Data Protection Policy
Corporate data protection and privacy governance framework defining technical safeguards, legal compliance baselines, and data principal rights.
1. Commitment to Data Protection Compliance
Arzenlabs ("Arzenlabs"), an enterprise registered under Udyam Registration Number UDYAM-KL-02-0152552, seeks to comply with applicable data protection and privacy laws in all jurisdictions where we operate.
This Data Protection Policy establishes the organizational standards, administrative controls, and technical safeguards implemented by Arzenlabs to protect personal data processed across our software platforms, engineering workflows, and customer systems.
2. Applicable Legal Frameworks
Arzenlabs aligns its data governance controls with the following statutory frameworks:
- Digital Personal Data Protection (DPDP) Act, 2023: Governing the processing of digital personal data within India.
- Digital Personal Data Protection Rules, 2025: Defining implementation guidelines for data principal consent, data fiduciaries, and breach notifications.
- Information Technology Act, 2000 & IT Rules: Regulating cyber security practices, electronic records, and inter-mediary obligations.
- CERT-In Cyber Security Directions: Mandating incident reporting timelines and system log preservation.
- EU General Data Protection Regulation (GDPR): Where processing involves data subjects located within the European Economic Area (EEA), applying controller/processor principles.
3. Data Fiduciary & Processor Roles
Arzenlabs clearly demarcates its operational role based on the specific processing activity:
Arzenlabs as Data Fiduciary / Controller
We determine the purpose and means of processing for customer account information, website analytics, billing data, employee records, and direct inquiry communications.
Arzenlabs as Data Processor
When enterprise clients engage Arzenlabs for custom infrastructure deployment or database reliability engineering, we process customer data strictly according to client instructions under a Data Processing Agreement (DPA).
4. Core Technical Safeguards
- Encryption Standards: Data in transit is protected using TLS 1.3 encryption. Persistent databases and backup vaults utilize AES-256 encryption.
- Access Control & Least Privilege: Access to production environments is governed by strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA).
- Audit Logging & Integrity: Immutable audit logs are maintained for all administrative system events and access attempts.
5. Data Protection Contact
For inquiries regarding our data protection framework or Data Processing Agreements (DPAs):
Arzenlabs seeks to comply with applicable data protection and privacy laws including the Digital Personal Data Protection Act (DPDP) 2023, Information Technology Act 2000, and applicable international privacy principles.