info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomePrivacy Policy

Privacy Policy

How Cetonix collects, uses and protects personal information — including GDPR, CCPA/CPRA rights and how we handle penetration test data.

Cetonix provides certification, training, GRC and security testing services to organizations in the United States, Canada, the European Union and India. This policy explains what personal information we collect, how we use it, and the rights you have over it.

Version 1.0 · Last updated: 1 October 2025

1. Who we are

Cetonix is the controller of the personal information described in this policy. Contact: privacy@cetonix.com, or write to us at EON Freezone, Kharadi, Pune, Maharashtra 411014, India.

2. What we collect and why

CategoryExamplesWhy
Contact and business dataName, work email, phone, employer, job titleTo respond to enquiries, scope engagements and administer contracts
Certification recordsQualifications, employment history, audit and training records, certificate detailsTo deliver accredited certification and training, and to meet accreditation requirements
Engagement data (security testing)Test findings, evidence, screenshots, credentials you supply, and any personal data incidentally present in systems under testTo perform the testing you have authorised in writing
Website dataIP address, browser type, pages visitedTo operate the site and understand how it is used

We do not sell or rent personal information to anyone, and we do not share it for cross-context behavioral advertising.

3. Legal basis (GDPR)

Where GDPR applies we rely on: contract for delivering services you have engaged us for; legitimate interests for responding to business enquiries and operating our website, balanced against your rights; legal obligation for records we must keep; and consent where we ask for it, which you may withdraw at any time.

4. Security testing data — specific commitments

Test data is the most sensitive information we hold. It is encrypted at rest and in transit, access is limited to the assigned engagement team and is logged, and it is retained only for the agreed retest window. At the end of that window, or earlier on written request, evidence and credentials are destroyed and destruction is confirmed to you in writing. Findings are never reused as examples or marketing material without specific written permission. Full detail is in our security practices, and the contractual terms are in our Data Processing Agreement.

5. Who we share it with

  • Accreditation bodies and regulators — UAF, SCC, KAB and Exemplar Global may review certification records as part of their oversight of us. This is a condition of accreditation.
  • Service providers — hosting, email, form processing and analytics providers acting on our instructions under written contract. A current list is available on request.
  • Where legally required — to comply with a valid legal obligation.

6. International transfers

We are established in India and serve clients in the US, EU, Canada and India, so personal information may be transferred across borders. For transfers of EU/EEA and UK personal data outside those areas, we rely on the European Commission's standard contractual clauses together with a transfer impact assessment, and apply supplementary technical measures including encryption in transit and at rest. Where an engagement requires data to remain in a specific jurisdiction, tell us at scoping and we will confirm in writing what we can accommodate.

7. How long we keep it

  • Enquiries that do not become engagements: 24 months
  • Certification and audit records: for the certification cycle plus the period required by our accreditation bodies, normally 6 years
  • Security testing evidence and credentials: the agreed retest window only, then destroyed
  • Final test reports: retained only where you ask us to; otherwise destroyed with the evidence
  • Contract and financial records: as required by applicable tax and company law

8. Your rights

If you are in the EU, EEA or UK

You have the right to access, rectify, erase, restrict and object to processing of your personal data, and the right to data portability. Where processing is based on consent you may withdraw it at any time. We respond within one month. You may also complain to your supervisory authority.

If you are a California resident

Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use, disclose and (if applicable) sell or share; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising these rights.

We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly collect personal information from anyone under 16.

The categories above map to CCPA categories: identifiers, professional or employment-related information, and internet activity. We collect them from you directly and from your use of our website, and disclose them for business purposes only, to the recipients listed in section 5.

Other US states

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah and Texas — have comparable rights to access, correct, delete and port their personal data, and to opt out of targeted advertising and profiling. We honour these requests on the same basis.

How to exercise a right

Email privacy@cetonix.com. We will verify your identity before acting, and will not charge a fee except where a request is manifestly unfounded or excessive. You may use an authorised agent.

9. Cookies and third-party requests

This website does not use advertising cookies and does not track you across other sites. Strictly necessary cookies may be used to operate the site.

The site loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When a page loads, your IP address is transmitted to Google in order to serve those files. If you would prefer this did not happen, you can block those domains at the browser or network level; the site remains fully functional with system fonts.

10. Security of personal information

We apply physical, technical and administrative safeguards appropriate to the sensitivity of the data, including encryption, access control on a least-privilege basis, logging, and confidentiality obligations on all personnel. No system is perfectly secure, and we do not claim otherwise. To report a security concern, see our security practices or email security@cetonix.com.

11. Changes

We may update this policy. Material changes will be flagged on this page, and the "last updated" date above always reflects the current version.

12. Contact

Privacy questions and rights requests: privacy@cetonix.com
Security matters: security@cetonix.com
Everything else: info@cetonix.com

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.