Privacy Policy
This policy explains how Knock Security Solutions Pvt. Ltd. ("Knock Security", "we", "us") collects and handles personal data through this website and in the course of providing security testing services.
1. Who we are
Knock Security Solutions Pvt. Ltd. is a private limited company registered in India, operating remote-first from Pune, Maharashtra. For any privacy question or request, contact info@knocksecurity.com.
2. Data we collect
2.1 Website enquiries
When you submit our contact form we collect the name, email address, company name (if provided), selected service interest, and the content of your message. Our server also records the originating IP address and submission timestamp for the sole purpose of preventing automated abuse.
2.2 Engagement data
When delivering a security engagement we necessarily encounter data within the systems we are authorised to test. This may include application data, configuration, credentials issued to us for testing, and — depending on your environment — personal data belonging to your users. We treat all of it as confidential client information and process it solely to deliver the engagement.
2.3 Server logs
Our hosting provider maintains standard web server logs, which may include IP address, user agent, requested URL, and timestamp. These are retained for security and operational diagnostics.
3. Cookies and analytics
This website does not set tracking or advertising cookies, and does not run third-party analytics or advertising scripts. No consent banner is required because we do not perform any non-essential tracking.
4. How we use your data
- To respond to your enquiry and scope a potential engagement
- To deliver, report on, and retest a contracted security engagement
- To meet legal, tax, and contractual record-keeping obligations
- To protect this website against automated abuse
We do not sell personal data, and we do not use enquiry data for unsolicited marketing.
5. Legal basis
Where the GDPR applies, we rely on: your consent or steps taken prior to entering a contract (enquiries); performance of a contract (engagement delivery); legitimate interests (website security and abuse prevention); and legal obligation (statutory record-keeping). Where we process personal data contained within a client environment, the client is the data controller and we act as a processor under the terms of the engagement contract.
6. Sharing and disclosure
We do not share client or enquiry data with third parties for their own purposes. Data may be handled by our hosting and email service providers strictly as necessary to operate this website and our correspondence, and may be disclosed where we are legally compelled to do so.
7. Retention
Website enquiries that do not lead to an engagement are retained for up to 24 months, then deleted. Engagement reports and supporting evidence are retained for the period stated in the engagement contract; where no period is specified, we retain them for 12 months following delivery of the retest report and then securely destroy them. Clients may request earlier destruction in writing at any time.
8. Security
Engagement data is encrypted in transit and at rest, access is restricted to personnel working on that engagement, and reports are delivered through channels agreed with the client. As a security practice we regard the protection of client findings as a core professional obligation — a report describing unpatched vulnerabilities is among the most sensitive documents a client can hold.
9. International transfers
We operate from India and serve clients internationally. Where personal data originating in the EEA or UK is transferred to us, that transfer is governed by the data-processing terms agreed in the engagement contract, including standard contractual clauses where required.
10. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, or portability, and you may object to processing based on legitimate interests. To exercise any of these rights, email info@knocksecurity.com. We will respond within the period required by applicable law. You also have the right to complain to your local data protection authority.
11. Changes to this policy
We may update this policy from time to time. The revision date at the top of this page indicates the most recent change.
12. Contact
Knock Security Solutions Pvt. Ltd., Pune, Maharashtra, India — info@knocksecurity.com