🛡️ Privacy Vault

Privacy Policy

Last Updated: August 29, 2026

Introduction

Welcome to VayuX Systems. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store, and process your information when you interact with our website or services. We comply with the Digital Personal Data Protection (DPDP) Act 2023 and maintain strict data sovereignty standards.

Data We Collect

We collect the following types of information:

  • Identity Data: First name, last name, job title, and professional credentials
  • Contact Data: Business email, phone number, organization name, and location
  • Security Data: When using our SOC, VAPT, or DFIR services, we process logs, telemetry, and security events exclusively within India-hosted infrastructure
  • Usage Data: Information about how you interact with our website and dashboards

How We Use Your Data

Your data is used exclusively for:

  • Service Delivery: Operating our SOC, conducting VAPT assessments, executing DFIR investigations, and maintaining GRC compliance
  • Threat Intelligence: Analyzing security patterns to improve our autonomous defense mechanisms (fully anonymized, no client identification)
  • Communication: Sending critical security alerts, incident reports, and compliance updates
  • R&D Advancement: Anonymized insights feed directly into VayuX research to improve security architectures

Data Sovereignty & Security

Your data stays in India.

All security telemetry and personal data processed by VayuX is stored exclusively on private, dedicated infrastructure located within India. We do not transmit any client security logs or telemetry to international cloud services. We implement AES-256 encryption for all data at rest and in transit, with strict access controls enforced through multi-factor authentication.

In compliance with CERT-In directives, we maintain audit logs for security investigations and regulatory compliance. All infrastructure meets or exceeds ISO 27001 standards.

DPDP Act 2023 & Data Retention

VayuX fully complies with the Digital Personal Data Protection Act 2023. As a Data Processor for client enterprise security logs, we retain security telemetry only as long as necessary to fulfill service commitments or as mandated by law.

  • SOC logs retained for 180 days (CERT-In mandate)
  • DFIR forensic artifacts retained for 90 days post-incident
  • GRC compliance records retained for 1 year
  • Website visitor data retained for 30 days

Your Legal Rights

Under the DPDP Act 2023, you have the right to:

  • Request access to your personal data
  • Request correction or deletion of your personal data
  • Withdraw consent for data processing (subject to service continuity requirements)
  • File a grievance with our Data Protection Officer at [email protected]

Third-Party Services

VayuX does not sell or share personal data with third parties. We may use service providers (email delivery, hosting, analytics) that process data on our behalf under strict Data Processing Agreements. All such services must comply with DPDP Act requirements and maintain equivalent security standards.

Contact Us

For privacy-related inquiries, data requests, or to exercise your rights:

Data Protection Officer: [email protected]

General Inquiries: [email protected]

Location: Vadodara, Gujarat, India