Enterprise Privacy Policy
Whitehats Technologies governance platforms · Last updated:
This Privacy Policy describes how Whitehats Technologies Private Limited (“Company”, “Whitehats”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal information in connection with the Site, pre-contractual interactions, and enterprise software-as-a-service (SaaS) platforms (collectively, the “Services”).
This policy should be read together with our Enterprise Terms of Use. Where the Customer and the Company execute a data processing agreement (“DPA”), Order Form, or Subscription Agreement with data protection schedules, those documents control with respect to Customer Data processed in the Services to the extent they conflict with this policy.
Definitions
- “Customer” means the organization that subscribes to or uses the Services under contract with the Company.
- “Authorized User” means an individual permitted by the Customer to access the Services.
- “Customer Data” means data submitted to or processed by the Services on behalf of the Customer, which may include personal information.
- “Personal information” means information relating to an identified or identifiable individual.
- “Site” means the Whitehats marketing website at whitehats.in and related pages.
Scope and Roles
This policy applies to:
- visitors to the Site and individuals who contact us for demos, support, or commercial enquiries;
- prospective and current Customers and their Authorized Users; and
- personal information processed through the Services, including ComplianceForesight, DataForesight.ai, iConsentO, OneDPDP, and iRegu.
Controller and processor roles.
- For Site interactions, marketing, billing contacts, and account administration relating to our relationship with a Customer, the Company generally acts as an independent controller of personal information.
- For Customer Data processed within the Services at the Customer’s direction, the Customer is generally the controller (or equivalent under applicable law) and the Company acts as a processor or service provider, as described in the applicable DPA or Order Form.
If an Authorized User’s personal information is processed inside a Customer tenant, the Customer’s privacy notice and internal policies may also apply. Authorized Users should contact their organization’s administrator before contacting the Company, except for security incidents or account access issues relating to the Services.
Information We Collect
Depending on the context, we may collect the following categories of information:
- Business contact information — name, business email, phone number, job title, company name, country, and billing details;
- Account and authentication information — user IDs, roles, login metadata, MFA status, and credentials managed through the Customer’s identity configuration;
- Communications — support tickets, emails, demo requests, and meeting notes;
- Technical and usage information — IP address, device identifiers, browser type, operating system, audit logs, feature usage, API calls, and diagnostic events;
- Customer Data — content, records, files, configuration data, and personal information uploaded or generated by the Customer or Authorized Users in the Services; and
- Compliance and security information — security questionnaire responses, audit artefacts, and incident records.
We collect information directly from individuals, from Customers, automatically through the Site and Services, and from integrated systems configured by the Customer.
How We Use Information
We use personal information to:
- provide, operate, maintain, secure, and support the Site and Services;
- authenticate Authorized Users and administer Customer accounts;
- process subscriptions, invoices, and contractual obligations;
- respond to enquiries, demos, support requests, and security incidents;
- monitor performance, troubleshoot, and improve reliability and user experience;
- develop features, including AI-assisted capabilities described in our Terms of Use;
- comply with law, regulatory requests, and enforce agreements; and
- send service notices and, where permitted, product updates or marketing communications to business contacts.
We process Customer Data only on documented instructions from the Customer, as necessary to deliver the subscribed Services, and as otherwise permitted by applicable law and the DPA.
Legal Bases for Processing
Where applicable privacy laws require a legal basis, we rely on one or more of the following: performance of a contract with the Customer or individual; legitimate interests in operating, securing, and improving our business, provided those interests are not overridden by individual rights; compliance with legal obligations; and consent, where required for specific activities such as certain marketing communications or non-essential cookies on the Site.
Customer Data
The Customer retains ownership of Customer Data. The Company does not sell Customer Data and does not use Customer Data for third-party advertising. Customer Data is processed to provide the Services, maintain security, provide support, comply with law, and improve the Services as permitted under the Terms of Use and DPA.
The Customer is responsible for providing lawful notices to data subjects, obtaining required consents, and configuring retention, access controls, and integrations within the Services. The Company’s obligations regarding subprocessors, cross-border transfers, assistance with data subject requests, and breach notification are set out in the applicable DPA or Order Form where required.
Subprocessors and Service Providers
We use infrastructure, hosting, communications, analytics, security, and professional service providers to operate the Site and Services. These providers process personal information only to perform services on our behalf or on behalf of the Customer under contract, and are subject to confidentiality and security obligations appropriate to their role.
A current list of material subprocessors for the Services may be made available to Customers upon request or as published in customer documentation. Where required by the DPA, the Company will provide notice of material subprocessor changes and reasonable objection mechanisms.
We do not sell personal information.
Log Data, Analytics, and Cookies
The Site and Services generate technical logs and telemetry, including IP addresses, timestamps, request metadata, and error diagnostics. We use tag-management and analytics tools on the marketing Site, such as Google Tag Manager, to understand traffic and improve content.
We and our providers may use cookies and similar technologies on the Site for essential functionality, analytics, and performance measurement. Browser settings can be used to manage cookies. Disabling certain cookies may affect Site functionality.
iConsentO helps Customers manage consent for their own digital properties. Use of iConsentO by a Customer is governed by that Customer’s policies and contract with the Company.
International Transfers
The Company serves Customers globally. Personal information and Customer Data may be processed in India and in other countries where we or our subprocessors maintain facilities. Where required by applicable law, we implement appropriate safeguards such as contractual clauses, documented transfer assessments, or other lawful mechanisms described in the DPA or Order Form.
Information Security
We maintain administrative, technical, and organizational measures aligned with ISO/IEC 27001 principles and enterprise SaaS practices, including encryption in transit and at rest where applicable, access controls, multi-factor authentication options, vulnerability management, logging, and secure development practices. Additional security commitments may be described in an Order Form, security exhibit, or DPA.
No method of transmission or storage is completely secure. The Customer is responsible for securing its endpoints, credentials, and integrations under its control.
AI and Automated Processing
Certain Services may use artificial intelligence or automated processing to classify data, prioritize risks, summarize regulatory content, or generate recommendations. AI outputs are assistive only and require human review. The Company does not use Customer Data to train public-facing third-party AI models except as expressly permitted in writing by the Customer or required to provide the subscribed feature under the Order Form.
Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, to comply with legal obligations, resolve disputes, and enforce agreements. Customer Data retention, export, and deletion after termination are governed by the Terms of Use, Order Form, and DPA.
Security Incidents
We maintain incident response procedures designed to detect, investigate, and remediate security events affecting the Services. Where the Company processes Customer Data as a processor, we will notify the Customer of confirmed personal data breaches affecting Customer Data in accordance with applicable law and the DPA, without undue delay after becoming aware of the breach.
Individual Rights and Choices
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or port personal information, or to withdraw consent where processing is consent-based. Business contacts may opt out of marketing emails using the unsubscribe mechanism in the message or by contacting us.
Requests relating to personal information processed within a Customer tenant should be directed to the Customer administrator in the first instance. The Company will assist the Customer with such requests as required by applicable law and the DPA. We may need to verify identity before responding to direct requests relating to our controller activities.
Regulatory Context
Our Services are designed to support enterprise privacy, security, and compliance programs globally. Customers are responsible for determining which laws apply to their operations, including the Digital Personal Data Protection Act, 2023 (India), GDPR, and other frameworks relevant to their processing activities. This policy does not constitute legal advice.
Children
The Site and Services are directed to business customers and are not intended for individuals under eighteen (18) years of age. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes affecting active subscriptions may be communicated through the Site, by email, or as required by contract.
Contact
For privacy enquiries, data subject requests relating to our controller activities, or security concerns, contact us via the contact section on the home page, [email protected], or [email protected]. Customers with active DPAs should also use the privacy or security contact details specified in their Order Form where available.