TECHOWL

Privacy Policy

Last updated: 20 August 2026. This is the privacy policy of Techowl Infosec Private Limited and it covers all of our websites and products. It replaces the separate policy dated 12 September 2023.

We value your privacy. This policy explains what personal data we collect, why we collect it, who else sees it, how long we keep it, and the rights you have over it. Section 4 sets this out product by product.

1. Who we are

We are Techowl Infosec Private Limited, an Indian company registered under the Companies Act, 2013, with our registered office at A-406 Monarch, Gaurav Path Road, Adajan, Surat, India 395009. We are the Data Fiduciary or the Data Processor, as section 2 explains, for the personal data described here.

In this policy, “we”, “us” and “our” mean Techowl Infosec Private Limited. “You” means the individual whose personal data we handle.

This one policy covers everything we do. It applies to techowl.com and techowlshield.com, and to every product listed in section 4, whichever website or address you reached us through. The same version is published at each of them.

A note on names, because two of them are similar. TechOwl, and the words we, us and our, mean the company. TechOwl Shield is the name of one particular product, our attack surface, dark web and brand monitoring service, described in section 4.1. Where this policy says TechOwl Shield it means that product and nothing wider.

2. There are two different situations, and they work differently

India’s Digital Personal Data Protection Act, 2023 distinguishes between a Data Fiduciary, meaning whoever decides the purpose and the means of processing personal data, and a Data Processor, meaning whoever processes personal data on a Data Fiduciary’s behalf. Which one we are depends on the activity, not on the company as a whole.

2.1 Where we are the Data Fiduciary

For the following, we decide why and how the data is used, this policy applies, and you can bring questions and requests directly to us:

  • your use of our website, including enquiries, demonstration requests and subscriptions
  • our marketing and sales communications
  • the account and access layer of every product, meaning your login credentials, authentication factors, session and login records, and the records of your account being set up and administered (section 4.9)
  • our own corporate and employment data

2.2 Where we are the Data Processor

If your employer or another organisation uses one of our products, that organisation decides why and how the data inside the product is used. For that data we act on their instructions, and their privacy notice governs it, not this one. This includes:

  • everything monitored, collected, analysed or reported inside a product for that organisation, as described for each product in section 4
  • your identity where it appears inside a service record, for example as the owner of a task, a reviewer, the author of a comment, the recipient of a simulated phishing message, or the subject of a monitored profile

The same person can fall on both sides of this line. A password reset is ours to answer for. Your name against a task inside a customer’s service record belongs to that customer.

2.3 A third situation: people neither of us signed up

Some of our products take in material from third party and public sources on a customer's instruction. Breach and dark web feeds, paste sites, threat intelligence feeds and files submitted for analysis all contain whatever their compilers or submitters put in them. That material can hold personal data about someone who has no account with us and no connection to the customer we collected it for.

The two situations above do not cover that person. She is not our website visitor or account holder, so section 2.1 does not reach her. And our customer never decided anything about her, so it is not honest to send her to them under section 2.2.

For that material we take the following position:

  • we do not use it to make any decision about the person it concerns
  • we do not sell it, license it, or enrich it with anything else
  • we hold it only for the security purpose it was collected for, and we delete it on the timetable in section 11
  • a request from that person comes to us, at [email protected], and we answer it ourselves. We will not route her to a customer who has never heard of her

Section 4 marks which products can hold this kind of material.

2.4 Material a person published herself

The Act does not apply to personal data that is made or caused to be made publicly available either by the person it relates to, or by someone who is under an obligation under a law in force in India to publish it. The Act gives the example of a person blogging her views on social media.

So the two halves of what our monitoring picks up are treated differently, and the difference matters:

What it is How it is treated
Material a person published herself, such as her own posts on a public social media account Outside the Act. We monitor it for impersonation and exposure without it engaging these obligations
Credentials and records appearing in breach dumps, combo lists and dark web sources Inside the Act in full. This material was not published by the person it concerns; it was taken from someone and circulated without her. We treat it as her personal data and section 2.3 applies to it

We do not treat domain registration data as published under a legal obligation unless that obligation arises under a law in force in India.

If you ask us to act on data we hold in this second situation, we will not answer it ourselves. We will pass your request to the organisation that controls the data, without delay, and tell you that we have done so. Under the Act, these rights are exercised against the Data Fiduciary.

