Skip to content
NS360

Trust · Privacy

Privacy Policy

Exactly what happens to personal data when you visit this website or send us an inquiry: what the contact form collects, where it goes, who helps us process it, how long we keep it, and how to reach us about it.

In short

  • 01The contact form asks for four things: your name, work email, what you need and a message, plus your agreement to the privacy notice. Everything else is optional.
  • 02Inquiries are kept in our own inquiries database, which only the people at NS360 who handle inquiries can open, for up to 24 months after our last contact unless we start working together.
  • 03The contact form uses your IP address only briefly, to stop spam, and it is not included in the inquiry we receive. Our hosting provider’s logs also record it; we keep those for the period in How long we keep it.
  • 04The site sets no cookies of its own, and nothing here tracks you for advertising.
  • 05You can see, correct or delete your data, withdraw consent, nominate someone or raise a grievance. We respond within 30 days.
  • 06We do not sell personal data, add you to marketing lists, or use your inquiry to train AI models.

01

What this policy covers

This policy covers the NS360 website and the inquiries you send us, not the data inside client projects.

This policy explains how NETSPHERE360 SOLUTIONS PRIVATE LIMITED handles personal data when you visit this website, send us an inquiry through the contact form, or write to one of the email addresses published on this site, including our privacy and security mailboxes.

Client projects are different. When we design, build or run software for a client, the personal data inside that system is the client’s. We handle it only on the client’s instructions, under our contract and any data processing agreement, and the client’s own privacy notice applies to it. Our Security and Compliance pages explain how we work in those engagements.

Other websites we link to have their own privacy policies, which this one does not cover. When we open roles, job applications will come with their own privacy notice.

02

Who we are

NETSPHERE360 SOLUTIONS PRIVATE LIMITED decides how and why the personal data described here is used, and answers for it.

This website is run by NETSPHERE360 SOLUTIONS PRIVATE LIMITED, a private limited company incorporated in India. We trade as NS360 (Netsphere360).

Under India’s Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described in this policy. Where the EU General Data Protection Regulation (GDPR) applies, we are the controller.

  • Registered name: NETSPHERE360 SOLUTIONS PRIVATE LIMITED
  • Brand: NS360 (Netsphere360)
  • Incorporated in: India

For anything about privacy, use the form on our Contact page.

03

What the contact form collects

We ask for your name, work email, what you need and a message, plus your agreement to the privacy notice; everything else is optional.

The form is deliberately short. There is no phone number field and no account to create.

Contact form fields
FieldRequired?What it is for
NameRequiredSo we know who we are talking to. Up to 120 characters.
Work emailRequiredSo we can reply. We use it only for this conversation.
What you needRequired (at least one)One or more of: A new product, An existing product, AI in production, Scale or security, Devices & real-time, Keep it running, Not sure yet.
MessageRequiredYour project or problem, in your own words. Between 20 and 5,000 characters.
CompanyOptionalUp to 160 characters.
StageOptionalOne of: Idea or early concept, Prototype or MVP, Live, with users, Scaling or mature.
TimelineOptionalOne of: As soon as possible, Within 1–3 months, Within 3–6 months, Later / exploring.
BudgetOptionalA range in USD or INR, or Not sure yet.
How you heard about usOptionalOne of: Search engine, AI assistant (ChatGPT, Claude, etc.), LinkedIn, Someone recommended you, A directory or listing, Somewhere else.
NDA firstOptionalAsks us to arrange a non-disclosure agreement before you share details.
Agreement to the privacy noticeRequiredYour agreement to the notice beside the form. The form cannot be sent without it, so every inquiry we receive was sent with your agreement. Its time of arrival shows which version of this policy applied.

Please don’t send passwords, API keys or other credentials, card or bank details, health information or other sensitive personal data through the form or by email. If your project involves confidential material, tick NDA first and we will agree how to share it safely.

The enterprise and partnership enquiry form

The form on our Enterprise page asks for a little more, so we can prepare a proposal. Only four fields are required; the rest can be skipped. It is protected and kept in exactly the same way as the contact form.

Enterprise enquiry form fields
FieldRequired?What it is for
Kind of enquiryRequiredOne of: Enterprise purchase, Partnership.
NameRequiredUp to 120 characters.
Work emailRequiredSo we can reply. We use it only for this conversation.
OrganizationRequiredThe organization you are enquiring for. Up to 160 characters.
Job titleOptionalUp to 120 characters.
CountryOptionalUp to 80 characters.
Organization sizeOptionalOne of: 1 to 50 people, 51 to 250 people, 251 to 1,000 people, 1,001 to 5,000 people, More than 5,000 people.
Products of interestOptionalAny of: Nexynt, Citesvue, MongoQUI, Linkzly, Custom engineering.
Approximate usersOptionalOne of: Up to 25, 26 to 100, 101 to 500, 501 to 2,000, More than 2,000, Not sure yet.
Deployment preferenceOptionalOne of: The vendor’s cloud (standard), Dedicated or private environment, Not sure yet.
TimelineOptionalOne of: Within a month, This quarter, Within six months, Exploring options.
RequirementsOptionalAny of: SSO and identity provider, Integrations with our systems, Data migration, Private deployment, Security review, Custom development, Implementation and training, Ongoing support, Purchase order or invoicing.
Kind of partnershipOptional (partnership enquiries)Any of: Resell or distribute, Refer clients, Implement or integrate, Technology partnership, List our product through NS360.
MessageOptionalUp to 4,000 characters.
Agreement to the privacy noticeRequiredAs for the contact form above.

What the forms handle that you don’t see

Your IP address
Used briefly and not kept by the form: as the key for a limit on how many messages one IP address can send each minute (held in a short-lived counter). It is not included in the inquiry we receive. Our hosting provider’s logs also record it; see How long we keep it.
A signed timestamp
The time the form was loaded, signed with a secret key so it cannot be forged. It contains no personal data. Messages sent within three seconds of loading, or more than two hours later, are treated as automated and are not saved, although you still see a confirmation. If the page has been open for more than two hours, reload it before you send.
A hidden “honeypot” field
A field people never see. Automated tools tend to fill it in; when it is filled, the message is not saved.
The page, the time and a reference
The address of the page you sent the form from (from your browser’s Referer header), the time we received it, and a reference number such as NS-7K2QXW, which we also show you. All three are included in the inquiry.
Browser details
Your browser sends a user-agent string with every request. The form handler does not include it in the inquiry and does not store it.

04

Where your inquiry goes

Your inquiry passes a few automated checks and is then saved in our inquiries database, which only the people who handle inquiries can open.

When you press send, our server handles your inquiry in this order:

  1. Automated checks. The hidden field and the signed timestamp are checked first, then the rate limit. A submission stopped here is not saved. If you reach the rate limit, you are asked to wait a minute; a submission stopped by the hidden field or the timestamp still shows a confirmation, so that automated tools learn nothing.
  2. Validation. Our server checks each field against the limits above, and checks that you agreed to the privacy notice. If something needs fixing, you are told what.
  3. Storage. The inquiry is saved as one record in our inquiries database: the form’s fields as submitted, a readable copy of them, which form you used, the reference number, the time, the page you sent it from, the version of this notice you agreed to, and a status we use to track our reply. The record does not include your IP address or browser details. We reply to the email address you gave us.
  4. Confirmation. You see a confirmation with your reference number. If the inquiry cannot be saved, you are told and asked to try again in a few minutes.

Only a submission that passes every check is saved. The inquiries database runs on Cloudflare D1, part of our hosting provider’s platform. Only the people at NS360 who handle inquiries can open it, through our Cloudflare account, which is protected with multi-factor authentication. When we reply, the conversation continues by email.

Our application logs record only the reference number and the final outcome of each submission, never your name, email address or message.

If you sent an inquiry more than two hours after opening the page, or have not heard back, reload the page and send it again.

If you email us directly instead of using the form, we handle your message in the same way, except that the website checks do not apply and we rely on your choice to send us the details (Section 7(a) of the DPDP Act) rather than on the form’s consent.

05

When you browse the site

Browsing needs no account; our hosting provider processes standard request data to deliver the site and keep it secure.

You can read every page without an account, a sign-in or a form. There are no comments, no chat widgets and nothing embedded from other sites.

Every request to the site passes through Cloudflare, which hosts and delivers it. To do that, Cloudflare processes the information any browser sends with a request: your IP address, the page requested, the time, and technical details such as your browser type and the page you came from. Cloudflare also uses this information to protect the site from attacks and abuse.

Our fonts and images, and our own scripts, are served from our own domain, so browsing does not send your data to font libraries or public code hosts. No scripts are loaded from other sites. The site’s Content Security Policy lets your browser connect only to our own domain and the services named in this policy.

06

Analytics

We currently run no analytics on this site.

No analytics scripts load on any page. If we add analytics, this section will name the tool and what it collects before it goes live.

07

Cookies and similar technologies

We set no cookies, and nothing on this site tracks you for advertising.

This site sets no cookies of its own. We use no analytics, advertising or social-media cookies, and no tracking pixels or fingerprinting.

Cloudflare, which protects the site, may occasionally set a strictly necessary security cookie, for example when it needs to check that traffic from your network is not automated. Such cookies are used only for security.

We do not use cookies, local storage or similar technology to identify you or follow you around the web.

08

How we use personal data

We use your data to reply to you, to keep the site and form safe, and to meet our legal duties. Nothing else.

