Introduction and Scope
Virus Solution Provider India ("VSP India", "we", "us", or "our"), a subsidiary brand of Virus Solution Provider founded and operated by Sundeep Maan, is a registered data recovery and cybersecurity service provider catering specifically to customers across India. Our principal place of business is located at GH 6, 451, near St Mark Girls School, Meera Bagh, Paschim Vihar, New Delhi, Delhi 110087, India. This Privacy Policy ("Policy") governs the collection, use, storage, processing, disclosure, and protection of personal information and data of users, visitors, and customers interacting with our website located at https://virusolutionprovider.in ("Website") or availing any of our data recovery, ransomware decryption, and related services ("Services"). By accessing our Website or using our Services, you expressly acknowledge that you have read, understood, and hereby consent to the terms and data practices described in this Policy. If you do not agree with any part of this Policy, you must immediately discontinue the use of our Website and Services.
Information We Collect
We collect information that you voluntarily provide to us, as well as information that is automatically gathered when you interact with our Website and Services. The categories of information we collect include, but are not limited to:
Personal Identification Information: When you fill out our contact forms, request a free pickup, initiate a service request, or communicate with us via phone, email, WhatsApp, or any digital channel, we may collect your full name, email address, telephone or mobile number, postal address (including city, state, and pincode), company name, job title, and any other identifying information you choose to share with us.
Device and Service-Related Information: When you engage our data recovery or cybersecurity services, we may collect detailed information about your device(s) including make, model, serial number, operating system, storage capacity, file system type, error messages, failure symptoms, pickup address details, and any other technical data necessary to diagnose, assess, and perform the requested service.
Technical Usage Data: When you visit our Website, we and our third-party service providers may automatically collect certain technical information including your Internet Protocol (IP) address, browser type and version, operating system, device type, referring and exit URLs, pages viewed, time and date of access, clickstream data, and other similar diagnostic and usage data collected using cookies, log files, web beacons, pixel tags, and similar tracking technologies.
Legal Basis for Processing
We process your personal information based on one or more of the following legal grounds, as applicable under the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023 (DPDPA) of India:
Consent: Where you have freely given specific, informed, and unambiguous consent for the processing of your personal data for one or more specific purposes.
Contractual Necessity: Where processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract, including but not limited to providing data recovery services, arranging free device pickup, processing payments, and delivering recovered data.
Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject, including but not limited to retaining records as required by applicable Indian laws, responding to lawful requests from Indian government or law enforcement authorities, and complying with court orders or legal processes.
Legitimate Interests: Where processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, including improving and securing our Services, conducting business analysis, preventing fraud and abuse, and enforcing our legal rights.
How We Use Your Information
We use the information we collect for the following business and operational purposes:
Service Delivery and Fulfillment: To respond to your inquiries, provide quotations, perform diagnostic assessments, arrange free device pickup across India, execute data recovery and cybersecurity services, process payments, communicate service status updates, and deliver recovered data through secure channels.
Business Operations and Improvement: To operate, maintain, analyze, and improve our Website and Services, develop new offerings, conduct research and analytics, monitor usage trends, personalize user experience, and optimize our service delivery processes across all cities we serve including Delhi NCR, Mumbai, Bangalore, Chennai, Hyderabad, Kolkata, Noida, Indore, Assam, and other locations.
Communication: To communicate with you regarding your service requests, respond to your comments, questions, and complaints, send administrative information such as confirmations, invoices, technical notices, updates, and security alerts, and, where permitted by applicable law, send marketing and promotional communications about our Services, special offers, and industry updates. You may opt out of marketing communications at any time.
Legal and Compliance: To comply with applicable legal and regulatory obligations under Indian law, establish, exercise, or defend legal claims, detect, prevent, and respond to fraud, abuse, security incidents, and technical issues, and enforce our Terms of Service and other legal agreements.
Data Sharing and Disclosure
We do not sell, trade, rent, or lease your personal information to third parties for their marketing purposes. We may share your information with the following categories of recipients:
Service Providers and Business Partners: We may share your personal information with trusted third-party service providers and business partners who assist us in operating our business, delivering our Services, processing payments, managing communications, hosting our Website, conducting data analytics, providing technical infrastructure, and performing other business functions. These service providers are contractually bound to maintain the confidentiality and security of your personal information.
