This Privacy Policy explains how ASPIA Infotech Private Limited ("ASPIA", "we", "us" or "our") collects, uses, stores, and discloses personal data when you visit our website, contact us, or use the ASPIA platform.
ASPIA provides an enterprise Governance, Risk and Compliance (GRC) and cybersecurity workflow platform through Software-as-a-Service (SaaS) and customer-managed on-premises deployments.
This Privacy Policy applies to our website and, where relevant, personal data processed through the ASPIA platform. It should be read together with applicable customer agreements and any additional privacy notices provided for specific services.
Depending on how you interact with our website, we may collect:
Depending on the features enabled and how the platform is used, ASPIA may process:
The information processed depends on the customer's use of the platform, enabled modules, configuration, integrations and deployment model. Customers should only submit personal data necessary for their intended use of the platform.
ASPIA may use personal data for the following purposes:
Customers determine the information they submit to the ASPIA platform and the purposes for which they use it. Customers are responsible for ensuring that they have the necessary rights and authorisations to provide such information to ASPIA for processing.
Where ASPIA processes customer data to provide, maintain or support the platform, it does so in accordance with the applicable Customer Agreement, authorised customer instructions and applicable legal requirements. The respective responsibilities of ASPIA and the customer, including responsibilities relating to personal data protection, access management, security, retention and deletion, are governed by the applicable Customer Agreement and related contractual terms.
ASPIA implements appropriate technical and organisational safeguards to protect customer data, taking into account the applicable deployment model, security configuration and contractual commitments. Access to customer data by ASPIA personnel for implementation, maintenance or support is limited to authorised activities and is subject to customer authorisation and the applicable support arrangements.
For SaaS deployments, ASPIA manages the platform hosting environment in accordance with the applicable service and customer arrangements. For on-premises deployments, the customer generally manages the underlying hosting environment and infrastructure, while ASPIA's responsibilities are determined by the applicable deployment and support arrangements.
Customers should ensure that only personal data necessary for the intended purpose is submitted to the platform. Customer data is retained, exported, returned or deleted in accordance with the applicable Customer Agreement, relevant customer requirements and ASPIA's documented operational processes.
ASPIA processes personal data on a basis permitted by applicable law. Depending on the circumstances, processing may be necessary to provide requested services, perform contractual obligations, respond to enquiries, maintain security, comply with legal requirements or fulfil another legally permitted purpose.
Where consent is required, ASPIA or the relevant responsible party will obtain consent in accordance with applicable law. Where consent is relied upon, applicable requirements concerning withdrawal of consent will be respected.
The applicable privacy notice and consent process may vary depending on the service, customer arrangement and context in which information is collected.
ASPIA may disclose or make personal data available to:
ASPIA does not sell personal data as a business model. Information is disclosed only as appropriate for the relevant purpose, contractual arrangement or legal requirement.
ASPIA uses technical and organisational safeguards intended to protect personal data against unauthorised access, loss, alteration or disclosure.
For SaaS deployments, access may be restricted through IP allowlisting and authentication controls, where configured. The controls applicable to each deployment depend on its architecture, configuration and contractual arrangements.
For on-premises deployments, security responsibilities are shared or allocated according to the deployment arrangement and applicable customer agreement.
Data is transmitted over HTTPS/TLS. Encryption at rest for databases and uploaded files depends on the applicable customer deployment, cloud configuration and storage arrangements.
No method of data transmission or storage can be guaranteed to be completely secure.
ASPIA retains personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected or processed, provide and support its services, comply with applicable legal and regulatory requirements, maintain necessary business and security records, resolve disputes and enforce applicable agreements.
For customer data processed through the ASPIA platform, retention periods depend on the applicable Customer Agreement, customer retention requirements, legal or regulatory obligations and the relevant deployment configuration.
Following termination of a SaaS service, customers may request an export of their data before deletion, subject to the applicable Customer Agreement and operational arrangements. Customer data, associated hosting resources and relevant backups are handled in accordance with the applicable agreement and ASPIA's documented deletion procedures.
For on-premises deployments, the customer generally manages retention and deletion within its own infrastructure, subject to the agreed deployment and support arrangements.
Where personal data must be retained to meet legal obligations, resolve disputes or maintain required records, it may be retained for the applicable period. When continued retention is no longer necessary, the data will be deleted or otherwise disposed of in accordance with applicable requirements and the relevant operational processes.
The location in which data is stored or accessed depends on the applicable deployment model, hosting arrangements, backup and disaster recovery configuration, service providers and authorised support access.
For SaaS deployments, ASPIA's platform may be hosted in different countries depending on the customer's hosting requirements and applicable service arrangements. The location of backup and disaster recovery (DR) data also depends on the applicable customer requirements, hosting configuration and service arrangements. For on-premises deployments, customer data is generally stored within the customer-managed infrastructure.
Any cross-border processing or transfer of personal data must be assessed and handled in accordance with applicable legal, regulatory and contractual requirements. Customer-specific data-location, backup and disaster recovery commitments, where applicable, are governed by the relevant service and customer agreement.
Subject to applicable law, individuals may have rights relating to their personal data, including the right to request access, correction, updating or erasure, withdraw consent where processing is based on consent, or exercise other applicable privacy rights.
Individuals may submit privacy-related requests or complaints using the contact details provided below. ASPIA will assess and handle requests in accordance with applicable law and its role in the relevant processing activity.
Where information is processed by ASPIA on behalf of a customer, the request may need to be directed to the customer, or ASPIA may assist the customer under the applicable agreement.
ASPIA may request information necessary to verify the identity of the requester and locate the relevant data.
If you have a concern about how ASPIA has handled your personal data, you may raise a complaint using the contact details provided in the Contact Us section below.
ASPIA will acknowledge and assess the complaint in accordance with applicable law and its role in the relevant processing activity. Where information is processed by ASPIA on behalf of a customer, the complaint may need to be directed to that customer, or ASPIA may assist the customer under the applicable agreement.
Please include sufficient information to help us understand and respond to your request. Applicable legal response timelines and escalation procedures will be followed.
Our website or platform may contain links to third-party websites or integrate with third-party services. Those websites and services may have their own privacy policies and data-handling practices.
ASPIA is not responsible for the privacy practices of third-party websites that it does not operate. Users should review the relevant third-party privacy policies before providing information to those services.
ASPIA may update this Privacy Policy from time to time to reflect changes in its services, data-processing practices, or applicable legal requirements.
Material changes will be communicated to affected customers through email. The updated Privacy Policy will also be published on the ASPIA website, along with the revised version number and effective or last-updated date.
Previous versions of this Privacy Policy will be maintained for recordkeeping and reference purposes.
Updates to this Privacy Policy do not, by themselves, amend or modify any existing Customer Agreement. Any changes to contractual obligations will be handled in accordance with the applicable Customer Agreement.