1. Scope & Regulatory Framework
This Global Privacy Policy (“Policy”) governs the personal data processing, technical security practices, and information governance protocols maintained by SHELL INFOSEC (referred to as “Company”, “we”, “our”, or “us”). We operate as a high-assurance cybersecurity consultancy, cloud infrastructure architect, and sovereign artificial intelligence engineering firm headquartered in New Delhi, India.
Because our core business involves the assessment, defense, and architecture of mission-critical systems, we hold ourselves to rigorous statutory and operational data protection benchmarks:
- The Digital Personal Data Protection Act, 2023 (DPDP Act - India): Governing our responsibilities as a Data Fiduciary and Data Processor across Indian territory, as well as extra-territorial processing related to goods or services offered to Data Principals in India.
- The General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR): Regulating all processing of personal data of individuals residing in the European Union (EU) and European Economic Area (EEA).
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA): Specifically Title II (Security and Privacy Rules, 45 CFR Parts 160 and 164) governing our obligations as a Business Associate when assessing, auditing, or managing healthcare digital infrastructure handling electronic Protected Health Information (ePHI).
- SOC 2 Type II Privacy & Confidentiality Criteria: Continuous alignment with the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for Security, Availability, and Confidentiality.
This Policy applies to visitors accessing our website (shellinfosec.com), enterprise prospective clients submitting technical consultation briefs, job applicants applying through our careers portal, and commercial partners interacting with our engineering team.
2. Identity of the Data Fiduciary & Controller
For the purposes of the Indian DPDP Act 2023, SHELL INFOSEC is the Data Fiduciary determining the purpose and means of personal data processed through our website, intake consultations, and candidate hiring workflows.
Under the EU GDPR, SHELL INFOSEC serves as the Data Controller for web visitor telemetry, communications, and direct inquiries. When delivering contracted penetration tests, vulnerability audits, or cloud architecture reviews on client applications, SHELL INFOSEC acts as a Data Processor under a formal Article 28 Data Processing Addendum (DPA) and executed Statement of Work (SOW).
3. Categories of Information We Collect
We practice strict data minimization. We do not collect unnecessary personal data, we do not purchase marketing contact lists, and we never sell, monetize, or broker personal information to data aggregators. We collect personal data exclusively through the following transparent channels:
A. Information You Provide Voluntarily
When scheduling a strategic technical consultation, requesting an engagement estimate, or applying for an open engineering position:
- Professional Contact Details: Full name, corporate email address, contact phone or WhatsApp number, job title, and organization name.
- Project Scoping Data: Target architecture category (web, mobile, cloud infrastructure, AI model), primary defensive objectives, target timelines, and approximate budget tier.
- Meeting Logistics: Preferred briefing calendar date, localized time slot, and time zone offset.
- Applicant & Recruitment Information: Resume/CV, work history, technical repository links (e.g., GitHub, GitLab), portfolio references, and written statements submitted through our careers workflow.
B. Automated Infrastructure Telemetry
When accessing our website, our edge security systems and analytics services collect standard technical metrics necessary for delivery, bot mitigation, and performance monitoring:
- Network Identifiers: Truncated IP addresses (anonymized at edge ingest), browser user-agent string, operating system architecture, and language preferences.
- Security Telemetry: Cloudflare Turnstile bot verification challenges and request timestamps to prevent automated scraping and denial-of-service attempts.
- Aggregated Behavioral Analytics: Anonymized interaction paths via Microsoft Clarity and Google Analytics with IP masking enabled, measuring page load timings, referral channels, and responsive viewport sizing.
C. Security Assessment Artifacts (Client Engagements)
During contracted penetration testing or source code review missions, we handle vulnerability evidence, system logs, test credentials, and architectural diagrams. These artifacts are classified under our highest internal confidentiality tier, encrypted with dedicated keys, accessible solely to cleared security researchers, and subject to automatic cryptographic purging post-engagement.
4. Lawful Grounds for Processing
In full accordance with the Indian DPDP Act 2023 (Sections 4, 5, and 6) and EU GDPR (Article 6), we process personal data solely when backed by a recognized lawful basis:
Processing necessary to evaluate consultation inquiries, draft Statements of Work, deliver contracted security penetration tests, and provide engineering deliverables.
Where you voluntarily provide contact data to request a briefing or submit an employment application. Consent may be withdrawn at any time through written notification.
Defending our web infrastructure against distributed denial-of-service (DDoS) attacks, brute-force exploits, and unauthorized intrusion attempts.
Complying with corporate governance rules, financial record-keeping requirements under Indian tax law, and lawful directives from judicial authorities.
5. Indian DPDP Act, 2023 Governance
As an Indian cybersecurity and cloud infrastructure enterprise, SHELL INFOSEC complies comprehensively with the Digital Personal Data Protection Act, 2023:
Prior to collecting personal data through our intake forms or scheduling components, we provide an itemized notice stating the specific purpose of collection, the exact data fields required, how consent may be withdrawn, and the coordinates of our Grievance Officer. Consent notices are drafted in plain English with clear, unambiguous language.
We implement reasonable security safeguards to prevent personal data breaches, including hardware-enforced FIDO2 multi-factor authentication, end-to-end transport encryption with TLS 1.3, AES-256-GCM storage encryption, and continuous vulnerability scanning of internal repositories.
In the unlikely event of a confirmed personal data breach affecting personal data under our custody, we execute an immediate internal containment protocol and report the breach to the Data Protection Board of India (DPBI) and affected Data Principals in the form and manner prescribed by statutory rules.
We have appointed a designated Grievance Officer stationed at our New Delhi headquarters to oversee data protection inquiries and resolve grievances. Any Data Principal may contact our Grievance Officer directly via email at [email protected].
6. EU GDPR Adherence & Cross-Border Transfers
When processing personal data originating within the European Union (EU) or European Economic Area (EEA), SHELL INFOSEC adheres to Regulation (EU) 2016/679:
Where personal data is transferred outside the European Economic Area, such transfers are governed by the European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporating Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) as applicable.
We deploy supplementary technical safeguards recommended by the European Data Protection Board (EDPB Recommendation 01/2020), including client-held encryption keys, zero plaintext data access by cloud providers, and localized EU hosting instances upon client request.
Our engineering lifecycle embeds privacy controls into the architectural design phase of every custom software build, sovereign AI deployment, and API integration.
7. Healthcare Data Safeguards & HIPAA Alignment
For enterprise clients operating in healthcare, digital therapeutics, and hospital systems in the United States, SHELL INFOSEC executes standard Business Associate Agreements (BAAs) under 45 CFR Parts 160 and 164:
All security personnel assigned to healthcare audits undergo formal background vetting, sign specialized health-data confidentiality covenants, and operate under strict role-based access restrictions.
All electronic Protected Health Information (ePHI) handled during testing is encrypted in transit via TLS 1.3 and at rest with AES-256-GCM. Penetration testing operations operate against synthetic test datasets whenever possible, adhering strictly to the Minimum Necessary rule under Section 164.502(b).
SHELL INFOSEC maintains zero secondary databases, backups, or shadow copies of client clinical data. Any temporary memory artifacts generated during vulnerability reproduction are destroyed within 14 days of final audit signoff.
8. SOC 2 Type II Confidentiality Governance
In alignment with the AICPA Trust Services Criteria, SHELL INFOSEC maintains rigorous operational safeguards to guarantee the security, availability, and confidentiality of all client assets:
- Least Privilege Access: Access to client repositories, server credentials, and penetration testing findings is strictly restricted on a need-to-know basis.
- Phishing-Resistant MFA: All engineers and researchers must authenticate with FIDO2 hardware security keys. Legacy SMS and unencrypted OTPs are prohibited for production access.
- Immutable Audit Telemetry: All developer access, repository pull requests, and server configuration changes are logged to centralized, append-only SIEM pipelines with 365-day retention.
- Continuous Automated Testing: Internal web services and release pipelines undergo daily static application security testing (SAST) and software composition analysis (SCA).
9. Engagement Artifacts & Zero Retention Policy
During security assessments, vulnerability reproduction, and sovereign AI model fine-tuning, our engineers may interact with proprietary source code, staging databases, API tokens, and architectural blueprints. We enforce a strict Zero Residual Retention Policy:
10. Third-Party Infrastructure & Sub-Processors
To maintain high availability, secure communications, and DDoS resilience, we partner with industry-leading infrastructure providers. Each provider undergoes strict third-party security vetting and is bound by written Data Processing Agreements:
Provides edge reverse proxy caching, DDoS scrubbing, Web Application Firewall (WAF), and Turnstile bot defense.
Provides serverless edge compute hosting for website rendering and static asset distribution.
Enterprise customer relationship management and real-time consultation messaging with localized Indian data hosting options.
Cryptographically verified transactional email delivery for consultation confirmations and strategic briefing notifications.
11. Your Statutory Data Protection Rights
Regardless of your physical location, SHELL INFOSEC extends comprehensive personal data rights in accordance with the Indian DPDP Act 2023 and EU GDPR:
You have the right to obtain a summary of personal data held about you, the processing identities involved, and third-party recipients.
You may request immediate correction of inaccurate or incomplete personal records, or the complete erasure of personal data where retention is no longer justified by contract or law.
You have the right to readily available grievance redressal mechanisms through our statutory Grievance Officer, with guaranteed acknowledgment within 24 hours.
Under Indian law, you may designate another individual who shall, in the event of death or incapacity, exercise your data rights on your behalf.
To exercise any of these rights, email your request to [email protected]. We will verify your identity before taking action and fulfill your verified request within thirty (30) days without charging a fee.
12. Grievance Officer & Statutory Contacts
In satisfaction of Section 8(10) of the Indian Digital Personal Data Protection Act, 2023, and global regulatory mandates, we maintain direct, responsive contact channels: