Skip to main content

Legal

Privacy policy.

How Threatsys collects, uses and protects personal data, under the Digital Personal Data Protection Act 2023 and the GDPR.

What we collect

  • Contact details you give us through forms: name, work email, company, phone
  • Requirement details you choose to share: company size, frameworks, timeline
  • Technical context attached to each enquiry: landing page, referrer, campaign parameters, browser language, timezone and viewport
  • Application data if you apply for a role, including anything in your CV

Why we collect it

  • To respond to your enquiry and schedule your consultation
  • To route your enquiry to the right specialist team
  • To understand which content and campaigns are useful
  • To assess your application if you are applying for a role

Your rights

Under the DPDP Act 2023 and the GDPR you can request access to your data, correction, erasure, and withdrawal of consent. Write to us and we will respond within the statutory window. If you are not satisfied you may complain to the relevant supervisory authority.

Retention

Enquiry data is kept for 24 months from last contact. Application data is kept for 12 months so we can come back to you when a suitable role opens, unless you ask us to delete it sooner.

This page is a starting point

This policy is drafted to reflect how the site actually behaves. Before launch it must be reviewed by your legal counsel and aligned to your registered entity details, grievance officer and DPDP consent notice obligations.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.