Legal
Privacy Policy
What personal data this website collects, why we collect it, how long we keep it and what you can ask us to do with it.
Last updated 1 August 2026
1. Scope
This policy applies to personal data that Infolocklabs LLP ("Infolocklabs", "we", "us") processes through the website at infolocklabs.com and through enquiries made to us using the contact details on this site.
It does not cover data we process on behalf of a client under a services agreement. In those engagements the client is the data controller or fiduciary, we act on their documented instructions, and the terms of that engagement govern.
This page describes our practices and is provided for information. It is not legal advice, and it does not create any advisory relationship. Obtain your own professional advice before relying on it.
2. Who we are
Infolocklabs LLP is a limited liability partnership providing cybersecurity and technology services, based in Gurugram, Haryana, India.
For any question about this policy or about the personal data we hold, contact us at contact@infolocklabs.com.
3. What we collect
We collect only what we need to respond to an enquiry and to keep this website secure and functioning.
| Category | Data | Source |
|---|---|---|
| Enquiry details | Name, company name, email address, phone number, the service you selected and the content of your message. | You, through the contact form. |
| Technical data | IP address, browser user agent, the time of the submission and an automated abuse score. | Collected automatically when you submit the form. |
| Consent record | Your cookie preference and when you set it. | Stored in a first-party cookie in your browser. |
| Analytics data | Aggregated usage such as pages viewed and approximate region, only if you accept analytics cookies. | Google Analytics, after consent. |
We do not ask for, and you should not send us, sensitive personal data through this website — including government identifiers, financial account details, health information or credentials of any kind.
4. Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| Responding to your enquiry and any follow-up correspondence. | Your consent, given when you submit the form, and our legitimate interest in conducting business correspondence. |
| Preventing spam, automated abuse and denial of service against this website. | Our legitimate interest in operating a secure service. |
| Keeping records of enquiries for business administration. | Our legitimate interest, and where applicable our legal obligation to retain business records. |
| Understanding how the website is used so that we can improve it. | Your consent, given through the cookie banner. |
We do not sell personal data, we do not share it with advertising networks, and we do not use it for automated decision-making that produces legal or similarly significant effects.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to an engagement | Up to 24 months from the last contact, then deleted. |
| Enquiries flagged as spam | Up to 90 days, then deleted. |
| Enquiries that lead to an engagement | For the duration of the engagement and for the period required for business and statutory record-keeping afterwards. |
| Website security logs | Retained for a limited operational period and then discarded. |
| Cookie consent record | Up to 6 months, after which you are asked again. |
You can ask us to delete your enquiry sooner. See section 9.
8. How we protect it
We apply the controls we would expect of any organisation we assessed:
- Data in transit is encrypted with TLS.
- Administrative access requires an individual account and is limited by role.
- Administrative passwords are stored using Argon2id password hashing; they are never stored in a recoverable form.
- Credentials for third-party integrations are encrypted at rest or held only in environment configuration.
- Administrative actions are recorded in an audit log.
- Access to the database is restricted to the application and to named administrators.
No control set makes a system immune to compromise. If a personal data breach occurs that is likely to result in risk to you, we will notify affected individuals and the relevant authority as required by applicable law.
9. Your rights
Subject to the law that applies to you, you may ask us to:
- Confirm what personal data we hold about you and provide a copy of it.
- Correct data that is inaccurate, incomplete or out of date.
- Delete data we no longer need for the purpose it was collected for.
- Restrict or object to a particular use of your data.
- Withdraw a consent you previously gave, without affecting processing already carried out.
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity, where the applicable law provides for it.
To make a request, email contact@infolocklabs.com with enough detail for us to identify your records. We will respond within the period required by the applicable law and, where none applies, within 30 days. We may ask you to verify your identity before acting on a request.
If you are not satisfied with our response, you may complain to the data protection authority with jurisdiction over your personal data. In India this is the Data Protection Board established under the Digital Personal Data Protection Act, 2023.
10. India's Digital Personal Data Protection Act
We are established in India, and where the Digital Personal Data Protection Act, 2023 applies to our processing we act as a Data Fiduciary in respect of the enquiry data described in this policy.
Our practices are intended to align with the principles of that Act: collecting only what is needed for a stated purpose, obtaining consent where consent is the basis, keeping the data accurate, retaining it no longer than necessary, securing it with reasonable safeguards, and honouring the rights of Data Principals set out in section 9.
Stating an intention to align with a statutory framework is not a claim of certified compliance with it. The Act and its rules continue to be implemented in stages, and we update this policy as obligations take effect.
11. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from a child. If you believe a child has submitted data to us, contact us and we will delete it.
12. Changes to this policy
We update this policy when our practices change. The date at the top of this page reflects the most recent substantive revision. Where a change materially affects how we use data you have already given us, we will take reasonable steps to tell you.
13. Contact
Infolocklabs LLP, Gurugram, Haryana, India. Email: contact@infolocklabs.com. Phone: +91 9372406405.