ISO Certifications | Compliance Services | Data Security | Risk Management | Audit & Consulting & ISO Certifications | Compliance Services | Data Security | Risk Management | Audit & Consulting

Surkshanow Privacy Policy & Compliance Statement

At Surkshanow, we value the trust our clients and partners place in us. This Privacy Policy explains how we collect, use, share, transfer, and protect your personal data when you visit our website, use our services, or contact us.

1. Scope and Who We Are

Surkshanow is a global professional services firm specializing in compliance and assurance, including SOC 2, ISO 27001, DPDPA, HIPAA, PCI-DSS, CMMI, and FedRAMP.

We act as a data controller when we decide how and why to process your personal data, such as information you submit through our website forms. In other situations, like when we provide compliance automation platforms, audit tools, or consulting services, we process data only on behalf of our clients and follow their instructions as a data processor.

2. Data We Collect

We collect information that is necessary to provide you with our professional compliance services and to maintain a secure website experience.

  • Contact Details: Name, business email, phone number, company name, and job title.
  • Professional & Business Information: Project scope, compliance goals, business documentation, and audit materials shared during consultations or service engagements.
  • Technical & Usage Data: IP address, browser type, operating system, and details about how you interact with our website (collected via cookies and analytics).

3. How We Use Your Data

We use the collected information to deliver high-quality cybersecurity and compliance assessments:

  • To evaluate your organization’s compliance readiness and deliver audit-related services.
  • To respond to inquiries, schedule consultations, and manage our professional relationship with you.
  • To send industry insights, regulatory updates, and promotional communications regarding global frameworks (you may opt out at any time).
  • To secure, improve, and optimize our website and service delivery.

4. Data Protection & Security

As an organization dedicated to security and compliance, we implement industry-leading technical and organizational measures to safeguard your data. This includes restricted access controls, encryption of sensitive information, and continuous monitoring to protect against unauthorized access, loss, or disclosure.

5. Sharing and Transfer of Data

We do not sell, rent, or trade your personal or business data. We may share information with trusted third-party service providers (such as secure cloud hosting providers or specialized audit tools) that perform services on our behalf, under strict confidentiality agreements.

Because we serve organizations globally, your data may be processed or stored in secure environments across multiple regions, always in full compliance with cross-border data transfer regulations.

6. Your Privacy Rights

Depending on your jurisdiction (including compliance with India's Digital Personal Data Protection (DPDP) Act 2023 and other global frameworks), you hold the following rights:

  • Right to Access and Review: Request a summary of the personal data we hold about you.
  • Right to Correction: Request that we update or correct inaccurate or incomplete data.
  • Right to Erasure / Erasure of Data: Request the deletion of your personal data when it is no longer required for business or legal purposes.
  • Right to Withdraw Consent: Easily withdraw consent previously given for data processing.

7. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your data, please contact our team at: