Privacy Policy

Effective date: 18 July 2026 · Version 2.0

1. Introduction

Baknet Cyber Solutions (“Baknet”, “we”, “us” or “our”) is a cyber security and quality assurance consulting firm with business development headquarters in the United Kingdom and the United Arab Emirates and a service delivery headquarters in Punjab, India. We are committed to protecting personal data in accordance with the laws of every jurisdiction in which we operate.

This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit baknet.io, contact us, engage our services, apply to our training programmes or otherwise interact with us. It is drafted to meet the requirements of, among others: the EU General Data Protection Regulation (GDPR); the UK GDPR and Data Protection Act 2018; the India Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules; the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its Executive Regulations; the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA) and other applicable US state privacy laws; the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA); the Australian Privacy Act 1988 and Australian Privacy Principles; and the New Zealand Privacy Act 2020.

For the purposes of the GDPR and UK GDPR, Baknet Cyber Solutions Ltd is the controller of personal data described in this policy. For the purposes of the DPDP Act, Baknet Cyber Solutions Ltd is the Data Fiduciary. For the purposes of the UAE PDPL, Baknet Cyber Solutions Ltd is the Controller. Contact details, including our designated data protection contact and Grievance Officer, are set out in Section 13.

2. Personal data we collect

We collect the following categories of personal data:

  • Enquiry and contact data. Name, work email address, company, job title, phone number and the content of your message when you use our contact form, email us or call us.
  • Business relationship data. Contact details, correspondence, contractual information and billing details of client, partner and supplier representatives.
  • Training and recruitment data. Information you submit when applying for our training programmes, internships or roles, such as your CV, education, work history and contact details.
  • Technical data. IP address, browser type and version, device information, pages visited and referring URLs, collected through server logs and the cookies described in our Cookie Policy.

We do not intentionally collect special category or sensitive personal data through this website, and we ask that you do not submit such data through our forms. Where our professional services require access to client systems or data, that access is governed by the engagement contract and applicable data processing terms, under which Baknet ordinarily acts as a processor (or equivalent role) on the client’s documented instructions.

3. How and why we use personal data

We use personal data to: respond to enquiries and provide requested information; prepare proposals and deliver contracted services; administer training programmes, internships and recruitment; manage client, partner and supplier relationships, including invoicing; operate, secure and improve this website; comply with legal, regulatory, tax and audit obligations; and establish, exercise or defend legal claims.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decision-making that produces legal or similarly significant effects.

4. Legal bases for processing

Where the GDPR, UK GDPR or similar laws apply, we rely on: contract (to take steps at your request before entering a contract and to perform it); legitimate interests (responding to business enquiries, securing our website and systems, and managing business relationships, balanced against your rights); legal obligation (tax, accounting and regulatory duties); and consent, where we specifically request it, which you may withdraw at any time.

Where the India DPDP Act applies, we process digital personal data on the basis of your consent or for certain legitimate uses recognised by that Act, such as a voluntary provision of data for a specified purpose. Where the UAE PDPL applies, we process personal data on the bases permitted by that law, including consent, contractual necessity and compliance with applicable legislation.

5. Sharing and disclosure

We share personal data only with: our group entities and delivery teams in the UK, UAE and India for the purposes described above; service providers who support our operations (such as hosting, email and business systems) under contracts that restrict their use of the data; professional advisers such as auditors, insurers and lawyers where necessary; and courts, regulators or law enforcement where disclosure is required by law. We require all processors to protect personal data to standards consistent with this policy.

6. International transfers

Because we operate across the UK, UAE, India and other regions, personal data may be transferred between these locations. Where personal data is transferred from the EU, UK or other jurisdictions that restrict international transfers, we use lawful transfer mechanisms, including adequacy decisions where available, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and the transfer conditions of the UAE PDPL and the India DPDP Act, together with supplementary technical and organisational safeguards.

7. Retention

We retain personal data only as long as necessary for the purposes described in this policy: enquiry data for as long as needed to handle the enquiry and for a reasonable follow-up period; contractual and billing records for the periods required by tax, accounting and limitation laws; recruitment and training data for the duration of the process and any agreed talent-pool period; and technical logs for short, security-appropriate periods. When data is no longer required, it is deleted or irreversibly anonymised.

