Privacy Policy
SHYAM VNL Private Limited (“SHYAM”, “we”, “our” or “us”) respects your privacy. We design and manufacture RF-Cyber Intelligence, TSCM and Secure Communications systems for government, defence, law enforcement and correctional users. Trust is the foundation of that work. It extends to how we handle your information.
This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit www.shyamvnl.com (the “Website”), submit an enquiry, request a demonstration, download a resource, apply for a role, or otherwise interact with us through our digital channels.
Please read this Policy together with our Website Terms & Conditions.
1. Scope and Applicability
This Policy applies to personal data collected by SHYAM through the Website and related digital channels that we operate.
This Policy does not apply to:
- Personal data processed under a separate contract, non-disclosure agreement, tender or procurement process. That processing is governed by the relevant agreement.
- Third-party websites, platforms or services that we link to.
- Data that we process on behalf of a customer in the capacity of a data processor. That processing is governed by the applicable customer contract.
2. Who We Are and How to Contact Us
SHYAM is the data fiduciary (data controller) for personal data collected through the Website.
Entity: SHYAM VNL Private Limited
CIN: U61900DL2023PTC412392
Regd. Office: A-60, Naraina Industrial Area Phase-1, New Delhi-110028
Corp Office: Plot No. 21-22, Phase-IV, Udyog Vihar, Gurugram 122015, Haryana, India
Email: info@shyamvnl.com
3. Information We Collect
3.1 Information you provide to us
- Full name, designation or rank.
- Organization name and organization type – government, defence, law enforcement, correctional administration, partner or commercial.
- Official or business email address, mobile or telephone number.
- Country, state and city.
- Enquiry details, requirement descriptions, tender references and any documents you attach.
- Career details and curriculum vitae, where you apply for a role.
- Records of correspondence with us, including emails, call notes and meeting records.
3.2 Information collected automatically
- IP address and the approximate location derived from it.
- Browser type, device type, operating system and screen characteristics.
- Pages viewed, time spent on each page and navigation path.
- Referring URL, referral source and search terms.
- Date and time stamps, cookie identifiers, server logs and security event logs.
3.3 Information from other sources
We may receive business contact information from publicly available business directories and official tender portals, from exhibitions, trade delegations and industry events, from business cards exchanged at such events, from our authorized partners and representatives, and from public professional networks.
3.4 Information you should not send us
Do not submit classified, restricted or operationally sensitive information through the Website or any public form. This includes details of live operations, deployment locations, force strengths, security arrangements and any material protected under applicable official secrets or security legislation. A public web form is not a secure channel. If your enquiry requires that level of detail, tell us and we will move the discussion to a secure channel.
We also do not seek financial account details, health data, biometric data or government identification numbers through Website forms. Please do not submit them.
4. Purposes and Legal Bases for Processing
We process personal data only where we have a lawful basis to do so.
S.No | Purpose | Basis under Indian law | Basis under GDPR, where applicable |
1 | Responding to enquiries, demonstration and consultation requests | Consent; steps taken at your request | Article 6(1)(b) – steps prior to a contract |
2 | Supplying brochures, datasheets, whitepapers and product information | Consent | Article 6(1)(a) – consent |
3 | Tender participation, pre-qualification and customer onboarding | Contractual necessity; legitimate business use | Article 6(1)(b) and 6(1)(c) |
4 | Business communications about products, solutions, events and company updates | Consent, withdrawable at any time | Article 6(1)(a) or 6(1)(f) |
5 | Website operation, security, abuse detection and fraud prevention | Legitimate business use | Article 6(1)(f) – legitimate interests |
6 | Analytics and improvement of the Website | Consent for non-essential cookies | Article 6(1)(a) or 6(1)(f) |
7 | End-use, export control and sanctions screening of enquiries | Compliance with legal obligation | Article 6(1)(c) – legal obligation |
8 | Recruitment and evaluation of applications | Steps taken at your request | Article 6(1)(b) |
9 | Legal, regulatory, audit and record-keeping requirements | Compliance with legal obligation | Article 6(1)(c) |
We do not use personal data collected through the Website for automated decision-making that produces legal or similarly significant effects.
