VCF Cyber Solutions Pvt. Ltd.

Start Here

Cyber Risk Health Check

Assess

External Attack Surface Assessment Web & API VAPT Network VAPT Cloud Security Assessment SaaS Security Readiness DPDP Security Readiness AI Security Assessment

Fix & Protect

Security Remediation & Hardening vCISO / Virtual Security Function Managed Security

Emergency

Incident Response
+91 73853 69311 | +91 82088 22572 contact@vigilantecyberforces.com

Privacy Policy

Effective date: 1 August 2026  |  Last updated: 11 August 2026

1. Introduction

VCF Cyber Solutions Pvt. Ltd. ("VCF Cyber Solutions," "we," "us," or "our") provides cybersecurity assessment, VAPT, remediation, vCISO, managed security, and incident response services. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, request a quote, engage us for services, or otherwise interact with us.

By using our website or engaging our services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our website or services.

2. Scope

This policy applies to personal data we collect through:

  • Our website and its contact/quote request forms;
  • Email, phone, and WhatsApp communications with our team;
  • The delivery of security assessments, VAPT, remediation, vCISO, managed security, and incident response engagements;
  • Any other interaction where this policy is referenced.

This policy does not apply to the systems, applications, or infrastructure we test on behalf of clients — the handling of client environment data during an engagement is instead governed by the confidentiality and data-handling terms in the applicable statement of work / service agreement.

3. Information We Collect

3.1 Information you provide directly

  • Contact details: name, company name, job title, email address, phone number.
  • Engagement details: information you share when requesting a quote or scoping an assessment (e.g. domains, applications, network ranges, environment descriptions).
  • Communications: messages sent via email, our contact forms, WhatsApp, or phone, including call and chat records where applicable.
  • During incident response engagements: information reasonably necessary to investigate, contain, and remediate a security incident, which may include logs, credentials for scoped systems, and other technical data you provide to us for that purpose.

3.2 Information collected automatically

  • Standard web analytics data (IP address, browser type, device type, pages visited, referring URL, approximate location) collected via cookies or similar technologies and tools such as Google Analytics.
  • Server and security logs generated in the ordinary course of operating our website.

3.3 Information from third parties

We may receive limited contact or company information from business partners, referral sources, or publicly available sources (e.g. LinkedIn, company websites) when reasonably relevant to a prospective engagement.

4. Cookies & Similar Technologies

Our website may use cookies and similar technologies to remember preferences, understand site usage, and support analytics. You can control or disable cookies through your browser settings; doing so may affect some site functionality. We do not use cookies for third-party advertising.

5. How We Use Your Information

  • To respond to enquiries and provide quotes for our services;
  • To scope, deliver, and support cybersecurity assessments and related services;
  • To communicate with you about ongoing or prospective engagements;
  • To send invoices and process payments for services rendered;
  • To maintain records required for audit, compliance, and legal purposes;
  • To improve our website and services;
  • To comply with applicable law, regulation, or lawful requests from authorities;
  • With your consent, to send updates about our services (you may opt out at any time).

6. Legal Basis for Processing

Where the Indian Digital Personal Data Protection Act, 2023 ("DPDP Act") or another applicable data protection law requires a legal basis, we rely on one or more of the following: your consent, the necessity of processing to perform a contract with you, our legitimate business interests (such as operating and securing our services), and compliance with our legal obligations.

7. How We Share Information

We do not sell personal data. We may share information with:

  • Service providers who support our operations (e.g. hosting, email, analytics, accounting, payment processing), bound by confidentiality and data protection obligations;
  • Subcontracted security professionals, only where necessary to deliver an engagement and under confidentiality obligations at least as protective as those in the client agreement;
  • Professional advisors such as auditors, insurers, or legal counsel, where necessary;
  • Authorities or regulators, where required by law, court order, or to protect our rights, safety, or property, or that of others;
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

8. Handling of Assessment & Engagement Data

Given the sensitive nature of our work, findings, reports, credentials, and any data accessed while delivering assessments, VAPT, remediation, vCISO, managed security, or incident response services are treated as strictly confidential and handled under the terms of the relevant engagement agreement / NDA, in addition to this Privacy Policy. Access is restricted to personnel directly involved in delivering the engagement, and such data is used solely for the purpose of that engagement. Engagement artefacts (reports, findings, and any credentials or data accessed during testing) are retained for 12 months after the engagement concludes and then securely deleted, unless a longer retention period is required by law or agreed with the Client.

9. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, to comply with our legal, accounting, or reporting obligations, and to resolve disputes. As a general rule, engagement-related data (reports, findings, and technical data accessed during an assessment) is retained for 12 months after the engagement ends and then securely deleted, and general enquiry/contact data is retained for as long as needed to respond to your enquiry or maintain the business relationship, unless a longer period is required by law.

10. Data Security

As a cybersecurity firm, we apply security practices commensurate with the sensitivity of the data we handle, including access controls, encryption in transit, restricted internal access, and confidentiality obligations for personnel and subcontractors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your Rights

Subject to applicable law (including the DPDP Act, where applicable), you may have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request erasure of your personal data, subject to our legal and contractual obligations;
  • Withdraw consent where processing is based on consent;
  • Nominate a representative to exercise your rights in the event of your death or incapacity;
  • Lodge a grievance with us, and where applicable, escalate to the relevant data protection authority.

To exercise any of these rights, contact us using the details in Section 15.

12. Grievance Officer

In accordance with applicable Indian law, grievances regarding this Privacy Policy or our handling of your personal data can be raised with our team at contact@vigilantecyberforces.com. We aim to acknowledge grievances promptly and resolve them within the timelines prescribed by applicable law.

13. Third-Party Links

Our website may contain links to third-party sites (e.g. LinkedIn). We are not responsible for the privacy practices of those sites and encourage you to review their policies separately.

14. Children's Privacy

Our website and services are intended for businesses and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

15. International Data Transfers

We are based in India. If we engage service providers or subcontractors located outside India, we take reasonable steps to ensure your data continues to receive an appropriate level of protection consistent with this policy and applicable law.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be reflected on this page.

17. Contact Us

For questions, requests, or concerns about this Privacy Policy or our data practices, contact us at:

VCF Cyber Solutions Pvt. Ltd.
3rd Floor, Vasant Villa, Bazaar Chowk, Jaitala Road, Nagpur, Maharashtra - 440010, India
Email: contact@vigilantecyberforces.com
Phone: +91 73853 69311 | +91 82088 22572

VCF Cyber Solutions Pvt. Ltd.

Cybersecurity for companies that are too small for a large internal team, but too important to ignore cyber risk.

Products

  • Health Check
  • Web & API VAPT
  • Cloud Security
  • vCISO

Company

  • All Services
  • Who We Are
  • Incident Response

Contact

  • contact@vigilantecyberforces.com
  • LinkedIn
+91 73853 69311 | +91 82088 22572 contact@vigilantecyberforces.com
© 2026 VCF Cyber Solutions Pvt. Ltd. All rights reserved.
Privacy Policy Terms of Service