Privacy Policy
This policy explains what personal data Intect collects, why, what we do with it, and the rights you hold over it. We have kept it in plain language on purpose — a privacy policy you cannot read protects no one.
01 Who we are
This website, theintect.com (the “Site”), is operated by Hion Security Pvt Ltd, an Indian company operating as Intect (“Intect”, “we”, “us”). For the personal data described in this policy, we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and, where the EU General Data Protection Regulation applies to you, the data controller.
Registered address: FIEE Complex, A-19, Okhla Phase 2, New Delhi 110020. Corporate office: B-18, Sector - 1, Noida, Uttar Pradesh 201301.
02 What we collect
Information you give us. When you use the contact form or write to us directly, we collect what you submit: your name, work email address, organization, the subject of your inquiry and your message. If we then work together, we hold the ordinary business contact information exchanged in the course of the engagement — names, roles, work email addresses and phone numbers. If you apply for a role through our careers page, section 06 describes that processing separately.
Information processed automatically. Like almost every website, our hosting infrastructure keeps standard server logs (requested pages, timestamps, IP address, browser type). Separately, when you submit the contact or job-application form, your IP address is processed to rate-limit submissions and filter spam; that anti-abuse record is kept for about one hour and is not accessible from the web.
A preference stored in your browser. Your light/dark theme choice is saved in your browser’s local storage. It never leaves your device and we cannot read it from our side.
What we deliberately do not do. This Site sets no cookies, runs no analytics or advertising trackers, uses no marketing pixels and builds no visitor profiles. We do not buy data about you from third parties, and we do not send marketing you have not asked for.
03 How we use it
We use personal data for a short list of purposes:
- to respond to your inquiry and follow up on it;
- to scope, contract and deliver the professional services you ask us about;
- to keep the Site and the contact form secure and free of abuse;
- to keep the business records — invoicing, correspondence, engagement files — that running a company and complying with law require; and
- to meet legal obligations and respond to lawful requests from authorities.
Under the DPDP Act we process your data on the basis of your consent (you choose to contact us) and for the legitimate uses the Act recognizes, such as processing you have voluntarily initiated. Where the GDPR applies, our legal bases are your consent, the steps needed to enter or perform a contract with you, our legitimate interest in operating and protecting the Site and our business, and compliance with legal obligations.
04 Who we share it with
We do not sell, rent, license or lease your personal data to anyone. We share it only with:
- Service providers that make the Site and our communications work — our hosting provider and email infrastructure — which process data on our instructions;
- Professional advisers — lawyers, accountants and auditors — where their work requires it;
- Authorities, where a law, regulation or binding order requires disclosure; and
- A successor entity, if Hion Security Pvt Ltd is ever party to a merger, acquisition or reorganization — under confidentiality consistent with this policy.
05 Data we encounter in security engagements
Intect is an offensive-security and audit firm. In the course of a penetration test, red-team exercise or audit we may unavoidably encounter personal data held in a client’s systems. That data is processed under the written engagement contract with the client, on the client’s instructions, under strict confidentiality — it is the client’s data, not ours. We do not extract, retain or reuse it beyond what the engagement and its evidence requirements demand. If your data is held by one of our clients, please direct requests about it to that organization; where the DPDP Act or GDPR applies to it, that organization is the Data Fiduciary or controller.
06 Job applications
When you apply for a role through our careers page, we collect what the application form asks for: your name, email address, phone number and CV, and — if you choose to provide them — a LinkedIn profile URL and a cover note. A CV usually contains personal data beyond what we ask for; we treat everything in it under this section.
We process this data for one purpose: to evaluate your candidacy for the role you applied to and for similar openings at Intect. The legal basis is your explicit consent — the application cannot be submitted without ticking the consent box, and the consent you gave, including the version of the consent text you saw and when you gave it, is recorded together with your application.
Retention. We keep applications for up to 12 months from the date you apply, then delete them. If you ask us to delete your application earlier, we will — write to info@theintect.com and we will confirm the deletion. Withdrawing consent stops any further processing from that point.
Where it lives. Applications are stored in a private database, and CV files in access-restricted storage that is not reachable from the web. Access is limited to the people involved in hiring. Recruitment data is shared with no one beyond the recipients listed in section 04, is never sold, and is never used for marketing. As with the contact form, your IP address is processed transiently to rate-limit submissions and is not stored with your application.
07 How long we keep it
Only as long as the purpose needs, and after that only as long as law requires. Inquiry correspondence is kept while we deal with it and for a reasonable period after. Engagement and financial records follow the retention periods Indian tax, accounting and company law prescribe. The contact form’s anti-abuse record of your IP address is kept for about one hour. Server logs rotate on our hosting provider’s standard schedule.
08 How we protect it
We apply reasonable security safeguards — technical and organizational — proportionate to the data we hold: encrypted transport for the Site, access limited to the people who need it, and the same security discipline we are hired to test in others. We will tell you the truth the industry sometimes avoids: no organization can guarantee absolute security. If a personal data breach affecting you occurs, we will notify you and the Data Protection Board of India as the DPDP Rules require.
09 Your rights — India (DPDP Act, 2023)
As a Data Principal you have the right to:
- Access — a summary of the personal data we hold about you and the processing activities applied to it;
- Correction and erasure — to have inaccurate data corrected and data erased once it is no longer needed for its purpose or a legal retention requirement;
- Withdraw consent — at any time, with effect going forward, as easily as you gave it;
- Grievance redressal — a working complaint mechanism, described below; and
- Nomination — to nominate another person to exercise these rights in the event of death or incapacity.
To exercise any of these, write to info@theintect.com. We aim to resolve requests and grievances quickly, and in every case within ninety (90) days — the published response window the DPDP Rules, 2025 require of us. If you remain unsatisfied after using our grievance mechanism, you may approach the Data Protection Board of India.
10 Your rights — EU and UK visitors (GDPR)
If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection — including an absolute right to object to direct marketing — plus the right to withdraw consent at any time and the right not to be subject to decisions based solely on automated processing that significantly affect you (we make no such decisions). You may also lodge a complaint with your supervisory authority. Note that we are located in India: data you send us is processed in India, and we protect it as this policy describes regardless of where you write from.
11 Children
The Site and our services are directed at organizations and working professionals, not at children. We do not knowingly collect personal data from anyone under 18; if you believe we have, tell us and we will delete it.
12 Links to other websites
Pages on this Site link to primary sources — standards bodies, regulators and publications. Those sites have their own privacy practices, which we do not control and this policy does not cover.
13 Changes to this policy
When we change this policy we will post the new version here and update the “last updated” date at the top. If a change meaningfully reduces your rights, we will say so plainly rather than bury it.
14 Contact & grievances
Grievance Officer — Hion Security Pvt Ltd
Email: info@theintect.com
Phone: +91 8882690146 / +91 8800299792
Registered Address: FIEE Complex, A-19, Okhla Phase 2, New Delhi 110020
See also: Terms of Service