Privacy Policy

Effective Date: July 19, 2026

Welcome to Innvikta Cybersecurity Solutions (“Innvikta”, “we”, “our”, or “us”). Your privacy is important to us. This Privacy Policy explains how we collect, use, store, protect, and disclose your information when you visit our website, use our cybersecurity awareness platform, or interact with our services.

By accessing or using our website and services, you agree to the practices described in this Privacy Policy.


1. Information We Collect

Information You Provide

We may collect information that you voluntarily provide, including your full name, company name, job title, business email address, phone number, country or region, contact form submissions, demo requests, support requests, newsletter subscriptions, and any information shared during meetings or product inquiries.

Information Collected Automatically

When you visit our website, we may automatically collect information such as your IP address, browser type and version, operating system, device information, pages visited, date and time of access, referral URLs, session duration, website interactions, and cookie identifiers.

Platform Usage Data

If you use Innvikta's security awareness platform, we may collect user account information, training completion status, quiz scores, learning progress, campaign participation, phishing simulation responses, risk assessment results, reporting activity, administrative settings, and audit logs. The exact information collected depends on your organization's configuration.


2. How We Use Your Information

We use your information to provide our products and services, deliver cybersecurity awareness training, conduct phishing simulation campaigns, generate reports and analytics, improve our platform, respond to inquiries and support requests, schedule demonstrations, send product updates, deliver newsletters and marketing communications where permitted, improve website performance, detect fraud and security incidents, comply with legal obligations, and enforce our Terms of Service.


3. Cookies and Similar Technologies

We use cookies and similar technologies to maintain website functionality, improve user experience, remember user preferences, analyze website traffic, measure marketing effectiveness, enhance security, and understand visitor behavior. You can control cookie preferences through your browser settings, although disabling cookies may affect certain website functionality.


4. Analytics

We may use analytics tools to understand how visitors use our website. These tools may collect information such as pages visited, time spent on pages, device information, browser information, approximate geographic region, and traffic sources. This information helps us improve our website and user experience.


5. Marketing Communications

If you subscribe to our newsletter or request information, we may send product updates, security insights, educational content, event invitations, industry news, and service announcements. You may unsubscribe from marketing emails at any time using the unsubscribe link included in our communications.


6. Information Sharing

We do not sell your personal information. We may share information with trusted service providers supporting our business operations, cloud hosting providers, analytics providers, email communication providers, customer support platforms, professional advisors, regulatory authorities when legally required, and law enforcement where required by applicable law. All third-party service providers are expected to maintain appropriate security and confidentiality measures.


7. Data Security

We implement appropriate technical and organizational measures to protect information against unauthorized access, disclosure, alteration, or destruction. Our security practices may include encryption in transit, access controls, authentication mechanisms, role-based permissions, security monitoring, regular security assessments, secure infrastructure, and audit logging. While we strive to protect your information, no internet transmission or storage system can be guaranteed to be completely secure.


8. Data Retention

We retain personal information only for as long as necessary to provide our services, meet contractual obligations, comply with legal requirements, resolve disputes, maintain security records, and improve our services. Retention periods may vary depending on the type of information and applicable legal requirements.


9. International Data Transfers

Your information may be processed or stored in countries other than your own. Where applicable, we take appropriate measures to ensure your personal information remains protected in accordance with applicable data protection laws.


10. Your Privacy Rights

Depending on your location and applicable law, you may have the right to access your personal information, correct inaccurate information, request deletion of your information, restrict processing, object to certain processing activities, withdraw consent where applicable, request data portability, and lodge a complaint with the appropriate supervisory authority. To exercise these rights, please contact us using the details provided below.


11. Children’s and Students’ Privacy

Our services are primarily intended for businesses and organisations. Certain cybersecurity-awareness programmes may also be offered to school and college students through authorised educational institutions.

Where required by applicable law, personal data of minors will be processed only with appropriate parental or guardian consent. We collect only the information necessary to deliver the programme and do not sell student data or use it for targeted advertising.


12. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those external websites. We encourage you to review their privacy policies before providing personal information.


13. Compliance

Innvikta is committed to supporting applicable privacy and data protection requirements. Depending on customer engagements, our services may support organizations in meeting obligations under regulations such as the Digital Personal Data Protection Act (DPDPA), India, the General Data Protection Regulation (GDPR), and other applicable regional privacy laws. Customers remain responsible for ensuring their own compliance with applicable legal and regulatory requirements.


14. Digital Personal Data Protection Act (DPDPA) – India

In accordance with the Digital Personal Data Protection Act, 2023 (India), Innvikta acts as a Data Fiduciary or Data Processor depending on the nature of the engagement.

Lawful Processing

We process personal data only for lawful purposes and based on valid grounds such as:

  • Consent provided by the Data Principal
  • Legitimate uses permitted under applicable law
  • Compliance with legal obligations

Consent

Where required, we obtain clear and informed consent before collecting or processing personal data. Data Principals have the right to withdraw consent at any time.

Data Principal Rights

Under DPDPA, individuals (Data Principals) have the right to:

  • Access information about their personal data
  • Request correction or erasure of personal data
  • Withdraw consent
  • Seek grievance redressal
  • Nominate another individual to exercise rights in case of incapacity or death

Data Minimization and Purpose Limitation

We collect only the data necessary for specified purposes and do not process it beyond those purposes without additional consent or legal basis.

Data Security Safeguards

We implement reasonable security safeguards to prevent personal data breaches, including technical and organizational measures aligned with industry standards.

Data Breach Notification

In the event of a personal data breach, we will notify relevant authorities and affected individuals as required under applicable law.

Grievance Redressal

We provide mechanisms for individuals to raise concerns or complaints regarding the processing of their personal data.


15. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, legal requirements, or business practices. The updated version will be posted on this page with a revised Effective Date, and continued use of our website or services after updates constitutes acceptance of the revised policy.


16. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:
Innvikta Cybersecurity Solutions
Email: privacy@innvikta.com
Website: https://innvikta.com


Consent

By accessing our website or using our services, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Hi! Need help? Chat with us.

Innvikta Assistant

Online • Responds Instantly