Privacy Policy

We sell risk management, so we will not hide how we handle yours. This policy sets out exactly what personal data TrustSphere Technologies collects through this website and our assessment tools, why we collect it, who else touches it, how long we keep it, and how you get it back or get it deleted.

Effective 8 September 2026 Last updated 8 September 2026 Applies to trustspheretechnologies.com

1. Who we are

TrustSphere Technologies Pvt. Ltd. ("TrustSphere", "we", "us") is the Data Fiduciary for the personal data described in this policy, as that term is used in India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). If you are in a jurisdiction that uses different vocabulary, "Data Fiduciary" is equivalent to "data controller" and "Data Principal" is equivalent to "data subject".

Registered office: Bengaluru, Karnataka, India. Contact: privacy@trustspheretechnologies.com.

This policy covers the public website at trustspheretechnologies.com, including the Lightweight Cyber Risk Quantification tool and the CRQ Maturity Self-Assessment. If you become a customer, the handling of data inside the 4sight and TrustCore platforms is governed additionally by your signed agreement and its data processing terms, which take precedence over this policy where they conflict.

2. What we collect

We collect only what a specific interaction requires. We do not buy personal data from brokers, and we do not build profiles on you from third-party sources.

Data you give us directly

WhereWhat
Demo / contact form First name, last name, work email, company name, area of interest, and any message you choose to write.
Lightweight CRQ tool Name, work email, mobile number, company name, designation — plus the organisational inputs you enter to run the calculation, such as sector, headcount, revenue band, records held and your own loss estimates.
CRQ Maturity Self-Assessment Name, work email, company name, and your answers to the maturity questions.
Email & direct contact Whatever you include when you write to us at a trustspheretechnologies.com address.

Data collected automatically

  • Technical context submitted with a form — browser, operating system, screen size, referring page, and the time of submission. This is attached to your enquiry so our team can reproduce problems and understand which page prompted the enquiry.
  • Analytics data, but only if you consent to it. See section 5.
  • Server and CDN logs held by our hosting and content-delivery providers, which may include IP address, user agent and requested URL. These are operational and security logs, retained by those providers under their own policies.

What we deliberately do not collect

  • We do not ask for, and do not want, financial account numbers, government identifiers (Aadhaar, PAN), health data, or credentials of any kind through this website. Please do not send them to us.
  • We do not operate advertising pixels or cross-site tracking on this website.
  • We do not sell personal data. Not to anyone, in any form.

3. Why we collect it, and on what basis

Under the DPDP Act we process personal data on the basis of your consent, given by the affirmative act of submitting a form after being shown notice of this policy, or on the basis of certain legitimate uses permitted by the Act — most relevantly, responding to a communication you voluntarily initiated with us.

PurposeBasis
Reply to your enquiry and arrange a demoConsent / voluntarily provided for that purpose
Generate and email your CRQ or maturity reportConsent
Follow up about the specific product or service you asked aboutConsent
Improve the website and the assessment toolsConsent (analytics), and aggregate use of non-identifying data
Detect and investigate abuse of our forms or infrastructureLegitimate use — security of our systems
Meet legal, tax and regulatory obligationsCompliance with law

We will not use your data for a materially different purpose without asking you first. If you gave us your details to receive a CRQ report, we will not silently add you to an unrelated marketing programme.

4. The assessment tools, specifically

The Lightweight CRQ tool and the Self-Assessment ask for information about your organisation that is more sensitive than a typical contact form — revenue bands, record volumes, control maturity and your own loss estimates. We want to be precise about what happens to it.

  • The calculation runs in your browser. The scoring and quantification logic executes locally on your device. Your inputs are not streamed to us keystroke by keystroke.
  • Your progress is stored in your own browser using sessionStorage, so that a refresh mid-assessment does not lose your work. It is cleared when you close the tab and it never leaves your device.
  • Data reaches us only when you submit — when you ask for the report to be emailed to you. At that point the inputs and results are sent, via our email delivery provider, to our sales inbox.
  • We do not publish, benchmark or resell your figures. If we ever want to use anonymised, aggregated data across many assessments to produce industry benchmarks, we will say so here first.
Please note

Assessment outputs are indicative estimates produced from the inputs you supply. They are not an audit, not a valuation, and not professional, legal or financial advice. See our Terms of Service for the full position.

5. Cookies and analytics

This website sets no cookies at all until you consent to analytics.

We use Google Analytics 4 to understand which pages are useful and where people give up. It is loaded only after you click "Accept" on the consent banner. If you decline, or simply ignore the banner, no analytics script is loaded, no analytics cookie is written and no data is sent to Google. Your choice is remembered in your browser's local storage so we do not ask again on every page.

Where analytics is enabled, we configure it to send the page path only — never the query string — because the assessment pages can carry answer data in the URL that we have no business handing to a third party. We do not enable Google Signals, advertising features or cross-device tracking.

You can change your mind at any time using the "Cookie settings" link in the footer of any page. Your browser's own controls and "Do Not Track" or global privacy control signals are also respected where your browser sends them.

Strictly necessary storage — such as the record of your consent choice, and the sessionStorage that preserves your assessment progress — is not analytics and is not covered by the banner. It is required for the site to function as you asked it to.

