Privacy Policy

Last updated: 31 July 2026

This policy explains how Knock Security Solutions Pvt. Ltd. ("Knock Security", "we", "us") collects and handles personal data through this website and in the course of providing security testing services.

1. Who we are

Knock Security Solutions Pvt. Ltd. is a private limited company registered in India, operating remote-first from Pune, Maharashtra. For any privacy question or request, contact info@knocksecurity.com.

2. Data we collect

2.1 Website enquiries

When you submit our contact form we collect the name, email address, company name (if provided), selected service interest, and the content of your message. Our server also records the originating IP address and submission timestamp for the sole purpose of preventing automated abuse.

2.2 Engagement data

When delivering a security engagement we necessarily encounter data within the systems we are authorised to test. This may include application data, configuration, credentials issued to us for testing, and — depending on your environment — personal data belonging to your users. We treat all of it as confidential client information and process it solely to deliver the engagement.

2.3 Server logs

Our hosting provider maintains standard web server logs, which may include IP address, user agent, requested URL, and timestamp. These are retained for security and operational diagnostics.

3. Cookies and analytics

This website does not set tracking or advertising cookies, and does not run third-party analytics or advertising scripts. No consent banner is required because we do not perform any non-essential tracking.

4. How we use your data

  • To respond to your enquiry and scope a potential engagement
  • To deliver, report on, and retest a contracted security engagement
  • To meet legal, tax, and contractual record-keeping obligations
  • To protect this website against automated abuse

We do not sell personal data, and we do not use enquiry data for unsolicited marketing.

5. Legal basis

Where the GDPR applies, we rely on: your consent or steps taken prior to entering a contract (enquiries); performance of a contract (engagement delivery); legitimate interests (website security and abuse prevention); and legal obligation (statutory record-keeping). Where we process personal data contained within a client environment, the client is the data controller and we act as a processor under the terms of the engagement contract.

6. Sharing and disclosure

We do not share client or enquiry data with third parties for their own purposes. Data may be handled by our hosting and email service providers strictly as necessary to operate this website and our correspondence, and may be disclosed where we are legally compelled to do so.

7. Retention

Website enquiries that do not lead to an engagement are retained for up to 24 months, then deleted. Engagement reports and supporting evidence are retained for the period stated in the engagement contract; where no period is specified, we retain them for 12 months following delivery of the retest report and then securely destroy them. Clients may request earlier destruction in writing at any time.

8. Security

Engagement data is encrypted in transit and at rest, access is restricted to personnel working on that engagement, and reports are delivered through channels agreed with the client. As a security practice we regard the protection of client findings as a core professional obligation — a report describing unpatched vulnerabilities is among the most sensitive documents a client can hold.

9. International transfers

We operate from India and serve clients internationally. Where personal data originating in the EEA or UK is transferred to us, that transfer is governed by the data-processing terms agreed in the engagement contract, including standard contractual clauses where required.

10. Your rights

Subject to applicable law, you may request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, or portability, and you may object to processing based on legitimate interests. To exercise any of these rights, email info@knocksecurity.com. We will respond within the period required by applicable law. You also have the right to complain to your local data protection authority.

11. Changes to this policy

We may update this policy from time to time. The revision date at the top of this page indicates the most recent change.

12. Contact

Knock Security Solutions Pvt. Ltd., Pune, Maharashtra, India — info@knocksecurity.com