Skip to content
Pinnacle ShieldBook a consultation

Legal

Privacy Policy

Draft: Draft prepared for legal review — not yet finalized by a qualified professional. Do not rely on this as your final published policy.

1. Overview

This Privacy Policy explains how Pinnacle Shield ("we", "us", "our") collects, uses, discloses, and protects personal data obtained through this website (the "Site"). It is drafted with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act") and its rules as notified from time to time, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), to the extent applicable.

By using this Site, you agree to the collection and use of information as described here. If you do not agree, please do not submit personal data through this Site.

2. Who we are

Pinnacle Shield is currently operated as an unincorporated business; a formal legal entity (expected to be registered as a Limited Liability Partnership) is being established. Until incorporation is complete, references in this policy to "Pinnacle Shield" mean the individuals and team currently operating this Site and delivering services under this name. This section will be updated with the registered entity name, registration number, and registered office address upon incorporation.

For the purposes of the DPDP Act, we act as the "Data Fiduciary" in respect of personal data collected through this Site.

3. Definitions

  • "Data Principal" means the individual to whom the personal data relates (i.e., you).
  • "Data Fiduciary" means the entity that determines the purpose and means of processing personal data (i.e., us).
  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Processing" means any operation performed on personal data, including collection, storage, use, sharing, and deletion.

4. Personal data we collect

We collect personal data that you voluntarily provide through forms on this Site (contact, consultation booking, and assessment requests), which may include:

  • Name
  • Work email address
  • Company name
  • Job role or title
  • The subject/topic of your inquiry and any message you provide
  • Timeline or urgency you indicate
  • Technical data collected automatically, such as IP address, browser type, and pages visited, via privacy-preserving, cookieless analytics (see our Cookie Policy)

5. How we use your personal data

We use the personal data we collect to:

  • Respond to your inquiry and correspond with you
  • Assess whether and how we can assist with the services you have inquired about
  • Schedule and conduct consultations you request
  • Maintain records of our business communications
  • Improve this Site and understand aggregate usage patterns
  • Comply with applicable legal obligations

6. Legal basis and consent

We process your personal data on the basis of your consent, given by voluntarily submitting a form on this Site (each form includes an explicit consent checkbox), and, where applicable, for the performance of steps requested by you prior to entering into a service arrangement.

You may withdraw your consent at any time by contacting us at the address below. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may limit our ability to respond to an inquiry already in progress.

7. Cookies and similar technologies

This Site is designed to operate without non-essential cookies. Analytics, where used, are cookieless and privacy-preserving by default. See our Cookie Policy for full details and for how this will be updated if that changes.

8. Sharing and disclosure of personal data

We do not sell personal data. We may share personal data with:

  • Service providers who process data on our behalf (for example, customer relationship management/CRM tooling, email delivery providers, and website hosting infrastructure), strictly to the extent needed to provide those services to us
  • Professional advisors (such as legal or accounting advisors), where necessary
  • Government authorities or regulators, where required by applicable law, including under the IT Act, 2000 or directions issued by the Indian Computer Emergency Response Team ('CERT-In')
  • A successor entity in connection with a merger, acquisition, or reorganization of our business, subject to that entity being bound by materially equivalent privacy commitments

9. Cross-border transfer of personal data

Some of our service providers (such as hosting or email infrastructure) may process personal data outside India. Where the DPDP Act restricts transfer of personal data to certain jurisdictions notified by the Central Government, we will not transfer personal data to those jurisdictions. Otherwise, we take reasonable steps to ensure that any recipient of personal data outside India provides a standard of protection consistent with this policy.

10. Data retention

We retain personal data only for as long as reasonably necessary to fulfil the purposes described in this policy, typically no longer than 24 months from your last interaction with us, unless a longer retention period is required to comply with a legal obligation, resolve a dispute, or enforce our agreements. Data submitted through forms that does not lead to further engagement is periodically reviewed and deleted.

11. Data security

We implement reasonable security practices and procedures, consistent with the SPDI Rules, to protect personal data against unauthorized access, disclosure, alteration, or destruction. These include encrypted transport (HTTPS/TLS) for all data submitted through this Site, access controls limiting who within our team can view submitted data, and periodic review of our security posture (as a security consultancy, we hold ourselves to this standard deliberately). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Your rights as a Data Principal

Subject to the DPDP Act and its rules, you have the right to:

  • Obtain a summary of the personal data we hold about you and the processing activities undertaken
  • Request correction, completion, or updating of your personal data
  • Request erasure of your personal data that is no longer necessary for the purpose it was collected, unless retention is required by law
  • Withdraw consent at any time
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Register a grievance regarding the processing of your personal data

13. Grievance redressal

You may reach us at hello@pinnashield.com. Until a named Grievance Officer is formally appointed, inquiries sent to this address are treated as grievance-redressal requests and handled by our team directly.

14. Children's data

This Site is intended for business use by professionals and is not directed at children. We do not knowingly collect personal data from individuals under the age of 18. If you believe a child has provided us personal data, please contact us so we can delete it.

15. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the notice at the top of this page. Continued use of the Site after changes take effect constitutes acceptance of the revised policy.

16. Governing law and jurisdiction

This policy is governed by the laws of India. Courts at a location to be specified upon incorporation of our registered entity shall have exclusive jurisdiction over any disputes arising from this policy.

17. Contact us

For any questions about this Privacy Policy or to exercise your rights, contact us at hello@pinnashield.com.