Privacy Policy
How we handle personal data across this website and the Kaska platform.
This Privacy Policy explains how Kaska Technologies & Services Pvt Ltd (“Kaska”, “we”, “us”) collects, uses, shares and protects personal data. It covers visitors to kaskatech.com and organisations that evaluate or use the Kaska Exposure Management platform. We handle personal data in line with India’s Digital Personal Data Protection Act, 2023 (DPDP) and a privacy-by-design approach.
1. Who we are
Kaska Technologies & Services Pvt Ltd is a cybersecurity company based in India. For any question about this policy or your personal data, contact us at privacy@kaskatech.com or through our contact page.
2. The data we collect
- Website visitors. Contact details you submit (name, work email, company, message), and basic technical data such as IP address, browser type and pages viewed.
- Prospects & design partners. Business-contact and evaluation details you share when you request a demo or a walkthrough.
- Platform customers. Account and configuration data, and the security telemetry your connected tools expose to the platform. Kaska accesses connected systems with least-privilege permissions — read-only wherever possible — and retains only the minimum signal required to produce risk, control and compliance results.
We do not sell personal data, and we do not use it for advertising.
3. How we use it
- To respond to enquiries and provide access to the platform and its results.
- To operate, secure, support and improve our services.
- To send service and, where you have opted in, product communications.
- To meet legal, regulatory and contractual obligations.
4. Legal basis
We process personal data on the basis of your consent, to perform a contract with you or your organisation, to meet legal obligations, and for certain legitimate uses permitted under the DPDP Act. Where we rely on consent, you may withdraw it at any time.
5. Sharing & processors
We share personal data only with service providers who process it on our behalf (for example hosting and infrastructure), under confidentiality and data-protection terms; when required by law; and with your organisation’s administrators for platform accounts. Any use of AI models is subject to our data-minimisation controls.
6. Data residency
Hosting location and data-residency requirements are agreed with each customer as part of their agreement. Where hosting is used, we apply appropriate safeguards and honour the deployment and residency commitments made to each customer.
7. Security
We apply layered technical and organisational safeguards — least-privilege access to connected systems, encryption of connector credentials and of data in transit, access controls and audit logging. No system is perfectly secure, but security is the core of what we do.
8. Retention
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it. Platform data retention follows the terms agreed with each customer.
9. Your rights
Subject to applicable law, you may request access to, correction of, or erasure of your personal data, withdraw consent, and raise a grievance. To exercise these rights, contact privacy@kaskatech.com. For platform data held on behalf of a customer, we act on the instructions of that customer as the data fiduciary.
10. Cookies
This website uses only the cookies needed to operate and secure the site and to understand basic, aggregated usage. We do not use advertising or cross-site tracking cookies.
11. Children
Our website and platform are intended for business use and are not directed at children.
12. Changes
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.
13. Contact & grievances
Privacy queries and grievances: privacy@kaskatech.com. We aim to acknowledge and address grievances within the timelines required under the DPDP Act.
This policy is provided for transparency and does not itself create contractual obligations beyond those in your agreement with Kaska.