Privacy Policy
We sell risk management, so we will not hide how we handle yours. This policy sets out exactly what personal data TrustSphere Technologies collects through this website and our assessment tools, why we collect it, who else touches it, how long we keep it, and how you get it back or get it deleted.
1. Who we are
TrustSphere Technologies Pvt. Ltd. ("TrustSphere", "we", "us") is the Data Fiduciary for the personal data described in this policy, as that term is used in India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). If you are in a jurisdiction that uses different vocabulary, "Data Fiduciary" is equivalent to "data controller" and "Data Principal" is equivalent to "data subject".
Registered office: Bengaluru, Karnataka, India. Contact: privacy@trustspheretechnologies.com.
This policy covers the public website at trustspheretechnologies.com, including the Lightweight Cyber Risk Quantification tool and the CRQ Maturity Self-Assessment. If you become a customer, the handling of data inside the 4sight and TrustCore platforms is governed additionally by your signed agreement and its data processing terms, which take precedence over this policy where they conflict.
2. What we collect
We collect only what a specific interaction requires. We do not buy personal data from brokers, and we do not build profiles on you from third-party sources.
Data you give us directly
| Where | What |
|---|---|
| Demo / contact form | First name, last name, work email, company name, area of interest, and any message you choose to write. |
| Lightweight CRQ tool | Name, work email, mobile number, company name, designation — plus the organisational inputs you enter to run the calculation, such as sector, headcount, revenue band, records held and your own loss estimates. |
| CRQ Maturity Self-Assessment | Name, work email, company name, and your answers to the maturity questions. |
| Email & direct contact | Whatever you include when you write to us at a trustspheretechnologies.com address. |
Data collected automatically
- Technical context submitted with a form — browser, operating system, screen size, referring page, and the time of submission. This is attached to your enquiry so our team can reproduce problems and understand which page prompted the enquiry.
- Analytics data, but only if you consent to it. See section 5.
- Server and CDN logs held by our hosting and content-delivery providers, which may include IP address, user agent and requested URL. These are operational and security logs, retained by those providers under their own policies.
What we deliberately do not collect
- We do not ask for, and do not want, financial account numbers, government identifiers (Aadhaar, PAN), health data, or credentials of any kind through this website. Please do not send them to us.
- We do not operate advertising pixels or cross-site tracking on this website.
- We do not sell personal data. Not to anyone, in any form.
3. Why we collect it, and on what basis
Under the DPDP Act we process personal data on the basis of your consent, given by the affirmative act of submitting a form after being shown notice of this policy, or on the basis of certain legitimate uses permitted by the Act — most relevantly, responding to a communication you voluntarily initiated with us.
| Purpose | Basis |
|---|---|
| Reply to your enquiry and arrange a demo | Consent / voluntarily provided for that purpose |
| Generate and email your CRQ or maturity report | Consent |
| Follow up about the specific product or service you asked about | Consent |
| Improve the website and the assessment tools | Consent (analytics), and aggregate use of non-identifying data |
| Detect and investigate abuse of our forms or infrastructure | Legitimate use — security of our systems |
| Meet legal, tax and regulatory obligations | Compliance with law |
We will not use your data for a materially different purpose without asking you first. If you gave us your details to receive a CRQ report, we will not silently add you to an unrelated marketing programme.
4. The assessment tools, specifically
The Lightweight CRQ tool and the Self-Assessment ask for information about your organisation that is more sensitive than a typical contact form — revenue bands, record volumes, control maturity and your own loss estimates. We want to be precise about what happens to it.
- The calculation runs in your browser. The scoring and quantification logic executes locally on your device. Your inputs are not streamed to us keystroke by keystroke.
- Your progress is stored in your own browser using
sessionStorage, so that a refresh mid-assessment does not lose your work. It is cleared when you close the tab and it never leaves your device. - Data reaches us only when you submit — when you ask for the report to be emailed to you. At that point the inputs and results are sent, via our email delivery provider, to our sales inbox.
- We do not publish, benchmark or resell your figures. If we ever want to use anonymised, aggregated data across many assessments to produce industry benchmarks, we will say so here first.
