Privacy Policy & Data Protection

How VSNOC-ITES collects, processes, stores and protects your personal data — in full compliance with applicable law.

📅 Last Updated: 1 March 2025  |  Version: 2.0  |  Effective: 1 March 2025

1. Overview

VSNOC-ITES ("we", "us", "our", or "the Company") is committed to protecting and respecting your privacy. This Privacy Policy and Data Protection Policy ("Policy") explains how we collect, use, disclose, transfer, and store your personal data when you visit our website at vsnocites.com, contact us, or use any of our services.

This Policy applies to all individuals ("you", "your", "the data subject") whose personal data we process, including website visitors, prospective clients, current clients, suppliers, and employees.

📌 Key Summary

We collect only the data we need, use it only for stated purposes, keep it securely, do not sell it to third parties, and respect your right to access, correct or delete it. For full details, please read this policy carefully.

By using our website or services, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of our website and services and contact us to withdraw any previously given consent.

2. Data Controller / Company Information

The data controller responsible for your personal data is:

Company Name: VSNOC-ITES (IT Enabled Services)

Registered Address: First Floor, Apsara Arcade, MKK Nair Rd, Palarivattom, Ernakulam, Kerala 682025, India

Email: sales@vsnocites.com

Phone: +91 8111815205

Website: vsnocites.com

Applicable Law: Information Technology Act, 2000 (India); IT (Amendment) Act, 2008; IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; Digital Personal Data Protection Act, 2023 (DPDPA)

3. Personal Data We Collect

We collect personal data in the following categories, depending on how you interact with us:

3.1 Data You Provide Directly

  • Identity Data: Full name, job title, company name
  • Contact Data: Email address, phone number, postal/billing address
  • Service Enquiry Data: Details of the services you enquire about, requirements, project scope
  • Communication Data: Records of correspondence, support tickets and call logs
  • Payment Data: Invoice details, billing address (we do not store card numbers — payments processed via secure third-party gateways)
  • Account Data: Login credentials for client portals (passwords stored in hashed form)
  • Marketing Preferences: Newsletter subscriptions and communication preferences

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, device type, operating system, time zone
  • Usage Data: Pages visited, time on page, referring URLs, links clicked
  • Cookie Data: Session cookies, analytics cookies and preference cookies (see Section 10)

3.3 Sensitive Personal Data

We do not intentionally collect sensitive personal data (such as health information, financial account numbers, religion, or biometric data) unless required to deliver a specific contracted service, in which case we obtain explicit consent.

⚠️ Minors

Our services are intended for business and adult use only. We do not knowingly collect personal data from individuals under 18 years of age. See Section 12 for our Children's Privacy policy.

4. How We Use Your Personal Data

We use your personal data for the following purposes:

  • Service Delivery: To provide, manage and support the NOC, VoIP, hosting, IT or marketing services you have engaged us for
  • Client Communication: To respond to enquiries, send service updates, incident notifications and account information
  • Billing & Invoicing: To process payments, manage invoices and comply with accounting obligations
  • Contract Management: To draft, execute and administer service agreements and SLAs
  • Marketing (with consent): To send newsletters, product updates and promotional material where you have opted in
  • Website Analytics: To understand how our website is used and improve user experience (using anonymised/aggregated data where possible)
  • Security & Fraud Prevention: To detect, investigate and prevent fraudulent activity, abuse or security incidents
  • Legal Compliance: To comply with applicable laws, regulations, court orders, or lawful requests from government authorities
  • Business Operations: Internal record-keeping, audits and quality assurance activities

We will not use your personal data for any purpose that is incompatible with those stated above without obtaining your prior consent.

6. Data Sharing and Disclosure

We do not sell, rent or trade your personal data to third parties. We may share your data only in the following circumstances:

6.1 Service Providers and Sub-processors

We engage trusted third-party service providers to assist in delivering our services, including:

  • Cloud infrastructure providers (e.g., AWS, Azure) — hosting servers and data storage
  • Payment gateway providers — for secure billing and invoice processing
  • Email / communication platforms — for client communication and support tickets
  • Analytics providers — for website usage analytics (anonymised data)
  • CRM/helpdesk software providers — for customer relationship and ticket management

All sub-processors are bound by data processing agreements and required to implement appropriate security measures.

6.2 Legal and Regulatory Obligations

We may disclose personal data to government authorities, regulators, law enforcement agencies or courts where required by applicable law, regulation, legal process or national security requirement, provided we have assessed the request is lawful.

6.3 Business Transfers

In the event of a merger, acquisition, reorganisation or sale of assets, your personal data may be transferred to the acquiring entity, subject to equivalent data protection commitments. We will notify you of any such transfer.

6.4 Professional Advisors

We may share data with our legal, financial, or auditing advisors under strict confidentiality obligations where necessary for our business operations.

