CtrlS DataPrivacy
This privacy notice for all PII/ Data Principals (Customers, Suppliers, Vendors, Employees, Visitors, Contractors and Subcontractors or other third party) and other (“Privacy notice”) applies to the CtrlS Data Centers Limited td (hereinafter referred to as “CtrlS”). The CtrlS company for the purpose of providing a service, CtrlS is responsible for processing your personal Information and controls its use in accordance with this privacy notice. We at CtrlS Datacenters Ltd. including its subsidiaries and affiliates (collectively referred to as “CtrlS or “our” or “we”) are strongly committed at to honouring and safeguarding your privacy. CtrlS, protecting your personal information is a top priority. This privacy notice describes our privacy practices regarding collecting, storing, processing and use of our personal data when you availing / providing a service to/for the company or visit our premises / Website.
CtrlS and its subsidiaries are responsible for your personal Information. In accordance with applicable information protection laws, the person responsible for processing your personal Information is the CtrlS subsidiary which communicates with you. Furthermore, other CtrlS subsidiaries may receive and process your information, either as the information controller or the information processor. Accordingly, this privacy notice applies equally to them. In your case, CtrlS or the respective company affiliated with CtrlS, as the “responsible party” applicable laws at the headquarter or Information Center of the country in which of the respective subsidiary, for what and how your personal information will be used in accordance with this privacy notice.
We collect and use the personal information that we receive from you within the scope or an existing business relationship with you or your company (hereinafter: “you”). We may also process personal information that we receive from you either as a result of your contact request, a specific pre-contractual inquiry or a registration for a specific event via our websites, by email or telephone or at a trade fair or event. In addition, to the extent necessary for the purposes stated in this privacy notice, we process personal information that we can obtain from publicly available sources or that is lawfully transmitted by other third parties in pursuant to Business relations. We process the following categories of your personal information to the extent required for the purposes of processing in accordance with this privacy notice:
- Identifying information and contact details that you provide us with, such as first name, last name, profession / position / title, business email address, postal address, telephone, cell phone and fax numbers, gender, date of birth, vehicle registration number, visit date time and number of a valid identification document as per law.
- Additional information that you provide us with during or in connection with your visit, such as registration details for facilities and sites, visits to an employee, purpose of the visit, records of your visit or information relating to the fulfilment of our contractual obligations and precontractual measures; To a certain extent, this information may also include your interests in our products, marketing preferences and registration information provided at training sessions, events or trade fairs, etc.
- Image and video recordings on which you are depicted (“recordings”)and which are produced by our video surveillance systems (CCTV) or by photographers or CtrlS employees working on our behalf at events organized by us.
- Children Information– The Data Fiduciary / Controller Shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed – sec 9(1) of DPDP Act 2023.
- Electronic identification information and information collected from communications systems, IT applications and web browsers (provided that the information you have has access to or is affected by such systems or applications and in accordance with applicable laws),such as use of information technology (system access, IT and Internet use), device identification (mobile device ID, PC ID), registration and login information, IP address, access information and log files, analysis ID, time and URL, search queries, website registration records and cookie information, sound recordings (e.g. voice message, meeting recordings).
If you wish to obtain information about a specific information processing activity, this can be requested from DPO at dpo@ctrls.in.
We process your personal information primarily to carry out and fulfil our business and contractual relations with you and to ensure security in our offices and premises of the people and items, security of confidential Information located in the company’s premises or accessible from the company’s premises. This is done to prevent loss, frauds, health safety thefts, injuries, terrorism, and other events of such kind in the company’s premises. In the context of this business relationship with you and your visit to our offices and premises, we must process your personal information, which we require in order to fulfil the associated contractual and legal obligations or which we are legally obliged to collect and process (e.g. health and safety laws, statutory insurance requirements). In particular, we process the personal information listed above for the following purposes:
- Visitor management which includes Approval, Visitor Registration and Gate pass processing and access creation if required.
- Health and safety management, including medical emergencies.
- Recording by video surveillance system (CCTV) for the purpose of public and employee safety, theft building security and the prevention and detection of crime.
- Monitoring and auditing of compliance with CtrlS and CtrlS’s corporate guidelines, contractual obligations and legal requirements.
- Conducting audits, evaluations and regulatory checks to ensure compliance with regulatory obligations.
We only collect the personal information from you that we require for the purposes described above. This means that you can no longer be directly or indirectly identified as an individual using this information.
In the case of processing operations in connection with your visit to CtrlS (as described above), without certain personal information, CtrlS may not be able to adequately ensure your security and the security of other persons in our offices and premises, monitor the security of the premises and its facilities, or fulfil the related legal obligations or the purposes described above in general. Although we cannot oblige you to provide us with your personal information, please be aware that your refusal could have consequences that could negatively affect your visit to our offices and premises or our business relationship. You will not be permitted, for example, to enter certain or any CtrlS facility or location for security reasons, nor will we be able to take requested precontractual or contractual measures to conclude or fulfil a contract with you.
We process your personal information for the purposes described above (WHY DO WE USE YOUR PERSONAL INFORMATION?) in accordance with the provisions of the the Information Technology Act 2000, IT Rules (2011) and DPDP Act 2023 India, especially in accordance with the following applicable legal bases:
- Where required, we process your personal information within the scope of your specific visit to our offices and premises, or your stay on our premises, as well as the existing business relationship with you or your company,in order to safeguard legitimate interests(ours and that of third parties).
CtrlS has implemented technical, physical, contractual, and organizational safeguards with a view to protecting the security of personal data from loss, damage, or unauthorized use, disclosure, alteration, or access, having regard to the nature of the data, and the risks to which they are exposed by virtue of human action or the physical or natural environment.
The disclosure may be subject to disclosure to the governments, courts or law enforcement or regulatory agencies of such other country, pursuant to the laws of the India.
We will only keep your personal data for as long as is reasonably necessary to fulfill the purposes for which it was collected, taking into consideration our need to respond to your queries or resolve problems, any other purpose outlined above or to comply with legal requirements under applicable law(s). This means that we may retain your personal data for a reasonable period after, for example, the end of the contract with the client you represent, or after your query has been addressed. After this period, your personal data will be deleted from all our system.
Our Privacy Notice may be updated from time to time. Any updates will appear on this www.CtrlS.com.
You can contact us by writing to: Data Protection Officer, If you have any questions about our privacy notice please contact the Data Protection Officer on data-protection email dpo@ctrls.in
CtrlS Data Centre Limited (hereinafter referred to as “the CtrlS us”, or “our”) is a premier provider of data center infrastructure services, including Colocation (Colo), Colocation Managed Services, and Cloud Managed Services. In the course of delivering these services, CtrlS processes significant volumes of personal data belonging to our customer, their end-users, our employees, vendors, and other stakeholders.
Ensuring full compliance with applicable data protection laws — including the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the EU General Data Protection Regulation 2016/679 (EU GDPR), and all relevant sector-specific regulations;
This Policy applies to all business units, operational teams, third-party processors, and sub-processors engaged by the organisation.
| Term | Definition |
| Personal Data / Personal Information | Any information that relates to an identified or identifiable natural person (Data Subject). Includes name, identification number, location data, online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity of that person. (Ref: EU GDPR Art. 4(1); DPDP Act Sec. 2(t)) |
| Digital Personal Data | Personal data in digital form. Under the DPDP Act, it includes personal data originally in non-digital form that is subsequently digitised. (Ref: DPDP Act Sec. 2(n)) |
| Sensitive Personal Data / Special Categories | Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life, or sexual orientation. Financial data and passwords are also treated as sensitive. (Ref: EU GDPR Art. 9; DPDP Act Sec. 2(t)) |
| Data Subject / Data Principal | The identified or identifiable natural person to whom the personal data relates. Under DPDP Act, referred to as ‘Data Principal’. (Ref: EU GDPR Art. 4(1); DPDP Act Sec. 2(j)) |
| Data Fiduciary | An entity that, alone or in conjunction with others, determines the purpose and means of processing of digital personal data. Equivalent to ‘Data Controller’ under EU GDPR. (Ref: DPDP Act Sec. 2(i)) |
| Data Controller | A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. (Ref: EU GDPR Art. 4(7)) |
| Data Processor | A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller / Data Fiduciary. (Ref: EU GDPR Art. 4(8); DPDP Act Sec. 2(k)) |
| Processing | Any operation or set of operations performed on personal data, whether or not by automated means — including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction. (Ref: EU GDPR Art. 4(2); DPDP Act Sec. 2(x)) |
| Consent | Any freely given, specific, informed, and unambiguous indication of the Data Subject’s agreement to the processing of their personal data. Under DPDP Act, consent must be free, informed, specific, unconditional, and unambiguous. (Ref: EU GDPR Art. 4(11); DPDP Act Sec. 6) |
| Legitimate Interests | A lawful basis for processing under EU GDPR where the controller has a legitimate interest and it is not overridden by the Data Subject’s rights and interests. Not applicable as a standalone basis under DPDP Act. (Ref: EU GDPR Art. 6(1)(f)) |
| Personal Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. (Ref: EU GDPR Art. 4(12); DPDP Act Sec. 8(6)) |
| Privacy Information Management System (PIMS) | An extension to the Information Security Management System (ISMS) that provides a framework for managing PII processing activities and demonstrating compliance with privacy regulations. (Ref: ISO/IEC 27701:2019) |
| PII Controller | An organisation that determines the purposes and means for processing Personally Identifiable Information (PII). Analogous to Data Controller / Data Fiduciary. (Ref: ISO/IEC 27701 Sec. 3.4) |
| PII Processor | An organisation that processes PII on behalf of and in accordance with the instructions of a PII Controller. (Ref: ISO/IEC 27701 Sec. 3.5) |
| Data Protection Officer (DPO) | A designated individual responsible for advising on, monitoring, and ensuring compliance with data protection obligations. Mandatory under EU GDPR Art. 37 and advisable under DPDP Act. Under DPDP Act, referred to as the ‘Consent Manager’ or responsible officer. |
| Data Processing Agreement (DPA) | A legally binding contract between a Data Controller and Data Processor setting out the scope, nature, purpose, and obligations of data processing. (Ref: EU GDPR Art. 28; DPDP Act Sec. 8) |
| Data Protection Impact Assessment (DPIA) | A process for identifying and minimising privacy risks in new or changed processing activities. (Ref: EU GDPR Art. 35; ISO/IEC 27701 Sec. 6.4) |
| Cross-Border Data Transfer | Transfer of personal data to a country or territory outside the jurisdiction of origin. (Ref: EU GDPR Chapter V; DPDP Act Sec. 16) |
| Pseudonymisation | The processing of personal data in such a manner that it can no longer be attributed to a specific data subject without the use of additional information. (Ref: EU GDPR Art. 4(5)) |
| Anonymisation | The irreversible alteration of personal data so that the data subject cannot be identified, directly or indirectly. Anonymised data falls outside the scope of data protection laws. |
| Record of Processing Activities (ROPA) | A register maintained by a Data Controller / Processor documenting all processing activities involving personal data. (Ref: EU GDPR Art. 30; ISO/IEC 27701 Sec. 6.12) |
| Sub-processor | A third party engaged by a Data Processor to carry out specific processing activities on behalf of the Data Controller. (Ref: EU GDPR Art. 28(4)) |
| Colocation (Colo) | A data centre service where customers rent physical space (racks, cages, or suites) to house their own servers and networking equipment. |
| Colocation Managed Services | An extension of colocation where CtrlS also provides management, monitoring, and operational support for customer infrastructure. |
| Cloud Managed Services | Services where CtrlS manages cloud environments (public, private, or hybrid) on behalf of customers, including provisioning, operations, security, and optimisation. |
| Significant Data Fiduciary (SDF) | A Data Fiduciary notified by the Indian Government as processing large volumes of sensitive personal data or data with significant impact on sovereignty, security, or public order. SDFs have additional obligations under DPDP Act Sec. 10. |
| Data Protection Board (DPB) | The adjudicatory body established under the DPDP Act (India) to address complaints, investigate breaches, and impose penalties. (Ref: DPDP Act Sec. 18) |
- All personal data processed by CtrlS as a Data Fiduciary (under DPDP Act), Data Controller (under EU GDPR), or PII Controller (under ISO/IEC 27701);
- All personal data processed on behalf of customers as a Data Processor (under EU GDPR) or Consent Manager / sub-processor;
- All employees, contractual staff, temporary workers, interns, and third-party service providers;
- All geographies in which CtrlS operates, hosts infrastructure, or provides services;
- All digital and physical systems that store, process, or transmit personal data.
Out of Scope
This Policy does not govern personal data processed entirely by customers on their own infrastructure colocated within the CtrlS facility, where the CtrlS has no access to or involvement with such data. A separate Data Processing Agreement (DPA) governs such arrangements.
The objective of this policy is to make sure that the provisioning of a service is in accordance with the business, data security and Privacy requirements with reference to the applicable laws and regulations.
- Protect CtrlS data by safeguarding its confidentiality, integrity, availability, and privacy.
- Establish effective governance arrangements, including accountability and responsibility for data protection and privacy within CtrlS.
- Maintain an appropriate level of awareness, knowledge, and skill among customers, vendors, suppliers, employees, and other stakeholders to minimize the occurrence and severity of data protection and privacy incidents.
- Ensure CtrlS is able to continue and/or rapidly recover its business operations in the event of a detrimental data breach or privacy incident.
- CtrlS is committed to protecting data and privacy. This policy addresses security, data protection, and privacy requirements throughout the design and lifecycle stages, including the collection, storage, maintenance, disclosure, securing, and disposal of personally identifiable information as per the policy.
- CtrlS proactively addresses data principals’ expectations concerning their privacy and security in order to create and maintain trust and confidence in CtrlS and the services it provides.
- Ensure compliance with relevant data protection laws, thereby minimizing legal liability, regulatory risk, and brand and reputational exposure.
- A data principal’s data is collected only after acquiring consent and is processed in a fair and transparent manner in compliance with applicable laws and regulations. CtrlS is committed to maintaining and improving data protection and privacy within the company while minimizing its exposure to risks.
4.1. THE PERSONAL DATA COLLECTION FROM THE USER:
CtrlS does not and will not collect any personal data about the User/ Principal unless such User/ Principal provides it to CtrlS with consent. CtrlS collects information during User’s interactions with CtrlS, whether through business related interactions or online (involuntary), including through CtrlS’s websites that is necessary to conduct its business, to provide the services to the customers, as part of business operations and optimization of its service offerings.