5. Consent and Withdrawal of Consent
Where we rely on your consent, we obtain it by clear affirmative action – for example, when you complete and submit a form after being shown a notice of purpose.
You may withdraw consent at any time by writing to legal@shyamvnl.com. Withdrawal is as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before we received your request. Where consent is the only basis on which we hold your information, withdrawal may mean we can no longer respond to your enquiry or continue an ongoing discussion.
6. Cookies and Similar Technologies
The Website may use cookies, pixels, tags and similar technologies in the following categories.
S.No | Category | What it does | Your control |
1 | Strictly necessary | Supports security, load balancing, session integrity and form submission | Cannot be disabled; the Website will not function correctly without these |
2 | Preference | Remembers language, region and display choices | Browser settings or the cookie banner, where offered |
3 | Analytics | Measures page views, traffic sources and navigation patterns in aggregate | May be declined through browser settings or the cookie banner |
4 | Campaign | Measures response to campaigns, referrals and outreach activity | May be declined through browser settings or the cookie banner |
You can control or delete cookies through your browser settings. Blocking certain cookies may affect Website functionality. We do not use cookies to build behavioural profiles of individual visitors for advertising purposes.
7. Analytics and Third-Party Service Providers
We engage third-party providers for hosting and content delivery, website security, analytics, email and communications, form handling, and customer relationship management.
These providers process personal data under contract, on our instructions, and for no other purpose. We carry out due diligence before engagement and require appropriate confidentiality and security commitments. Their own privacy policies and applicable laws also govern their processing.
8. Sharing and Disclosure of Information
We do not sell, rent or trade personal data. We share personal data only in the following circumstances:
- With service providers, as described above, to the extent necessary to operate the Website and respond to you.
- With our authorized partners, distributors or representatives for a territory, where your enquiry relates to that territory and disclosure is necessary to serve you.
- With professional advisers – legal, audit, insurance and compliance – under duties of confidentiality.
- With statutory authorities, regulators, law enforcement agencies or courts, where required by law or by a valid legal process.
- With an acquirer or successor entity in the event of a merger, acquisition, restructuring or transfer of business, subject to equivalent protection.
- With any other party, where you have given us your consent to do so.
9. Business and B2B Communications
If you provide business contact information, we may contact you regarding products, solutions, demonstrations, technical and commercial discussions, exhibitions, tenders, whitepapers and relevant company updates.
Every marketing communication carries an unsubscribe option. You may ask us to discontinue non-essential communications at any time by writing to legal@shyamvnl.com. We will continue to send operational communications that you have asked for, such as a reply to your enquiry, a quotation, or a notice under a contract.
10. Data Security
We maintain reasonable technical and organizational security practices, including:
- Access to personal data on a need-to-know basis, with periodic review of access rights.
- Encryption of data in transit using HTTPS and TLS.
- Network and endpoint protection, logging and monitoring.
- Due diligence on vendors and contractual security obligations.
- Confidentiality obligations and security awareness training for employees.
- Controlled retention schedules and secure disposal of data no longer required.
Our security practices are maintained consistently with Section 43A of the Information Technology Act, 2000 and the rules made under it. No website, system or internet transmission can be guaranteed to be completely secure, and any transmission is at your own risk.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, and thereafter as required by law.
S.No | Category of record | Indicative retention period |
1 | Website enquiries that do not progress | Up to 24 months from the date of last contact |
2 | Customer, partner and tender records | For the duration of the relationship, and thereafter as required by contract, limitation periods and applicable law |
3 | Recruitment applications | Up to 12 months, unless you ask us to retain them for future consideration |
4 | Server, access and security logs | Up to 12 months, or longer where required for an investigation |
5 | Accounting, tax and statutory records | As required under the Companies Act, 2013 and other applicable law |
When personal data is no longer required, it is securely deleted or anonymized, subject to any legal hold or statutory obligation to retain it.
