LEGAL

Privacy Policy

This policy explains how PoCForge (Cyber Security) handles personal data when you use https://pocforge.com, contact us, or engage our remote offensive-security / VAPT services. It is written in plain language for clients and website visitors in India and internationally.

Last updated: 30 September 2026 · Contact: [email protected]

1. Who controls your data

For website enquiries and marketing communications related to this site, PoCForge (Cyber Security) is the organisation deciding why and how personal data is processed. For engagement work, the SoW and any data-processing terms agreed with the client also apply — especially where we process client system data or credentials solely to deliver testing.

Contact for privacy questions: [email protected].

2. What we collect

2.1 Contact and enquiry forms

When you use the homepage scope form (or email us), we typically receive:

  • name;
  • work email address;
  • company name (optional);
  • phone number (optional);
  • service interest (for example web, API, mobile, cloud);
  • message / scope notes you choose to provide;
  • security challenge response (Cloudflare Turnstile) to reduce automated abuse.

A honeypot field may be present to deter bots; legitimate users should leave it blank.

2.2 Email and commercial correspondence

If you email [email protected] or exchange SoW, invoices or reports, we process the contact and business details you include, plus engagement artefacts needed to deliver and support the work.

2.3 Technical and hosting data

Like most websites, our hosting and CDN stack may process technical data such as IP address, approximate location derived from IP, browser/user-agent, requested URLs, timestamps and security logs. This site is commonly served with LiteSpeed caching and Cloudflare in front (CDN / security features such as email-address obfuscation and Turnstile). Exact third-party processing depends on their roles as processors or independent controllers of their own telemetry.

2.4 Cookies and similar technologies

We may use:

  • Essential / operational cookies — for example WordPress session or logged-in cookies (admin only), LiteSpeed cache-vary cookies, and security cookies needed for form protection;
  • CDN / security cookies — set by Cloudflare or similar edge services for bot management and delivery;
  • Analytics — if enabled in future, we will describe them here. As of the last update date above, we do not intentionally run a separate third-party marketing analytics pixel on public pages beyond what the hosting/CDN stack may collect for operations and security.

You can control cookies through your browser settings. Blocking essential cookies may break form submission or logged-in admin features.

3. Why we use personal data

  • to respond to scope and sales enquiries;
  • to prepare quotes, SoWs and invoices;
  • to deliver security-testing services under agreed RoE;
  • to protect the website against abuse and spam;
  • to maintain business records and comply with legal obligations;
  • to improve site reliability and security.

We do not sell personal data. We do not use enquiry details for unrelated third-party advertising.

4. Legal bases (high level)

Depending on your location and the context, we rely on one or more of: performance of a contract or steps prior to contract (quotes / engagements); legitimate interests in operating a security practice and securing our website; consent where required for optional cookies or marketing; and legal obligation where records must be kept. For individuals in India, we aim to process personal data in line with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules, including providing clear notice and honouring rights requests as required.

This summary is not legal advice and does not create rights beyond those applicable law already grants.

5. Engagement / client system data

During VAPT engagements we may access systems, logs, credentials and sample data as authorised in the RoE. That material is handled as confidential client information: used only to test, evidence findings and support remediation/retest, retained no longer than needed for the engagement and reasonable follow-up (or as required by law / agreed contract), and shared only with personnel or specialists bound to confidentiality who need it for delivery.

6. Sharing with third parties

We use service providers to run the website and communications, which may include:

  • web hosting and LiteSpeed cache;
  • Cloudflare (CDN, DNS/security features, Turnstile);
  • email delivery / mailbox providers;
  • specialist collaborators engaged under confidentiality when a scope needs additional coverage.

They receive only what is needed to perform their function. We may also disclose information if required by law, regulation or valid legal process, or to protect rights, safety and security.

7. International transfers

PoCForge (Cyber Security) serves India-market and international clients remotely. Personal data may be processed on infrastructure or by providers located in more than one country (for example hosting/CDN). Where transfers occur, we take reasonable contractual and organisational steps appropriate to the context. Engagement-specific residency requirements should be stated in the SoW.

8. Retention

  • Website enquiries: typically kept while an active conversation continues and for a reasonable period afterwards (often up to 24 months) unless you ask us to delete sooner and we have no overriding need to retain;
  • Contracts, invoices and engagement records: retained as needed for accounting, dispute handling and legal retention duties;
  • Security / server logs: retained according to hosting/CDN defaults and operational need, usually for shorter rolling periods.

9. Security

We apply access control, least-privilege handling of credentials, and confidential treatment of reports. No method of transmission or storage is perfectly secure; please use work email and avoid sending production secrets in initial enquiry forms when a secure channel can be arranged after scoping.

10. Your rights (including DPDP Act 2023 at a high level)

Subject to applicable law, you may have rights to:

  • request access to personal data we hold about you;
  • request correction of inaccurate personal data;
  • request erasure or withdrawal of consent where processing is consent-based and no other lawful ground applies;
  • nominate another person to exercise rights on your behalf where the law allows;
  • raise a grievance with us, and with the relevant Data Protection Board / authority where applicable.

To exercise rights, email [email protected] with enough detail for us to verify and respond. We may need to confirm identity before acting. Some requests can be refused or limited where the law allows (for example where data must be retained for contracts or legal claims).

We do not claim to be a registered “Significant Data Fiduciary” or any other special status under the DPDP Act on this page; obligations depend on facts and notifications under the Act and rules as they apply over time.

11. Children

Our website and services are directed at organisations and professionals. We do not knowingly collect personal data from children for marketing. If you believe a child has provided personal data, contact us and we will take appropriate steps.

12. Changes

We may update this Privacy Policy by publishing a revised version here with a new “Last updated” date. Significant changes affecting an active engagement will also be communicated through the engagement channel where appropriate.

13. Contact

Privacy and data requests: [email protected]. Related: Terms of Service, Contact.

Questions before you enquire?

We use contact details only to respond to your scope request — see also our Terms.

Contact PoCForge (Cyber Security) →