Privacy Policy

 

SHYAM VNL Private Limited (“SHYAM”, “we”, “our” or “us”) respects your privacy. We design and manufacture RF-Cyber Intelligence, TSCM and Secure Communications systems for government, defence, law enforcement and correctional users. Trust is the foundation of that work. It extends to how we handle your information.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit www.shyamvnl.com (the “Website”), submit an enquiry, request a demonstration, download a resource, apply for a role, or otherwise interact with us through our digital channels.

Please read this Policy together with our Website Terms & Conditions.

1. Scope and Applicability

This Policy applies to personal data collected by SHYAM through the Website and related digital channels that we operate.

This Policy does not apply to:

  1. Personal data processed under a separate contract, non-disclosure agreement, tender or procurement process. That processing is governed by the relevant agreement.
  2. Third-party websites, platforms or services that we link to.
  3. Data that we process on behalf of a customer in the capacity of a data processor. That processing is governed by the applicable customer contract.

2. Who We Are and How to Contact Us

SHYAM is the data fiduciary (data controller) for personal data collected through the Website.

Entity: SHYAM VNL Private Limited

CIN: U61900DL2023PTC412392

Regd. Office: A-60, Naraina Industrial Area Phase-1, New Delhi-110028

Corp Office: Plot No. 21-22, Phase-IV, Udyog Vihar, Gurugram 122015, Haryana, India

Email: info@shyamvnl.com

 

3. Information We Collect

3.1 Information you provide to us

  1. Full name, designation or rank.
  2. Organization name and organization type – government, defence, law enforcement, correctional administration, partner or commercial.
  3. Official or business email address, mobile or telephone number.
  4. Country, state and city.
  5. Enquiry details, requirement descriptions, tender references and any documents you attach.
  6. Career details and curriculum vitae, where you apply for a role.
  7. Records of correspondence with us, including emails, call notes and meeting records.

3.2 Information collected automatically

  1. IP address and the approximate location derived from it.
  2. Browser type, device type, operating system and screen characteristics.
  3. Pages viewed, time spent on each page and navigation path.
  4. Referring URL, referral source and search terms.
  5. Date and time stamps, cookie identifiers, server logs and security event logs.

3.3 Information from other sources

We may receive business contact information from publicly available business directories and official tender portals, from exhibitions, trade delegations and industry events, from business cards exchanged at such events, from our authorized partners and representatives, and from public professional networks.

3.4 Information you should not send us

Do not submit classified, restricted or operationally sensitive information through the Website or any public form. This includes details of live operations, deployment locations, force strengths, security arrangements and any material protected under applicable official secrets or security legislation. A public web form is not a secure channel. If your enquiry requires that level of detail, tell us and we will move the discussion to a secure channel.

We also do not seek financial account details, health data, biometric data or government identification numbers through Website forms. Please do not submit them.

4. Purposes and Legal Bases for Processing

We process personal data only where we have a lawful basis to do so.

S.No

Purpose

Basis under Indian law

Basis under GDPR, where applicable

1

Responding to enquiries, demonstration and consultation requests

Consent; steps taken at your request

Article 6(1)(b) – steps prior to a contract

2

Supplying brochures, datasheets, whitepapers and product information

Consent

Article 6(1)(a) – consent

3

Tender participation, pre-qualification and customer onboarding

Contractual necessity; legitimate business use

Article 6(1)(b) and 6(1)(c)

4

Business communications about products, solutions, events and company updates

Consent, withdrawable at any time

Article 6(1)(a) or 6(1)(f)

5

Website operation, security, abuse detection and fraud prevention

Legitimate business use

Article 6(1)(f) – legitimate interests

6

Analytics and improvement of the Website

Consent for non-essential cookies

Article 6(1)(a) or 6(1)(f)

7

End-use, export control and sanctions screening of enquiries

Compliance with legal obligation

Article 6(1)(c) – legal obligation

8

Recruitment and evaluation of applications

Steps taken at your request

Article 6(1)(b)

9

Legal, regulatory, audit and record-keeping requirements

Compliance with legal obligation

Article 6(1)(c)

We do not use personal data collected through the Website for automated decision-making that produces legal or similarly significant effects.

