We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Privacy Policy

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

1

About this policy

Current as of: 2 August 2026 (v2.1). This policy is versioned — see Version history below.

Cyber Sigma Consulting Services LLP ("CyberSigma", "we") is a cybersecurity and compliance consultancy — CERT-In empanelled and a PCI SSC-listed Qualified Security Assessor company — with its registered office at 405, 4th Floor, Majestic Signia, Sector 62, Noida, Uttar Pradesh 201309, India. For personal data collected through this website, we act as the data fiduciary under the Digital Personal Data Protection Act, 2023 (and as controller under the GDPR where it applies).

We advise clients on privacy law for a living, so we hold this policy to the standard we recommend: specific about what we collect, why, where it goes, how long we keep it, and how you exercise your rights.

2

What we collect, and why

Information you give us :

When you submit a form on this site — an enquiry, an assessment, a download, a newsletter signup or a review — we collect what the form asks for, typically:

  • Name, work email address, company name, designation and phone number.
  • The content of your enquiry or the answers you give in a self-assessment or checker tool.
  • The page you were on when you submitted (so we can respond in context).

Purpose :

We use this information to respond to your enquiry, deliver the resource you requested, provide the assessment result, and — where you have consented or it is otherwise permitted — to send you relevant compliance updates. We do not sell personal data.

Information collected automatically :

We use analytics and advertising measurement (Google Analytics 4 and ad-platform tags) gated behind a consent banner implementing Google Consent Mode v2 — analytics and advertising cookies do not fire until you consent. See the Cookie Policy at /cookie-policy/ for the full list and your controls.

3

Legal bases

Under the DPDP Act, we process personal data on the basis of your consent (which you may withdraw at any time), and for certain legitimate uses recognised by the Act, such as responding to an enquiry you have voluntarily made.

Where the GDPR applies to you, our bases are: consent (newsletter, non-essential cookies); performance of steps you request prior to a contract (enquiries, assessments); and legitimate interests (responding to business enquiries, protecting our services) balanced against your rights.

4

AI processing statement

We use AI systems to help route, summarise and draft responses to enquiries, and to operate assessment tools on this site. Two commitments govern this:

  • Outbound communications prepared with AI assistance are reviewed and approved by a human before they are sent — approval is a structural control in our platform, not a preference.
  • We do not use AI to make automated decisions about you that produce legal or similarly significant effects.
5

Where your data lives, and who processes it

Enquiry and assessment data is processed in systems operated by CyberSigma on cloud infrastructure. We use a small set of sub-processors for specific functions:

  • Mailchimp (Intuit) : newsletter delivery, if you subscribe.
  • Google : analytics and advertising measurement, only after cookie consent.
  • Microsoft : business email and calendaring.
  • Meta and LinkedIn : advertising measurement, only after cookie consent.
  • Twilio : telephony, if you request or receive a call.

For client engagements (as opposed to website visits), data-residency commitments are agreed per contract and documented in our Trust Center, which also carries our current sub-processor register.

6

Retention and erasure

We retain enquiry and assessment data for as long as it serves the purpose you gave it to us for — responding to you, and maintaining the business relationship you initiated — and then delete it, unless a legal obligation requires longer retention.

Consistent with section 8(7) of the DPDP Act, we erase personal data when you withdraw consent or when the specified purpose is no longer served, whichever is earlier, unless retention is required by law. When you unsubscribe from the newsletter, we retain a suppression entry so we do not contact you again.

To request erasure, use the contact route below; we will also instruct our processors to erase.

7

Your rights

Under the DPDP Act (India) :

  • Access a summary of the personal data we hold about you and how it has been processed.
  • Correction and erasure of your personal data.
  • Grievance redressal through the contact below.
  • Nominate another individual to exercise your rights in the event of death or incapacity.

Under the GDPR (where applicable) :

  • Access, rectification, erasure and restriction of processing.
  • Portability of data you provided to us.
  • Objection to processing based on legitimate interests, and the right to withdraw consent at any time.
  • The right to lodge a complaint with your supervisory authority.

We respond to rights requests within the timelines applicable law requires.

8

Grievance redressal and contact

For any privacy question, rights request or grievance, contact us through the website contact page, by email to sales@cybersigmacs.com marked "Privacy", or by post to: Grievance Redressal — Privacy, Cyber Sigma Consulting Services LLP, 405, 4th Floor, Majestic Signia, Sector 62, Noida, Uttar Pradesh 201309, India.

Your message is routed to the executive office responsible for privacy governance and acknowledged in line with applicable law.

9

Security

We apply the controls we advise clients to apply: role-based access on tenant-isolated systems, encrypted storage of integration credentials, audit logging of administrative actions, tested backups, and phishing-resistant (passkey) authentication for platform access. No internet transmission is perfectly secure; we design so that a single failure does not expose your data.

10

Children

Our services are directed at businesses. We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact us and we will delete it.

11

Links to other websites

Where we link to third-party sites (including the primary legal sources we cite in our research), their privacy practices are their own — review their policies.

12

How to exercise your rights — the workflow

So a request never disappears into a mailbox, this is the exact path it takes:

  • Step 1 — Submit: use the contact page or email sales@cybersigmacs.com with the subject "Privacy request", stating what you want (access, correction, erasure, consent withdrawal) and the email address you interacted with us from.
  • Step 2 — Verification: we confirm the request comes from the data principal (normally by replying to the email address on record) before acting on it.
  • Step 3 — Action and response: we act on the request and respond within the timeline applicable law requires, including instructing our processors where erasure applies.
  • Step 4 — Escalation: if you are unsatisfied, you may escalate — in India to the Data Protection Board of India once its grievance mechanism applies to your matter; in the EEA/UK to your supervisory authority.
13

Version history

  • v2.1 — 2 August 2026: added the data-subject request workflow and this version history.
  • v2.0 — 2 August 2026: full governance rewrite — DPDP fiduciary identification, legal bases, AI processing statement, named sub-processors, s.8(7) erasure commitment, jurisdiction-split rights, grievance route.
  • v1.x — prior: template-based policy (superseded).
14

Changes to this policy

We update this policy when our practices change, and update the "Current as of" date above. Material changes affecting your rights will be flagged prominently on this page.

Ready to discuss your requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →