Legal

Privacy Policy

How we collect, use, and protect personal data — and the rights you have over it.

Last updated 12 August 2026 · Applies to hapsatechnologies.com

Plain summary. We collect only what you send us through the enquiry form. We use it to reply to your enquiry and nothing else. We do not sell it, we do not run advertising trackers, and the domain checker on our site does not store anything you type into it.

1. Who we are

HAPSA Technologies ("HAPSA", "we", "us") is a security-first consulting company based in India. For anything in this policy, contact us at info@hapsatechnologies.com, or by phone using the call button on our contact section.

For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP Act), HAPSA Technologies is the Data Fiduciary for personal data collected through this website. Where the EU GDPR applies, we act as the Data Controller.

2. What we collect

DataWhenWhy
Name, email, phoneYou submit the enquiry formTo reply to your enquiry
Service interest, and your answers to the scoping questions (focus area, environment size, hosting, driver)You submit the enquiry formTo scope the assessment before we speak
Message contentYou choose to write oneTo understand your request
Domain name entered into the exposure checkerYou run the checkUsed only to build the DNS query. Not stored, not logged by us, not transmitted to us.

We do not collect special category or sensitive personal data through this website, and we ask that you do not send it to us via the form.

3. Legal basis and consent

Under the DPDP Act we process your personal data on the basis of the consent you give when you knowingly submit the enquiry form, for the specific purpose of responding to that enquiry. Where GDPR applies, our basis is consent and our legitimate interest in responding to a business enquiry you initiated.

You can withdraw consent at any time (see section 8). Withdrawing consent does not affect processing already carried out.

4. How long we keep it

Enquiry data is retained for 24 months from your last contact with us, so we can follow up on an ongoing conversation, then deleted. If you become a client, engagement records are retained under the terms of the engagement contract and any applicable statutory retention period. If you ask us to erase your data sooner, we will, unless we are legally required to keep it.

5. Who we share it with

We do not sell personal data. We never share it for advertising. We share it only with the service providers needed to run this site:

Some of these providers operate outside India. Where personal data is transferred abroad, we rely on the provider's contractual safeguards and transfer only what is necessary to deliver the service.

6. Cookies and tracking

This website sets no cookies and runs no advertising or cross-site tracking. There is no analytics profiling of individuals. If we add privacy-respecting, aggregate analytics in future, we will update this policy before doing so.

7. How we protect it

The site is served over HTTPS. Form submissions are transmitted over an encrypted connection. Access to enquiry data is limited to HAPSA personnel who need it to respond to you. We apply the same hardening practices to our own systems that we recommend to clients.

No system is perfectly secure. If a personal data breach affects you, we will notify you and the relevant authority as required by the DPDP Act and any other applicable law.

8. Your rights

Under the DPDP Act, as a Data Principal you have the right to:

Where GDPR applies you additionally have rights to restriction, portability, objection, and to lodge a complaint with your supervisory authority.

To exercise any of these, email info@hapsatechnologies.com. We respond within 30 days.

9. Grievance officer

Questions, complaints, or requests about personal data should be sent to info@hapsatechnologies.com, marked "Attn: Grievance Officer", or by phone using the call button on our contact page. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

10. Children

This website is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18 through this site. Where we deliver training to school students, that is governed by a separate agreement with the institution, which handles parental consent.

11. Changes

If we change this policy we will update the date at the top of this page. Material changes to how we use personal data will be notified to anyone whose data we hold.

← Back to hapsatechnologies.com