Last updated: 20 August 2026. This is the privacy policy of Techowl
Infosec Private Limited and it covers all of our websites and products. It replaces the separate
policy dated 12 September 2023.
We value your privacy. This policy explains what personal data we collect,
why we collect it, who else sees it, how long we keep it, and the rights you have over it.
Section 4 sets this out product by product.
1. Who we are
We are Techowl Infosec Private Limited, an Indian company registered under the Companies
Act, 2013, with our registered office at A-406 Monarch, Gaurav Path Road, Adajan, Surat,
India 395009. We are the Data Fiduciary or the Data Processor, as section 2 explains, for
the personal data described here.
In this policy, “we”, “us” and “our” mean Techowl
Infosec Private Limited. “You” means the individual whose personal data we
handle.
This one policy covers everything we do. It applies to techowl.com and
techowlshield.com, and to every product listed in section 4, whichever
website or address you reached us through. The same version is published at each of them.
A note on names, because two of them are similar. TechOwl, and the words
we, us and our, mean the company. TechOwl Shield is the name of one
particular product, our attack surface, dark web and brand monitoring service, described
in section 4.1. Where this policy says TechOwl Shield it means that product and nothing
wider.
2. There are two different situations, and they work
differently
India’s Digital Personal Data Protection Act, 2023 distinguishes between a Data
Fiduciary, meaning whoever decides the purpose and the means of processing personal data,
and a Data Processor, meaning whoever processes personal data on a Data Fiduciary’s
behalf. Which one we are depends on the activity, not on the company as a whole.
2.1 Where we are the Data Fiduciary
For the following, we decide why and how the data is used, this policy applies, and you can
bring questions and requests directly to us:
your use of our website, including enquiries, demonstration requests and
subscriptions
our marketing and sales communications
the account and access layer of every product, meaning your login credentials,
authentication factors, session and login records, and the records of your account
being set up and administered (section 4.9)
our own corporate and employment data
2.2 Where we are the Data Processor
If your employer or another organisation uses one of our products, that organisation
decides why and how the data inside the product is used. For that data we act on their
instructions, and their privacy notice governs it, not this one. This includes:
everything monitored, collected, analysed or reported inside a product for that
organisation, as described for each product in section 4
your identity where it appears inside a service record, for example as the owner of a
task, a reviewer, the author of a comment, the recipient of a simulated phishing
message, or the subject of a monitored profile
The same person can fall on both sides of this line. A password reset is ours
to answer for. Your name against a task inside a customer’s service record belongs
to that customer.
2.3 A third situation: people neither of us signed up
Some of our products take in material from third party and public sources on a
customer's instruction. Breach and dark web feeds, paste sites, threat intelligence
feeds and files submitted for analysis all contain whatever their compilers or submitters
put in them. That material can hold personal data about someone who has no account with us
and no connection to the customer we collected it for.
The two situations above do not cover that person. She is not our website visitor or
account holder, so section 2.1 does not reach her. And our customer never decided anything
about her, so it is not honest to send her to them under section 2.2.
For that material we take the following position:
we do not use it to make any decision about the person it concerns
we do not sell it, license it, or enrich it with anything else
we hold it only for the security purpose it was collected for, and we delete it on the
timetable in section 11
a request from that person comes to us, at
[email protected],
and we answer it ourselves. We will not route her to a customer who
has never heard of her
Section 4 marks which products can hold this kind of material.
2.4 Material a person published herself
The Act does not apply to personal data that is made or caused to be made publicly
available either by the person it relates to, or by someone who is under an obligation
under a law in force in India to publish it. The Act gives the example of a person
blogging her views on social media.
So the two halves of what our monitoring picks up are treated differently, and the
difference matters:
What it is
How it is treated
Material a person published herself, such as her
own posts on a public social media account
Outside the Act. We monitor it for
impersonation and exposure without it engaging these obligations
Credentials and records appearing in breach dumps,
combo lists and dark web sources
Inside the Act in full.
This material was not published by the person it concerns; it was taken
from someone and circulated without her. We treat it as her personal data
and section 2.3 applies to it
We do not treat domain registration data as published under a legal obligation
unless that obligation arises under a law in force in India.
If you ask us to act on data we hold in this second situation, we will not answer it
ourselves. We will pass your request to the organisation that controls the data, without
delay, and tell you that we have done so. Under the Act, these rights are exercised
against the Data Fiduciary.
