Privacy Policy

How ZenOffense collects, uses, protects and shares your information.

LAST UPDATED: JULY 2026

1. Introduction

ZenOffense ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, contact us, or use our cybersecurity services — including VAPT, ISO certification support, and Red Team assessments. As a cybersecurity company, we hold ourselves to the same standards of data protection that we help our clients achieve.

2. Information We Collect

We may collect the following categories of information:

  • Contact information — name, email address, phone number, and company name that you provide through our contact forms or when engaging our services.
  • Business information — details about your organization's systems, infrastructure, and security posture that you share with us for the purpose of delivering services.
  • Technical information — browser type, device information, and pages visited, collected automatically to improve website performance and security.
  • Communication records — correspondence and support requests, retained to serve you better and maintain engagement history.

3. How We Use Your Information

  • To respond to your enquiries and provide the services you request.
  • To scope, deliver, and report on security engagements (VAPT, ISO, Red Team).
  • To send service updates, security advisories, and — only with your consent — marketing communications.
  • To improve our website, services, and customer experience.
  • To comply with legal obligations and enforce our agreements.

4. How We Protect Your Data

Security is our business. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to client information is restricted to authorized personnel on a strict need-to-know, least-privilege basis, with audit logging in place. Engagement data — including vulnerability findings and assessment reports — is stored in isolated, access-controlled environments and retained only as long as necessary for the engagement and applicable legal requirements.

5. Sharing of Information

We do not sell, rent, or trade your personal information. We may share limited information with trusted service providers who assist in operating our business (for example, hosting or email providers), all of whom are bound by confidentiality obligations. We may also disclose information when required by law, court order, or to protect our legal rights.

6. Cookies

Our website uses a small number of cookies and similar technologies for essential functionality (such as remembering your theme preference) and basic, privacy-respecting analytics. You can control or delete cookies through your browser settings; the site remains fully functional without non-essential cookies.

7. GDPR & Your Rights

If you are located in the European Economic Area (EEA) or another jurisdiction with similar data-protection laws, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing — request that we limit how we use your data.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, contact us at support@zenoffense.com. We will respond within the timeframes required by applicable law.

8. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, deliver contracted services, and meet legal, accounting, or reporting requirements. Engagement artifacts are securely destroyed at the end of their agreed retention period.

9. Third-Party Links

Our website may contain links to external sites. We are not responsible for the privacy practices or content of those sites and encourage you to review their policies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of our website after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, reach us at: