Loading
Loading
LoadingLegal
This page summarises the terms on which Accurith processes personal data on a client's behalf during an engagement. It is a description of our position, not the executable agreement — the signed DPA attached to your engagement paperwork is the document that binds us.
Last updated · Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India
Our work often means handling systems and records that contain personal data — reviewing access logs during an IS audit, examining a device in a forensic engagement, testing an application that holds customer records. Where we do that on your instructions, you are the data fiduciary or controller and we are the data processor.
This does not describe personal data you give us through this website, such as an enquiry or a job application. There we act for ourselves, and our Privacy Policy governs.
The specifics are set per engagement, because they follow the work. The signed DPA records them for that engagement:
| Item | How it is fixed |
|---|---|
| Subject matter and duration | The services in the statement of work, for the term of that engagement |
| Nature and purpose | Audit, assessment, forensic examination, advisory or automation work as scoped |
| Categories of personal data | Identified per engagement — typically identifiers, contact details, employment and access records; special-category or financial data only where the scope requires it |
| Categories of data principals | Typically your employees, contractors and, where in scope, your customers |
| Your obligations | Ensuring you have a lawful basis for the data you give us, and that your instructions are lawful |
We ask for the minimum personal data the work requires, and prefer masked, redacted or synthetic data whenever it will do the job. The cheapest way to protect a record is not to hold it.
Measures are proportionate to the engagement and recorded in the signed DPA. Our baseline includes encryption in transit and at rest, access restricted to the engagement team on a need-to-know basis, multi-factor authentication on the systems that hold client data, logging of access, segregation of client data between engagements, and secure disposal at the end of the retention period.
For forensic engagements we additionally maintain evidence handling and chain-of-custody procedures appropriate to material that may be relied on in a proceeding.
We engage a sub-processor only where the engagement needs it. Any sub-processor is bound by written terms no less protective than these, and we remain responsible to you for its performance.
We maintain a current list of sub-processors and give notice before adding one, so you have the opportunity to object. Where we host or transmit client data, the underlying cloud and communications providers are the sub-processors most likely to be relevant.
Where personal data is stored depends on the engagement, and we agree it with you rather than assume it. Our own website infrastructure is hosted in the United States; client engagement data does not automatically follow that choice, and for a regulated client it usually should not.
If you require the data to remain in India, tell us before the engagement starts so we can scope the tooling accordingly. Where a transfer outside India or outside your region is necessary, we implement the safeguards the applicable law requires, and the DPA records them.
If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any case within the period stated in the signed DPA. Our notice sets out what we know: the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.
We do not notify a regulator or your data principals on your behalf unless you instruct us to — that reporting decision is yours to make, and we support it with the facts.
You may audit our compliance with these obligations, on reasonable notice and without disrupting our other clients' confidentiality. Where an independent report or completed assessment questionnaire answers your question, we will offer it first — but a report is not a substitute for an audit you are entitled to, and we will not treat it as one.
We hold ourselves to the standard we advise. If our answers do not satisfy your security reviewer, that is a problem for us to fix rather than for you to accept.
At the end of the engagement we return your data, delete it, or both, as you choose. Where we are required by law to retain a copy — or where working papers must be kept to evidence an audit opinion — we retain only what is necessary, keep it protected under these terms, and tell you what has been kept and for how long.
The executable DPA is issued with your engagement paperwork. To review it before then, or to have us complete your own DPA template or security questionnaire, write to info@accurith.com.
Listed here rather than answered with a guess — a policy that states a commitment nobody has agreed to is worse than one that admits the gap.