Privacy Policy

Effective Date: 14th November 2025

Oxenor Infosec ("Oxenor," "we," "our," or "us") is committed to maintaining the confidentiality, integrity, and availability of personal data and client information in accordance with internationally recognized security and privacy frameworks. As a cybersecurity and governance organization, we design our data protection practices to align with ISO information security principles, the EU General Data Protection Regulation (GDPR), SOC 2 Trust Services Criteria, and the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act").

This Privacy Policy explains how we collect, process, use, disclose, store, and protect personal data when individuals interact with our website, services, managed security engagements, consulting services, compliance programs, and software platforms including Uplift GRC.

Data Collection and Scope

Oxenor Infosec collects personal data that is necessary, proportionate, and relevant to defined business purposes. This may include professional contact information such as name, business email address, phone number, job title, organization name, and contractual details. When individuals visit our website, certain technical data such as IP address, browser type, device information, and interaction logs may be collected for security monitoring and service improvement purposes.

In the course of delivering cybersecurity services, Oxenor may process client-controlled data including risk registers, audit documentation, security logs, infrastructure metadata, compliance evidence, and governance records. In such cases, Oxenor acts either as a Data Processor or Service Organization, processing data strictly under documented instructions and contractual obligations.

We do not sell personal data.

Legal Basis for Processing (GDPR & DPDP Alignment)

Where applicable under GDPR, Oxenor processes personal data based on lawful grounds including performance of a contract, legitimate interests, legal obligations, or explicit consent. For data subjects located in the European Economic Area (EEA), we ensure processing activities meet Article 6 GDPR requirements.

Under India's DPDP Act, Oxenor processes personal data for lawful purposes with notice, consent where required, and adherence to principles of purpose limitation, data minimization, and storage limitation. Individuals retain the right to withdraw consent subject to legal or contractual restrictions.

Information Security and ISO Alignment

Oxenor maintains information security practices aligned with ISO/IEC 27001 principles and related ISO standards governing information security management systems (ISMS). Our security controls are designed to ensure confidentiality of personal and client data, integrity of systems and processing activities, availability of services and information, continuous risk assessment and mitigation, access control based on least privilege principles, secure data transmission using encryption protocols, and monitoring, logging, and incident response procedures. Security controls are periodically reviewed, assessed, and improved as part of our internal governance and risk management processes.

SOC 2 Trust Services Criteria Commitment

Oxenor's privacy and security practices are structured in alignment with the SOC 2 Trust Services Criteria, particularly in the areas of Security, Availability, Confidentiality, and Privacy. Our controls include logical access restrictions, secure configuration management, risk assessment procedures, vendor management controls, and documented incident response mechanisms.

Where Oxenor provides services that fall within SOC 2 audit scope, controls are implemented to ensure personal data is collected, used, retained, disclosed, and disposed of in accordance with defined commitments and applicable regulations.

Purpose of Processing

Personal data is processed for legitimate business purposes including delivering cybersecurity services, conducting compliance and risk assessments, managing contracts, providing technical support, maintaining service integrity, and fulfilling regulatory obligations. Technical information collected through the website is used to enhance security posture, detect anomalies, and improve user experience.

Processing activities are limited to the purposes for which data was collected, and data is not repurposed in a manner incompatible with those objectives.

Data Sharing and Sub-Processors

Oxenor may engage trusted service providers, cloud hosting partners, and professional advisors who support our service delivery. Such entities are contractually bound to maintain appropriate technical and organizational safeguards and process personal data solely for authorized purposes.

Where cross-border transfers occur, appropriate safeguards such as contractual protections or equivalent lawful mechanisms are implemented to ensure adequate levels of protection consistent with GDPR and DPDP requirements.

Data Retention

Personal data is retained only for as long as necessary to fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, or support legitimate business operations. Retention schedules are defined internally and aligned with compliance obligations. Client-controlled data retention is governed by contractual agreements and applicable regulatory mandates.

Data Subject Rights (GDPR & DPDP)

Subject to applicable law, individuals may have the right to access, correct, update, or request deletion of their personal data. Data subjects may also have the right to restrict processing, object to certain processing activities, request data portability, or withdraw previously provided consent. Requests to exercise these rights will be assessed and fulfilled in accordance with applicable legal obligations and identity verification procedures.

Incident Management and Breach Notification

Oxenor maintains a documented incident response framework designed to detect, assess, contain, and remediate security incidents. Where required under GDPR, DPDP, or other applicable regulations, affected parties and regulatory authorities will be notified within legally prescribed timelines.

Children's Data

Oxenor's services are intended for business and professional use. We do not knowingly collect personal data from individuals under the age of 18.

Policy Updates

This Privacy Policy may be updated periodically to reflect changes in regulatory requirements, operational practices, or technological developments. The "Last Updated" date will reflect the most recent revision.

Contact Information

For questions regarding this Privacy Policy, data protection matters, or to exercise your data protection rights, please contact Oxenor Infosec at info@oxenorinfosec.com or visit www.oxenorinfosec.com.

Last updated: 14th November 2025 — Subject to periodic review and updates.