Legal
Privacy Policy & Legal
Introduction
Nexarcane Forensics & Technology (OPC) Pvt. Ltd. ("Nexarcane", "we", "us", or "our") is committed to protecting the privacy and confidentiality of all individuals and organizations whose personal data we process. This Privacy Policy explains how we collect, use, store, share, and protect information in connection with our website (nexarcane.com) and our professional services.
This policy is compliant with India's Digital Personal Data Protection Act 2023 (DPDPA), the Information Technology Act 2000 and its amendments, and our ISO 27001:2022 certified information security management framework.
By using our website or engaging our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please refrain from using our services or contact us at info@nexarcane.com to discuss alternatives.
Information We Collect
Information You Provide Directly
We collect personal data that you voluntarily provide when you:
- Fill out our contact form or inquiry form
- Email or call us directly
- Engage us for professional services
- Apply for a career opportunity
- Subscribe to our newsletter or insights
This may include: your full name, email address, phone number, company name, designation, and the nature of your inquiry or case.
Information Collected Automatically
When you visit our website, we may automatically collect certain technical information including:
- IP address and approximate geographic location
- Browser type and version
- Pages visited, time spent, and referral source
- Device type and operating system
This data is collected through cookies and similar technologies (see our Cookies Policy section below) and is used only for website analytics and improvement purposes.
Client Engagement Data
For clients who engage our forensics, cybersecurity, or other professional services, we may handle highly sensitive data as part of the service delivery — including digital evidence, system logs, network data, and personal communications. All such data is governed by a separate Non-Disclosure Agreement (NDA) entered into prior to any engagement, and is handled under our ISO 27001:2022 and ISO 27037:2012 certified frameworks.
How We Use Information
We use the personal information we collect for the following purposes:
- Service Delivery: To provide, operate, and improve our cybersecurity, forensics, and related services
- Communication: To respond to inquiries, provide quotations, and maintain client relationships
- Legal & Compliance: To meet our legal obligations, maintain records as required by law, and support court or regulatory proceedings where applicable
- Security: To protect the integrity of our systems, services, and client data from unauthorized access or misuse
- Analytics: To understand how our website is used and improve user experience
- Marketing (with consent): To send insights, updates, and relevant information — only where you have consented to receive such communications
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data to any third party for commercial purposes — ever.
We may share your information only in the following limited circumstances:
- Service Providers: Trusted technology partners who assist in delivering our services (such as email hosting, CRM, or cloud storage), all of whom are bound by confidentiality obligations and data processing agreements
- Legal Requirements: When required by Indian law, court order, or regulatory authority (such as CERT-In, law enforcement agencies, or judicial authorities) — and only to the extent required
- Client-Authorized Disclosure: Where a client specifically authorizes disclosure as part of a forensic investigation or legal proceeding
- Business Continuity: In the event of a merger, acquisition, or organizational restructuring, subject to equivalent privacy protections
In all cases, disclosures are made on a need-to-know basis and consistent with our confidentiality obligations and this Privacy Policy.
Data Security
Nexarcane is certified to ISO 27001:2022 — the international standard for information security management. This means our security controls, processes, and infrastructure have been independently audited and verified against global benchmarks.
Our security measures include:
- Encrypted data storage and transmission (TLS 1.2+)
- Role-based access controls and least-privilege principles
- Regular vulnerability assessments of our own infrastructure
- Employee security training and awareness programs
- Incident response procedures compliant with DPDPA 2023 breach notification requirements
- Physical security controls at our Bengaluru office
All client engagement data is handled under signed NDA and our ISO 27037:2012 certified digital evidence handling procedures. In the event of a personal data breach affecting your data, we will notify you as required under applicable law.
Cookies Policy
Our website uses cookies — small text files stored on your device — to enhance your browsing experience. We use the following types of cookies:
- Essential Cookies: Required for basic website functionality (e.g., your cookie consent preference stored in
localStorage). These cannot be disabled. - Analytics Cookies: Used to understand how visitors interact with our website (page views, time on site, referral sources). We use aggregated, anonymized data only.
