Legal
Privacy Policy
Last updated: July 2026
Kaitara Security is a security and compliance business. We hold ourselves to the same standards we deliver for clients. This notice explains, in plain language, how we handle your personal data in accordance with the Digital Personal Data Protection Act 2023 and the IT Act 2000.
1. Who we are
Kaitara Security is a security and compliance services business operating in India. We help businesses implement security and data privacy obligations.
Contact: security@kaitara.com
2. What data we collect
We collect different data depending on how you use this website.
If you contact us — the "Book a call" and contact links open your own email client. Nothing is submitted through this website; we receive whatever you choose to put in your email, typically your name, company and message.
If you run a free security scan — we collect the website address or public repository URL you submit, the email address you give us to receive the report, and standard request metadata (your IP address, browser user-agent, and referring page). The scan results are stored so we can generate and re-send your report. We do not log into your systems; the scan only looks at information your domain already exposes publicly.
If you use the client portal — we collect your email address, company name and company domain at registration, and the information you enter during intake, in compliance checklists, in uploaded or generated documents, and in any incident report you file.
Cookies and tracking — we do not use analytics, advertising or third-party tracking scripts. This website stores a single value in your browser's local storage to remember that you have dismissed the consent notice. It contains no personal data and is not shared with anyone.
3. Why we collect it
Enquiry data — to respond to you and assess whether a Kaitara Security engagement fits your business.
Scan data — to run the scan you requested, generate your report, send it to you, and prevent abuse of a free service through rate limiting.
Portal data — to deliver the engagement you have contracted for: producing your regulatory profile, compliance documents, checklists and incident reports.
We do not use any of this data for advertising, and we do not sell it.
4. Legal basis
Where you contact us or request a scan, we process your data on the basis of your consent, given when you send us the enquiry or submit the scan request.
Where you are a client, we process data as necessary to perform the engagement agreement between you and Kaitara Security.
You may withdraw consent at any time by writing to security@kaitara.com. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide the service.
5. How long we keep it
Enquiry data — up to 12 months from receipt, then deleted.
Scan data — scan results and the associated email address are retained for up to 12 months so we can re-send a report you have asked for, then deleted.
Client portal data — retained for the duration of the engagement and afterwards as set out in the engagement agreement, or as required by law. You may request deletion at any time, subject to any legal retention obligation.
6. Where data is stored, and who processes it
Our primary processing is in India. The scan service runs on Google Cloud Run in asia-south1 (Mumbai), with scan records in Google Cloud Firestore and job queuing in the same region. The client portal database is hosted on Supabase in ap-south-1 (Mumbai).
Some processing takes place outside India, and we would rather tell you than claim otherwise:
• This website is served by Firebase Hosting, which uses Google's global content delivery network.
• Email is sent and received through Google Workspace, which operates globally.
• Compliance documents in the client portal are generated using the Anthropic API, which processes the request outside India. Document generation runs only for clients, only on data you have provided for that purpose.
We do not sell, rent, or share your personal data. We disclose it only to the service providers above, acting on our instructions to deliver the service, or where required by law.
7. Your rights under the DPDP Act 2023
Under the Digital Personal Data Protection Act 2023, you have the right to:
• Access the personal data we hold about you
• Correct inaccurate or incomplete data
• Request erasure of your data
• Withdraw consent at any time
• Nominate a representative to exercise these rights on your behalf
To exercise any of these rights, write to: security@kaitara.com
We will respond within 30 days.
8. Grievance Officer
If you have a complaint about how we handle your personal data, you may raise it with us at:
security@kaitara.com
We will acknowledge your complaint within 7 days and resolve it within 30 days. If you are not satisfied with our response, you may approach the Data Protection Board of India, established under the DPDP Act 2023.
9. Security
We take reasonable technical and organisational measures to protect your personal data from unauthorised access, disclosure, or loss. In practice that means access to client data is restricted and authenticated, data is encrypted in transit, credentials are held in a managed secret store rather than in code or configuration files, and our infrastructure providers are established platforms with their own security programmes.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a security issue affecting this website or our services, please write to security@kaitara.com and we will respond.
10. Data breach notification
If a personal data breach occurs that is likely to affect you, we will notify you without undue delay at the email address we hold for you. We will describe what happened, the data involved, the likely consequences, and what we are doing about it.
Separately, and as an entity operating in India, we report qualifying cyber incidents to CERT-In within six hours of becoming aware of them, as required by the CERT-In Directions of 28 April 2022, and we meet the personal-data-breach notification requirements of the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 — an initial intimation to affected data principals without delay, and a detailed report to the Data Protection Board within 72 hours of becoming aware.
To report a suspected security incident involving your data, write to: security@kaitara.com
11. Changes to this policy
We may update this policy as our services evolve or as legal requirements change. The current version will always be available at security.kaitara.com/privacy. Material changes will be communicated to you if we hold your contact details.
Questions about this policy? security@kaitara.com