3. What we collect and why

Information you give us

What Why we need it
Name, work email address, telephone number To create and operate your account, and to contact you about the service
Organisation name and your role To connect your account to the correct customer organisation
The content of your enquiry, demonstration request or support message To answer you
Marketing preferences To send you only the updates you have asked for

Information collected automatically

What Why we need it
Login records, session records and access logs To operate the service, to control access, and to detect and investigate unauthorised access
IP address, browser, device and operating system information To keep the service secure and working correctly
Pages visited, time spent and how you arrived at the site To understand how the site is used and improve it

Personal data processed inside a particular product is described in section 4.

4. What each product processes

We operate the products below. What personal data is involved, where it comes from, and whether a request should come to us or to the organisation that engaged us depends on which product is in question. Not every customer uses every product.

In every product, the account and access layer described in section 4.9 is ours as Data Fiduciary. What the product then does for a customer organisation belongs to that organisation, and we act as its Data Processor. Some products also take in material about people who are connected to neither of us; section 2.3 governs those, and the products concerned are marked below. Where a product departs from the pattern, it is stated in its own entry.

4.1 TechOwl Shield: attack surface, dark web and brand monitoring

What it does Monitors a customer organisation’s domains, brands, executives and the assets it exposes to the internet, and reports exposures: credentials appearing in third party breaches, material on dark web and paste sources, lookalike and phishing domains, impersonating websites and social media accounts, and the security posture of the organisation’s external assets.
Personal data processed Email addresses, usernames and passwords or password hashes appearing in third party breach, combo list and dark web sources; names and roles of executives and staff who appear in monitored material; social media account names and content connected with impersonation; domain registration details, which can include a registrant’s name, email address, telephone number and postal address; asset inventories and scan findings for the organisation’s systems.
Where it comes from The customer organisation, which tells us what to monitor; and third party and publicly available sources, including breach and dark web feeds, paste sites, domain registration data, certificate transparency logs and social media platforms.
Our role Two roles, depending on whose data it is. Data Processor on the customer organisation's instructions for its own domains, brands, assets and staff. Section 2.3 applies to anyone else caught in breach, combo list or dark web material, because that person has no connection to our customer and our customer decided nothing about her. Material she published herself is outside the Act under section 2.4. If you believe you appear in this data, contact us at [email protected] and we will answer you ourselves.

4.2 TechOwl SOC and Ticketing: security operations and incident management

What it does Receives, triages and tracks security incidents for a customer organisation. Analysts work incidents raised by monitoring systems, by email and by the customer, and record their findings, actions and communications.
Personal data processed Names, work email addresses and telephone numbers of the customer’s staff and of our analysts; the content of email correspondence about an incident, including sender, recipients, subject, body and attachments; records of telephone calls made to confirm urgent incidents; user, device and host identifiers appearing in security alerts, such as usernames, IP addresses, hostnames and endpoint identifiers; and any personal data a person chooses to put into a ticket, a comment or an attachment. Screenshots, log extracts, exported records and spreadsheets are routinely attached.
Where it comes from The customer organisation and its users, our analysts, the customer’s own security tooling, and email sent to the service desk.
Our role Data Processor for incidents and their contents. Where you write to us with an enquiry or a support request about our own service rather than about an incident, that message is ours as Data Fiduciary.

4.3 TechOwl DMARC Shield: email authentication monitoring

What it does Collects and interprets DMARC, SPF and DKIM reporting for a customer’s email domains, monitors the DNS records that support it, and alerts on failures and changes.
Personal data processed Aggregate reports, which contain the IP addresses of systems sending mail using the domain together with volumes and authentication results; failure reports, which can contain detail drawn from individual messages, including sender and recipient email addresses, subject lines and message headers; the credentials of the mailbox from which reports are collected; and the names and email addresses of the people who use the product.
Where it comes from Mailbox providers and other receiving mail servers that generate the reports, public DNS, and the customer organisation.
Our role Data Processor. Failure reports can carry the details of people outside the customer's organisation, on either end of a message. Section 2.3 applies to them.

