Data Receipt and Acceptance
When you entrust your storage device or media to Virus Solution Provider ("VSP") for data recovery services, a formal chain of custody is established from the moment of receipt at our laboratory facility located at Paschim Vihar, New Delhi. Upon arrival, each device is logged into our secure laboratory management system with a unique service identification number, and its physical condition is documented through detailed written notes and photographic evidence. You will be issued a media receipt acknowledging our custody of your device, which serves as the official record of the chain of custody. All devices are stored in a secure, access-controlled environment within our laboratory premises, with restricted access limited to authorized laboratory personnel only. We maintain detailed logs of all movements, access events, and handling activities performed on your device throughout the duration of the service engagement, ensuring full traceability and accountability at every stage of the data recovery process.
Data Access During Recovery
During the diagnostic assessment and active recovery phases, only designated and certified engineers with a legitimate need to access your device and data are granted permission to do so. All access is logged and monitored through our laboratory access control system, and each engineer is bound by strict confidentiality obligations enforceable under this policy and our separate confidentiality agreements. Our engineers access your data solely for the purpose of diagnosing the failure, performing recovery procedures, verifying recovered data integrity, and facilitating the secure transfer of recovered data to you. We employ the principle of least privilege, meaning that engineers access only the specific data and device components strictly necessary to perform their assigned tasks. Under no circumstances do our engineers browse, copy, disclose, or utilize your data for any purpose beyond the specific service engagement, except as may be required by applicable law or legal process. Any access to your data is conducted within our secure laboratory environment under continuous video surveillance.
Data Handling and Storage Protocols
All data recovered during the service engagement is handled in accordance with our standard operating procedures designed to maintain data integrity, confidentiality, and security throughout the recovery process. Recovered data is stored on secure, encrypted storage systems within our laboratory network, which is isolated from external internet access and protected by multiple layers of security controls including firewalls, intrusion detection systems, and role-based access controls. During the recovery process, your data may be temporarily stored on various secure media as necessary for the technical procedures being performed. All such media are subject to the same security protocols and access controls as our primary storage systems. We maintain comprehensive audit trails documenting all data access, transfer, and storage activities, and these logs are retained for a minimum period of 3 years for security and compliance purposes.
Post-Recovery Data Delivery
Upon successful completion of the data recovery process, recovered data is made available for your verification and approval through a secure channel determined at our discretion. Following your approval and receipt of full payment, the recovered data is transferred to you via a secure delivery method, which may include encrypted digital transfer through a secure portal, delivery on an encrypted storage medium provided by us, or physical delivery through our authorized courier partners. We will provide you with a detailed inventory of all recovered files and folders to facilitate your verification. It is your sole responsibility to review, verify, and create your own backup copies of all recovered data immediately upon receipt, as we do not maintain responsibility for any loss, corruption, or unavailability of data occurring after delivery has been effected to you.
Data Retention Period and Secure Erasure
Following the delivery of recovered data to you, VSP will retain a secure backup copy of your recovered data for a period of 30 calendar days from the date of delivery (the "Retention Period"). This retention is maintained solely for the purposes of quality assurance, dispute resolution, and ensuring that you have adequate opportunity to confirm the completeness and accuracy of the delivered data. Upon expiration of the Retention Period, or earlier upon your written request, the retained backup copy of your recovered data will be securely and permanently erased using industry-standard data destruction methods that render the data irrecoverable, including but not limited to secure overwriting using recognized algorithms (such as the Gutmann method or DoD 5220.22-M standard), degaussing of magnetic media where applicable, or physical destruction of storage media at our discretion. You may request earlier erasure of your data at any time by submitting a written request to us, and we will comply with such request within 5 business days of receipt. Please note that any unrecovered data remaining on your original device will not be accessible following the conclusion of the service engagement, and your original device will be returned to you in its then-current condition.
Physical Security and Facility Controls
Our laboratory facility at Paschim Vihar, New Delhi is equipped with comprehensive physical security measures designed to prevent unauthorized access to your device and data at all times. These measures include, but are not limited to: 24/7 video surveillance covering all laboratory areas, entry points, and storage zones; biometric and keycard access control systems restricting entry to authorized personnel only; intrusion detection and alarm systems; secure lockable storage cabinets and safes for devices awaiting processing or return; and a documented visitor management protocol requiring all visitors to sign in, wear visible identification, and be accompanied by authorized personnel at all times within the facility. Our cleanroom laboratory, where sensitive recovery procedures are conducted, maintains ISO Class 100 (ISO 5) certification and is subject to additional access restrictions and environmental controls. All personnel undergo background verification and are trained on our security protocols and confidentiality obligations prior to being granted access to laboratory areas.
Data Breach Response and Notification
VSP maintains a documented incident response plan to promptly detect, respond to, contain, and mitigate any actual or suspected data breach, security incident, or unauthorized access to customer data within our custody. In the event of a data breach that is reasonably likely to result in a risk to your rights, freedoms, or interests, we will notify you without undue delay and within the timeframes required by applicable law, providing you with a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures we have taken or propose to take to address the breach and mitigate its potential adverse effects. We will also cooperate fully with relevant regulatory authorities and law enforcement agencies as required by applicable law. Our incident response plan is reviewed and tested periodically to ensure its effectiveness, and all personnel are trained on their roles and responsibilities in the event of a security incident.