✅ No Selling of Data

VSNOC-ITES does not and will never sell your personal data to data brokers, advertisers or any other third party for commercial gain.

7. Data Protection & Security Measures

VSNOC-ITES implements a comprehensive, multi-layered data security framework in alignment with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and industry best practices including ISO/IEC 27001 principles.

7.1 Technical Safeguards

  • Encryption in Transit: All data transmitted over our website and systems uses TLS 1.2/1.3 encryption (HTTPS)
  • Encryption at Rest: Sensitive personal data stored on our servers is encrypted using AES-256
  • Access Controls: Role-based access control (RBAC) — data is accessible only to authorised personnel with a legitimate need
  • Authentication: Multi-factor authentication (MFA) required for all administrative system access
  • Network Security: Firewalls, intrusion detection/prevention systems (IDS/IPS) and DDoS protection
  • Vulnerability Management: Regular security patching, penetration testing and vulnerability assessments
  • Backups: Encrypted, geo-redundant backups with regular restoration testing

7.2 Organisational Safeguards

  • Designated Data Protection responsibilities within senior management
  • Employee data protection training and awareness programmes
  • Confidentiality obligations in all employment and contractor agreements
  • Data Protection Impact Assessments (DPIA) for high-risk processing activities
  • Incident Response Plan for data breaches (see Section 7.3)
  • Regular internal security audits and policy reviews

7.3 Data Breach Response

In the event of a personal data breach that presents a risk to the rights and freedoms of individuals, we will:

  • Investigate and contain the breach immediately upon detection
  • Notify affected data subjects without undue delay where the breach presents a high risk
  • Report to relevant authorities (CERT-In and applicable data protection authorities) within timelines required by law
  • Document all breaches in our internal breach register regardless of whether notification is required
  • Implement remediation measures to prevent recurrence

⚠️ Important Notice

While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data, but we commit to taking all reasonable steps to protect it.

8. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:

Data Category Retention Period Reason
Client contract & service data 7 years after contract end Legal & tax obligation
Billing & financial records 7 years Companies Act / Tax law
Support tickets & communications 3 years Service quality & disputes
Website contact form enquiries 2 years Legitimate interest
Marketing / newsletter subscribers Until unsubscription + 1 year Consent-based
Website analytics data 26 months (anonymised) Legitimate interest
NOC system logs 90 days (operational) / 1 year (archived) Security & audit
Employee / HR data Employment period + 5 years Labour law compliance

Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or archived in compliance with our data disposal procedures. Physical records containing personal data are shredded.

9. Your Data Subject Rights

Under the Digital Personal Data Protection Act, 2023 (India) and applicable international data protection laws, you have the following rights regarding your personal data:

9.1 Right of Access

You have the right to request confirmation of whether we hold personal data about you, and to receive a copy of that data along with information about how it is processed.

9.2 Right to Correction

You have the right to request correction of any inaccurate, incomplete or outdated personal data we hold about you.

9.3 Right to Erasure ("Right to be Forgotten")

You may request deletion of your personal data where: (i) it is no longer necessary for the purpose it was collected; (ii) you withdraw consent; (iii) you object to processing; or (iv) the data was unlawfully processed — subject to applicable legal obligations that require us to retain certain data.

9.4 Right to Restrict Processing

You may request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have disputed.

9.5 Right to Data Portability

Where processing is based on consent or contract, and carried out by automated means, you may request your personal data in a structured, commonly used and machine-readable format.

9.6 Right to Object

You may object at any time to the processing of your personal data for direct marketing purposes. You also have the right to object to processing based on legitimate interests.

9.7 Right to Withdraw Consent

Where we process data based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

9.8 Right to Grievance Redressal

You have the right to have your grievances addressed expeditiously. We will respond to all data subject requests within 30 calendar days.

📬 How to Exercise Your Rights

Submit a written request to sales@vsnocites.com with subject line "Data Rights Request". Include your full name, contact details and the specific right you wish to exercise. We may request identity verification before processing your request. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.

9.9 Right to Complain

If you believe we have not handled your personal data in accordance with this Policy or applicable law, you have the right to lodge a complaint with the relevant data protection authority. For India, this is the Data Protection Board of India (established under the DPDPA 2023). You may also contact us directly first to resolve any concerns — we are committed to addressing complaints promptly.

10. Cookies Policy

Our website uses cookies and similar tracking technologies to enhance your browsing experience. A cookie is a small text file placed on your device by a website server.

10.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the website to function correctly (e.g., session management, security). Cannot be disabled. No consent required.
  • Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics — data is anonymised). Require your consent.
  • Functional Cookies: Remember your preferences and settings (e.g., language, region). Require your consent.
  • Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness. We currently do not use marketing cookies. If introduced, prior consent will be obtained.

