1. Who we are (Data Fiduciary)
WarnHack Technologies Private Limited(“WarnHack”, “we”, “our”, or “us”) is the data fiduciary / data controller responsible for your personal data. We are a company incorporated in India (CIN U62090MP2026PTC082281), with our office at Bhopal, Madhya Pradesh, India.
For any privacy question, email us at [email protected]. Grievance redressal contact details are in section 11.
2. Scope and the laws we follow
This policy applies to personal data we process about visitors, prospects, and customers through this website and our products. We process personal data in accordance with the DPDP Act 2023 and DPDP Rules 2025 (for individuals in India, called “Data Principals”) and, where applicable, the GDPR (for individuals in the EU/UK, called “Data Subjects”).
3. Personal data we collect
- Identity data — name, username, job title, and company where you provide it.
- Contact data — email address, phone number, and billing/postal address.
- Account & transaction data — account credentials, plan, and payment records (payments are processed by our payment partners; we do not store full card details).
- Technical & usage data — IP address, device and browser type, pages visited, and interactions, collected through logs and (with your consent) analytics cookies.
- Communications — messages you send us via forms, email, or support.
We collect data directly from you, automatically as you use the site, and from service providers such as our analytics provider.
4. How we use your data and our legal basis
We use personal data only where the law allows. Our purposes and legal bases are:
- To provide our services and contracts — performance of a contract / necessary legitimate use.
- To respond to enquiries and provide support — legitimate interests / your request.
- For analytics and site improvement — your consent (you can decline; see cookies).
- For marketing communications — your consent, which you may withdraw at any time.
- To meet legal, tax, and security obligations — compliance with a legal obligation.
Under the DPDP Act we rely on your consent or on “certain legitimate uses” permitted by the Act. Under the GDPR we rely on the equivalent lawful bases (consent, contract, legitimate interests, and legal obligation).
5. Cookies and analytics
We use strictly necessary cookies to run the site, and — only with your consent — Google Analytics (with IP anonymisation) to understand usage. Non-essential cookies are off until you opt in, and you can change your choice at any time.
See our Cookie Policy for the full list and durations. You can update your preferences here:
6. Sharing your data and our processors
We do not sell your personal data. We share it only with service providers (data processors) who help us run WarnHack, under contracts that require them to protect it. These currently include:
- Google LLC — Google Analytics and Search Console (website analytics).
- Our cloud hosting & infrastructure providers — to host the website and store data.
- Email & communication providers — to send transactional and, with consent, marketing email.
- Payment providers — to process payments securely.
We may also disclose data where required by law or to protect our legal rights.
7. International data transfers
Some of our processors (for example, Google) may process data on servers outside India. Where we transfer personal data across borders we do so in accordance with the DPDP Act (which permits transfers except to countries restricted by the Government of India) and, for GDPR data, using appropriate safeguards such as Standard Contractual Clauses.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes above or as required by law, after which it is deleted or anonymised. Indicative periods:
- Account data — for the life of your account and a reasonable period afterwards.
- Contact / enquiry messages — up to 24 months after our last interaction.
- Analytics data — per our analytics provider's retention (Google Analytics, up to 26 months).
- Server / access logs — typically up to 180 days.
- Invoices & tax records — as required by Indian tax law.
9. How we protect your data
We apply appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, and least-privilege practices. No method of transmission or storage is completely secure, but we work to protect your data and to review our safeguards.
10. Your rights
If you are in India (DPDP Act), you have the right to:
- Access a summary of the personal data we process about you and how we process it.
- Correction, completion, and updating of your personal data.
- Erasure of your personal data where it is no longer needed.
- Grievance redressal (see section 11).
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Withdraw consent at any time — as easily as you gave it.
If you are in the EU/UK (GDPR), you also have the right to:
- Restrict or object to processing, and data portability.
- Lodge a complaint with your local supervisory authority.
To exercise any right, email [email protected]. We will respond within the timelines required by law (generally within 30 days). We may need to verify your identity first. See our GDPR Policy if you are in the EU/UK.
11. Grievance redressal (DPDP Act)
If you have a concern about how we handle your personal data, you can contact our Grievance Officer:
The Grievance Officer
WarnHack Technologies Private Limited
We aim to acknowledge and respond to grievances within 7 working days (and in any case within 90 days as prescribed under the DPDP Rules).
If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act.
12. Children's data
Our services are intended for business users and are not directed at children. We do not knowingly process the personal data of children under 18 without verifiable parental or guardian consent, and we do not carry out tracking or targeted advertising directed at children, in line with the DPDP Act. If you believe a child has provided us data, contact us and we will delete it.
13. Data breach notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Rules, and — for GDPR data — the relevant supervisory authority, without undue delay.
14. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “last updated” date, and where required we will ask for renewed consent.
15. Contact us
Questions about this policy or your data? Email [email protected] or [email protected], or write to us at Bhopal, Madhya Pradesh, India.