In the course of providing Colo, Colo Managed Services, and Cloud Managed Services, the Organisation may process the following categories of personal data:
Customer & Customers’ Personnel Data
Identification data: full name, employee ID, designation, employer name
- Contact data: email address, phone number, business address
- Access credentials: usernames, password hashes, multi-factor authentication tokens
- Contractual data: signatures, billing information, service agreements
- Technical data: IP addresses, device identifiers, access logs
Employee & HR Data
- Personal identifiers: name, date of birth, government-issued ID numbers, PAN, Aadhaar (masked)
- Employment data: employment history, payroll, performance records
- Health and emergency data: emergency contacts, medical fitness declarations
- Biometric data (where applicable): fingerprints or facial recognition for physical access control
Visitor Data
- Name, identity proof type, contact number
- Purpose of visit, time of entry and exit
- CCTV footage (where installed)
Vendor and Partner Data
- Contact details of authorised representatives
- Financial and banking details for payment processing
- Professional qualification and background verification data
Customer End-User Data (As Processor)
In our role as Data Processor / PII Processor, we may incidentally process personal data of customer stored on infrastructure hosted within our facilities. This data is processed solely under the instructions of the customer (Data Controller / Data Fiduciary), governed by a Data Processing Agreement.
4.2. HOW IS YOUR PERSONAL DATA COLLECTED AND USED?
Generally, CtrlS collects personal data related to the customers and their representatives, as well CtrlS employees, visitors, vendors, contractors, subcontractors and other third party. The kind of data that CtrlS collects and/or has visibility/access to, depends solely on the context and the nature of user’s interaction with CtrlS and in case of CtrlS’s customers, the nature service offering by CtrlS. CtrlS do not solicit and/or collect any sort of personal information that is irrelevant/not necessary for the provision of services to the User. CtrlS further declare that it does not participate in any sort of data mining activities whatsoever, with any third parties. CtrlS uses customer data only to the extent such data is required to provide the services agreed upon, and does not mine it for marketing or advertising. In case a Customer decides to suspend the services or terminates the requirement for availing services, CtrlS shall, in accordance with Customer’s requirements, and any applicable laws, policies it has, follows standards and requisite processes for deleting customer data from its servers /application.
Customer or Individual have choices when it comes to the use of the data shared. When CtrlS asks to provide personal data, Customer or Individual can decline. Many of our services require personal data to provide with a service. If Customer or Individual choose not to provide data required to provide with a service or feature, Customer or Individual cannot use that service or feature. Likewise, where CtrlS needs to collect personal data by law or to enter into or carry out a contract with Customer or Individual, and they do not provide the data, CtrlS will not be able to enter into the contract; or if this relates to an existing service being used, CtrlS may have to suspend or cancel it. We will notify Customer or Individual if this is the case at the time. Where providing the data is optional, and Customer or Individual choose not to share personal data, features like personalization that use such data will not work for them.
CtrlS undertakes that CtrlS uses personal data strictly in compliance with applicable laws / legitimate use. Purposes for which CtrlS may collect the personal data belonging to the User and the rationale behind such collection:
CtrlS uses personal information only where required for specific purposes. The following table serves as an explainer for the purpose for which CtrlS collect/uses of the personal data belonging to the User and the rationale behind such collection/use:
| Purpose | Applicable Service / Function |
| Identity verification and physical access control | Colo, Colo Managed Services |
| Provisioning and management of contracted services | All service lines |
| Technical support, incident management, and monitoring | Colo Managed, Cloud Managed |
| Billing, invoicing, and financial reconciliation | All service lines |
| Security operations, threat detection, and log management | All service lines |
| Employee recruitment, onboarding, payroll, and offboarding | Internal HR |
| Regulatory compliance, audit, and legal obligations | All service lines |
| Marketing communications (with consent) | Sales & Marketing |
| CCTV surveillance for physical security | Colo, Facilities, Security |
| Disaster recovery and business continuity operations | All service lines |
| Training and awareness programs | Internal |
| Contractual relationship management with vendors and partners | Procurement |
4.3. DATA MINIMISATION
- CtrlS shall ensure that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
4.4. HOW WE SHARE / DISCLOSE YOUR PERSONAL DATA
Purposes for which CtrlS may share personal data belonging to the user:
CtrlS shares / disclose the user’s personal data with the user’s consent and/or to carry out any transaction and/or provide any service that the user has authorized or requested. CtrlS also shares/ disclose any such personal data with its wholly owned subsidiaries and affiliates whenever necessary, to optimize CtrlS service offerings.
Further, CtrlS may also share / disclose User’s personal data with its vendors/suppliers/third parties when customer or user separately consent to or request such sharing on strict need to know basis, ensuring that such parties are bound by the agreement, privacy principles detailed herein and are bound by strict confidentiality obligations.
Lastly, CtrlS shares / disclose the personal data when required by applicable laws/legal mandates and/or in order to respond to any legal process, including but not limited to protection of the rights and property of CtrlS and its customers.
4.5. IN RESPONSE TO THE LAW
CtrlS may disclose Customer’s information if it required to comply with a law, regulation, or valid legal process. If CtrlS is going to disclose Customer’s information, CtrlS will provide Customer with a notice unless it is prohibited from doing so under law or under judicial or executive order. Further, CtrlS may disclose Customer’s information without providing customer with a prior notice if it reasonably be required that such disclosure is necessary to prevent imminent and serious harm to a person.
4.6. THIRD PARTY & VENDOR MANAGEMENT
CtrlS recognizes that engaging sub-processors and third-party vendors introduces privacy risks. All third-party relationships involving personal data are governed by robust contractual and operational controls.
Vendor Due Diligence
Before engaging any vendor, supplier, or sub-processor that will process personal data on behalf of the us, the following due diligence is conducted:
- Assessment of the vendor’s data protection and information security practices
- Review of compliance certifications (DPDP Act, GDPR, ISO 27001, ISO 27701, SOC 2 Type II, etc.)
- Legal review of the vendor’s standard terms and data protection provisions
- Geographic and jurisdictional analysis of data processing locations
Contractual Requirements
All vendors processing personal data on behalf of the us must sign a Data Processing Agreement (DPA) or equivalent contractual instrument incorporating:
- Purpose and scope of processing clearly defined
- Obligation to process data only on documented instructions
- Confidentiality obligations for all personnel with data access
- Appropriate technical and organisational measures
- Sub-processing restrictions and approval requirements
- Data breach notification obligations (within 24 hours to CtrlS)
- Data return or deletion upon termination of services
- Audit rights for CtrlS or its appointed auditors
Sub-processor Register
We maintain a Sub-processor Register listing all authorised sub-processors, the categories of
personal data processed, jurisdictions, and contractual safeguards in place. This register is
reviewed and shared with customers upon request.
4.7. VENDOR HAVING ACCESS TO PERSONAL DATA
Service or work involving vendor access to Personal Data include:
- A contractor is hired to provide payroll services to assist the organization’s Performance Management System. The potential exists for the contractor to have access to employees’ personal data such as names, mailing addresses, salary slips, personal telephone numbers, and financial account information.
- A vendor or contractor is hired to perform surveys on the organization’s work culture or corporate programs to be used by CtrlS Top Management. Depending on the nature of the survey, the vendor or contractor may have access to personal data such as names of survey respondents, email addresses, and related information.
- A contractor is hired to deploy or upgrade physical access control systems (e.g., card swipe entry readers) and biometric access cards. The potential exists for the contractor to have access to personal data collected through card swipes and thumb impressions, such as names, organization ID numbers, and fingerprints.
4.8. DATA RETENTION AND DISPOSAL
Personal data shall not be retained for longer than is necessary for the purposes for which it was collected or as required by applicable law. We maintain a data retention schedule that specifies retention periods for all categories of personal data.
Secure Disposal
Upon expiry of the retention period, personal data shall be securely deleted or anonymised using industrystandard methods, including:
- Electronic data: Multi-pass overwriting (DoD 5220.22-M), cryptographic erasure, or physical destruction of storage media.
- Physical records: Cross-cut shredding by certified vendors.
- Cloud environments: Vendor-certified deletion processes with confirmation certificates. All disposal activities are logged and retained as evidence of compliance. Disposal is coordinated with the customer’s data governance team where the CtrlS acts as a processor.
4.9. LEGAL BASIS FOR DATA PROCESSING
We ensures that every processing activity is grounded in a valid lawful basis. The applicable lawful bases differ across jurisdictions as follows:
Under the DPDP Act, 2023 (Section 4 & 6)
| Legal Basis | Application in Our Context |
| Consent | Express, free, informed, specific, and unconditional consent of the Data Principal for processing personal data. |
| Legitimate Uses (Sec. 7) | Processing for purposes of the State (subsidies, benefits), compliance with law, medical emergency, employment, or public interest — without requiring consent. |
Under the EU GDPR (Article 6)
| Legal Basis | Application in Our Context |
| Consent (Art. 6(1)(a)) | Processing marketing communications, opt-in analytics, and where no other lawful basis applies. |
| Contract Performance (Art. 6(1)(b)) | Processing necessary to provide Colo, Managed Services, or Cloud services to customers. |
| Legal Obligation (Art. 6(1)(c)) | Compliance with tax laws, employment law, court orders, and regulatory requirements. |
| Vital Interests (Art. 6(1)(d)) | Emergency access to data where life is at risk (rare, exceptional scenarios). |
| Legitimate Interests (Art. 6(1)(f)) | Security monitoring, fraud prevention, internal reporting, and network integrity. |
Special Category / Sensitive Data
Processing of sensitive personal data (health, biometric, financial, etc.) requires explicit consent under EU GDPR Art. 9 and heightened safeguards under the DPDP Act. We restrict such processing to clearly defined and documented purposes only.
