Privacy Policy
Last Updated: June 10, 2026
Effective Date: June 10, 2026
Aceloking (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website aceloking.com (the “Site”) or use our services (the “Services”).
By using our Site or Services, you agree to the collection and use of information in accordance with this policy.
1. About Aceloking
Aceloking is a subscription-based security engineering practice for B2B SaaS startups closing enterprise deals, with compliance evidence mapped from the same technical work. Our founder, Manish Sharma, operates from India, and serves clients globally.
For the purposes of India’s Digital Personal Data Protection Act, 2023 (“DPDPA”), Aceloking acts as a Data Fiduciary. For the purposes of the EU General Data Protection Regulation (“GDPR”), Aceloking acts as a Data Controller for the personal data we collect directly.
2. Information We Collect
2.1 Information You Provide Directly
Contact Form: When you reach out through our Site, we collect your full name, company name, work email address, phone number (optional), and reason for contact.
Client Intake Form: When you subscribe to our Services, we collect information about your tech stack, cloud provider, existing security tools, compliance requirements, and most urgent security or compliance concern.
Subscription and Payment: Payment details are collected and processed by Dodo Payments, our third-party payment processor. We receive confirmation of payment status and subscription tier but do not store your full payment instrument details on our own systems.
Async Workspace: During service delivery, you may submit security requests, code snippets, architecture descriptions, compliance documentation, and other materials. This data is used solely to deliver our advisory, assessment, and compliance services.
2.2 Information Collected Automatically
Site Usage Data: Our Site is a Hugo static site with minimal tracking. We may collect standard server logs (IP address, browser type, referring page, date and time of visit) for operational and security purposes.
Cookies: We use minimal cookies necessary for Site functionality. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can disable cookies in your browser settings without affecting core Site functionality.
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Lawful Basis (GDPR) | Legal Ground (DPDPA) |
|---|---|---|
| To deliver our compliance advisory, security assessment, and deal-readiness Services | Performance of a contract | Consent / Legitimate Uses (Section 5, DPDPA) |
| To communicate with you about your account, subscriptions, and service requests | Performance of a contract | Consent |
| To process payments via Dodo Payments | Performance of a contract | Consent |
| To respond to inquiries submitted through our contact form | Legitimate interest | Consent |
| To improve our Site and Services | Legitimate interest | Legitimate uses |
| To comply with legal obligations (tax, regulatory, law enforcement) | Legal obligation | Compliance with law |
| To send administrative communications (billing reminders, renewal notices, policy updates) | Legitimate interest | Legitimate uses |
We do not use your personal data for automated decision-making or profiling.
4. Your Rights Under DPDPA 2023
Under India’s Digital Personal Data Protection Act, 2023, you (the “Data Principal”) have the following rights:
- Right to Access (Section 11): You may request a summary of the personal data we process, the processing activities, and the categories of recipients.
- Right to Correction and Erasure (Section 12): You may request correction, completion, updating, or erasure of your personal data.
- Right to Grievance Redressal (Section 13): You have the right to a timely and accessible grievance redressal mechanism.
- Right to Nominate (Section 14): You may nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to Withdraw Consent (Section 8(7)): You may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing before withdrawal. The process for withdrawal shall be as easy as the process for giving consent.
To exercise any of these rights, contact us at [email protected]. We will respond within the timelines prescribed under applicable law.
5. Your Rights Under GDPR (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights under the GDPR:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure / right to be forgotten (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object to processing (Article 21)
- Right to withdraw consent at any time (Article 7(3))
To exercise your GDPR rights, email [email protected] with the subject “GDPR Request.” We will respond within 30 days. If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority.
6. Your Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: Request disclosure of the categories and specific pieces of personal data we have collected about you.
- Right to Delete: Request deletion of your personal data, subject to certain exceptions.
- Right to Opt-Out: We do not sell personal data.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, email [email protected] with the subject “CCPA Request.” We will verify your identity and respond within 45 days.
7. Data Storage, Retention, and Security
7.1 Storage
Your data is stored on secure cloud infrastructure. We implement reasonable security safeguards as required under Section 8(5) of the DPDPA, including encryption in transit and at rest, access controls, and regular security reviews.
7.2 Retention
We retain personal data only as long as necessary for the purposes described in this policy or as required by applicable law:
- Active clients: Data retained for the duration of the subscription plus 90 days after termination.
- Contact form inquiries (no subscription): Retained for 12 months.
- Payment records: Retained as required by Indian tax and accounting law (typically 8 years under the Income Tax Act, 1961).
After the retention period, personal data is deleted or anonymized.
7.3 Security Measures
We apply our own security methodology to our infrastructure. Measures include encryption of data in transit (TLS 1.3) and at rest, role-based access controls, regular vulnerability assessments, and secure workspace authentication.
8. Third-Party Sharing
We share your information only as described below.
8.1 Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Dodo Payments | Payment processing, subscription management, invoicing | Name, email, payment amount, subscription tier |
| Async Workspace Platform | Service delivery, client communication, file sharing | Security requests, code snippets, architecture descriptions, compliance documentation |
These providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection laws.
8.2 Legal Compliance
We may disclose your information if required by law, court order, or governmental regulation, including under Section 8(6) of the DPDPA and the Information Technology Act, 2000.
8.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. You will be notified via email and prominent notice on our Site.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
9. International Data Transfers
Aceloking is based in India. Your data is processed and stored in India and may be transferred to other countries where our service providers operate.
Under DPDPA Section 16, cross-border transfers are permitted except to countries restricted by the Central Government of India. We will monitor and comply with any such notifications as they are issued.
For GDPR-governed data, we rely on standard contractual clauses (SCCs) or adequacy decisions as the lawful transfer mechanism where applicable.
10. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a child has provided us with personal data, we will delete it promptly. Contact us at [email protected] if you believe a minor has submitted personal data to us.
11. Data Breach Notification
In the event of a personal data breach, we will notify affected individuals and the relevant data protection authority as required under Section 8(6) of the DPDPA, GDPR Articles 33 and 34, and applicable provisions of the Information Technology Act, 2000.
12. Grievance Officer
Under Section 8(9) of the DPDPA and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer to address your concerns regarding data privacy and processing.
Grievance Officer: Manish Sharma Email: [email protected] Response Time: We will acknowledge your grievance within 24 hours and resolve it within 15 days.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised Effective Date and sending an email to active subscribers at least 14 days before changes take effect.
Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
14. Contact Us
- Email: [email protected]
- Founder: Manish Sharma
- Website: aceloking.com
Last updated: June 10, 2026