SHELL INFOSEC

Privacy Policy

How SHELL INFOSEC handles personal data, client confidentiality, and security assessment telemetry. Written with clarity, rigor, and full respect for your legal rights.

DPDP ACTINDIA · 2023
DPDP Act 2023
India Compliant
GDPREU SOVEREIGN
EU GDPR
Articles 12–23
HIPAA
HIPAA Ready
BAA Protected
SOC 2TYPE IIAICPA
SOC 2 Type II
Confidentiality
Effective Date: September 14, 2026
Seat: New Delhi, India
Privacy Desk: [email protected]

1. Scope & Regulatory Framework

This Global Privacy Policy (“Policy”) governs the personal data processing, technical security practices, and information governance protocols maintained by SHELL INFOSEC (referred to as “Company”, “we”, “our”, or “us”). We operate as a high-assurance cybersecurity consultancy, cloud infrastructure architect, and sovereign artificial intelligence engineering firm headquartered in New Delhi, India.

Because our core business involves the assessment, defense, and architecture of mission-critical systems, we hold ourselves to rigorous statutory and operational data protection benchmarks:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act - India): Governing our responsibilities as a Data Fiduciary and Data Processor across Indian territory, as well as extra-territorial processing related to goods or services offered to Data Principals in India.
  • The General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR): Regulating all processing of personal data of individuals residing in the European Union (EU) and European Economic Area (EEA).
  • The Health Insurance Portability and Accountability Act of 1996 (HIPAA): Specifically Title II (Security and Privacy Rules, 45 CFR Parts 160 and 164) governing our obligations as a Business Associate when assessing, auditing, or managing healthcare digital infrastructure handling electronic Protected Health Information (ePHI).
  • SOC 2 Type II Privacy & Confidentiality Criteria: Continuous alignment with the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for Security, Availability, and Confidentiality.

This Policy applies to visitors accessing our website (shellinfosec.com), enterprise prospective clients submitting technical consultation briefs, job applicants applying through our careers portal, and commercial partners interacting with our engineering team.

2. Identity of the Data Fiduciary & Controller

For the purposes of the Indian DPDP Act 2023, SHELL INFOSEC is the Data Fiduciary determining the purpose and means of personal data processed through our website, intake consultations, and candidate hiring workflows.

Under the EU GDPR, SHELL INFOSEC serves as the Data Controller for web visitor telemetry, communications, and direct inquiries. When delivering contracted penetration tests, vulnerability audits, or cloud architecture reviews on client applications, SHELL INFOSEC acts as a Data Processor under a formal Article 28 Data Processing Addendum (DPA) and executed Statement of Work (SOW).

Legal Entity: SHELL INFOSEC
MSME Registration: UDYAM-DL-09-0012062
Registered Address: New Delhi, Delhi 110001, Republic of India
Direct Telephony: +91 99119 48198
Official Communications: [email protected]

3. Categories of Information We Collect

We practice strict data minimization. We do not collect unnecessary personal data, we do not purchase marketing contact lists, and we never sell, monetize, or broker personal information to data aggregators. We collect personal data exclusively through the following transparent channels:

A. Information You Provide Voluntarily

When scheduling a strategic technical consultation, requesting an engagement estimate, or applying for an open engineering position:

  • Professional Contact Details: Full name, corporate email address, contact phone or WhatsApp number, job title, and organization name.
  • Project Scoping Data: Target architecture category (web, mobile, cloud infrastructure, AI model), primary defensive objectives, target timelines, and approximate budget tier.
  • Meeting Logistics: Preferred briefing calendar date, localized time slot, and time zone offset.
  • Applicant & Recruitment Information: Resume/CV, work history, technical repository links (e.g., GitHub, GitLab), portfolio references, and written statements submitted through our careers workflow.

B. Automated Infrastructure Telemetry

When accessing our website, our edge security systems and analytics services collect standard technical metrics necessary for delivery, bot mitigation, and performance monitoring:

  • Network Identifiers: Truncated IP addresses (anonymized at edge ingest), browser user-agent string, operating system architecture, and language preferences.
  • Security Telemetry: Cloudflare Turnstile bot verification challenges and request timestamps to prevent automated scraping and denial-of-service attempts.
  • Aggregated Behavioral Analytics: Anonymized interaction paths via Microsoft Clarity and Google Analytics with IP masking enabled, measuring page load timings, referral channels, and responsive viewport sizing.