5. Consent and Withdrawal of Consent

Where we rely on your consent, we obtain it by clear affirmative action – for example, when you complete and submit a form after being shown a notice of purpose.

You may withdraw consent at any time by writing to legal@shyamvnl.com. Withdrawal is as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before we received your request. Where consent is the only basis on which we hold your information, withdrawal may mean we can no longer respond to your enquiry or continue an ongoing discussion.

6. Cookies and Similar Technologies

The Website may use cookies, pixels, tags and similar technologies in the following categories.

S.No

Category

What it does

Your control

1

Strictly necessary

Supports security, load balancing, session integrity and form submission

Cannot be disabled; the Website will not function correctly without these

2

Preference

Remembers language, region and display choices

Browser settings or the cookie banner, where offered

3

Analytics

Measures page views, traffic sources and navigation patterns in aggregate

May be declined through browser settings or the cookie banner

4

Campaign

Measures response to campaigns, referrals and outreach activity

May be declined through browser settings or the cookie banner

 

You can control or delete cookies through your browser settings. Blocking certain cookies may affect Website functionality. We do not use cookies to build behavioural profiles of individual visitors for advertising purposes.

7. Analytics and Third-Party Service Providers

We engage third-party providers for hosting and content delivery, website security, analytics, email and communications, form handling, and customer relationship management.

These providers process personal data under contract, on our instructions, and for no other purpose. We carry out due diligence before engagement and require appropriate confidentiality and security commitments. Their own privacy policies and applicable laws also govern their processing.

8. Sharing and Disclosure of Information

We do not sell, rent or trade personal data. We share personal data only in the following circumstances:

  1. With service providers, as described above, to the extent necessary to operate the Website and respond to you.
  2. With our authorized partners, distributors or representatives for a territory, where your enquiry relates to that territory and disclosure is necessary to serve you.
  3. With professional advisers – legal, audit, insurance and compliance – under duties of confidentiality.
  4. With statutory authorities, regulators, law enforcement agencies or courts, where required by law or by a valid legal process.
  5. With an acquirer or successor entity in the event of a merger, acquisition, restructuring or transfer of business, subject to equivalent protection.
  6. With any other party, where you have given us your consent to do so.

9. Business and B2B Communications

If you provide business contact information, we may contact you regarding products, solutions, demonstrations, technical and commercial discussions, exhibitions, tenders, whitepapers and relevant company updates.

Every marketing communication carries an unsubscribe option. You may ask us to discontinue non-essential communications at any time by writing to legal@shyamvnl.com. We will continue to send operational communications that you have asked for, such as a reply to your enquiry, a quotation, or a notice under a contract.

10. Data Security

We maintain reasonable technical and organizational security practices, including:

  1. Access to personal data on a need-to-know basis, with periodic review of access rights.
  2. Encryption of data in transit using HTTPS and TLS.
  3. Network and endpoint protection, logging and monitoring.
  4. Due diligence on vendors and contractual security obligations.
  5. Confidentiality obligations and security awareness training for employees.
  6. Controlled retention schedules and secure disposal of data no longer required.

Our security practices are maintained consistently with Section 43A of the Information Technology Act, 2000 and the rules made under it. No website, system or internet transmission can be guaranteed to be completely secure, and any transmission is at your own risk.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, and thereafter as required by law.

 

S.No

Category of record

Indicative retention period

1

Website enquiries that do not progress

Up to 24 months from the date of last contact

2

Customer, partner and tender records

For the duration of the relationship, and thereafter as required by contract, limitation periods and applicable law

3

Recruitment applications

Up to 12 months, unless you ask us to retain them for future consideration

4

Server, access and security logs

Up to 12 months, or longer where required for an investigation

5

Accounting, tax and statutory records

As required under the Companies Act, 2013 and other applicable law

When personal data is no longer required, it is securely deleted or anonymized, subject to any legal hold or statutory obligation to retain it.

