Last updated 16 July 2026
ACH Security ("we", "us", "our") provides offensive security testing (VAPT) and DPDP Act compliance services to businesses in India. This policy explains what personal data we collect through achsecurity.com and our customer console, why we collect it, and the rights you have over it under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
When you use our contact form, request a DPDP gap report, or sign up for the console, we collect the information you provide directly — typically your name, work email, company name, and any message or scan target you submit. When you use our console we also store your account details, scan history, and support ticket messages.
The purpose of collecting this information is to respond to your enquiry, generate the report or scan you requested, operate your account, and — where you've agreed to be contacted — to follow up about our services. We use your personal data only for these purposes and do not use it to build advertising profiles.
Your data is used to deliver the service you requested (e.g. emailing a DPDP gap report or VAPT report to the address you provided), to maintain your console account, to respond to support tickets, and to send operational notifications about scans and reports. We do not sell personal data to third parties.
Your VAPT reports are written and verified by our own analysts. We share data with service providers strictly to deliver the service: our transactional email provider (to send reports and notifications), and, for VAPT report generation, specialized analysis tooling that assists our analysts in preparing draft findings from tool output they supply — every finding is reviewed and finalized by a human analyst before it reaches you. These providers may process data on infrastructure located outside India as part of delivering their service to us; we only work with providers under contractual confidentiality obligations.
We retain account and scan data for as long as your account is active, and contact-form or report-request data for as long as needed to respond to your enquiry and for a reasonable period afterward for our own records — typically no more than 24 months from your last interaction with us, unless a longer retention period is required by law or an active engagement. You can request earlier deletion at any time — see "Your rights" below for how we retain that request.
We apply reasonable technical and organisational security measures to protect the personal data we hold, including encrypted transport (HTTPS/TLS everywhere), hashed passwords and verification codes, rate limiting on public forms, and access controls restricting customer data to authorised team members only. No system is completely immune to risk, and we continuously work to improve these safeguards.
If a personal data breach occurs that is likely to result in risk to you, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, without undue delay, along with the nature of the breach and the steps we are taking.
Our services are directed at businesses, not children. We do not knowingly collect personal data from individuals under 18, and we do not process children's data without verified parental consent. If you believe we have inadvertently collected a minor's data, contact our Grievance Officer below and we will delete it.
Where our service providers process data outside India (see "Who we share it with" above), we take reasonable steps to ensure it remains protected to a standard consistent with the DPDP Act, and we do not transfer personal data to any country restricted by the Central Government.
As a data principal under the DPDP Act, you have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure, and withdraw consent at any time. See our Data Principal Rights page for how to exercise these.
You may withdraw your consent to our processing of your personal data, opt out of marketing communications, or revoke consent given via any form on this site at any time — email us using the Grievance Officer contact below and we will act on it within 7 business days. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Grievance Officer: ACH Security Compliance Desk
Email: support@achsecurity.com
We acknowledge grievances within 24 hours and aim to resolve them within 30 days, in line with the DPDP Act. See our Grievance Redressal page for the full process.
Data Protection Officer (DPO): ACH Security Compliance Desk
Email: support@achsecurity.com
Contact our DPO with any question about how we process personal data or to exercise a data-principal right.
We may update this policy as our services or legal obligations change. Material changes will be reflected by updating the date at the top of this page.