3. What we collect and why
Information you give us
What
Why we need it
Name, work email address, telephone number
To create and operate your account, and to
contact you about the service
Organisation name and your role
To connect your account to the correct
customer organisation
The content of your enquiry, demonstration request or
support message
To answer you
Marketing preferences
To send you only the updates you have asked
for
Information collected automatically
What
Why we need it
Login records, session records and access logs
To operate the service, to control access, and
to detect and investigate unauthorised access
IP address, browser, device and operating system
information
To keep the service secure and working
correctly
Pages visited, time spent and how you arrived at the
site
To understand how the site is used and improve
it
Personal data processed inside a particular product is described in section
4.
4. What each product processes
We operate the products below. What personal data is involved, where it comes from, and
whether a request should come to us or to the organisation that engaged us depends on
which product is in question. Not every customer uses every product.
In every product, the account and access layer described in section 4.9 is ours as Data
Fiduciary. What the product then does for a customer organisation belongs to that
organisation, and we act as its Data Processor. Some products also take in material about
people who are connected to neither of us; section 2.3 governs those, and the products
concerned are marked below. Where a product departs from the pattern, it is stated in its
own entry.
4.1 TechOwl Shield: attack surface, dark web and brand monitoring
What it does
Monitors a customer organisation’s domains, brands, executives and
the assets it exposes to the internet, and reports exposures: credentials
appearing in third party breaches, material on dark web and paste sources,
lookalike and phishing domains, impersonating websites and social media
accounts, and the security posture of the organisation’s external
assets.
Personal data processed
Email addresses, usernames and passwords or password hashes appearing in
third party breach, combo list and dark web sources; names and roles of
executives and staff who appear in monitored material; social media
account names and content connected with impersonation; domain
registration details, which can include a registrant’s name, email
address, telephone number and postal address; asset inventories and scan
findings for the organisation’s systems.
Where it comes from
The customer organisation, which tells us what to monitor; and third party
and publicly available sources, including breach and dark web feeds, paste
sites, domain registration data, certificate transparency logs and social
media platforms.
Our role
Two roles, depending on whose data it is. Data Processor
on the customer organisation's instructions for its own domains, brands,
assets and staff. Section 2.3 applies to anyone else
caught in breach, combo list or dark web material, because that person has
no connection to our customer and our customer decided nothing about her.
Material she published herself is outside the Act under section 2.4. If
you believe you appear in this data, contact us at
[email protected]
and we will answer you ourselves.
4.2 TechOwl SOC and Ticketing: security operations and incident management
What it does
Receives, triages and tracks security incidents for a customer
organisation. Analysts work incidents raised by monitoring systems, by
email and by the customer, and record their findings, actions and
communications.
Personal data processed
Names, work email addresses and telephone numbers of the customer’s
staff and of our analysts; the content of email correspondence about an
incident, including sender, recipients, subject, body and attachments;
records of telephone calls made to confirm urgent incidents; user, device
and host identifiers appearing in security alerts, such as usernames, IP
addresses, hostnames and endpoint identifiers; and any personal data a
person chooses to put into a ticket, a comment or an attachment.
Screenshots, log extracts, exported records and spreadsheets are routinely
attached.
Where it comes from
The customer organisation and its users, our analysts, the
customer’s own security tooling, and email sent to the service desk.
Our role
Data Processor for incidents and their contents. Where you write to us
with an enquiry or a support request about our own service rather than
about an incident, that message is ours as Data Fiduciary.
Collects and interprets DMARC, SPF and DKIM reporting for a
customer’s email domains, monitors the DNS records that support it,
and alerts on failures and changes.
Personal data processed
Aggregate reports, which contain the IP addresses of systems sending mail
using the domain together with volumes and authentication results; failure
reports, which can contain detail drawn from individual messages,
including sender and recipient email addresses, subject lines and message
headers; the credentials of the mailbox from which reports are collected;
and the names and email addresses of the people who use the product.
Where it comes from
Mailbox providers and other receiving mail servers that generate the
reports, public DNS, and the customer organisation.
Our role
Data Processor. Failure reports can carry the details of
people outside the customer's organisation, on either end of a
message. Section 2.3 applies to them.
4.4 PhishGuard: phishing simulation and security awareness training
What it does
Runs simulated phishing campaigns for a customer organisation and assigns
security awareness training based on how people respond.
