Privacy policy
Effective date: 2 September 2026
Table of contents
Introduction
This notice explains what personal data Nexix Security Labs collects through this website, why we collect it, who we share it with, and the rights you hold over it. It is written to be read, so it describes what the site actually does rather than every activity we might conceivably undertake.
We have not added any advertising pixel or third-party marketing tracker of our own to this site. Our hosting platform does load its own analytics on every page, which is described honestly and in full in Cookies and tracking technologies rather than glossed over.
Who we are
Nexix Security Labs provides cybersecurity assessment, managed security operations, operational technology security, data engineering and IT consulting services. We also operate Nexix Academy, a separate cyber training and assessment platform.
For the purposes of India's Digital Personal Data Protection Act 2023, Nexix Security Labs is the Data Fiduciary for personal data collected through this website. Our registered details are:
- Registered entity name: Nexix Security Lab
- Registered address: Indraprastha Nagar, Nagpur, Maharashtra, India 440022
- Email: contact@nexixsecuritylabs.com
Applicability
This notice covers nexixsecuritylabs.com and its
subdomains. It applies to prospective clients, clients, website
visitors, and anyone who contacts us through this site.
It does not cover the Nexix Academy platform at
nexixsecurity.training, which handles learner accounts and
assessment records and publishes its own notice. It also does not cover
data we process while carrying out a security engagement, which is
governed by the contract for that engagement. See
Data handled during a security engagement.
Personal data we collect
We collect only what the site needs to work and to answer enquiries. There is no account system, no login, and no comment facility on this website, so there is no profile to build.
Data you give us
When you submit the contact form, we collect exactly the fields that form asks for:
- Full name
- Work email address
- Phone number
- Company name
- Job title
- The service you are interested in
- The enquiry text you write, and anything you choose to put in it
If you email or call us directly, we hold that correspondence and whatever it contains.
Data collected automatically
Serving a web page necessarily involves your device telling our host who and where it is. Our hosting provider records standard request information for delivery, security and abuse prevention: IP address, browser and device type, the page requested, the referring page, and the time of the request.
The contact form also records the time the page was loaded and includes a hidden field that humans never fill in. Both are used solely to reject automated spam submissions before they are stored. Submissions caught this way are discarded, not retained.
Data collected by analytics
We also record how the site is used — pages viewed, links clicked, how far you read, and a masked reconstruction of the visit. This is set out in full, including what is excluded from it, in Cookies and tracking technologies.
What we do not collect
We do not collect special category or sensitive personal data through this website, and we ask you not to send it to us in an enquiry. We do not buy personal data from data brokers, and we do not build advertising profiles or sell access to you as an audience.
How we use personal data
Each purpose below maps to data listed in the previous section.
- Answering your enquiry. Contact form and email data is used to reply to you, understand what you need, and where relevant prepare a scope and proposal.
- Managing the client relationship. Contact details are used to deliver services you have engaged us for and to administer the contract.
- Operating and securing the website. Request logs are used to serve pages, diagnose faults, and detect and block abuse.
- Meeting legal and regulatory obligations. Where a law, court or regulator requires us to retain or produce records.
We do not use your data to make automated decisions that produce legal or similarly significant effects, and we do not sell personal data.
Our basis for processing
Under the Digital Personal Data Protection Act 2023 we process personal data on the basis of your consent, given when you choose to submit an enquiry, and for certain legitimate uses permitted by the Act. You can withdraw consent at any time; see Your rights over your data. Withdrawing consent does not affect processing already carried out.
We do not target our services at individuals in the European Union or the United Kingdom, and we do not monitor their behaviour, so no UK or EU GDPR lawful-basis statement is made here. If you are in either and believe we hold your personal data, contact us using the details in How to contact us and we will handle your request on the same terms set out in this notice.
Storage and international transfer
Nexix Security Labs operates from India. Our hosting, CRM and analytics providers operate globally, so both the enquiry data you submit and the usage data our analytics collect may be stored or processed on infrastructure outside India — including in the European Union and the United States. Where that happens we rely on the provider's contractual data protection commitments, and on transfers being permitted under the Digital Personal Data Protection Act 2023.