Purposes, the data used and the basis under India’s DPDP Act
PurposeData usedBasis in India (DPDP Act)
Reply to your inquiry and discuss working together, including arranging an NDA if you ask for oneEverything in the inquiryYour consent, given through the form (Section 6). If you email us directly, the data you chose to send us for this purpose (Section 7(a)).
Keep the contact form free of spam and abuseIP address (briefly), signed timestamp, hidden fieldNeeded to run the form you chose to use, as the notice beside it explains. The IP-based rate limit uses data your browser sends when you send the form (Section 7(a)).
Deliver the website and protect it from attacksIP address and request details, in website logsData your browser sends to receive the site, used only to deliver and protect it (Section 7(a)); for logs we must be able to produce to CERT-In, our legal duty to disclose them (Section 7(d))
Answer privacy requests and grievancesYour contact details, your request and our responseData you give us to make the request (Section 7(a)), and our duties under the DPDP Act
Meet legal obligations, such as a court order or a lawful request from an authorityOnly the data the obligation coversA legal duty to disclose information to the State, or a judgment or order we must comply with (Sections 7(d) and 7(e))

What we never do

  • Sell, rent or trade personal data.
  • Use it for advertising, retargeting or cross-site tracking.
  • Add you to a marketing list. If we ever start a newsletter, joining it will be a separate, explicit choice.
  • Put your personal details into AI tools, or use your inquiry to train AI models. No AI features are connected to the inquiries database, and AI assistant features are switched off in the mailbox we reply from; see Responsible AI.
  • Make decisions about you by automated means alone.
  • Ask for sensitive personal data such as financial, health or biometric information.

10

Who processes data for us

A small number of service providers help us run the site and store inquiries, each under written terms.

We share personal data only with the service providers below, and only what each one needs. They process it on our behalf under written data processing terms, as the DPDP Act requires.

Service providers
ProviderWhat they do for usPersonal data involved
Cloudflare, Inc.Hosts and delivers the website (Cloudflare Workers and its global network), protects it from attacks, keeps its logs, enforces the contact form’s rate limit, and hosts our inquiries database (Cloudflare D1).IP address and request details; everything in the inquiry, stored in our inquiries database.
Our business email providerHosts the NS360 mailbox we reply from, where our correspondence with you is kept.Your name and email address, anything from your inquiry we quote in a reply, and our correspondence with you.

Anyone else?

  • We do not share your inquiry with anyone outside NS360, such as a specialist partner, without asking you first.
  • We disclose personal data to authorities only when Indian law requires it, such as under a valid court order or a lawful direction from a government agency, and only what that requires.
  • If NS360 is ever merged or restructured, inquiry records may pass to the company that takes over, which must continue to honor this policy.

11

Where your data is processed

Some of our providers process data outside India; we use them only under written terms and within the limits Indian law sets.

Cloudflare serves the site from its global network, so your request is usually handled in a data center near you, which may be outside India. We asked Cloudflare to keep our inquiries database in its Asia-Pacific region. Cloudflare treats this as a preference, not a guarantee, so the database and its recovery copies may be held elsewhere, including outside India. Our business email provider, which holds our replies and the correspondence that follows, may store and process it outside India, including in the United States.

The DPDP Act allows personal data to be transferred outside India, except to countries the Government of India restricts by notification. We do not transfer personal data to any country it restricts.

Where the GDPR applies, we rely on the safeguards in our providers’ data processing terms, such as the European Commission’s Standard Contractual Clauses, for onward transfers.

12

How long we keep it

We keep inquiries for up to 24 months after our last contact; every other retention period is listed below.

Retention periods
DataHow long we keep it
Inquiries and our email correspondenceUp to 24 months after our last contact with you, then deleted at our next monthly clean-up. A record deleted from the inquiries database can remain in the database’s point-in-time recovery for up to 30 days before it is gone for good, and deleted emails may stay in our email provider’s recovery store for a short period set by the provider. If we start working together, our contract governs from then on.
Submissions stopped by automated checksNever saved, apart from the log line described in Where your inquiry goes.
IP address used for the rate limitHeld in a short-lived counter that expires within minutes.
Website logs, held by our hosting providerAt least 180 days, as the CERT-In Directions require (and at least one year where the DPDP Rules require it from May 2027), then deleted, unless we need a specific log for longer to investigate an incident.
Privacy requests and grievances24 months after the request is closed, so we can show how we handled it.
NominationsUntil you withdraw the nomination, or until we delete the data it relates to.

The 180-day minimum for website logs comes from the CERT-In Directions of 28 April 2022, which require the logs of ICT systems to be kept securely for a rolling 180 days and produced to CERT-In on request. The Directions ask for these logs to be kept within Indian jurisdiction; CERT-In’s published FAQs allow storage elsewhere if the logs can still be produced when asked. Ours may be stored outside India, and we keep them so we can produce them. We use them only for security, incident response and legal compliance.

