Privacy Policy
NAZZTEC treats personal data with the same rigour we apply to our clients' systems. This notice explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights available to you.
This notice applies to NAZZTEC PRIVATE LIMITED (India), acting as the lead entity for the NAZZTEC group and to the NAZZTEC websites, proposals, service delivery and recruitment activity operated by it. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, India's Digital Personal Data Protection Act 2023 and other applicable data protection laws.
If anything here is unclear, contact us at privacy@nazztec.com and a member of our privacy team will respond.
1. Who we are and how to contact us
Data controller: NAZZTEC PRIVATE LIMITED.
Registered address: World Trade Center Bangalore, Regus, Unit No 2201A, 22nd Floor, Brigade Gateway, Rajajinagar Extension, Malleswaram (W), Bangalore, Karnataka 560055, India.
Privacy contact: privacy@nazztec.com
Data Protection Officer: dpo@nazztec.com
NAZZTEC operates through separate legal entities in the Kingdom of Saudi Arabia, India and the United States. Where you engage a specific entity, that entity is the controller for the personal data processed under that engagement. The entities share common privacy standards and an intra-group data transfer agreement.
2. The personal data we collect
We collect only what we need for a defined purpose. We do not sell personal data, and we do not use it to train third-party artificial intelligence models.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and enquiry data | Name, business email, telephone number, employer, job title, country, the content of your enquiry | Provided directly by you through our contact form, email, telephone or at events |
| Client engagement data | Contract and billing details, named stakeholder contacts, correspondence, meeting notes, project documentation | Provided by you or your organisation during an engagement |
| Technical and usage data | IP address, browser and device type, operating system, referring page, pages visited, session duration, approximate city-level location | Collected automatically by our website and analytics tools, subject to your cookie choices |
| Recruitment data | CV, employment and education history, certifications, right-to-work and visa status, references, interview notes, salary expectations | Provided by you, by a recruitment agency acting for you, or from public professional profiles |
| Supplier and partner data | Contact details of individuals at our suppliers, subcontractors and technology partners, due diligence responses | Provided by the supplier or partner organisation |
| Security and access data | Access logs, authentication records, security monitoring data, CCTV at our offices where applicable | Generated automatically by our systems and premises |
| Marketing preference data | Subscription status, consent records, engagement with our communications | Provided by you and recorded when you interact with us |
Data encountered during service delivery. When delivering security testing, audits, managed services or staffing, we may encounter personal data held within your systems. In that context you are the controller and NAZZTEC acts as a processor on your documented instructions, governed by the data processing terms in our engagement contract. We do not use that data for any purpose other than delivering the contracted service.
Sensitive personal data. We do not seek special-category or sensitive personal data through our website. Where recruitment or visa processing requires it — for example medical fitness or biometric information required by immigration authorities — we collect it only where lawfully required, with appropriate safeguards and, where applicable, your explicit consent.
Children. Our services and website are directed at businesses and professionals. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact privacy@nazztec.com and we will delete it.
3. Why we process your data and our lawful basis
Under the GDPR we must have a lawful basis for each processing activity. The table below sets out our purposes and the basis relied on for each.
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and providing information you requested | Consent, and steps taken at your request prior to entering a contract (GDPR Art. 6(1)(a), 6(1)(b)) |
| Delivering contracted services and managing the client relationship | Performance of a contract (GDPR Art. 6(1)(b)) |
| Invoicing, payment collection and financial record keeping | Contract and legal obligation (GDPR Art. 6(1)(b), 6(1)(c)) |
| Operating, securing and improving our website | Legitimate interests (GDPR Art. 6(1)(f)) |
| Analytics and measuring website performance | Consent (GDPR Art. 6(1)(a)) |
| Sending marketing communications and insights | Consent, or legitimate interests for existing business contacts where permitted (GDPR Art. 6(1)(a), 6(1)(f)) |
| Recruitment and candidate assessment | Pre-contractual steps and consent (GDPR Art. 6(1)(b), 6(1)(a)) |
| Protecting our systems, detecting fraud and investigating security incidents | Legitimate interests and legal obligation (GDPR Art. 6(1)(f), 6(1)(c)) |
| Meeting regulatory, tax, audit and statutory reporting obligations | Legal obligation (GDPR Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Legitimate interests (GDPR Art. 6(1)(f)) |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests do not override your rights and freedoms. You may request a summary of that assessment at privacy@nazztec.com.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Who we share your data with
We share personal data only where there is a clear need, and always under contractual controls. We do not sell, rent or trade personal data.
- NAZZTEC group entities in Saudi Arabia, India and the United States, where necessary to deliver a service or manage the relationship, under an intra-group data transfer agreement.
- Service providers acting as processors on our behalf — cloud hosting, email and collaboration platforms, customer relationship management, analytics, recruitment systems, payroll and accounting. Each is bound by a written data processing agreement requiring confidentiality, security and deletion or return of data on termination.
- Professional advisers — lawyers, auditors, insurers and accountants, where necessary and under professional duties of confidentiality.
- Subcontractors and associate consultants, where they form part of a delivery team, under equivalent confidentiality and data protection obligations.
- Regulators, law enforcement and courts, where we are legally required to disclose or where disclosure is necessary to establish or defend legal claims.