4.4 PhishGuard: phishing simulation and security awareness training

What it does Runs simulated phishing campaigns for a customer organisation and assigns security awareness training based on how people respond.
Personal data processed Name, work email address, and the department, group or role the customer assigns. For each simulated message: whether it was delivered, opened and clicked, whether credentials were entered on the simulated page, whether an attachment was opened, whether it was replied to and the content of that reply, and whether it was reported; the time taken to click or to report; and the IP address, browser, device type and approximate location of the interaction. Training assignments, completion, scores and any feedback given.
Where it comes from The customer organisation, which supplies the people to include; and the individual’s own interaction with the simulated message and the training.
Our role Data Processor. The customer organisation decides who is included in a simulation, what is measured, and what is done with the result.

4.5 Complython: governance, risk and compliance

What it does Manages a customer’s compliance programme: control frameworks and assessments, audits, risk registers, policies, tasks, and the evidence collected against them.
Personal data processed Names, work email addresses and roles of the customer’s staff, auditors and reviewers; the record of who was assigned a task, who reviewed it, who approved it and when; comments and discussion; and the contents of evidence documents uploaded to demonstrate a control, which are supplied by the customer and can contain personal data.
Where it comes from The customer organisation and its users.
Our role Data Processor.

4.6 Vendor and third party risk management

What it does Sends security questionnaires to a customer’s vendors, collects their responses and evidence, scores them, and tracks remediation.
Personal data processed Names, work email addresses and roles of the customer’s staff and of contacts at the vendor being assessed, including guest reviewers who are invited to respond and have no other relationship with us; questionnaire responses, uploaded evidence documents, discussion threads and approval decisions; and access records for guest users, including IP address and browser.
Where it comes from The customer organisation, and the vendor’s own personnel when they respond.
Our role Data Processor for the organisation that commissioned the assessment. Vendor contacts should bring requests to that organisation; if they come to us we will pass them on without delay and tell them we have done so.

4.7 ThreatPulse: threat intelligence distribution

What it does Collects indicators of compromise from upstream threat intelligence feeds, normalises them into the STIX 2.1 format, and distributes them to subscribing customers through a TAXII 2.1 API and file exports.
Personal data processed The account and access data of subscribing customers, including API keys and usage records of API calls such as time, endpoint and source IP address. Indicators themselves describe infrastructure, such as addresses, domains, URLs and file hashes, but an indicator can incidentally contain personal data, for example an email address used in a phishing campaign, or contact details held in domain registration data.
Where it comes from Upstream threat intelligence feeds and open sources; and, for account data, the subscribing customer.
Our role Data Fiduciary for subscriber accounts and usage records. For indicator content obtained from upstream feeds and redistributed, section 2.3 applies: we do not use it to make decisions about any individual and we do not sell personal data. If you believe an indicator contains your personal data, contact us at [email protected] and we will answer you ourselves.

4.8 TechOwl Sandbox: malware and file analysis

What it does Executes submitted files and URLs in an isolated environment and reports what they do.
Personal data processed The account data of the person submitting; the submitted file or URL itself, which can contain personal data, as documents submitted for analysis frequently do; the artefacts produced by the analysis, including screenshots of execution, network requests, dropped files and recordings of interactive analysis sessions; and analysis comments and tags.
Where it comes from The person or organisation that submits the sample.
Our role Data Processor for samples and results submitted by a customer organisation. Where a sample contains personal data about someone who has no relationship with us or with the submitter, section 2.3 applies: we process it only to produce the analysis, we make no decision about that person, and we apply the retention in section 11.

4.9 Account and access layer: all products

What it does Creates accounts, authenticates you across products through one central login, holds your session, and records access.
Personal data processed Name, work email address, telephone number where given, the organisation and role you are attached to, credentials and authentication factors, session records, login history including IP address and browser, and the record of your account being created, changed and closed.
Where it comes from You, and the organisation that engaged us where an account is created for you.
Our role Data Fiduciary. Questions and requests about this layer come to us directly, whichever product you use it to reach.

5. Our lawful basis for using it

The Act permits personal data to be processed either with your consent, or for one of the specific purposes it lists as “certain legitimate uses”.