12. Your Rights as a Data Principal
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, and subject to verification of your identity, you have the right to:
- Obtain a summary of the personal data we hold about you and how we process it.
- Have inaccurate or misleading personal data corrected, completed or updated.
- Request erasure of personal data where it is no longer required and we are not obliged to retain it.
- Withdraw consent, where processing is based on consent.
- Nominate another individual to exercise your rights in the event of your death or incapacity.
- Have your grievance addressed through the process set out in this Policy.
To exercise any of these rights, write to legal@shyamvnl.com. We will verify your identity before acting on a request and will ordinarily respond within thirty (30) days. We do not charge a fee.
The Digital Personal Data Protection Act, 2023 also places duties on data principals. You must not furnish false particulars, impersonate another person, suppress material information, or register a false or frivolous grievance.
13. Visitors in the European Economic Area and the United Kingdom
Where the GDPR or the UK GDPR applies to our processing, you additionally have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing carried out on the basis of legitimate interests – including an absolute right to object to direct marketing.
We do not carry out solely automated decision-making that produces legal or similarly significant effects. If you are not satisfied with our response, you may lodge a complaint with your national supervisory authority.
14. International Data Transfers
SHYAM is established in India and personal data is primarily processed in India. Depending on the service providers used, personal data may be processed or stored in other countries.
Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including standard contractual clauses or equivalent contractual protections. Transfers of personal data outside India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Government of India.
15. Children and Persons with Disability
The Website is intended for businesses, government and institutional users, and professionals. We do not knowingly collect personal data of children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
Where the personal data of a child or of a person with a disability who has a lawful guardian is to be processed, we will obtain verifiable consent from the parent or lawful guardian as required by law. If you believe that a child has provided personal data to us, write to legal@shyamvnl.com and we will delete it.
16. Third-Party Websites and Social Media
The Website may contain links to third-party websites, embedded content, and social media buttons. SHYAM does not control and is not responsible for the content, security, availability or privacy practices of those third parties. Interacting with embedded or linked content may allow that third party to collect information about you. We encourage you to review the privacy policy of every third-party service you use.
17. Recruitment and Career Enquiries
Where you apply for a role or send us your curriculum vitae, we use that information only to assess your application and to communicate with you about it. Access is limited to the hiring team and the relevant managers.
Certain roles at SHYAM involve access to sensitive technologies and customer environments. Where a background verification or reference check is required for such a role, it will be carried out in accordance with applicable law and with your knowledge.
18. Security Incidents and Breach Notification
We maintain an incident response process for security events affecting the Website or personal data. In the event of a personal data breach, we will notify the Data Protection Board of India and the affected data principals in the manner and within the timelines required under the Digital Personal Data Protection Act, 2023, and will report cyber security incidents to CERT-In in accordance with the directions issued under the Information Technology Act, 2000.
19. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, services or legal obligations. Updated versions are published on this page with a revised Last Updated date and revision number. Where changes are material, we will take reasonable steps to highlight them. Your continued use of the Website after publication constitutes acknowledgement of the revised Policy.
20. Grievance Redressal
If you have a concern about how your personal data has been handled, write to our
Email: legal@shyamvnl.com
21. Contact Us
For any question, concern or request relating to this Privacy Policy, please contact:
SHYAM VNL Private Limited
Email: info@shyamvnl.com
Address: Plot No. 21-22, Phase-IV, Udyog Vihar, Gurugram 122015, Haryana, India
Website: www.shyamvnl.com
22. Acknowledgement and Consent
By using the Website, or by voluntarily providing personal data through our forms and communication channels, you confirm that you have read and understood this Privacy Policy and, where required by applicable law, consent to the collection and use of your information as described in it.
Conceptualized, Designed and Manufactured in India.

