CertiTrust Consulting is committed to protecting your personal data. This policy explains what we collect, why we collect it, and how we keep it safe — in plain language.
Last updated: 5 May 2026 | Effective date: 5 May 2026
Applicable law: This policy is governed by the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and applicable rules thereunder. References to "personal data" carry the meaning assigned in the DPDP Act.
CertiTrust Consulting ("we", "us", "our") is a professional services firm providing ISO 27001:2022, ISO 27701:2025, SOC 2, IT audit, and cybersecurity advisory services. Our registered office is at 305, Vihav Business Square, Nr. HCG Cancer Hospital, Sun Pharma Road, Atladara, Vadodara — 390012, Gujarat, India.
For data protection queries, contact us at: audit@itauditor.co.in
We collect only the personal data necessary to respond to your enquiry or deliver our services:
We do not collect sensitive personal data (as defined under the DPDP Act), payment card information, or government-issued identification numbers through this website.
We use your personal data solely to:
We do not use your data for automated profiling, targeted advertising, or sale to third parties.
We process your personal data on the following bases under the DPDP Act: (a) consent — provided when you submit a contact form or email us; (b) legitimate interest — to respond to business enquiries; and (c) contractual necessity — where data processing is required to deliver agreed services.
This website uses the following third-party services that may process limited technical data:
We do not use tracking pixels, third-party advertising networks, or any analytics platform on this website.
We retain enquiry data for up to 24 months from the date of last contact, or as required by applicable law or the terms of a signed engagement. Data is securely deleted or anonymised thereafter.
As a data principal under the DPDP Act, you have the right to:
To exercise any of these rights, email us at audit@itauditor.co.in. We will respond within 30 days.
We apply technical and organisational measures proportionate to the risk — including HTTPS transmission, access controls, and data-minimisation practices — to protect your personal data. As an information security consulting firm, the same standards we advise our clients to adopt are applied internally.
This website does not use tracking cookies, analytics cookies, or advertising cookies. Only technically necessary session behaviour is maintained in your browser during your visit. No cookie consent banner is required.
We may update this policy to reflect changes in law or our practices. The "last updated" date at the top of this page will reflect any revision. Continued use of the website after an update constitutes acceptance of the revised policy.
For any privacy-related query or grievance, contact: