Legal & Compliance

Privacy Policy

ASPIA Infotech Private Limited

Last updated: 8 August 2025 Version 1.4 Enterprise Governance, Risk & Security Operations Platform
01

Introduction

This Privacy Policy explains how ASPIA Infotech Private Limited ("ASPIA", "we", "us" or "our") collects, uses, stores, and discloses personal data when you visit our website, contact us, or use the ASPIA platform.

ASPIA provides an enterprise Governance, Risk and Compliance (GRC) and cybersecurity workflow platform through Software-as-a-Service (SaaS) and customer-managed on-premises deployments.

This Privacy Policy applies to our website and, where relevant, personal data processed through the ASPIA platform. It should be read together with applicable customer agreements and any additional privacy notices provided for specific services.

02

Information We Collect

2.1 Website Visitors and Enquiries

Depending on how you interact with our website, we may collect:

  • Contact information: Name, business email address, organisation, telephone number and enquiry details submitted through contact forms or other communications.
  • Technical information: IP address, browser information, access timestamps and website security logs, where collected.
  • Cookie and analytics information: Information collected through cookies or similar technologies, where these are used on our website.

2.2 Platform Users and Customer Data

Depending on the features enabled and how the platform is used, ASPIA may process:

  • Account information: Full name, registered email address, user/login ID and internal application or organisation identifiers.
  • Authentication information: ASPIA uses hashed passwords. MFA, SAML SSO and Active Directory authentication are supported depending on customer requirements and configuration.
  • Technical and activity information: IP addresses and application activity information, where recorded in application, access or security logs.
  • Customer-provided information: GRC assessments, audit records, vendor information, risk records, findings, evidence files, asset information and workflow data entered or uploaded by authorised users.
  • Integration information: Information received from connected systems where the relevant integration is enabled and configured.

The information processed depends on the customer's use of the platform, enabled modules, configuration, integrations and deployment model. Customers should only submit personal data necessary for their intended use of the platform.

03

How We Use Information

ASPIA may use personal data for the following purposes:

  • Responding to enquiries, demonstration requests and support requests.
  • Creating and administering user accounts and authenticating users.
  • Managing user roles, permissions and organisation-level access separation.
  • Providing GRC, risk management, audit, vulnerability management, incident management and related workflow functionality.
  • Operating, maintaining, troubleshooting and protecting the website and platform.
  • Investigating suspected misuse or security incidents and maintaining relevant operational records.
  • Fulfilling contractual obligations and complying with applicable legal requirements.
04

Customer Data and Our Role

Customers determine the information they submit to the ASPIA platform and the purposes for which they use it. Customers are responsible for ensuring that they have the necessary rights and authorisations to provide such information to ASPIA for processing.

Where ASPIA processes customer data to provide, maintain or support the platform, it does so in accordance with the applicable Customer Agreement, authorised customer instructions and applicable legal requirements. The respective responsibilities of ASPIA and the customer, including responsibilities relating to personal data protection, access management, security, retention and deletion, are governed by the applicable Customer Agreement and related contractual terms.

ASPIA implements appropriate technical and organisational safeguards to protect customer data, taking into account the applicable deployment model, security configuration and contractual commitments. Access to customer data by ASPIA personnel for implementation, maintenance or support is limited to authorised activities and is subject to customer authorisation and the applicable support arrangements.

For SaaS deployments, ASPIA manages the platform hosting environment in accordance with the applicable service and customer arrangements. For on-premises deployments, the customer generally manages the underlying hosting environment and infrastructure, while ASPIA's responsibilities are determined by the applicable deployment and support arrangements.

Customers should ensure that only personal data necessary for the intended purpose is submitted to the platform. Customer data is retained, exported, returned or deleted in accordance with the applicable Customer Agreement, relevant customer requirements and ASPIA's documented operational processes.

06

Cookies and Similar Technologies

Our website may use cookies or similar technologies to support website functionality, security and, where enabled, analytics.

Information about the specific cookies and tracking technologies used should be provided through the relevant website cookie notice or settings, where applicable. Cookie use and preferences depend on the technologies implemented on the website.

07

Disclosure of Information

ASPIA may disclose or make personal data available to:

  • Authorised personnel: Employees and authorised personnel who require access for legitimate business, operational or support purposes.
  • Service providers: Providers supporting hosting, communications, maintenance, security or other services, where used and subject to applicable contractual safeguards.
  • Customer-authorised integrations: Connected systems and third parties authorised by the customer.
  • Legal and regulatory authorities: Where disclosure is required by applicable law or a valid legal process.

ASPIA does not sell personal data as a business model. Information is disclosed only as appropriate for the relevant purpose, contractual arrangement or legal requirement.

08

Data Security

ASPIA uses technical and organisational safeguards intended to protect personal data against unauthorised access, loss, alteration or disclosure.