Personal data processed
Name, work email address, and the department, group or role the customer
assigns. For each simulated message: whether it was delivered, opened and
clicked, whether credentials were entered on the simulated page, whether
an attachment was opened, whether it was replied to and the content of
that reply, and whether it was reported; the time taken to click or to
report; and the IP address, browser, device type and approximate location
of the interaction. Training assignments, completion, scores and any
feedback given.
Where it comes from
The customer organisation, which supplies the people to include; and the
individual’s own interaction with the simulated message and the
training.
Our role
Data Processor. The customer organisation decides who is included in a
simulation, what is measured, and what is done with the result.
4.5 Complython: governance, risk and compliance
What it does
Manages a customer’s compliance programme: control frameworks and
assessments, audits, risk registers, policies, tasks, and the evidence
collected against them.
Personal data processed
Names, work email addresses and roles of the customer’s staff,
auditors and reviewers; the record of who was assigned a task, who
reviewed it, who approved it and when; comments and discussion; and the
contents of evidence documents uploaded to demonstrate a control, which
are supplied by the customer and can contain personal data.
Where it comes from
The customer organisation and its users.
Our role
Data Processor.
4.6 Vendor and third party risk management
What it does
Sends security questionnaires to a customer’s vendors, collects
their responses and evidence, scores them, and tracks remediation.
Personal data processed
Names, work email addresses and roles of the customer’s staff and of
contacts at the vendor being assessed, including guest reviewers who are
invited to respond and have no other relationship with us; questionnaire
responses, uploaded evidence documents, discussion threads and approval
decisions; and access records for guest users, including IP address and
browser.
Where it comes from
The customer organisation, and the vendor’s own personnel when they
respond.
Our role
Data Processor for the organisation that commissioned the assessment.
Vendor contacts should bring requests to that organisation; if they come
to us we will pass them on without delay and tell them we have done so.
4.7 ThreatPulse: threat intelligence distribution
What it does
Collects indicators of compromise from upstream threat intelligence feeds,
normalises them into the STIX 2.1 format, and distributes them to
subscribing customers through a TAXII 2.1 API and file exports.
Personal data processed
The account and access data of subscribing customers, including API keys
and usage records of API calls such as time, endpoint and source IP
address. Indicators themselves describe infrastructure, such as addresses,
domains, URLs and file hashes, but an indicator can incidentally contain
personal data, for example an email address used in a phishing campaign,
or contact details held in domain registration data.
Where it comes from
Upstream threat intelligence feeds and open sources; and, for account
data, the subscribing customer.
Our role
Data Fiduciary for subscriber accounts and usage records.
For indicator content obtained from upstream feeds and redistributed,
section 2.3 applies: we do not use it to make decisions
about any individual and we do not sell personal data. If you believe an
indicator contains your personal data, contact us at
[email protected]
and we will answer you ourselves.
4.8 TechOwl Sandbox: malware and file analysis
What it does
Executes submitted files and URLs in an isolated environment and reports
what they do.
Personal data processed
The account data of the person submitting; the submitted file or URL
itself, which can contain personal data, as documents submitted for
analysis frequently do; the artefacts produced by the analysis, including
screenshots of execution, network requests, dropped files and recordings
of interactive analysis sessions; and analysis comments and tags.
Where it comes from
The person or organisation that submits the sample.
Our role
Data Processor for samples and results submitted by a
customer organisation. Where a sample contains personal data about someone
who has no relationship with us or with the submitter,
section 2.3 applies: we process it only to produce the
analysis, we make no decision about that person, and we apply the
retention in section 11.
4.9 Account and access layer: all products
What it does
Creates accounts, authenticates you across products through one central
login, holds your session, and records access.
Personal data processed
Name, work email address, telephone number where given, the organisation
and role you are attached to, credentials and authentication factors,
session records, login history including IP address and browser, and the
record of your account being created, changed and closed.
Where it comes from
You, and the organisation that engaged us where an account is created for
you.
Our role
Data Fiduciary. Questions and requests about this layer come to us
directly, whichever product you use it to reach.
5. Our lawful basis for using it
The Act permits personal data to be processed either with your consent, or for one of the
specific purposes it lists as “certain legitimate uses”.
Operating your account, responding to you and keeping the service secure. We rely on
the legitimate use covering personal data that you have voluntarily provided to us for
a specified purpose and have not objected to. This is section 7(a) of the Act.
Marketing communications. We rely on your consent, which you can withdraw at any time.
See section 10.
Data inside a product. Where we process personal data inside a product for a customer
organisation, we do so on that organisation’s documented instructions, and the
organisation is responsible for the lawful basis.
Records we are required to keep by law. Where another law requires us to retain
information, we rely on that obligation.
We do not use your personal data for any purpose we have not described in this
policy. If we ever need to, we will tell you and, where the law requires it, ask you
first.
6. Where the information comes from
Directly from you, when you create an account, contact us, request a demonstration, or
subscribe to updates.
Automatically, when you use the website or a product, through server logs, cookies and
similar technologies.
From your employer or the organisation that engaged us, where an account is created
for you or where you are included in a service they have commissioned.
From third party and publicly available sources, where a product monitors for
exposures on a customer’s behalf. This includes breach and dark web feeds, paste
sites, domain registration data, certificate transparency logs, social media
platforms, threat intelligence feeds and mail authentication reports. Section 4 says
which products do this.
7. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, to keep the service secure,
and to understand how the site is used. Analytics tools help us see which pages are
visited and how people arrive at the site.
You can control or delete cookies through your browser settings. Blocking some cookies may
stop parts of the site working.
8. Who else sees it
We do not sell your personal data.
We share it only with the following, and only so far as each needs it:
Service providers who work on our instructions, including hosting and cloud
infrastructure, email delivery, customer support tooling, analytics, and providers
that help us secure and monitor our own systems. They may use the data only to provide
those services to us.
The customer organisation that engaged us, where the data sits inside a product we
operate for them.
Courts, regulators, government agencies and law enforcement, where we are required to
disclose information, where we must respond to a lawful order or request, or where we
are investigating suspected fraud or misuse of the service.
A successor organisation, if all or part of our business is transferred. We will tell
you before your personal data becomes subject to a different privacy policy.
Some of our service providers may be located outside India.
9. Information going outside India
The Act permits personal data to be transferred outside India, subject to any restriction
that the Central Government may notify in respect of a particular country or territory.
Where we transfer personal data outside India, we do so in line with those restrictions
and with any requirements the Central Government specifies about making personal data
available to a foreign State or to an entity under the control of a foreign State.
Where another Indian law places a stricter restriction on transfer than the Act does, that
stricter requirement continues to apply, and we comply with it.
10. Marketing, and how to stop it
We send marketing communications only where you have agreed to receive them.
You can withdraw that agreement at any time by emailing
[email protected]. We
will act on your request promptly and will stop sending marketing communications.
We will still send you messages about your account and your service, such as security
alerts and service updates. These are not marketing and they continue while you hold an
account.
11. How long we keep it
We keep personal data only for as long as we need it for the purpose we collected it for,
and then we delete it, unless a law requires us to keep it for longer.
In practice this means:
Account information is kept while your account is open and for a reasonable period
after it closes, so that we can deal with questions, disputes and any legal
obligations arising from your use of the service.
Login records, session records and access logs are kept for at least one year. The
Rules require logs and the related personal data to be retained for one year so that
unauthorised access can be detected, investigated and remedied, unless another law
requires otherwise.
Data inside a product, including tickets and their attachments, monitoring findings,
assessment responses, simulation results and submitted samples, is kept for the period
agreed with the customer organisation that engaged us, and is deleted or returned at
the end of that engagement in line with our agreement with them.
Material taken from third party and public sources, where it concerns
someone unconnected to the customer we collected it for, is kept only while the
security purpose needs it. Where a finding is closed as a false positive, the
underlying material is deleted at closure rather than kept to the end of the
engagement.
Records we are required to keep by another law are kept for the period that law
requires.
Enquiries and demonstration requests are kept for as long as we are in contact with
you about them and for a reasonable period afterwards.
Marketing contact details are kept until you withdraw your agreement. After that we
keep the minimum needed to make sure we do not contact you again.
Two points worth being clear about. A one year minimum is a floor, not a
deadline, and it does not mean that all personal data is kept for one year. And closing
your account does not delete everything at once, because a record that must be kept for
its retention period is kept even after the account closes.
12. Your rights
Under the Act, where we are the Data Fiduciary for your personal data, you have the right
to:
Right
What it means
Access
Obtain a summary of the personal data we are
processing about you, an account of what we have done with it, and the
identities of others we have shared it with
Correction
Have inaccurate or misleading data corrected,
incomplete data completed, and out of date data updated
Erasure
Have your personal data erased, unless we still
need it for the purpose we told you about, or a law requires us to keep it
Grievance redressal
Complain to us about how we have handled your
personal data or your request
Nomination
Nominate another individual who may exercise
your rights on your behalf if you die or become unable to act
How to make a request
Email [email protected].
To help us find your records and confirm it is you, please tell us your full name, the
email address associated with your account or your enquiry, and the organisation you
belong to if you use a product through your employer. Please describe what you would like
us to do. If your request concerns a specific product, telling us which one helps us route
it correctly.
How long we take
If you are raising a grievance, the Rules require us to publish the period
within which we will respond, to set that period at no more than ninety days, and to put
the measures in place to actually meet it. Our published period is seven working
days.
If you are asking us to access, correct, erase or nominate, the Rules do
not set a response period at all. We work in two stages. We acknowledge your
request within seven working days and tell you what we hold, and we
complete it within thirty days.
The second stage takes longer than the first for a reason. An access request asks us for
the identities of everyone your data has been shared with, and answering that honestly
means searching every product in section 4 rather than the one you came in through. We
would rather publish a period we meet than a shorter one we miss.
Ninety days is a ceiling the Rules place on the grievance period. It is not a target, and
it is not the standard we hold ourselves to for the other rights.
If your data sits with a customer organisation
Where we hold the data as a Data Processor, as described in section 2.2 and section 4, we
will pass your request to that organisation without delay and let you know. This applies
if you are an employee of that organisation, or a contact at one of its vendors.
It does not apply if you appear in material drawn from a third party or
public source and have no relationship with that organisation. Section 2.3 covers you, and
we answer you ourselves.
13. Security
We take reasonable security safeguards to protect personal data in our possession or under
our control, and to prevent a personal data breach.
The Rules set out what these safeguards include as a minimum, and we work to them. They
cover measures to secure personal data such as encryption, masking or the use of tokens,
controls over who can access the systems that hold personal data, logging and monitoring
so that unauthorised access can be detected and investigated, measures to keep the service
running if data is lost or becomes unavailable, retention of logs so that incidents can be
investigated, appropriate security provisions in our contracts with service providers who
process personal data for us, and organisational measures to make sure these safeguards
are actually followed.
No system can be guaranteed completely secure. If something goes wrong, section 14 explains
what we do.
14. If there is a personal data breach
If a personal data breach affects personal data for which we are the Data Fiduciary, we
will tell you without delay, in clear and plain language, through your account or through
a contact channel you have registered with us. We will tell you what happened, including
its nature, extent and timing, what it is likely to mean for you, what we have done and
are doing to reduce the risk, what you can do to protect yourself, and how to reach
someone who can answer your questions.
We will also report the breach to the Data Protection Board of India, without delay and
then in fuller detail within seventy two hours of becoming aware of it, as the Rules
require.
Where the affected data is held by us as a Data Processor for a customer organisation, we
will notify that organisation and support them in meeting their own reporting
obligations.
15. Children
Our products are business services. They are not directed at children, and we do not
knowingly collect the personal data of anyone under the age of eighteen. Accounts are
created for people at work, by their employer or by us at their employer’s request.
Some products process material obtained from third party and public sources, as section 4
describes, and we do not control what those sources contain. If you believe a
child’s personal data has reached us in any way, contact us at
[email protected] and we
will delete it.
16. Other websites
Our websites may link to websites we do not control. This policy does not apply to them.
Please read the privacy policy of any website you visit through a link from ours. Links
between our own sites, techowl.com and techowlshield.com, stay within this policy.
17. Contact us
For privacy questions, to exercise your rights, or to raise a grievance:
[email protected]
Grievance Officer
Mr Abhishek Chaudhary
Techowl Infosec Private Limited
A-406 Monarch, Gaurav Path Road, Adajan, Surat, India 395009
If you are not satisfied with how we have handled your complaint, you may escalate it to
the Data Protection Board of India.
18. Changes to this policy
We may update this policy from time to time. When we do, we will post the updated version
on this page and change the date at the top. Where a change is material, we will notify
you as the law requires.
19. Governing law
This policy and any dispute arising under it are governed by the laws of India.