How Cetonix collects, uses and protects personal information — including GDPR, CCPA/CPRA rights and how we handle penetration test data.
Cetonix provides certification, training, GRC and security testing services to organizations in the United States, Canada, the European Union and India. This policy explains what personal information we collect, how we use it, and the rights you have over it.
Version 1.0 · Last updated: 1 October 2025
Cetonix is the controller of the personal information described in this policy. Contact: privacy@cetonix.com, or write to us at EON Freezone, Kharadi, Pune, Maharashtra 411014, India.
| Category | Examples | Why |
|---|---|---|
| Contact and business data | Name, work email, phone, employer, job title | To respond to enquiries, scope engagements and administer contracts |
| Certification records | Qualifications, employment history, audit and training records, certificate details | To deliver accredited certification and training, and to meet accreditation requirements |
| Engagement data (security testing) | Test findings, evidence, screenshots, credentials you supply, and any personal data incidentally present in systems under test | To perform the testing you have authorised in writing |
| Website data | IP address, browser type, pages visited | To operate the site and understand how it is used |
We do not sell or rent personal information to anyone, and we do not share it for cross-context behavioral advertising.
Where GDPR applies we rely on: contract for delivering services you have engaged us for; legitimate interests for responding to business enquiries and operating our website, balanced against your rights; legal obligation for records we must keep; and consent where we ask for it, which you may withdraw at any time.
Test data is the most sensitive information we hold. It is encrypted at rest and in transit, access is limited to the assigned engagement team and is logged, and it is retained only for the agreed retest window. At the end of that window, or earlier on written request, evidence and credentials are destroyed and destruction is confirmed to you in writing. Findings are never reused as examples or marketing material without specific written permission. Full detail is in our security practices, and the contractual terms are in our Data Processing Agreement.
We are established in India and serve clients in the US, EU, Canada and India, so personal information may be transferred across borders. For transfers of EU/EEA and UK personal data outside those areas, we rely on the European Commission's standard contractual clauses together with a transfer impact assessment, and apply supplementary technical measures including encryption in transit and at rest. Where an engagement requires data to remain in a specific jurisdiction, tell us at scoping and we will confirm in writing what we can accommodate.
You have the right to access, rectify, erase, restrict and object to processing of your personal data, and the right to data portability. Where processing is based on consent you may withdraw it at any time. We respond within one month. You may also complain to your supervisory authority.
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use, disclose and (if applicable) sell or share; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly collect personal information from anyone under 16.
The categories above map to CCPA categories: identifiers, professional or employment-related information, and internet activity. We collect them from you directly and from your use of our website, and disclose them for business purposes only, to the recipients listed in section 5.
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah and Texas — have comparable rights to access, correct, delete and port their personal data, and to opt out of targeted advertising and profiling. We honour these requests on the same basis.
Email privacy@cetonix.com. We will verify your identity before acting, and will not charge a fee except where a request is manifestly unfounded or excessive. You may use an authorised agent.
This website does not use advertising cookies and does not track you across other sites. Strictly necessary cookies may be used to operate the site.
The site loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When a page loads, your IP address is transmitted to Google in order to serve those files. If you would prefer this did not happen, you can block those domains at the browser or network level; the site remains fully functional with system fonts.
We apply physical, technical and administrative safeguards appropriate to the sensitivity of the data, including encryption, access control on a least-privilege basis, logging, and confidentiality obligations on all personnel. No system is perfectly secure, and we do not claim otherwise. To report a security concern, see our security practices or email security@cetonix.com.
We may update this policy. Material changes will be flagged on this page, and the "last updated" date above always reflects the current version.
Privacy questions and rights requests: privacy@cetonix.com
Security matters: security@cetonix.com
Everything else: info@cetonix.com
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.