  • Operating your account, responding to you and keeping the service secure. We rely on the legitimate use covering personal data that you have voluntarily provided to us for a specified purpose and have not objected to. This is section 7(a) of the Act.
  • Marketing communications. We rely on your consent, which you can withdraw at any time. See section 10.
  • Data inside a product. Where we process personal data inside a product for a customer organisation, we do so on that organisation’s documented instructions, and the organisation is responsible for the lawful basis.
  • Records we are required to keep by law. Where another law requires us to retain information, we rely on that obligation.

We do not use your personal data for any purpose we have not described in this policy. If we ever need to, we will tell you and, where the law requires it, ask you first.

6. Where the information comes from

  • Directly from you, when you create an account, contact us, request a demonstration, or subscribe to updates.
  • Automatically, when you use the website or a product, through server logs, cookies and similar technologies.
  • From your employer or the organisation that engaged us, where an account is created for you or where you are included in a service they have commissioned.
  • From third party and publicly available sources, where a product monitors for exposures on a customer’s behalf. This includes breach and dark web feeds, paste sites, domain registration data, certificate transparency logs, social media platforms, threat intelligence feeds and mail authentication reports. Section 4 says which products do this.

7. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, to keep the service secure, and to understand how the site is used. Analytics tools help us see which pages are visited and how people arrive at the site.

You can control or delete cookies through your browser settings. Blocking some cookies may stop parts of the site working.

8. Who else sees it

We do not sell your personal data.

We share it only with the following, and only so far as each needs it:

  • Service providers who work on our instructions, including hosting and cloud infrastructure, email delivery, customer support tooling, analytics, and providers that help us secure and monitor our own systems. They may use the data only to provide those services to us.
  • The customer organisation that engaged us, where the data sits inside a product we operate for them.
  • Courts, regulators, government agencies and law enforcement, where we are required to disclose information, where we must respond to a lawful order or request, or where we are investigating suspected fraud or misuse of the service.
  • A successor organisation, if all or part of our business is transferred. We will tell you before your personal data becomes subject to a different privacy policy.

Some of our service providers may be located outside India.

9. Information going outside India

The Act permits personal data to be transferred outside India, subject to any restriction that the Central Government may notify in respect of a particular country or territory. Where we transfer personal data outside India, we do so in line with those restrictions and with any requirements the Central Government specifies about making personal data available to a foreign State or to an entity under the control of a foreign State.

Where another Indian law places a stricter restriction on transfer than the Act does, that stricter requirement continues to apply, and we comply with it.

10. Marketing, and how to stop it

We send marketing communications only where you have agreed to receive them.

You can withdraw that agreement at any time by emailing [email protected]. We will act on your request promptly and will stop sending marketing communications.

We will still send you messages about your account and your service, such as security alerts and service updates. These are not marketing and they continue while you hold an account.

11. How long we keep it

We keep personal data only for as long as we need it for the purpose we collected it for, and then we delete it, unless a law requires us to keep it for longer.

In practice this means:

  • Account information is kept while your account is open and for a reasonable period after it closes, so that we can deal with questions, disputes and any legal obligations arising from your use of the service.
  • Login records, session records and access logs are kept for at least one year. The Rules require logs and the related personal data to be retained for one year so that unauthorised access can be detected, investigated and remedied, unless another law requires otherwise.
  • Data inside a product, including tickets and their attachments, monitoring findings, assessment responses, simulation results and submitted samples, is kept for the period agreed with the customer organisation that engaged us, and is deleted or returned at the end of that engagement in line with our agreement with them.
  • Material taken from third party and public sources, where it concerns someone unconnected to the customer we collected it for, is kept only while the security purpose needs it. Where a finding is closed as a false positive, the underlying material is deleted at closure rather than kept to the end of the engagement.
  • Records we are required to keep by another law are kept for the period that law requires.
  • Enquiries and demonstration requests are kept for as long as we are in contact with you about them and for a reasonable period afterwards.
  • Marketing contact details are kept until you withdraw your agreement. After that we keep the minimum needed to make sure we do not contact you again.

Two points worth being clear about. A one year minimum is a floor, not a deadline, and it does not mean that all personal data is kept for one year. And closing your account does not delete everything at once, because a record that must be kept for its retention period is kept even after the account closes.