10.2 Managing Cookies

You can manage your cookie preferences through your browser settings. Most browsers allow you to:

  • View cookies stored on your device
  • Block all or specific cookies
  • Delete existing cookies
  • Set preferences for specific websites

Please note that disabling strictly necessary cookies may impair website functionality. For guidance on managing cookies in popular browsers, visit: www.allaboutcookies.org.

10.3 Third-Party Cookies

Some pages may include content from third parties (e.g., embedded maps, social media buttons) which may set their own cookies. We have no control over these and recommend reviewing the respective third parties' cookie/privacy policies.

11. International Data Transfers

VSNOC-ITES is headquartered in India and primarily processes data within India. However, some of our service providers (cloud platforms, software vendors) may store or process data outside India.

Where personal data is transferred internationally, we ensure adequate safeguards are in place, including:

  • Transfers only to countries with adequate data protection laws (as notified by the Indian government under DPDPA 2023)
  • Standard contractual clauses and data processing agreements with international sub-processors
  • Ensuring all sub-processors implement security standards equivalent to those required by Indian law

If you have questions about international data transfers, please contact us at sales@vsnocites.com.

12. Children's Privacy

Our website and services are directed exclusively to businesses and individuals who are 18 years of age or older. We do not knowingly collect, process or store personal data from individuals under the age of 18.

If you believe we have inadvertently collected personal data from a minor, please contact us immediately at sales@vsnocites.com and we will take prompt steps to delete such data.

Under the DPDPA 2023 (India), processing of personal data of children requires verifiable parental consent. We do not process such data.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy
  • Post the revised Policy on our website at the same URL
  • Notify registered users or clients by email where changes are significant

We encourage you to review this Policy periodically. Your continued use of our website or services after the effective date of any changes constitutes acceptance of the updated Policy.

Previous versions of this Policy are available upon request by emailing sales@vsnocites.com.

14. Terms of Use

By accessing and using the VSNOC-ITES website (vsnocites.com) and services, you agree to the following terms:

14.1 Acceptable Use

  • You will use our website and services only for lawful purposes and in a manner that does not infringe the rights of others
  • You will not attempt to gain unauthorised access to our systems, networks or client data
  • You will not use our services to transmit unsolicited communications (spam), malware, or harmful content
  • You will not misrepresent your identity or affiliation when contacting us

14.2 Intellectual Property

All content on this website — including text, graphics, logos, images, and software — is the property of VSNOC-ITES or its content suppliers and is protected by applicable intellectual property laws. You may not reproduce, distribute or create derivative works without prior written permission.

14.3 Disclaimer of Warranties

Our website is provided on an "as is" and "as available" basis. While we strive to ensure accuracy, we make no warranties, express or implied, regarding the completeness, accuracy or fitness for a particular purpose of any content on this website.

14.4 Limitation of Liability

To the fullest extent permitted by law, VSNOC-ITES shall not be liable for any indirect, incidental, special, consequential or punitive damages arising from your use of, or inability to use, this website or our services — except where such liability cannot be excluded under applicable Indian law.

14.5 Governing Law & Jurisdiction

This Policy and any disputes arising from it shall be governed by and construed in accordance with the laws of India. Any legal proceedings shall be subject to the exclusive jurisdiction of the courts of Ernakulam, Kerala, India.

14.6 Links to Third-Party Sites

Our website may contain links to third-party websites. These links are provided for your convenience only. VSNOC-ITES is not responsible for the content, privacy practices or security of any third-party websites. We recommend reviewing their respective privacy policies before providing any personal data.

15. Contact Us / Data Protection Enquiries

For all privacy, data protection and data rights enquiries, or to exercise your rights under this Policy, please contact us through any of the following channels:

📬 Data Protection Contact

Company: VSNOC-ITES (IT Enabled Services)

For Attention: Data Protection / Privacy Team

Email: sales@vsnocites.com (Subject: "Data Privacy Enquiry")

Phone: +91 8111815205

Address: First Floor, Apsara Arcade, MKK Nair Rd, Palarivattom, Ernakulam, Kerala 682025, India

We are committed to responding to all data protection enquiries and complaints within 30 calendar days of receipt. Where a request is complex or we receive a large volume, we may extend this period by a further 30 days and will inform you accordingly.

🏛️ Regulatory Authority

You also have the right to lodge a complaint directly with the Data Protection Board of India (established under the Digital Personal Data Protection Act, 2023) or other competent supervisory authority in your jurisdiction. We strongly encourage you to contact us first to give us the opportunity to address your concern before escalating to a regulatory body.

This Privacy Policy & Data Protection Policy was prepared by VSNOC-ITES and is effective as of 1 March 2025. It supersedes all previous versions. VSNOC-ITES reserves the right to amend this Policy at any time with notice as described in Section 13.

Questions About Our Privacy Practices?

Our team is happy to answer any questions about how we handle and protect your data.