- A purchaser or successor entity, in the event of a merger, acquisition or reorganisation, under confidentiality obligations and with notice to affected individuals where required.
A current list of our material processors is available on request from privacy@nazztec.com.
5. International transfers of personal data
NAZZTEC operates across multiple jurisdictions. Where personal data is transferred outside the country in which it was collected, we do so only where an appropriate legal transfer mechanism is in place.
- Transfer to a jurisdiction benefiting from an adequacy decision.
- Transfer under Standard Contractual Clauses approved by the European Commission, or the UK International Data Transfer Agreement, together with a transfer impact assessment.
- Transfer necessary for the performance of a contract with you.
- Transfer with your explicit informed consent.
- Where you require data to remain within a specific jurisdiction, we can design the engagement accordingly, including in-country hosting and delivery. Tell us at the outset if this applies.
6. How long we keep your data
We retain personal data only for as long as necessary for the purpose it was collected, plus any period required by law, regulation or the defence of legal claims. Our retention schedule is reviewed annually.
| Data category | Retention period |
|---|---|
| Website enquiries that do not become an engagement | 24 months from last contact, then deleted |
| Client engagement records and correspondence | Duration of the engagement plus 7 years, to meet contractual, tax and audit obligations |
| Contracts and statements of work | Duration plus 10 years, for limitation-period purposes |
| Financial and tax records | As required by applicable tax law, typically 7 to 10 years |
| Security testing reports and findings | As agreed in the engagement contract; deleted or returned on request, and by default within 12 months of closure unless retention is contractually agreed |
| Unsuccessful candidate records | 12 months from the hiring decision, or longer with your consent for our talent pool |
| Successful candidate and employee records | Duration of employment plus the period required by applicable employment law |
| Marketing consent records | Until consent is withdrawn, plus 3 years to evidence the consent position |
| Website analytics data | Up to 14 months in aggregated form |
| Security and access logs | 12 months, or longer where required for an active investigation |
Where data is no longer required, it is securely deleted or irreversibly anonymised. Backup copies are overwritten in the ordinary backup cycle.
7. Your rights
Subject to the applicable law, you have the following rights in relation to your personal data.
- Right of access — to obtain confirmation of whether we process your data and a copy of it.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure — to have your data deleted where there is no overriding basis to retain it.
- Right to restriction — to limit how we process your data in defined circumstances.
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object — to object to processing based on legitimate interests, and to object to direct marketing at any time and without justification.
- Right to withdraw consent — at any time, without affecting prior lawful processing.
- Rights relating to automated decision-making — we do not make decisions producing legal or similarly significant effects on you by automated means alone.
How to exercise your rights. Email privacy@nazztec.com or our Data Protection Officer at dpo@nazztec.com with your request. We may ask for information to verify your identity, which we use only for that purpose. We will respond within one month (extendable by two further months for complex requests). There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before proceeding.
Complaints. If you are not satisfied with our response, you may lodge a complaint with your local supervisory authority for data protection. We would appreciate the opportunity to address your concern first.
8. How we protect your data
Information security is our profession, and we hold ourselves to the standards we ask our clients to meet. Our controls include:
- Encryption of data in transit (TLS 1.2 or above) and at rest.
- Multi-factor authentication on all corporate and administrative accounts.
- Role-based access control applied on a least-privilege basis, with periodic access reviews.
- Centralised logging and 24x7 security monitoring of our own environment.
- Endpoint protection, patch management and hardened device configuration baselines.
- Segregation of client engagement data, with separate access controls per engagement.
- Confidentiality obligations and background verification for personnel, proportionate to their role.
- Security awareness training, including phishing simulation, for all staff.
- Written data processing agreements and security due diligence for every material supplier.
- A documented incident response plan, tested through exercises.
- Secure disposal of media and certified destruction of decommissioned equipment.
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify your local supervisory authority for data protection within 72 hours of becoming aware of it where required, and notify affected individuals without undue delay where the risk is high.
No absolute guarantee. No system can be made completely secure. While we apply controls proportionate to the risk, we cannot guarantee the security of information transmitted to us over the internet, and any transmission is at your own risk.
9. Cookies and similar technologies
Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may change at any time through the cookie preferences link in our footer. Full detail is set out in our Cookie Policy.
10. Third-party links
Our website contains links to third-party sites, including our technology partners, regulators and standards bodies. We provide these for your convenience and because linking to authoritative sources is good practice. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their privacy notices.
11. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The effective date is shown at the top of the page and a summary of material changes is published alongside it. Where a change materially affects how we use your data, we will notify you directly if we hold contact details for you and the change requires it.
12. Contact us
For any privacy question, request or complaint:
Email: privacy@nazztec.com
Data Protection Officer: dpo@nazztec.com
Post: Privacy Team, NAZZTEC PRIVATE LIMITED, World Trade Center Bangalore, Regus, Unit No 2201A, 22nd Floor, Brigade Gateway, Rajajinagar Extension, Malleswaram (W), Bangalore, Karnataka 560055, India
We aim to acknowledge every privacy enquiry within two business days.
Questions about this policy?
Our privacy team responds to every enquiry. Email privacy@nazztec.com or use the contact form.
We aim to acknowledge every privacy enquiry within two business days.