Aceloking
Home How It Works About Contact
Get Started
Home How It Works About Contact Get Started

Privacy Policy

Last Updated: June 10, 2026

Effective Date: June 10, 2026

Aceloking (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website aceloking.com (the “Site”) or use our services (the “Services”).

By using our Site or Services, you agree to the collection and use of information in accordance with this policy.

1. About Aceloking

Aceloking is a subscription-based security engineering practice for B2B SaaS startups closing enterprise deals, with compliance evidence mapped from the same technical work. Our founder, Manish Sharma, operates from India, and serves clients globally.

For the purposes of India’s Digital Personal Data Protection Act, 2023 (“DPDPA”), Aceloking acts as a Data Fiduciary. For the purposes of the EU General Data Protection Regulation (“GDPR”), Aceloking acts as a Data Controller for the personal data we collect directly.

2. Information We Collect

2.1 Information You Provide Directly

Contact Form: When you reach out through our Site, we collect your full name, company name, work email address, phone number (optional), and reason for contact.

Client Intake Form: When you subscribe to our Services, we collect information about your tech stack, cloud provider, existing security tools, compliance requirements, and most urgent security or compliance concern.

Subscription and Payment: Payment details are collected and processed by Dodo Payments, our third-party payment processor. We receive confirmation of payment status and subscription tier but do not store your full payment instrument details on our own systems.

Async Workspace: During service delivery, you may submit security requests, code snippets, architecture descriptions, compliance documentation, and other materials. This data is used solely to deliver our advisory, assessment, and compliance services.

2.2 Information Collected Automatically

Site Usage Data: Our Site is a Hugo static site with minimal tracking. We may collect standard server logs (IP address, browser type, referring page, date and time of visit) for operational and security purposes.

Cookies: We use minimal cookies necessary for Site functionality. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can disable cookies in your browser settings without affecting core Site functionality.

3. How We Use Your Information

We use the information we collect for the following purposes:

PurposeLawful Basis (GDPR)Legal Ground (DPDPA)
To deliver our compliance advisory, security assessment, and deal-readiness ServicesPerformance of a contractConsent / Legitimate Uses (Section 5, DPDPA)
To communicate with you about your account, subscriptions, and service requestsPerformance of a contractConsent
To process payments via Dodo PaymentsPerformance of a contractConsent
To respond to inquiries submitted through our contact formLegitimate interestConsent
To improve our Site and ServicesLegitimate interestLegitimate uses
To comply with legal obligations (tax, regulatory, law enforcement)Legal obligationCompliance with law
To send administrative communications (billing reminders, renewal notices, policy updates)Legitimate interestLegitimate uses

We do not use your personal data for automated decision-making or profiling.

4. Your Rights Under DPDPA 2023

Under India’s Digital Personal Data Protection Act, 2023, you (the “Data Principal”) have the following rights:

  • Right to Access (Section 11): You may request a summary of the personal data we process, the processing activities, and the categories of recipients.
  • Right to Correction and Erasure (Section 12): You may request correction, completion, updating, or erasure of your personal data.
  • Right to Grievance Redressal (Section 13): You have the right to a timely and accessible grievance redressal mechanism.
  • Right to Nominate (Section 14): You may nominate another individual to exercise your rights in the event of your death or incapacity.
  • Right to Withdraw Consent (Section 8(7)): You may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing before withdrawal. The process for withdrawal shall be as easy as the process for giving consent.

To exercise any of these rights, contact us at [email protected]. We will respond within the timelines prescribed under applicable law.

5. Your Rights Under GDPR (EU/EEA Users)

If you are located in the European Union or European Economic Area, you have the following rights under the GDPR:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / right to be forgotten (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object to processing (Article 21)
  • Right to withdraw consent at any time (Article 7(3))

To exercise your GDPR rights, email [email protected] with the subject “GDPR Request.” We will respond within 30 days. If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority.

6. Your Rights Under CCPA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to Know: Request disclosure of the categories and specific pieces of personal data we have collected about you.
  • Right to Delete: Request deletion of your personal data, subject to certain exceptions.
  • Right to Opt-Out: We do not sell personal data.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, email [email protected] with the subject “CCPA Request.” We will verify your identity and respond within 45 days.

7. Data Storage, Retention, and Security

7.1 Storage

Your data is stored on secure cloud infrastructure. We implement reasonable security safeguards as required under Section 8(5) of the DPDPA, including encryption in transit and at rest, access controls, and regular security reviews.

7.2 Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by applicable law:

  • Active clients: Data retained for the duration of the subscription plus 90 days after termination.
  • Contact form inquiries (no subscription): Retained for 12 months.
  • Payment records: Retained as required by Indian tax and accounting law (typically 8 years under the Income Tax Act, 1961).

After the retention period, personal data is deleted or anonymized.

7.3 Security Measures

We apply our own security methodology to our infrastructure. Measures include encryption of data in transit (TLS 1.3) and at rest, role-based access controls, regular vulnerability assessments, and secure workspace authentication.

8. Third-Party Sharing

We share your information only as described below.

8.1 Service Providers

ProviderPurposeData Shared
Dodo PaymentsPayment processing, subscription management, invoicingName, email, payment amount, subscription tier
Async Workspace PlatformService delivery, client communication, file sharingSecurity requests, code snippets, architecture descriptions, compliance documentation

These providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection laws.

8.2 Legal Compliance

We may disclose your information if required by law, court order, or governmental regulation, including under Section 8(6) of the DPDPA and the Information Technology Act, 2000.

8.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. You will be notified via email and prominent notice on our Site.

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

9. International Data Transfers

Aceloking is based in India. Your data is processed and stored in India and may be transferred to other countries where our service providers operate.

Under DPDPA Section 16, cross-border transfers are permitted except to countries restricted by the Central Government of India. We will monitor and comply with any such notifications as they are issued.

For GDPR-governed data, we rely on standard contractual clauses (SCCs) or adequacy decisions as the lawful transfer mechanism where applicable.

10. Children’s Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a child has provided us with personal data, we will delete it promptly. Contact us at [email protected] if you believe a minor has submitted personal data to us.

11. Data Breach Notification

In the event of a personal data breach, we will notify affected individuals and the relevant data protection authority as required under Section 8(6) of the DPDPA, GDPR Articles 33 and 34, and applicable provisions of the Information Technology Act, 2000.

12. Grievance Officer

Under Section 8(9) of the DPDPA and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer to address your concerns regarding data privacy and processing.

Grievance Officer: Manish Sharma Email: [email protected] Response Time: We will acknowledge your grievance within 24 hours and resolve it within 15 days.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised Effective Date and sending an email to active subscribers at least 14 days before changes take effect.

Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

14. Contact Us

  • Email: [email protected]
  • Founder: Manish Sharma
  • Website: aceloking.com

Last updated: June 10, 2026

Aceloking

Security engineering for B2B SaaS startups. Secure code review, cloud security, and penetration testing from a practitioner - compliance evidence for SOC 2, ISO 27001, and DPDPA comes from the same work, with each request returned as a Remediation Blueprint within 72 hours. No lock-in.

Product

  • Services & Pricing
  • How It Works

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Express MNDA

© 2026 Aceloking. All rights reserved.

Privacy Terms Refunds