You can ask us to delete your inquiry sooner. See Your rights.

13

How we protect it

We collect little, encrypt it in transit, and limit who can see it.

  • The whole site is served over HTTPS, and browsers are told to use nothing else (HTTP Strict Transport Security).
  • A Content Security Policy limits where the site can load scripts, frames and connections from: our own domain and the services named in this policy. It also stops other sites from embedding our pages.
  • The site cannot ask for your camera, microphone or location.
  • Form input is validated on our server, and only an inquiry that passes every check is saved to the inquiries database.
  • Application logs never contain names, email addresses or messages; see Where your inquiry goes.
  • Keys and secrets for form signing and bot verification are kept as encrypted platform secrets, never in source code.
  • Access to the inquiries database, and to our hosting and email accounts, is limited to the people who need it and protected with multi-factor authentication.

We hold no ISO/IEC 27001 certificate or SOC 2 report today. Our Security page describes the practices we follow instead, and our responsible disclosure policy explains how to report a vulnerability.

If something goes wrong

If a breach affects your personal data, we tell you without delay: what happened, what it means for you and what we are doing about it.

  • Once the DPDP Rules’ breach obligations apply in May 2027, we also inform the Data Protection Board of India without delay and send it a detailed report within 72 hours, as the Rules require.
  • We report specified cyber security incidents to CERT-In within 6 hours of noticing them or being told about them, as its Directions of 28 April 2022 require.
  • Where the GDPR applies, we notify the relevant supervisory authority within 72 hours where the GDPR requires it.

14

Your rights

You can see, correct and delete your data, withdraw consent, nominate someone to act for you and raise a grievance; the GDPR adds more rights where it applies.

We offer these rights to everyone who contacts us, whether or not a particular law requires it of us yet.

Under the DPDP Act

Access
A summary of the personal data we hold about you, how we use it, and the service providers and other organizations we have shared it with.
Correction and erasure
Correct, complete or update inaccurate data, or ask us to delete it. We delete it unless the law requires us to keep it, and if so, we tell you why.
Withdrawing consent
Withdraw your consent at any time, as easily as you gave it.
Grievance redressal
Complain to our Grievance Officer about how we handle your data, and get a response within 30 days.
Nomination
Nominate another person to exercise these rights for you in the event of your death or incapacity.

Under the GDPR

The rights above also apply under the GDPR. In addition, you can ask us to restrict our processing, object to processing based on legitimate interests, receive your data in a portable format, and complain to a data protection authority in the EEA.

15

How to exercise your rights

Tell us what you would like; we reply within 30 days, free of charge.

  1. Use the form on our Contact page with the email address you used before: choose Not sure yet under What you need, and start your message with Privacy request.
  2. Tell us which right you want to use. If you have an inquiry reference (it looks like NS-7K2QXW), include it; it helps us find your data quickly.
  3. We confirm the request is yours by replying to the email address linked to your data. We ask for more only if we genuinely cannot confirm it another way.

We acknowledge requests within 5 business days (Monday to Friday, excluding public holidays in India) and respond in full within 30 days. There is no charge.

To nominate someone, send us their name and email address and tell us they are your nominee. You can change or withdraw a nomination the same way. Someone else can also make a request for you if they show us your authorization.

16

Grievance Officer and complaints

Our Grievance Officer handles privacy complaints; if you are not satisfied, you can go to the Data Protection Board of India.

Our Grievance Officer answers questions and complaints about how we handle personal data:

Grievance Officer, NETSPHERE360 SOLUTIONS PRIVATE LIMITED, at the form on our Contact page

We resolve grievances within 30 days of receiving them.

Once the relevant provisions of the DPDP Act take effect in May 2027, if you are not satisfied with our response, you can complain to the Data Protection Board of India. The Act asks you to use our grievance process first. The Act sets the Board up to work as a digital office, so complaints can be made online; when its complaint channel opens, we will link to it here.

If the GDPR applies, you can also complain to the data protection authority in the EEA country where you live or work, or where you believe the problem happened.

17

Children

This site is for businesses, not children, and we do not knowingly collect children’s data.

This website and our services are meant for businesses and professionals. They are not directed at children, who under the DPDP Act are anyone under 18.

We do not knowingly collect personal data from children. If you believe a child has sent us personal data, use the form on our Contact page and we will delete it.

18

Changes to this policy

When this policy changes, the version and date at the top change too, and the changelog records what changed.

We update this policy when the site, our providers or the law change. Each version has an effective date and a version number, shown at the top of this page, and the changelog on this page records what changed.

If a change affects how we use personal data we already hold, we tell the people affected where we have a way to reach them, and ask for consent again where the law requires it.

If you would like this policy in a language listed in the Eighth Schedule to the Constitution of India, such as Hindi or Telugu, ask us and we will provide it.

Revision history

  1. v1.0First published.