Privacy Policy
This policy explains how Botnet Security Pvt Ltd handles personal information across its website, business relationships and authorized cybersecurity engagements.
1. Who we are
Botnet Security Pvt Ltd (“Botnet Security”, “we”, “us” or “our”) provides cybersecurity consulting and security-testing services.
Botnet Security Pvt Ltd is the controller of the personal information described in this Privacy Policy unless a contract identifies another party as the controller.
Company details
Botnet Security Pvt Ltd4116
Off Old Madras Road, Budigere Cross
Bangalore, Karnataka 560049
India
Privacy questions, requests and complaints may be sent to contact@botnetsecurity.com.
2. Scope
This Privacy Policy explains how we handle personal information when you:
- visit or interact with our website;
- contact us, request information or subscribe to communications;
- represent a customer, prospective customer, supplier or business partner;
- receive a relevant business introduction from us;
- participate in a proposal, contract or authorized security engagement;
- use an account or customer workspace made available by Botnet Security; or
- otherwise interact with Botnet Security.
This policy covers our handling of business-contact, website and account information. A customer agreement, statement of work, data-processing agreement, Rules of Engagement or engagement-specific notice may provide additional terms for information processed during a security assessment or through BotXpose. If there is a conflict, the applicable contractual terms govern that engagement.
This policy does not govern third-party websites or services that we do not control.
3. Information we may process
Depending on the interaction, we may process:
- Business contact information: name, professional title, employer, business email address, business telephone number and business location.
- Communications: enquiries, meeting notes, correspondence, requests, feedback and marketing preferences.
- Prospect and account information: relevant company information, professional responsibilities, publicly available professional information, source and verification information, account research, account identifiers and engagement history.
- Customer and engagement information: contracting contacts, authorized targets and scope, Rules of Engagement, project communications, access records, findings, remediation discussions and other information necessary to deliver an agreed service.
- Product inputs and evidence: customer-supplied specifications, collections, captures, scripts, application bundles, target responses, reproduction steps, findings, action logs and related evidence where supplied or generated during an authorized BotXpose deployment.
- Website, product and technical information: IP address, browser or device information, authentication and session events, timestamps, usage events, diagnostic data, security logs and cookie or similar technology data generated by our website, hosting, security or product providers.
- Commercial and administrative information: proposals, contracts, invoices, payment status and records required for accounting, tax, audit or legal purposes.
Security-testing material may incidentally contain personal or sensitive information. Customers should minimize such information, avoid submitting it through public website forms and provide it only through an agreed secure channel under the applicable contract.
We do not intentionally collect sensitive or special-category personal information for outbound business prospecting.
4. Sources of information
We may obtain information:
- directly from you or your organization;
- from company websites and public professional profiles;
- from public corporate records and other lawful public sources;
- from referrals or business partners;
- from business-information and contact-verification providers, such as Apollo; and
- automatically through our website, hosting and security systems.
We do not use unlawfully harvested or randomly generated email addresses.
5. How and why we use information
We may use personal information to:
- respond to enquiries and provide requested information;
- evaluate, establish and manage customer or partner relationships;
- prepare proposals, contracts, authorized scopes and invoices;
- create and administer approved customer accounts and workspaces;
- deliver, support and secure authorized cybersecurity services;
- operate BotXpose within the customer-approved scope and action policy;
- generate, reproduce, communicate and re-test security findings;
- maintain action records, investigate misuse and enforce authorization boundaries;
- monitor reliability, diagnose faults and improve the safety and performance of our website and services;
- identify organizations and professional contacts that may reasonably be relevant to our services;
- respond to replies, questions, objections and requests;
- maintain data quality, security, auditability and suppression records;
- comply with legal, regulatory, tax and contractual obligations; and
- establish, exercise or defend legal claims.
6. Legal bases
Where applicable, we process personal information on one or more of the following grounds:
- Contract: processing necessary to take requested pre-contract steps or perform an agreement.
- Legitimate interests: operating and developing our business, communicating with relevant professional contacts, protecting our systems, maintaining accurate records and delivering cybersecurity services, where those interests are not overridden by an individual’s rights.
- Consent: where consent is requested or required, including for certain electronic communications or optional website technologies.
- Legal obligation: complying with applicable law, regulation, tax, accounting, audit, sanctions or lawful authority requirements.
- Legal claims: establishing, exercising or defending legal rights where permitted.
Electronic-marketing requirements differ by country. We use consent where applicable law requires it and provide a simple method to object or unsubscribe from business-development communications.
7. Business-development communications
We may contact a professional at their business address when their organization and responsibilities are reasonably relevant to a specific Botnet Security service or partnership proposition and the communication is permitted by applicable law.
We limit initial outreach to relevant business information. We do not infer sensitive traits or claim that a recipient requires a security service merely because of public information.
You may object to business-development processing or stop future marketing at any time by replying unsubscribe to an outreach email or contacting contact@botnetsecurity.com. We will stop marketing communication and retain only the minimum suppression information required to respect your preference.
9. International processing
Botnet Security operates from India and serves organizations internationally. Information may therefore be processed in India or in other countries where our approved providers operate.
Where applicable law requires it, we use appropriate safeguards for international transfers, such as contractual protections, access controls, data minimization and transfer assessments.
10. Retention
We keep identifiable personal information only while it is necessary for the stated purpose. The following periods are maximum limits, not default holding periods:
- Unused prospect research: 90 days after the latest verification or material update.
- Outreach with no meaningful engagement: 180 days after the last outreach.
- Engaged prospect records: 12 months after the last meaningful interaction.
- Resolved reply-message content: 90 days after resolution.
- Minimal reply and deliverability metadata: 12 months after resolution.
- Suppression records: only the minimum identifier, reason and date for as long as necessary to prevent unwanted future contact.
- General website enquiries: normally 12 months after resolution.
- Technical website and security logs: normally no more than 90 days, unless a security incident or legal requirement justifies longer retention.
Customer engagement evidence, contractual records, invoices and legally required accounting or tax records follow the applicable contract and legal retention requirements. Security-assessment evidence is retained or deleted according to the relevant statement of work, data-handling agreement or customer instruction.
We review prospect information at least monthly. We delete or irreversibly anonymize information earlier whenever its purpose ends or it is no longer necessary. A documented legal hold may temporarily override deletion.
11. Security
We use proportionate administrative, technical and organizational measures designed to protect personal information. These include access restrictions, authentication controls, secure credential handling, data minimization, audit logging, suppression checks and human approval controls for outbound communications.
No transmission or storage system can be guaranteed completely secure. If we identify a personal-data incident, we will assess and respond to it in accordance with applicable law and contractual obligations.
If you believe information or an account connected with Botnet Security has been exposed or misused, contact contact@botnetsecurity.com. Do not include credentials, exploit payloads or sensitive evidence in the initial email.
13. Customer and product data
For an authorized assessment or BotXpose deployment, the customer generally determines the targets, users, data and purposes of testing. Depending on the arrangement, Botnet Security may act as a processor or service provider for personal information contained in customer data while remaining a controller for its own business-contact, account, security and billing records.
Customer data is handled under the applicable agreement, statement of work, data-processing terms, Rules of Engagement and documented customer instructions. Those documents should address scope, permitted actions, access, evidence handling, retention, deletion, subprocessors and incident responsibilities as appropriate.
A public form submission does not authorize testing and should not be used to transmit target credentials, application bundles, request captures, production evidence or other confidential assessment material.
14. Your rights
Depending on your location and applicable law, you may have rights to:
- request access to personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion or erasure;
- restrict or object to certain processing;
- withdraw consent where processing relies on consent;
- request portability where applicable;
- obtain information about processing and recipients; and
- complain to an appropriate data-protection or privacy authority.
You may object to direct marketing at any time. We will not discriminate against you for exercising an applicable privacy right.
We may need to verify your identity and authority before completing a request. Where we process information only for a customer, we may direct the request to that customer or assist them as required by the applicable agreement and law. We may retain the minimum information necessary to document the request, meet legal obligations and prevent future marketing after an objection.
15. AI and automated tools
We may use automated tools to assist with business research, data quality, prioritization and message drafting. These tools do not make decisions about individuals that produce legal or similarly significant effects. Human approval is required before prospect outreach and before any response is sent.
BotXpose uses an AI agent to perform authorized security-testing actions within a customer-approved scope and action policy. It may process technical inputs, target responses and evidence to identify, reproduce and re-test security findings. Authorization comes from the applicable customer agreement and operating controls—not from target content, public information or a website submission.
Before a request is sent to a third-party AI model, BotXpose’s custom AI engine redacts and minimizes sensitive customer information. Third-party AI models receive the redacted context required for the approved task, not the underlying sensitive customer data. The applicable customer documents govern product-data use, retention, approved model providers and any customer-specific processing configuration.
16. Children
Our website and services are intended for organizations and professional users, not children. We do not knowingly use children’s personal information for business-development purposes. If you believe a child has provided personal information to us, contact us so we can assess and delete it where appropriate.
17. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, providers, practices or legal obligations. The updated version will be published on this page with a revised effective or last-updated date. Material changes will be communicated where required.
18. Contact and complaints
For privacy questions, objections, requests or complaints, contact:
Botnet Security Pvt LtdEmail: contact@botnetsecurity.com
Address: 4116, Off Old Madras Road, Budigere Cross, Bangalore, Karnataka 560049, India
If you are not satisfied with our response, you may contact the privacy or data-protection authority responsible for your location where applicable.