C. Security Assessment Artifacts (Client Engagements)

During contracted penetration testing or source code review missions, we handle vulnerability evidence, system logs, test credentials, and architectural diagrams. These artifacts are classified under our highest internal confidentiality tier, encrypted with dedicated keys, accessible solely to cleared security researchers, and subject to automatic cryptographic purging post-engagement.

4. Lawful Grounds for Processing

In full accordance with the Indian DPDP Act 2023 (Sections 4, 5, and 6) and EU GDPR (Article 6), we process personal data solely when backed by a recognized lawful basis:

1. Performance of a Contract

Processing necessary to evaluate consultation inquiries, draft Statements of Work, deliver contracted security penetration tests, and provide engineering deliverables.

2. Informed, Explicit Consent

Where you voluntarily provide contact data to request a briefing or submit an employment application. Consent may be withdrawn at any time through written notification.

3. Legitimate Interests

Defending our web infrastructure against distributed denial-of-service (DDoS) attacks, brute-force exploits, and unauthorized intrusion attempts.

4. Statutory Obligations

Complying with corporate governance rules, financial record-keeping requirements under Indian tax law, and lawful directives from judicial authorities.

5. Indian DPDP Act, 2023 Governance

As an Indian cybersecurity and cloud infrastructure enterprise, SHELL INFOSEC complies comprehensively with the Digital Personal Data Protection Act, 2023:

Notice & Consent Architecture (Section 5)

Prior to collecting personal data through our intake forms or scheduling components, we provide an itemized notice stating the specific purpose of collection, the exact data fields required, how consent may be withdrawn, and the coordinates of our Grievance Officer. Consent notices are drafted in plain English with clear, unambiguous language.

Reasonable Security Safeguards (Section 8(5))

We implement reasonable security safeguards to prevent personal data breaches, including hardware-enforced FIDO2 multi-factor authentication, end-to-end transport encryption with TLS 1.3, AES-256-GCM storage encryption, and continuous vulnerability scanning of internal repositories.

Breach Escalation & Notification (Section 8(6))

In the unlikely event of a confirmed personal data breach affecting personal data under our custody, we execute an immediate internal containment protocol and report the breach to the Data Protection Board of India (DPBI) and affected Data Principals in the form and manner prescribed by statutory rules.

Statutory Grievance Redressal Officer (Section 8(10))

We have appointed a designated Grievance Officer stationed at our New Delhi headquarters to oversee data protection inquiries and resolve grievances. Any Data Principal may contact our Grievance Officer directly via email at [email protected].

6. EU GDPR Adherence & Cross-Border Transfers

When processing personal data originating within the European Union (EU) or European Economic Area (EEA), SHELL INFOSEC adheres to Regulation (EU) 2016/679:

Standard Contractual Clauses (SCCs - Articles 44–49)

Where personal data is transferred outside the European Economic Area, such transfers are governed by the European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporating Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) as applicable.

Supplementary Technical Measures (Schrems II Compliance)

We deploy supplementary technical safeguards recommended by the European Data Protection Board (EDPB Recommendation 01/2020), including client-held encryption keys, zero plaintext data access by cloud providers, and localized EU hosting instances upon client request.

Data Protection by Design and by Default (Article 25)

Our engineering lifecycle embeds privacy controls into the architectural design phase of every custom software build, sovereign AI deployment, and API integration.

7. Healthcare Data Safeguards & HIPAA Alignment

For enterprise clients operating in healthcare, digital therapeutics, and hospital systems in the United States, SHELL INFOSEC executes standard Business Associate Agreements (BAAs) under 45 CFR Parts 160 and 164:

Administrative Safeguards (Section 164.308)

All security personnel assigned to healthcare audits undergo formal background vetting, sign specialized health-data confidentiality covenants, and operate under strict role-based access restrictions.

Technical Safeguards (Section 164.312)

All electronic Protected Health Information (ePHI) handled during testing is encrypted in transit via TLS 1.3 and at rest with AES-256-GCM. Penetration testing operations operate against synthetic test datasets whenever possible, adhering strictly to the Minimum Necessary rule under Section 164.502(b).

Zero Secondary Retention

SHELL INFOSEC maintains zero secondary databases, backups, or shadow copies of client clinical data. Any temporary memory artifacts generated during vulnerability reproduction are destroyed within 14 days of final audit signoff.