- Preference Cookies: Remember your settings and preferences for future visits.
When you first visit our website, you will be presented with a cookie consent banner. You may accept or decline non-essential cookies at any time. Your choice is stored locally on your device and respected on subsequent visits.
We do not use tracking cookies for advertising, retargeting, or cross-site behavioral tracking. You may also control cookies through your browser settings.
Your Rights Under DPDPA 2023
India's Digital Personal Data Protection Act 2023 (DPDPA) grants you the following rights as a "Data Principal" (the individual whose data we process). We are committed to honouring these rights promptly and transparently:
- Right to Access: You may request a summary of the personal data we hold about you and the purposes for which it is processed
- Right to Correction: You may request that inaccurate or incomplete personal data be corrected or updated
- Right to Erasure: You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations
- Right to Grievance Redressal: You may raise a grievance regarding our handling of your data, and we will respond within a reasonable timeframe
- Right to Nominate: You may nominate another individual to exercise your data rights in the event of your incapacity
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time — without affecting the lawfulness of processing prior to withdrawal
To exercise any of these rights, please contact our Privacy Officer at info@nexarcane.com. We will respond within 30 days. If you are dissatisfied with our response, you may approach the Data Protection Board of India once established under the DPDPA 2023.
Retention Policy
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law:
- Website inquiry data: Retained for 2 years after last contact, then securely deleted
- Client engagement records: Retained for 7 years from project completion (as required by Indian commercial and tax law), then securely destroyed
- Digital evidence (forensic cases): Retained as agreed in the engagement contract, typically until legal proceedings are concluded or the client confirms destruction
- Employment applications: Retained for 1 year after the recruitment process concludes
- Financial records: Retained for 8 years as required under the Companies Act 2013 and GST regulations
When data reaches the end of its retention period, it is securely deleted from all systems using methods appropriate to the sensitivity of the data (including cryptographic erasure for digital evidence).
Legal & Terms of Service
Terms of Service Summary
By accessing and using the Nexarcane website or engaging our professional services, you agree to the following terms:
- Our website content is provided for informational purposes only and does not constitute legal or professional advice
- Unauthorized use of our website, services, or intellectual property (including our logo, brand name, and content) is strictly prohibited
- All service engagements are governed by a separate Service Agreement and NDA signed prior to commencement
- We reserve the right to modify our website, services, and these terms at any time, with changes effective upon publication
Limitation of Liability
To the maximum extent permitted under applicable Indian law, Nexarcane Forensics & Technology (OPC) Pvt. Ltd. shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from:
- Use of or inability to use our website
- Reliance on information provided on our website without a formal engagement
- Third-party actions, cyberattacks, or force majeure events beyond our reasonable control
Our total liability in connection with any professional service engagement shall not exceed the fees paid by the client for that specific engagement, except in cases of gross negligence or wilful misconduct.
Intellectual Property
All content on this website — including text, graphics, logos, icons, images, and software — is the property of Nexarcane Forensics & Technology (OPC) Pvt. Ltd. and is protected under applicable Indian intellectual property laws. Reproduction, distribution, or commercial use of any content without prior written consent is prohibited.
Governing Law & Jurisdiction
This Privacy Policy and all legal matters relating to Nexarcane's services are governed by the laws of the Republic of India. Any disputes arising under or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of Bengaluru, Karnataka, India. Before initiating formal proceedings, we encourage all parties to attempt resolution through good-faith negotiation.
Contact for Privacy
If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our data handling practices, please contact our Privacy Officer:
We will acknowledge your request within 72 hours and endeavour to resolve it within 30 days. For complex requests or legal proceedings, timelines may be extended with appropriate notice.
This policy was last reviewed and updated in June 2026. We may update this policy periodically. Material changes will be notified via a prominent notice on our website prior to taking effect.
We use cookies to improve your experience. Learn more