locations

Bengaluru HQ: 2727, Vallabha Pamadi, 3rd Floor, 16th Cross, 27th Main Rd, 1st Sector, HSR Layout, Bengaluru, Karnataka 560102

Navi Mumbai: Krishna Business Park Mukund, Plot Kx14, Thane-Belapur Rd, Dighe, Navi Mumbai, Maharashtra 400708

Have questions about our data practices or DPDP Act compliance?

Talk to our operating team.