Assessment outputs are indicative estimates produced from the inputs you supply. They are not an audit, not a valuation, and not professional, legal or financial advice. See our Terms of Service for the full position.
7. Cross-border transfers
TrustSphere operates from India, and India is the default location for the data we hold. Some of the processors listed above operate globally, so form submissions and analytics data may be processed on infrastructure outside India.
We make such transfers in accordance with section 16 of the DPDP Act and any restrictions the Central Government notifies, and we impose contractual confidentiality and security obligations on each processor. For customers of the 4sight platform, data residency — including India-resident deployment — is set out in your agreement and described on our Trust Center.
8. How long we keep it
The DPDP Act requires us to erase personal data once the purpose it was collected for is served. We apply these periods:
| Data | Retention |
|---|---|
| Enquiries that do not become an opportunity | 24 months from last contact, then deleted |
| Assessment submissions and generated reports | 24 months from submission, then deleted |
| Active prospect and customer contact records | For the duration of the relationship, and 24 months after it ends |
| Records required for tax, statutory or audit purposes | As required by Indian law, typically 8 years |
| Consent records | For as long as needed to evidence the consent, and a reasonable period after withdrawal |
| Analytics data | Per the retention configured in Google Analytics, currently 14 months |
You can ask us to delete your data sooner. See section 10.
9. How we protect it
We take reasonable security safeguards to prevent personal data breaches, as section 8(5) of the DPDP Act requires. In practical terms, for this website and the data it collects:
- All traffic is served over TLS; the site is not reachable over plain HTTP.
- Form contents are escaped before being rendered into the notification emails, so submitted content cannot execute as markup.
- Access to the inbox and tooling that receives submissions is restricted to staff who need it, protected by multi-factor authentication.
- Our security posture, control set and certification status are documented in full on the Trust Center.
If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal as required by the DPDP Act and its rules. Our breach response, and how to report a vulnerability to us, are described on the Trust Center.
No safeguard is absolute, and we will not claim otherwise. What we will do is tell you honestly and promptly if something goes wrong.
10. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we hold about you, the processing we have carried out, and the identities of others with whom we have shared it.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and data updated.
- Erasure — have your personal data deleted, unless we are required by law to retain it.
- Withdraw consent — as easily as you gave it. Withdrawal does not affect processing already carried out lawfully before you withdrew.
- Grievance redressal — a readily available means of raising a complaint with us. See section 11.
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these, email privacy@trustspheretechnologies.com from the address you gave us, or write to our Grievance Officer. We respond within 30 days. We will not charge you for this, and we will not make you justify the request.
If you are covered by the EU or UK GDPR, you additionally have rights of portability, restriction and objection, and the right to lodge a complaint with your local supervisory authority. We will honour those requests on the same timeline.
11. Grievance redressal
The DPDP Act requires us to publish the contact details of a Grievance Officer who will answer questions about how we process your personal data.
TrustSphere Technologies Pvt. Ltd.
Email: grievance@trustspheretechnologies.com
Address: Bengaluru, Karnataka, India
We acknowledge every grievance within 7 working days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
12. Children
This is a business-to-business website. It is not directed at children, and we do not knowingly collect the personal data of anyone under 18. Under the DPDP Act we do not undertake tracking, behavioural monitoring or targeted advertising directed at children in any case. If you believe a child has submitted data to us, contact us and we will delete it.
13. Changes to this policy
We update this policy when our practices change. The "Last updated" date at the top always reflects the current version. If a change materially affects how we handle data you have already given us, we will notify you directly rather than relying on you to notice the date change.
This policy is published in English. If you would like it in another language listed in the Eighth Schedule to the Constitution of India, write to us and we will provide one.
14. Contact us
Privacy questions and rights requests: privacy@trustspheretechnologies.com
Grievances: grievance@trustspheretechnologies.com
Security vulnerabilities: security@trustspheretechnologies.com — see our disclosure policy
Everything else: sales@trustspheretechnologies.com
Related reading: Terms of Service · Trust Center
We hold ourselves to what we sell.
Our Trust Center documents the controls behind this policy — certification status, data residency, subprocessors, and how to report a vulnerability to us.