For SaaS deployments, access may be restricted through IP allowlisting and authentication controls, where configured. The controls applicable to each deployment depend on its architecture, configuration and contractual arrangements.

For on-premises deployments, security responsibilities are shared or allocated according to the deployment arrangement and applicable customer agreement.

Data is transmitted over HTTPS/TLS. Encryption at rest for databases and uploaded files depends on the applicable customer deployment, cloud configuration and storage arrangements.

No method of data transmission or storage can be guaranteed to be completely secure.

09

Data Retention and Deletion

ASPIA retains personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected or processed, provide and support its services, comply with applicable legal and regulatory requirements, maintain necessary business and security records, resolve disputes and enforce applicable agreements.

For customer data processed through the ASPIA platform, retention periods depend on the applicable Customer Agreement, customer retention requirements, legal or regulatory obligations and the relevant deployment configuration.

Following termination of a SaaS service, customers may request an export of their data before deletion, subject to the applicable Customer Agreement and operational arrangements. Customer data, associated hosting resources and relevant backups are handled in accordance with the applicable agreement and ASPIA's documented deletion procedures.

For on-premises deployments, the customer generally manages retention and deletion within its own infrastructure, subject to the agreed deployment and support arrangements.

Where personal data must be retained to meet legal obligations, resolve disputes or maintain required records, it may be retained for the applicable period. When continued retention is no longer necessary, the data will be deleted or otherwise disposed of in accordance with applicable requirements and the relevant operational processes.

10

Data Location and International Transfers

The location in which data is stored or accessed depends on the applicable deployment model, hosting arrangements, backup and disaster recovery configuration, service providers and authorised support access.

For SaaS deployments, ASPIA's platform may be hosted in different countries depending on the customer's hosting requirements and applicable service arrangements. The location of backup and disaster recovery (DR) data also depends on the applicable customer requirements, hosting configuration and service arrangements. For on-premises deployments, customer data is generally stored within the customer-managed infrastructure.

Any cross-border processing or transfer of personal data must be assessed and handled in accordance with applicable legal, regulatory and contractual requirements. Customer-specific data-location, backup and disaster recovery commitments, where applicable, are governed by the relevant service and customer agreement.

11

Privacy Rights and Requests

Subject to applicable law, individuals may have rights relating to their personal data, including the right to request access, correction, updating or erasure, withdraw consent where processing is based on consent, or exercise other applicable privacy rights.

Individuals may submit privacy-related requests or complaints using the contact details provided below. ASPIA will assess and handle requests in accordance with applicable law and its role in the relevant processing activity.

Where information is processed by ASPIA on behalf of a customer, the request may need to be directed to the customer, or ASPIA may assist the customer under the applicable agreement.

ASPIA may request information necessary to verify the identity of the requester and locate the relevant data.

12

Privacy Complaints

If you have a concern about how ASPIA has handled your personal data, you may raise a complaint using the contact details provided in the Contact Us section below.

ASPIA will acknowledge and assess the complaint in accordance with applicable law and its role in the relevant processing activity. Where information is processed by ASPIA on behalf of a customer, the complaint may need to be directed to that customer, or ASPIA may assist the customer under the applicable agreement.

Please include sufficient information to help us understand and respond to your request. Applicable legal response timelines and escalation procedures will be followed.

13

Third-Party Websites and Services

Our website or platform may contain links to third-party websites or integrate with third-party services. Those websites and services may have their own privacy policies and data-handling practices.

ASPIA is not responsible for the privacy practices of third-party websites that it does not operate. Users should review the relevant third-party privacy policies before providing information to those services.

14

Changes to This Privacy Policy

ASPIA may update this Privacy Policy from time to time to reflect changes in its services, data-processing practices, or applicable legal requirements.

Material changes will be communicated to affected customers through email. The updated Privacy Policy will also be published on the ASPIA website, along with the revised version number and effective or last-updated date.

Previous versions of this Privacy Policy will be maintained for recordkeeping and reference purposes.

Updates to this Privacy Policy do not, by themselves, amend or modify any existing Customer Agreement. Any changes to contractual obligations will be handled in accordance with the applicable Customer Agreement.

Get in Touch

Let's Talk Privacy

For privacy-related questions, requests or complaints, contact us through the channels below. We will review your request in accordance with applicable legal requirements and our internal procedures.

Grievance Redressal Mechanism

ASPIA Infotech is committed to addressing privacy-related queries, requests and complaints fairly and in accordance with applicable legal requirements and contractual obligations.

How to Raise a Grievance: Individuals may submit their concerns to privacy@aspiainfotech.com or grievance@aspiainfotech.com. Please describe the concern clearly and avoid sharing passwords, authentication tokens or unnecessary sensitive information.

Review and Resolution: Grievances will be reviewed and directed to the appropriate personnel for assessment and resolution. Additional information may be requested where necessary. Grievances will be handled in accordance with applicable requirements and ASPIA's internal procedures.