4.10. CONSENT MANAGEMENT
Where consent is the lawful basis for processing, we implement a robust Consent Management Framework aligned to the DPDP Act and EU GDPR requirements. CtrlS maintains and manages all the consents within the organization’s systems.
Consent Standards
- Consent must be Free: Not coerced or conditional upon service delivery (where not necessary).
- Consent must be Informed: Accompanied by a clear privacy notice explaining purpose, duration, and data sharing.
- Consent must be Specific: Granular consent for distinct purposes and not bundled.
- Consent must be Unambiguous: Affirmative action is required; pre-ticked boxes are not valid.
- Consent must be Withdrawable: Data subjects must be able to withdraw consent as easily as it was given.
Consent for Sensitive Data
Explicit and separate consent is required for processing sensitive personal data. This includes health information, biometric data, and financial data.
Consent Records
We maintain auditable records of all consents, including: who consented, when, what they consented to, the version of the notice shown, and the method of consent. These records are maintained in our in-house systems for a minimum of 1 year post-withdrawal or cessation of the relevant processing.
Children’s Data
We do not collect personal data from individuals under the age of 18 (minors under DPDP Act; children under EU GDPR). Where such data is collected, verifiable parental or guardian consent is obtained. Processing of children’s data is prohibited for purposes that are detrimental to the child’s well-being or involve behavioural monitoring.
4.11. DATA PROTECTION PRINCIPLES
We process personal data in strict adherence to the following principles, which are harmonised across the DPDP Act, EU GDPR, and ISO/IEC 27701:
| Principle | EU GDPR Ref. | DPDP Act / PIMS Ref. |
| Lawfulness, Fairness & Transparency | Art. 5(1)(a) | Sec. 4, 5 / ISO 27701 Cl. 7.2 |
| Purpose Limitation | Art. 5(1)(b) | Sec. 5(1) / ISO 27701 Cl. 7.2.1 |
| Data Minimization | Art. 5(1)(c) | Sec. 8(3) / ISO 27701 Cl. 7.4 |
| Accuracy | Art. 5(1)(d) | Sec. 8(4) / ISO 27701 Cl. 7.4.4 |
| Storage Limitation | Art. 5(1)(e) | Sec. 8(7) / ISO 27701 Cl. 7.4.7 |
| Integrity & Confidentiality | Art. 5(1)(f) | Sec. 8(5) / ISO 27701 Cl. 6.13 |
| Accountability | Art. 5(2) | Sec. 8, 10 / ISO 27701 Cl. 5.2 |
| Privacy by Design & Default | Art. 25 | Sec. 8 / ISO 27701 Cl. 6.3 |
CtrlS operationalizes these principles through its PIMS framework, which includes documented policies, procedures, technical controls, training programs, and regular audits.
4.12. DATA SUBJECTS / PRINCIPAL RIGHTS
We are committed to respecting and facilitating the rights of data subjects (Data Principals under the DPDP Act).
The following rights are available to individuals whose personal data we process:
| Right | EU GDPR Ref. | DPDP Act Ref. |
| Right to be Informed / Notice | Art. 13, 14 | Sec. 5 |
| Right of Access | Art. 15 | Sec. 11 |
| Right to Rectification / Correction | Art. 16 | Sec. 12 |
| Right to Erasure / Deletion (“Right to be Forgotten”) | Art. 17 | Sec. 12(3) |
| Right to Restriction of Processing | Art. 18 | N/A (principle-based) |
| Right to Data Portability | Art. 20 | Sec. 12(3) |
| Right to Object | Art. 21 | Sec. 6(4) – Withdrawal of Consent |
| Rights related to Automated Decision-Making | Art. 22 | N/A (under review) |
| Right to Nominate (in case of death/incapacity) | N/A | Sec. 14 |
| Right to Grievance Redressal | Art. 77-79 | Sec. 13 |
Exercising Rights
Data subjects may submit requests to exercise their rights through the following channels:
- Email: dpo@ctrls.in
- Written request to the Data Protection Officer at the registered address
We acknowledge all requests within 72 hours and respond within:
- 30 days (EU GDPR) — extendable by 2 months for complex requests.
- 30 days (DPDP Act) — as may be notified by the Data Protection Board.
Limitations on Rights
Rights may be restricted in limited circumstances where legally permitted, including for national security, law enforcement, or where the exercise of rights would adversely affect the rights of other persons. Such restrictions will be communicated to the data subject with reasons wherever legally permissible.
4.13. PRIVACY BY DESIGN AND DEFAULT
CtrlS embeds privacy considerations into the design of all new services, infrastructure deployments, and internal systems from the outset, in accordance with EU GDPR Art. 25 and ISO/IEC 27701 Clause 6.3.
Privacy by Design Principles Applied
- Proactive, not reactive: Privacy risks are identified and mitigated before deployment.
- Privacy as the default setting: Maximum privacy protection is the default; data subjects do not need to take action to protect their privacy.
