In short
- 01NS360 is the brand of NETSPHERE360 SOLUTIONS PRIVATE LIMITED, a private limited company incorporated in India.
- 02For this website and inquiries we are a Data Fiduciary under India’s DPDP Act. On client projects we usually act as a Data Processor, on your instructions and under a written contract.
- 03Most obligations under India’s DPDP Act and the DPDP Rules, 2025 take effect in May 2027. We are preparing now, and we follow the IT Act’s SPDI Rules and CERT-In’s 2022 Directions today.
- 04Where the EU GDPR applies to a project, we sign a data processing agreement and use the Standard Contractual Clauses for transfers to India.
- 05We build and evidence the technical controls behind SOC 2, ISO/IEC 27001, HIPAA, PCI DSS, GDPR and DPDP programs. Any certificate or report comes from your auditor, not from us.
- 06We hold no certifications, attestations or audit reports today. When that changes, this page will say so.
01
Corporate information
The registered details of the company behind NS360, as Indian company law asks every company website to show them.
NS360 (Netsphere360) is the trading brand of NETSPHERE360 SOLUTIONS PRIVATE LIMITED, a private limited company incorporated in India.
- Registered name: NETSPHERE360 SOLUTIONS PRIVATE LIMITED
- Brand: NS360 (Netsphere360)
- Incorporated in: India
- Queries and grievances: Grievance Officer, NETSPHERE360 SOLUTIONS PRIVATE LIMITED, at the form on our Contact page
Our Corporate Identity Number will be listed here before this page goes live.
Why we publish this
Rule 26 of the Companies (Incorporation) Rules, 2014, made under the Companies Act, 2013, asks every company with a website to show on its home page its name, registered office address, Corporate Identity Number, telephone number, fax number (if any), email address, and the name of the person to contact with queries or grievances.
We set out these details in full here and on our About page, and every page of the site links here from its footer.
The same details appear on our agreements and invoices, so you can confirm that the company you speak to is the company you sign with.
02
Our role with data
For our own website we decide how data is used; on client projects we usually process data only on your instructions.
| Context | India’s DPDP Act | EU GDPR, where it applies | Where it is set out |
|---|---|---|---|
| This website and project inquiries | Data Fiduciary | Controller | Our Privacy Policy |
| Client projects | Usually a Data Processor | Usually a processor | Our agreement with you and, where needed, a data processing agreement |
This website and your inquiries
We decide what this website collects and why, so for the contact form and the site itself we are the Data Fiduciary (and, where the GDPR applies, the controller). Our Privacy Policy sets out what we collect, why, who processes it for us and how long we keep it.
Client projects
When we build or run systems that handle your customers’ or employees’ personal data, your organization decides why and how that data is processed. You are the Data Fiduciary, or controller; we are usually your Data Processor, or processor. The DPDP Act lets a Data Fiduciary engage a Data Processor only under a valid contract, and we work that way on every project.
- We process personal data only on your documented instructions, and only for the project.
- We build and test with synthetic or masked data by default, and ask for access to production data only when the work needs it.
- Access is limited to the people working on your project and removed when they no longer need it.
- If an incident affects your data, we tell you without undue delay and in any case within 24 hours of becoming aware of it, sooner if our agreement says so. If an early sign could start one of your own deadlines, such as CERT-In’s 6-hour window, we tell you as soon as we see it, before anything is confirmed.
- When the engagement ends, we return or delete your data within 30 days, unless our agreement says otherwise, and confirm it in writing.
If a project ever required us to decide the purposes of processing ourselves, we would say so and write it into the agreement before work starts.
03
India: DPDP Act and Rules
India’s data protection law is phasing in, with most duties from May 2027, and we are building to it now rather than waiting.
The Digital Personal Data Protection Act, 2023 is India’s general data protection law. The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, bring it into force in phases. The provisions that set up the Data Protection Board of India took effect first. Most obligations on Data Fiduciaries, including notice, consent, security safeguards, breach intimation, retention and erasure, and grievance redress, take effect in May 2027.
What we are doing to be ready
- Notices
- Our Privacy Policy is a standalone notice in plain language. It says what we collect and why, how to withdraw consent, how to exercise your rights and, from May 2027, how to complain to the Data Protection Board. It is versioned and dated. You can ask for it in any language listed in the Eighth Schedule to the Constitution, as the Act requires, and we will provide it.
- Notice and consent records
- The contact form cannot be sent until you agree to the privacy notice beside it, so every inquiry we receive carries that agreement. Each inquiry records when it arrived and its reference number, and because the notice is versioned and dated, we can match an inquiry to the notice in force at the time.
- Your rights
- You can ask to access, correct or erase your personal data, withdraw consent or nominate someone to act for you, through the form on our Contact page. Withdrawing consent is as simple as giving it, and we respond in full within 30 days. The Privacy Policy explains how.
- Breach procedure
- We keep a written incident procedure. For a personal data breach it covers informing the Data Protection Board and each affected person without delay, and sending the Board a detailed report within 72 hours, as the Rules will require from May 2027.