8. SOC 2 Type II Confidentiality Governance

In alignment with the AICPA Trust Services Criteria, SHELL INFOSEC maintains rigorous operational safeguards to guarantee the security, availability, and confidentiality of all client assets:

  • Least Privilege Access: Access to client repositories, server credentials, and penetration testing findings is strictly restricted on a need-to-know basis.
  • Phishing-Resistant MFA: All engineers and researchers must authenticate with FIDO2 hardware security keys. Legacy SMS and unencrypted OTPs are prohibited for production access.
  • Immutable Audit Telemetry: All developer access, repository pull requests, and server configuration changes are logged to centralized, append-only SIEM pipelines with 365-day retention.
  • Continuous Automated Testing: Internal web services and release pipelines undergo daily static application security testing (SAST) and software composition analysis (SCA).

9. Engagement Artifacts & Zero Retention Policy

During security assessments, vulnerability reproduction, and sovereign AI model fine-tuning, our engineers may interact with proprietary source code, staging databases, API tokens, and architectural blueprints. We enforce a strict Zero Residual Retention Policy:

14-Day Purge Window: Within fourteen (14) calendar days following final deliverable handover and executive signoff, all raw network traces, temporary staging dumps, local test containers, and client API tokens are cryptographically wiped following NIST SP 800-88 Rev 1 guidelines.
Encrypted Archival of Final Reports: Only the final executive vulnerability assessment report and formal remediation verification certificate are retained in our encrypted client vault for accounting and warranty verification purposes.
Written Destruction Certification: Upon formal client request, our technical director issues a written certificate of data destruction confirming complete sanitization of all engagement assets.

10. Third-Party Infrastructure & Sub-Processors

To maintain high availability, secure communications, and DDoS resilience, we partner with industry-leading infrastructure providers. Each provider undergoes strict third-party security vetting and is bound by written Data Processing Agreements:

Cloudflare, Inc. (USA / Global)

Provides edge reverse proxy caching, DDoS scrubbing, Web Application Firewall (WAF), and Turnstile bot defense.

Vercel Inc. (USA / Global Edge)

Provides serverless edge compute hosting for website rendering and static asset distribution.

Zoho Corporation (India / Global)

Enterprise customer relationship management and real-time consultation messaging with localized Indian data hosting options.

Resend, Inc. / Postmark (Transactional Mail)

Cryptographically verified transactional email delivery for consultation confirmations and strategic briefing notifications.

11. Your Statutory Data Protection Rights

Regardless of your physical location, SHELL INFOSEC extends comprehensive personal data rights in accordance with the Indian DPDP Act 2023 and EU GDPR:

Right to Access & Information Summary:

You have the right to obtain a summary of personal data held about you, the processing identities involved, and third-party recipients.

Right to Correction & Erasure:

You may request immediate correction of inaccurate or incomplete personal records, or the complete erasure of personal data where retention is no longer justified by contract or law.

Right of Grievance Redressal:

You have the right to readily available grievance redressal mechanisms through our statutory Grievance Officer, with guaranteed acknowledgment within 24 hours.

Right to Nominate (DPDP Act Section 14):

Under Indian law, you may designate another individual who shall, in the event of death or incapacity, exercise your data rights on your behalf.

To exercise any of these rights, email your request to [email protected]. We will verify your identity before taking action and fulfill your verified request within thirty (30) days without charging a fee.

12. Grievance Officer & Statutory Contacts

In satisfaction of Section 8(10) of the Indian Digital Personal Data Protection Act, 2023, and global regulatory mandates, we maintain direct, responsive contact channels:

Statutory Grievance Officer (India)
Designation: Head of Information Governance
Jurisdiction: DPDP Act 2023 / MeitY Mandates
Office: SHELL INFOSEC, New Delhi 110001, India
Dedicated Email: [email protected]
Statutory SLA: Acknowledgment <24 hrs · Resolution <30 days
Global Privacy & Security Desk
Entity: SHELL INFOSEC (UDYAM-DL-09-0012062)
General Email: [email protected]
Data Privacy: [email protected]
Direct Telephony: +91 99119 48198
Operating Seat: New Delhi, India
Contact & Inquiries

Questions Regarding Your Privacy Rights?

Whether you wish to exercise your statutory rights under the Indian DPDP Act or EU GDPR, request a custom Data Processing Addendum, or consult our Grievance Officer, our team is directly accessible.

Privacy Desk[email protected]
Grievance Officer[email protected]
Telephony+91 99119 48198