12. Your rights

Under the Act, where we are the Data Fiduciary for your personal data, you have the right to:

Right What it means
Access Obtain a summary of the personal data we are processing about you, an account of what we have done with it, and the identities of others we have shared it with
Correction Have inaccurate or misleading data corrected, incomplete data completed, and out of date data updated
Erasure Have your personal data erased, unless we still need it for the purpose we told you about, or a law requires us to keep it
Grievance redressal Complain to us about how we have handled your personal data or your request
Nomination Nominate another individual who may exercise your rights on your behalf if you die or become unable to act

How to make a request

Email [email protected]. To help us find your records and confirm it is you, please tell us your full name, the email address associated with your account or your enquiry, and the organisation you belong to if you use a product through your employer. Please describe what you would like us to do. If your request concerns a specific product, telling us which one helps us route it correctly.

How long we take

If you are raising a grievance, the Rules require us to publish the period within which we will respond, to set that period at no more than ninety days, and to put the measures in place to actually meet it. Our published period is seven working days.

If you are asking us to access, correct, erase or nominate, the Rules do not set a response period at all. We work in two stages. We acknowledge your request within seven working days and tell you what we hold, and we complete it within thirty days.

The second stage takes longer than the first for a reason. An access request asks us for the identities of everyone your data has been shared with, and answering that honestly means searching every product in section 4 rather than the one you came in through. We would rather publish a period we meet than a shorter one we miss.

Ninety days is a ceiling the Rules place on the grievance period. It is not a target, and it is not the standard we hold ourselves to for the other rights.

If your data sits with a customer organisation

Where we hold the data as a Data Processor, as described in section 2.2 and section 4, we will pass your request to that organisation without delay and let you know. This applies if you are an employee of that organisation, or a contact at one of its vendors.

It does not apply if you appear in material drawn from a third party or public source and have no relationship with that organisation. Section 2.3 covers you, and we answer you ourselves.

13. Security

We take reasonable security safeguards to protect personal data in our possession or under our control, and to prevent a personal data breach.

The Rules set out what these safeguards include as a minimum, and we work to them. They cover measures to secure personal data such as encryption, masking or the use of tokens, controls over who can access the systems that hold personal data, logging and monitoring so that unauthorised access can be detected and investigated, measures to keep the service running if data is lost or becomes unavailable, retention of logs so that incidents can be investigated, appropriate security provisions in our contracts with service providers who process personal data for us, and organisational measures to make sure these safeguards are actually followed.

No system can be guaranteed completely secure. If something goes wrong, section 14 explains what we do.

14. If there is a personal data breach

If a personal data breach affects personal data for which we are the Data Fiduciary, we will tell you without delay, in clear and plain language, through your account or through a contact channel you have registered with us. We will tell you what happened, including its nature, extent and timing, what it is likely to mean for you, what we have done and are doing to reduce the risk, what you can do to protect yourself, and how to reach someone who can answer your questions.

We will also report the breach to the Data Protection Board of India, without delay and then in fuller detail within seventy two hours of becoming aware of it, as the Rules require.

Where the affected data is held by us as a Data Processor for a customer organisation, we will notify that organisation and support them in meeting their own reporting obligations.

15. Children

Our products are business services. They are not directed at children, and we do not knowingly collect the personal data of anyone under the age of eighteen. Accounts are created for people at work, by their employer or by us at their employer’s request.

Some products process material obtained from third party and public sources, as section 4 describes, and we do not control what those sources contain. If you believe a child’s personal data has reached us in any way, contact us at [email protected] and we will delete it.

16. Other websites

Our websites may link to websites we do not control. This policy does not apply to them. Please read the privacy policy of any website you visit through a link from ours. Links between our own sites, techowl.com and techowlshield.com, stay within this policy.

17. Contact us

For privacy questions, to exercise your rights, or to raise a grievance: [email protected]

Grievance Officer

Mr Abhishek Chaudhary

Techowl Infosec Private Limited

A-406 Monarch, Gaurav Path Road, Adajan, Surat, India 395009

[email protected]

If you are not satisfied with how we have handled your complaint, you may escalate it to the Data Protection Board of India.

18. Changes to this policy

We may update this policy from time to time. When we do, we will post the updated version on this page and change the date at the top. Where a change is material, we will notify you as the law requires.

19. Governing law

This policy and any dispute arising under it are governed by the laws of India.