- Security logs
- From May 2027, the DPDP Rules require Data Fiduciaries to keep logs of access to personal data for one year. We are extending our logging and retention to meet that before then.
- Retention schedule
- We keep personal data only as long as its purpose needs, following a written retention schedule. Our Privacy Policy lists the periods.
- Grievance channel
- Complaints come to us first: Grievance Officer, NETSPHERE360 SOLUTIONS PRIVATE LIMITED, at the form on our Contact page. From May 2027, when the relevant provisions of the Act take effect, you can take a complaint we have not resolved to the Data Protection Board of India. The Act asks you to use our grievance process first.
This website is meant for businesses and is not directed at children. For client products that may reach children, we design for the verifiable parental consent the Act and Rules require from May 2027.
If you are a Data Fiduciary
We can build the parts of your system the Act expects to work: consent capture and records, notice versioning, rights-request workflows, erasure that reaches backups on a defined schedule, access logging and breach runbooks. See Supporting your compliance program.
04
India: IT Act and SPDI Rules
Until the DPDP Act replaces them in May 2027, the IT Act’s data protection rules still apply, and we follow them.
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, known as the SPDI Rules, were made under the Information Technology Act, 2000 and give effect to its section 43A. They require a body corporate that handles personal information to publish a privacy policy, collect sensitive personal data only with consent, maintain reasonable security practices and appoint a Grievance Officer.
The DPDP Act removes section 43A from the IT Act in May 2027. Until then, these rules remain in force, and we follow both.
- Our Privacy Policy is published on this site.
- This website does not ask for sensitive personal data or information as the rules define it, such as passwords, financial account details, health information or biometrics.
- Our security practices, proportionate to a company of our size, are described on our Security page.
- Our Grievance Officer addresses grievances within 30 days of receipt, inside the one-month limit the rules set. Contact: Grievance Officer, NETSPHERE360 SOLUTIONS PRIVATE LIMITED, at the form on our Contact page.
The SPDI Rules treat IS/ISO/IEC 27001 as one way to show reasonable security practices, provided it is audited at least once a year by an independent auditor approved by the Central Government. We are not certified or audited against it.
05
India: CERT-In Directions
CERT-In requires fast incident reporting and log retention; we apply it to our own systems and design client systems to support it.
On 28 April 2022, the Indian Computer Emergency Response Team (CERT-In) issued Directions under section 70B(6) of the Information Technology Act, 2000. They apply to service providers, intermediaries, data centers, body corporates and government organizations. The main requirements are:
- Report specified cyber incidents to CERT-In within 6 hours of noticing them or being told about them.
- Keep logs of all ICT systems securely for a rolling 180 days within Indian jurisdiction, and provide them to CERT-In on request. CERT-In’s published FAQs allow logs to be stored outside India if they can still be produced to CERT-In in a reasonable time.
- Synchronize system clocks with the NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or with servers traceable to them.
- Designate a point of contact to liaise with CERT-In, and send CERT-In that person’s details in its prescribed format.
Our own systems
As a body corporate, we treat the Directions as applying to us.
- Our incident procedure starts a 6-hour reporting clock as soon as a reportable incident is noticed, and names who files the report.
- We keep logs of our own systems for at least 180 days, and for one year where the DPDP Rules require it from May 2027, then delete them unless a specific log is needed to investigate an incident. On managed services, we set retention where the service allows it and export logs where it does not, so we can produce them to CERT-In on request.
Systems we build for you
If your organization is covered, your systems have to make these duties practical. Unless you ask otherwise, we design for:
- Centralized, access-controlled logs, kept for at least 180 days to meet CERT-In, and for one year where the DPDP Rules apply to you from May 2027.
- Log storage in India by default, or elsewhere only where the logs can still be produced to CERT-In in a reasonable time.
- Clock synchronization to NIC, NPL or traceable NTP sources, so timestamps line up across services.
- Alerting and an incident runbook that tracks the 6-hour reporting window and gathers what the report needs.
As the covered entity, you file the report; we help you assemble the facts quickly.
06
International clients
For clients outside India, we contract for the data protection law that applies to you, including the EU GDPR.
The EU General Data Protection Regulation (GDPR) applies to our client work when you are subject to it, for example because you are established in the EU or offer services to people there, and we process personal data for you. (How it applies to this website is in our Privacy Policy.) In those projects:
- We sign a data processing agreement that meets Article 28 of the GDPR, on your template or ours.
- For transfers of EU personal data to us in India, including remote access, we use the European Commission’s Standard Contractual Clauses.
- Where UK personal data is involved, we add the UK’s International Data Transfer Addendum to those Clauses.
- We support your transfer assessment with a clear account of where data is accessed from, by whom and under which safeguards.
The data processing agreement and the Standard Contractual Clauses are available on request, before any personal data is shared.