Legal and Regulatory Authorities: We may disclose your personal information if required to do so by Indian law, regulation, legal process, subpoena, court order, or governmental or regulatory request, including but not limited to responding to requests from Indian law enforcement authorities, courts, or regulatory bodies such as CERT-In where applicable.
Professional Advisors: We may disclose your personal information to our legal counsel, auditors, accountants, insurers, and other professional advisors where necessary for the purpose of obtaining professional advice, managing risks, or establishing, exercising, or defending legal rights.
With Your Consent: We may share your personal information for any other purpose with your explicit consent obtained prior to such sharing.
Data Retention and Storage
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected. Customer data, including device details and service records, is retained for the duration of the service engagement and for a period of up to 3 years thereafter for warranty, quality assurance, and legal compliance purposes. Recovered data is retained for a maximum of 30 days following delivery to the customer, after which it is securely and permanently erased. Contact information and communications records are retained for up to 3 years from the date of your last interaction with us. Log files, analytics data, and usage information are retained for a period of up to 26 months from the date of collection. Records maintained for legal, regulatory, or compliance purposes may be retained for longer periods as required or permitted by applicable Indian law, including up to 8 years as prescribed under Indian company and tax laws.
Data Security Measures
We implement and maintain reasonable and appropriate technical, organizational, administrative, and physical security measures designed to protect your personal information against unauthorized access, alteration, disclosure, destruction, loss, or misuse. Our security measures include SSL/TLS encryption protocols to protect data transmitted between your browser and our servers, encryption at rest for stored data where appropriate, role-based access controls restricting access to authorized personnel only, 24/7 video surveillance and access control systems at our New Delhi facility, and a documented incident response plan to promptly address any actual or suspected data breaches. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by applicable law. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
Digital Personal Data Protection Act, 2023 (DPDPA) Compliance
We are committed to complying with the Digital Personal Data Protection Act, 2023 (DPDPA) of India, which governs the processing of digital personal data within India. In accordance with the DPDPA, we acknowledge and affirm the following:
Data Fiduciary Obligations: We act as a Data Fiduciary as defined under Section 2(i) of the DPDPA and are responsible for determining the purpose and means of processing your personal data. We have implemented appropriate technical and organizational measures to ensure compliance with our obligations under the DPDPA, including but not limited to implementing reasonable security safeguards to prevent personal data breaches, ensuring the completeness, accuracy, and consistency of personal data, and establishing effective grievance redressal mechanisms.
Notice and Consent: We provide this Privacy Policy as a comprehensive notice to you, the Data Principal, regarding the personal data we collect, the purposes for which we process such data, and your rights in relation thereto, in compliance with Section 5 of the DPDPA. Your consent, where required, is obtained in a clear, specific, and informed manner, and you have the right to withdraw such consent at any time in accordance with Section 9 of the DPDPA.
Data Principal Rights: We respect and facilitate the exercise of all rights granted to Data Principals under Chapter III of the DPDPA, including the right to access information about your personal data processed by us, the right to correction and erasure of your personal data, the right to grievance redressal, the right to nominate a representative to exercise your rights in the event of your death or incapacity, and the right to withdraw consent where processing is based on consent.
Data Breach Notification: In compliance with Section 8(6) of the DPDPA, we have implemented protocols to promptly notify the Data Protection Board of India and affected Data Principals in the event of any personal data breach that is likely to cause harm to you.
Grievance Redressal: We have appointed a Grievance Officer as required under Section 11 of the DPDPA. You may contact our Grievance Officer in relation to any grievance relating to the processing of your personal data. We will acknowledge and address your grievance within the time period prescribed under the DPDPA and applicable rules.
Cross-Border Data Transfer: Where we transfer your personal data outside India, we ensure that such transfers are made in compliance with the restrictions and conditions set forth under Section 16 of the DPDPA and any rules or guidelines issued thereunder by the central government.
Your Rights and Choices
Subject to applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDPA), you may have the following rights with respect to your personal information: the right to access and obtain confirmation of whether we are processing your personal information; the right to rectify any inaccurate or incomplete personal information; the right to request erasure of your personal information where it is no longer necessary for the purposes for which it was collected or processed; the right to restrict processing of your personal information under certain circumstances; the right to data portability in a structured, commonly used, and machine-readable format; the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal; and the right to lodge a complaint with the relevant data protection authority in India. To exercise any of these rights, please submit a written request to us. We will respond to your request within the time period prescribed by applicable law.