Compliance
Data Protection Policy
eNeoteric is committed to protecting the personal and organisational data entrusted to us in the course of our services. This policy describes how we collect, use, store, and protect data in alignment with India's Digital Personal Data Protection Act 2023 (DPDPA) and applicable international standards. Effective date: 1 January 2026.
Data we collect and why
Customer engagement data
Name, contact details, company information, and technical data necessary to deliver our services. Collected under contractual necessity. Retained for the duration of the engagement plus 7 years for compliance record-keeping.
Website visitor data
IP address, browser type, pages visited, and session data collected via analytics tools (Google Analytics, Plausible). Collected under legitimate interest (website improvement) or consent where applicable. Retained for 13 months.
Marketing contact data
Name, email, company, and role of contacts who have requested information or subscribed to our communications. Collected under consent. Retained until consent is withdrawn.
Incident response data
During incident response engagements, we may process personal data contained in compromised systems as part of the forensic investigation. This data is handled under a Data Processing Agreement, used solely for investigation purposes, and deleted upon engagement closure unless required for legal proceedings.
Your rights under DPDPA
- Right to access — You may request a summary of personal data we hold about you.
- Right to correction — You may request correction of inaccurate personal data.
- Right to erasure — You may request deletion of personal data where we have no legal basis for continued retention.
- Right to grievance redressal — You may raise a complaint with our Data Protection Officer, and if unresolved, with the Data Protection Board of India.
- Right to nominate — You may nominate a person to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email [email protected]. We respond to rights requests within 30 days.
Frequently asked questions
- Who is eNeoteric's Data Protection Officer?
- Our Data Protection Officer (DPO) can be contacted at [email protected]. The DPO is responsible for overseeing our DPDPA compliance programme, responding to rights requests, and serving as the point of contact for the Data Protection Board of India.
- Does eNeoteric transfer personal data outside India?
- eNeoteric may transfer personal data to our Singapore office for APAC engagements, subject to DPDPA's cross-border transfer requirements. We ensure that transfers occur only to countries with adequate data protection standards or under contractual safeguards. We do not sell or share personal data with third parties for their own marketing purposes.
- How does eNeoteric handle a personal data breach?
- In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals within the timeframes mandated by DPDPA. We will provide details of the breach, the data affected, and the measures taken to contain and remediate it.
- Does eNeoteric use cookies?
- Yes. Our website uses essential cookies for functionality, analytics cookies (with consent) for website improvement, and marketing cookies (with consent) for tracking campaign effectiveness. You can manage your cookie preferences via the consent banner on our website. See our Privacy Policy for full details.
Data protection questions?
[email protected]Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.