Working within your framework
You may already have a security policy, a vendor-onboarding questionnaire, data residency rules or sector requirements. We work inside them: we use your identity provider and access controls when you ask, keep data in the regions you choose, and answer security questionnaires truthfully, including where the answer is “no”. If a requirement is beyond what we can meet, we tell you before we sign.
07
Supporting your compliance program
We build and evidence the technical controls your program needs; certificates and reports come from your auditor.
If you are working toward SOC 2, ISO/IEC 27001, HIPAA, PCI DSS, GDPR or DPDP readiness, we can build the technical controls your program depends on, and the evidence that shows they operate.
- Identity and access: single sign-on, least-privilege roles, access reviews and automated joiner, mover and leaver changes.
- Change management: protected branches, required reviews and CI/CD pipelines whose history serves as evidence.
- Logging and monitoring: centralized, retained logs, alerting and audit trails for sensitive actions.
- Data protection: encryption in transit and at rest, key and secret management, data classification, and retention and deletion jobs.
- Vulnerability management: dependency and container scanning, patch cadences and tracked remediation.
- Resilience: backups with tested restores, disaster recovery runbooks and incident exercises.
- Privacy operations: consent records, notice versioning and data subject request workflows.
| Framework | What we can help build | Who issues the result |
|---|---|---|
| SOC 2 | Controls and evidence mapped to the Trust Services Criteria | An independent CPA firm, as an attestation report |
| ISO/IEC 27001 | Technical controls and records for your information security management system | An accredited certification body |
| HIPAA (US) | Safeguards for systems that handle protected health information | No official certification exists; you demonstrate compliance and the US Department of Health and Human Services enforces it |
| PCI DSS | Scope reduction and controls for systems that touch cardholder data | A Qualified Security Assessor, or a self-assessment where your acquiring bank permits one |
| GDPR | Privacy by design, records of processing, rights workflows and transfer safeguards | You, as controller, through demonstrated accountability |
| DPDP Act (India) | Consent, notice, rights, retention and breach tooling | You, as Data Fiduciary; the Data Protection Board of India enforces it |
Certification or attestation is issued by your auditor, not by us. We can get your systems ready to be assessed; we cannot pass the assessment for you, and we never describe a client system as “certified” on anyone’s behalf.
Standards we build to
- OWASP ASVS
- Application security requirements. We agree the verification level with you and use it in design and review.
- OWASP Top 10
- The baseline of common web application risks that our code reviews check against.
- NIST SSDF (SP 800-218)
- Secure development practices: preparing the organization, protecting the software, producing well-secured software and responding to vulnerabilities. They shape how we run delivery.
- CIS Benchmarks
- Hardening baselines for cloud accounts, operating systems and containers.
- WCAG 2.2 AA
- Accessibility for the interfaces we design and build. See Accessibility.
Building to a standard is not the same as being certified against it. These are the references we work from, not badges we hold. For AI features, see Responsible AI.
08
Contracts
Confidentiality can start before the first call, and the work we create for you is yours.
- NDA before discovery
- If you ask, we sign a mutual non-disclosure agreement before you share anything sensitive, on your template or ours. The contact form has a box for it.
- Intellectual property
- Our agreements assign to you the intellectual property in the work we create for you, including code, designs and documentation, as the agreement sets out. Open-source components stay under their own licenses. Tools we built before your project stay ours, and the agreement gives you a license to use them with the work. We list both.
- Confidentiality
- Everyone at NS360 who works on your project is bound by written confidentiality and intellectual-property terms. We bring a subcontractor onto your work only with your written agreement, and on terms at least as protective as ours with you.
- Your accounts, your access
- Where possible, code lives in your repositories and infrastructure in your cloud accounts, so you hold the keys, not us.
- Subprocessor transparency
- Before work starts, we list every third-party service that will handle your data or code, and we tell you before adding a new one so you can object.
- Health data (US)
- Before we handle protected health information, we sign a Business Associate Agreement with you.
- End of an engagement
- We remove the access we control on the same business day an engagement ends, and ask you to remove the rest. Within 30 days, unless the agreement says otherwise, we return or delete your data, including working copies of your code, and confirm both in writing.
Terms for using this website are in our Terms. Project terms are in the agreement we sign with you, and our working method is on the Approach page.
09
What we do not claim
We are new and hold no certifications, attestations or audit reports, and we would rather say so than imply otherwise.
As of the effective date of this page:
- We hold no ISO/IEC 27001 certificate, SOC 2 report, PCI DSS assessment or any other certification or attestation.
- We have not commissioned an independent security audit or penetration test of our own systems.
- We are not a law firm and do not give legal advice. We work alongside your counsel or compliance lead.
- We do not describe any client, product or system as compliant or certified on the strength of our work.
When any of this changes, we will update this page with what was obtained, its scope, who issued it and when, and record the change in this page’s changelog.
Questions about compliance, contracts or this page reach us through the form on our Contact page. Privacy requests go through the form on our Contact page. To report a vulnerability, follow our responsible disclosure policy. More about the company is on About.
Revision history
- v1.0First published.