6. Who we share it with

We share personal data with a small number of processors who perform a specific function for us under contract. Each is bound to use the data only on our instructions. Our current subprocessors for this website are:

ProviderFunctionData involved
EmailJSDelivers form submissions and report emails to our inbox and to youForm contents, including assessment inputs and results
Google Analytics (Google LLC)Website analytics — only with your consentPage path, approximate location, device and browser characteristics
Google Fonts (Google LLC)Serves the site's typefacesIP address and user agent, as an inherent part of the request
jsDelivrContent delivery network for JavaScript libraries used by the assessment toolsIP address and user agent, as an inherent part of the request

We maintain the authoritative, dated list of subprocessors on our Trust Center and update it there when it changes.

Beyond these processors, we disclose personal data only:

  • where we are legally required to, by a court, regulator or law enforcement body acting under valid authority — and we will tell you unless we are legally prohibited from doing so;
  • to our professional advisers where necessary and under a duty of confidentiality; and
  • to an acquirer, in the event of a merger, acquisition or restructuring — in which case the data remains subject to protections no weaker than those in this policy.

7. Cross-border transfers

TrustSphere operates from India, and India is the default location for the data we hold. Some of the processors listed above operate globally, so form submissions and analytics data may be processed on infrastructure outside India.

We make such transfers in accordance with section 16 of the DPDP Act and any restrictions the Central Government notifies, and we impose contractual confidentiality and security obligations on each processor. For customers of the 4sight platform, data residency — including India-resident deployment — is set out in your agreement and described on our Trust Center.

8. How long we keep it

The DPDP Act requires us to erase personal data once the purpose it was collected for is served. We apply these periods:

DataRetention
Enquiries that do not become an opportunity24 months from last contact, then deleted
Assessment submissions and generated reports24 months from submission, then deleted
Active prospect and customer contact recordsFor the duration of the relationship, and 24 months after it ends
Records required for tax, statutory or audit purposesAs required by Indian law, typically 8 years
Consent recordsFor as long as needed to evidence the consent, and a reasonable period after withdrawal
Analytics dataPer the retention configured in Google Analytics, currently 14 months

You can ask us to delete your data sooner. See section 10.

9. How we protect it

We take reasonable security safeguards to prevent personal data breaches, as section 8(5) of the DPDP Act requires. In practical terms, for this website and the data it collects:

  • All traffic is served over TLS; the site is not reachable over plain HTTP.
  • Form contents are escaped before being rendered into the notification emails, so submitted content cannot execute as markup.
  • Access to the inbox and tooling that receives submissions is restricted to staff who need it, protected by multi-factor authentication.
  • Our security posture, control set and certification status are documented in full on the Trust Center.

If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal as required by the DPDP Act and its rules. Our breach response, and how to report a vulnerability to us, are described on the Trust Center.

No safeguard is absolute, and we will not claim otherwise. What we will do is tell you honestly and promptly if something goes wrong.

10. Your rights

As a Data Principal under the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we hold about you, the processing we have carried out, and the identities of others with whom we have shared it.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and data updated.
  • Erasure — have your personal data deleted, unless we are required by law to retain it.
  • Withdraw consent — as easily as you gave it. Withdrawal does not affect processing already carried out lawfully before you withdrew.
  • Grievance redressal — a readily available means of raising a complaint with us. See section 11.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of these, email privacy@trustspheretechnologies.com from the address you gave us, or write to our Grievance Officer. We respond within 30 days. We will not charge you for this, and we will not make you justify the request.

If you are covered by the EU or UK GDPR, you additionally have rights of portability, restriction and objection, and the right to lodge a complaint with your local supervisory authority. We will honour those requests on the same timeline.

11. Grievance redressal

The DPDP Act requires us to publish the contact details of a Grievance Officer who will answer questions about how we process your personal data.

Grievance Officer

TrustSphere Technologies Pvt. Ltd.
Email: grievance@trustspheretechnologies.com
Address: Bengaluru, Karnataka, India

We acknowledge every grievance within 7 working days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

12. Children

This is a business-to-business website. It is not directed at children, and we do not knowingly collect the personal data of anyone under 18. Under the DPDP Act we do not undertake tracking, behavioural monitoring or targeted advertising directed at children in any case. If you believe a child has submitted data to us, contact us and we will delete it.

13. Changes to this policy

We update this policy when our practices change. The "Last updated" date at the top always reflects the current version. If a change materially affects how we handle data you have already given us, we will notify you directly rather than relying on you to notice the date change.

This policy is published in English. If you would like it in another language listed in the Eighth Schedule to the Constitution of India, write to us and we will provide one.

14. Contact us

Privacy questions and rights requests: privacy@trustspheretechnologies.com
Grievances: grievance@trustspheretechnologies.com
Security vulnerabilities: security@trustspheretechnologies.com — see our disclosure policy
Everything else: sales@trustspheretechnologies.com

Related reading: Terms of Service · Trust Center

We hold ourselves to what we sell.

Our Trust Center documents the controls behind this policy — certification status, data residency, subprocessors, and how to report a vulnerability to us.