Privacy Policy

Legal

Privacy Policy & Legal

Last Updated: June 2026 Nexarcane Forensics & Technology (OPC) Pvt. Ltd. Bengaluru, Karnataka, India

Introduction

Nexarcane Forensics & Technology (OPC) Pvt. Ltd. ("Nexarcane", "we", "us", or "our") is committed to protecting the privacy and confidentiality of all individuals and organizations whose personal data we process. This Privacy Policy explains how we collect, use, store, share, and protect information in connection with our website (nexarcane.com) and our professional services.

This policy is compliant with India's Digital Personal Data Protection Act 2023 (DPDPA), the Information Technology Act 2000 and its amendments, and our ISO 27001:2022 certified information security management framework.

By using our website or engaging our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please refrain from using our services or contact us at info@nexarcane.com to discuss alternatives.

Information We Collect

Information You Provide Directly

We collect personal data that you voluntarily provide when you:

  • Fill out our contact form or inquiry form
  • Email or call us directly
  • Engage us for professional services
  • Apply for a career opportunity
  • Subscribe to our newsletter or insights

This may include: your full name, email address, phone number, company name, designation, and the nature of your inquiry or case.

Information Collected Automatically

When you visit our website, we may automatically collect certain technical information including:

  • IP address and approximate geographic location
  • Browser type and version
  • Pages visited, time spent, and referral source
  • Device type and operating system

This data is collected through cookies and similar technologies (see our Cookies Policy section below) and is used only for website analytics and improvement purposes.

Client Engagement Data

For clients who engage our forensics, cybersecurity, or other professional services, we may handle highly sensitive data as part of the service delivery — including digital evidence, system logs, network data, and personal communications. All such data is governed by a separate Non-Disclosure Agreement (NDA) entered into prior to any engagement, and is handled under our ISO 27001:2022 and ISO 27037:2012 certified frameworks.

How We Use Information

We use the personal information we collect for the following purposes:

  • Service Delivery: To provide, operate, and improve our cybersecurity, forensics, and related services
  • Communication: To respond to inquiries, provide quotations, and maintain client relationships
  • Legal & Compliance: To meet our legal obligations, maintain records as required by law, and support court or regulatory proceedings where applicable
  • Security: To protect the integrity of our systems, services, and client data from unauthorized access or misuse
  • Analytics: To understand how our website is used and improve user experience
  • Marketing (with consent): To send insights, updates, and relevant information — only where you have consented to receive such communications

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data to any third party for commercial purposes — ever.

We may share your information only in the following limited circumstances:

  • Service Providers: Trusted technology partners who assist in delivering our services (such as email hosting, CRM, or cloud storage), all of whom are bound by confidentiality obligations and data processing agreements
  • Legal Requirements: When required by Indian law, court order, or regulatory authority (such as CERT-In, law enforcement agencies, or judicial authorities) — and only to the extent required
  • Client-Authorized Disclosure: Where a client specifically authorizes disclosure as part of a forensic investigation or legal proceeding
  • Business Continuity: In the event of a merger, acquisition, or organizational restructuring, subject to equivalent privacy protections

In all cases, disclosures are made on a need-to-know basis and consistent with our confidentiality obligations and this Privacy Policy.

Data Security

Nexarcane is certified to ISO 27001:2022 — the international standard for information security management. This means our security controls, processes, and infrastructure have been independently audited and verified against global benchmarks.

Our security measures include:

  • Encrypted data storage and transmission (TLS 1.2+)
  • Role-based access controls and least-privilege principles
  • Regular vulnerability assessments of our own infrastructure
  • Employee security training and awareness programs
  • Incident response procedures compliant with DPDPA 2023 breach notification requirements
  • Physical security controls at our Bengaluru office

All client engagement data is handled under signed NDA and our ISO 27037:2012 certified digital evidence handling procedures. In the event of a personal data breach affecting your data, we will notify you as required under applicable law.

Cookies Policy

Our website uses cookies — small text files stored on your device — to enhance your browsing experience. We use the following types of cookies:

  • Essential Cookies: Required for basic website functionality (e.g., your cookie consent preference stored in localStorage). These cannot be disabled.
  • Analytics Cookies: Used to understand how visitors interact with our website (page views, time on site, referral sources). We use aggregated, anonymized data only.
  • Preference Cookies: Remember your settings and preferences for future visits.

When you first visit our website, you will be presented with a cookie consent banner. You may accept or decline non-essential cookies at any time. Your choice is stored locally on your device and respected on subsequent visits.

We do not use tracking cookies for advertising, retargeting, or cross-site behavioral tracking. You may also control cookies through your browser settings.

Your Rights Under DPDPA 2023

India's Digital Personal Data Protection Act 2023 (DPDPA) grants you the following rights as a "Data Principal" (the individual whose data we process). We are committed to honouring these rights promptly and transparently:

  • Right to Access: You may request a summary of the personal data we hold about you and the purposes for which it is processed
  • Right to Correction: You may request that inaccurate or incomplete personal data be corrected or updated
  • Right to Erasure: You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations
  • Right to Grievance Redressal: You may raise a grievance regarding our handling of your data, and we will respond within a reasonable timeframe
  • Right to Nominate: You may nominate another individual to exercise your data rights in the event of your incapacity
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time — without affecting the lawfulness of processing prior to withdrawal

To exercise any of these rights, please contact our Privacy Officer at info@nexarcane.com. We will respond within 30 days. If you are dissatisfied with our response, you may approach the Data Protection Board of India once established under the DPDPA 2023.

Retention Policy

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law:

  • Website inquiry data: Retained for 2 years after last contact, then securely deleted
  • Client engagement records: Retained for 7 years from project completion (as required by Indian commercial and tax law), then securely destroyed
  • Digital evidence (forensic cases): Retained as agreed in the engagement contract, typically until legal proceedings are concluded or the client confirms destruction
  • Employment applications: Retained for 1 year after the recruitment process concludes
  • Financial records: Retained for 8 years as required under the Companies Act 2013 and GST regulations

When data reaches the end of its retention period, it is securely deleted from all systems using methods appropriate to the sensitivity of the data (including cryptographic erasure for digital evidence).

Contact for Privacy

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our data handling practices, please contact our Privacy Officer:

Nexarcane Forensics & Technology (OPC) Pvt. Ltd.
3rd Floor, 18/3, Andree Rd, Shanti Nagar, Bengaluru, Karnataka 560027, India

We will acknowledge your request within 72 hours and endeavour to resolve it within 30 days. For complex requests or legal proceedings, timelines may be extended with appropriate notice.

This policy was last reviewed and updated in June 2026. We may update this policy periodically. Material changes will be notified via a prominent notice on our website prior to taking effect.

Nexarcane
Scroll to Top