8. Security

We apply the same discipline to our own data that we bring to client engagements: encryption of data in transit, access on a least-privilege basis, logging and monitoring, and organisational controls aligned with ISO/IEC 27001:2022 practices. No system is perfectly secure, and we cannot guarantee absolute security, but we review and test our controls continuously. If a personal data breach occurs, we will notify affected individuals and the competent authorities where and when applicable law requires, including the notification requirements of the GDPR, UK GDPR, DPDP Act and UAE PDPL.

9. Your rights

European Union and United Kingdom

If you are in the EU/EEA or the UK, you have the rights of access, rectification, erasure, restriction of processing, data portability and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority, including the Information Commissioner’s Office (ICO) in the UK or your local EU data protection authority.

India

If the DPDP Act applies to our processing of your digital personal data, you have the right to access a summary of the personal data we process about you, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity. You may withdraw consent at any time with effect for future processing. Complaints may be raised first through our Grievance Officer (Section 13), and thereafter with the Data Protection Board of India in the manner prescribed by law.

United Arab Emirates

If the UAE PDPL applies, you have rights to access your personal data and information about its processing, to rectification and erasure, to restrict or object to processing in the circumstances defined by the PDPL, to data portability, and to withdraw consent. Complaints may be made to the UAE Data Office in accordance with the PDPL and its Executive Regulations. Separate regimes apply within the DIFC and ADGM financial free zones where relevant.

United States

If you are a resident of California or another US state with a comprehensive privacy law, you have, subject to that law: the right to know the categories and specific pieces of personal information collected, the rights to deletion and correction, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information as those terms are defined), the right to limit use of sensitive personal information (which we do not collect through this site), and the right not to be discriminated against for exercising your rights. You may exercise these rights, including through an authorised agent, using the contact details in Section 13.

Canada, Australia and New Zealand

If PIPEDA, the Australian Privacy Act or the New Zealand Privacy Act 2020 applies, you have rights of access to and correction of your personal information and the right to complain to us and to the relevant authority: the Office of the Privacy Commissioner of Canada, the Office of the Australian Information Commissioner, or the Office of the Privacy Commissioner (New Zealand).

We respond to verified rights requests within the timeframes required by the applicable law, free of charge except where that law permits a fee for manifestly unfounded or excessive requests.

10. Children

This website and our services are directed at businesses and professionals. We do not knowingly collect personal data from children as defined by applicable law (including persons under 18 for the purposes of the DPDP Act), and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided personal data to us, contact us and we will delete it.

11. Third-party links

This website may link to third-party sites, including client and partner sites. We are not responsible for their privacy practices, and this policy does not apply to them. Review the privacy policy of any site you visit.

12. Changes to this policy

We review this policy regularly and update it when our practices or legal obligations change. Material changes will be signposted on this page with a revised effective date and version number. Where a change requires fresh consent under applicable law, we will seek it.

13. Contact, Grievance Officer and complaints

To exercise any right, withdraw consent, or ask a question about this policy, contact our designated data protection contact. The same individual serves as our Grievance Officer for the purposes of the India DPDP Act and the DPDP Rules, and as our nominated privacy contact wherever applicable law in any other jurisdiction requires a named officer or representative:

  • Name: Ramandeep Singh Bakshi
  • Designation: Director, Information Security & QA
  • Organisation: Baknet Cyber Solutions Ltd
  • Address: Baknet Cyber Solutions, 124 City Road, London, EC1V 2NX, United Kingdom
  • Email: ramandeep@baknet.uk (mark your message “Data Protection Request”, or “Attention: Grievance Officer” for India DPDP Act matters)
  • Phone: India +91-89286-49091 · USA and Canada +1-437-886-1175 · UK and rest of world +44-7458-149124

General enquiries may also be sent to contact@baknet.io. We will acknowledge and respond to rights requests and grievances within the timelines prescribed by the applicable law. Postal contact points: Business Development HQs, United Kingdom and UAE; Service Delivery HQ, Punjab, India.

If you remain dissatisfied after contacting us, you may complain to the authority for your jurisdiction identified in Section 9.