- Privacy embedded into design: Privacy safeguards are integrated into architecture, not added as a bolt-on.
- Full functionality — positive-sum: Privacy is not treated as a trade-off with functionality.
Operationalization
- Privacy Impact Assessments (PIAs) / DPIAs are mandatory for all projects involving personal data.
- Privacy review is mandatory in the project delivery and change management processes.
- Default settings on all systems minimize data collection and sharing to what is strictly necessary.
Data – any information that, by means of use or correlation with other data or information, can be used to uniquely identify an entity. Data has been categorised by CtrlS into the following three types:
- Sensitive Personal Data
- Highly Sensitive Personal Data
- Non-Sensitive / Public or Personal Data
5.1 Sensitive Personal Data
Sensitive Personal Data is defined as information that, if lost, compromised, or disclosed, could result in substantial harm, inconvenience, or unfairness to an individual.
Sensitive data includes:
- Bank account numbers
- Passport information
- Driver’s license
- Address
- Employees Dependants data
5.2 Highly Sensitive Data
- Healthcare-related information
- Medical insurance information
- Biometric data: Fingerprint or voice signatures
- Social Security Number
- Children’s data (below 18 years)
- Government-issued IDs
- Driver’s License Number
- Passport Number
- Personal banking, debit, or credit card account information
5.3 Non-Sensitive or Public Data
- Visiting cards
- Business telephone number
- Business mailing or email address
- The above list contains examples of non-sensitive information that can be released to the public. This type of information cannot be used alone to determine an individual’s identity.
However, non-sensitive information, although not sensitive, is linkable. This means that non-sensitive data, when used with other personally linkable information, can reveal the identity of an individual.
CtrlS will ensure that all relationships it enters into that involve the processing of data are subject to a documented contract that includes the specific information and terms required by the applicable legislation, including a Data Processing Agreement.
The global nature of data centre and cloud services may necessitate the transfer of personal data across international borders. In such cases, CtrlS applies the following safeguards for these transfers:
Under the DPDP Act, 2023
CtrlS shall not transfer personal data to countries or territories that the Central Government of India has restricted by notification. Subject to this restriction, cross-border transfers are governed by contractual obligations ensuring equivalent protection. CtrlS monitors the Government’s notified whitelist/blacklist of permitted countries and adjusts data flows accordingly.
Data Residency / Localisation Commitments
For customers with data residency/localisation requirements, CtrlS offers dedicated infrastructure configurations ensuring that data does not leave the designated geographic region. Data residency/localisation commitments are formally documented in service agreements and technically enforced through network and storage controls.
A defined role of Data Protection Officer (DPO) is generally required under privacy legislation if an organization is a service provider who deal with Data Principals/ Subjects, if it performs large scale monitoring or if it processes particularly sensitive types of data on a large scale. The DPO is required to have an appropriate level of knowledge and can either be an in-house resource or outsourced to an appropriate service provider. Based on these criteria, CtrlS has appointed the Data Protection Officer.
CtrlS maintains a documented Personal Data Breach Response Procedure aligned to EU GDPR Art. 33-34 and DPDP Act Sec. 8(6) requirements.
Breach Classification
| Severity | Description | Examples |
| Critical | High volume of sensitive data exposed; potential for widespread harm. | Ransomware attack on customer data, mass credential theft. |
| High | Sensitive data of limited individuals exposed with potential harm. | Unauthorised access to HR system, customer data mistakenly shared. |
| Medium | Non-sensitive data exposed or limited impact. | Email sent to the wrong recipient, accidental log exposure. |
| Low | Minimal or no personal data involved; negligible risk. | Temporary loss of an encrypted device with no access to data. |
Breach Response Timeline
| Timeframe | Action Required |
| 0-2 hours | Detection, initial containment, and escalation to DPO (dpo@ctrls.in) and CISO. |
| 2-24 hours | Preliminary assessment, evidence preservation, and internal notification. |
| 24-72 hours | Mandatory notification to the Supervisory Authority (EU GDPR Art. 33) / Data Protection Board (DPDP Act Sec. 8(6)) where the breach is likely to result in a risk to rights and freedoms. |
| 72+ hours | Notification to affected Data Subjects if high risk (EU GDPR Art. 34); coordination with customers where applicable. |
| Post-incident | Root cause analysis, remediation, and lessons learned. |
Customer Notification (As Processor)
Where a breach involves customer data and CtrlS acts as a Data Processor, we will notify the relevant customer (Data Controller) without undue delay and within the timeframes prescribed in the applicable Data Processing Agreement, typically within 24 hours of confirmed breach identification.
A Data Protection Impact Assessment (DPIA) is mandatory for any processing activity likely to result in a high risk to the rights and freedoms of natural persons. The CtrlS has defined triggers, methodology, and governance for DPIAs. DPIA review is performed annually on regular basis.
Organizations that collect, process or use personal data themselves or on behalf of others must take the technical and organizational measures necessary to ensure compliance with the provisions of the data protection laws. The measures must be suitable to adequately protect the personal data according to their nature and category. The measures are only necessary if their effort is in a reasonable relation to the intended protection purpose.
Organizational management and dedicated staff responsible for the development, implementation, and maintenance of CtrlS’s information security, data protection and privacy program.
Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to the CtrlS organization, monitoring and maintaining compliance with CtrlS policies and procedures, and reporting the condition of its information security and compliance to senior internal management.
Maintain Information security policies and make sure that policies and measures are regularly reviewed and where necessary, improve them.
Communication with CtrlS applications utilizes cryptographic protocols such as TLS to protect information in transit over public networks. At the network edge, stateful firewalls, web application firewalls, and DDoS protection are used to filter attacks. Within the internal network, applications follow a multi-tiered model which provides the ability to apply security controls between each layer.
Data security controls which include logical segregation of data, restricted (e.g. role-based) access and monitoring, and where applicable, utilization of commercially available and industry-standard encryption technologies.
Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, (e.g. granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
Password controls designed to manage and control password strength, and usage including prohibiting users from sharing passwords.
System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review.
Physical and environmental security of data center, server room facilities and other areas containing customer confidential information designed to: (i) protect information assets from unauthorized physical access, (ii) manage, monitor and log movement of persons into and out of CtrlS facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.
Operational procedures and controls to provide for configuration, monitoring, and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from CtrlS possession.
Change management procedures and tracking mechanisms to designed to test, approve and monitor all changes to CtrlS technology and information assets.
Incident / problem management procedures designed to allow to CtrlS investigate, respond to, mitigate and notify of events related to CtrlS technology and information assets.
Network security controls that provide for the use of enterprise firewalls and layered DMZ architectures, and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
Vulnerability assessment, patch management, and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
Business resiliency/continuity and disaster recovery procedures, as appropriate, designed to maintain service and/or recovery from foreseeable emergency situations or disasters.
Formal Vendor Management program, including vendor security reviews for critical vendors to ensure compliance with CtrlS Information Security Policies.
A Data Protection Officer (DPO) who is independent, regularly reviews data protection and privacy risks and controls.
The IS- Compliance Committee is responsible for ensuring this is policy is adopted and implemented. This committee should consist of stakeholders from key department who oversee the privacy in the organization at various levels.
Data Protection Officer is responsible for the data protection and privacy at organization level. The DPO is supported by the Privacy Manager who should accountable for personal information within organization, ie., implementation of CtrlS data protection privacy program.
The operations team and support functions comprise of Privacy Management team and privacy champions who are responsible for compliance with privacy policies on a day to day basis. Privacy Manager would laisse with multiple department that collect, store, process or dispose of personal information. Privacy Managed team comprise of technology security and process representatives.
| Role | Responsibilities |
| IS Compliance Committee |
|
| Chief Information Security Officer |
|
| Information Security Officer |
|
| Data Protection Officer |
|
| Asset Owners |
|
| IT Security Team |
|
| Users |
|
| Specific Department Heads |
|
| All Employees, Contractors, and Other Third-Party Personnel |
|
| Enforcement |
|
| Privacy Manager / Lead Implementer |
|
| Privacy Champions |
|
Major Departments Identified as Data Controllers and Processors with concern Data Subjects /Principals
| Department Name | Controller | Processor | Data Principal |
| Physical and Environmental Security | Yes | Visitor, Employee, Customer, Supplier, Vendor, Other Third Parties | |
| Human Resources | Yes | Employee, Vendor, Supplier | |
| Procurement | Yes | Supplier, Vendor | |
| Corporate IT | Yes | Employee, Vendor, Employee | |
| Automation | Yes | Customer, Vendor, Employee | |
| Networking | Yes | Customer, Employee, Vendor | |
| DC Infra | Yes | Customer, Vendor, Employee | |
| Marketing | Yes | Customer | |
| Sales | Yes | Yes | Customer |
| Billing | Yes | Yes | Customer, Supplier, Vendor, Employee |
| Admin | Yes | Employees, Supplier |
All personnel with access to personal data are required to complete mandatory data protection and privacy training. Our Company’s training program includes:
Training completion is tracked and recorded. Non-completion is escalated and may result in disciplinary action. Training effectiveness is assessed through knowledge assessments and periodic simulations.
This document will be reviewed and updated on an annual basis or when significant changes occur to the organization systems and information security standards.
Any user found to have violated this Policy may be subjected to disciplinary action, up to and including termination of employment
This Policy is intended to address Data protection and Privacy requirements. Requested waivers shall be formally submitted to the Head – data security and privacy including justification and benefits attributed to the waiver for approval. The waiver shall only be used in exceptional situations for communicating non-compliance with the policy for a specific period of time (subject to a maximum period of 30 days). At the completion of the time period the need for the waiver shall be reassessed and re-approved, if necessary. Waiver shall not be provided for more than three consecutive terms. The waiver shall be monitored to help ensure its concurrence with the specified period of time and exception.