12. Your Rights as a Data Principal

Subject to applicable law, including the Digital Personal Data Protection Act, 2023, and subject to verification of your identity, you have the right to:

  1. Obtain a summary of the personal data we hold about you and how we process it.
  2. Have inaccurate or misleading personal data corrected, completed or updated.
  3. Request erasure of personal data where it is no longer required and we are not obliged to retain it.
  4. Withdraw consent, where processing is based on consent.
  5. Nominate another individual to exercise your rights in the event of your death or incapacity.
  6. Have your grievance addressed through the process set out in this Policy.

To exercise any of these rights, write to legal@shyamvnl.com. We will verify your identity before acting on a request and will ordinarily respond within thirty (30) days. We do not charge a fee.

The Digital Personal Data Protection Act, 2023 also places duties on data principals. You must not furnish false particulars, impersonate another person, suppress material information, or register a false or frivolous grievance.

13. Visitors in the European Economic Area and the United Kingdom

Where the GDPR or the UK GDPR applies to our processing, you additionally have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing carried out on the basis of legitimate interests – including an absolute right to object to direct marketing.

We do not carry out solely automated decision-making that produces legal or similarly significant effects. If you are not satisfied with our response, you may lodge a complaint with your national supervisory authority.

14. International Data Transfers

SHYAM is established in India and personal data is primarily processed in India. Depending on the service providers used, personal data may be processed or stored in other countries.

Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including standard contractual clauses or equivalent contractual protections. Transfers of personal data outside India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Government of India.

15. Children and Persons with Disability

The Website is intended for businesses, government and institutional users, and professionals. We do not knowingly collect personal data of children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.

Where the personal data of a child or of a person with a disability who has a lawful guardian is to be processed, we will obtain verifiable consent from the parent or lawful guardian as required by law. If you believe that a child has provided personal data to us, write to legal@shyamvnl.com and we will delete it.

16. Third-Party Websites and Social Media

The Website may contain links to third-party websites, embedded content, and social media buttons. SHYAM does not control and is not responsible for the content, security, availability or privacy practices of those third parties. Interacting with embedded or linked content may allow that third party to collect information about you. We encourage you to review the privacy policy of every third-party service you use.

17. Recruitment and Career Enquiries

Where you apply for a role or send us your curriculum vitae, we use that information only to assess your application and to communicate with you about it. Access is limited to the hiring team and the relevant managers.

Certain roles at SHYAM involve access to sensitive technologies and customer environments. Where a background verification or reference check is required for such a role, it will be carried out in accordance with applicable law and with your knowledge.

18. Security Incidents and Breach Notification

We maintain an incident response process for security events affecting the Website or personal data. In the event of a personal data breach, we will notify the Data Protection Board of India and the affected data principals in the manner and within the timelines required under the Digital Personal Data Protection Act, 2023, and will report cyber security incidents to CERT-In in accordance with the directions issued under the Information Technology Act, 2000.

19. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, services or legal obligations. Updated versions are published on this page with a revised Last Updated date and revision number. Where changes are material, we will take reasonable steps to highlight them. Your continued use of the Website after publication constitutes acknowledgement of the revised Policy.

20. Grievance Redressal

If you have a concern about how your personal data has been handled, write to our

Email: legal@shyamvnl.com

21. Contact Us

For any question, concern or request relating to this Privacy Policy, please contact:

SHYAM VNL Private Limited

Email: info@shyamvnl.com

Address: Plot No. 21-22, Phase-IV, Udyog Vihar, Gurugram 122015, Haryana, India

Website: www.shyamvnl.com

22. Acknowledgement and Consent

By using the Website, or by voluntarily providing personal data through our forms and communication channels, you confirm that you have read and understood this Privacy Policy and, where required by applicable law, consent to the collection and use of your information as described in it.

Conceptualized, Designed and Manufactured in India.

Conceptualized, Designed & Manufactured in Bharat