How we collect, use, protect, and share personal data — and the rights you have over it.
This Privacy Policy explains how ThetaSecure Technologies Private Limited and its affiliates ("ThetaSecure", "we", "us", or "our") collect, use, disclose, retain, and protect personal data when you visit thetasecure.com, use our products and services (including TS Connect, TS Identity, and TS Filter), contact us, or otherwise interact with us (collectively, the "Services"). It also describes the choices and rights available to you. We are committed to handling personal data responsibly and in accordance with applicable data protection laws, including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
We collect personal data in the following ways:
Note on product data: operational logs and security telemetry generated by our products (such as authentication events, connection metadata, and device posture) are stored and processed entirely within your on-premises deployment. ThetaSecure does not receive or have access to that data.
We do not seek to collect special categories of data (such as health, biometric, or precise geolocation data) through our website. Please do not send us sensitive personal data unless specifically requested.
Where we act as a controller, we use personal data to:
Where the GDPR or similar laws apply, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services and fulfilling a contract with you | Performance of a contract |
| Security, fraud prevention, product improvement, and B2B marketing | Legitimate interests (balanced against your rights) |
| Optional cookies, certain marketing, and other elective processing | Consent (which you may withdraw at any time) |
| Tax, accounting, and other regulatory requirements | Legal obligation |
We do not sell your personal data. We share personal data only as described below:
ThetaSecure operates globally and is headquartered in India. Personal data may be processed in, or transferred to, countries other than your own, including India and countries where our service providers operate. Where we transfer personal data from the EEA, the UK, or other regions with transfer restrictions, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms. You may request a copy of the relevant safeguards using the contact details below.
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to provide the Services, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the type of data and the context. When personal data is no longer required, we delete or anonymise it. Personal data inside an enterprise's on-premises product deployment is retained and deleted by that enterprise according to its own configuration and policies; ThetaSecure has no access to, or control over, that data.
Security is at the core of what we do. We implement administrative, technical, and organisational measures designed to protect personal data, including encryption in transit and at rest, least-privilege access controls, network segmentation, logging and monitoring, and regular security reviews. No method of transmission or storage is completely secure; while we work hard to protect your data, we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
Subject to applicable law and verification of your identity, you may have the right to:
To exercise any of these rights, contact us at privacy@thetasecure.com. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising your privacy rights. If your request concerns data held inside an enterprise's self-hosted ThetaSecure deployment, that enterprise is the controller and operator of that data — please direct your request to your organisation, as ThetaSecure has no access to it.
California residents have the right to know what personal information we collect, use, and disclose; to request deletion or correction; and to opt out of "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising. You may exercise these rights, or designate an authorised agent, by contacting us at the address below.
If you are a Data Principal in India, you have the right to access, correction, and erasure of your personal data, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity. You can exercise these rights or raise a grievance with our Grievance Officer at privacy@thetasecure.com.
We use cookies and similar technologies to operate our website, remember your preferences, measure performance, and understand usage. Strictly necessary cookies are required for the site to function. Where required by law, we ask for your consent before setting non-essential cookies (such as analytics). You can control cookies through your browser settings and, where available, our cookie banner. Disabling some cookies may affect site functionality.
Our Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children under the age required by applicable law (e.g., 16 in parts of the EEA, and as defined under the DPDP Act in India). If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
Our website and Services may contain links to third-party websites and services that we do not control. This Policy does not apply to those third parties, and we encourage you to review their privacy notices.
Depending on where you live, you may have additional rights or we may provide additional disclosures under local law (for example, the EEA/UK GDPR, Brazil's LGPD, Canada's PIPEDA, or other applicable regimes). Where local law grants you greater rights than described above, those rights apply.
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (such as by email or a notice on our website). Your continued use of the Services after the changes take effect constitutes acceptance of the updated Policy.
If you have any questions, requests, or complaints about this Policy or our handling of personal data, please contact us:
ThetaSecure Technologies Private Limited
Attn: Privacy / Grievance Officer
No 17, 7th Main Road, II Stage, Indiranagar
Bangalore, Karnataka, India - 560038
Email: privacy@thetasecure.com