How long we keep personal data
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires, then delete it.
- Enquiries that do not become engagements — kept for 24 months from your last contact with us, then deleted. This covers both the contact record and the copy posted into our internal Google Chat space.
- Client contact records — kept for the life of the relationship and for 8 years after it ends, which is the period Indian company and tax record-keeping rules require.
- Analytics records — retained under the retention period configured on our PostHog account, and by Wix under its own platform policy for the data it collects.
- Server and platform logs — kept for our hosting provider's standard window and not extended by us.
You can ask us to delete your data sooner. See Your rights over your data.
Your rights over your data
As a Data Principal under the Digital Personal Data Protection Act 2023, you have the following rights over personal data we hold about you:
- Access. A summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
- Correction and completion. To have inaccurate or misleading data corrected, incomplete data completed, and data updated.
- Erasure. To have your personal data deleted, unless we are required to keep it to comply with a law.
- Withdrawal of consent. To withdraw consent at any time, as easily as it was given.
- Nomination. To nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal. To raise a complaint with us and receive a response, before escalating.
Exercising these rights costs nothing and we will not treat you differently for doing so.
If you are not satisfied with how we handle your request, you may complain to the Data Protection Board of India. If you are in the EU or UK, you may also have the right to complain to your local supervisory authority.
How to exercise your rights
Write to us at the address below and we will handle it. Requests are answered by a person, not a ticket queue.
Exercise your data rights
Your data, your call.
Send your request to the address below. To let us act on it without going back and forth, please include:
- Which right you are exercising: access, correction, erasure, withdrawal of consent, or nomination.
- The name, email address or phone number you gave us, so we can locate the right record.
- Any detail that helps: roughly when you contacted us, or which service you enquired about.
We will confirm receipt, verify that the request comes from you or someone authorised to act for you, and respond within 30 days.
Email your requestVerification exists to protect you: it stops someone else obtaining or deleting your data by pretending to be you. We ask for the minimum needed and use it for nothing else.
Data handled during a security engagement
This is a security company, so it is worth being explicit about something a generic privacy notice would leave out.
When we carry out a penetration test, vulnerability assessment or similar engagement, we may encounter personal data held in the systems we are testing. That data is not collected through this website and is not governed by this notice. It is handled under the engagement contract, the rules of engagement and the non-disclosure agreement signed before any testing begins, which set out what may be accessed, how findings are stored and transmitted, and when evidence is destroyed.
In that context our client is the Data Fiduciary and we act on their instructions. If your personal data was held in a system we tested, the organisation that owns that system is the right place to direct a request, and we will support them in answering it.
How we protect personal data
Enquiries are submitted over an encrypted connection and stored in our hosting provider's contact system with access limited to the people who need it. The website holds no credentials in the browser: the contact form is processed on the server, so no key or token is ever sent to your device.
No control set makes a breach impossible, and we will not claim otherwise. If a breach affects your personal data, we will notify you and the Data Protection Board of India as the Act requires.
Children's personal data
This website sells professional services to organisations and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
Links to other websites
This site links to Nexix Academy, to our profiles on LinkedIn, X, Instagram and YouTube, and from research articles to third-party sources. Once you follow a link you are on someone else's site under their privacy notice, not ours. A link is not an endorsement of their data practices, and we have no control over them.
Changes to this notice
We update this notice when our practices or the law change. The effective date at the top tells you which version you are reading. Where a change materially affects your rights we will take reasonable steps to tell you rather than relying on you to notice.
How to contact us
For any question about this notice, or to exercise a right, contact us:
- Email: contact@nexixsecuritylabs.com
- Phone: +91 8956018674
- Post: Indraprastha Nagar, Nagpur, Maharashtra, India 440022
Grievance redressal
Under the Digital Personal Data Protection Act 2023 you may raise a grievance about how we handle your personal data. Send it to the address above with “Grievance” in the subject line and it will be routed to the person responsible for answering questions about our processing. We will acknowledge it and respond within 30 days.
If we do not resolve your grievance to your satisfaction, you may complain to the Data Protection Board of India.